Investigation Workspace

Entity: 2a00:f2a0:0:f783::100 (Ip)

Entity Details
Type
Ip
ASN
AS12555 - Data-center IMAQLIQ Ltd.
Threat Intelligence
High ratio of detected threat requests (~85.7%), the root path was flagged by WAF, and multiple critical security alerts including 'BOT-BROWSER-IMPERSONATOR' were triggered, indicating severe automated malicious probing. This behavior is consistent with other blocklisted IPs from high-risk geo-locations.
Linked Entities
TLS Fingerprints (3)
Hostnames Targeted
Hostname Request Count
www.darcherif.fr 32
akamai.darcherif.fr 13
Paths Targeted (with Request Counts)
Path Request Count
/ 25
favicon.ico 15
security.txt 2
.well-known/security.txt 2
favicon.png 1
ℹ️

Ignore

No detected threat requests, no WAF flags, and no security rule hits for 6 total requests, indicating benign activity.

2026-01-31 22:01:49
ℹ️

Ignore

No suspicious activity detected; zero threat requests, no WAF flags, and no security rule hits. This IP is clean.

2026-01-31 22:11:46
ℹ️

Ignore

No malicious activity detected through WAF, threat requests, or security rule hits across 7 requests, indicating benign behavior.

2026-01-31 22:21:53
ℹ️

Ignore

No detected threat requests, WAF flags, or security rule hits over 7 requests to benign paths, suggesting legitimate activity.

2026-01-31 22:31:49
ℹ️

Ignore

No detected threat requests, WAF flags, or security rule hits. Observed benign activity including access to common website resources.

2026-01-31 22:41:45
ℹ️

Watchlist

Initial review shows no immediate malicious activity, but geo-location from a high-risk region (RU) warrants continued monitoring.

2026-01-31 22:51:53
ℹ️

Ignore

No new or detected malicious activity since being added to the watchlist, and accessed benign paths.

2026-02-02 17:55:38
🚫

Block

High ratio of detected threat requests (~85.7%), the root path was flagged by WAF, and multiple critical security alerts including 'BOT-BROWSER-IMPERSONATOR' were triggered, indicating severe automated malicious probing. This behavior is consistent with other blocklisted IPs from high-risk geo-locations.

2026-02-02 18:05:34