Investigation Workspace

Entity: 35.75.145.215 (Ip)

Entity Details
Type
Ip
Linked Entities
TLS Fingerprints (2)
Hostnames Targeted
Hostname Request Count
www.darcherif.fr 15
1
Paths Targeted (with Request Counts)
Path Request Count
/ 1
akam/13/495284bd 1
akam/13/pixel_495284bd 1
wp-includes/js/masonry.min.js 1
wp-content/plugins/mesmerize-companion/theme-data/mesmerize/assets/js/companion.bundle.min.js 1
wp-content/themes/mesmerize/assets/css/theme.bundle.min.css 1
wp-content/themes/mesmerize/assets/js/theme.bundle.min.js 1
wp-content/themes/highlight/customizer/sections/content.css 1
wp-includes/js/jquery/jquery.min.js 1
wp-includes/css/dist/block-library/style.min.css 1
wp-content/themes/mesmerize/style.min.css 1
wp-content/themes/highlight/style.min.css 1
wp-includes/js/jquery/jquery-migrate.min.js 1
wp-content/themes/highlight/assets/js/theme-child.js 1
wp-includes/js/imagesloaded.min.js 1
wp-content/plugins/mesmerize-companion/theme-data/mesmerize/assets/css/companion.bundle.min.css 1
ℹ️

Ignore

Entity accessed standard WordPress paths without triggering any WAF flags, security rules, or detected threat requests. Activity appears benign.

2026-02-14 03:17:00
ℹ️

Ignore

Analysis shows no suspicious activity. All accessed paths are standard WordPress paths, and there are no WAF flags, security rule hits, or detected threat requests.

2026-02-14 03:27:09
ℹ️

Watchlist

The entity's 'last_seen' timestamp is in the future (2026-02-14T03:02:37), which indicates a severe data integrity issue or potential log manipulation. Further investigation is required to determine the cause and impact.

2026-02-14 03:37:15
ℹ️

Ignore

This IP address shows no detected threat requests or WAF rule hits. All accessed paths are legitimate WordPress static files. The current data contradicts the previous high AI confidence and critical severity assessment.

2026-02-14 07:28:14
ℹ️

Watchlist

IP accessed multiple WordPress-related paths (wp-content, wp-includes) indicative of scanning or reconnaissance. The 'last_seen' timestamp is in the future, suggesting a data anomaly or a highly unusual event. No direct threats were flagged by WAF or security rules.

2026-02-14 07:38:20
ℹ️

Ignore

No new malicious activity detected. All accessed paths are legitimate, and no WAF flags or threat requests were recorded. Current observations contradict initial watchlist flagging.

2026-02-14 08:08:31
ℹ️

Watchlist

Initial access to WordPress resources from an AWS IP associated with an external domain (darcherif.fr). No immediate threats or WAF flags detected, but warrants monitoring for any developing patterns.

2026-02-14 08:18:44
ℹ️

Ignore

No detected threat requests, WAF flags, or security rule hits. AI confidence score is low, indicating no current malicious activity.

2026-02-14 12:39:29
ℹ️

Ignore

No malicious activity detected. All accessed paths are common WordPress files, no WAF flags, no threat requests, and no security rule hits observed.

2026-02-14 12:49:37
ℹ️

Watchlist

Observed accessing numerous common WordPress paths, potentially indicating reconnaissance. While no explicit malicious activity or WAF flags were detected, the 'last_seen' timestamp is unusually in the future (2026-02-14), which warrants continued monitoring for unusual behavior or potential data anomalies.

2026-02-14 12:59:44
ℹ️

Ignore

No current malicious activity observed: 0 detected threat requests, 0 WAF flags, and no security rule hits. All accessed paths are standard WordPress files, except for 'akam/13/495284bd' which is not malicious in isolation. The entity's traffic does not support its current watchlist status.

2026-02-14 14:40:09
ℹ️

Ignore

No suspicious activity observed. All accessed paths are standard components of a WordPress site, and there are no recorded WAF flags, security rule hits, or detected threat requests. The IP belongs to Amazon and resolves to a legitimate-looking hostname.

