System Note
$ cat /proc/ai-disclosure
本記事の構成および論理分析にはAI(人工知能)を使用しています。情報の正確性は、システム管理者(UNIXユーザー)による手動検証済みです。
* 当サイトでは、コンテンツの一部に広告を掲載しています。
本記事の構成および論理分析にはAI(人工知能)を使用しています。情報の正確性は、システム管理者(UNIXユーザー)による手動検証済みです。

2026年5月より、セキュリティ日報の掲載フォーマットを見直しました。これまでのインシデントログ中心の形式から、当日に新規隔離したIPと継続隔離中のIPを分かりやすく整理した、SOC運用向けの一覧形式へ変更しています。
新しい形式では、WHOIS情報、攻撃種別、遮断状況を中心に、必要な情報を簡潔に確認できる構成に統一しました。また、記事内では個別サイト名や内部運用向けの詳細パラメータは掲載せず、複数サイトにまたがるアクセスは「複数の管理環境」として表記する運用に変更しています。
この見直しにより、日々の観測傾向や継続的な不審アクセスの把握を、以前より短時間で確認しやすくなりました。
[2026-07-31 SOC運用向け]
### Jul 31, 2026 | 2 New IPs Quarantined
本日の新規隔離は 2 件でした。2026-07-31 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 5 件です。
本日新規隔離
- 20.104.22.47
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (5 hits across multiple environments)
- 34.23.178.20
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (2 hits)
継続隔離中
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 20.79.29.209
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and dangerous backup paths
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
common_security.txt 更新判断
- static deny 済み
- 20.79.29.209
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-07-31 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は .git/config 露出確認 1 件、不審 PHP 探索 1 件で、探索初動の整理が中心でした
- 20.104.22.47 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 5 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、20.79.29.209 は危険パスで 200 応答が確認されているため優先確認が必要です
[2026-07-30 SOC運用向け]
### Jul 30, 2026 | 3 New IPs Quarantined
本日の新規隔離は 3 件でした。2026-07-30 時点で当日日報内に再犯として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 20.104.22.47
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (5 hits across multiple environments)
- 34.23.178.20
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (2 hits)
- 4.225.166.222
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (112 hits)
継続隔離中
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-07-30 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 2 件、.git/config 露出確認 1 件で、探索初動の整理が中心でした
- 20.104.22.47 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、再出現の可能性がある
[2026-07-29 SOC運用向け]
### Jul 29, 2026 | 20 New IPs Quarantined
本日の新規隔離は 20 件でした。2026-07-29 時点で当日日報内に再犯として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 80.94.92.67
WHOIS Info: https://dmzhost.co, NL, Abuse Contact, Allocated
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (1 hits)
- 20.91.140.156
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (147 hits across multiple environments)
- 35.227.106.50
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for exposed backup, archive, and database dump files
Status: Blacklisted (2 hits)
- 18.202.218.25
WHOIS Info: Amazon (AWS), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (286 hits)
- 158.101.144.198
WHOIS Info: Oracle Corporation (ORACLE-4), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (2 hits)
- 20.203.135.57
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (259 hits)
- 172.202.44.182
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (4 hits across multiple environments)
- 20.151.221.234
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (14 hits across multiple environments)
- 172.213.8.106
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (366 hits)
- 158.158.32.229
WHOIS Info: Asia Pacific Network Information Centre (APNIC), AU, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (78 hits)
- 51.120.79.193
WHOIS Info: Microsoft Corporation (Azure), NO, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (156 hits)
- 20.79.250.162
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (131 hits)
- 80.94.92.167
WHOIS Info: https://dmzhost.co, NL, Abuse Contact, Allocated
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (2 hits across multiple environments)
- 20.100.173.28
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (258 hits)
- 3.149.2.121
WHOIS Info: Amazon (AWS), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (247 hits)
- 81.171.72.93
WHOIS Info: Unknown (Unresolved), DE, Abuse Contact, Allocated
Comment: [Fingerprinting] probing for exposed backup, archive, and database dump files
Status: Blacklisted (13 hits)
- 20.251.58.190
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (155 hits)
- 5.223.46.133
WHOIS Info: Hetzner Online GmbH, SG, Abuse Contact, Allocated
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (2 hits)
- 4.223.71.149
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (94 hits)
- 20.79.29.209
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (128 hits)
継続隔離中
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-07-29 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 12 件、.env 露出確認 3 件、.git/config 露出確認 3 件、バックアップ/DBダンプ探索 2 件で、探索初動の整理が中心でした
- 20.91.140.156 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、再出現の可能性がある
[2026-07-28 SOC運用向け]
### Jul 28, 2026 | 20 New IPs Quarantined
本日の新規隔離は 20 件でした。2026-07-28 時点で当日日報内に再犯として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 80.94.92.67
WHOIS Info: https://dmzhost.co, NL, Abuse Contact, Allocated
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (1 hits)
