Table: Security_events
Displaying rows 97151 - 97200 of 120479 (Page 1944 / 2410)
| Entity | Type | Event time | Action taken | Ai reason | Ai confidence score | Ai details | Event id |
|---|---|---|---|---|---|---|---|
| 195.178.110.161 | ip | 2025-07-22 13:50:33 | block | Critical malicious activity; scanning for sensitive JS config, JSON creds, env vars; browser impersonation. | 0.8999999761581421 | severity: Severity.critical | 3a832120-ba03-4706-97fc-47a3ae0d6144 |
| 194.50.16.252 | ip | 2025-07-22 13:50:33 | block | Critical malicious activity; targeting Spring Boot Actuator with command injection attempts. | 1.0 | severity: Severity.critical | 911ac064-4eda-428d-b1ba-70db7084aaa0 |
| 2001:4878:8216:510:dddd:b98a:3a76:296c | ip | 2025-07-22 13:50:33 | block | Critical malicious activity; accessed obfuscated path linked to prior critical activity. | 0.949999988079071 | severity: Severity.critical | 674b390c-a458-4732-b028-22a86b9dd402 |
| 20.171.207.158 | ip | 2025-07-22 13:50:33 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 1a1c4ae0-1d44-4347-85eb-20c5cf5546b9 |
| 205.169.39.130 | ip | 2025-07-22 13:50:33 | block | Critical malicious activity; triggered IP blocking due to burst activity. | 0.8999999761581421 | severity: Severity.critical | b0ac84b5-abb7-45ed-9a94-dd1f7d1da43d |
| 2001:bc8:1f90:4:7ec2:55ff:fe9e:8476 | ip | 2025-07-22 13:50:33 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 141a690b-3889-47a2-ba0d-fe0c8a03c929 |
| 2001:bc8:1201:19:46a8:42ff:fe1b:ae29 | ip | 2025-07-22 13:50:33 | block | Persistent medium malicious activity; all requests flagged by WAF. | 0.8500000238418579 | severity: Severity.medium | 2e206263-4b94-486d-97eb-9c6d5d9edbde |
| 216.126.227.20 | ip | 2025-07-22 13:50:33 | block | Critical malicious activity; targeted WordPress paths (wlwmanifest.xml, xmlrpc.php); browser impersonation. | 1.0 | severity: Severity.critical | 5347120e-5e86-4533-9ebb-27459c1b77a3 |
| 205.169.39.4 | ip | 2025-07-22 13:50:33 | block | Critical malicious activity; high flagged requests, triggered IP blocking by burst. | 0.8999999761581421 | severity: Severity.critical | d5ecb150-bcbf-47ce-8e83-108e35bcec07 |
| 3.92.177.104 | ip | 2025-07-22 13:50:33 | block | Critical malicious activity; targeting WordPress wlwmanifest.xml and xmlrpc.php; WAF IPBLOCK. | 1.0 | severity: Severity.critical | e215875d-93ce-466e-8d17-efcaa2ab115c |
| 2604:a880:400:d1:0:1:4cea:4001 | ip | 2025-07-22 13:50:33 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 9f19fd08-39ad-4afc-8265-f7034b895ba5 |
| 34.116.246.85 | ip | 2025-07-22 13:50:33 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | f9146f66-55d9-4795-8b02-2ca585f9dfd7 |
| 34.116.172.61 | ip | 2025-07-22 13:50:33 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | d8705981-f688-4fea-bb0d-fbd9a9cdcdff |
| 66.249.77.104 | ip | 2025-07-22 13:50:33 | block | Critical malicious activity; all requests flagged by WAF and security alerts. | 0.949999988079071 | severity: Severity.critical | 8f430946-2558-4954-9584-d75371c4fce3 |
| 66.249.68.133 | ip | 2025-07-22 13:50:33 | block | Persistent medium malicious scanning; all requests flagged by WAF (100% threat detection). | 0.8999999761581421 | severity: Severity.medium | c5a06812-2708-46bd-8839-6fc29b988497 |
| 51.38.105.105 | ip | 2025-07-22 13:50:33 | block | Critical malicious activity; extensive scanning for sensitive files/PHP info; browser impersonation. | 0.8999999761581421 | severity: Severity.critical | 5e78d063-f986-4d46-9870-d93302d75235 |
| AS211590 | asn | 2025-07-22 13:50:33 | block | Critical malicious activity; 100% threat detection targeting sensitive files/creds/LFI. | 1.0 | severity: Severity.critical | 2bb810a6-4051-4792-8c03-08623abb690f |
