Table: Security_events
Displaying rows 96601 - 96650 of 120479 (Page 1933 / 2410)
| Entity | Type | Event time | Action taken | Ai reason | Ai confidence score | Ai details | Event id |
|---|---|---|---|---|---|---|---|
| 2604:a880:400:d1:0:1:4cea:4001 | ip | 2025-07-22 18:14:16 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | b6d41b3d-5c62-4d36-bd6e-e3c2a9b986d8 |
| 34.116.246.85 | ip | 2025-07-22 18:14:16 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | cec6fa3a-2b72-4940-bf4c-b1f3bc2dffc9 |
| 34.116.172.61 | ip | 2025-07-22 18:14:16 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 3e8ed939-ea51-47ca-bb70-2e9eeebb17a2 |
| 66.249.77.104 | ip | 2025-07-22 18:14:16 | block | Critical malicious activity; all requests flagged by WAF and security alerts. | 0.949999988079071 | severity: Severity.critical | 50a52ad4-8177-46f6-9ed1-736f92e752cb |
| 66.249.68.133 | ip | 2025-07-22 18:14:16 | block | Persistent medium malicious scanning; all requests flagged by WAF (100% threat detection). | 0.8999999761581421 | severity: Severity.medium | 1e5a5694-03fd-4820-aea6-72569d364c98 |
| 51.38.105.105 | ip | 2025-07-22 18:14:16 | block | Critical malicious activity; extensive scanning for sensitive files/PHP info; browser impersonation. | 0.8999999761581421 | severity: Severity.critical | 08427774-8b6b-47bd-948e-635e948e5ddc |
| AS211590 | asn | 2025-07-22 18:14:16 | block | Critical malicious activity; 100% threat detection targeting sensitive files/creds/LFI. | 1.0 | severity: Severity.critical | e9d407f0-28a8-40e3-8ff5-9d72dfadfc67 |
| AS16276 | asn | 2025-07-22 18:14:16 | block | Critical malicious activity; aggregated traffic with high threat detection, diverse malicious activities. | 1.0 | severity: Severity.critical | 0024d0e2-5511-4d6f-9884-3efd394572eb |
| AS132203 | asn | 2025-07-22 18:14:16 | block | Critical malicious activity; high volume 100% flagged requests targeting WordPress; obfuscated paths. | 0.8999999761581421 | severity: Severity.critical | 2365e6c9-9ef3-4e60-ad8a-3a82a674a7bb |
| 3%7e7bcf51bfc0d0b65f | tls | 2025-07-22 18:14:16 | block | Critical malicious activity; extensive reconnaissance for sensitive app configs/creds; LFI attempts. | 1.0 | severity: Severity.critical | 0ef3e4f8-74b5-472d-9f84-e9399c77bb06 |
| 3%7e2faa3a9db1c111de | tls | 2025-07-22 18:14:16 | block | Critical malicious activity; high volume 100% flagged requests targeting WordPress/sensitive configs/obfuscated paths. | 1.0 | severity: Severity.critical | fafcd118-7d87-4b7b-a789-fb8d3a366483 |
| 3%7ede29393936a8dc4153 | tls | 2025-07-22 18:14:16 | block | Critical malicious activity; all requests flagged by WAF; targeting WordPress endpoints; obfuscated paths; browser impersonation. | 0.949999988079071 | severity: Severity.critical | 516263d9-23db-45e2-9355-4e990e8a8538 |
| 3%7ede293936a8dc4153 | tls | 2025-07-22 18:14:16 | block | Critical malicious activity; all requests flagged by WAF; targeting WordPress endpoints; obfuscated paths; browser impersonation. | 0.949999988079071 | severity: Severity.critical | dbcaa304-c8b3-4bdb-923b-ca01719bd7ec |
| 3%7ebaae1457ad64ff16 | tls | 2025-07-22 18:14:16 | block | Critical malicious activity; all requests flagged by WAF; obfuscated paths; reconnaissance. | 0.8999999761581421 | severity: Severity.critical | 0795d7e2-b0e0-46e8-9144-36a027d0aa27 |
| 3%7ea97fdb0b70d4a7b7 | tls | 2025-07-22 18:14:16 | block | Critical malicious activity; 100% flagged; aggressive scanning for sensitive files/creds/phpinfo; browser impersonation. | 0.9800000190734863 | severity: Severity.critical | 289d2800-fc4d-473c-8cdd-7765a1c39273 |
| UNKNOWN | tls | 2025-07-22 18:14:16 | block | Critical malicious activity; comprehensive/aggressive attacks: sensitive file probing, WordPress exploits, web shell probing, LFI. | 1.0 | severity: Severity.critical | bd67b14f-667e-447d-acca-d7d004774735 |