- 20.91.140.156
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (147 hits across multiple environments)
- 35.227.106.50
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for exposed backup, archive, and database dump files
Status: Blacklisted (2 hits)
- 18.202.218.25
WHOIS Info: Amazon (AWS), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (286 hits)
- 158.101.144.198
WHOIS Info: Oracle Corporation (ORACLE-4), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (2 hits)
- 20.203.135.57
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (259 hits)
- 172.202.44.182
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (4 hits across multiple environments)
- 20.151.221.234
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (14 hits across multiple environments)
- 172.213.8.106
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (366 hits)
- 158.158.32.229
WHOIS Info: Asia Pacific Network Information Centre (APNIC), AU, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (78 hits)
- 51.120.79.193
WHOIS Info: Microsoft Corporation (Azure), NO, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (156 hits)
- 20.79.250.162
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (131 hits)
- 80.94.92.167
WHOIS Info: https://dmzhost.co, NL, Abuse Contact, Allocated
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (2 hits across multiple environments)
- 20.100.173.28
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (258 hits)
- 3.149.2.121
WHOIS Info: Amazon (AWS), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (247 hits)
- 81.171.72.93
WHOIS Info: Unknown (Unresolved), DE, Abuse Contact, Allocated
Comment: [Fingerprinting] probing for exposed backup, archive, and database dump files
Status: Blacklisted (13 hits)
- 20.251.58.190
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (155 hits)
- 5.223.46.133
WHOIS Info: Hetzner Online GmbH, SG, Abuse Contact, Allocated
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (2 hits)
- 4.223.71.149
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (94 hits)
- 20.79.29.209
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (128 hits)
継続隔離中
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-07-28 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 12 件、.env 露出確認 3 件、.git/config 露出確認 3 件、バックアップ/DBダンプ探索 2 件で、探索初動の整理が中心でした
- 20.91.140.156 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、再出現の可能性がある
[2026-07-27 SOC運用向け]
### Jul 27, 2026 | 6 New IPs Quarantined
本日の新規隔離は 6 件でした。2026-07-27 時点で当日日報内に再犯として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 158.101.144.198
WHOIS Info: Oracle Corporation (ORACLE-4), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (2 hits)
- 20.203.135.57
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (259 hits)
- 172.213.8.106
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (244 hits)
- 5.223.46.133
WHOIS Info: Hetzner Online GmbH, SG, Abuse Contact, Allocated
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (2 hits)
- 4.223.71.149
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (94 hits)
- 20.79.29.209
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (128 hits)
継続隔離中
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-07-27 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 4 件、.env 露出確認 1 件、.git/config 露出確認 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、再出現の可能性がある
[2026-07-26 SOC運用向け]
### Jul 26, 2026 | 8 New IPs Quarantined
本日の新規隔離は 8 件でした。2026-07-26 時点で当日日報内に再犯として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 34.65.71.174
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (25 hits)
- 34.39.25.103
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (25 hits)
- 20.100.178.92
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (238 hits)
- 103.168.67.253
WHOIS Info: DiGiVPS.com, US, Abuse Contact, Allocated
Comment: [Fingerprinting] probing for exposed backup, archive, and database dump files
Status: Blacklisted (2 hits)
- 74.248.33.172
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Allocated
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (238 hits)
- 51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (125 hits)
- 196.250.200.4
WHOIS Info: WAW, SN, Unknown (Unresolved), Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (8 hits)
- 172.202.26.222
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (103 hits)
継続隔離中
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-07-26 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 4 件、.env 露出確認 3 件、バックアップ/DBダンプ探索 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、再出現の可能性がある
[2026-07-25 SOC運用向け]
### Jul 25, 2026 | 4 New IPs Quarantined
本日の新規隔離は 4 件でした。2026-07-25 時点で当日日報内に再犯として確認できた継続隔離中のIPは 3 件です。
本日新規隔離
- 20.100.203.84
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for file manager and backdoor plugin paths
Status: Blacklisted (2 hits)
- 51.107.70.126
WHOIS Info: Microsoft Corporation (Azure), EU, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (278 hits)
- 52.165.196.84
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (94 hits)
