System Note
$ cat /proc/ai-disclosure
本記事の構成および論理分析にはAI(人工知能)を使用しています。情報の正確性は、システム管理者(UNIXユーザー)による手動検証済みです。
* 当サイトでは、コンテンツの一部に広告を掲載しています。
本記事の構成および論理分析にはAI(人工知能)を使用しています。情報の正確性は、システム管理者(UNIXユーザー)による手動検証済みです。

2026年5月より、セキュリティ日報の掲載フォーマットを見直しました。これまでのインシデントログ中心の形式から、当日に新規隔離したIPと継続隔離中のIPを分かりやすく整理した、SOC運用向けの一覧形式へ変更しています。
新しい形式では、WHOIS情報、攻撃種別、遮断状況を中心に、必要な情報を簡潔に確認できる構成に統一しました。また、記事内では個別サイト名や内部運用向けの詳細パラメータは掲載せず、複数サイトにまたがるアクセスは「複数の管理環境」として表記する運用に変更しています。
この見直しにより、日々の観測傾向や継続的な不審アクセスの把握を、以前より短時間で確認しやすくなりました。
[2026-08-31 SOC運用向け]
### Aug 31, 2026 | 2 New IPs Quarantined
本日の新規隔離は 2 件でした。2026-08-31 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 8 件です。
本日新規隔離
- 4.204.224.164
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (243 hits)
- 34.130.66.222
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (247 hits)
継続隔離中
- 135.119.47.58
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 116.202.252.125
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/116.202.252.125
WHOIS Info: Transferred to the RIPE region on 2018-08-28T00:42:30Z., ZZ, Abuse Contact, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.169.16.7
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.169.16.7
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.48.147.90
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.48.147.90
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.104.18.15
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.104.18.15
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 146.190.211.127
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/146.190.211.127
WHOIS Info: DigitalOcean, LLC, LLC, Abuse Contact, Abuse Contact, Abuse Contact, Abuse Contact, Abuse Contact, Abuse Contact, Digit19-Arin, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- 監視継続
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
- 116.202.252.125
- 20.169.16.7
- 20.48.147.90
- 20.104.18.15
- 146.190.211.127
運用補足
- common_security.txt はローカルで更新後、サーバーへ転送して update_htaccess.sh で一斉配信します
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-08-31 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は .env 露出確認 1 件、不審 PHP 探索 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 8 IP は.git/config 露出確認とWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
[2026-08-30 SOC運用向け]
### Aug 30, 2026 | 13 New IPs Quarantined
本日の新規隔離は 13 件でした。2026-08-30 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 8 件です。
本日新規隔離
- 84.246.212.174
WHOIS Info: AXARNET COMUNICACIONES, S.L., Abuse Contact, Abit11-Ripe, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Blacklisted (4 hits across multiple environments)
- 193.70.46.29
WHOIS Info: OVH SAS, FR, Abuse Contact, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Blacklisted (11 hits across multiple environments)
- 172.93.101.38
WHOIS Info: ReliableSite.Net LLC (RL-323), US, Abuse Contact, Legacy
Comment: [Auth Attack] probing login and admin entry points
Status: Blacklisted (4 hits across multiple environments)
- 35.201.239.244
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (79 hits)
- 54.90.130.223
WHOIS Info: Amazon (AWS), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (14 hits)
- 20.151.200.44
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.151.200.44
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (119 hits across multiple environments)
- 34.74.115.242
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (19 hits)
- 34.134.58.178
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (19 hits)
- 185.19.40.47
WHOIS Info: 1337 Services GmbH, RO, Abuse Contact, Allocated
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (68 hits)
- 146.190.211.127
WHOIS Info: DigitalOcean, LLC, LLC, Abuse Contact, Abuse Contact, Abuse Contact, Abuse Contact, Abuse Contact, Digit19-Arin, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (2 hits)
- 34.150.117.71
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (24 hits)
- 34.9.246.55
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (19 hits)
- 35.190.146.131
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (19 hits)
継続隔離中
- 135.119.47.58
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 116.202.252.125
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/116.202.252.125
WHOIS Info: Transferred to the RIPE region on 2018-08-28T00:42:30Z., ZZ, Abuse Contact, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.169.16.7
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.169.16.7
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.48.147.90
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.48.147.90
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.104.18.15
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.104.18.15
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 146.190.211.127
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/146.190.211.127
