Table: Security_events
Displaying rows 96951 - 97000 of 120479 (Page 1940 / 2410)
| Entity | Type | Event time | Action taken | Ai reason | Ai confidence score | Ai details | Event id |
|---|---|---|---|---|---|---|---|
| 20.171.207.158 | ip | 2025-07-22 14:55:39 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 83ca1969-40b6-468e-947e-62460df3c6e9 |
| 205.169.39.130 | ip | 2025-07-22 14:55:39 | block | Critical malicious activity; triggered IP blocking due to burst activity. | 0.8999999761581421 | severity: Severity.critical | 8bce9701-3602-4b9c-9bea-ec4d0123234e |
| 2001:bc8:1f90:4:7ec2:55ff:fe9e:8476 | ip | 2025-07-22 14:55:39 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 8a53790f-906a-40f4-a8cb-8d9d14dba938 |
| 2001:bc8:1201:19:46a8:42ff:fe1b:ae29 | ip | 2025-07-22 14:55:39 | block | Persistent medium malicious activity; all requests flagged by WAF. | 0.8500000238418579 | severity: Severity.medium | 50a52d08-4e58-416f-9999-dee4c62beb0e |
| 216.126.227.20 | ip | 2025-07-22 14:55:39 | block | Critical malicious activity; targeted WordPress paths (wlwmanifest.xml, xmlrpc.php); browser impersonation. | 1.0 | severity: Severity.critical | 44b91e38-3fdf-4568-9aef-7021546eb8fe |
| 205.169.39.4 | ip | 2025-07-22 14:55:39 | block | Critical malicious activity; high flagged requests, triggered IP blocking by burst. | 0.8999999761581421 | severity: Severity.critical | cad198e3-798d-436c-996f-282211485035 |
| 3.92.177.104 | ip | 2025-07-22 14:55:39 | block | Critical malicious activity; targeting WordPress wlwmanifest.xml and xmlrpc.php; WAF IPBLOCK. | 1.0 | severity: Severity.critical | dcf01c7f-4e18-4f49-8255-fc9a5e9984ba |
| 2604:a880:400:d1:0:1:4cea:4001 | ip | 2025-07-22 14:55:39 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 60452643-edca-42da-a9f7-b8c18fa0773e |
| 34.116.246.85 | ip | 2025-07-22 14:55:39 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 919a5047-532d-432a-be82-195f5cc4dcdc |
| 34.116.172.61 | ip | 2025-07-22 14:55:39 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 21fa7766-46dc-4104-9848-c3e9298d50b8 |
| 66.249.77.104 | ip | 2025-07-22 14:55:39 | block | Critical malicious activity; all requests flagged by WAF and security alerts. | 0.949999988079071 | severity: Severity.critical | 314861b9-9e4c-4bd2-9bda-110ad8bb5f1a |
| 66.249.68.133 | ip | 2025-07-22 14:55:39 | block | Persistent medium malicious scanning; all requests flagged by WAF (100% threat detection). | 0.8999999761581421 | severity: Severity.medium | 5fc645cc-a231-4e0c-9603-c3df08f278c0 |
| 51.38.105.105 | ip | 2025-07-22 14:55:39 | block | Critical malicious activity; extensive scanning for sensitive files/PHP info; browser impersonation. | 0.8999999761581421 | severity: Severity.critical | a845b161-eade-4367-a9c2-cc362befed22 |
| AS211590 | asn | 2025-07-22 14:55:39 | block | Critical malicious activity; 100% threat detection targeting sensitive files/creds/LFI. | 1.0 | severity: Severity.critical | 8c153410-bdcf-4cc2-9b44-55031245cb0c |
| AS16276 | asn | 2025-07-22 14:55:39 | block | Critical malicious activity; aggregated traffic with high threat detection, diverse malicious activities. | 1.0 | severity: Severity.critical | 143e6c7e-075c-4b45-aaff-01a9614a4564 |
| AS132203 | asn | 2025-07-22 14:55:39 | block | Critical malicious activity; high volume 100% flagged requests targeting WordPress; obfuscated paths. | 0.8999999761581421 | severity: Severity.critical | e501720a-6c5b-4854-a32b-6512ae3cc409 |
| 3%7e7bcf51bfc0d0b65f | tls | 2025-07-22 14:55:39 | block | Critical malicious activity; extensive reconnaissance for sensitive app configs/creds; LFI attempts. | 1.0 | severity: Severity.critical | 4ad6dcef-4529-43b9-8506-f7d2322ab230 |
