Table: Security_events
Displaying rows 97101 - 97150 of 120479 (Page 1943 / 2410)
| Entity | Type | Event time | Action taken | Ai reason | Ai confidence score | Ai details | Event id |
|---|---|---|---|---|---|---|---|
| 185.177.72.12 | ip | 2025-07-22 13:55:36 | block | Critical malicious reconnaissance for sensitive app configs/creds; LFI attempts. | 1.0 | severity: Severity.critical | ef48f71d-a03a-4b00-83c8-420397f88e83 |
| 185.177.72.11 | ip | 2025-07-22 13:55:36 | block | Critical malicious activity; targeting sensitive credentials, env files, server info. | 1.0 | severity: Severity.critical | b1447254-9bb9-4430-bcd0-34d882e3d49b |
| 185.177.72.3 | ip | 2025-07-22 13:55:36 | block | Critical malicious activity; targeting sensitive creds/config files; LFI anomalies; AS211590 related. | 1.0 | severity: Severity.critical | c6199a94-80a8-42c7-8d36-13f9bd571b6b |
| 185.177.72.205 | ip | 2025-07-22 13:55:36 | block | Critical malicious activity; attempting cloud creds, env files, config access; LFI. | 1.0 | severity: Severity.critical | 43856558-7f20-4123-bb55-aa7c125357a8 |
| 185.177.72.204 | ip | 2025-07-22 13:55:36 | block | Critical malicious activity; scanning for config files and source code repos. | 1.0 | severity: Severity.critical | 9c91b721-7ecc-495e-a6a0-9e933eba8b6b |
| 185.177.72.2 | ip | 2025-07-22 13:55:36 | block | Critical malicious activity; targeting sensitive config files; browser impersonation; AS211590 related. | 1.0 | severity: Severity.critical | 0ebc6e2c-1f59-4868-a6a6-daeee85be43d |
| 195.178.110.161 | ip | 2025-07-22 13:55:36 | block | Critical malicious activity; scanning for sensitive JS config, JSON creds, env vars; browser impersonation. | 0.8999999761581421 | severity: Severity.critical | b1038d12-ce1f-45f8-92e1-17c7399359f7 |
| 194.50.16.252 | ip | 2025-07-22 13:55:36 | block | Critical malicious activity; targeting Spring Boot Actuator with command injection attempts. | 1.0 | severity: Severity.critical | 46d25b22-c659-4a80-bf76-dd6bc4c75c7f |
| 2001:4878:8216:510:dddd:b98a:3a76:296c | ip | 2025-07-22 13:55:36 | block | Critical malicious activity; accessed obfuscated path linked to prior critical activity. | 0.949999988079071 | severity: Severity.critical | 3980b8ee-985d-4a0b-aa6b-f3aaef0e7e7d |
| 20.171.207.158 | ip | 2025-07-22 13:55:36 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 37c50273-55d6-4e0e-9603-f0e6ae2491e3 |
| 205.169.39.130 | ip | 2025-07-22 13:55:36 | block | Critical malicious activity; triggered IP blocking due to burst activity. | 0.8999999761581421 | severity: Severity.critical | ad48fce8-e74d-4c4c-b348-3b56e75e756d |
| 2001:bc8:1f90:4:7ec2:55ff:fe9e:8476 | ip | 2025-07-22 13:55:36 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | f251d39e-f2e8-4878-a734-9f8f7584587f |
| 2001:bc8:1201:19:46a8:42ff:fe1b:ae29 | ip | 2025-07-22 13:55:36 | block | Persistent medium malicious activity; all requests flagged by WAF. | 0.8500000238418579 | severity: Severity.medium | 1a3f8e65-3214-4f72-a3be-7f3c46df8962 |
| 216.126.227.20 | ip | 2025-07-22 13:55:36 | block | Critical malicious activity; targeted WordPress paths (wlwmanifest.xml, xmlrpc.php); browser impersonation. | 1.0 | severity: Severity.critical | 3dc4ac59-0c62-495e-a864-075aff7f65d4 |
| 205.169.39.4 | ip | 2025-07-22 13:55:36 | block | Critical malicious activity; high flagged requests, triggered IP blocking by burst. | 0.8999999761581421 | severity: Severity.critical | 507bf89b-d9ca-45f2-baf1-df1be55428de |
| 3.92.177.104 | ip | 2025-07-22 13:55:36 | block | Critical malicious activity; targeting WordPress wlwmanifest.xml and xmlrpc.php; WAF IPBLOCK. | 1.0 | severity: Severity.critical | b8a4b95f-d906-4c0a-bc9e-0082084d3f89 |
| 2604:a880:400:d1:0:1:4cea:4001 | ip | 2025-07-22 13:55:36 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | bcbfcf99-2f33-42b9-aeb8-5721b37146a1 |