WHOIS Info: DigitalOcean, LLC, LLC, Abuse Contact, Abuse Contact, Abuse Contact, Abuse Contact, Abuse Contact, Digit19-Arin, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- 監視継続
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
- 116.202.252.125
- 20.169.16.7
- 20.48.147.90
- 20.104.18.15
- 146.190.211.127
運用補足
- common_security.txt はローカルで更新後、サーバーへ転送して update_htaccess.sh で一斉配信します
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-08-30 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は .env 露出確認 7 件、認証系探索 3 件、.git/config 露出確認 2 件、不審 PHP 探索 1 件で、探索初動の整理が中心でした
- 84.246.212.174 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 8 IP は.git/config 露出確認とWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
[2026-08-29 SOC運用向け]
### Aug 29, 2026 | 4 New IPs Quarantined
本日の新規隔離は 4 件でした。2026-08-29 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 7 件です。
本日新規隔離
- 54.90.130.223
WHOIS Info: Amazon (AWS), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (14 hits)
- 34.134.58.178
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (19 hits)
- 34.9.246.55
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (19 hits)
- 35.190.146.131
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (19 hits)
継続隔離中
- 135.119.47.58
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 116.202.252.125
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/116.202.252.125
WHOIS Info: Transferred to the RIPE region on 2018-08-28T00:42:30Z., ZZ, Abuse Contact, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.169.16.7
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.169.16.7
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.48.147.90
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.48.147.90
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.104.18.15
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.104.18.15
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- 監視継続
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
- 116.202.252.125
- 20.169.16.7
- 20.48.147.90
- 20.104.18.15
運用補足
- common_security.txt はローカルで更新後、サーバーへ転送して update_htaccess.sh で一斉配信します
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-08-29 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は .env 露出確認 4 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 7 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
[2026-08-28 SOC運用向け]
### Aug 28, 2026 | 5 New IPs Quarantined
本日の新規隔離は 5 件でした。2026-08-28 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 7 件です。
本日新規隔離
- 34.246.185.237
WHOIS Info: Amazon (AWS), US, Abuse Contact, Legacy
Comment: [Auth Attack] probing login and admin entry points
Status: Blacklisted (14 hits)
- 20.48.179.39
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (196 hits)
- 34.73.30.5
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (24 hits)
- 136.114.6.248
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (19 hits)
- 104.196.53.55
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Allocated
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (59 hits)
継続隔離中
- 135.119.47.58
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 116.202.252.125
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/116.202.252.125
WHOIS Info: Transferred to the RIPE region on 2018-08-28T00:42:30Z., ZZ, Abuse Contact, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.169.16.7
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.169.16.7
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.48.147.90
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.48.147.90
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.104.18.15
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.104.18.15
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- 監視継続
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
- 116.202.252.125
- 20.169.16.7
- 20.48.147.90
- 20.104.18.15
運用補足
- common_security.txt はローカルで更新後、サーバーへ転送して update_htaccess.sh で一斉配信します
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-08-28 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は .env 露出確認 2 件、.git/config 露出確認 1 件、不審 PHP 探索 1 件、認証系探索 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 7 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
[2026-08-27 SOC運用向け]
### Aug 27, 2026 | 9 New IPs Quarantined
本日の新規隔離は 9 件でした。2026-08-27 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 7 件です。
本日新規隔離
- 158.23.184.117
WHOIS Info: Asia Pacific Network Information Centre (APNIC), AU, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (51 hits)
- 148.72.244.235
WHOIS Info: GoDaddy.com, LLC (GODAD), Abuse Contact, Abuse51-Arin, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (14 hits)
- 40.85.222.29
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (176 hits)
- 20.104.104.62
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (276 hits)
- 20.48.251.3
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (436 hits)
