Investigation Workspace

Entity: 91.224.92.99 (Ip)

Entity Details
Type
Ip
ASN
AS209605 - UAB Host Baltic
Threat Intelligence
Detected brute-force or credential stuffing attempts targeting 'wp-login.php', with WAF flagging the path and triggering security alert '3900998'. Associated ASN (AS209605) has other IPs blocklisted for similar WordPress enumeration and bot activity.
Linked Entities
TLS Fingerprints (3)
Hostnames Targeted
Hostname Request Count
akamai.darcherif.fr 107
www.darcherif.fr 102
Paths Targeted (with Request Counts)
Path Request Count
wp-login.php 100
_sec/cp_challenge/challenge 27
/ 6
feed/ 5
xmlrpc.php 5
wp/wp-includes/wlwmanifest.xml 5
site/wp-includes/wlwmanifest.xml 5
shop/wp-includes/wlwmanifest.xml 5
2020/wp-includes/wlwmanifest.xml 5
cms/wp-includes/wlwmanifest.xml 5
2021/wp-includes/wlwmanifest.xml 5
blog/wp-includes/wlwmanifest.xml 5
2019/wp-includes/wlwmanifest.xml 5
wp-includes/ID3/license.txt 5
wp1/wp-includes/wlwmanifest.xml 5
wordpress/wp-includes/wlwmanifest.xml 5
web/wp-includes/wlwmanifest.xml 5
test/wp-includes/wlwmanifest.xml 5
index.php/author/admin3157/ 1
ℹ️

Watchlist

Accessed 'wp-login.php' and triggered a WAF alert indicative of brute-force attempts. Not enough deny rules or total threat requests to block immediately, but requires monitoring.

2025-12-17 08:29:42
ℹ️

Watchlist

Entity continues to target wp-login.php with a low rate of threat requests (25%) and triggered a relevant alert (3900998), requiring further monitoring but not immediate blocking.

2025-12-17 08:49:40
ℹ️

Ignore

No new activity or detected threat requests since being added to the watchlist, suggesting it's no longer a threat or was a false positive.

2025-12-17 09:59:31
🚫

Block

Detected brute-force or credential stuffing attempts targeting 'wp-login.php', with WAF flagging the path and triggering security alert '3900998'. Associated ASN (AS209605) has other IPs blocklisted for similar WordPress enumeration and bot activity.

2025-12-17 10:09:33