| 34.116.246.85 | ip | 2025-07-22 13:55:36 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | c772efd9-b20c-44ba-8bbc-4ed8f6737ad1 |
| 34.116.172.61 | ip | 2025-07-22 13:55:36 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 26852b18-0ff9-4fd9-90c6-c9fb04285510 |
| 66.249.77.104 | ip | 2025-07-22 13:55:36 | block | Critical malicious activity; all requests flagged by WAF and security alerts. | 0.949999988079071 | severity: Severity.critical | 5a22af56-3d9e-4615-9d67-f70d0afc7ef1 |
| 66.249.68.133 | ip | 2025-07-22 13:55:36 | block | Persistent medium malicious scanning; all requests flagged by WAF (100% threat detection). | 0.8999999761581421 | severity: Severity.medium | 6b0e51eb-36bf-48cf-a454-9b996708329f |
| 51.38.105.105 | ip | 2025-07-22 13:55:36 | block | Critical malicious activity; extensive scanning for sensitive files/PHP info; browser impersonation. | 0.8999999761581421 | severity: Severity.critical | c33758ef-d51a-4d97-aed3-2c50c0690ea3 |
| AS211590 | asn | 2025-07-22 13:55:36 | block | Critical malicious activity; 100% threat detection targeting sensitive files/creds/LFI. | 1.0 | severity: Severity.critical | fa25c6cc-bdf4-4918-b1f1-81919a4a61b8 |
| AS16276 | asn | 2025-07-22 13:55:36 | block | Critical malicious activity; aggregated traffic with high threat detection, diverse malicious activities. | 1.0 | severity: Severity.critical | 7427f7a8-1fda-4630-89e4-6a1802e859dd |
| AS132203 | asn | 2025-07-22 13:55:36 | block | Critical malicious activity; high volume 100% flagged requests targeting WordPress; obfuscated paths. | 0.8999999761581421 | severity: Severity.critical | 39063889-73f7-4966-8d58-460381a06cac |
| 3%7e7bcf51bfc0d0b65f | tls | 2025-07-22 13:55:36 | block | Critical malicious activity; extensive reconnaissance for sensitive app configs/creds; LFI attempts. | 1.0 | severity: Severity.critical | 06c750a2-025e-4d77-94a8-6bba931d720d |
| 3%7e2faa3a9db1c111de | tls | 2025-07-22 13:55:36 | block | Critical malicious activity; high volume 100% flagged requests targeting WordPress/sensitive configs/obfuscated paths. | 1.0 | severity: Severity.critical | 2ba52fba-d4af-4c3c-a88b-94539badbfb0 |
| 3%7ede29393936a8dc4153 | tls | 2025-07-22 13:55:36 | block | Critical malicious activity; all requests flagged by WAF; targeting WordPress endpoints; obfuscated paths; browser impersonation. | 0.949999988079071 | severity: Severity.critical | 7155c919-f148-43b9-8b10-a1c4fdf13b4d |
| 3%7ede293936a8dc4153 | tls | 2025-07-22 13:55:36 | block | Critical malicious activity; all requests flagged by WAF; targeting WordPress endpoints; obfuscated paths; browser impersonation. | 0.949999988079071 | severity: Severity.critical | 9042f970-0658-4c6a-9760-ebe06c1adf7c |
| 3%7ebaae1457ad64ff16 | tls | 2025-07-22 13:55:36 | block | Critical malicious activity; all requests flagged by WAF; obfuscated paths; reconnaissance. | 0.8999999761581421 | severity: Severity.critical | 9912d0bf-6e93-47d7-a733-af18eea042d8 |
| 3%7ea97fdb0b70d4a7b7 | tls | 2025-07-22 13:55:36 | block | Critical malicious activity; 100% flagged; aggressive scanning for sensitive files/creds/phpinfo; browser impersonation. | 0.9800000190734863 | severity: Severity.critical | 2ad68814-93f1-44bc-ad03-5976debda8dc |
| UNKNOWN | tls | 2025-07-22 13:55:36 | block | Critical malicious activity; comprehensive/aggressive attacks: sensitive file probing, WordPress exploits, web shell probing, LFI. | 1.0 | severity: Severity.critical | 82e9d1ae-9850-4b20-ae7f-495bb2126c51 |
| 3%7ee35ec11fcbea7346 | tls | 2025-07-22 13:55:36 | block | Critical malicious activity; very high flagged requests, obfuscated paths; triggered IP blocking by burst. | 0.8999999761581421 | severity: Severity.critical | 249d0e57-3d20-457d-8f6c-dbb6219b5731 |
