Investigation Workspace

Entity: AS48090 (Asn)

Entity Details
Type
Asn
ASN
AS48090 - TECHOFF SRV LIMITED
Threat Intelligence
Associated with IP 45.148.10.246, which demonstrated extensive probing of sensitive files, had all requests flagged by WAF, and triggered critical deny rules including LFI-ANOMALY and IPBLOCK.
Linked Entities
TLS Fingerprints (16)
Hostnames Targeted
Hostname Request Count
akamai.darcherif.fr 6532
www.darcherif.fr 325
akamai.darcherif.fr:443 4
akamai.darcherif.fr:80 4
2
Paths Targeted (with Hostname Counts)
Path Distinct Hostnames
.env.old 2
.git/HEAD 2
.env.backup 2
dev/.env 2
.env.prod 2
info 2
php_info.php 2
credentials.json 2
backend/.env 2
phpinfo 2
.env 2
admin/.env 2
.aws/credentials 2
.git/config 2
configuration.php.bak 2
.env.example 2
phpinfo.php 2
test.php 2
config.json 2
api/.env 2
config.js 2
.env.save 2
_profiler/phpinfo 2
aws.env 2
config.php.bak 2
secrets.json 2
appsettings.json 2
info.php 2
application/.env 2
.env.production 2
application.yml 2
.env.staging 2
cdnjs.cloudflare.com/ajax/libs/font-awesome/5.13.0/js/all.min.js 1
migrations/stripe_config.sql 1
./config/phpmailer_config.php 1
wp-content/plugins/wp-mandrill/wpmandrill.class.php/ 1
./application/config/sendgrid.php 1
archives/config/stripe.php/ 1
./tests/fixtures/mail.php 1
./wp-content/plugins/wp-mail-smtp/wp-mail-smtp.php 1
wp-content/plugins/yith-woocommerce-email-templates/yith-woocommerce-email-templates.php/ 1
./config/mail.production.php 1
wp-content/plugins/arweave-mail/arweave-mail.php/ 1
./config/packages/stage/mailer.yaml 1
config/autoload/global.php 1
wp-content/themes/oceanwp/functions.php/ 1
.ebextensions/01-stripe.config/ 1
app/config/stripe_backup.php/ 1
app/config/parameters.yml 1
config/local/payment.php/ 1
🚫

Block

Associated with IP 45.148.10.246, which demonstrated extensive probing of sensitive files, had all requests flagged by WAF, and triggered critical deny rules including LFI-ANOMALY and IPBLOCK.

2025-12-04 12:34:38