| 3%7ee35ec11fcbea7346 | tls | 2025-07-22 18:14:16 | block | Critical malicious activity; very high flagged requests, obfuscated paths; triggered IP blocking by burst. | 0.8999999761581421 | severity: Severity.critical | adadd30b-132f-48cf-853e-64d9aaa3a00a |
| 157.180.49.118 | ip | 2025-07-22 17:13:34 | block | Persistent medium malicious probing; all requests flagged by WAF. | 0.8500000238418579 | severity: Severity.medium | 11b70751-c1b1-4a03-a873-6658f6b386d3 |
| 123.6.49.50 | ip | 2025-07-22 17:13:34 | block | Critical malicious activity; all requests flagged by WAF with multiple rule hits. | 0.8999999761581421 | severity: Severity.critical | 399be430-ba42-437b-a0c5-07e586e68853 |
| 103.207.148.148 | ip | 2025-07-22 17:13:34 | block | Critical malicious probing for sensitive config/env files; browser impersonation detected. | 0.949999988079071 | severity: Severity.critical | 8a3aa3d4-7bd7-41b3-b852-57b11321a0b5 |
| 101.55.81.36 | ip | 2025-07-22 17:13:34 | block | Persistent critical activity targeting sensitive files and web shell paths, indicating exploitation. | 1.0 | severity: Severity.critical | 3debca2a-da6b-4be3-8a9d-cf067bd3bf25 |
| 185.177.72.104 | ip | 2025-07-22 17:13:34 | block | Critical malicious activity; aggressive scanning for .env, phpinfo, .git files. | 1.0 | severity: Severity.critical | 9cb1b5ea-8862-4037-b96c-b65bc657cf9f |
| 178.33.134.25 | ip | 2025-07-22 17:13:34 | block | Critical malicious activity; scanning common directories with browser impersonation. | 0.8999999761581421 | severity: Severity.critical | bbbf39b0-f597-42e7-9fb8-0e2fbca87a00 |
| 185.177.72.144 | ip | 2025-07-22 17:13:34 | block | Critical malicious activity; widespread probing for sensitive files/LFI; AS211590 related. | 1.0 | severity: Severity.critical | 66b7dd3a-c7d4-4aba-a81a-aa13c92e0423 |
| 185.177.72.12 | ip | 2025-07-22 17:13:34 | block | Critical malicious reconnaissance for sensitive app configs/creds; LFI attempts. | 1.0 | severity: Severity.critical | d91ba6e2-79e9-495f-a5b2-423459f7a0d7 |
| 185.177.72.11 | ip | 2025-07-22 17:13:34 | block | Critical malicious activity; targeting sensitive credentials, env files, server info. | 1.0 | severity: Severity.critical | 63641deb-e9f1-4056-8523-898663eb7597 |
| 185.177.72.3 | ip | 2025-07-22 17:13:34 | block | Critical malicious activity; targeting sensitive creds/config files; LFI anomalies; AS211590 related. | 1.0 | severity: Severity.critical | 5facb31e-1169-4ff7-b5c6-a475d6b3cd4f |
| 185.177.72.205 | ip | 2025-07-22 17:13:34 | block | Critical malicious activity; attempting cloud creds, env files, config access; LFI. | 1.0 | severity: Severity.critical | 9eba9cb5-57ae-454f-8511-9c1653652d8a |
| 185.177.72.204 | ip | 2025-07-22 17:13:34 | block | Critical malicious activity; scanning for config files and source code repos. | 1.0 | severity: Severity.critical | cec0b79a-bd61-46db-90f4-696cd9d3cb11 |
| 185.177.72.2 | ip | 2025-07-22 17:13:34 | block | Critical malicious activity; targeting sensitive config files; browser impersonation; AS211590 related. | 1.0 | severity: Severity.critical | 62fde02c-c04f-4a72-9d2e-05c21087d78f |
| 195.178.110.161 | ip | 2025-07-22 17:13:34 | block | Critical malicious activity; scanning for sensitive JS config, JSON creds, env vars; browser impersonation. | 0.8999999761581421 | severity: Severity.critical | 53b9d5de-4e28-4a8b-bf9b-e5cee7fe3a79 |
| 194.50.16.252 | ip | 2025-07-22 17:13:34 | block | Critical malicious activity; targeting Spring Boot Actuator with command injection attempts. | 1.0 | severity: Severity.critical | 1968274a-6075-49e4-a117-cb05b742ea32 |
