Table: Security_events
Displaying rows 97201 - 97250 of 120479 (Page 1945 / 2410)
| Entity | Type | Event time | Action taken | Ai reason | Ai confidence score | Ai details | Event id |
|---|---|---|---|---|---|---|---|
| 2604:a880:400:d1:0:1:4cea:4001 | ip | 2025-07-22 13:35:38 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | eb728ef4-1032-4436-ae2e-907ce63ac00c |
| 34.116.246.85 | ip | 2025-07-22 13:35:38 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 0b80869e-f5ff-4417-b66e-096b980d1afa |
| 34.116.172.61 | ip | 2025-07-22 13:35:38 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | a6980aab-7480-48ba-b8f8-cdabedbd53bc |
| 66.249.77.104 | ip | 2025-07-22 13:35:38 | block | Critical malicious activity; all requests flagged by WAF and security alerts. | 0.949999988079071 | severity: Severity.critical | 9bf3289f-6172-44f1-838b-a44cd725daa3 |
| 66.249.68.133 | ip | 2025-07-22 13:35:38 | block | Persistent medium malicious scanning; all requests flagged by WAF (100% threat detection). | 0.8999999761581421 | severity: Severity.medium | 93f3d91f-5873-4f28-a578-ecebc6f30e8f |
| 51.38.105.105 | ip | 2025-07-22 13:35:38 | block | Critical malicious activity; extensive scanning for sensitive files/PHP info; browser impersonation. | 0.8999999761581421 | severity: Severity.critical | 3befd69a-2f14-4434-9faf-e0879cd8ab60 |
| AS211590 | asn | 2025-07-22 13:35:38 | block | Critical malicious activity; 100% threat detection targeting sensitive files/creds/LFI. | 1.0 | severity: Severity.critical | 9f8a8478-3f0f-48cb-bf1f-64c219ab3f24 |
| AS16276 | asn | 2025-07-22 13:35:38 | block | Critical malicious activity; aggregated traffic with high threat detection, diverse malicious activities. | 1.0 | severity: Severity.critical | fde19d18-c464-49a7-8dde-6be6f95fc622 |
| AS132203 | asn | 2025-07-22 13:35:38 | block | Critical malicious activity; high volume 100% flagged requests targeting WordPress; obfuscated paths. | 0.8999999761581421 | severity: Severity.critical | ecd48df5-a377-4cb5-9a93-9922fc0d1ab6 |
| 3%7e7bcf51bfc0d0b65f | tls | 2025-07-22 13:35:38 | block | Critical malicious activity; extensive reconnaissance for sensitive app configs/creds; LFI attempts. | 1.0 | severity: Severity.critical | b35bd30b-501f-4996-84a6-99f27ab955eb |
| 3%7e2faa3a9db1c111de | tls | 2025-07-22 13:35:38 | block | Critical malicious activity; high volume 100% flagged requests targeting WordPress/sensitive configs/obfuscated paths. | 1.0 | severity: Severity.critical | fdad5667-ed5c-4a79-90dc-363452a33187 |
| 3%7ede29393936a8dc4153 | tls | 2025-07-22 13:35:38 | block | Critical malicious activity; all requests flagged by WAF; targeting WordPress endpoints; obfuscated paths; browser impersonation. | 0.949999988079071 | severity: Severity.critical | 278fd343-4b05-4f15-b8b1-1204a9447311 |
| 3%7ede293936a8dc4153 | tls | 2025-07-22 13:35:38 | block | Critical malicious activity; all requests flagged by WAF; targeting WordPress endpoints; obfuscated paths; browser impersonation. | 0.949999988079071 | severity: Severity.critical | deda3d44-c82d-4aca-919d-c1c856e6052f |
| 3%7ebaae1457ad64ff16 | tls | 2025-07-22 13:35:38 | block | Critical malicious activity; all requests flagged by WAF; obfuscated paths; reconnaissance. | 0.8999999761581421 | severity: Severity.critical | 492ae527-8f17-4b2e-940a-b03412fea02b |
| 3%7ea97fdb0b70d4a7b7 | tls | 2025-07-22 13:35:38 | block | Critical malicious activity; 100% flagged; aggressive scanning for sensitive files/creds/phpinfo; browser impersonation. | 0.9800000190734863 | severity: Severity.critical | 3bb68527-2eca-49ec-9c1e-bf5a1bbcc23e |
| UNKNOWN | tls | 2025-07-22 13:35:38 | block | Critical malicious activity; comprehensive/aggressive attacks: sensitive file probing, WordPress exploits, web shell probing, LFI. | 1.0 | severity: Severity.critical | 42e680ff-cec7-4138-aabb-cf2c533c9272 |
