Investigation Workspace

Entity: 4.205.16.4 (Ip)

Entity Details
Type
Ip
ASN
AS8075 - Microsoft Corporation
Threat Intelligence
All requests detected as threats, probing for common web shell locations and WordPress vulnerabilities. IP has triggered IPBLOCK deny rules, indicating previous malicious activity.
Linked Entities
Hostnames Targeted
Hostname Request Count
akamai.darcherif.fr 91
Paths Targeted (with Request Counts)
Path Request Count
file.php 2
wp-good.php 2
goods.php 2
ioxi-o.php 2
as.php 2
admin.php 2
wp-content/admin.php 2
about.php 2
adminfuns.php 2
classwithtostring.php 2
info.php 2
wp-includes/js/crop/cropper.php 1
abcd.php 1
wp-admin/network/index.php 1
wp-content/themes/admin.php 1
wp-content/uploads/ 1
index/function.php 1
wp-admin/css/colors 1
wp-content/plugins/hellopress/wp_filemanager.php 1
wp-includes/html-api/ 1
wp-content/themes/ 1
wp-admin/js/widgets/ 1
wp-admin/css/colors/ectoplasm/ 1
wp-admin/alfa.php 1
wp-content/themes/hideo/network.php 1
wp-content/plugins/WordPressCore/ 1
wp-admin/user/index.php 1
wp-includes/images/ 1
wp-includes/PHPMailer/ 1
wp-content/themes/index.php 1
wp-content/plugins/core-plugin/include.php 1
autoload_classmap.php 1
function/function.php 1
xmrlpc.php 1
wp-admin/js/ 1
wp-includes/Requests/src/Response/about.php 1
wp-content/plugins/index.php 1
chosen.php 1
xmlrpc.php 1
wp-content/uploads/index.php 1
test1.php 1
wp-includes/IXR/test1.php 1
.well-known/ 1
wp-includes/ID3/ 1
uploads/ 1
ws.php 1
cgi-bin/ 1
moon.php 1
o.php 1
css/autoload_classmap.php 1
🚫

Block

All requests detected as threats, probing for common web shell locations and WordPress vulnerabilities. IP has triggered IPBLOCK deny rules, indicating previous malicious activity.

2026-03-13 23:57:50