Investigation Workspace

Entity: 109.205.180.195 (Ip)

Entity Details
Type
Ip
ASN
AS51167 - Contabo GmbH
Threat Intelligence
Multiple attempts to access sensitive configuration files (.env, mysql.sql) and Local File Inclusion (LFI) attempts, evidenced by WAF rule hits (LFI-ANOMALY) and a high ratio of detected threat requests.
Linked Entities
TLS Fingerprints (1)
Hostnames Targeted
Hostname Request Count
www.darcherif.fr 259
akamai.darcherif.fr 53
Paths Targeted (with Request Counts)
Path Request Count
/ 8
.env.dev.local 3
env.sh 2
debug/default/view 2
bucoffea/.env 2
platform/.env 2
phpinfo.php 2
error.log 2
.env.example 2
icons/.env 2
postfixadmin/.env 2
source/.env 2
mail/.env 2
rust-backend/dao/.env 2
config/config.yml 2
api/register 2
option/.env 2
server-status 2
_ignition/ 2
api/env 2
.env.test 2
micro-app-react/.env 2
env/.env 2
wp-config.php.backup 2
fastlane/.env 2
debug-output.txt 2
en/.env 2
owncloud/.env 2
info.php.back 2
wp-content/mysql.sql 2
tools/phpinfo.php 2
.env.swp 2
.bash_history 2
key.pem 2
_info.php 2
.env.stage 2
application/.env 2
yarn-debug.log 2
psnlink/.env 2
admin/.env 2
node_modules/.env 2
app/config/.env 2
examples/react-dashboard/backend/.env 2
theme/.env 2
test/fixtures/app_types/rails/.env 2
django-blog/.env 2
results 2
conn.asp.bak 2
phpinfo.php3 2
Dockerfile 2
🚫

Block

Multiple attempts to access sensitive configuration files (.env, mysql.sql) and Local File Inclusion (LFI) attempts, evidenced by WAF rule hits (LFI-ANOMALY) and a high ratio of detected threat requests.

2026-02-16 17:52:42