Table: Security_events
Displaying rows 96151 - 96200 of 120479 (Page 1924 / 2410)
| Entity | Type | Event time | Action taken | Ai reason | Ai confidence score | Ai details | Event id |
|---|---|---|---|---|---|---|---|
| 3%7ede293936a8dc4153 | tls | 2025-07-23 08:11:00 | block | Critical malicious activity; all requests flagged by WAF; targeting WordPress endpoints; obfuscated paths; browser impersonation. | 0.949999988079071 | severity: Severity.critical | 58ef3bf2-6581-483e-b05e-eab580cb50b3 |
| 3%7ebaae1457ad64ff16 | tls | 2025-07-23 08:11:00 | block | Critical malicious activity; all requests flagged by WAF; obfuscated paths; reconnaissance. | 0.8999999761581421 | severity: Severity.critical | e98de584-47a3-4e92-9a8d-a8f777f9be45 |
| 3%7ea97fdb0b70d4a7b7 | tls | 2025-07-23 08:11:00 | block | Critical malicious activity; 100% flagged; aggressive scanning for sensitive files/creds/phpinfo; browser impersonation. | 0.9800000190734863 | severity: Severity.critical | 6721ae8b-e7fb-4353-af73-2ab10a4c316f |
| UNKNOWN | tls | 2025-07-23 08:11:00 | block | Critical malicious activity; comprehensive/aggressive attacks: sensitive file probing, WordPress exploits, web shell probing, LFI. | 1.0 | severity: Severity.critical | 50e143d7-c71f-4337-b34e-8e48543ccb96 |
| 3%7ee35ec11fcbea7346 | tls | 2025-07-23 08:11:00 | block | Critical malicious activity; very high flagged requests, obfuscated paths; triggered IP blocking by burst. | 0.8999999761581421 | severity: Severity.critical | b2ceac81-60b2-4759-9bc5-a68ca7953d64 |
| 157.180.49.118 | ip | 2025-07-23 08:06:01 | block | Persistent medium malicious probing; all requests flagged by WAF. | 0.8500000238418579 | severity: Severity.medium | 4b02924e-0a77-4422-b06f-b53041fefb5a |
| 123.6.49.50 | ip | 2025-07-23 08:06:01 | block | Critical malicious activity; all requests flagged by WAF with multiple rule hits. | 0.8999999761581421 | severity: Severity.critical | 485a26de-d7f0-4d5f-aeaf-a039cc15a524 |
| 103.207.148.148 | ip | 2025-07-23 08:06:01 | block | Critical malicious probing for sensitive config/env files; browser impersonation detected. | 0.949999988079071 | severity: Severity.critical | 65943d16-8172-4eef-84de-a6c96ce4dd2b |
| 101.55.81.36 | ip | 2025-07-23 08:06:01 | block | Persistent critical activity targeting sensitive files and web shell paths, indicating exploitation. | 1.0 | severity: Severity.critical | a24115b3-5233-46d1-8acd-59084956585a |
| 185.177.72.106 | ip | 2025-07-23 08:06:01 | block | Critical malicious activity; 100% of requests flagged by WAF, aggressively targeting sensitive configuration and credential files like .env and aws/credentials. This IP is part of AS211590, which is already blocklisted for similar critical threats. | 1.0 | severity: Severity.critical | d5cbe20b-1920-4637-8113-0cffc455dd8c |
| 185.177.72.104 | ip | 2025-07-23 08:06:01 | block | Critical malicious activity; aggressive scanning for .env, phpinfo, .git files. | 1.0 | severity: Severity.critical | 8a3efad3-fe7a-4c7f-8262-cac304f3d16e |
| 178.33.134.25 | ip | 2025-07-23 08:06:01 | block | Critical malicious activity; scanning common directories with browser impersonation. | 0.8999999761581421 | severity: Severity.critical | 2dfd94a4-29cb-437e-bf69-e4589248dda7 |
| 185.177.72.16 | ip | 2025-07-23 08:06:01 | block | Critical malicious activity; 100% of requests flagged by WAF, aggressively targeting sensitive configuration and credential files like .env and aws/credentials, coupled with LFI attempts. This IP is part of AS211590, which is already blocklisted for similar critical threats. | 1.0 | severity: Severity.critical | 8df0a952-20fd-4d8a-a38e-da23de1ba2c8 |
| 185.177.72.144 | ip | 2025-07-23 08:06:01 | block | Critical malicious activity; widespread probing for sensitive files/LFI; AS211590 related. | 1.0 | severity: Severity.critical | 2fd0bcb1-3c3a-4b9e-b314-d91bcf538361 |