- 51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (139 hits)
継続隔離中
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
- 94.143.139.248
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-07-25 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 3 件、不審プラグイン探索 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 3 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、再出現の可能性がある
[2026-07-24 SOC運用向け]
### Jul 24, 2026 | 5 New IPs Quarantined
本日の新規隔離は 5 件でした。2026-07-24 時点で当日日報内に再犯として確認できた継続隔離中のIPは 3 件です。
本日新規隔離
- 20.226.83.28
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (279 hits)
- 94.143.231.161
WHOIS Info: dataforest GmbH, DE, Abuse Contact, Allocated
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (7 hits across multiple environments)
- 158.51.126.144
WHOIS Info: Hostodo (HL-658), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (25 hits)
- 20.203.219.190
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (148 hits)
- 34.145.166.183
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (1 hits)
継続隔離中
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
- 94.143.139.248
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-07-24 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は .env 露出確認 2 件、不審 PHP 探索 2 件、.git/config 露出確認 1 件で、探索初動の整理が中心でした
- 94.143.231.161 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 3 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、再出現の可能性がある
[2026-07-23 SOC運用向け]
### Jul 23, 2026 | 4 New IPs Quarantined
本日の新規隔離は 4 件でした。2026-07-23 時点で当日日報内に再犯として確認できた継続隔離中のIPは 3 件です。
本日新規隔離
- 203.25.124.74
WHOIS Info: Transferred to the RIPE region on 2020-09-24T09:24:29Z., ZZ, Abuse Contact, Allocated
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (167 hits)
- 172.202.100.37
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (244 hits)
- 20.100.176.141
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (32 hits)
- 20.10.203.190
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (99 hits)
継続隔離中
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
- 94.143.139.248
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-07-23 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 4 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 3 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、再出現の可能性がある
[2026-07-21 SOC運用向け]
### Jul 21, 2026 | 2 New IPs Quarantined
本日の新規隔離は 2 件でした。2026-07-21 時点で当日日報内に再犯として確認できた継続隔離中のIPは 3 件です。
本日新規隔離
- 35.190.144.148
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for exposed backup, archive, and database dump files
Status: Blacklisted (2 hits)
- 206.81.12.187
WHOIS Info: DigitalOcean, LLC, LLC, Abuse Contact, Abuse Contact, Digit19-Arin, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Blacklisted (5 hits)
継続隔離中
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
- 94.143.139.248
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-07-21 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は バックアップ/DBダンプ探索 1 件、認証系探索 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 3 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、再出現の可能性がある
[2026-07-20 SOC運用向け]
### Jul 20, 2026 | 4 New IPs Quarantined
本日の新規隔離は 4 件でした。2026-07-20 時点で当日日報内に再犯として確認できた継続隔離中のIPは 3 件です。
本日新規隔離
- 20.12.214.177
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (27 hits)
- 35.242.232.108
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (24 hits)
- 136.115.64.49
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (1 hits)
- 23.102.123.231
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Allocated
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (98 hits)
継続隔離中
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
- 94.143.139.248
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-07-20 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 2 件、.env 露出確認 1 件、.git/config 露出確認 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 3 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、再出現の可能性がある
[2026-07-18 SOC運用向け]
### Jul 18, 2026 | 18 New IPs Quarantined
本日の新規隔離は 18 件でした。2026-07-18 時点で当日日報内に再犯として確認できた継続隔離中のIPは 6 件です。
本日新規隔離
- 64.89.160.220
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Fingerprinting] probing for exposed backup, archive, and database dump files
Status: Blacklisted (14 hits across multiple environments)
- 91.148.245.81
WHOIS Info: Unknown (Unresolved), NL, Abuse Contact, Allocated
Comment: [Fingerprinting] probing for exposed backup, archive, and database dump files
Status: Blacklisted (13 hits)
- 159.89.12.166
WHOIS Info: DigitalOcean, LLC, LLC (DO-13), Abuse Contact, Digit19-Arin, Legacy
Comment: [Auth Attack] probing login and admin entry points
Status: Blacklisted (5 hits)
- 35.243.243.53
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (15 hits)
- 196.65.151.96
WHOIS Info: ADSL_Maroc_telecom, MA, Unknown (Unresolved), Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (2 hits)
- 31.56.58.124
WHOIS Info: Zkillu SAS, FR, Abuse Contact, Allocated
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (4 hits)
- 3.80.153.227
WHOIS Info: Amazon (AWS), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (2 hits)
