Investigation Workspace

Entity: 40.83.76.149 (Ip)

Entity Details
Type
Ip
ASN
AS8075 - Microsoft Corporation
Threat Intelligence
All requests (100%) from this IP were flagged by WAF, accessing suspicious PHP files, and triggered an 'IPBLOCK' deny rule. Its associated ASN (AS8075) is already blocklisted for persistent malicious activity.
Linked Entities
Hostnames Targeted
Hostname Request Count
akamai.darcherif.fr 126
Paths Targeted (with Request Counts)
Path Request Count
api.php 2
bless.php 2
as.php 2
karak.php 1
class.php 1
wp.php 1
alfa.php 1
2.php 1
406.php 1
dex.php 1
321.php 1
doc.php 1
info.php 1
cc.php 1
jp.php 1
r.php 1
autoload_classmap.php 1
moon.php 1
mini.php 1
bs1.php 1
ant.php 1
max.php 1
css.php 1
new.php 1
zfile.php 1
ar.php 1
content.php 1
file1.php 1
ioxi-rex4.php7 1
angelV2.php 1
about.php 1
mpvloi.php 1
goat1.php 1
wp-includes/rest-api/alfa-rex.php7 1
simple.php 1
classwithtostring.php 1
xmrlpc.php 1
lock360.php 1
gecko.php 1
makeasmtp.php 1
ioxi-o.php 1
NewFile.php 1
warm.PhP7 1
chosen.php 1
pekok.php 1
cloud.php 1
wp-activate.php 1
radio.php 1
manager.php 1
bak.php 1
🚫

Block

All requests (100%) from this IP were flagged by WAF, accessing suspicious PHP files, and triggered an 'IPBLOCK' deny rule. Its associated ASN (AS8075) is already blocklisted for persistent malicious activity.

2025-12-10 00:46:02