Investigation Workspace

Entity: 40.115.138.121 (Ip)

Entity Details
Type
Ip
ASN
AS8075 - Microsoft Corporation
Threat Intelligence
Accessed multiple highly suspicious PHP paths commonly associated with web shell uploads or compromise attempts (e.g., hehe.php, wp-content/cong.php, alfa-rex.php, admin/function.php).
Linked Entities
TLS Fingerprints (1)
Hostnames Targeted
Hostname Request Count
www.darcherif.fr 222
Paths Targeted (with Request Counts)
Path Request Count
autoload_classmap.php 3
admin.php 3
file.php 3
about.php 2
wp-includes/images/ 2
wp-content/admin.php 2
wp-includes/html-api/ 2
ioxi-o.php 2
chosen.php 2
functions.php 2
xmlrpc.php 2
flower.php 2
file5.php 2
.well-known/ 2
goods.php 2
index/function.php 2
wp-includes/ 2
inputs.php 2
wp-content/uploads/ 2
defaults.php 2
radio.php 2
1.php 2
edit.php 2
cgi-bin/ 2
wp-includes/ID3/autoload_classmap.php 1
cgi-bin/wp-login.php 1
wp-content/uploads/json.php 1
wp-admin/setup-config.php 1
wp-admin/css/colors/index.php 1
wp-content/uploads/2024/index.php 1
wp-includes/shell20211028.php 1
.well-known/gecko-litespeed.php 1
wp-admin/css/colors/blue/atomlib.php 1
wp-includes/ID3/file.php 1
wp-admin/css/colors/modern/ 1
wp-includes/customize/ 1
aa.php 1
wp-content/file.php 1
wp-content/alfa.php 1
modules/ 1
wp-includes/file.php 1
wp-content/index.php 1
wp/wp-admin/includes/ 1
wp-admin/network/chosen.php 1
wp-content/plugins/ 1
wp-content/style-css.php 1
assets/images/doc.php 1
wp-includes/css/dist/ 1
wp-admin/network/ 1
wp-includes/block-supports/ 1
🚫

Block

Accessed multiple highly suspicious PHP paths commonly associated with web shell uploads or compromise attempts (e.g., hehe.php, wp-content/cong.php, alfa-rex.php, admin/function.php).

2026-02-18 12:20:45