| 3%7e2faa3a9db1c111de | tls | 2025-07-22 14:55:39 | block | Critical malicious activity; high volume 100% flagged requests targeting WordPress/sensitive configs/obfuscated paths. | 1.0 | severity: Severity.critical | f33eaa88-6cd1-48d5-ae7b-bf3057a95713 |
| 3%7ede29393936a8dc4153 | tls | 2025-07-22 14:55:39 | block | Critical malicious activity; all requests flagged by WAF; targeting WordPress endpoints; obfuscated paths; browser impersonation. | 0.949999988079071 | severity: Severity.critical | f24af55b-f770-4269-a781-bc9176792f57 |
| 3%7ede293936a8dc4153 | tls | 2025-07-22 14:55:39 | block | Critical malicious activity; all requests flagged by WAF; targeting WordPress endpoints; obfuscated paths; browser impersonation. | 0.949999988079071 | severity: Severity.critical | 355be388-630d-47cf-954c-a8fb0e15e0ef |
| 3%7ebaae1457ad64ff16 | tls | 2025-07-22 14:55:39 | block | Critical malicious activity; all requests flagged by WAF; obfuscated paths; reconnaissance. | 0.8999999761581421 | severity: Severity.critical | 5b2d1d55-673e-443a-97c0-18877fb5e28d |
| 3%7ea97fdb0b70d4a7b7 | tls | 2025-07-22 14:55:39 | block | Critical malicious activity; 100% flagged; aggressive scanning for sensitive files/creds/phpinfo; browser impersonation. | 0.9800000190734863 | severity: Severity.critical | 08a22820-f241-4f20-9777-93abe2ac1b8b |
| UNKNOWN | tls | 2025-07-22 14:55:39 | block | Critical malicious activity; comprehensive/aggressive attacks: sensitive file probing, WordPress exploits, web shell probing, LFI. | 1.0 | severity: Severity.critical | 0c95a4e3-5a10-4112-818f-467489d56004 |
| 3%7ee35ec11fcbea7346 | tls | 2025-07-22 14:55:39 | block | Critical malicious activity; very high flagged requests, obfuscated paths; triggered IP blocking by burst. | 0.8999999761581421 | severity: Severity.critical | 655a2c64-d6dc-4b6f-b582-718ede752609 |
| 123.6.49.50 | ip | 2025-07-22 14:55:38 | block | Critical malicious activity; all requests flagged by WAF with multiple rule hits. | 0.8999999761581421 | severity: Severity.critical | 21ed3fa4-0872-4021-a3d4-08c61b758bea |
| 103.207.148.148 | ip | 2025-07-22 14:55:38 | block | Critical malicious probing for sensitive config/env files; browser impersonation detected. | 0.949999988079071 | severity: Severity.critical | c3539534-a116-4a15-8bca-8023792e3e4b |
| 101.55.81.36 | ip | 2025-07-22 14:55:38 | block | Persistent critical activity targeting sensitive files and web shell paths, indicating exploitation. | 1.0 | severity: Severity.critical | 46631c6e-9ba0-451a-96bd-1a432332ff17 |
| 157.180.49.118 | ip | 2025-07-22 14:15:51 | block | Persistent medium malicious probing; all requests flagged by WAF. | 0.8500000238418579 | severity: Severity.medium | 8a6f3500-c2d7-4b81-91ca-150b99ff4cf5 |
| 185.177.72.104 | ip | 2025-07-22 14:15:51 | block | Critical malicious activity; aggressive scanning for .env, phpinfo, .git files. | 1.0 | severity: Severity.critical | 00d68c69-a5c3-40bd-b8bd-245521c56a3b |
| 178.33.134.25 | ip | 2025-07-22 14:15:51 | block | Critical malicious activity; scanning common directories with browser impersonation. | 0.8999999761581421 | severity: Severity.critical | 889bd58c-7ef1-4978-8daa-0277f0a76ff2 |
| 185.177.72.144 | ip | 2025-07-22 14:15:51 | block | Critical malicious activity; widespread probing for sensitive files/LFI; AS211590 related. | 1.0 | severity: Severity.critical | 64cba02e-06c5-4ee1-ab3c-0bcda71fc084 |
| 185.177.72.12 | ip | 2025-07-22 14:15:51 | block | Critical malicious reconnaissance for sensitive app configs/creds; LFI attempts. | 1.0 | severity: Severity.critical | 48a45b59-8521-4deb-aeae-6e9b0ecee3f3 |