- 161.118.226.254
WHOIS Info: Asia Pacific Network Information Centre (APNIC), AU, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (8 hits across multiple environments)
- 20.104.50.220
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.104.50.220
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (176 hits across multiple environments)
- 34.87.137.171
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (2 hits)
- 20.104.18.15
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (88 hits)
継続隔離中
- 135.119.47.58
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 116.202.252.125
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/116.202.252.125
WHOIS Info: Transferred to the RIPE region on 2018-08-28T00:42:30Z., ZZ, Abuse Contact, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.169.16.7
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.169.16.7
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.48.147.90
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.48.147.90
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.104.18.15
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.104.18.15
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- 監視継続
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
- 116.202.252.125
- 20.169.16.7
- 20.48.147.90
- 20.104.18.15
運用補足
- common_security.txt はローカルで更新後、サーバーへ転送して update_htaccess.sh で一斉配信します
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-08-27 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 8 件、.git/config 露出確認 1 件で、探索初動の整理が中心でした
- 161.118.226.254 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 7 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
[2026-08-26 SOC運用向け]
### Aug 26, 2026 | 11 New IPs Quarantined
本日の新規隔離は 11 件でした。2026-08-26 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 6 件です。
本日新規隔離
- 198.199.82.222
WHOIS Info: DigitalOcean, LLC, LLC (DO-13), Abuse Contact, Digit19-Arin, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (2 hits)
- 192.241.171.92
WHOIS Info: DigitalOcean, LLC, LLC (DO-13), Abuse Contact, Digit19-Arin, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (2 hits)
- 20.104.87.97
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (295 hits)
- 20.104.86.241
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (210 hits)
- 20.48.163.91
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (295 hits)
- 104.23.229.130
WHOIS Info: Cloudflare, Inc. (CLOUD14), Abuse Contact, Abuse2916-Arin, Allocated
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (1 hits)
- 20.48.147.90
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (148 hits)
- 20.104.18.15
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (126 hits)
- 68.155.159.216
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Allocated
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (325 hits)
- 146.190.211.127
WHOIS Info: DigitalOcean, LLC, LLC (DO-13), Abuse Contact, Digit19-Arin, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (4 hits)
- 52.139.44.162
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (73 hits)
継続隔離中
- 135.119.47.58
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 116.202.252.125
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/116.202.252.125
WHOIS Info: Transferred to the RIPE region on 2018-08-28T00:42:30Z., ZZ, Abuse Contact, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.169.16.7
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.169.16.7
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
- 20.48.147.90
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/20.48.147.90
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Monitor Only
Decision: 現時点では監視継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- 監視継続
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
- 116.202.252.125
- 20.169.16.7
- 20.48.147.90
運用補足
- common_security.txt はローカルで更新後、サーバーへ転送して update_htaccess.sh で一斉配信します
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-08-26 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 7 件、.git/config 露出確認 3 件、.env 露出確認 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 6 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
[2026-08-24 SOC運用向け]
### Aug 24, 2026 | 4 New IPs Quarantined
本日の新規隔離は 4 件でした。2026-08-24 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 20.48.147.90
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (217 hits)
- 84.239.42.25
WHOIS Info: ORIGIN INTERNET NETWORK, GB, Unknown (Unresolved), Allocated
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (2 hits)
- 194.33.44.39
WHOIS Info: ExpressVPN, IM, Abuse Contact, Allocated
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (2 hits)
- 170.64.223.193
WHOIS Info: DigitalOcean, LLC, LLC (DO-13), Abuse Contact, Digit19-Arin, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (2 hits)
継続隔離中
- 135.119.47.58
