Investigation Workspace

Entity: 91.224.92.99 (Ip)

Entity Details
Type
Ip
ASN
AS209605 - UAB Host Baltic
Threat Intelligence
Detected brute-force or credential stuffing attempts targeting 'wp-login.php', with WAF flagging the path and triggering security alert '3900998'. Associated ASN (AS209605) has other IPs blocklisted for similar WordPress enumeration and bot activity.
Linked Entities
TLS Fingerprints (3)
Hostnames Targeted
Hostname Request Count
www.darcherif.fr 86
akamai.darcherif.fr 65
Paths Targeted (with Hostname Counts)
Path Distinct Hostnames
feed/ 1
wp-login.php 1
xmlrpc.php 1
wp/wp-includes/wlwmanifest.xml 1
site/wp-includes/wlwmanifest.xml 1
shop/wp-includes/wlwmanifest.xml 1
2020/wp-includes/wlwmanifest.xml 1
cms/wp-includes/wlwmanifest.xml 1
_sec/cp_challenge/challenge 1
2021/wp-includes/wlwmanifest.xml 1
blog/wp-includes/wlwmanifest.xml 1
index.php/author/admin3157/ 1
2019/wp-includes/wlwmanifest.xml 1
wp-includes/ID3/license.txt 1
wp1/wp-includes/wlwmanifest.xml 1
wordpress/wp-includes/wlwmanifest.xml 1
web/wp-includes/wlwmanifest.xml 1
test/wp-includes/wlwmanifest.xml 1
ℹ️

Watchlist

Accessed 'wp-login.php' and triggered a WAF alert indicative of brute-force attempts. Not enough deny rules or total threat requests to block immediately, but requires monitoring.

2025-12-17 08:29:42
ℹ️

Watchlist

Entity continues to target wp-login.php with a low rate of threat requests (25%) and triggered a relevant alert (3900998), requiring further monitoring but not immediate blocking.

2025-12-17 08:49:40
ℹ️

Ignore

No new activity or detected threat requests since being added to the watchlist, suggesting it's no longer a threat or was a false positive.

2025-12-17 09:59:31
🚫

Block

Detected brute-force or credential stuffing attempts targeting 'wp-login.php', with WAF flagging the path and triggering security alert '3900998'. Associated ASN (AS209605) has other IPs blocklisted for similar WordPress enumeration and bot activity.

2025-12-17 10:09:33