本記事の構成および論理分析にはAI(人工知能)を使用しています。情報の正確性は、システム管理者(UNIXユーザー)による手動検証済みです。
2026年10月度 セキュリティログ:複数管理環境における不正試行の観測と遮断

目次
Monthly Incident Report: Oct. 2026 — managed environments
2026年5月より、セキュリティ日報の掲載フォーマットを見直しました。これまでのインシデントログ中心の形式から、当日に新規隔離したIPと継続隔離中のIPを分かりやすく整理した、SOC運用向けの一覧形式へ変更しています。
新しい形式では、WHOIS情報、攻撃種別、遮断状況を中心に、必要な情報を簡潔に確認できる構成に統一しました。また、記事内では個別サイト名や内部運用向けの詳細パラメータは掲載せず、複数サイトにまたがるアクセスは「複数の管理環境」として表記する運用に変更しています。
この見直しにより、日々の観測傾向や継続的な不審アクセスの把握を、以前より短時間で確認しやすくなりました。
2026年8月より、継続隔離中のIPについては、世界中のセキュリティ管理者による報告や危険度スコアを確認しやすいよう、AbuseIPDBの個別照会アドレスを追記し、追跡調査の利便性を高めました。
[2026-10-06 SOC運用向け]
### Oct 06, 2026 | 6 New IPs Quarantined
本日の新規隔離は 6 件でした。2026-10-06 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 11 件です。
本日新規隔離
- 20.194.30.107
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (60 hits)
- 20.214.109.68
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (124 hits)
- 20.24.217.162
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (103 hits)
- 144.172.99.29
WHOIS Info: FranTech Solutions (SYNDI-5), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (1 hits)
- 139.59.107.185
WHOIS Info: Asia Pacific Network Information Centre (APNIC), AU, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (12 hits)
- 20.210.128.125
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (110 hits)
継続隔離中
- 94.143.139.248
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 159.89.12.166
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/159.89.12.166
WHOIS Info: DigitalOcean, LLC, US, Abuse Contact, Legacy
Comment: [Auth Attack] probing login and admin entry points
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 4.225.166.222
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/4.225.166.222
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 116.202.252.125
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/116.202.252.125
WHOIS Info: Transferred to the RIPE region on 2018-08-28T00:42:30Z., ZZ, Abuse Contact, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.169.16.7
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.169.16.7
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.48.147.90
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.48.147.90
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.220.10.235
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.220.10.235
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.104.18.15
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.104.18.15
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 146.190.211.127
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/146.190.211.127
WHOIS Info: DigitalOcean, LLC, US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 35.237.212.49
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/35.237.212.49
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- 今回の反映処理: 新規追加なし(既存登録済みは下記に記載)
- static deny 済み(危険パス200): なし
- static deny 済み: なし
- common_security.txt 追記候補: なし
- 監視継続
- 94.143.139.248
- 159.89.12.166
- 51.116.233.22
- 4.225.166.222
- 116.202.252.125
- 20.169.16.7
- 20.48.147.90
- 20.220.10.235
- 20.104.18.15
- 146.190.211.127
- 35.237.212.49
運用補足
- common_security.txt はローカルで更新後、サーバーへ転送して update_htaccess.sh で一斉配信します
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-10-06 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 5 件、.git/config 露出確認 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 11 IP は.env 露出確認と.git/config 露出確認とWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
[2026-10-05 SOC運用向け]
### Oct 05, 2026 | 3 New IPs Quarantined
本日の新規隔離は 3 件でした。2026-10-05 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 11 件です。
本日新規隔離
- 139.59.247.91
WHOIS Info: Asia Pacific Network Information Centre (APNIC), AU, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (12 hits)
- 139.59.229.172
WHOIS Info: Asia Pacific Network Information Centre (APNIC), AU, Abuse Contact, Legacy
Comment: [Auth Attack] probing login and admin entry points
Status: Blacklisted (12 hits)
- 20.210.186.186
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (56 hits)
継続隔離中
- 94.143.139.248
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 159.89.12.166
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/159.89.12.166
WHOIS Info: DigitalOcean, LLC, US, Abuse Contact, Legacy
Comment: [Auth Attack] probing login and admin entry points
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 4.225.166.222
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/4.225.166.222
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 116.202.252.125
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/116.202.252.125
WHOIS Info: Transferred to the RIPE region on 2018-08-28T00:42:30Z., ZZ, Abuse Contact, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.169.16.7
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.169.16.7
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.48.147.90
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.48.147.90
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.220.10.235
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.220.10.235
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.104.18.15
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.104.18.15
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 146.190.211.127
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/146.190.211.127
WHOIS Info: DigitalOcean, LLC, US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 35.237.212.49
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/35.237.212.49
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- 今回の反映処理: 新規追加なし(既存登録済みは下記に記載)
- static deny 済み(危険パス200): なし
- static deny 済み: なし
- common_security.txt 追記候補: なし
- 監視継続
- 94.143.139.248
- 159.89.12.166
- 51.116.233.22
- 4.225.166.222
- 116.202.252.125
- 20.169.16.7
- 20.48.147.90
- 20.220.10.235
- 20.104.18.15
- 146.190.211.127
- 35.237.212.49
運用補足
- common_security.txt はローカルで更新後、サーバーへ転送して update_htaccess.sh で一斉配信します
