Investigation Workspace

Entity: 3%7e2c022104e7e56fbe (Tls)

Entity Details
Type
Tls
Linked Entities
IPs Linked to TLS Fingerprint (50)
Hostnames Targeted
Hostname Request Count
www.darcherif.fr 1540
akamai.darcherif.fr 62
Paths Targeted (with Request Counts)
Path Request Count
wp-login.php 456
/ 114
.env 27
index.php/author/admin3157/ 17
wp-admin/ 9
robots.txt 8
favicon.ico 7
sellers.json 5
ads.txt 5
app-ads.txt 5
.env.development 3
wp-content/ 3
.env.production 3
api/.env 3
.env.local 3
wp-includes/ 3
.env.save 3
.env.example 3
.git/config 3
backend/.env 3
.env.prod 3
application/.env 3
admin/.env 3
dev/.env 3
config/.env 3
app/.env 3
wp-admin/upgrade.php 3
phpinfo 2
style.php 2
_profiler/phpinfo 2
phpinfo.php 2
xmlrpc.php 2
wp-json/wp/v2/users 2
sendgrid.env 2
wp-includes/ID3/ 2
info 2
php_info.php 2
marketing/.env.dev 1
wp-admin/install.php 1
.github/workflows/.env 1
functions/api/.env 1
laravel/.env.local 1
storage/.env.local 1
services/.env.staging 1
testing/.env.local 1
wp-content/mu-plugins/ 1
admin/.env.staging 1
tenants/.env 1
developer/config.env 1
prod/.env.local 1
🚫

Block

TLS fingerprint detected probing 'wp-login.php', triggering a WAF alert (3900998) indicative of brute-force or credential stuffing attempts, consistent with previously blocked malicious activity.

2025-12-19 11:42:24