Investigation Workspace

Entity: 52.169.124.184 (Ip)

Entity Details
Type
Ip
ASN
AS8075 - Microsoft Corporation
Threat Intelligence
All requests (100%) from this IP were detected as threats, accessing highly suspicious PHP files including a known WordPress File Manager exploit ('wp-content/plugins/hellopress/wp_filemanager.php'), and triggered a critical 'IPBLOCK' WAF deny rule. Its associated ASN (AS8075) is already blocklisted for persistent and identical malicious activity from multiple other IPs.
Linked Entities
Hostnames Targeted
Hostname Request Count
akamai.darcherif.fr 31
Paths Targeted (with Request Counts)
Path Request Count
data.php 1
ceiif.php 1
e.php 1
nf.php 1
990.php 1
xxxx.php 1
ws.php 1
abcd.php 1
z.php 1
1.php 1
pro.php 1
sst.php 1
css.php 1
ver.php 1
ultra.php 1
baixy.php 1
error.php 1
class-db.php 1
wp-configs.php 1
bgymj.php 1
check.php 1
file56.php 1
tmpls.php 1
davaa.php 1
wp-content/plugins/hellopress/wp_filemanager.php 1
wp-good.php 1
xmlrpc.php 1
image.php 1
file22.php 1
wp-header-json.php 1
fm.php 1
🚫

Block

All requests (100%) from this IP were detected as threats, accessing highly suspicious PHP files including a known WordPress File Manager exploit ('wp-content/plugins/hellopress/wp_filemanager.php'), and triggered a critical 'IPBLOCK' WAF deny rule. Its associated ASN (AS8075) is already blocklisted for persistent and identical malicious activity from multiple other IPs.

2026-01-26 07:40:36