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-10-05 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 2 件、認証系探索 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 11 IP は.env 露出確認と.git/config 露出確認とWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
[2026-10-04 SOC運用向け]
### Oct 04, 2026 | 1 New IPs Quarantined
本日の新規隔離は 1 件でした。2026-10-04 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 11 件です。
本日新規隔離
- 34.138.206.23
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (2 hits)
継続隔離中
- 94.143.139.248
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 159.89.12.166
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/159.89.12.166
WHOIS Info: DigitalOcean, LLC, US, Abuse Contact, Legacy
Comment: [Auth Attack] probing login and admin entry points
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 4.225.166.222
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/4.225.166.222
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 116.202.252.125
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/116.202.252.125
WHOIS Info: Transferred to the RIPE region on 2018-08-28T00:42:30Z., ZZ, Abuse Contact, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.169.16.7
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.169.16.7
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.48.147.90
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.48.147.90
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.220.10.235
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.220.10.235
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.104.18.15
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.104.18.15
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 146.190.211.127
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/146.190.211.127
WHOIS Info: DigitalOcean, LLC, US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 35.237.212.49
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/35.237.212.49
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- 今回の反映処理: 新規追加なし(既存登録済みは下記に記載)
- static deny 済み(危険パス200): なし
- static deny 済み: なし
- common_security.txt 追記候補: なし
- 監視継続
- 94.143.139.248
- 159.89.12.166
- 51.116.233.22
- 4.225.166.222
- 116.202.252.125
- 20.169.16.7
- 20.48.147.90
- 20.220.10.235
- 20.104.18.15
- 146.190.211.127
- 35.237.212.49
運用補足
- common_security.txt はローカルで更新後、サーバーへ転送して update_htaccess.sh で一斉配信します
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-10-04 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は .git/config 露出確認 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 11 IP は.env 露出確認と.git/config 露出確認とWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
[2026-10-03 SOC運用向け]
### Oct 03, 2026 | 1 New IPs Quarantined
本日の新規隔離は 1 件でした。2026-10-03 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 11 件です。
本日新規隔離
- 34.138.206.23
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (2 hits)
継続隔離中
- 94.143.139.248
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 159.89.12.166
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/159.89.12.166
WHOIS Info: DigitalOcean, LLC, US, Abuse Contact, Legacy
Comment: [Auth Attack] probing login and admin entry points
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 4.225.166.222
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/4.225.166.222
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 116.202.252.125
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/116.202.252.125
WHOIS Info: Transferred to the RIPE region on 2018-08-28T00:42:30Z., ZZ, Abuse Contact, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.169.16.7
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.169.16.7
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.48.147.90
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.48.147.90
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.220.10.235
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.220.10.235
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.104.18.15
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.104.18.15
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 146.190.211.127
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/146.190.211.127
WHOIS Info: DigitalOcean, LLC, US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 35.237.212.49
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/35.237.212.49
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- 今回の反映処理: 新規追加なし(既存登録済みは下記に記載)
- static deny 済み(危険パス200): なし
- static deny 済み: なし
- common_security.txt 追記候補: なし
- 監視継続
- 94.143.139.248
- 159.89.12.166
- 51.116.233.22
- 4.225.166.222
- 116.202.252.125
- 20.169.16.7
- 20.48.147.90
- 20.220.10.235
- 20.104.18.15
- 146.190.211.127
- 35.237.212.49
運用補足
- common_security.txt はローカルで更新後、サーバーへ転送して update_htaccess.sh で一斉配信します
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-10-03 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は .git/config 露出確認 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 11 IP は.env 露出確認と.git/config 露出確認とWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
[2026-10-02 SOC運用向け]
### Oct 02, 2026 | 12 New IPs Quarantined
本日の新規隔離は 12 件でした。2026-10-02 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 11 件です。
本日新規隔離
- 159.89.81.187
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/159.89.81.187
WHOIS Info: DigitalOcean, LLC, US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (2 hits across multiple environments)
- 62.60.130.252
WHOIS Info: CIPHER OPERATIONS DOO BEOGRAD - NOVI BEOGRAD, GB, Abuse Contact, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Blacklisted (4 hits across multiple environments)
- 192.253.209.70
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (967 hits)
- 192.253.209.98
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (75 hits)
- 141.101.98.224
WHOIS Info: CloudFlare CDN network, EU, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (5 hits)
- 141.101.98.35
