Investigation Workspace

Entity: AS14061 (Asn)

Entity Details
Type
Asn
ASN
AS14061 - DigitalOcean, LLC
Threat Intelligence
All requests from IPs associated with this ASN were flagged by WAF, extensively probing sensitive configurations and known exploit paths (including LFI and Jira exploits), and consistently triggered critical 'LFI-ANOMALY' deny rules. This ASN is confirmed to be highly malicious and is already in the blocklist.
Linked Entities
TLS Fingerprints (29)
Hostnames Targeted
Hostname Request Count
akamai.darcherif.fr 4408
www.darcherif.fr 2434
akamai.darcherif.fr: 41
14
Paths Targeted (with Hostname Counts)
Path Distinct Hostnames
site/wp-includes/wlwmanifest.xml 2
sito/wp-includes/wlwmanifest.xml 2
login.action 2
cms/wp-includes/wlwmanifest.xml 2
config.json 2
v2/_catalog 2
shop/wp-includes/wlwmanifest.xml 2
appsettings.json 2
xmlrpc.php 2
webjars/swagger-ui/index.html 2
.aws/credentials 2
appsettings.Production.json 2
vendor/laravel-filemanager/js/script.js 2
s/330313e2338313e26313e223/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties 2
_ignition/execute-solution 2
D/128057/1081022/000/akamai.darcherif.fr/_sec/cp_challenge/challenge 2
test/wp-includes/wlwmanifest.xml 2
ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application 2
swagger.json 2
actuator; 2
graphql/api 2
wp2/wp-includes/wlwmanifest.xml 2
public/_ignition/execute-solution 2
wp/wp-includes/wlwmanifest.xml 2
.env 2
swagger/v1/swagger.json 2
_all_dbs 2
info.php 2
index.php 2
server 2
about 2
actuator 2
api 2
server-status 2
.git/config 2
swagger-ui.html 2
telescope/requests 2
wp-login.php 2
debug/default/view 2
media/wp-includes/wlwmanifest.xml 2
ads.txt 2
api/graphql 2
swagger/swagger-ui.html 2
v3/api-docs 2
graphql 2
v2/api-docs 2
actuator/env 2
prod-api;/actuator; 2
web/wp-includes/wlwmanifest.xml 2
api/swagger.json 2
🚫

Block

All requests from IPs associated with this ASN were flagged by WAF, extensively probing sensitive configurations and known exploit paths (including LFI and Jira exploits), and consistently triggered critical 'LFI-ANOMALY' deny rules. This ASN is confirmed to be highly malicious and is already in the blocklist.

2025-12-12 00:08:31