Investigation Workspace

Entity: 135.181.246.140 (Ip)

Entity Details
Type
Ip
Linked Entities
TLS Fingerprints (1)
Hostnames Targeted
Hostname Request Count
www.darcherif.fr 20
5
Paths Targeted (with Request Counts)
Path Request Count
/ 5
index.php/category/industry-4-0/ 5
index.php/category/cybersecurity/ 5
akam/13/a6b6e19 1
akam/13/a6b6d26 1
akam/13/a6b6ebf 1
akam/13/a6b6f33 1
akam/13/a6b6dbf 1
akam/13/pixel_a6b6d26 1
akam/13/pixel_a6b6f33 1
akam/13/pixel_a6b6ebf 1
akam/13/pixel_a6b6dbf 1
akam/13/pixel_a6b6e19 1
ℹ️

Watchlist

Accessed obfuscated and suspicious paths (e.g., 'akam/13/a6b6d26', 'akam/13/pixel_a6b6d26'), indicating potential malicious probing.

2026-01-02 04:51:46
ℹ️

Ignore

No recent malicious activity detected; no WAF flags, threat requests, or security rule hits observed.

2026-01-02 06:42:08
ℹ️

Watchlist

Accessed unusual 'akam' paths which can sometimes be associated with tracking or malicious activity, despite no direct WAF flags or detected threats yet. Warrants further monitoring.

2026-01-02 06:51:56
ℹ️

Ignore

No current malicious activity detected, no WAF flags or security rule hits, and low AI confidence score. Behavior no longer warrants watchlist inclusion.

2026-01-02 10:12:10
ℹ️

Ignore

No detected malicious activity, WAF not triggered, and no security rule hits for this IP. Appears to be benign traffic.

2026-01-02 10:22:06
ℹ️

Watchlist

IP accessed obfuscated 'akam' paths, which is suspicious and similar to patterns observed in other blocklisted entities. Lacks direct WAF flags for immediate blocking.

2026-01-02 10:42:10
ℹ️

Ignore

No detected threat requests, WAF flags, or security rule hits observed, indicating the entity no longer exhibits suspicious behavior.

2026-01-02 22:12:51
ℹ️

Watchlist

Accessed obfuscated 'akam' paths similar to those seen in blocklisted IPs, suggesting potential malicious probing, though no direct WAF flags or threat requests detected yet.

2026-01-02 22:22:48
ℹ️

Ignore

Entity previously added to watchlist showed no actual malicious activity, with 0 detected threat requests, no WAF flags, and no security rule hits observed since being placed on the watchlist.

2026-01-02 22:32:52
ℹ️

Watchlist

Accessed suspicious 'akam' paths which are similar in pattern to those found in blocklisted entities. While no direct WAF flags or security rules were triggered for this specific IP, the pattern warrants further monitoring.

2026-01-02 22:42:53
ℹ️

Ignore

No recent detected threat requests, WAF flags, or security rule hits. Behavior no longer appears suspicious.

2026-01-04 23:15:24
ℹ️

Watchlist

Associated with hostname 'www.darcherif.fr', which is being targeted by another highly suspicious IP in the watchlist. While this IP's direct activity is not malicious, its association warrants continued monitoring.

2026-02-27 22:48:10
ℹ️

Ignore

No detected threat requests, no WAF flags, no security rule hits, and accessed paths appear benign. Older last_seen timestamp.

2026-02-28 02:38:55
ℹ️

Watchlist

Entity has a future 'last_seen' timestamp (2026-02-27T22:40:24) which is highly anomalous, despite no direct threat detections. This warrants further investigation and monitoring for potential data integrity issues or evasive behavior.

2026-02-28 02:49:02
ℹ️

Ignore

Despite previous AI assessment, the entity shows 0 detected threat requests out of 5 total requests and no security rule hits. There is no current evidence of malicious activity.

