Investigation Workspace

Entity: AS51167 (Asn)

Entity Details
Type
Asn
ASN
AS51167
Threat Intelligence
Active exploitation attempts targeting sensitive files like .env and SQL backups, with multiple critical WAF deny rules triggered, including Local File Inclusion (LFI) anomalies.
Linked Entities
TLS Fingerprints (7)
Hostnames Targeted
Hostname Request Count
akamai.darcherif.fr 658
www.darcherif.fr 284
Paths Targeted (with Request Counts)
Path Request Count
/ 30
scripts.js 12
mpulse.js 11
cdnjs.cloudflare.com/ajax/libs/font-awesome/5.13.0/js/all.min.js 11
stackpath.bootstrapcdn.com/bootstrap/4.4.1/js/bootstrap.bundle.min.js 11
mail/contact_me.js 11
cdnjs.cloudflare.com/ajax/libs/jquery-easing/1.4.1/jquery.easing.min.js 11
mail/jqBootstrapValidation.js 11
cdnjs.cloudflare.com/ajax/libs/jquery/3.4.1/jquery.min.js 11
.env 8
.env.dev.local 3
.git/config 3
django-blog/.env 2
admin/.env 2
admin/config 2
theme/.env 2
_ignition/ 2
error.log 2
app/config/.env 2
examples/sdl-first/.env 2
.docker/.env 2
node_modules/.env 2
owncloud/.env 2
mail/.env 2
yarn-debug.log 2
rust-backend/dao/.env 2
debug-output.txt 2
postfixadmin/.env 2
debug/default/view 2
wp-content/mysql.sql 2
phpinfo.php3 2
platform/.env 2
Dockerfile 2
bucoffea/.env 2
conn.asp.bak 2
config/config.yml 2
_info.php 2
.env.test 2
tools/phpinfo.php 2
application/.env 2
micro-app-react/.env 2
wp-config.php.backup 2
api/register 2
env/.env 2
app/.env 2
phpinfo.php 2
.env.stage 2
.env.example 2
fastlane/.env 2
info.php.back 2
ℹ️

Watchlist

Associated with an IP address (109.205.180.195) engaged in critical security threats, including LFI attempts and sensitive file access. Requires monitoring for broader malicious activity from this ASN.

2026-02-16 17:52:42
🚫

Block

Active exploitation attempts targeting sensitive files like .env and SQL backups, with multiple critical WAF deny rules triggered, including Local File Inclusion (LFI) anomalies.

2026-02-16 18:52:58