- 34.174.112.118
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for exposed backup, archive, and database dump files
Status: Blacklisted (2 hits)
- 54.184.91.239
WHOIS Info: Amazon (AWS), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (293 hits)
- 181.41.206.227
WHOIS Info: Private Customer, EU, Abuse Contact, Allocated
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (3 hits across multiple environments)
- 82.39.206.158
WHOIS Info: Chunkserve Mateusz Peplinski, PL, Abuse Contact, Allocated
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (1 hits)
- 20.46.252.52
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (163 hits across multiple environments)
- 20.226.60.151
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (267 hits)
- 20.195.181.252
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (182 hits)
- 158.94.209.225
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Static Deny Applied (6 hits)
Decision: 危険パスで 200 応答があり、webshell 投下 payload を確認。想定ファイルと同時刻周辺の更新ファイルはサーバー上で未検出。侵害痕跡なしとして static deny 反映済み。
- 103.253.146.145
WHOIS Info: Digital Ocean, Inc., Abuse Contact, Ad699-Ap, Allocated
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (12 hits)
- 18.232.125.234
WHOIS Info: Amazon (AWS), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (13 hits)
- 20.220.225.223
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (180 hits)
継続隔離中
- 62.197.156.35
WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
Comment: [Auth Attack] probing login and admin entry points
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 172.212.217.10
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 191.237.255.150
WHOIS Info: Microsoft Corporation (Azure), BR, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
common_security.txt 更新判断
- static deny 済み
- 62.197.156.35
- 172.212.217.10
- 191.237.255.150
- 158.94.209.225
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
- 94.143.139.248
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-18 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 6 件、.env 露出確認 5 件、.git/config 露出確認 3 件、バックアップ/DBダンプ探索 3 件、認証系探索 1 件で、探索初動の整理が中心でした
- 158.94.209.225 は Twig/SSTI 経由で `wp-content/uploads/wp-object-check.php` の作成を狙う webshell 投下 payload でした。`wp-object-check.php` / `wp-temp-restore.php` / `wp-cache-validate.php` は未検出で、2026-07-18 16:40-16:50 の更新ファイルもありませんでした
- 64.89.160.220 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 6 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
[2026-07-17 SOC運用向け]
### Jul 17, 2026 | 2 New IPs Quarantined
本日の新規隔離は 2 件でした。2026-07-17 時点で当日日報内に再犯として確認できた継続隔離中のIPは 6 件です。
本日新規隔離
- 103.253.146.145
WHOIS Info: Digital Ocean, Inc., Abuse Contact, Ad699-Ap, Allocated
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (12 hits)
- 20.220.225.223
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (180 hits)
継続隔離中
- 62.197.156.35
WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
Comment: [Auth Attack] probing login and admin entry points
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 172.212.217.10
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 191.237.255.150
WHOIS Info: Microsoft Corporation (Azure), BR, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
common_security.txt 更新判断
- static deny 済み
- 62.197.156.35
- 172.212.217.10
- 191.237.255.150
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
- 94.143.139.248
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-17 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 2 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 6 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
[2026-07-16 SOC運用向け]
### Jul 16, 2026 | 1 New IPs Quarantined
本日の新規隔離は 1 件でした。2026-07-16 時点で当日日報内に再犯として確認できた継続隔離中のIPは 6 件です。
本日新規隔離
- 4.213.167.22
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (153 hits)
継続隔離中
- 62.197.156.35
WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
Comment: [Auth Attack] probing login and admin entry points
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 172.212.217.10
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 191.237.255.150
WHOIS Info: Microsoft Corporation (Azure), BR, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
common_security.txt 更新判断
- static deny 済み
- 62.197.156.35
- 172.212.217.10
- 191.237.255.150
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
- 94.143.139.248
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-16 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 6 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
[2026-07-15 SOC運用向け]
### Jul 15, 2026 | 1 New IPs Quarantined
本日の新規隔離は 1 件でした。2026-07-15 時点で当日日報内に再犯として確認できた継続隔離中のIPは 6 件です。
本日新規隔離
- 35.243.245.112
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for exposed backup, archive, and database dump files
Status: Blacklisted (2 hits)
継続隔離中
- 62.197.156.35
WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
Comment: [Auth Attack] probing login and admin entry points
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 172.212.217.10
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 191.237.255.150