2026-02-28 07:19:56
ℹ️

Watchlist

No direct malicious activity detected, however, the 'last_seen' timestamp is reported as 2026-02-27T22:40:24, which is in the future. This anomaly warrants further investigation into data integrity or potential sophisticated time manipulation.

2026-02-28 07:30:09
ℹ️

Ignore

No threats detected, no WAF flags, and no security rule hits across 5 requests. Initial AI confidence was low, suggesting minimal or no malicious intent.

2026-02-28 07:50:20
ℹ️

Ignore

No suspicious activity detected. The entity shows no WAF flags, detected threat requests, or security rule hits. The accessed paths are consistent with normal website browsing. The 'last_seen' timestamp is unusual (in the future) but not indicative of maliciousness without other supporting evidence.

2026-02-28 08:00:30
ℹ️

Watchlist

The 'last_seen' timestamp is in the future, suggesting a data anomaly. No direct threat indicators (WAF flags, security rule hits, detected threat requests) were found.

2026-02-28 08:10:35
ℹ️

Ignore

No malicious activity was detected from this IP based on the accessed paths, which appear benign. The existing AI confidence score and severity for this entity are low, and the shared hostname with a newly identified malicious IP is not sufficient reason to maintain its watchlist status without direct malicious behavior from this specific IP.

2026-02-28 13:01:33
ℹ️

Watchlist

Anomalous 'last_seen' timestamp in the future, suggesting a potential data anomaly or obfuscation, warrants further monitoring despite no other direct malicious indicators.

2026-02-28 13:11:45
ℹ️

Ignore

This IP had zero detected threat requests, no WAF flags, and no security rule hits from its 5 requests. Its previous AI confidence score was low, and it was classified as low severity, indicating no current malicious activity.

2026-02-28 16:52:27
ℹ️

Ignore

No detected threat requests, WAF flags, or security rule hits. Entity appears benign based on current data.

2026-02-28 17:02:36
ℹ️

Ignore

No evidence of malicious activity, WAF flags, or security rule hits detected. All observed requests and paths accessed are consistent with normal web browsing. The future 'last_seen' timestamp is noted but not indicative of malice without further correlating factors.

2026-02-28 17:12:44
ℹ️

Ignore

No malicious activity detected. All accessed paths are benign, no WAF flags, detected threat requests, or security rule hits. The IP resolves to a legitimate domain.

2026-02-28 17:22:51
ℹ️

Ignore

No malicious activity detected, no WAF flags, and no security rule hits. Low request count to legitimate-looking paths.

2026-02-28 17:32:57
ℹ️

Ignore

No malicious activity detected. All security indicators, including WAF flags, detected threat requests, and security rule hits, are clear. Accessed hostnames and paths appear benign.

2026-02-28 17:43:07
ℹ️

Ignore

No suspicious activity detected: low request count, no WAF flags, no security rule hits, and access to standard website paths. Entity appears benign.

2026-02-28 17:53:18
ℹ️

Ignore

No security rule hits, WAF flags, or detected threat requests. Entity's activity appears benign with low request volume.

2026-02-28 18:03:27
ℹ️

Ignore

No malicious activity detected. The IP shows no WAF flags, no detected threat requests, and no security rule hits. Accessed paths appear benign, and the hostname 'www.darcherif.fr' seems legitimate.

2026-02-28 18:13:35
ℹ️

Ignore

No suspicious activity or threat indicators detected. The IP accessed standard web paths of a legitimate domain, and no WAF flags or security rule hits were recorded.

2026-02-28 18:23:44
ℹ️

Ignore

No detected threats, WAF flags, or security rule hits. Accessed paths are benign and related to a legitimate website. Entity exhibits no malicious behavior.

2026-02-28 18:33:51
ℹ️

Ignore

No suspicious activity detected; accessed paths appear legitimate, no WAF flags or security rule hits.

2026-02-28 18:43:59
ℹ️

Ignore

No suspicious activity, WAF flags, or security rule hits detected. Entity exhibits benign browsing behavior (low requests, common paths, legitimate hostname). There is no indication of malicious intent or compromise, therefore it does not warrant inclusion on a watchlist.

