Investigation Workspace

Entity: 134.122.136.96 (Ip)

Entity Details
Type
Ip
ASN
AS152194 - CTG Server Limited
Threat Intelligence
Multiple critical WAF deny rules triggered, including LFI, command injection, XSS, and bot impersonation, indicating severe malicious probing and exploit attempts. All accessed paths were flagged.
Linked Entities
TLS Fingerprints (1)
Hostnames Targeted
Hostname Request Count
www.darcherif.fr 1891
Paths Targeted (with Request Counts)
Path Request Count
nuclei.svg 204
/ 151
index.php 89
wp-admin/admin-ajax.php 15
install.php 10
install/ 9
_session 9
install 7
index.action 7
login 6
miscadmin 6
setup 5
install/index.php 4
wls-wsat/CoordinatorPortType 4
solr/admin/cores 4
Users/authenticatebyname 4
cgi-bin/account_mgr.cgi 4
install/install.php 4
json 4
include/thumb.php 4
login.php 3
eam/vib 3
cgi-bin/webproc 3
wp-admin/admin-post.php 3
tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp 3
Visitor/bin/WebStrings.srf 3
__ 3
cgi-bin/kerbynet 3
download.php 3
CFIDE/wizards/common/utils.cfc 3
webtools/control/forgotPassword/%2e/%2e/ProgramExport 3
ajax-api/2.0/mlflow/experiments/create 3
webui/ 3
api/users 3
parse 3
cgi-bin/cgiServer.exx 3
ajax-api/2.0/mlflow/model-versions/create 3
php/ping.php 3
installer 3
api/geojson 3
fileDownload 3
app 3
login.action 3
card_scan.php 2
NCFindWeb 2
jexws/jexws.jsp 2
getCorsFile 2
users/sign_in 2
../../../../../../../../../../../../../etc/passwd 2
../../../../../../../../../etc/passwd 2
🚫

Block

Multiple critical WAF deny rules triggered, including LFI, command injection, XSS, and bot impersonation, indicating severe malicious probing and exploit attempts. All accessed paths were flagged.

2025-11-30 14:03:57