WHOIS Info: Microsoft Corporation (Azure), BR, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
common_security.txt 更新判断
- static deny 済み
- 62.197.156.35
- 172.212.217.10
- 191.237.255.150
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
- 94.143.139.248
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-15 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は バックアップ/DBダンプ探索 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 6 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
本日の新規隔離は 3 件でした。2026-07-14 時点で当日日報内に再犯として確認できた継続隔離中のIPは 6 件です。
本日新規隔離
- 191.237.250.106
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (281 hits)
- 20.220.9.199
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (141 hits)
- 20.151.205.204
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (140 hits)
継続隔離中
- 62.197.156.35
WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
Comment: [Auth Attack] probing login and admin entry points
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 172.212.217.10
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 191.237.255.150
WHOIS Info: Microsoft Corporation (Azure), BR, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
common_security.txt 更新判断
- static deny 済み
- 62.197.156.35
- 172.212.217.10
- 191.237.255.150
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
- 94.143.139.248
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-14 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 3 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 6 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
本日の新規隔離は 10 件でした。2026-07-13 時点で当日日報内に再犯として確認できた継続隔離中のIPは 6 件です。
本日新規隔離
- 34.53.116.212
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Fingerprinting] probing for exposed backup, archive, and database dump files
Status: Blacklisted (2 hits)
- 158.173.77.46
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (11 hits across multiple environments)
- 20.226.26.5
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (277 hits)
- 20.220.9.199
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (281 hits)
- 20.48.236.161
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (594 hits across multiple environments)
- 188.166.99.91
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (1 hits)
- 206.123.156.179
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Auth Attack] probing XML-RPC entry points
Status: Blacklisted (10 hits)
- 81.171.74.60
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Fingerprinting] probing for exposed backup, archive, and database dump files
Status: Blacklisted (13 hits)
- 178.128.57.200
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Auth Attack] probing login and admin entry points
Status: Blacklisted (12 hits)
- 168.110.218.47
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (49 hits)
継続隔離中
- 62.197.156.35
WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
Comment: [Auth Attack] probing login and admin entry points
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 172.212.217.10
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 191.237.255.150
WHOIS Info: Microsoft Corporation (Azure), BR, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
common_security.txt 更新判断
- static deny 済み
- 62.197.156.35
- 172.212.217.10
- 191.237.255.150
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
- 94.143.139.248
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-13 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 4 件、バックアップ/DBダンプ探索 2 件、認証系探索 2 件、.env 露出確認 1 件、.git/config 露出確認 1 件で、探索初動の整理が中心でした
- 158.173.77.46 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 6 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
本日の新規隔離は 4 件でした。2026-07-12 時点で当日日報内に再犯として確認できた継続隔離中のIPは 6 件です。
本日新規隔離
- 140.248.75.183
WHOIS Info: Fastly, Inc. (SKYCA-3), Abuse Contact, Abuse4771-Arin, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (1 hits)
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Blacklisted (22 hits)
- 157.52.122.49
WHOIS Info: Fastly, Inc. (SKYCA-3), Abuse Contact, Abuse4771-Arin, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (1 hits)
- 35.236.130.189
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (1 hits)
継続隔離中
- 62.197.156.35
WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
Comment: [Auth Attack] probing login and admin entry points
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 172.212.217.10
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 191.237.255.150
WHOIS Info: Microsoft Corporation (Azure), BR, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
common_security.txt 更新判断
- static deny 済み
- 62.197.156.35
- 172.212.217.10
- 191.237.255.150
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
- 94.143.139.248
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-12 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は .git/config 露出確認 3 件、WordPress 設定露出探索 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 6 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
本日の新規隔離は 1 件でした。2026-07-11 時点で当日日報内に再犯として確認できた継続隔離中のIPは 5 件です。
