2026年7月度 セキュリティログ:複数管理環境における不正試行の観測と遮断

* 当サイトでは、コンテンツの一部に広告を掲載しています。

System Note $ cat /proc/ai-disclosure

本記事の構成および論理分析にはAI(人工知能)を使用しています。情報の正確性は、システム管理者(UNIXユーザー)による手動検証済みです。

双眼鏡を持つ監視オペレーターと、UNIX CAFEのデジタル・ファイアウォールを死守するペンギン騎士
目次

Monthly Incident Report: March 2026 — managed environments

2026年5月より、セキュリティ日報の掲載フォーマットを見直しました。これまでのインシデントログ中心の形式から、当日に新規隔離したIPと継続隔離中のIPを分かりやすく整理した、SOC運用向けの一覧形式へ変更しています。

新しい形式では、WHOIS情報、攻撃種別、遮断状況を中心に、必要な情報を簡潔に確認できる構成に統一しました。また、記事内では個別サイト名や内部運用向けの詳細パラメータは掲載せず、複数サイトにまたがるアクセスは「複数の管理環境」として表記する運用に変更しています。

この見直しにより、日々の観測傾向や継続的な不審アクセスの把握を、以前より短時間で確認しやすくなりました。

[2026-07-31 SOC運用向け]

### Jul 31, 2026 | 2 New IPs Quarantined

本日の新規隔離は 2 件でした。2026-07-31 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 5 件です。

本日新規隔離

- 20.104.22.47
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (5 hits across multiple environments)

- 34.23.178.20
  WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
  Comment: [Fingerprinting] probing for .git/config exposure
  Status: Blacklisted (2 hits)

継続隔離中

- 20.78.158.176
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 135.119.47.58
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 94.143.139.248
  WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
  Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 51.116.233.22
  WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 20.79.29.209
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and dangerous backup paths
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

common_security.txt 更新判断

- static deny 済み
  - 20.79.29.209
- common_security.txt 追記候補: なし
- runtime quarantine 継続
  - 20.78.158.176
  - 135.119.47.58
  - 94.143.139.248
  - 51.116.233.22

運用補足

- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-07-31 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います

分析メモ

- 本日新規隔離は .git/config 露出確認 1 件、不審 PHP 探索 1 件で、探索初動の整理が中心でした
- 20.104.22.47 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 5 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、20.79.29.209 は危険パスで 200 応答が確認されているため優先確認が必要です
[2026-07-30 SOC運用向け]

### Jul 30, 2026 | 3 New IPs Quarantined

本日の新規隔離は 3 件でした。2026-07-30 時点で当日日報内に再犯として確認できた継続隔離中のIPは 4 件です。

本日新規隔離

- 20.104.22.47
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (5 hits across multiple environments)

- 34.23.178.20
  WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
  Comment: [Fingerprinting] probing for .git/config exposure
  Status: Blacklisted (2 hits)

- 4.225.166.222
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (112 hits)

継続隔離中

- 20.78.158.176
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 135.119.47.58
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 94.143.139.248
  WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
  Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 51.116.233.22
  WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

common_security.txt 更新判断

- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
  - 20.78.158.176
  - 135.119.47.58
  - 94.143.139.248
  - 51.116.233.22

運用補足

- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-07-30 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います

分析メモ

- 本日新規隔離は 不審 PHP 探索 2 件、.git/config 露出確認 1 件で、探索初動の整理が中心でした
- 20.104.22.47 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、再出現の可能性がある
[2026-07-29 SOC運用向け]

### Jul 29, 2026 | 20 New IPs Quarantined

本日の新規隔離は 20 件でした。2026-07-29 時点で当日日報内に再犯として確認できた継続隔離中のIPは 4 件です。

本日新規隔離

- 80.94.92.67
  WHOIS Info: https://dmzhost.co, NL, Abuse Contact, Allocated
  Comment: [Fingerprinting] probing for .git/config exposure
  Status: Blacklisted (1 hits)

- 20.91.140.156
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (147 hits across multiple environments)

- 35.227.106.50
  WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
  Comment: [Fingerprinting] probing for exposed backup, archive, and database dump files
  Status: Blacklisted (2 hits)

- 18.202.218.25
  WHOIS Info: Amazon (AWS), US, Abuse Contact, Legacy
  Comment: [Fingerprinting] probing for .env and related exposed files
  Status: Blacklisted (286 hits)

- 158.101.144.198
  WHOIS Info: Oracle Corporation (ORACLE-4), US, Abuse Contact, Legacy
  Comment: [Fingerprinting] probing for .git/config exposure
  Status: Blacklisted (2 hits)

- 20.203.135.57
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (259 hits)

- 172.202.44.182
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (4 hits across multiple environments)

- 20.151.221.234
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (14 hits across multiple environments)

- 172.213.8.106
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (366 hits)

- 158.158.32.229
  WHOIS Info: Asia Pacific Network Information Centre (APNIC), AU, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (78 hits)

- 51.120.79.193
  WHOIS Info: Microsoft Corporation (Azure), NO, Unknown (Unresolved), Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (156 hits)

- 20.79.250.162
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (131 hits)

- 80.94.92.167
  WHOIS Info: https://dmzhost.co, NL, Abuse Contact, Allocated
  Comment: [Fingerprinting] probing for .git/config exposure
  Status: Blacklisted (2 hits across multiple environments)

- 20.100.173.28
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (258 hits)

- 3.149.2.121
  WHOIS Info: Amazon (AWS), US, Abuse Contact, Legacy
  Comment: [Fingerprinting] probing for .env and related exposed files
  Status: Blacklisted (247 hits)

- 81.171.72.93
  WHOIS Info: Unknown (Unresolved), DE, Abuse Contact, Allocated
  Comment: [Fingerprinting] probing for exposed backup, archive, and database dump files
  Status: Blacklisted (13 hits)

- 20.251.58.190
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (155 hits)

- 5.223.46.133
  WHOIS Info: Hetzner Online GmbH, SG, Abuse Contact, Allocated
  Comment: [Fingerprinting] probing for .env and related exposed files
  Status: Blacklisted (2 hits)

- 4.223.71.149
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (94 hits)

- 20.79.29.209
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (128 hits)

