Investigation Workspace

Entity: 68.183.180.73 (Ip)

Entity Details
Type
Ip
ASN
AS14061 - DigitalOcean, LLC
Threat Intelligence
Aggressive reconnaissance targeting sensitive files and API documentation (e.g., '.git/config', '.env', 'server-status'), all requests flagged by WAF, and triggered a critical 'LFI-ANOMALY' deny rule. This IP's ASN (AS14061) is already blocklisted for identical malicious activity.
Linked Entities
TLS Fingerprints (2)
Hostnames Targeted
Hostname Request Count
akamai.darcherif.fr 35
Paths Targeted (with Request Counts)
Path Request Count
/ 3
v2/api-docs 1
swagger/v1/swagger.json 1
.env 1
info.php 1
server 1
about 1
api 1
server-status 1
graphql 1
actuator/env 1
graphql/api 1
swagger.json 1
.DS_Store 1
login.action 1
api/graphql 1
api/gql 1
v3/api-docs 1
v2/_catalog 1
swagger-ui.html 1
config.json 1
@vite/env 1
api/swagger.json 1
telescope/requests 1
debug/default/view 1
swagger/swagger-ui.html 1
ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application 1
.vscode/sftp.json 1
api-docs/swagger.json 1
swagger/index.html 1
s/433313e2133313e20353e23323/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties 1
webjars/swagger-ui/index.html 1
.git/config 1
🚫

Block

Aggressive reconnaissance targeting sensitive files and API documentation (e.g., '.git/config', '.env', 'server-status'), all requests flagged by WAF, and triggered a critical 'LFI-ANOMALY' deny rule. This IP's ASN (AS14061) is already blocklisted for identical malicious activity.

2026-02-03 11:06:57