Table: Security_events
Displaying rows 96201 - 96250 of 120479 (Page 1925 / 2410)
| Entity | Type | Event time | Action taken | Ai reason | Ai confidence score | Ai details | Event id |
|---|---|---|---|---|---|---|---|
| 101.55.81.36 | ip | 2025-07-23 08:00:59 | block | Persistent critical activity targeting sensitive files and web shell paths, indicating exploitation. | 1.0 | severity: Severity.critical | cb6cd8a7-81e8-4872-a900-6f35361abedd |
| 185.177.72.106 | ip | 2025-07-23 08:00:59 | block | Critical malicious activity; 100% of requests flagged by WAF, aggressively targeting sensitive configuration and credential files like .env and aws/credentials. This IP is part of AS211590, which is already blocklisted for similar critical threats. | 1.0 | severity: Severity.critical | 7f0b27d7-0c02-4159-9659-fd7194376e59 |
| 185.177.72.104 | ip | 2025-07-23 08:00:59 | block | Critical malicious activity; aggressive scanning for .env, phpinfo, .git files. | 1.0 | severity: Severity.critical | c7a2b684-dab9-4321-bb93-f6a25ee7984a |
| 178.33.134.25 | ip | 2025-07-23 08:00:59 | block | Critical malicious activity; scanning common directories with browser impersonation. | 0.8999999761581421 | severity: Severity.critical | 9779acb6-9b17-425c-a024-eed01b330aed |
| 185.177.72.16 | ip | 2025-07-23 08:00:59 | block | Critical malicious activity; 100% of requests flagged by WAF, aggressively targeting sensitive configuration and credential files like .env and aws/credentials, coupled with LFI attempts. This IP is part of AS211590, which is already blocklisted for similar critical threats. | 1.0 | severity: Severity.critical | 4c6c2718-cc23-4b9c-bd73-bff557260d69 |
| 185.177.72.144 | ip | 2025-07-23 08:00:59 | block | Critical malicious activity; widespread probing for sensitive files/LFI; AS211590 related. | 1.0 | severity: Severity.critical | 4c22dc2c-ac3a-42ab-abd8-fe52edff0aeb |
| 185.177.72.12 | ip | 2025-07-23 08:00:59 | block | Critical malicious reconnaissance for sensitive app configs/creds; LFI attempts. | 1.0 | severity: Severity.critical | 0ca3cee3-08fc-4420-9bb4-d8620953614b |
| 185.177.72.11 | ip | 2025-07-23 08:00:59 | block | Critical malicious activity; targeting sensitive credentials, env files, server info. | 1.0 | severity: Severity.critical | 1627cf4e-76e5-4bd6-80ea-8897debc227e |
| 185.177.72.3 | ip | 2025-07-23 08:00:59 | block | Critical malicious activity; targeting sensitive creds/config files; LFI anomalies; AS211590 related. | 1.0 | severity: Severity.critical | 6ad52d39-97ad-4c61-994e-b2f8a79898b5 |
| 185.177.72.205 | ip | 2025-07-23 08:00:59 | block | Critical malicious activity; attempting cloud creds, env files, config access; LFI. | 1.0 | severity: Severity.critical | 6ad7eabb-9199-45c3-bdad-4ceca00d0a0d |
| 185.177.72.204 | ip | 2025-07-23 08:00:59 | block | Critical malicious activity; scanning for config files and source code repos. | 1.0 | severity: Severity.critical | 34c8a228-e845-4161-a85e-0cd3eac8c416 |
| 185.177.72.2 | ip | 2025-07-23 08:00:59 | block | Critical malicious activity; targeting sensitive config files; browser impersonation; AS211590 related. | 1.0 | severity: Severity.critical | 2b1c91d5-5aa3-4de8-8fbf-c02ac9803785 |
| 195.178.110.161 | ip | 2025-07-23 08:00:59 | block | Critical malicious activity; scanning for sensitive JS config, JSON creds, env vars; browser impersonation. | 0.8999999761581421 | severity: Severity.critical | 0eabdfa7-f001-4b3e-83d9-c1ecc35b150a |
| 194.50.16.252 | ip | 2025-07-23 08:00:59 | block | Critical malicious activity; targeting Spring Boot Actuator with command injection attempts. | 1.0 | severity: Severity.critical | 2a1beb21-df4b-4322-99db-83adaa04bec1 |
| 2001:4878:8216:510:dddd:b98a:3a76:296c | ip | 2025-07-23 08:00:59 | block | Critical malicious activity; accessed obfuscated path linked to prior critical activity. | 0.949999988079071 | severity: Severity.critical | 82983d5d-7bc8-4253-aaff-b96caa15341d |