継続隔離中

- 20.78.158.176
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 135.119.47.58
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 94.143.139.248
  WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
  Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 51.116.233.22
  WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

common_security.txt 更新判断

- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
  - 20.78.158.176
  - 135.119.47.58
  - 94.143.139.248
  - 51.116.233.22

運用補足

- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-07-29 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います

分析メモ

- 本日新規隔離は 不審 PHP 探索 12 件、.env 露出確認 3 件、.git/config 露出確認 3 件、バックアップ/DBダンプ探索 2 件で、探索初動の整理が中心でした
- 20.91.140.156 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、再出現の可能性がある
[2026-07-28 SOC運用向け]

### Jul 28, 2026 | 20 New IPs Quarantined

本日の新規隔離は 20 件でした。2026-07-28 時点で当日日報内に再犯として確認できた継続隔離中のIPは 4 件です。

本日新規隔離

- 80.94.92.67
  WHOIS Info: https://dmzhost.co, NL, Abuse Contact, Allocated
  Comment: [Fingerprinting] probing for .git/config exposure
  Status: Blacklisted (1 hits)

- 20.91.140.156
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (147 hits across multiple environments)

- 35.227.106.50
  WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
  Comment: [Fingerprinting] probing for exposed backup, archive, and database dump files
  Status: Blacklisted (2 hits)

- 18.202.218.25
  WHOIS Info: Amazon (AWS), US, Abuse Contact, Legacy
  Comment: [Fingerprinting] probing for .env and related exposed files
  Status: Blacklisted (286 hits)

- 158.101.144.198
  WHOIS Info: Oracle Corporation (ORACLE-4), US, Abuse Contact, Legacy
  Comment: [Fingerprinting] probing for .git/config exposure
  Status: Blacklisted (2 hits)

- 20.203.135.57
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (259 hits)

- 172.202.44.182
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (4 hits across multiple environments)

- 20.151.221.234
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (14 hits across multiple environments)

- 172.213.8.106
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (366 hits)

- 158.158.32.229
  WHOIS Info: Asia Pacific Network Information Centre (APNIC), AU, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (78 hits)

- 51.120.79.193
  WHOIS Info: Microsoft Corporation (Azure), NO, Unknown (Unresolved), Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (156 hits)

- 20.79.250.162
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (131 hits)

- 80.94.92.167
  WHOIS Info: https://dmzhost.co, NL, Abuse Contact, Allocated
  Comment: [Fingerprinting] probing for .git/config exposure
  Status: Blacklisted (2 hits across multiple environments)

- 20.100.173.28
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (258 hits)

- 3.149.2.121
  WHOIS Info: Amazon (AWS), US, Abuse Contact, Legacy
  Comment: [Fingerprinting] probing for .env and related exposed files
  Status: Blacklisted (247 hits)

- 81.171.72.93
  WHOIS Info: Unknown (Unresolved), DE, Abuse Contact, Allocated
  Comment: [Fingerprinting] probing for exposed backup, archive, and database dump files
  Status: Blacklisted (13 hits)

- 20.251.58.190
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (155 hits)

- 5.223.46.133
  WHOIS Info: Hetzner Online GmbH, SG, Abuse Contact, Allocated
  Comment: [Fingerprinting] probing for .env and related exposed files
  Status: Blacklisted (2 hits)

- 4.223.71.149
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (94 hits)

- 20.79.29.209
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (128 hits)

継続隔離中

- 20.78.158.176
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 135.119.47.58
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 94.143.139.248
  WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
  Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 51.116.233.22
  WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

common_security.txt 更新判断

- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
  - 20.78.158.176
  - 135.119.47.58
  - 94.143.139.248
  - 51.116.233.22

運用補足

- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-07-28 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います

分析メモ

- 本日新規隔離は 不審 PHP 探索 12 件、.env 露出確認 3 件、.git/config 露出確認 3 件、バックアップ/DBダンプ探索 2 件で、探索初動の整理が中心でした
- 20.91.140.156 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、再出現の可能性がある
[2026-07-27 SOC運用向け]

### Jul 27, 2026 | 6 New IPs Quarantined

本日の新規隔離は 6 件でした。2026-07-27 時点で当日日報内に再犯として確認できた継続隔離中のIPは 4 件です。

本日新規隔離

- 158.101.144.198
  WHOIS Info: Oracle Corporation (ORACLE-4), US, Abuse Contact, Legacy
  Comment: [Fingerprinting] probing for .git/config exposure
  Status: Blacklisted (2 hits)

- 20.203.135.57
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (259 hits)

- 172.213.8.106
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (244 hits)

- 5.223.46.133
  WHOIS Info: Hetzner Online GmbH, SG, Abuse Contact, Allocated
  Comment: [Fingerprinting] probing for .env and related exposed files
  Status: Blacklisted (2 hits)

- 4.223.71.149
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (94 hits)

- 20.79.29.209
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (128 hits)

継続隔離中

- 20.78.158.176
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 135.119.47.58
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 94.143.139.248
  WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
  Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 51.116.233.22
  WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

common_security.txt 更新判断

- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
  - 20.78.158.176
  - 135.119.47.58
  - 94.143.139.248
  - 51.116.233.22

運用補足

- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-07-27 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います

分析メモ

- 本日新規隔離は 不審 PHP 探索 4 件、.env 露出確認 1 件、.git/config 露出確認 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、再出現の可能性がある
[2026-07-26 SOC運用向け]

### Jul 26, 2026 | 8 New IPs Quarantined

本日の新規隔離は 8 件でした。2026-07-26 時点で当日日報内に再犯として確認できた継続隔離中のIPは 4 件です。

本日新規隔離

- 34.65.71.174
  WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
  Comment: [Fingerprinting] probing for .env and related exposed files
  Status: Blacklisted (25 hits)

- 34.39.25.103
  WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
  Comment: [Fingerprinting] probing for .env and related exposed files
  Status: Blacklisted (25 hits)

- 20.100.178.92
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (238 hits)

- 103.168.67.253
  WHOIS Info: DiGiVPS.com, US, Abuse Contact, Allocated
  Comment: [Fingerprinting] probing for exposed backup, archive, and database dump files
  Status: Blacklisted (2 hits)

