Investigation Workspace

Entity: 167.71.81.114 (Ip)

Entity Details
Type
Ip
ASN
AS14061 - DigitalOcean, LLC
Threat Intelligence
All requests were flagged by WAF, targeting sensitive endpoints (actuator/env, api/swagger.json, .env, .vscode/sftp.json) and triggered a critical 'LFI-ANOMALY' deny rule. Its associated ASN (AS14061) is already blocklisted for persistent malicious activity.
Linked Entities
TLS Fingerprints (2)
Hostnames Targeted
Hostname Request Count
www.darcherif.fr 36
akamai.darcherif.fr 36
Paths Targeted (with Hostname Counts)
Path Distinct Hostnames
api/gql 2
webjars/swagger-ui/index.html 2
_all_dbs 2
.env 2
info.php 2
server 2
about 2
api 2
server-status 2
graphql 2
actuator/env 2
graphql/api 2
swagger.json 2
api/graphql 2
login.action 2
.DS_Store 2
v2/api-docs 2
v3/api-docs 2
v2/_catalog 2
swagger-ui.html 2
config.json 2
@vite/env 2
api/swagger.json 2
telescope/requests 2
debug/default/view 2
swagger/swagger-ui.html 2
ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application 2
.vscode/sftp.json 2
api-docs/swagger.json 2
swagger/index.html 2
swagger/v1/swagger.json 2
.git/config 2
s/63e2031313e2030313e25393/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties 1
s/330313e2338313e26313e223/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties 1
🚫

Block

All requests were flagged by WAF, targeting sensitive endpoints (actuator/env, api/swagger.json, .env, .vscode/sftp.json) and triggered a critical 'LFI-ANOMALY' deny rule. Its associated ASN (AS14061) is already blocklisted for persistent malicious activity.

2025-12-12 00:08:31