| 3%7ee35ec11fcbea7346 | tls | 2025-07-22 13:35:38 | block | Critical malicious activity; very high flagged requests, obfuscated paths; triggered IP blocking by burst. | 0.8999999761581421 | severity: Severity.critical | 54eb5122-507c-4b96-86ae-6121bbb18795 |
| 157.180.49.118 | ip | 2025-07-22 13:30:33 | block | Persistent medium malicious probing; all requests flagged by WAF. | 0.8500000238418579 | severity: Severity.medium | fa88ec9a-380c-4734-a2da-a28e9d49512e |
| 123.6.49.50 | ip | 2025-07-22 13:30:33 | block | Critical malicious activity; all requests flagged by WAF with multiple rule hits. | 0.8999999761581421 | severity: Severity.critical | 7921bc81-78f5-4ea3-8fa7-ee3f699e89d1 |
| 185.177.72.104 | ip | 2025-07-22 13:30:33 | block | Critical malicious activity; aggressive scanning for .env, phpinfo, .git files. | 1.0 | severity: Severity.critical | 8c6698f2-2c5f-4989-8867-cc5ac0747b77 |
| 178.33.134.25 | ip | 2025-07-22 13:30:33 | block | Critical malicious activity; scanning common directories with browser impersonation. | 0.8999999761581421 | severity: Severity.critical | dd928be6-8aaa-4007-ba91-bead6939172c |
| 185.177.72.144 | ip | 2025-07-22 13:30:33 | block | Critical malicious activity; widespread probing for sensitive files/LFI; AS211590 related. | 1.0 | severity: Severity.critical | 195328fd-1881-486d-ab55-72d73b859e45 |
| 185.177.72.12 | ip | 2025-07-22 13:30:33 | block | Critical malicious reconnaissance for sensitive app configs/creds; LFI attempts. | 1.0 | severity: Severity.critical | 27cc2e54-7da2-4b56-8aca-5ed672358494 |
| 185.177.72.11 | ip | 2025-07-22 13:30:33 | block | Critical malicious activity; targeting sensitive credentials, env files, server info. | 1.0 | severity: Severity.critical | b56f8e91-1922-433b-808a-cf311fe9e2ac |
| 185.177.72.3 | ip | 2025-07-22 13:30:33 | block | Critical malicious activity; targeting sensitive creds/config files; LFI anomalies; AS211590 related. | 1.0 | severity: Severity.critical | d2796970-1af8-461e-b1d4-958c21f1584c |
| 185.177.72.205 | ip | 2025-07-22 13:30:33 | block | Critical malicious activity; attempting cloud creds, env files, config access; LFI. | 1.0 | severity: Severity.critical | 6b22f093-b102-435a-bb68-8cb489fd91dc |
| 185.177.72.204 | ip | 2025-07-22 13:30:33 | block | Critical malicious activity; scanning for config files and source code repos. | 1.0 | severity: Severity.critical | 72cc8345-ca6b-4520-b62c-826596998215 |
| 185.177.72.2 | ip | 2025-07-22 13:30:33 | block | Critical malicious activity; targeting sensitive config files; browser impersonation; AS211590 related. | 1.0 | severity: Severity.critical | 4fe4be89-f9fa-4b2e-a017-dd73323c76cb |
| 195.178.110.161 | ip | 2025-07-22 13:30:33 | block | Critical malicious activity; scanning for sensitive JS config, JSON creds, env vars; browser impersonation. | 0.8999999761581421 | severity: Severity.critical | 6c2a8a4c-505c-4aa1-9163-c5244198e9ac |
| 194.50.16.252 | ip | 2025-07-22 13:30:33 | block | Critical malicious activity; targeting Spring Boot Actuator with command injection attempts. | 1.0 | severity: Severity.critical | 9003e821-9686-4481-86ba-5f76f55cba91 |
| 2001:4878:8216:510:dddd:b98a:3a76:296c | ip | 2025-07-22 13:30:33 | block | Critical malicious activity; accessed obfuscated path linked to prior critical activity. | 0.949999988079071 | severity: Severity.critical | 7b0cb6dc-6c08-4d3b-81c8-f295b59e9f3f |
| 20.171.207.158 | ip | 2025-07-22 13:30:33 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 57f4d6e7-59e1-4ee2-9333-3aeee8d8f606 |
| 205.169.39.130 | ip | 2025-07-22 13:30:33 | block | Critical malicious activity; triggered IP blocking due to burst activity. | 0.8999999761581421 | severity: Severity.critical | 1c3c8442-e304-4654-8b85-b9fa4943190f |