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 116.202.252.125
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/116.202.252.125
WHOIS Info: Transferred to the RIPE region on 2018-08-28T00:42:30Z., ZZ, Abuse Contact, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
- 116.202.252.125
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-08-24 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
- 手動監視帯 20.151.9.0/24 では 20.151.9.127 を 1 回観測しました。単発のログイン探索として監視継続とします
分析メモ
- 本日新規隔離は .git/config 露出確認 3 件、不審 PHP 探索 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
- 手動監視帯の単発観測は現時点で隔離件数には含めず、同一帯から翌日以降も継続する場合に CIDR 昇格候補として確認する[2026-08-23 SOC運用向け]
### Aug 23, 2026 | 2 New IPs Quarantined
本日の新規隔離は 2 件でした。2026-08-23 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 20.203.162.73
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (161 hits)
- 20.151.141.175
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (4 hits across multiple environments)
継続隔離中
- 135.119.47.58
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 116.202.252.125
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/116.202.252.125
WHOIS Info: Transferred to the RIPE region on 2018-08-28T00:42:30Z., ZZ, Abuse Contact, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
- 116.202.252.125
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-08-23 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 2 件で、探索初動の整理が中心でした
- 20.151.141.175 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
[2026-08-22 SOC運用向け]
### Aug 22, 2026 | 5 New IPs Quarantined
本日の新規隔離は 5 件でした。2026-08-22 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 104.23.225.88
WHOIS Info: Cloudflare, Inc. (CLOUD14), Abuse Contact, Abuse2916-Arin, Allocated
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (1 hits)
- 35.231.135.223
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (46 hits)
- 34.59.202.31
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (39 hits)
- 34.23.120.252
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (1 hits)
- 20.151.129.194
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (168 hits)
継続隔離中
- 135.119.47.58
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 116.202.252.125
AbuseIPDB 個別照会: https://www.abuseipdb.com/check/116.202.252.125
WHOIS Info: Transferred to the RIPE region on 2018-08-28T00:42:30Z., ZZ, Abuse Contact, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
- 116.202.252.125
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-08-22 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は .env 露出確認 2 件、.git/config 露出確認 2 件、不審 PHP 探索 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
[2026-08-20 SOC運用向け]
### Aug 20, 2026 | 7 New IPs Quarantined
本日の新規隔離は 7 件でした。2026-08-20 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 84.239.42.49
WHOIS Info: ORIGIN INTERNET NETWORK, GB, Unknown (Unresolved), Allocated
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (2 hits)
- 34.138.55.185
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (32 hits)
- 45.33.90.81
WHOIS Info: Akamai Technologies, Inc. (AKAMAI), Abuse Contact, Nus-Arin, Legacy
Comment: [Fingerprinting] probing for exposed backup, archive, and database dump files
Status: Blacklisted (2 hits)
- 35.227.106.70
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (24 hits)
- 34.74.34.49
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (26 hits)
- 104.196.55.154
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Allocated
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (26 hits)
- 34.138.5.59
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (32 hits)
継続隔離中
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 116.202.252.125
WHOIS Info: Transferred to the RIPE region on 2018-08-28T00:42:30Z., ZZ, Abuse Contact, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
- 116.202.252.125
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-08-20 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は .env 露出確認 5 件、.git/config 露出確認 1 件、バックアップ/DBダンプ探索 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
[2026-08-19 SOC運用向け]
### Aug 19, 2026 | 8 New IPs Quarantined
本日の新規隔離は 8 件でした。2026-08-19 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 161.97.167.48
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (1 hits)
- 172.182.200.96
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (202 hits)
- 34.139.244.215
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (32 hits)
- 144.172.103.213
WHOIS Info: FranTech Solutions (SYNDI-5), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for exposed backup, archive, and database dump files
Status: Blacklisted (1 hits)
- 20.7.73.61
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (180 hits)
- 20.169.136.165
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (99 hits)
- 132.196.61.152
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (54 hits)