| 2001:4878:8216:510:dddd:b98a:3a76:296c | ip | 2025-07-22 17:13:34 | block | Critical malicious activity; accessed obfuscated path linked to prior critical activity. | 0.949999988079071 | severity: Severity.critical | 84532f9f-aff1-474f-a3d7-a80d52c5c1ca |
| 20.171.207.158 | ip | 2025-07-22 17:13:34 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 93c5df32-76dd-4318-a319-bdea1e11a6ef |
| 205.169.39.130 | ip | 2025-07-22 17:13:34 | block | Critical malicious activity; triggered IP blocking due to burst activity. | 0.8999999761581421 | severity: Severity.critical | 81838f33-fe47-44ca-8c45-7335761045ef |
| 2001:bc8:1f90:4:7ec2:55ff:fe9e:8476 | ip | 2025-07-22 17:13:34 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 7525a672-adca-439f-a996-169b20bbecc7 |
| 2001:bc8:1201:19:46a8:42ff:fe1b:ae29 | ip | 2025-07-22 17:13:34 | block | Persistent medium malicious activity; all requests flagged by WAF. | 0.8500000238418579 | severity: Severity.medium | 68574aba-1844-4373-a3fb-46d1eb0fbab3 |
| 216.126.227.20 | ip | 2025-07-22 17:13:34 | block | Critical malicious activity; targeted WordPress paths (wlwmanifest.xml, xmlrpc.php); browser impersonation. | 1.0 | severity: Severity.critical | f38de4d9-3b4c-4400-be80-348dfb9a87dd |
| 205.169.39.4 | ip | 2025-07-22 17:13:34 | block | Critical malicious activity; high flagged requests, triggered IP blocking by burst. | 0.8999999761581421 | severity: Severity.critical | 7de8c7ed-ce7f-4263-9974-7447dc4d5c25 |
| 3.92.177.104 | ip | 2025-07-22 17:13:34 | block | Critical malicious activity; targeting WordPress wlwmanifest.xml and xmlrpc.php; WAF IPBLOCK. | 1.0 | severity: Severity.critical | d6e23435-501e-4e03-a6fd-54014e9cb13a |
| 2604:a880:400:d1:0:1:4cea:4001 | ip | 2025-07-22 17:13:34 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 4c3ce040-030e-45a6-a9cd-25ca09983a8a |
| 34.116.246.85 | ip | 2025-07-22 17:13:34 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 0915197c-d8d3-46bb-9e49-29ad2e9f9b08 |
| 34.116.172.61 | ip | 2025-07-22 17:13:34 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 2d285550-64ba-40fc-bce5-8cabe3e19c24 |
| 66.249.77.104 | ip | 2025-07-22 17:13:34 | block | Critical malicious activity; all requests flagged by WAF and security alerts. | 0.949999988079071 | severity: Severity.critical | df7ef0c8-efc6-4bc4-b903-c38200a39642 |
| 66.249.68.133 | ip | 2025-07-22 17:13:34 | block | Persistent medium malicious scanning; all requests flagged by WAF (100% threat detection). | 0.8999999761581421 | severity: Severity.medium | b2211d8d-fb52-4e11-8d0a-37406daf0aea |
| 51.38.105.105 | ip | 2025-07-22 17:13:34 | block | Critical malicious activity; extensive scanning for sensitive files/PHP info; browser impersonation. | 0.8999999761581421 | severity: Severity.critical | 84eb9b61-14d7-49b8-b6ff-c4b4a1d5357e |
| AS211590 | asn | 2025-07-22 17:13:34 | block | Critical malicious activity; 100% threat detection targeting sensitive files/creds/LFI. | 1.0 | severity: Severity.critical | 176b99a8-39d6-4337-869f-99c2ea93b1ce |
| AS16276 | asn | 2025-07-22 17:13:34 | block | Critical malicious activity; aggregated traffic with high threat detection, diverse malicious activities. | 1.0 | severity: Severity.critical | 7dbd7c6c-f12d-4973-8410-ebdcbcf5dd90 |
| AS132203 | asn | 2025-07-22 17:13:34 | block | Critical malicious activity; high volume 100% flagged requests targeting WordPress; obfuscated paths. | 0.8999999761581421 | severity: Severity.critical | 69c2e673-4008-45f3-8244-79b94b330ba2 |
| 3%7e7bcf51bfc0d0b65f | tls | 2025-07-22 17:13:34 | block | Critical malicious activity; extensive reconnaissance for sensitive app configs/creds; LFI attempts. | 1.0 | severity: Severity.critical | 2c6995ec-e294-4e4e-a431-480a27739189 |