| AS16276 | asn | 2025-07-22 13:50:33 | block | Critical malicious activity; aggregated traffic with high threat detection, diverse malicious activities. | 1.0 | severity: Severity.critical | 71535b25-3884-47c3-a20f-ae121f24a96c |
| AS132203 | asn | 2025-07-22 13:50:33 | block | Critical malicious activity; high volume 100% flagged requests targeting WordPress; obfuscated paths. | 0.8999999761581421 | severity: Severity.critical | f305f03c-409b-4840-86b0-838401f192d4 |
| 3%7e7bcf51bfc0d0b65f | tls | 2025-07-22 13:50:33 | block | Critical malicious activity; extensive reconnaissance for sensitive app configs/creds; LFI attempts. | 1.0 | severity: Severity.critical | 28a980e8-52e3-4293-84d7-3b7ac59ba14a |
| 3%7e2faa3a9db1c111de | tls | 2025-07-22 13:50:33 | block | Critical malicious activity; high volume 100% flagged requests targeting WordPress/sensitive configs/obfuscated paths. | 1.0 | severity: Severity.critical | 421fbf07-37a5-4798-9cc3-89311ab9398c |
| 3%7ede29393936a8dc4153 | tls | 2025-07-22 13:50:33 | block | Critical malicious activity; all requests flagged by WAF; targeting WordPress endpoints; obfuscated paths; browser impersonation. | 0.949999988079071 | severity: Severity.critical | 301396f9-f063-479c-ab4a-16161b81e79b |
| 3%7ede293936a8dc4153 | tls | 2025-07-22 13:50:33 | block | Critical malicious activity; all requests flagged by WAF; targeting WordPress endpoints; obfuscated paths; browser impersonation. | 0.949999988079071 | severity: Severity.critical | ee70bd1a-c11f-4e9b-b251-e271865c06b8 |
| 3%7ebaae1457ad64ff16 | tls | 2025-07-22 13:50:33 | block | Critical malicious activity; all requests flagged by WAF; obfuscated paths; reconnaissance. | 0.8999999761581421 | severity: Severity.critical | 33309f32-4777-40dc-8794-4eb17de9c99f |
| 3%7ea97fdb0b70d4a7b7 | tls | 2025-07-22 13:50:33 | block | Critical malicious activity; 100% flagged; aggressive scanning for sensitive files/creds/phpinfo; browser impersonation. | 0.9800000190734863 | severity: Severity.critical | 105b71d4-00ec-421a-b0cf-c88b7610eaea |
| UNKNOWN | tls | 2025-07-22 13:50:33 | block | Critical malicious activity; comprehensive/aggressive attacks: sensitive file probing, WordPress exploits, web shell probing, LFI. | 1.0 | severity: Severity.critical | 4d742b72-429e-4b58-8ccf-380aa4e26e9a |
| 3%7ee35ec11fcbea7346 | tls | 2025-07-22 13:50:33 | block | Critical malicious activity; very high flagged requests, obfuscated paths; triggered IP blocking by burst. | 0.8999999761581421 | severity: Severity.critical | fb2c6da2-aed9-4157-8c59-f9588c3732a8 |
| 157.180.49.118 | ip | 2025-07-22 13:35:38 | block | Persistent medium malicious probing; all requests flagged by WAF. | 0.8500000238418579 | severity: Severity.medium | a67e68b7-ffb3-4df3-87c7-439456bc0d19 |
| 123.6.49.50 | ip | 2025-07-22 13:35:38 | block | Critical malicious activity; all requests flagged by WAF with multiple rule hits. | 0.8999999761581421 | severity: Severity.critical | 030b3edf-91b6-49bc-9ecd-9b7544921282 |
| 103.207.148.148 | ip | 2025-07-22 13:35:38 | block | Critical malicious probing for sensitive config/env files; browser impersonation detected. | 0.949999988079071 | severity: Severity.critical | ed40d945-80cc-4155-9dd8-c9cd9739254b |
| 101.55.81.36 | ip | 2025-07-22 13:35:38 | block | Persistent critical activity targeting sensitive files and web shell paths, indicating exploitation. | 1.0 | severity: Severity.critical | bad7fb47-8527-4f0e-9463-1c4df53e2c84 |
| 185.177.72.104 | ip | 2025-07-22 13:35:38 | block | Critical malicious activity; aggressive scanning for .env, phpinfo, .git files. | 1.0 | severity: Severity.critical | 3353c9a4-cc98-430c-a123-2afbd9912d82 |
| 178.33.134.25 | ip | 2025-07-22 13:35:38 | block | Critical malicious activity; scanning common directories with browser impersonation. | 0.8999999761581421 | severity: Severity.critical | 0b13d34d-b4e2-4f02-ab02-61313951826f |