- 74.248.33.172
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Allocated
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (238 hits)

- 51.116.233.22
  WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (125 hits)

- 196.250.200.4
  WHOIS Info: WAW, SN, Unknown (Unresolved), Legacy
  Comment: [Fingerprinting] probing for .env and related exposed files
  Status: Blacklisted (8 hits)

- 172.202.26.222
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (103 hits)

継続隔離中

- 20.78.158.176
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 135.119.47.58
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 94.143.139.248
  WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
  Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 51.116.233.22
  WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

common_security.txt 更新判断

- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
  - 20.78.158.176
  - 135.119.47.58
  - 94.143.139.248
  - 51.116.233.22

運用補足

- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-07-26 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います

分析メモ

- 本日新規隔離は 不審 PHP 探索 4 件、.env 露出確認 3 件、バックアップ/DBダンプ探索 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、再出現の可能性がある
[2026-07-25 SOC運用向け]

### Jul 25, 2026 | 4 New IPs Quarantined

本日の新規隔離は 4 件でした。2026-07-25 時点で当日日報内に再犯として確認できた継続隔離中のIPは 3 件です。

本日新規隔離

- 20.100.203.84
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for file manager and backdoor plugin paths
  Status: Blacklisted (2 hits)

- 51.107.70.126
  WHOIS Info: Microsoft Corporation (Azure), EU, Unknown (Unresolved), Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (278 hits)

- 52.165.196.84
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (94 hits)

- 51.116.233.22
  WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (139 hits)

継続隔離中

- 20.78.158.176
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 135.119.47.58
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 94.143.139.248
  WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
  Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

common_security.txt 更新判断

- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
  - 20.78.158.176
  - 135.119.47.58
  - 94.143.139.248

運用補足

- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-07-25 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います

分析メモ

- 本日新規隔離は 不審 PHP 探索 3 件、不審プラグイン探索 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 3 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、再出現の可能性がある
[2026-07-24 SOC運用向け]

### Jul 24, 2026 | 5 New IPs Quarantined

本日の新規隔離は 5 件でした。2026-07-24 時点で当日日報内に再犯として確認できた継続隔離中のIPは 3 件です。

本日新規隔離

- 20.226.83.28
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (279 hits)

- 94.143.231.161
  WHOIS Info: dataforest GmbH, DE, Abuse Contact, Allocated
  Comment: [Fingerprinting] probing for .env and related exposed files
  Status: Blacklisted (7 hits across multiple environments)

- 158.51.126.144
  WHOIS Info: Hostodo (HL-658), US, Abuse Contact, Legacy
  Comment: [Fingerprinting] probing for .env and related exposed files
  Status: Blacklisted (25 hits)

- 20.203.219.190
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (148 hits)

- 34.145.166.183
  WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
  Comment: [Fingerprinting] probing for .git/config exposure
  Status: Blacklisted (1 hits)

継続隔離中

- 20.78.158.176
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 135.119.47.58
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 94.143.139.248
  WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
  Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

common_security.txt 更新判断

- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
  - 20.78.158.176
  - 135.119.47.58
  - 94.143.139.248

運用補足

- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-07-24 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います

分析メモ

- 本日新規隔離は .env 露出確認 2 件、不審 PHP 探索 2 件、.git/config 露出確認 1 件で、探索初動の整理が中心でした
- 94.143.231.161 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 3 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、再出現の可能性がある
[2026-07-23 SOC運用向け]

### Jul 23, 2026 | 4 New IPs Quarantined

本日の新規隔離は 4 件でした。2026-07-23 時点で当日日報内に再犯として確認できた継続隔離中のIPは 3 件です。

本日新規隔離

- 203.25.124.74
  WHOIS Info: Transferred to the RIPE region on 2020-09-24T09:24:29Z., ZZ, Abuse Contact, Allocated
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (167 hits)

- 172.202.100.37
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (244 hits)

- 20.100.176.141
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (32 hits)

- 20.10.203.190
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (99 hits)

継続隔離中

- 20.78.158.176
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 135.119.47.58
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 94.143.139.248
  WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
  Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

common_security.txt 更新判断

- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
  - 20.78.158.176
  - 135.119.47.58
  - 94.143.139.248

運用補足

- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-07-23 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います

分析メモ

- 本日新規隔離は 不審 PHP 探索 4 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 3 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、再出現の可能性がある
[2026-07-21 SOC運用向け]

### Jul 21, 2026 | 2 New IPs Quarantined

本日の新規隔離は 2 件でした。2026-07-21 時点で当日日報内に再犯として確認できた継続隔離中のIPは 3 件です。

本日新規隔離

- 35.190.144.148
  WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
  Comment: [Fingerprinting] probing for exposed backup, archive, and database dump files
  Status: Blacklisted (2 hits)

- 206.81.12.187
  WHOIS Info: DigitalOcean, LLC, LLC, Abuse Contact, Abuse Contact, Digit19-Arin, Allocated
  Comment: [Auth Attack] probing login and admin entry points
  Status: Blacklisted (5 hits)

継続隔離中

- 20.78.158.176
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 135.119.47.58
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 94.143.139.248
  WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
  Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

common_security.txt 更新判断

- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
  - 20.78.158.176
  - 135.119.47.58
  - 94.143.139.248

運用補足

- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-07-21 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います

分析メモ

- 本日新規隔離は バックアップ/DBダンプ探索 1 件、認証系探索 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 3 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、再出現の可能性がある
[2026-07-20 SOC運用向け]

### Jul 20, 2026 | 4 New IPs Quarantined

本日の新規隔離は 4 件でした。2026-07-20 時点で当日日報内に再犯として確認できた継続隔離中のIPは 3 件です。

本日新規隔離

- 20.12.214.177
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (27 hits)

- 35.242.232.108
  WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
  Comment: [Fingerprinting] probing for .env and related exposed files
  Status: Blacklisted (24 hits)

- 136.115.64.49
  WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
  Comment: [Fingerprinting] probing for .git/config exposure
  Status: Blacklisted (1 hits)

- 23.102.123.231
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Allocated
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (98 hits)

継続隔離中

- 20.78.158.176
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 135.119.47.58
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 94.143.139.248
  WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
  Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

common_security.txt 更新判断

- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
  - 20.78.158.176
  - 135.119.47.58
  - 94.143.139.248

