Investigation Workspace

Entity: 185.177.72.67 (Ip)

Entity Details
Type
Ip
ASN
AS211590 - Bucklog SARL
Threat Intelligence
IP is aggressively probing for sensitive configuration and credential files, with all requests flagged by WAF, triggering critical 'LFI-ANOMALY' and reputation-based deny rules. Its associated ASN AS211590 is already blocklisted for persistent malicious activity, with other IPs from this ASN exhibiting identical severe malicious behavior.
Linked Entities
Hostnames Targeted
Hostname Request Count
akamai.darcherif.fr 22
Paths Targeted (with Hostname Counts)
Path Distinct Hostnames
info 1
test.php 1
.env.bak 1
php.php 1
wp/.env 1
phpinfo 1
.env 1
.git/config 1
credentials.json 1
.env.save 1
.env.deploy 1
.env.prod 1
appsettings.json 1
.git-credentials 1
.env.development 1
.gitconfig 1
configuration.php.bak 1
config/secrets.env 1
wp-config.php.bak 1
wp-admin/phpinfo.php 1
🚫

Block

IP is aggressively probing for sensitive configuration and credential files, with all requests flagged by WAF, triggering critical 'LFI-ANOMALY' and reputation-based deny rules. Its associated ASN AS211590 is already blocklisted for persistent malicious activity, with other IPs from this ASN exhibiting identical severe malicious behavior.

2026-01-09 10:21:40