2026-02-28 18:54:10
ℹ️

Ignore

IP shows no detected threats, WAF flags, or security rule hits. Activity appears to be benign web traffic accessing standard website paths and CDN resources. Although not currently in the watchlist, analysis confirms it is not suspicious and does not warrant monitoring.

2026-02-28 19:04:25
ℹ️

Ignore

No detected threats, WAF flags, or security rule hits. Low total requests and clean paths accessed.

2026-02-28 19:14:31
ℹ️

Ignore

No malicious activity detected. All requests appear legitimate, with no WAF flags, detected threat requests, or security rule hits.

2026-02-28 19:24:37
ℹ️

Watchlist

Although no direct malicious activity (threat requests, WAF flags, security rule hits) was observed, the 'last_seen' timestamp of '2026-02-27T22:40:24' is in the future, indicating a potential data anomaly that warrants further investigation into the data source.

2026-02-28 19:34:53
ℹ️

Ignore

No new suspicious activity detected. All 5 requests had 0 detected threats, and no WAF rules were triggered. The initial watchlist entry seems to be a false positive or the threat has subsided.

2026-02-28 20:55:12
ℹ️

Ignore

Analysis shows no suspicious activity: 0 detected threat requests, no WAF flags, and no security rule hits. The hostname 'www.darcherif.fr' appears legitimate, and paths accessed are consistent with normal website browsing or tracking. The low request count (5) also suggests no unusual activity.

2026-02-28 21:35:30
ℹ️

Ignore

No detected threat requests or security rule hits observed, indicating benign activity.

2026-03-01 01:16:18
ℹ️

Watchlist

No direct threats detected, but accessed paths include generic Akamai-related resources which can sometimes be associated with bot activity. Further monitoring is warranted.

2026-03-01 02:26:33
ℹ️

Ignore

No threat requests detected (0 out of 5 total requests), no paths flagged by WAF, and no security rule hits. The accessed paths appear benign and consistent with normal website browsing. Existing AI confidence and severity are low.

2026-03-01 05:47:09
ℹ️

Ignore

No malicious activity detected, zero threat requests, no WAF flags, and no security rule hits. The IP hosts a legitimate website and shows no signs of compromise or malicious intent.

2026-03-01 05:57:17
ℹ️

Ignore

No malicious activity detected: zero WAF flags, zero threat requests, and no security rule hits over a low number of total requests. Appears to be benign traffic.

2026-03-01 08:07:54
ℹ️

Ignore

No security rule hits, WAF flags, or detected threats. Low request volume (5) to a seemingly legitimate website. Akamai-related paths are likely benign CDN/tracking elements.

2026-03-01 08:18:11
ℹ️

Ignore

Analysis shows no detected threat requests, no WAF flags, and no security rule hits. All observed activity, including accessed paths and hostnames, appears legitimate and non-malicious. This entity is deemed benign.

2026-03-01 08:28:23
ℹ️

Ignore

Entity exhibits no malicious activity. No WAF flags, security rule hits, or detected threat requests were observed. Accessed paths appear consistent with benign web browsing.

2026-03-01 08:38:31
ℹ️

Ignore

No malicious activity detected, zero threat requests, no WAF flags, and no security rule hits. Observed traffic patterns are consistent with normal web browsing.

2026-03-01 08:48:38
ℹ️

Ignore

No suspicious activity detected. The IP address shows normal web traffic, no WAF flags, no detected threat requests, and no security rule hits.

2026-03-01 08:58:45
ℹ️

Ignore

No malicious activity detected; zero threat requests, WAF flags, or security rule hits. Low volume of benign requests observed across standard paths.

2026-03-01 09:08:56
ℹ️

Ignore

No malicious activity detected. The entity shows a low number of requests (5), no WAF flags, and no security rule hits. Associated hostname 'www.darcherif.fr' appears to be a legitimate website, and the ASN belongs to a common hosting provider without specific threat indicators in this context.

