Investigation Workspace

Entity: 45.148.10.246 (Ip)

Entity Details
Type
Ip
ASN
AS48090 - TECHOFF SRV LIMITED
Threat Intelligence
Extensive probing of sensitive configuration files and backups (e.g., .env, config/mail), all requests (100%) flagged by WAF, and multiple critical deny rules triggered including LFI-ANOMALY and IPBLOCK.
Linked Entities
Hostnames Targeted
Hostname Request Count
akamai.darcherif.fr 146
Paths Targeted (with Hostname Counts)
Path Distinct Hostnames
./config/email.php.back 1
./config/.env.staging 1
app/Config/email.php/ 1
./config/email.php.save 1
./config/email.php.bak 1
./config/.env.production 1
config/.env.local/ 1
./.env.production.backup 1
config/email.php.save/ 1
config/mail.php.save 1
config/mail.php.bak 1
config/mail.php%7e 1
./config/email.php%7e 1
./app/Config/stripe.php 1
config/mail.php.swp/ 1
config/.env.staging 1
config/environments/development.rb 1
config/mail.old.php 1
config/stripe.yml/ 1
config/.env.production/ 1
config/mail_backup.php/ 1
config/email.bak.php/ 1
config/email.php.swp/ 1
./.env.test.backup 1
config/mail.bak.php/ 1
config/stripe.yml 1
app/.env.production/ 1
app/Config/email.php 1
./config/.env.dev 1
config/email.php.old 1
./config/.env.local 1
.env.production.backup 1
./config/environments/development.rb 1
config/email.php%7e 1
config/initializers/email.rb 1
config/environments/production.rb 1
config/initializers/mail.rb 1
config/credentials.yml.enc/ 1
config/initializers/smtp.rb 1
./protected/config/stripe.php 1
config/initializers/stripe.rb 1
applications/init/private/appconfig.ini/ 1
./config/environments/test.rb 1
config/initializers/smtp.rb/ 1
applications/init/private/appconfig.ini 1
config/initializers/stripe.rb/ 1
./applications/init/models/db.py 1
./config/initializers/mailer.rb 1
./config/initializers/stripe_config.rb 1
config/environments/production.rb/ 1
🚫

Block

Extensive probing of sensitive configuration files and backups (e.g., .env, config/mail), all requests (100%) flagged by WAF, and multiple critical deny rules triggered including LFI-ANOMALY and IPBLOCK.

2025-12-04 12:34:38