| 185.177.72.11 | ip | 2025-07-22 14:15:51 | block | Critical malicious activity; targeting sensitive credentials, env files, server info. | 1.0 | severity: Severity.critical | 2a97696b-3177-4079-92a3-adfe73d10a19 |
| 185.177.72.3 | ip | 2025-07-22 14:15:51 | block | Critical malicious activity; targeting sensitive creds/config files; LFI anomalies; AS211590 related. | 1.0 | severity: Severity.critical | 3343350b-2ede-4724-917b-f71221fc48d3 |
| 185.177.72.205 | ip | 2025-07-22 14:15:51 | block | Critical malicious activity; attempting cloud creds, env files, config access; LFI. | 1.0 | severity: Severity.critical | 8279de69-1e92-4657-885b-bf543cd84993 |
| 185.177.72.204 | ip | 2025-07-22 14:15:51 | block | Critical malicious activity; scanning for config files and source code repos. | 1.0 | severity: Severity.critical | b8f0e39f-cd2b-4f9e-ac9a-b42ba3dc230b |
| 185.177.72.2 | ip | 2025-07-22 14:15:51 | block | Critical malicious activity; targeting sensitive config files; browser impersonation; AS211590 related. | 1.0 | severity: Severity.critical | 4c4fb154-58a2-4eb0-90cb-7fbc4eea9c2a |
| 195.178.110.161 | ip | 2025-07-22 14:15:51 | block | Critical malicious activity; scanning for sensitive JS config, JSON creds, env vars; browser impersonation. | 0.8999999761581421 | severity: Severity.critical | 8d8e410f-e7b3-46d4-acf1-25c79101be53 |
| 194.50.16.252 | ip | 2025-07-22 14:15:51 | block | Critical malicious activity; targeting Spring Boot Actuator with command injection attempts. | 1.0 | severity: Severity.critical | 2fab3b06-e041-40e5-8e83-e64cbb23128a |
| 2001:4878:8216:510:dddd:b98a:3a76:296c | ip | 2025-07-22 14:15:51 | block | Critical malicious activity; accessed obfuscated path linked to prior critical activity. | 0.949999988079071 | severity: Severity.critical | 5b05af24-784e-424a-a4bc-e7d3cfeb58ee |
| 20.171.207.158 | ip | 2025-07-22 14:15:51 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | cdf2f8fe-74ed-4a7a-a8b1-ed771a4f1338 |
| 205.169.39.130 | ip | 2025-07-22 14:15:51 | block | Critical malicious activity; triggered IP blocking due to burst activity. | 0.8999999761581421 | severity: Severity.critical | f59bc9fe-2b7f-42ac-a706-d5a2b7ec4353 |
| 2001:bc8:1f90:4:7ec2:55ff:fe9e:8476 | ip | 2025-07-22 14:15:51 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | d10d6ae6-e178-4c7c-80e1-82e1f1ad68e1 |
| 2001:bc8:1201:19:46a8:42ff:fe1b:ae29 | ip | 2025-07-22 14:15:51 | block | Persistent medium malicious activity; all requests flagged by WAF. | 0.8500000238418579 | severity: Severity.medium | bee5b9ce-69fc-4619-a27e-87bc5a664387 |
| 216.126.227.20 | ip | 2025-07-22 14:15:51 | block | Critical malicious activity; targeted WordPress paths (wlwmanifest.xml, xmlrpc.php); browser impersonation. | 1.0 | severity: Severity.critical | e84ca538-5329-4737-8cd4-c200a69055c9 |
| 205.169.39.4 | ip | 2025-07-22 14:15:51 | block | Critical malicious activity; high flagged requests, triggered IP blocking by burst. | 0.8999999761581421 | severity: Severity.critical | 5a7734d1-e9dd-4812-afaf-accc35d4eb58 |
| 3.92.177.104 | ip | 2025-07-22 14:15:51 | block | Critical malicious activity; targeting WordPress wlwmanifest.xml and xmlrpc.php; WAF IPBLOCK. | 1.0 | severity: Severity.critical | b9fadeac-9a99-4c8d-b329-57a4c0a2d481 |
| 2604:a880:400:d1:0:1:4cea:4001 | ip | 2025-07-22 14:15:51 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 278fdcba-8a8a-4c83-a376-d37c20e83710 |
| 34.116.246.85 | ip | 2025-07-22 14:15:51 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 8c9ae187-516d-4f37-a994-e08eca11eb6e |
| 34.116.172.61 | ip | 2025-07-22 14:15:51 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 7f52bf56-9cbf-48c3-b0a7-60886e5f9b6d |