Investigation Workspace

Entity: 134.209.25.199 (Ip)

Entity Details
Type
Ip
ASN
AS14061 - DigitalOcean, LLC
Threat Intelligence
Aggressive reconnaissance for sensitive files and API documentation, all requests flagged by WAF, multiple critical security alerts (including bot impersonation), and triggered critical deny rules (LFI-ANOMALY, IPBLOCK-PENALTY-BOX). Associated ASN AS14061 is blocklisted for identical malicious activity.
Linked Entities
TLS Fingerprints (4)
Hostnames Targeted
Hostname Request Count
akamai.darcherif.fr 59
Paths Targeted (with Request Counts)
Path Request Count
/ 7
ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application 2
.vscode/sftp.json 2
_all_dbs 2
.env 2
info.php 2
server 2
about 2
debug/default/view 2
server-status 2
.git/config 2
actuator/env 2
telescope/requests 2
@vite/env 2
.DS_Store 2
login.action 2
config.json 2
v2/_catalog 2
v3/api-docs 1
v2/api-docs 1
swagger-ui.html 1
api/graphql 1
swagger.json 1
api/swagger.json 1
graphql/api 1
api 1
swagger/swagger-ui.html 1
swagger/v1/swagger.json 1
graphql 1
api-docs/swagger.json 1
swagger/index.html 1
_sec/cp_challenge/challenge 1
webjars/swagger-ui/index.html 1
api/gql 1
s/6383e2430323e26313e223/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties 1
s/031323e2236313e26333e23323/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties 1
🚫

Block

Aggressive reconnaissance for sensitive files and API documentation, all requests flagged by WAF, multiple critical security alerts (including bot impersonation), and triggered critical deny rules (LFI-ANOMALY, IPBLOCK-PENALTY-BOX). Associated ASN AS14061 is blocklisted for identical malicious activity.

2026-01-14 09:49:05