Investigation Workspace

Entity: 195.178.110.156 (Ip)

Entity Details
Type
Ip
ASN
AS48090 - TECHOFF SRV LIMITED
Threat Intelligence
All requests from this IP targeted sensitive configuration files and triggered multiple critical WAF deny rules, including LFI-ANOMALY, IPBLOCK, and reputation-based blocking. The associated ASN (AS48090) is already blocklisted for identical malicious activity.
Linked Entities
Hostnames Targeted
Hostname Request Count
akamai.darcherif.fr 138
Paths Targeted (with Request Counts)
Path Request Count
/ 15
api/session 2
admin/phpinfo.php 2
api/cache 2
admin/.env 2
phpinfo.php 2
_profiler/phpinfo 2
test/phpinfo.php 2
api/decode 2
.env 2
.git/config 2
info.php 2
api_keys.json 1
config/sendgrid.json 1
home/user/.aws/credentials 1
config/app.php 1
debug.log 1
.env.live 1
.env.development 1
frontend/.env 1
config/aws.json 1
app/settings.php 1
app/config.php 1
server/.env 1
config.py 1
config/mail.json 1
.env.example 1
config/smtp.php 1
.aws/credentials 1
.env.staging 1
.env.dist 1
.env.backup 1
config.yml 1
config/mail.php 1
react-app/.env.production 1
private/.env 1
latest/meta-data/iam/security-credentials/ 1
.envs/.production/.django 1
configuration.php 1
administrator/.env 1
secrets/config.json 1
var/log/nginx/error.log 1
backup/config.php 1
config/services.php 1
config/mailgun.json 1
backend/.env 1
config/database.php 1
config/config.json 1
config/settings.json 1
config.json 1
🚫

Block

All requests from this IP targeted sensitive configuration files and triggered multiple critical WAF deny rules, including LFI-ANOMALY, IPBLOCK, and reputation-based blocking. The associated ASN (AS48090) is already blocklisted for identical malicious activity.

2025-12-24 21:00:20