本日新規隔離
- 157.52.122.74
WHOIS Info: Fastly, Inc. (SKYCA-3), Abuse Contact, Abuse4771-Arin, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (1 hits)
継続隔離中
- 62.197.156.35
WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
Comment: [Auth Attack] probing login and admin entry points
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 172.212.217.10
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 191.237.255.150
WHOIS Info: Microsoft Corporation (Azure), BR, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
common_security.txt 更新判断
- static deny 済み
- 62.197.156.35
- 172.212.217.10
- 191.237.255.150
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-11 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は .git/config 露出確認 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 5 IP は不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
本日の新規隔離は 12 件でした。2026-07-10 時点で当日日報内に再犯として確認できた継続隔離中のIPは 6 件です。
本日新規隔離
- 85.11.167.242
WHOIS Info: TechTies Inc., NL, Abuse Contact, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Blacklisted (19 hits)
- 153.239.163.134
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Auth Attack] probing login and admin entry points
Status: Blacklisted (7 hits across multiple environments)
- 20.195.178.90
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (279 hits)
- 156.146.39.52
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (2 hits across multiple environments)
- 54.241.202.114
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Fingerprinting] probing for exposed backup, archive, and database dump files
Status: Blacklisted (6 hits)
- 81.199.26.100
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (1 hits)
- 34.71.105.137
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (1 hits)
- 144.172.103.251
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (1 hits)
- 20.220.212.5
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (419 hits)
- 66.171.162.195
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Fingerprinting] probing for exposed backup, archive, and database dump files
Status: Blacklisted (3 hits)
- 191.237.255.150
WHOIS Info: Microsoft Corporation (Azure), BR, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (42 hits)
- 157.52.122.75
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (1 hits)
継続隔離中
- 62.197.156.35
WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
Comment: [Auth Attack] probing login and admin entry points
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 172.212.217.10
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 191.237.255.150
WHOIS Info: Microsoft Corporation (Azure), BR, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
common_security.txt 更新判断
- static deny 済み
- 62.197.156.35
- 172.212.217.10
- 191.237.255.150
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
- 94.143.139.248
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-10 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は .git/config 露出確認 3 件、不審 PHP 探索 3 件、.env 露出確認 2 件、バックアップ/DBダンプ探索 2 件、認証系探索 2 件で、探索初動の整理が中心でした
- 153.239.163.134 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 6 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
本日の新規隔離は 8 件でした。2026-07-09 時点で当日日報内に再犯として確認できた継続隔離中のIPは 5 件です。
本日新規隔離
- 191.237.255.150
WHOIS Info: Microsoft Corporation (Azure), BR, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (100 hits)
- 47.108.20.158
WHOIS Info: Asia Pacific Network Information Centre (APNIC), AU, Abuse Contact, Legacy
Comment: [Auth Attack] probing login and admin entry points
Status: Blacklisted (6 hits across multiple environments)
- 130.12.182.12
WHOIS Info: Netiface LLC (NL-846), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (1 hits)
- 20.197.60.102
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (417 hits)
- 20.48.255.163
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (52 hits)
- 195.178.110.18
WHOIS Info: TECHOFF SRV LIMITED, AD, Abuse Contact, Allocated
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (1 hits)
- 40.115.138.243
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (152 hits)
- 62.60.130.233
WHOIS Info: CIPHER OPERATIONS DOO BEOGRAD - NOVI BEOGRAD, GB, Abuse Contact, Allocated
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (12 hits)
継続隔離中
- 62.197.156.35
WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
Comment: [Auth Attack] probing login and admin entry points
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 172.212.217.10
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 191.237.255.150
WHOIS Info: Microsoft Corporation (Azure), BR, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み
- 62.197.156.35
- 172.212.217.10
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
- 191.237.255.150
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-09 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 5 件、.env 露出確認 1 件、.git/config 露出確認 1 件、認証系探索 1 件で、探索初動の整理が中心でした
- 47.108.20.158 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 5 IP は不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