| 2001:bc8:1f90:4:7ec2:55ff:fe9e:8476 | ip | 2025-07-22 13:30:33 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 72028ef1-1777-4306-9019-b1e38062891c |
| 2001:bc8:1201:19:46a8:42ff:fe1b:ae29 | ip | 2025-07-22 13:30:33 | block | Persistent medium malicious activity; all requests flagged by WAF. | 0.8500000238418579 | severity: Severity.medium | e6de1727-03bd-46b6-92dc-eb725272f0b3 |
| 216.126.227.20 | ip | 2025-07-22 13:30:33 | block | Critical malicious activity; targeted WordPress paths (wlwmanifest.xml, xmlrpc.php); browser impersonation. | 1.0 | severity: Severity.critical | c4167fe5-f16b-4254-9466-03e406d5f2f0 |
| 205.169.39.4 | ip | 2025-07-22 13:30:33 | block | Critical malicious activity; high flagged requests, triggered IP blocking by burst. | 0.8999999761581421 | severity: Severity.critical | 91252e1e-7f91-461b-be71-5b03df6c4d96 |
| 3.92.177.104 | ip | 2025-07-22 13:30:33 | block | Critical malicious activity; targeting WordPress wlwmanifest.xml and xmlrpc.php; WAF IPBLOCK. | 1.0 | severity: Severity.critical | 9d4623d8-3172-40a4-89f3-23a8616e5429 |
| 2604:a880:400:d1:0:1:4cea:4001 | ip | 2025-07-22 13:30:33 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 8dea1385-e486-42da-91a0-6d554144f371 |
| 34.116.246.85 | ip | 2025-07-22 13:30:33 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | bdf77ff8-a06c-4bc1-a68a-19aeee6edb6b |
| 34.116.172.61 | ip | 2025-07-22 13:30:33 | block | Persistent medium malicious activity; all requests flagged by WAF; obfuscated paths. | 0.8500000238418579 | severity: Severity.medium | 123a0857-3497-48fc-a322-766be950bcc7 |
| 66.249.77.104 | ip | 2025-07-22 13:30:33 | block | Critical malicious activity; all requests flagged by WAF and security alerts. | 0.949999988079071 | severity: Severity.critical | af21a61f-cbeb-4fac-9719-6c7c875266b2 |
| 66.249.68.133 | ip | 2025-07-22 13:30:33 | block | Persistent medium malicious scanning; all requests flagged by WAF (100% threat detection). | 0.8999999761581421 | severity: Severity.medium | 92a60ead-3ddb-49de-939b-5df68f31eb8e |
| 51.38.105.105 | ip | 2025-07-22 13:30:33 | block | Critical malicious activity; extensive scanning for sensitive files/PHP info; browser impersonation. | 0.8999999761581421 | severity: Severity.critical | 9dbf2ae7-b82b-41cc-ad33-1fb8175304d8 |
| AS211590 | asn | 2025-07-22 13:30:33 | block | Critical malicious activity; 100% threat detection targeting sensitive files/creds/LFI. | 1.0 | severity: Severity.critical | d9700f02-c602-4fc7-802c-ebbb6801d04d |
| AS16276 | asn | 2025-07-22 13:30:33 | block | Critical malicious activity; aggregated traffic with high threat detection, diverse malicious activities. | 1.0 | severity: Severity.critical | 212c3aba-4b91-43ee-bed8-bb32b96beaeb |
| AS132203 | asn | 2025-07-22 13:30:33 | block | Critical malicious activity; high volume 100% flagged requests targeting WordPress; obfuscated paths. | 0.8999999761581421 | severity: Severity.critical | 71736624-8022-4ce9-8ddb-39f308f5f143 |
| 3%7e7bcf51bfc0d0b65f | tls | 2025-07-22 13:30:33 | block | Critical malicious activity; extensive reconnaissance for sensitive app configs/creds; LFI attempts. | 1.0 | severity: Severity.critical | 171e7957-14c6-40e2-bb2d-002479cbf800 |
| 3%7e2faa3a9db1c111de | tls | 2025-07-22 13:30:33 | block | Critical malicious activity; high volume 100% flagged requests targeting WordPress/sensitive configs/obfuscated paths. | 1.0 | severity: Severity.critical | 3a19e004-9520-4ea1-9f24-f92be707eac5 |
| 3%7ede29393936a8dc4153 | tls | 2025-07-22 13:30:33 | block | Critical malicious activity; all requests flagged by WAF; targeting WordPress endpoints; obfuscated paths; browser impersonation. | 0.949999988079071 | severity: Severity.critical | 61ff961c-ad13-4f59-967d-f6aa06048573 |