2026-02-14 14:50:23
ℹ️

Watchlist

The 'last_seen' timestamp for this entity is in the future (2026-02-14T03:02:37), which indicates a significant data anomaly or potential system clock manipulation. While no direct malicious activity (WAF flags, threat requests, or security rule hits) was detected, this anomaly warrants further investigation and observation.

2026-02-14 15:00:38
ℹ️

Ignore

No detected threat requests, WAF flags, or security rule hits observed during the current period. The activity appears benign, primarily accessing WordPress assets.

2026-02-15 00:12:30
ℹ️

Ignore

No WAF flags, no detected threat requests, and no security rule hits. Traffic appears legitimate and does not exhibit any suspicious behavior.

2026-02-15 00:22:41
ℹ️

Ignore

No malicious activity detected. Entity exhibits standard WordPress accesses with no WAF flags, detected threat requests, or security rule hits. Appears to be benign.

2026-02-15 00:32:51
ℹ️

Watchlist

The 'last_seen' timestamp is in the future (2026-02-14T03:02:37), indicating a potential data integrity issue or an attempt to obfuscate activity. While no immediate security rule hits or WAF flags were observed, this anomaly warrants further investigation.

2026-02-15 00:42:58
ℹ️

Watchlist

Entity previously identified by AI with high confidence (0.9) and medium severity. No new active threats or WAF flags detected in the current observation period, but continued monitoring is warranted.

2026-02-15 01:03:09
ℹ️

Watchlist

Previously flagged by AI with high confidence and medium severity. No new activity observed in the current period to either confirm maliciousness or justify removal from watchlist; continued monitoring is required.

2026-02-15 01:33:22
ℹ️

Watchlist

Previously flagged by AI with high confidence (0.9 score). No new activity or threats observed since first seen to warrant immediate blocking or removal from watchlist.

2026-02-15 11:15:08
ℹ️

Ignore

Entity shows no observed activity (0 total requests, 0 detected threat requests, no paths accessed) since its last brief appearance, despite being on the watchlist. No current evidence justifies its continued inclusion.

2026-02-15 14:45:48
ℹ️

Watchlist

Entity's last_seen timestamp is in the future (2026), indicating a potential data anomaly or sophisticated spoofing attempt, despite no other immediate threat indicators.

2026-02-15 14:55:56
ℹ️

Watchlist

Previously flagged by AI with medium confidence and severity, and accessing a potentially unusual path ('akam/13/495284bd'), though no direct WAF or security rule hits were observed in recent activity. Requires further monitoring.

2026-02-15 15:06:03
ℹ️

Ignore

No recent activity, zero requests, and no security rule hits observed since initial detection.

2026-02-15 22:27:24
ℹ️

Ignore

No malicious activity detected. IP accessed common WordPress paths with no WAF flags, security rule hits, or detected threat requests. Associated hostname 'www.darcherif.fr' appears legitimate.

2026-02-15 22:37:32
ℹ️

Watchlist

IP associated with Amazon AWS accessing standard WordPress paths for 'www.darcherif.fr'. No WAF flags, threat detections, or security rule hits. Observed a future 'last_seen' timestamp which is anomalous, but no other suspicious activity was identified. Appears benign, continued monitoring recommended for any new behavioral changes.

2026-02-15 22:47:41
ℹ️

Ignore

No suspicious activity detected in the current access logs. All accessed paths are legitimate WordPress files, and there are no WAF flags, security rule hits, or detected threat requests. AI details also indicate low severity.

2026-02-16 00:48:15
ℹ️

Watchlist

The 'last_seen' timestamp is in the future (2026-02-14T03:02:37), indicating a significant data anomaly or logging issue. While no direct malicious activity (such as detected threat requests, WAF flags, or security rule hits) was observed from the network activity itself, the integrity issue of the timestamp warrants keeping this entity in the watchlist for further investigation into the data source or potential underlying system issues.

2026-02-16 00:58:26
ℹ️

Ignore

No recent malicious activity detected. All accessed paths are legitimate WordPress static assets, with zero threat requests, WAF flags, or security rule hits. Previous AI assessment likely a false positive or outdated.

2026-02-16 06:49:50