本日の新規隔離は 6 件でした。2026-07-08 時点で当日日報内に再犯として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 52.231.76.18
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (277 hits)
- 20.46.177.15
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (269 hits)
- 158.94.210.233
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (225 hits)
- 20.205.32.154
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (268 hits)
- 191.237.255.150
WHOIS Info: Microsoft Corporation (Azure), BR, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (60 hits)
- 20.89.242.68
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (152 hits)
継続隔離中
- 62.197.156.35
WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
Comment: [Auth Attack] probing login and admin entry points
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 172.212.217.10
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み
- 62.197.156.35
- 172.212.217.10
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-08 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 5 件、.env 露出確認 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 4 IP は不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
本日の新規隔離は 17 件でした。2026-07-07 時点で当日日報内に再犯として確認できた継続隔離中のIPは 6 件です。
本日新規隔離
- 158.94.210.233
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (239 hits)
- 64.89.160.220
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (25 hits across multiple environments)
- 52.253.101.220
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (246 hits)
- 40.115.140.72
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (284 hits across multiple environments)
- 152.53.54.209
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Auth Attack] probing login and admin entry points
Status: Blacklisted (17 hits across multiple environments)
- 20.198.90.154
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (275 hits)
- 8.231.134.21
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Fingerprinting] probing for exposed backup, archive, and database dump files
Status: Blacklisted (2 hits)
- 40.74.69.175
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (182 hits)
- 191.237.255.150
WHOIS Info: Microsoft Corporation (Azure), BR, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (114 hits across multiple environments)
- 162.243.79.174
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (2 hits)
- 94.154.43.177
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (1 hits)
- 20.235.127.11
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (245 hits)
- 153.75.89.214
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Blacklisted (2 hits across multiple environments)
- 41.143.156.66
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (2 hits)
- 20.89.248.158
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (138 hits)
- 20.214.163.77
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (275 hits)
- 94.154.43.185
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (1 hits)
継続隔離中
- 62.197.156.35
WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
Comment: [Auth Attack] probing login and admin entry points
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 172.212.217.10
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 191.237.255.150
WHOIS Info: Microsoft Corporation (Azure), BR, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
common_security.txt 更新判断
- static deny 済み
- 62.197.156.35
- 172.212.217.10
- 191.237.255.150
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
- 94.143.139.248
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-07 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 9 件、.env 露出確認 5 件、WordPress 設定露出探索 1 件、バックアップ/DBダンプ探索 1 件、認証系探索 1 件で、探索初動の整理が中心でした
- 64.89.160.220 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 6 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
本日の新規隔離は 4 件でした。2026-07-06 時点で当日日報内に再犯として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 20.226.80.53
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (140 hits)
- 20.63.42.26
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (278 hits)
- 162.243.170.185
WHOIS Info: DigitalOcean, LLC, LLC (DO-13), Abuse Contact, Digit19-Arin, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (1 hits)
- 20.24.203.130
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (71 hits)
継続隔離中
- 62.197.156.35
WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
Comment: [Auth Attack] probing login and admin entry points
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 172.212.217.10
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み
- 62.197.156.35
- 172.212.217.10
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-06 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 3 件、.env 露出確認 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 4 IP は不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
本日の新規隔離は 1 件でした。2026-07-05 時点で当日日報内に再犯として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 51.103.130.248
WHOIS Info: Microsoft Corporation (Azure), EU, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (251 hits)
継続隔離中
- 62.197.156.35
WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