運用補足

- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-07-20 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います

分析メモ

- 本日新規隔離は 不審 PHP 探索 2 件、.env 露出確認 1 件、.git/config 露出確認 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 3 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、再出現の可能性がある
[2026-07-18 SOC運用向け]

### Jul 18, 2026 | 18 New IPs Quarantined

本日の新規隔離は 18 件でした。2026-07-18 時点で当日日報内に再犯として確認できた継続隔離中のIPは 6 件です。

本日新規隔離

- 64.89.160.220
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Fingerprinting] probing for exposed backup, archive, and database dump files
  Status: Blacklisted (14 hits across multiple environments)

- 91.148.245.81
  WHOIS Info: Unknown (Unresolved), NL, Abuse Contact, Allocated
  Comment: [Fingerprinting] probing for exposed backup, archive, and database dump files
  Status: Blacklisted (13 hits)

- 159.89.12.166
  WHOIS Info: DigitalOcean, LLC, LLC (DO-13), Abuse Contact, Digit19-Arin, Legacy
  Comment: [Auth Attack] probing login and admin entry points
  Status: Blacklisted (5 hits)

- 35.243.243.53
  WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
  Comment: [Fingerprinting] probing for .env and related exposed files
  Status: Blacklisted (15 hits)

- 196.65.151.96
  WHOIS Info: ADSL_Maroc_telecom, MA, Unknown (Unresolved), Legacy
  Comment: [Fingerprinting] probing for .env and related exposed files
  Status: Blacklisted (2 hits)

- 31.56.58.124
  WHOIS Info: Zkillu SAS, FR, Abuse Contact, Allocated
  Comment: [Fingerprinting] probing for .git/config exposure
  Status: Blacklisted (4 hits)

- 3.80.153.227
  WHOIS Info: Amazon (AWS), US, Abuse Contact, Legacy
  Comment: [Fingerprinting] probing for .git/config exposure
  Status: Blacklisted (2 hits)

- 34.174.112.118
  WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
  Comment: [Fingerprinting] probing for exposed backup, archive, and database dump files
  Status: Blacklisted (2 hits)

- 54.184.91.239
  WHOIS Info: Amazon (AWS), US, Abuse Contact, Legacy
  Comment: [Fingerprinting] probing for .env and related exposed files
  Status: Blacklisted (293 hits)

- 181.41.206.227
  WHOIS Info: Private Customer, EU, Abuse Contact, Allocated
  Comment: [Fingerprinting] probing for .env and related exposed files
  Status: Blacklisted (3 hits across multiple environments)

- 82.39.206.158
  WHOIS Info: Chunkserve Mateusz Peplinski, PL, Abuse Contact, Allocated
  Comment: [Fingerprinting] probing for .git/config exposure
  Status: Blacklisted (1 hits)

- 20.46.252.52
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (163 hits across multiple environments)

- 20.226.60.151
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (267 hits)

- 20.195.181.252
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (182 hits)

- 158.94.209.225
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Static Deny Applied (6 hits)
  Decision: 危険パスで 200 応答があり、webshell 投下 payload を確認。想定ファイルと同時刻周辺の更新ファイルはサーバー上で未検出。侵害痕跡なしとして static deny 反映済み。

- 103.253.146.145
  WHOIS Info: Digital Ocean, Inc., Abuse Contact, Ad699-Ap, Allocated
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (12 hits)

- 18.232.125.234
  WHOIS Info: Amazon (AWS), US, Abuse Contact, Legacy
  Comment: [Fingerprinting] probing for .env and related exposed files
  Status: Blacklisted (13 hits)

- 20.220.225.223
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (180 hits)

継続隔離中

- 62.197.156.35
  WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
  Comment: [Auth Attack] probing login and admin entry points
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 172.212.217.10
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 20.78.158.176
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 135.119.47.58
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 94.143.139.248
  WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
  Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 191.237.255.150
  WHOIS Info: Microsoft Corporation (Azure), BR, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

common_security.txt 更新判断

- static deny 済み
  - 62.197.156.35
  - 172.212.217.10
  - 191.237.255.150
  - 158.94.209.225
- common_security.txt 追記候補: なし
- runtime quarantine 継続
  - 20.78.158.176
  - 135.119.47.58
  - 94.143.139.248

運用補足

- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-18 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います

分析メモ

- 本日新規隔離は 不審 PHP 探索 6 件、.env 露出確認 5 件、.git/config 露出確認 3 件、バックアップ/DBダンプ探索 3 件、認証系探索 1 件で、探索初動の整理が中心でした
- 158.94.209.225 は Twig/SSTI 経由で `wp-content/uploads/wp-object-check.php` の作成を狙う webshell 投下 payload でした。`wp-object-check.php` / `wp-temp-restore.php` / `wp-cache-validate.php` は未検出で、2026-07-18 16:40-16:50 の更新ファイルもありませんでした
- 64.89.160.220 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 6 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
[2026-07-17 SOC運用向け]

### Jul 17, 2026 | 2 New IPs Quarantined

本日の新規隔離は 2 件でした。2026-07-17 時点で当日日報内に再犯として確認できた継続隔離中のIPは 6 件です。

本日新規隔離

- 103.253.146.145
  WHOIS Info: Digital Ocean, Inc., Abuse Contact, Ad699-Ap, Allocated
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (12 hits)

- 20.220.225.223
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (180 hits)

継続隔離中

- 62.197.156.35
  WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
  Comment: [Auth Attack] probing login and admin entry points
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 172.212.217.10
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 20.78.158.176
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 135.119.47.58
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 94.143.139.248
  WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
  Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 191.237.255.150
  WHOIS Info: Microsoft Corporation (Azure), BR, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

common_security.txt 更新判断

- static deny 済み
  - 62.197.156.35
  - 172.212.217.10
  - 191.237.255.150
- common_security.txt 追記候補: なし
- runtime quarantine 継続
  - 20.78.158.176
  - 135.119.47.58
  - 94.143.139.248

運用補足

- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-17 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います

分析メモ

- 本日新規隔離は 不審 PHP 探索 2 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 6 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
[2026-07-16 SOC運用向け]