| 185.177.72.12 | ip | 2025-07-23 08:06:01 | block | Critical malicious reconnaissance for sensitive app configs/creds; LFI attempts. | 1.0 | severity: Severity.critical | 00deb139-5d69-425c-a88a-5bd4578a78a2 |
| 185.177.72.11 | ip | 2025-07-23 08:06:01 | block | Critical malicious activity; targeting sensitive credentials, env files, server info. | 1.0 | severity: Severity.critical | b83b9792-f283-41a1-ad96-2206ed852b73 |
| 185.177.72.3 | ip | 2025-07-23 08:06:01 | block | Critical malicious activity; targeting sensitive creds/config files; LFI anomalies; AS211590 related. | 1.0 | severity: Severity.critical | bb570759-fcb1-4715-aa38-36ddd0784f03 |
| 185.177.72.205 | ip | 2025-07-23 08:06:01 | block | Critical malicious activity; attempting cloud creds, env files, config access; LFI. | 1.0 | severity: Severity.critical | 37e7abdb-d8ae-486e-8028-4a24282466c2 |
| 185.177.72.204 | ip | 2025-07-23 08:06:01 | block | Critical malicious activity; scanning for config files and source code repos. | 1.0 | severity: Severity.critical | a57af3d1-c25d-43c1-b742-0d2993df82a4 |
| 185.177.72.2 | ip | 2025-07-23 08:06:01 | block | Critical malicious activity; targeting sensitive config files; browser impersonation; AS211590 related. | 1.0 | severity: Severity.critical | e0cacbf6-e7dc-4c3f-b339-b27dc478a2ea |
| 195.178.110.161 | ip | 2025-07-23 08:06:01 | block | Critical malicious activity; scanning for sensitive JS config, JSON creds, env vars; browser impersonation. | 0.8999999761581421 | severity: Severity.critical | 067ce5d9-4f94-4508-874e-0cc6dcad1d79 |
| 194.50.16.252 | ip | 2025-07-23 08:06:01 | block | Critical malicious activity; targeting Spring Boot Actuator with command injection attempts. | 1.0 | severity: Severity.critical | c34741c5-ea99-4246-a3d5-2d60dbe7a26e |
| 2001:4878:8216:510:dddd:b98a:3a76:296c | ip | 2025-07-23 08:06:01 | block | Critical malicious activity; accessed obfuscated path linked to prior critical activity. | 0.949999988079071 | severity: Severity.critical | 21544efc-4eab-45a9-aa05-205439f8f606 |
| 20.171.207.158 | ip | 2025-07-23 08:06:01 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | f5c55162-6d00-4706-983c-fede27c736bc |
| 205.169.39.130 | ip | 2025-07-23 08:06:01 | block | Critical malicious activity; triggered IP blocking due to burst activity. | 0.8999999761581421 | severity: Severity.critical | 748b084b-667a-4007-968a-cf6506135c1a |
| 2001:bc8:1f90:4:7ec2:55ff:fe9e:8476 | ip | 2025-07-23 08:06:01 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 0a8024be-a814-4036-a740-525d8f5fd330 |
| 2001:bc8:1201:19:46a8:42ff:fe1b:ae29 | ip | 2025-07-23 08:06:01 | block | Persistent medium malicious activity; all requests flagged by WAF. | 0.8500000238418579 | severity: Severity.medium | 39269af7-3a10-4324-aa4a-733552ed66f6 |
| 216.126.227.20 | ip | 2025-07-23 08:06:01 | block | Critical malicious activity; targeted WordPress paths (wlwmanifest.xml, xmlrpc.php); browser impersonation. | 1.0 | severity: Severity.critical | 0cf60968-daee-4cce-8162-4ac41d71a525 |
| 205.169.39.4 | ip | 2025-07-23 08:06:01 | block | Critical malicious activity; high flagged requests, triggered IP blocking by burst. | 0.8999999761581421 | severity: Severity.critical | f06a7c9f-6dcf-4a29-9823-f335fdb9ff36 |
| 3.92.177.104 | ip | 2025-07-23 08:06:01 | block | Critical malicious activity; targeting WordPress wlwmanifest.xml and xmlrpc.php; WAF IPBLOCK. | 1.0 | severity: Severity.critical | 48a98cb3-d39d-4e3f-afbc-7e2574cb4a06 |
| 2604:a880:400:d1:0:1:4cea:4001 | ip | 2025-07-23 08:06:01 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 19d408b8-f5eb-47f0-8fa1-2e347ee5ba7f |
| 34.116.246.85 | ip | 2025-07-23 08:06:01 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | feb75a30-1186-4a84-859e-374c3bed1e84 |
| 34.116.172.61 | ip | 2025-07-23 08:06:01 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | bd273b64-426a-44e1-bedd-5ad31ecfd0e2 |
| 66.249.77.104 | ip | 2025-07-23 08:06:01 | block | Critical malicious activity; all requests flagged by WAF and security alerts. | 0.949999988079071 | severity: Severity.critical | 05c113df-7f48-4757-b414-005bfd8c94d1 |