Comment: [Auth Attack] probing login and admin entry points
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 172.212.217.10
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み
- 62.197.156.35
- 172.212.217.10
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-05 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 4 IP は不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
本日の新規隔離は 3 件でした。2026-07-04 時点で当日日報内に再犯として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 185.150.0.143
WHOIS Info: VPN Consumer Singapore, Republic of Singapore, Abuse Contact, Vcar3-Ripe, Allocated
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (4 hits across multiple environments)
- 52.138.1.81
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (91 hits)
- 170.64.180.91
WHOIS Info: DigitalOcean, LLC, LLC (DO-13), Abuse Contact, Digit19-Arin, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (2 hits)
継続隔離中
- 62.197.156.35
WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
Comment: [Auth Attack] probing login and admin entry points
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 172.212.217.10
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み
- 62.197.156.35
- 172.212.217.10
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-04 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 2 件、.git/config 露出確認 1 件で、探索初動の整理が中心でした
- 185.150.0.143 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 4 IP は不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
本日の新規隔離は 5 件でした。2026-07-03 時点で当日日報内に再犯として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 20.243.184.229
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Auth Attack] probing XML-RPC entry points
Status: Blacklisted (6 hits across multiple environments)
- 35.185.141.157
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (1 hits)
- 40.83.92.182
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (32 hits)
- 20.210.248.27
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (99 hits)
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (2 hits)
継続隔離中
- 62.197.156.35
WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
Comment: [Auth Attack] probing login and admin entry points
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 172.212.217.10
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み
- 62.197.156.35
- 172.212.217.10
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-03 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 3 件、.git/config 露出確認 1 件、認証系探索 1 件で、探索初動の整理が中心でした
- 20.243.184.229 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 4 IP は不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
本日の新規隔離は 4 件でした。2026-07-02 時点で当日日報内に再犯として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 78.189.24.202
WHOIS Info: TT ADSL-TTnet alcatel static_aci, tr, Abuse Contact, Allocated
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (49 hits)
- 67.205.147.135
WHOIS Info: DigitalOcean, LLC, LLC (DO-13), Abuse Contact, Digit19-Arin, Allocated
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (2 hits)
- 34.133.214.222
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (1 hits)
- 52.184.100.96
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (93 hits)
継続隔離中
- 62.197.156.35
WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
Comment: [Auth Attack] probing login and admin entry points
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 172.212.217.10
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み
- 62.197.156.35
- 172.212.217.10
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-02 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は .git/config 露出確認 2 件、.env 露出確認 1 件、不審 PHP 探索 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 4 IP は不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
本日の新規隔離は 5 件でした。2026-07-01 時点で当日日報内に再犯として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 20.89.237.101
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (289 hits)
- 20.220.14.153
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (95 hits)
- 181.41.206.215
WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Allocated
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (1 hits)
- 20.220.223.15
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (147 hits)
- 45.55.71.64
WHOIS Info: DigitalOcean, LLC, LLC (DO-13), Abuse Contact, Digit19-Arin, Legacy
Comment: [Auth Attack] probing login and admin entry points
Status: Blacklisted (8 hits)
継続隔離中
- 62.197.156.35
WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
Comment: [Auth Attack] probing login and admin entry points
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 172.212.217.10
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Static Deny Applied
Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み
- 62.197.156.35
- 172.212.217.10
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-01 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 3 件、.env 露出確認 1 件、認証系探索 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 4 IP は不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性があるUNIX Cafe フロア案内(ハブページ)