| 157.180.49.118 | ip | 2025-07-22 13:55:35 | block | Persistent medium malicious probing; all requests flagged by WAF. | 0.8500000238418579 | severity: Severity.medium | 5f643014-8f2d-40b2-a0f4-e1aec54f197e |
| 123.6.49.50 | ip | 2025-07-22 13:55:35 | block | Critical malicious activity; all requests flagged by WAF with multiple rule hits. | 0.8999999761581421 | severity: Severity.critical | ed0ec08a-088d-45c0-b474-f51be418b4a8 |
| 103.207.148.148 | ip | 2025-07-22 13:55:35 | block | Critical malicious probing for sensitive config/env files; browser impersonation detected. | 0.949999988079071 | severity: Severity.critical | de2bb1a9-bd2d-4fe2-abef-4fe305cda687 |
| 101.55.81.36 | ip | 2025-07-22 13:55:35 | block | Persistent critical activity targeting sensitive files and web shell paths, indicating exploitation. | 1.0 | severity: Severity.critical | f93e2411-4953-4520-b931-31ef075b696c |
| 157.180.49.118 | ip | 2025-07-22 13:50:33 | block | Persistent medium malicious probing; all requests flagged by WAF. | 0.8500000238418579 | severity: Severity.medium | 2a0ec4c9-f19f-4d49-9f8c-555e0628bda9 |
| 123.6.49.50 | ip | 2025-07-22 13:50:33 | block | Critical malicious activity; all requests flagged by WAF with multiple rule hits. | 0.8999999761581421 | severity: Severity.critical | 1c8f5d83-9b72-40bd-aebc-3c22201b5a4e |
| 103.207.148.148 | ip | 2025-07-22 13:50:33 | block | Critical malicious probing for sensitive config/env files; browser impersonation detected. | 0.949999988079071 | severity: Severity.critical | f4763d95-2d81-4aaa-b412-f20fbca4f708 |
| 101.55.81.36 | ip | 2025-07-22 13:50:33 | block | Persistent critical activity targeting sensitive files and web shell paths, indicating exploitation. | 1.0 | severity: Severity.critical | 1217516e-f062-43f2-b119-f2a8040b1106 |
| 185.177.72.104 | ip | 2025-07-22 13:50:33 | block | Critical malicious activity; aggressive scanning for .env, phpinfo, .git files. | 1.0 | severity: Severity.critical | df6e0d25-7eaf-403b-83ff-8aff2d82ad3b |
| 178.33.134.25 | ip | 2025-07-22 13:50:33 | block | Critical malicious activity; scanning common directories with browser impersonation. | 0.8999999761581421 | severity: Severity.critical | 473ad967-ea6a-420a-ab0e-6cce1cd1d75b |
| 185.177.72.144 | ip | 2025-07-22 13:50:33 | block | Critical malicious activity; widespread probing for sensitive files/LFI; AS211590 related. | 1.0 | severity: Severity.critical | 10f18ec7-effe-415a-9c63-bb7cca0b4ed6 |
| 185.177.72.12 | ip | 2025-07-22 13:50:33 | block | Critical malicious reconnaissance for sensitive app configs/creds; LFI attempts. | 1.0 | severity: Severity.critical | b4c7d383-b756-466e-b6d3-5482c647d9c1 |
| 185.177.72.11 | ip | 2025-07-22 13:50:33 | block | Critical malicious activity; targeting sensitive credentials, env files, server info. | 1.0 | severity: Severity.critical | fb73f4da-985d-487c-a11b-956174330cdd |
| 185.177.72.3 | ip | 2025-07-22 13:50:33 | block | Critical malicious activity; targeting sensitive creds/config files; LFI anomalies; AS211590 related. | 1.0 | severity: Severity.critical | 7cca2857-8b7f-4a34-8162-41bc0d328401 |
| 185.177.72.205 | ip | 2025-07-22 13:50:33 | block | Critical malicious activity; attempting cloud creds, env files, config access; LFI. | 1.0 | severity: Severity.critical | 28e5b68c-8820-4ea8-b3c5-4361c3476cbf |
| 185.177.72.204 | ip | 2025-07-22 13:50:33 | block | Critical malicious activity; scanning for config files and source code repos. | 1.0 | severity: Severity.critical | 99ff8a9c-2cc3-492e-bf28-3192b081a698 |
| 185.177.72.2 | ip | 2025-07-22 13:50:33 | block | Critical malicious activity; targeting sensitive config files; browser impersonation; AS211590 related. | 1.0 | severity: Severity.critical | 5b896da3-8ffc-4fbb-9264-b33e298bff2e |