Blocks IP addresses searching for suspicious PHP files in website root directories, commonly associated with web shells, malware and WordPress exploit scanners.
Why Are These IP Addresses Listed?
- Requests targeting PHP files that legitimate visitors normally never access.
- Large numbers of requests to root PHP files within a short period.
- Typical web shell filenames such as shell.php, x.php, fileXX.php and wp-load.php probes.
- Often originates from VPS or cloud infrastructure.
- After reaching the threshold the IP is added to IPSet and blocked at firewall level.
Data from this security module is automatically included in the public Threat Intelligence Feed.