| 20.171.207.158 | ip | 2025-07-23 08:00:59 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | d4570c53-7056-4a09-b01b-0a13b847ae20 |
| 205.169.39.130 | ip | 2025-07-23 08:00:59 | block | Critical malicious activity; triggered IP blocking due to burst activity. | 0.8999999761581421 | severity: Severity.critical | ac86ccbd-f4f0-4424-aca5-aa5de23a2377 |
| 2001:bc8:1f90:4:7ec2:55ff:fe9e:8476 | ip | 2025-07-23 08:00:59 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 63e78091-f96c-4f70-b2fb-c1d6c935f478 |
| 2001:bc8:1201:19:46a8:42ff:fe1b:ae29 | ip | 2025-07-23 08:00:59 | block | Persistent medium malicious activity; all requests flagged by WAF. | 0.8500000238418579 | severity: Severity.medium | b7d8d81b-c7d9-4e00-96e3-e77c7aa245ad |
| 216.126.227.20 | ip | 2025-07-23 08:00:59 | block | Critical malicious activity; targeted WordPress paths (wlwmanifest.xml, xmlrpc.php); browser impersonation. | 1.0 | severity: Severity.critical | 09846a70-6f59-4f84-8a87-85492bcfc92d |
| 205.169.39.4 | ip | 2025-07-23 08:00:59 | block | Critical malicious activity; high flagged requests, triggered IP blocking by burst. | 0.8999999761581421 | severity: Severity.critical | d92971d7-61c2-4d4b-a740-52b6245f8767 |
| 3.92.177.104 | ip | 2025-07-23 08:00:59 | block | Critical malicious activity; targeting WordPress wlwmanifest.xml and xmlrpc.php; WAF IPBLOCK. | 1.0 | severity: Severity.critical | 9642030b-7fec-4e24-a5d1-95ff9ad43f91 |
| 2604:a880:400:d1:0:1:4cea:4001 | ip | 2025-07-23 08:00:59 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 3da28468-0f40-4995-b9b3-f0df28ec0386 |
| 34.116.246.85 | ip | 2025-07-23 08:00:59 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 8788046f-f031-4569-b822-a003af195ae8 |
| 34.116.172.61 | ip | 2025-07-23 08:00:59 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | c55fc2be-8047-4e3b-9000-1b419f18be85 |
| 66.249.77.104 | ip | 2025-07-23 08:00:59 | block | Critical malicious activity; all requests flagged by WAF and security alerts. | 0.949999988079071 | severity: Severity.critical | 16986f99-a6b2-4b67-8604-9ff31a37232a |
| 66.249.68.133 | ip | 2025-07-23 08:00:59 | block | Persistent medium malicious scanning; all requests flagged by WAF (100% threat detection). | 0.8999999761581421 | severity: Severity.medium | e5529419-e1fa-4d26-a68b-6a0e3b946537 |
| 51.38.105.105 | ip | 2025-07-23 08:00:59 | block | Critical malicious activity; extensive scanning for sensitive files/PHP info; browser impersonation. | 0.8999999761581421 | severity: Severity.critical | 48dc8e08-ec93-45db-ae96-fac95ee06d49 |
| AS211590 | asn | 2025-07-23 08:00:59 | block | Critical malicious activity; 100% threat detection targeting sensitive files/creds/LFI. | 1.0 | severity: Severity.critical | 02d13df7-7fe9-4353-9ba0-40898bfd8e18 |
| AS16276 | asn | 2025-07-23 08:00:59 | block | Critical malicious activity; aggregated traffic with high threat detection, diverse malicious activities. | 1.0 | severity: Severity.critical | 888f1368-49be-4345-8f9a-3f363be635f4 |
| AS132203 | asn | 2025-07-23 08:00:59 | block | Critical malicious activity; high volume 100% flagged requests targeting WordPress; obfuscated paths. | 0.8999999761581421 | severity: Severity.critical | 12ca0ec7-a301-415e-ab7a-00532a7b59a1 |
| 3%7e7bcf51bfc0d0b65f | tls | 2025-07-23 08:00:59 | block | Critical malicious activity; extensive reconnaissance for sensitive app configs/creds; LFI attempts. | 1.0 | severity: Severity.critical | e3e82efa-d4e6-40ff-a11d-2344ccbbce5e |
| 3%7e2faa3a9db1c111de | tls | 2025-07-23 08:00:59 | block | Critical malicious activity; high volume 100% flagged requests targeting WordPress/sensitive configs/obfuscated paths. | 1.0 | severity: Severity.critical | 4f6cd345-e90e-4192-889a-4004a92410ba |
