Investigation Workspace

Entity: 195.178.110.156 (Ip)

Entity Details
Type
Ip
ASN
AS48090 - TECHOFF SRV LIMITED
Threat Intelligence
All requests from this IP targeted sensitive configuration files and triggered multiple critical WAF deny rules, including LFI-ANOMALY, IPBLOCK, and reputation-based blocking. The associated ASN (AS48090) is already blocklisted for identical malicious activity.
Linked Entities
Hostnames Targeted
Hostname Request Count
akamai.darcherif.fr 138
Paths Targeted (with Hostname Counts)
Path Distinct Hostnames
api/cache 1
config.yaml 1
config/.env 1
.env.staging 1
config/mail.json 1
admin/.env 1
react-app/.env.production 1
test/phpinfo.php 1
frontend/.env 1
.env.live 1
config.json 1
config/app.php 1
debug.log 1
.env.development 1
config/aws.json 1
app/settings.php 1
app/config.php 1
server/.env 1
phpinfo.php 1
api_keys.json 1
.env.example 1
config/smtp.php 1
.aws/credentials 1
.env.dist 1
.env.backup 1
config.yml 1
config/mail.php 1
private/.env 1
config.py 1
backend/.env 1
home/user/.aws/credentials 1
latest/meta-data/iam/security-credentials/ 1
.envs/.production/.django 1
configuration.php 1
administrator/.env 1
src/config.php 1
secrets/config.json 1
var/log/nginx/error.log 1
backup/config.php 1
config/services.php 1
config/mailgun.json 1
config/settings.json 1
config/database.php 1
_profiler/phpinfo 1
config/config.json 1
config/sendgrid.json 1
config/database.json 1
private/keys.json 1
admin/phpinfo.php 1
config/settings.php 1
🚫

Block

All requests from this IP targeted sensitive configuration files and triggered multiple critical WAF deny rules, including LFI-ANOMALY, IPBLOCK, and reputation-based blocking. The associated ASN (AS48090) is already blocklisted for identical malicious activity.

2025-12-24 21:00:20