- 198.199.64.18
WHOIS Info: DigitalOcean, LLC, LLC (DO-13), Abuse Contact, Digit19-Arin, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (2 hits)
継続隔離中
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 116.202.252.125
WHOIS Info: Transferred to the RIPE region on 2018-08-28T00:42:30Z., ZZ, Abuse Contact, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
- 116.202.252.125
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-08-19 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 4 件、.git/config 露出確認 2 件、.env 露出確認 1 件、バックアップ/DBダンプ探索 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
[2026-08-18 SOC運用向け]
### Aug 18, 2026 | 11 New IPs Quarantined
本日の新規隔離は 11 件でした。2026-08-18 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 20.196.200.88
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (222 hits)
- 45.91.20.6
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (396 hits)
- 45.91.20.31
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Auth Attack] probing login and admin entry points
Status: Blacklisted (27 hits)
- 88.99.104.138
WHOIS Info: Hetzner Online GmbH, DE, Abuse Contact, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Blacklisted (5 hits across multiple environments)
- 130.131.48.48
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (2 hits)
- 45.91.20.69
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Auth Attack] probing login and admin entry points
Status: Blacklisted (27 hits)
- 104.196.165.40
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Allocated
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (32 hits)
- 20.151.109.219
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (19 hits)
- 144.172.109.237
WHOIS Info: FranTech Solutions (SYNDI-5), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (1 hits)
- 45.91.20.7
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (167 hits)
- 45.91.20.20
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Auth Attack] probing login and admin entry points
Status: Blacklisted (22 hits)
継続隔離中
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 116.202.252.125
WHOIS Info: Transferred to the RIPE region on 2018-08-28T00:42:30Z., ZZ, Abuse Contact, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
- 116.202.252.125
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-08-18 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 4 件、認証系探索 4 件、.env 露出確認 2 件、.git/config 露出確認 1 件で、探索初動の整理が中心でした
- 88.99.104.138 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
[2026-08-17 SOC運用向け]
### Aug 17, 2026 | 11 New IPs Quarantined
本日の新規隔離は 11 件でした。2026-08-17 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 20.196.200.88
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (222 hits)
- 45.91.20.6
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (396 hits)
- 45.91.20.31
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Auth Attack] probing login and admin entry points
Status: Blacklisted (27 hits)
- 88.99.104.138
WHOIS Info: Hetzner Online GmbH, DE, Abuse Contact, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Blacklisted (5 hits across multiple environments)
- 130.131.48.48
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (2 hits)
- 45.91.20.69
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Auth Attack] probing login and admin entry points
Status: Blacklisted (27 hits)
- 104.196.165.40
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Allocated
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (32 hits)
- 20.151.109.219
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (19 hits)
- 144.172.109.237
WHOIS Info: FranTech Solutions (SYNDI-5), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (1 hits)
- 45.91.20.7
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (167 hits)
- 45.91.20.20
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Auth Attack] probing login and admin entry points
Status: Blacklisted (22 hits)
継続隔離中
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 116.202.252.125
WHOIS Info: Transferred to the RIPE region on 2018-08-28T00:42:30Z., ZZ, Abuse Contact, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
- 116.202.252.125
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-08-17 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 4 件、認証系探索 4 件、.env 露出確認 2 件、.git/config 露出確認 1 件で、探索初動の整理が中心でした
- 88.99.104.138 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
[2026-08-16 SOC運用向け]
### Aug 16, 2026 | 3 New IPs Quarantined
本日の新規隔離は 3 件でした。2026-08-16 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 20.79.222.117
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (55 hits)
- 72.146.2.52
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Allocated
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (41 hits)
- 20.116.17.175
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (121 hits)
継続隔離中