| 3%7ede29393936a8dc4153 | tls | 2025-07-23 08:00:59 | block | Critical malicious activity; all requests flagged by WAF; targeting WordPress endpoints; obfuscated paths; browser impersonation. | 0.949999988079071 | severity: Severity.critical | 3f3533f1-cab0-41a6-b88f-77d88db0c553 |
| 3%7ede293936a8dc4153 | tls | 2025-07-23 08:00:59 | block | Critical malicious activity; all requests flagged by WAF; targeting WordPress endpoints; obfuscated paths; browser impersonation. | 0.949999988079071 | severity: Severity.critical | 287240cc-b737-47aa-bf93-29b6d20728b0 |
| 3%7ebaae1457ad64ff16 | tls | 2025-07-23 08:00:59 | block | Critical malicious activity; all requests flagged by WAF; obfuscated paths; reconnaissance. | 0.8999999761581421 | severity: Severity.critical | 5bfb7911-cdde-4571-a21b-bb190fab6fc9 |
| 3%7ea97fdb0b70d4a7b7 | tls | 2025-07-23 08:00:59 | block | Critical malicious activity; 100% flagged; aggressive scanning for sensitive files/creds/phpinfo; browser impersonation. | 0.9800000190734863 | severity: Severity.critical | b15d2ac3-2df2-42fb-8abd-27cac0afdc54 |
| UNKNOWN | tls | 2025-07-23 08:00:59 | block | Critical malicious activity; comprehensive/aggressive attacks: sensitive file probing, WordPress exploits, web shell probing, LFI. | 1.0 | severity: Severity.critical | b1cdbc7b-4ca4-4100-a110-e36751d84443 |
| 3%7ee35ec11fcbea7346 | tls | 2025-07-23 08:00:59 | block | Critical malicious activity; very high flagged requests, obfuscated paths; triggered IP blocking by burst. | 0.8999999761581421 | severity: Severity.critical | e6ddb35d-885d-4f21-b9b7-cb41d96f5abd |
| 157.180.49.118 | ip | 2025-07-23 07:55:59 | ignore | Entity is already present in the blocklist and should be removed from watchlists. | 0.8500000238418579 | severity: Severity.medium | 56750afd-5575-496b-9f18-6496334c8553 |
| 123.6.49.50 | ip | 2025-07-23 07:55:59 | ignore | Entity is already present in the blocklist and should be removed from watchlists. | 0.8999999761581421 | severity: Severity.critical | 31ec02c3-9a42-4087-9baf-bb0c00ac350e |
| 103.207.148.148 | ip | 2025-07-23 07:55:59 | ignore | Entity is already present in the blocklist and should be removed from watchlists. | 0.949999988079071 | severity: Severity.critical | bfacc1e5-0353-4aae-b2f6-3cdd40d93233 |
| 101.55.81.36 | ip | 2025-07-23 07:55:59 | ignore | Entity is already present in the blocklist and should be removed from watchlists. | 1.0 | severity: Severity.critical | 42a1d6d5-9045-478a-9b6e-3cbd34123483 |
| 185.177.72.106 | ip | 2025-07-23 07:55:59 | ignore | Entity is already present in the blocklist and should be removed from watchlists. | 1.0 | severity: Severity.critical | 42a530c7-9333-45cc-8977-68a57b5e2edb |
| 185.177.72.104 | ip | 2025-07-23 07:55:59 | ignore | Entity is already present in the blocklist and should be removed from watchlists. | 1.0 | severity: Severity.critical | fb12ef7c-9b9f-44e2-91a9-dd95f4109e0c |
| 178.33.134.25 | ip | 2025-07-23 07:55:59 | ignore | Entity is already present in the blocklist and should be removed from watchlists. | 0.8999999761581421 | severity: Severity.critical | 0493f7cb-26f8-4f92-a8fe-92b144055be5 |
| 185.177.72.16 | ip | 2025-07-23 07:55:59 | ignore | Entity is already present in the blocklist and should be removed from watchlists. | 1.0 | severity: Severity.critical | ab8e8c02-15c8-44a7-a94c-f636087b9f2c |
| 185.177.72.144 | ip | 2025-07-23 07:55:59 | ignore | Entity is already present in the blocklist and should be removed from watchlists. | 1.0 | severity: Severity.critical | 6c71300a-09b9-46e5-a9c2-396282738738 |
| 185.177.72.12 | ip | 2025-07-23 07:55:59 | ignore | Entity is already present in the blocklist and should be removed from watchlists. | 1.0 | severity: Severity.critical | 26ac0813-f69c-4a84-a998-ba48569ef155 |
| 185.177.72.11 | ip | 2025-07-23 07:55:59 | ignore | Entity is already present in the blocklist and should be removed from watchlists. | 1.0 | severity: Severity.critical | b7255204-327e-4356-87d6-1cd907e0c292 |