Investigation Workspace

Entity: 3%7e32bee0f5e54580be (Tls)

Entity Details
Type
Tls
Linked Entities
IPs Linked to TLS Fingerprint (3)
Hostnames Targeted
Hostname Request Count
www.darcherif.fr 49
5
Paths Targeted (with Hostname Counts)
Path Distinct Hostnames
Lk4TRUPUqhrDr/tAn/f7XLQlaR8xY/ri1hVDa9akG7VcaLV9/YyZNWVcPAQ/HAYUASFM/PisB 2
favicon.ico 1
akam/13/pixel_479e18f4 1
wp-content/themes/mesmerize/assets/fonts/fontawesome-webfont.woff2 1
wp-includes/js/wp-emoji-release.min.js 1
wp-includes/js/masonry.min.js 1
wp-content/themes/highlight/assets/images/hero-1.jpg 1
wp-content/plugins/mesmerize-companion/theme-data/mesmerize/assets/js/companion.bundle.min.js 1
akam/13/479e18f4 1
wp-content/themes/mesmerize/assets/css/theme.bundle.min.css 1
wp-content/themes/mesmerize/assets/js/theme.bundle.min.js 1
wp-content/themes/highlight/assets/images/hero-inner.jpg 1
wp-content/uploads/2020/01/solar-eclipse_dp_680-768x443.jpg 1
wp-content/uploads/2020/01/Czech-Republic-operation-Temelin-Nuclear-Power-Plant-2003-768x502.jpg 1
wp-content/themes/highlight/customizer/sections/content.css 1
wp-includes/js/jquery/jquery.min.js 1
wp-includes/css/dist/block-library/style.min.css 1
wp-content/themes/mesmerize/style.min.css 1
wp-content/themes/highlight/style.min.css 1
wp-includes/js/jquery/jquery-migrate.min.js 1
wp-content/themes/highlight/assets/js/theme-child.js 1
wp-includes/js/imagesloaded.min.js 1
wp-content/uploads/2020/05/ConferenceIndiaCropped.png 1
wp-content/themes/highlight/assets/images/hero-2.jpg 1
wp-content/plugins/mesmerize-companion/theme-data/mesmerize/assets/css/companion.bundle.min.css 1
ℹ️

Watchlist

Associated with an IP (2a01:e34:ec44:99d0:8c2f:82c6:25b6:fab0) that accessed a highly obfuscated and suspicious path, indicating a potentially malicious client fingerprint.

2026-01-17 12:23:13
ℹ️

Ignore

No detected threat requests, WAF flags, or security rule hits from entities using this TLS fingerprint since being added to the watchlist.

2026-01-17 15:43:37
🚫

Block

Associated with IP 2a01:e34:ec44:99d0:8c2f:82c6:25b6:fab0 which accessed a highly obfuscated and suspicious path, indicating a malicious client fingerprint consistent with previously blocklisted TLS fingerprints.

2026-01-17 15:53:44