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 116.202.252.125
WHOIS Info: Transferred to the RIPE region on 2018-08-28T00:42:30Z., ZZ, Abuse Contact, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
- 116.202.252.125
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-08-16 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 3 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
[2026-08-15 SOC運用向け]
### Aug 15, 2026 | 3 New IPs Quarantined
本日の新規隔離は 3 件でした。2026-08-15 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 20.79.222.117
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (55 hits)
- 72.146.2.52
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Allocated
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (41 hits)
- 20.116.17.175
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (121 hits)
継続隔離中
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 116.202.252.125
WHOIS Info: Transferred to the RIPE region on 2018-08-28T00:42:30Z., ZZ, Abuse Contact, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
- 116.202.252.125
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-08-15 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 3 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
[2026-08-14 SOC運用向け]
### Aug 14, 2026 | 5 New IPs Quarantined
本日の新規隔離は 5 件でした。2026-08-14 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 35.201.254.49
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (1 hits)
- 51.116.180.165
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (61 hits)
- 20.104.218.184
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (88 hits)
- 172.213.18.162
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (62 hits)
- 74.248.115.87
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Allocated
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (31 hits)
継続隔離中
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 116.202.252.125
WHOIS Info: Transferred to the RIPE region on 2018-08-28T00:42:30Z., ZZ, Abuse Contact, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
- 116.202.252.125
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-08-14 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 4 件、.git/config 露出確認 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
[2026-08-13 SOC運用向け]
### Aug 13, 2026 | 6 New IPs Quarantined
本日の新規隔離は 6 件でした。2026-08-13 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 162.144.21.160
WHOIS Info: Unified Layer (BLUEH-2), US, Abuse Contact, Legacy
Comment: [Auth Attack] probing login and admin entry points
Status: Blacklisted (4 hits across multiple environments)
- 188.40.26.206
WHOIS Info: Hetzner Online AG, DE, Abuse Contact, Legacy
Comment: [Auth Attack] probing login and admin entry points
Status: Blacklisted (6 hits across multiple environments)
- 34.24.242.42
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (1 hits)
- 4.223.165.84
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (31 hits)
- 8.235.35.123
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (31 hits)
- 20.113.132.165
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (131 hits)
継続隔離中
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 116.202.252.125
WHOIS Info: Transferred to the RIPE region on 2018-08-28T00:42:30Z., ZZ, Abuse Contact, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
- 116.202.252.125
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-08-13 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 2 件、認証系探索 2 件、.env 露出確認 1 件、.git/config 露出確認 1 件で、探索初動の整理が中心でした
- 162.144.21.160 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
[2026-08-12 SOC運用向け]
### Aug 12, 2026 | 5 New IPs Quarantined
本日の新規隔離は 5 件でした。2026-08-12 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 149.102.230.138
WHOIS Info: Cogent Communications, LLC (COGC), Abuse Contact, Cogen-Arin, Legacy
Comment: [Auth Attack] probing login and admin entry points
Status: Blacklisted (22 hits)
- 91.92.40.175
WHOIS Info: TechTies Inc., NL, Abuse Contact, Allocated
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (1 hits)
- 40.80.90.100
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (110 hits)
- 20.210.129.15
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (257 hits)
- 40.83.93.253
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (63 hits)
継続隔離中
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 116.202.252.125
WHOIS Info: Transferred to the RIPE region on 2018-08-28T00:42:30Z., ZZ, Abuse Contact, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
- 116.202.252.125
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-08-12 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 3 件、.env 露出確認 1 件、認証系探索 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
[2026-08-11 SOC運用向け]
### Aug 11, 2026 | 3 New IPs Quarantined
本日の新規隔離は 3 件でした。2026-08-11 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 34.136.28.246
