Investigation Workspace

Entity: 67.227.1.140 (Ip)

Entity Details
Type
Ip
Threat Intelligence
Accessed a highly obfuscated and suspicious path ('TXopfWNANuR3i/si/1SETC7qsZnKc/3cp5fp1mD3Lif4OJ/PD1OGXQoKgE/dTch/U2dsdHkB'), indicating malicious probing and attempted exploitation, consistent with blocklisted entities exhibiting similar behavior.
Linked Entities
TLS Fingerprints (1)
Hostnames Targeted
Hostname Request Count
www.darcherif.fr 23
2
Paths Targeted (with Hostname Counts)
Path Distinct Hostnames
TXopfWNANuR3i/si/1SETC7qsZnKc/3cp5fp1mD3Lif4OJ/PD1OGXQoKgE/dTch/U2dsdHkB 2
akam/13/653cae37 1
akam/13/pixel_653cae37 1
wp-content/themes/mesmerize/assets/fonts/fontawesome-webfont.woff2 1
wp-includes/js/wp-emoji-release.min.js 1
wp-includes/js/masonry.min.js 1
wp-content/themes/highlight/assets/images/hero-1.jpg 1
wp-content/plugins/mesmerize-companion/theme-data/mesmerize/assets/js/companion.bundle.min.js 1
wp-content/themes/mesmerize/assets/css/theme.bundle.min.css 1
wp-content/themes/mesmerize/assets/js/theme.bundle.min.js 1
wp-content/themes/highlight/customizer/sections/content.css 1
wp-includes/js/jquery/jquery.min.js 1
wp-includes/css/dist/block-library/style.min.css 1
wp-content/themes/mesmerize/style.min.css 1
wp-content/themes/highlight/style.min.css 1
wp-includes/js/jquery/jquery-migrate.min.js 1
wp-content/themes/highlight/assets/js/theme-child.js 1
wp-includes/js/imagesloaded.min.js 1
wp-content/uploads/2020/05/ConferenceIndiaCropped.png 1
wp-content/themes/highlight/assets/images/hero-2.jpg 1
wp-content/plugins/mesmerize-companion/theme-data/mesmerize/assets/css/companion.bundle.min.css 1
wp-content/uploads/2020/01/Czech-Republic-operation-Temelin-Nuclear-Power-Plant-2003-1024x669.jpg 1
ℹ️

Ignore

No malicious activity detected: 0 detected threat requests, no WAF flags, and no security rule hits. This entity appears to be benign.

2026-01-21 21:01:36
ℹ️

Watchlist

IP accessed a highly obfuscated and suspicious path on a frequently targeted domain, indicating potential malicious reconnaissance despite no direct WAF flags or detected threat requests.

2026-01-21 21:11:28
🚫

Block

Accessed a highly obfuscated and suspicious path ('TXopfWNANuR3i/si/1SETC7qsZnKc/3cp5fp1mD3Lif4OJ/PD1OGXQoKgE/dTch/U2dsdHkB'), indicating malicious probing and attempted exploitation, consistent with blocklisted entities exhibiting similar behavior.

2026-01-22 16:24:04