### Jul 16, 2026 | 1 New IPs Quarantined

本日の新規隔離は 1 件でした。2026-07-16 時点で当日日報内に再犯として確認できた継続隔離中のIPは 6 件です。

本日新規隔離

- 4.213.167.22
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (153 hits)

継続隔離中

- 62.197.156.35
  WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
  Comment: [Auth Attack] probing login and admin entry points
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 172.212.217.10
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 20.78.158.176
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 135.119.47.58
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 94.143.139.248
  WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
  Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 191.237.255.150
  WHOIS Info: Microsoft Corporation (Azure), BR, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

common_security.txt 更新判断

- static deny 済み
  - 62.197.156.35
  - 172.212.217.10
  - 191.237.255.150
- common_security.txt 追記候補: なし
- runtime quarantine 継続
  - 20.78.158.176
  - 135.119.47.58
  - 94.143.139.248

運用補足

- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-16 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います

分析メモ

- 本日新規隔離は 不審 PHP 探索 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 6 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
[2026-07-15 SOC運用向け]

### Jul 15, 2026 | 1 New IPs Quarantined

本日の新規隔離は 1 件でした。2026-07-15 時点で当日日報内に再犯として確認できた継続隔離中のIPは 6 件です。

本日新規隔離

- 35.243.245.112
  WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
  Comment: [Fingerprinting] probing for exposed backup, archive, and database dump files
  Status: Blacklisted (2 hits)

継続隔離中

- 62.197.156.35
  WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
  Comment: [Auth Attack] probing login and admin entry points
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 172.212.217.10
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 20.78.158.176
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 135.119.47.58
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 94.143.139.248
  WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
  Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 191.237.255.150
  WHOIS Info: Microsoft Corporation (Azure), BR, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

common_security.txt 更新判断

- static deny 済み
  - 62.197.156.35
  - 172.212.217.10
  - 191.237.255.150
- common_security.txt 追記候補: なし
- runtime quarantine 継続
  - 20.78.158.176
  - 135.119.47.58
  - 94.143.139.248

運用補足

- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-15 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います

分析メモ

- 本日新規隔離は バックアップ/DBダンプ探索 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 6 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
本日の新規隔離は 3 件でした。2026-07-14 時点で当日日報内に再犯として確認できた継続隔離中のIPは 6 件です。

本日新規隔離

- 191.237.250.106
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (281 hits)

- 20.220.9.199
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (141 hits)

- 20.151.205.204
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (140 hits)

継続隔離中

- 62.197.156.35
  WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
  Comment: [Auth Attack] probing login and admin entry points
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 172.212.217.10
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 20.78.158.176
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 135.119.47.58
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 94.143.139.248
  WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
  Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 191.237.255.150
  WHOIS Info: Microsoft Corporation (Azure), BR, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

common_security.txt 更新判断

- static deny 済み
  - 62.197.156.35
  - 172.212.217.10
  - 191.237.255.150
- common_security.txt 追記候補: なし
- runtime quarantine 継続
  - 20.78.158.176
  - 135.119.47.58
  - 94.143.139.248

運用補足

- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-14 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います

分析メモ

- 本日新規隔離は 不審 PHP 探索 3 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 6 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
本日の新規隔離は 10 件でした。2026-07-13 時点で当日日報内に再犯として確認できた継続隔離中のIPは 6 件です。

本日新規隔離

- 34.53.116.212
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Fingerprinting] probing for exposed backup, archive, and database dump files
  Status: Blacklisted (2 hits)

- 158.173.77.46
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (11 hits across multiple environments)

- 20.226.26.5
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (277 hits)

- 20.220.9.199
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (281 hits)

- 20.48.236.161
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (594 hits across multiple environments)

- 188.166.99.91
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Fingerprinting] probing for .git/config exposure
  Status: Blacklisted (1 hits)

- 206.123.156.179
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Auth Attack] probing XML-RPC entry points
  Status: Blacklisted (10 hits)

- 81.171.74.60
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Fingerprinting] probing for exposed backup, archive, and database dump files
  Status: Blacklisted (13 hits)

- 178.128.57.200
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Auth Attack] probing login and admin entry points
  Status: Blacklisted (12 hits)

- 168.110.218.47
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Fingerprinting] probing for .env and related exposed files
  Status: Blacklisted (49 hits)

継続隔離中

- 62.197.156.35
  WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
  Comment: [Auth Attack] probing login and admin entry points
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 172.212.217.10
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 20.78.158.176
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 135.119.47.58
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 94.143.139.248
  WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
  Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 191.237.255.150
  WHOIS Info: Microsoft Corporation (Azure), BR, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

common_security.txt 更新判断

- static deny 済み
  - 62.197.156.35
  - 172.212.217.10
  - 191.237.255.150
- common_security.txt 追記候補: なし
- runtime quarantine 継続
  - 20.78.158.176
  - 135.119.47.58
  - 94.143.139.248

運用補足

- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-13 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います

分析メモ

- 本日新規隔離は 不審 PHP 探索 4 件、バックアップ/DBダンプ探索 2 件、認証系探索 2 件、.env 露出確認 1 件、.git/config 露出確認 1 件で、探索初動の整理が中心でした
- 158.173.77.46 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 6 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
本日の新規隔離は 4 件でした。2026-07-12 時点で当日日報内に再犯として確認できた継続隔離中のIPは 6 件です。

本日新規隔離

- 140.248.75.183
  WHOIS Info: Fastly, Inc. (SKYCA-3), Abuse Contact, Abuse4771-Arin, Legacy
  Comment: [Fingerprinting] probing for .git/config exposure
  Status: Blacklisted (1 hits)

- 94.143.139.248
  WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
  Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
  Status: Blacklisted (22 hits)

- 157.52.122.49
  WHOIS Info: Fastly, Inc. (SKYCA-3), Abuse Contact, Abuse4771-Arin, Legacy
  Comment: [Fingerprinting] probing for .git/config exposure
  Status: Blacklisted (1 hits)

- 35.236.130.189
  WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
  Comment: [Fingerprinting] probing for .git/config exposure
  Status: Blacklisted (1 hits)