| 185.177.72.144 | ip | 2025-07-22 13:35:38 | block | Critical malicious activity; widespread probing for sensitive files/LFI; AS211590 related. | 1.0 | severity: Severity.critical | f4f5aaef-1442-4a16-83b4-32b472c911d7 |
| 185.177.72.12 | ip | 2025-07-22 13:35:38 | block | Critical malicious reconnaissance for sensitive app configs/creds; LFI attempts. | 1.0 | severity: Severity.critical | 6610f04e-0d5d-4651-9d51-5d4209849528 |
| 185.177.72.11 | ip | 2025-07-22 13:35:38 | block | Critical malicious activity; targeting sensitive credentials, env files, server info. | 1.0 | severity: Severity.critical | c36da2d5-7b0d-47c9-bec3-24778e762164 |
| 185.177.72.3 | ip | 2025-07-22 13:35:38 | block | Critical malicious activity; targeting sensitive creds/config files; LFI anomalies; AS211590 related. | 1.0 | severity: Severity.critical | 9a2f21f0-79cb-4657-b20c-a48e1e6dcdcc |
| 185.177.72.205 | ip | 2025-07-22 13:35:38 | block | Critical malicious activity; attempting cloud creds, env files, config access; LFI. | 1.0 | severity: Severity.critical | 26ef60c4-3815-40cf-9cae-70685ff75f85 |
| 185.177.72.204 | ip | 2025-07-22 13:35:38 | block | Critical malicious activity; scanning for config files and source code repos. | 1.0 | severity: Severity.critical | afb58d2b-7ad6-4547-b015-cd6eda0f61e0 |
| 185.177.72.2 | ip | 2025-07-22 13:35:38 | block | Critical malicious activity; targeting sensitive config files; browser impersonation; AS211590 related. | 1.0 | severity: Severity.critical | 22962064-60d1-4a93-84dd-f248c574828e |
| 195.178.110.161 | ip | 2025-07-22 13:35:38 | block | Critical malicious activity; scanning for sensitive JS config, JSON creds, env vars; browser impersonation. | 0.8999999761581421 | severity: Severity.critical | a6124072-644e-43d6-8152-ddcb355ed087 |
| 194.50.16.252 | ip | 2025-07-22 13:35:38 | block | Critical malicious activity; targeting Spring Boot Actuator with command injection attempts. | 1.0 | severity: Severity.critical | 8058485d-6f09-4285-ab81-e3fc882075fb |
| 2001:4878:8216:510:dddd:b98a:3a76:296c | ip | 2025-07-22 13:35:38 | block | Critical malicious activity; accessed obfuscated path linked to prior critical activity. | 0.949999988079071 | severity: Severity.critical | d77616ac-072f-4e75-a3f9-56c466ced9b8 |
| 20.171.207.158 | ip | 2025-07-22 13:35:38 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 6ff2fbf2-f0e2-4860-adcf-2db58b9e4df6 |
| 205.169.39.130 | ip | 2025-07-22 13:35:38 | block | Critical malicious activity; triggered IP blocking due to burst activity. | 0.8999999761581421 | severity: Severity.critical | 3bdceea0-5833-4a1d-80b9-669ad243edb7 |
| 2001:bc8:1f90:4:7ec2:55ff:fe9e:8476 | ip | 2025-07-22 13:35:38 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 733ad280-494c-41cd-89c0-a549358b7356 |
| 2001:bc8:1201:19:46a8:42ff:fe1b:ae29 | ip | 2025-07-22 13:35:38 | block | Persistent medium malicious activity; all requests flagged by WAF. | 0.8500000238418579 | severity: Severity.medium | 9c9cbadc-6f79-416d-bd39-84be569fd545 |
| 216.126.227.20 | ip | 2025-07-22 13:35:38 | block | Critical malicious activity; targeted WordPress paths (wlwmanifest.xml, xmlrpc.php); browser impersonation. | 1.0 | severity: Severity.critical | 445faed1-91e5-4e5b-8040-5e008686dfbc |
| 205.169.39.4 | ip | 2025-07-22 13:35:38 | block | Critical malicious activity; high flagged requests, triggered IP blocking by burst. | 0.8999999761581421 | severity: Severity.critical | 96370dfd-f186-4f3d-825f-0f2bdabacddd |
| 3.92.177.104 | ip | 2025-07-22 13:35:38 | block | Critical malicious activity; targeting WordPress wlwmanifest.xml and xmlrpc.php; WAF IPBLOCK. | 1.0 | severity: Severity.critical | 40ad57a6-245c-40c8-83db-6af7f59813c7 |