WHOIS Info: CloudFlare CDN network, EU, Unknown (Unresolved), Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (3 hits)
- 141.101.99.15
WHOIS Info: CloudFlare CDN network, EU, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (3 hits)
- 141.101.99.16
WHOIS Info: CloudFlare CDN network, EU, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (4 hits)
- 141.101.99.82
WHOIS Info: CloudFlare CDN network, EU, Unknown (Unresolved), Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (1 hits)
- 192.253.209.61
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (967 hits)
- 192.253.209.65
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (75 hits)
- 209.99.188.156
WHOIS Info: SKN Subnet & Telecom Ltd (SSTL-49), KN, Abuse Contact, Allocated
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (1 hits)
継続隔離中
- 94.143.139.248
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 159.89.12.166
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/159.89.12.166
WHOIS Info: DigitalOcean, LLC, US, Abuse Contact, Legacy
Comment: [Auth Attack] probing login and admin entry points
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 4.225.166.222
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/4.225.166.222
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 116.202.252.125
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/116.202.252.125
WHOIS Info: Transferred to the RIPE region on 2018-08-28T00:42:30Z., ZZ, Abuse Contact, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.169.16.7
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.169.16.7
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.48.147.90
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.48.147.90
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.220.10.235
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.220.10.235
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.104.18.15
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.104.18.15
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 146.190.211.127
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/146.190.211.127
WHOIS Info: DigitalOcean, LLC, US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 35.237.212.49
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/35.237.212.49
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- 今回の反映処理: 新規追加なし(既存登録済みは下記に記載)
- static deny 済み(危険パス200): なし
- static deny 済み: なし
- common_security.txt 追記候補: なし
- 監視継続
- 94.143.139.248
- 159.89.12.166
- 51.116.233.22
- 4.225.166.222
- 116.202.252.125
- 20.169.16.7
- 20.48.147.90
- 20.220.10.235
- 20.104.18.15
- 146.190.211.127
- 35.237.212.49
運用補足
- common_security.txt はローカルで更新後、サーバーへ転送して update_htaccess.sh で一斉配信します
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-10-02 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 7 件、.git/config 露出確認 3 件、.env 露出確認 1 件、認証系探索 1 件で、探索初動の整理が中心でした
- 159.89.81.187 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 11 IP は.env 露出確認と.git/config 露出確認とWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
[2026-10-01 SOC運用向け]
### Oct 01, 2026 | 5 New IPs Quarantined
本日の新規隔離は 5 件でした。2026-10-01 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 11 件です。
本日新規隔離
- 141.101.98.224
WHOIS Info: CloudFlare CDN network, EU, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (5 hits)
- 141.101.98.35
WHOIS Info: CloudFlare CDN network, EU, Unknown (Unresolved), Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (3 hits)
- 141.101.99.15
WHOIS Info: CloudFlare CDN network, EU, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (3 hits)
- 141.101.99.16
WHOIS Info: CloudFlare CDN network, EU, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (4 hits)
- 141.101.99.82
WHOIS Info: CloudFlare CDN network, EU, Unknown (Unresolved), Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (1 hits)
継続隔離中
- 94.143.139.248
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 159.89.12.166
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/159.89.12.166
WHOIS Info: DigitalOcean, LLC, US, Abuse Contact, Legacy
Comment: [Auth Attack] probing login and admin entry points
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 4.225.166.222
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/4.225.166.222
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 116.202.252.125
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/116.202.252.125
WHOIS Info: Transferred to the RIPE region on 2018-08-28T00:42:30Z., ZZ, Abuse Contact, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.169.16.7
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.169.16.7
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.48.147.90
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.48.147.90
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.220.10.235
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.220.10.235
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.104.18.15
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.104.18.15
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 146.190.211.127
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/146.190.211.127
WHOIS Info: DigitalOcean, LLC, US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 35.237.212.49
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/35.237.212.49
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- 今回の反映処理: 新規追加なし(既存登録済みは下記に記載)
- static deny 済み(危険パス200): なし
- static deny 済み: なし
- common_security.txt 追記候補: なし
- 監視継続
- 94.143.139.248
- 159.89.12.166
- 51.116.233.22
- 4.225.166.222
- 116.202.252.125
- 20.169.16.7
- 20.48.147.90
- 20.220.10.235
- 20.104.18.15
- 146.190.211.127
- 35.237.212.49
運用補足
- common_security.txt はローカルで更新後、サーバーへ転送して update_htaccess.sh で一斉配信します
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-10-01 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 3 件、.env 露出確認 1 件、.git/config 露出確認 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 11 IP は.env 露出確認と.git/config 露出確認とWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
