Investigation Workspace

Entity: 45.153.34.212 (Ip)

Entity Details
Type
Ip
ASN
AS51396 - Pfcloud UG
Threat Intelligence
All requests from this IP were flagged by WAF, targeting sensitive configuration files and known exploit paths (.git/config, .env, wp-config.php), and triggered multiple critical WAF deny rules including LFI-ANOMALY and IPBLOCK-BURST4, along with bot impersonation.
Linked Entities
TLS Fingerprints (1)
Hostnames Targeted
Hostname Request Count
akamai.darcherif.fr 133
Paths Targeted (with Request Counts)
Path Request Count
_sec/cp_challenge/challenge 38
composer.json 3
phpinfo.php 3
.env.js 3
php_info.php 3
app.js 3
info.php 3
portal/phpinfo.php 3
.git/config 3
docker-compose.yml 3
config/application.yml 3
application.yml 3
settings.php 3
settings.py 3
server_info.php 3
db.php 3
.gitconfig 3
server.js 3
.aws/credentials 3
database.php 3
.env-config.js 3
appsettings.json 3
phpinfo/info.php 3
config.js 3
functions.php 2
config.json 2
test.php 2
pinfo.php 2
config.php 2
web.config 2
.env.bak 2
wp-config.php 2
index.php 2
configuration.php 2
config/parameters.yml 2
app/config/parameters.yml 2
.env 2
🚫

Block

All requests from this IP were flagged by WAF, targeting sensitive configuration files and known exploit paths (.git/config, .env, wp-config.php), and triggered multiple critical WAF deny rules including LFI-ANOMALY and IPBLOCK-BURST4, along with bot impersonation.

2025-12-24 18:00:07