継続隔離中

- 62.197.156.35
  WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
  Comment: [Auth Attack] probing login and admin entry points
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 172.212.217.10
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 20.78.158.176
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 135.119.47.58
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 94.143.139.248
  WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
  Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 191.237.255.150
  WHOIS Info: Microsoft Corporation (Azure), BR, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

common_security.txt 更新判断

- static deny 済み
  - 62.197.156.35
  - 172.212.217.10
  - 191.237.255.150
- common_security.txt 追記候補: なし
- runtime quarantine 継続
  - 20.78.158.176
  - 135.119.47.58
  - 94.143.139.248

運用補足

- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-12 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います

分析メモ

- 本日新規隔離は .git/config 露出確認 3 件、WordPress 設定露出探索 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 6 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
本日の新規隔離は 1 件でした。2026-07-11 時点で当日日報内に再犯として確認できた継続隔離中のIPは 5 件です。

本日新規隔離

- 157.52.122.74
  WHOIS Info: Fastly, Inc. (SKYCA-3), Abuse Contact, Abuse4771-Arin, Legacy
  Comment: [Fingerprinting] probing for .git/config exposure
  Status: Blacklisted (1 hits)

継続隔離中

- 62.197.156.35
  WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
  Comment: [Auth Attack] probing login and admin entry points
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 172.212.217.10
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 20.78.158.176
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 135.119.47.58
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 191.237.255.150
  WHOIS Info: Microsoft Corporation (Azure), BR, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

common_security.txt 更新判断

- static deny 済み
  - 62.197.156.35
  - 172.212.217.10
  - 191.237.255.150
- common_security.txt 追記候補: なし
- runtime quarantine 継続
  - 20.78.158.176
  - 135.119.47.58

運用補足

- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-11 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います

分析メモ

- 本日新規隔離は .git/config 露出確認 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 5 IP は不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
本日の新規隔離は 12 件でした。2026-07-10 時点で当日日報内に再犯として確認できた継続隔離中のIPは 6 件です。

本日新規隔離

- 85.11.167.242
  WHOIS Info: TechTies Inc., NL, Abuse Contact, Allocated
  Comment: [Auth Attack] probing login and admin entry points
  Status: Blacklisted (19 hits)

- 153.239.163.134
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Auth Attack] probing login and admin entry points
  Status: Blacklisted (7 hits across multiple environments)

- 20.195.178.90
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (279 hits)

- 156.146.39.52
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Fingerprinting] probing for .env and related exposed files
  Status: Blacklisted (2 hits across multiple environments)

- 54.241.202.114
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Fingerprinting] probing for exposed backup, archive, and database dump files
  Status: Blacklisted (6 hits)

- 81.199.26.100
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Fingerprinting] probing for .env and related exposed files
  Status: Blacklisted (1 hits)

- 34.71.105.137
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Fingerprinting] probing for .git/config exposure
  Status: Blacklisted (1 hits)

- 144.172.103.251
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Fingerprinting] probing for .git/config exposure
  Status: Blacklisted (1 hits)

- 20.220.212.5
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (419 hits)

- 66.171.162.195
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Fingerprinting] probing for exposed backup, archive, and database dump files
  Status: Blacklisted (3 hits)

- 191.237.255.150
  WHOIS Info: Microsoft Corporation (Azure), BR, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (42 hits)

- 157.52.122.75
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Fingerprinting] probing for .git/config exposure
  Status: Blacklisted (1 hits)

継続隔離中

- 62.197.156.35
  WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
  Comment: [Auth Attack] probing login and admin entry points
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 172.212.217.10
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 20.78.158.176
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 135.119.47.58
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 94.143.139.248
  WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
  Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 191.237.255.150
  WHOIS Info: Microsoft Corporation (Azure), BR, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

common_security.txt 更新判断

- static deny 済み
  - 62.197.156.35
  - 172.212.217.10
  - 191.237.255.150
- common_security.txt 追記候補: なし
- runtime quarantine 継続
  - 20.78.158.176
  - 135.119.47.58
  - 94.143.139.248

運用補足

- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-10 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います

分析メモ

- 本日新規隔離は .git/config 露出確認 3 件、不審 PHP 探索 3 件、.env 露出確認 2 件、バックアップ/DBダンプ探索 2 件、認証系探索 2 件で、探索初動の整理が中心でした
- 153.239.163.134 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 6 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
本日の新規隔離は 8 件でした。2026-07-09 時点で当日日報内に再犯として確認できた継続隔離中のIPは 5 件です。

本日新規隔離

- 191.237.255.150
  WHOIS Info: Microsoft Corporation (Azure), BR, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (100 hits)

- 47.108.20.158
  WHOIS Info: Asia Pacific Network Information Centre (APNIC), AU, Abuse Contact, Legacy
  Comment: [Auth Attack] probing login and admin entry points
  Status: Blacklisted (6 hits across multiple environments)

- 130.12.182.12
  WHOIS Info: Netiface LLC (NL-846), US, Abuse Contact, Legacy
  Comment: [Fingerprinting] probing for .env and related exposed files
  Status: Blacklisted (1 hits)

- 20.197.60.102
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (417 hits)

- 20.48.255.163
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (52 hits)

- 195.178.110.18
  WHOIS Info: TECHOFF SRV LIMITED, AD, Abuse Contact, Allocated
  Comment: [Fingerprinting] probing for .git/config exposure
  Status: Blacklisted (1 hits)

- 40.115.138.243
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (152 hits)

- 62.60.130.233
  WHOIS Info: CIPHER OPERATIONS DOO BEOGRAD - NOVI BEOGRAD, GB, Abuse Contact, Allocated
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (12 hits)

継続隔離中

- 62.197.156.35
  WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
  Comment: [Auth Attack] probing login and admin entry points
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 172.212.217.10
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 20.78.158.176
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 135.119.47.58
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 191.237.255.150
  WHOIS Info: Microsoft Corporation (Azure), BR, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

common_security.txt 更新判断

- static deny 済み
  - 62.197.156.35
  - 172.212.217.10
- common_security.txt 追記候補: なし
- runtime quarantine 継続
  - 20.78.158.176
  - 135.119.47.58
  - 191.237.255.150

運用補足

- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-09 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います

