Investigation Workspace

Entity: AS14061 (Asn)

Entity Details
Type
Asn
ASN
AS14061 - DigitalOcean, LLC
Threat Intelligence
All requests from IPs associated with this ASN were flagged by WAF, extensively probing sensitive configurations and known exploit paths (including LFI and Jira exploits), and consistently triggered critical 'LFI-ANOMALY' deny rules. This ASN is confirmed to be highly malicious and is already in the blocklist.
Linked Entities
TLS Fingerprints (31)
Hostnames Targeted
Hostname Request Count
akamai.darcherif.fr 5086
www.darcherif.fr 2541
akamai.darcherif.fr: 41
14
akamai.darcherif.fr:443 2
akamai.darcherif.fr:80 2
Paths Targeted (with Request Counts)
Path Request Count
/ 3778
_sec/cp_challenge/challenge 564
favicon.ico 241
D/128057/1081022/000/akamai.darcherif.fr/_sec/cp_challenge/challenge 102
.env 89
.git/config 73
telescope/requests 65
info.php 65
config.json 64
ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application 60
@vite/env 60
actuator/env 60
debug/default/view 60
.vscode/sftp.json 60
login.action 59
about 59
server-status 59
server 59
v2/_catalog 55
.DS_Store 55
_all_dbs 47
swagger/swagger-ui.html 39
v3/api-docs 39
api/swagger.json 39
swagger/index.html 39
webjars/swagger-ui/index.html 39
swagger.json 39
v2/api-docs 39
api-docs/swagger.json 39
swagger-ui.html 39
swagger/v1/swagger.json 39
wp-login.php 38
graphql/api 35
api/gql 35
graphql 35
api/graphql 35
api 35
xmlrpc.php 30
wp1/wp-includes/wlwmanifest.xml 17
wordpress/wp-includes/wlwmanifest.xml 17
wp/wp-includes/wlwmanifest.xml 17
site/wp-includes/wlwmanifest.xml 17
news/wp-includes/wlwmanifest.xml 17
web/wp-includes/wlwmanifest.xml 17
blog/wp-includes/wlwmanifest.xml 17
cms/wp-includes/wlwmanifest.xml 17
website/wp-includes/wlwmanifest.xml 17
test/wp-includes/wlwmanifest.xml 17
wp-includes/wlwmanifest.xml 17
sito/wp-includes/wlwmanifest.xml 17
🚫

Block

All requests from IPs associated with this ASN were flagged by WAF, extensively probing sensitive configurations and known exploit paths (including LFI and Jira exploits), and consistently triggered critical 'LFI-ANOMALY' deny rules. This ASN is confirmed to be highly malicious and is already in the blocklist.

2025-12-12 00:08:31