| 66.249.68.133 | ip | 2025-07-23 08:06:01 | block | Persistent medium malicious scanning; all requests flagged by WAF (100% threat detection). | 0.8999999761581421 | severity: Severity.medium | 6c87ac15-c73f-4f0e-9c1f-7a9dd7eed8fa |
| 51.38.105.105 | ip | 2025-07-23 08:06:01 | block | Critical malicious activity; extensive scanning for sensitive files/PHP info; browser impersonation. | 0.8999999761581421 | severity: Severity.critical | d48f917c-2db1-4f0c-a884-82235be0cac1 |
| AS211590 | asn | 2025-07-23 08:06:01 | block | Critical malicious activity; 100% threat detection targeting sensitive files/creds/LFI. | 1.0 | severity: Severity.critical | 3b00f135-ec58-41d5-8b1f-673324fed41b |
| AS16276 | asn | 2025-07-23 08:06:01 | block | Critical malicious activity; aggregated traffic with high threat detection, diverse malicious activities. | 1.0 | severity: Severity.critical | 30ffae8d-b10a-4ae1-aa7f-7ce556783f98 |
| AS132203 | asn | 2025-07-23 08:06:01 | block | Critical malicious activity; high volume 100% flagged requests targeting WordPress; obfuscated paths. | 0.8999999761581421 | severity: Severity.critical | 9bd889b9-e1ff-4841-b9ab-26401c348b9a |
| 3%7e7bcf51bfc0d0b65f | tls | 2025-07-23 08:06:01 | block | Critical malicious activity; extensive reconnaissance for sensitive app configs/creds; LFI attempts. | 1.0 | severity: Severity.critical | 13095935-7cab-4a2b-8706-966d2ab3ecac |
| 3%7e2faa3a9db1c111de | tls | 2025-07-23 08:06:01 | block | Critical malicious activity; high volume 100% flagged requests targeting WordPress/sensitive configs/obfuscated paths. | 1.0 | severity: Severity.critical | d7162ca8-1479-4a4b-a758-56097ff484fb |
| 3%7ede29393936a8dc4153 | tls | 2025-07-23 08:06:01 | block | Critical malicious activity; all requests flagged by WAF; targeting WordPress endpoints; obfuscated paths; browser impersonation. | 0.949999988079071 | severity: Severity.critical | 03715a6d-d8b0-41a4-9a68-ee855ac187ff |
| 3%7ede293936a8dc4153 | tls | 2025-07-23 08:06:01 | block | Critical malicious activity; all requests flagged by WAF; targeting WordPress endpoints; obfuscated paths; browser impersonation. | 0.949999988079071 | severity: Severity.critical | 91df76e9-7a4f-4e67-a1cb-e4c41c31853a |
| 3%7ebaae1457ad64ff16 | tls | 2025-07-23 08:06:01 | block | Critical malicious activity; all requests flagged by WAF; obfuscated paths; reconnaissance. | 0.8999999761581421 | severity: Severity.critical | 135da0ee-8085-4853-9f2e-d00cf89f9380 |
| 3%7ea97fdb0b70d4a7b7 | tls | 2025-07-23 08:06:01 | block | Critical malicious activity; 100% flagged; aggressive scanning for sensitive files/creds/phpinfo; browser impersonation. | 0.9800000190734863 | severity: Severity.critical | 9d86f522-3899-4060-8c95-0b068b192ea4 |
| UNKNOWN | tls | 2025-07-23 08:06:01 | block | Critical malicious activity; comprehensive/aggressive attacks: sensitive file probing, WordPress exploits, web shell probing, LFI. | 1.0 | severity: Severity.critical | 75398753-a2f3-42f0-9dab-1b5d97f0b2d9 |
| 3%7ee35ec11fcbea7346 | tls | 2025-07-23 08:06:01 | block | Critical malicious activity; very high flagged requests, obfuscated paths; triggered IP blocking by burst. | 0.8999999761581421 | severity: Severity.critical | b9b33f83-e0bf-4290-ad23-1bdedcf484df |
| 157.180.49.118 | ip | 2025-07-23 08:00:59 | block | Persistent medium malicious probing; all requests flagged by WAF. | 0.8500000238418579 | severity: Severity.medium | ff79e519-1c0a-4bbb-997c-af38f9284a42 |
| 123.6.49.50 | ip | 2025-07-23 08:00:59 | block | Critical malicious activity; all requests flagged by WAF with multiple rule hits. | 0.8999999761581421 | severity: Severity.critical | c4ac02c6-bb54-4d42-a1e1-b82284dea807 |
| 103.207.148.148 | ip | 2025-07-23 08:00:59 | block | Critical malicious probing for sensitive config/env files; browser impersonation detected. | 0.949999988079071 | severity: Severity.critical | b5af571f-f89a-40b6-9b47-1f9897aab1fb |