Investigation Workspace

Entity: AS201814 (Asn)

Entity Details
Type
Asn
ASN
AS201814 - MEVSPACE sp. z o.o.
Threat Intelligence
Extremely high number of detected threat requests (68 out of 74 total) from this ASN, targeting critical paths like 'wp-login.php' and '.git/HEAD', and triggering multiple WAF alerts ('3900998', '3990001'). Indicates widespread malicious activity.
Linked Entities
TLS Fingerprints (9)
Hostnames Targeted
Hostname Request Count
akamai.darcherif.fr 181
www.darcherif.fr 148
Paths Targeted (with Request Counts)
Path Request Count
wp-login.php 117
/ 19
.env 12
js/mpulse.js 9
js/scripts.js 9
.git/config 9
assets/mail/contact_me.js 9
stackpath.bootstrapcdn.com/bootstrap/4.4.1/js/bootstrap.bundle.min.js 4
cdnjs.cloudflare.com/ajax/libs/font-awesome/5.13.0/js/all.min.js 4
cdnjs.cloudflare.com/ajax/libs/jquery-easing/1.4.1/jquery.easing.min.js 4
wp-emoji-release.min.js 4
mail/jqBootstrapValidation.js 4
phpinfo.php 4
mail/contact_me.js 4
_profiler/phpinfo 4
cdnjs.cloudflare.com/ajax/libs/jquery/3.4.1/jquery.min.js 4
mpulse.js 4
scripts.js 4
www.darcherif.fr/wp-includes/js/imagesloaded.min.js 4
www.darcherif.fr/wp-content/themes/highlight/assets/js/theme-child.js 4
www.darcherif.fr/wp-content/plugins/mesmerize-companion/theme-data/mesmerize/assets/js/companion.bundle.min.js 3
phpinfo 3
.env.production 3
test.php 3
dashboard/info.php 3
admin/phpinfo.php 3
www.darcherif.fr/wp-includes/js/jquery/jquery-migrate.min.js 3
info.php 3
wp-content/debug.log 3
.aws/credentials 3
.env.development 3
.env.example 3
logs/debug.log 2
www.darcherif.fr/wp-includes/js/jquery/jquery.min.js 2
app_dev.php/_profiler/phpinfo 2
symfony/_profiler/phpinfo 2
backend/.env 2
api/.env 2
index.php/phpinfo 2
www.darcherif.fr/wp-content/themes/mesmerize/assets/js/theme.bundle.min.js 2
www.darcherif.fr/wp-includes/js/masonry.min.js 2
index.php/author/admin3157/ 1
config/database.yml 1
docker-compose.yml 1
storage/logs/laravel.log 1
config/settings.js 1
.vscode/settings.json 1
backup/phpinfo.php 1
config/parameters.yml 1
staging/phpinfo.php 1
🚫

Block

Extremely high number of detected threat requests (68 out of 74 total) from this ASN, targeting critical paths like 'wp-login.php' and '.git/HEAD', and triggering multiple WAF alerts ('3900998', '3990001'). Indicates widespread malicious activity.

2026-02-25 13:20:45