Investigation Workspace

Entity: 54.71.96.232 (Ip)

Entity Details
Type
Ip
ASN
AS16509 - Amazon.com, Inc.
Threat Intelligence
Associated with ASN AS16509, which is already blocklisted for persistent malicious activity and triggering critical WAF deny rules. This IP also generated a WAF alert.
Linked Entities
TLS Fingerprints (2)
Hostnames Targeted
Hostname Request Count
www.darcherif.fr 21
2
Paths Targeted (with Hostname Counts)
Path Distinct Hostnames
hiiNmC-QC/81HD6/wJFw/t3Ya2pc9pYf3cb/DVxdSAE/OSJgFF/tAEy4 2
favicon.ico 1
akam/13/60afa1b7 1
akam/13/pixel_60afa1b7 1
wp-content/themes/mesmerize/assets/fonts/fontawesome-webfont.woff2 1
wp-includes/js/masonry.min.js 1
wp-content/plugins/mesmerize-companion/theme-data/mesmerize/assets/js/companion.bundle.min.js 1
wp-content/themes/mesmerize/assets/css/theme.bundle.min.css 1
wp-content/themes/mesmerize/assets/js/theme.bundle.min.js 1
wp-content/themes/highlight/customizer/sections/content.css 1
wp-includes/js/jquery/jquery.min.js 1
wp-includes/css/dist/block-library/style.min.css 1
wp-content/themes/mesmerize/style.min.css 1
wp-content/themes/highlight/style.min.css 1
wp-includes/js/jquery/jquery-migrate.min.js 1
wp-content/themes/highlight/assets/js/theme-child.js 1
wp-includes/js/imagesloaded.min.js 1
wp-content/uploads/2020/05/ConferenceIndiaCropped.png 1
wp-content/plugins/mesmerize-companion/theme-data/mesmerize/assets/css/companion.bundle.min.css 1
wp-content/uploads/2020/01/Czech-Republic-operation-Temelin-Nuclear-Power-Plant-2003-1024x669.jpg 1
ℹ️

Watchlist

Low number of detected threat requests (1/23) but includes a suspicious 'akam' path and a WAF alert, warranting continued monitoring.

2025-12-16 15:59:12
ℹ️

Watchlist

Low percentage of detected threat requests and low AI confidence, but still triggered a WAF alert, warranting continued monitoring.

2025-12-16 16:38:53
ℹ️

Ignore

Entity in watchlist shows no current activity or detected threats since being added, indicating it is no longer suspicious.

2025-12-16 17:18:45
🚫

Block

Associated with ASN AS16509, which is already blocklisted for persistent malicious activity and triggering critical WAF deny rules. This IP also generated a WAF alert.

2025-12-16 17:28:39