Investigation Workspace

Entity: 3%7ed09afd3ffe9bdf7b (Tls)

Entity Details
Type
Tls
Linked Entities
IPs Linked to TLS Fingerprint (50)
Hostnames Targeted
Hostname Request Count
www.darcherif.fr 1974
akamai.darcherif.fr 80
Paths Targeted (with Request Counts)
Path Request Count
/ 216
nuclei.svg 204
index.php 94
robots.txt 21
.git/config 17
wp-admin/admin-ajax.php 15
.env 13
install.php 10
_session 9
install/ 9
index.action 7
install 7
miscadmin 6
login 6
setup 5
api/.env 4
json 4
install/index.php 4
wls-wsat/CoordinatorPortType 4
include/thumb.php 4
install/install.php 4
solr/admin/cores 4
cgi-bin/account_mgr.cgi 4
Users/authenticatebyname 4
enhancecp 4
cgi-bin/cgiServer.exx 3
eam/vib 3
app 3
webtools/control/forgotPassword/%2e/%2e/ProgramExport 3
webui/ 3
download.php 3
login.php 3
Visitor/bin/WebStrings.srf 3
api/geojson 3
wp-admin/admin-post.php 3
login.action 3
CFIDE/wizards/common/utils.cfc 3
__ 3
ajax-api/2.0/mlflow/model-versions/create 3
cgi-bin/webproc 3
tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp 3
fileDownload 3
parse 3
admin/login 3
installer 3
php/ping.php 3
ajax-api/2.0/mlflow/experiments/create 3
cgi-bin/kerbynet 3
api/users 3
php/upload.php 2
🚫

Block

Associated with IP 134.122.136.96, which triggered multiple critical WAF deny rules including LFI, command injection, XSS, and bot impersonation. This TLS fingerprint is used by a highly malicious client.

2025-11-30 14:03:57