Table: Security_events
Displaying rows 96851 - 96900 of 120479 (Page 1938 / 2410)
| Entity | Type | Event time | Action taken | Ai reason | Ai confidence score | Ai details | Event id |
|---|---|---|---|---|---|---|---|
| 185.177.72.2 | ip | 2025-07-22 15:20:43 | block | Critical malicious activity; targeting sensitive config files; browser impersonation; AS211590 related. | 1.0 | severity: Severity.critical | 679d41aa-5199-4505-aa9e-7e894258e677 |
| 195.178.110.161 | ip | 2025-07-22 15:20:43 | block | Critical malicious activity; scanning for sensitive JS config, JSON creds, env vars; browser impersonation. | 0.8999999761581421 | severity: Severity.critical | 15a67f48-0937-4a5c-9115-a0896859e750 |
| 194.50.16.252 | ip | 2025-07-22 15:20:43 | block | Critical malicious activity; targeting Spring Boot Actuator with command injection attempts. | 1.0 | severity: Severity.critical | 12026f27-1415-4e70-924e-3e173450b158 |
| 2001:4878:8216:510:dddd:b98a:3a76:296c | ip | 2025-07-22 15:20:43 | block | Critical malicious activity; accessed obfuscated path linked to prior critical activity. | 0.949999988079071 | severity: Severity.critical | 3e96e21c-308f-4a79-ae3d-67153a42122f |
| 20.171.207.158 | ip | 2025-07-22 15:20:43 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 89926ba9-465c-4b73-8a59-cda776fd6122 |
| 2001:bc8:1f90:4:7ec2:55ff:fe9e:8476 | ip | 2025-07-22 15:20:43 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 0c859900-6fb8-4d81-b239-f2827def70f5 |
| 2001:bc8:1201:19:46a8:42ff:fe1b:ae29 | ip | 2025-07-22 15:20:43 | block | Persistent medium malicious activity; all requests flagged by WAF. | 0.8500000238418579 | severity: Severity.medium | 74046f76-4486-4e50-8971-da5d965f20a5 |
| 157.180.49.118 | ip | 2025-07-22 15:10:44 | block | Persistent medium malicious probing; all requests flagged by WAF. | 0.8500000238418579 | severity: Severity.medium | 8fdec77d-fead-4ec2-a25d-31f32bc2af03 |
| 123.6.49.50 | ip | 2025-07-22 15:10:44 | block | Critical malicious activity; all requests flagged by WAF with multiple rule hits. | 0.8999999761581421 | severity: Severity.critical | 9e8ec0d4-2ae9-4bea-badf-bc02c8263736 |
| 103.207.148.148 | ip | 2025-07-22 15:10:44 | block | Critical malicious probing for sensitive config/env files; browser impersonation detected. | 0.949999988079071 | severity: Severity.critical | 24c1038b-6f4a-4554-a89c-1e0cd7445ecf |
| 101.55.81.36 | ip | 2025-07-22 15:10:44 | block | Persistent critical activity targeting sensitive files and web shell paths, indicating exploitation. | 1.0 | severity: Severity.critical | c118bb52-fe60-4920-9302-3272440f7788 |
| 185.177.72.104 | ip | 2025-07-22 15:10:44 | block | Critical malicious activity; aggressive scanning for .env, phpinfo, .git files. | 1.0 | severity: Severity.critical | bcfd290c-53a5-43a1-88c0-684c26c15dc1 |
| 178.33.134.25 | ip | 2025-07-22 15:10:44 | block | Critical malicious activity; scanning common directories with browser impersonation. | 0.8999999761581421 | severity: Severity.critical | 7dba8a06-a553-4049-97ea-e1cce48beeed |
| 185.177.72.144 | ip | 2025-07-22 15:10:44 | block | Critical malicious activity; widespread probing for sensitive files/LFI; AS211590 related. | 1.0 | severity: Severity.critical | a04242cd-4a05-4fa1-867d-43ff983c5ad4 |
| 185.177.72.12 | ip | 2025-07-22 15:10:44 | block | Critical malicious reconnaissance for sensitive app configs/creds; LFI attempts. | 1.0 | severity: Severity.critical | 1c547cfc-d21e-4d65-bad1-c8ffb1f07a3c |
| 185.177.72.11 | ip | 2025-07-22 15:10:44 | block | Critical malicious activity; targeting sensitive credentials, env files, server info. | 1.0 | severity: Severity.critical | 825ab655-eb26-4cda-bf20-65ac83287ed0 |