2026-03-01 09:19:07
ℹ️

Ignore

No suspicious activity detected. The IP shows no WAF flags, no security rule hits, and no detected threat requests. Activity appears to be benign web browsing.

2026-03-01 09:29:15
ℹ️

Ignore

No detected threat requests, WAF flags, or security rule hits. All observed activity appears benign.

2026-03-01 09:39:23
ℹ️

Ignore

No suspicious activity detected, no security rule hits, and zero detected threat requests. The accessed paths and hostnames appear benign.

2026-03-01 09:49:31
ℹ️

Ignore

No suspicious activity detected, zero threat requests, and no WAF flags. The entity exhibits low request volume to a hostname associated with a legitimate website. It does not warrant further monitoring at this time.

2026-03-01 09:59:38
ℹ️

Ignore

Analysis shows no detected threat requests, WAF flags, or security rule hits. Observed activity (low request count, common paths, legitimate hostname) appears benign. No indicators of compromise found.

2026-03-01 10:09:47
ℹ️

Ignore

No malicious indicators found. Entity appears benign and is not currently in the watchlist. WAF logs, detected threat requests, and security rule hits are all clear. The associated hostname `www.darcherif.fr` suggests a legitimate website. Therefore, no action is required to add or keep this entity in the watchlist.

2026-03-01 10:19:59
ℹ️

Ignore

No malicious activity detected. All security indicators are clean (no WAF flags, no detected threat requests, no security rule hits). Activity consists of low volume legitimate-looking web requests.

2026-03-01 10:30:06
ℹ️

Watchlist

Anomalous future timestamp ('last_seen': 2026-02-27T22:40:24) identified. This could indicate a data integrity issue or a sophisticated attempt to evade detection, warranting further monitoring despite the absence of other direct threat indicators.

2026-03-01 10:40:21
ℹ️

Watchlist

This IP shares the hostname 'www.darcherif.fr' with a newly identified critical threat (40.85.219.62) that is actively performing malicious activities. Further investigation is warranted to understand the correlation.

2026-03-01 11:00:29
ℹ️

Ignore

No malicious activity detected since being added to the watchlist; zero requests, threat requests, and security rule hits observed.

2026-03-01 15:41:18
ℹ️

Ignore

No suspicious activity detected for this IP address. It has no WAF flags, security rule hits, or detected threat requests. The accessed paths suggest benign web browsing activity on a public-facing website. Although not explicitly on the watchlist, this action signifies it poses no current threat.

2026-03-01 15:51:29
ℹ️

Ignore

Analysis indicates no malicious activity: 0 detected threat requests, no WAF flags, and no security rule hits. Entity appears benign.

2026-03-01 16:01:37
ℹ️

Ignore

No malicious activity detected. Entity shows zero detected threat requests, no flagged paths by WAF, and no security rule hits. The accessed paths and hostnames appear benign.

2026-03-01 16:11:49
ℹ️

Ignore

This IP address shows no signs of malicious activity. Its requests are for legitimate WordPress categories and Akamai tracking pixels, with zero detected threat requests and no WAF flags.

2026-03-01 17:12:07
ℹ️

Ignore

No malicious activity detected. Analysis shows a low volume of benign requests to a legitimate website with no WAF flags or security rule hits.

2026-03-01 17:42:15
ℹ️

Ignore

No malicious activity detected. This IP address shows no threat requests, WAF flags, or security rule hits. It appears to be a legitimate web server for www.darcherif.fr.

2026-03-01 19:02:33
ℹ️

Ignore

No suspicious activity detected. Low request count and paths accessed appear to be normal website browsing or analytics. No WAF flags or security rule hits reported.

2026-03-01 21:03:04
ℹ️

Ignore

No malicious activity, threat requests, WAF flags, or security rule hits detected. Entity appears benign.

2026-03-02 01:04:01