分析メモ

- 本日新規隔離は 不審 PHP 探索 5 件、.env 露出確認 1 件、.git/config 露出確認 1 件、認証系探索 1 件で、探索初動の整理が中心でした
- 47.108.20.158 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 5 IP は不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
本日の新規隔離は 6 件でした。2026-07-08 時点で当日日報内に再犯として確認できた継続隔離中のIPは 4 件です。

本日新規隔離

- 52.231.76.18
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (277 hits)

- 20.46.177.15
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (269 hits)

- 158.94.210.233
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Fingerprinting] probing for .env and related exposed files
  Status: Blacklisted (225 hits)

- 20.205.32.154
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (268 hits)

- 191.237.255.150
  WHOIS Info: Microsoft Corporation (Azure), BR, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (60 hits)

- 20.89.242.68
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (152 hits)

継続隔離中

- 62.197.156.35
  WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
  Comment: [Auth Attack] probing login and admin entry points
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 172.212.217.10
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 20.78.158.176
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 135.119.47.58
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

common_security.txt 更新判断

- static deny 済み
  - 62.197.156.35
  - 172.212.217.10
- common_security.txt 追記候補: なし
- runtime quarantine 継続
  - 20.78.158.176
  - 135.119.47.58

運用補足

- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-08 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います

分析メモ

- 本日新規隔離は 不審 PHP 探索 5 件、.env 露出確認 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 4 IP は不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
本日の新規隔離は 17 件でした。2026-07-07 時点で当日日報内に再犯として確認できた継続隔離中のIPは 6 件です。

本日新規隔離

- 158.94.210.233
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Fingerprinting] probing for .env and related exposed files
  Status: Blacklisted (239 hits)

- 64.89.160.220
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (25 hits across multiple environments)

- 52.253.101.220
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (246 hits)

- 40.115.140.72
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (284 hits across multiple environments)

- 152.53.54.209
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Auth Attack] probing login and admin entry points
  Status: Blacklisted (17 hits across multiple environments)

- 20.198.90.154
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (275 hits)

- 8.231.134.21
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Fingerprinting] probing for exposed backup, archive, and database dump files
  Status: Blacklisted (2 hits)

- 40.74.69.175
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (182 hits)

- 191.237.255.150
  WHOIS Info: Microsoft Corporation (Azure), BR, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (114 hits across multiple environments)

- 162.243.79.174
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Fingerprinting] probing for .env and related exposed files
  Status: Blacklisted (2 hits)

- 94.154.43.177
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Fingerprinting] probing for .env and related exposed files
  Status: Blacklisted (1 hits)

- 20.235.127.11
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (245 hits)

- 153.75.89.214
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
  Status: Blacklisted (2 hits across multiple environments)

- 41.143.156.66
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Fingerprinting] probing for .env and related exposed files
  Status: Blacklisted (2 hits)

- 20.89.248.158
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (138 hits)

- 20.214.163.77
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (275 hits)

- 94.154.43.185
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved)
  Comment: [Fingerprinting] probing for .env and related exposed files
  Status: Blacklisted (1 hits)

継続隔離中

- 62.197.156.35
  WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
  Comment: [Auth Attack] probing login and admin entry points
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 172.212.217.10
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 20.78.158.176
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 135.119.47.58
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 94.143.139.248
  WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
  Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 191.237.255.150
  WHOIS Info: Microsoft Corporation (Azure), BR, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

common_security.txt 更新判断

- static deny 済み
  - 62.197.156.35
  - 172.212.217.10
  - 191.237.255.150
- common_security.txt 追記候補: なし
- runtime quarantine 継続
  - 20.78.158.176
  - 135.119.47.58
  - 94.143.139.248

運用補足

- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-07 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います

分析メモ

- 本日新規隔離は 不審 PHP 探索 9 件、.env 露出確認 5 件、WordPress 設定露出探索 1 件、バックアップ/DBダンプ探索 1 件、認証系探索 1 件で、探索初動の整理が中心でした
- 64.89.160.220 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 6 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
本日の新規隔離は 4 件でした。2026-07-06 時点で当日日報内に再犯として確認できた継続隔離中のIPは 4 件です。

本日新規隔離

- 20.226.80.53
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (140 hits)

- 20.63.42.26
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (278 hits)

- 162.243.170.185
  WHOIS Info: DigitalOcean, LLC, LLC (DO-13), Abuse Contact, Digit19-Arin, Legacy
  Comment: [Fingerprinting] probing for .env and related exposed files
  Status: Blacklisted (1 hits)

- 20.24.203.130
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (71 hits)

継続隔離中

- 62.197.156.35
  WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
  Comment: [Auth Attack] probing login and admin entry points
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 172.212.217.10
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 20.78.158.176
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 135.119.47.58
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

common_security.txt 更新判断

- static deny 済み
  - 62.197.156.35
  - 172.212.217.10
- common_security.txt 追記候補: なし
- runtime quarantine 継続
  - 20.78.158.176
  - 135.119.47.58

運用補足

- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-06 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います

分析メモ

- 本日新規隔離は 不審 PHP 探索 3 件、.env 露出確認 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 4 IP は不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
本日の新規隔離は 1 件でした。2026-07-05 時点で当日日報内に再犯として確認できた継続隔離中のIPは 4 件です。

本日新規隔離

- 51.103.130.248
  WHOIS Info: Microsoft Corporation (Azure), EU, Unknown (Unresolved), Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (251 hits)

継続隔離中

- 62.197.156.35
  WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
  Comment: [Auth Attack] probing login and admin entry points
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 172.212.217.10
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 20.78.158.176
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 135.119.47.58
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

common_security.txt 更新判断

- static deny 済み
  - 62.197.156.35
  - 172.212.217.10
- common_security.txt 追記候補: なし
- runtime quarantine 継続
  - 20.78.158.176
  - 135.119.47.58

運用補足

- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-05 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います

分析メモ

- 本日新規隔離は 不審 PHP 探索 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 4 IP は不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
本日の新規隔離は 3 件でした。2026-07-04 時点で当日日報内に再犯として確認できた継続隔離中のIPは 4 件です。

本日新規隔離

- 185.150.0.143
  WHOIS Info: VPN Consumer Singapore, Republic of Singapore, Abuse Contact, Vcar3-Ripe, Allocated
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (4 hits across multiple environments)