| 185.177.72.3 | ip | 2025-07-22 15:10:44 | block | Critical malicious activity; targeting sensitive creds/config files; LFI anomalies; AS211590 related. | 1.0 | severity: Severity.critical | 6e3d9088-cb87-4abb-a79e-aa663518d2e9 |
| 185.177.72.205 | ip | 2025-07-22 15:10:44 | block | Critical malicious activity; attempting cloud creds, env files, config access; LFI. | 1.0 | severity: Severity.critical | 5ff2c3a7-65c5-43c9-8da7-dd79cfec5b1b |
| 185.177.72.204 | ip | 2025-07-22 15:10:44 | block | Critical malicious activity; scanning for config files and source code repos. | 1.0 | severity: Severity.critical | 19201c50-872f-4b8a-9875-4975f379ea16 |
| 185.177.72.2 | ip | 2025-07-22 15:10:44 | block | Critical malicious activity; targeting sensitive config files; browser impersonation; AS211590 related. | 1.0 | severity: Severity.critical | fb679795-d259-4cc2-a0ec-aa028331b7b5 |
| 195.178.110.161 | ip | 2025-07-22 15:10:44 | block | Critical malicious activity; scanning for sensitive JS config, JSON creds, env vars; browser impersonation. | 0.8999999761581421 | severity: Severity.critical | 621c1dad-2846-4f3a-85ac-f237135f6edf |
| 194.50.16.252 | ip | 2025-07-22 15:10:44 | block | Critical malicious activity; targeting Spring Boot Actuator with command injection attempts. | 1.0 | severity: Severity.critical | 02ebdcd2-bc6c-44bd-a932-b46ca3b0b2a2 |
| 2001:4878:8216:510:dddd:b98a:3a76:296c | ip | 2025-07-22 15:10:44 | block | Critical malicious activity; accessed obfuscated path linked to prior critical activity. | 0.949999988079071 | severity: Severity.critical | daccd3cf-f742-4bef-bbfe-cc6f5a187c5b |
| 20.171.207.158 | ip | 2025-07-22 15:10:44 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 88bdbae8-9900-47bb-bb09-083ccaeca57c |
| 205.169.39.130 | ip | 2025-07-22 15:10:44 | block | Critical malicious activity; triggered IP blocking due to burst activity. | 0.8999999761581421 | severity: Severity.critical | f783be78-6833-4a1d-8eb1-e9cad927a5fb |
| 2001:bc8:1f90:4:7ec2:55ff:fe9e:8476 | ip | 2025-07-22 15:10:44 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 050fd61a-fec8-41cf-bc8f-666850cec21a |
| 2001:bc8:1201:19:46a8:42ff:fe1b:ae29 | ip | 2025-07-22 15:10:44 | block | Persistent medium malicious activity; all requests flagged by WAF. | 0.8500000238418579 | severity: Severity.medium | dcf88674-abe9-4f6b-991c-f40c07812a74 |
| 216.126.227.20 | ip | 2025-07-22 15:10:44 | block | Critical malicious activity; targeted WordPress paths (wlwmanifest.xml, xmlrpc.php); browser impersonation. | 1.0 | severity: Severity.critical | aed8e46c-f8a3-4355-bcde-d80dd1ca90c1 |
| 205.169.39.4 | ip | 2025-07-22 15:10:44 | block | Critical malicious activity; high flagged requests, triggered IP blocking by burst. | 0.8999999761581421 | severity: Severity.critical | d2bf085f-e6f7-4680-9944-cfb61f1a55be |
| 3.92.177.104 | ip | 2025-07-22 15:10:44 | block | Critical malicious activity; targeting WordPress wlwmanifest.xml and xmlrpc.php; WAF IPBLOCK. | 1.0 | severity: Severity.critical | 3f32a143-2c7e-4930-8807-2943721a2f01 |
| 2604:a880:400:d1:0:1:4cea:4001 | ip | 2025-07-22 15:10:44 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | c279b828-194f-4015-a5fa-8281eb790459 |
| 34.116.246.85 | ip | 2025-07-22 15:10:44 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | a9f3a06e-4e3c-42e5-b816-35795f99aa57 |
| 34.116.172.61 | ip | 2025-07-22 15:10:44 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 477816d7-4c14-4eba-a55d-fe689836ad61 |
| 66.249.77.104 | ip | 2025-07-22 15:10:44 | block | Critical malicious activity; all requests flagged by WAF and security alerts. | 0.949999988079071 | severity: Severity.critical | b33a814c-94a3-4bc2-b7b2-0c48936db530 |
| 66.249.68.133 | ip | 2025-07-22 15:10:44 | block | Persistent medium malicious scanning; all requests flagged by WAF (100% threat detection). | 0.8999999761581421 | severity: Severity.medium | 12bc3c53-484e-4829-b429-467f8f0a9015 |