- 52.138.1.81
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (91 hits)

- 170.64.180.91
  WHOIS Info: DigitalOcean, LLC, LLC (DO-13), Abuse Contact, Digit19-Arin, Legacy
  Comment: [Fingerprinting] probing for .git/config exposure
  Status: Blacklisted (2 hits)

継続隔離中

- 62.197.156.35
  WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
  Comment: [Auth Attack] probing login and admin entry points
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 172.212.217.10
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 20.78.158.176
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 135.119.47.58
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

common_security.txt 更新判断

- static deny 済み
  - 62.197.156.35
  - 172.212.217.10
- common_security.txt 追記候補: なし
- runtime quarantine 継続
  - 20.78.158.176
  - 135.119.47.58

運用補足

- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-04 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います

分析メモ

- 本日新規隔離は 不審 PHP 探索 2 件、.git/config 露出確認 1 件で、探索初動の整理が中心でした
- 185.150.0.143 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 4 IP は不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
本日の新規隔離は 5 件でした。2026-07-03 時点で当日日報内に再犯として確認できた継続隔離中のIPは 4 件です。

本日新規隔離

- 20.243.184.229
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Auth Attack] probing XML-RPC entry points
  Status: Blacklisted (6 hits across multiple environments)

- 35.185.141.157
  WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
  Comment: [Fingerprinting] probing for .git/config exposure
  Status: Blacklisted (1 hits)

- 40.83.92.182
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (32 hits)

- 20.210.248.27
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (99 hits)

- 94.143.139.248
  WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (2 hits)

継続隔離中

- 62.197.156.35
  WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
  Comment: [Auth Attack] probing login and admin entry points
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 172.212.217.10
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 20.78.158.176
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 135.119.47.58
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

common_security.txt 更新判断

- static deny 済み
  - 62.197.156.35
  - 172.212.217.10
- common_security.txt 追記候補: なし
- runtime quarantine 継続
  - 20.78.158.176
  - 135.119.47.58

運用補足

- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-03 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います

分析メモ

- 本日新規隔離は 不審 PHP 探索 3 件、.git/config 露出確認 1 件、認証系探索 1 件で、探索初動の整理が中心でした
- 20.243.184.229 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 4 IP は不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
本日の新規隔離は 4 件でした。2026-07-02 時点で当日日報内に再犯として確認できた継続隔離中のIPは 4 件です。

本日新規隔離

- 78.189.24.202
  WHOIS Info: TT ADSL-TTnet alcatel static_aci, tr, Abuse Contact, Allocated
  Comment: [Fingerprinting] probing for .env and related exposed files
  Status: Blacklisted (49 hits)

- 67.205.147.135
  WHOIS Info: DigitalOcean, LLC, LLC (DO-13), Abuse Contact, Digit19-Arin, Allocated
  Comment: [Fingerprinting] probing for .git/config exposure
  Status: Blacklisted (2 hits)

- 34.133.214.222
  WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
  Comment: [Fingerprinting] probing for .git/config exposure
  Status: Blacklisted (1 hits)

- 52.184.100.96
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (93 hits)

継続隔離中

- 62.197.156.35
  WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
  Comment: [Auth Attack] probing login and admin entry points
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 172.212.217.10
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 20.78.158.176
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 135.119.47.58
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

common_security.txt 更新判断

- static deny 済み
  - 62.197.156.35
  - 172.212.217.10
- common_security.txt 追記候補: なし
- runtime quarantine 継続
  - 20.78.158.176
  - 135.119.47.58

運用補足

- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-02 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います

分析メモ

- 本日新規隔離は .git/config 露出確認 2 件、.env 露出確認 1 件、不審 PHP 探索 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 4 IP は不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
本日の新規隔離は 5 件でした。2026-07-01 時点で当日日報内に再犯として確認できた継続隔離中のIPは 4 件です。

本日新規隔離

- 20.89.237.101
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (289 hits)

- 20.220.14.153
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (95 hits)

- 181.41.206.215
  WHOIS Info: Unknown (Unresolved), Unknown (Unresolved), Unknown (Unresolved), Allocated
  Comment: [Fingerprinting] probing for .env and related exposed files
  Status: Blacklisted (1 hits)

- 20.220.223.15
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Blacklisted (147 hits)

- 45.55.71.64
  WHOIS Info: DigitalOcean, LLC, LLC (DO-13), Abuse Contact, Digit19-Arin, Legacy
  Comment: [Auth Attack] probing login and admin entry points
  Status: Blacklisted (8 hits)

継続隔離中

- 62.197.156.35
  WHOIS Info: Cyberzon S.A, SG, Abuse Contact, Data Center/Web Hosting/Transit
  Comment: [Auth Attack] probing login and admin entry points
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 172.212.217.10
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Early Registrations / Transferred to RIPE NCC
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Static Deny Applied
  Decision: common_security.txt 反映済み。サーバー側 .htaccess 反映確認のみ。

- 20.78.158.176
  WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

- 135.119.47.58
  WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
  Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
  Status: Runtime Quarantine Only
  Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。

common_security.txt 更新判断

- static deny 済み
  - 62.197.156.35
  - 172.212.217.10
- common_security.txt 追記候補: なし
- runtime quarantine 継続
  - 20.78.158.176
  - 135.119.47.58

運用補足

- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- 本日新規隔離は 2026-07-01 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯または継続遮断が確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います

分析メモ

- 本日新規隔離は 不審 PHP 探索 3 件、.env 露出確認 1 件、認証系探索 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 4 IP は不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
よかったらシェアしてね!
  • URLをコピーしました!
  • URLをコピーしました!

この記事を書いた人

のいのアバター のい UNIX Cafe マスター

Macintosh Color Classicから始まった旅は、長いWindows時代を経て、Windows10のサポート終了をきっかけにUNIXの世界へ戻ってきました。UNIX Cafeでは、UNIX・Linux・そしてMacな世界を、むずかしい言葉を使わず、物語のように書いています。プログラミングは、アイデアをコンピューターに伝えるための言葉です。簡単な単語と文法を覚えれば、誰でもコマンドを使えます。ぜひ一度、やさしいプログラミングの世界をのぞいてみてください。

目次