| 51.38.105.105 | ip | 2025-07-22 15:10:44 | block | Critical malicious activity; extensive scanning for sensitive files/PHP info; browser impersonation. | 0.8999999761581421 | severity: Severity.critical | a06e5718-95ae-4c0f-8a81-267f20814306 |
| AS211590 | asn | 2025-07-22 15:10:44 | block | Critical malicious activity; 100% threat detection targeting sensitive files/creds/LFI. | 1.0 | severity: Severity.critical | f24e99f2-7240-4467-84de-bb1bbb70313b |
| AS16276 | asn | 2025-07-22 15:10:44 | block | Critical malicious activity; aggregated traffic with high threat detection, diverse malicious activities. | 1.0 | severity: Severity.critical | 0485407c-f555-482a-a250-f249f0aae9c5 |
| AS132203 | asn | 2025-07-22 15:10:44 | block | Critical malicious activity; high volume 100% flagged requests targeting WordPress; obfuscated paths. | 0.8999999761581421 | severity: Severity.critical | e8f91453-2d3a-4af2-b2bd-0e1243ea1280 |
| 3%7e7bcf51bfc0d0b65f | tls | 2025-07-22 15:10:44 | block | Critical malicious activity; extensive reconnaissance for sensitive app configs/creds; LFI attempts. | 1.0 | severity: Severity.critical | 0caba1b6-9605-4123-a71a-ddb0e636b84c |
| 3%7e2faa3a9db1c111de | tls | 2025-07-22 15:10:44 | block | Critical malicious activity; high volume 100% flagged requests targeting WordPress/sensitive configs/obfuscated paths. | 1.0 | severity: Severity.critical | e3af2e04-66f2-4d6f-9938-0307f99f1e76 |
| 3%7ede29393936a8dc4153 | tls | 2025-07-22 15:10:44 | block | Critical malicious activity; all requests flagged by WAF; targeting WordPress endpoints; obfuscated paths; browser impersonation. | 0.949999988079071 | severity: Severity.critical | c87b87c4-5219-4269-a6ce-44ab136600e8 |
| 3%7ede293936a8dc4153 | tls | 2025-07-22 15:10:44 | block | Critical malicious activity; all requests flagged by WAF; targeting WordPress endpoints; obfuscated paths; browser impersonation. | 0.949999988079071 | severity: Severity.critical | 43d33e40-baa4-4565-84a9-9476fe00244a |
| 3%7ebaae1457ad64ff16 | tls | 2025-07-22 15:10:44 | block | Critical malicious activity; all requests flagged by WAF; obfuscated paths; reconnaissance. | 0.8999999761581421 | severity: Severity.critical | b53e18fc-1bd0-49e7-bbed-946d84fe1e91 |
| 3%7ea97fdb0b70d4a7b7 | tls | 2025-07-22 15:10:44 | block | Critical malicious activity; 100% flagged; aggressive scanning for sensitive files/creds/phpinfo; browser impersonation. | 0.9800000190734863 | severity: Severity.critical | be7db301-987b-4c08-9f48-a966f8a8b2e6 |
| UNKNOWN | tls | 2025-07-22 15:10:44 | block | Critical malicious activity; comprehensive/aggressive attacks: sensitive file probing, WordPress exploits, web shell probing, LFI. | 1.0 | severity: Severity.critical | 0e10d1e7-9e59-4824-8209-21d11135fdfc |
| 3%7ee35ec11fcbea7346 | tls | 2025-07-22 15:10:44 | block | Critical malicious activity; very high flagged requests, obfuscated paths; triggered IP blocking by burst. | 0.8999999761581421 | severity: Severity.critical | b3f7f961-9238-41a9-ab7b-f586d10b63e5 |
| 157.180.49.118 | ip | 2025-07-22 15:00:34 | block | Persistent medium malicious probing; all requests flagged by WAF. | 0.8500000238418579 | severity: Severity.medium | 7dd8a74a-9816-47de-8f0a-1ae1af506717 |
| 123.6.49.50 | ip | 2025-07-22 15:00:34 | block | Critical malicious activity; all requests flagged by WAF with multiple rule hits. | 0.8999999761581421 | severity: Severity.critical | 4c60ea8b-396e-4c43-bd72-ec32c675ddf3 |
| 103.207.148.148 | ip | 2025-07-22 15:00:34 | block | Critical malicious probing for sensitive config/env files; browser impersonation detected. | 0.949999988079071 | severity: Severity.critical | 8789f0bd-0c3a-4f52-948e-1213f547c6cf |