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Auth Attack] probing login and admin entry points
Status: Blacklisted (10 hits)
- 8.221.104.113
WHOIS Info: Asia Pacific Network Information Centre (APNIC), AU, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (1 hits)
- 35.79.220.88
WHOIS Info: Amazon (AWS), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for exposed backup, archive, and database dump files
Status: Blacklisted (1 hits)
継続隔離中
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 116.202.252.125
WHOIS Info: Transferred to the RIPE region on 2018-08-28T00:42:30Z., ZZ, Abuse Contact, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
- 116.202.252.125
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-08-11 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は .env 露出確認 1 件、バックアップ/DBダンプ探索 1 件、認証系探索 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
[2026-08-10 SOC運用向け]
### Aug 10, 2026 | 3 New IPs Quarantined
本日の新規隔離は 3 件でした。2026-08-10 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 35.223.188.109
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (2 hits)
- 116.202.252.125
WHOIS Info: Transferred to the RIPE region on 2018-08-28T00:42:30Z., ZZ, Abuse Contact, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Blacklisted (4 hits across multiple environments)
- 95.111.251.70
WHOIS Info: Unknown (Unresolved), DE, Unknown (Unresolved), Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Blacklisted (4 hits across multiple environments)
継続隔離中
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 116.202.252.125
WHOIS Info: Transferred to the RIPE region on 2018-08-28T00:42:30Z., ZZ, Abuse Contact, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
- 116.202.252.125
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-08-10 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 認証系探索 2 件、.git/config 露出確認 1 件で、探索初動の整理が中心でした
- 116.202.252.125 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索と認証系探索の継続観察対象であり、再出現の可能性がある
[2026-08-09 SOC運用向け]
### Aug 09, 2026 | 6 New IPs Quarantined
本日の新規隔離は 6 件でした。2026-08-09 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 3 件です。
本日新規隔離
- 35.187.160.223
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (149 hits)
- 34.9.233.214
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (2 hits)
- 35.203.138.218
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (91 hits)
- 116.202.252.125
WHOIS Info: Transferred to the RIPE region on 2018-08-28T00:42:30Z., ZZ, Abuse Contact, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Blacklisted (6 hits across multiple environments)
- 69.30.231.90
WHOIS Info: WholeSale Internet, Inc. (WHOLE-125), Abuse Contact, Netwo1111-Arin, Allocated
Comment: [Auth Attack] probing login and admin entry points
Status: Blacklisted (6 hits across multiple environments)
- 8.229.64.168
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (2 hits)
継続隔離中
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-08-09 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は .env 露出確認 2 件、.git/config 露出確認 2 件、認証系探索 2 件で、探索初動の整理が中心でした
- 116.202.252.125 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 3 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、再出現の可能性がある
[2026-08-08 SOC運用向け]
### Aug 08, 2026 | 1 New IPs Quarantined
本日の新規隔離は 1 件でした。2026-08-08 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 35.239.100.77
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (2 hits)
継続隔離中
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-08-08 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は .git/config 露出確認 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、再出現の可能性がある
[2026-08-07 SOC運用向け]
### Aug 07, 2026 | 5 New IPs Quarantined
本日の新規隔離は 5 件でした。2026-08-07 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 35.204.22.121
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (2 hits)
- 84.247.153.86
WHOIS Info: Contabo GmbH, DE, Abuse Contact, Allocated
Comment: [Fingerprinting] probing for exposed backup, archive, and database dump files
Status: Blacklisted (4 hits across multiple environments)
- 172.161.0.2
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (148 hits)
- 51.103.131.31
WHOIS Info: Microsoft Corporation (Azure), EU, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (123 hits)
- 147.93.97.103
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (1 hits)
継続隔離中
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-08-07 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 2 件、.env 露出確認 1 件、.git/config 露出確認 1 件、バックアップ/DBダンプ探索 1 件で、探索初動の整理が中心でした
- 84.247.153.86 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、再出現の可能性がある
[2026-08-06 SOC運用向け]
### Aug 06, 2026 | 2 New IPs Quarantined
本日の新規隔離は 2 件でした。2026-08-06 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 136.107.61.91
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (2 hits)
- 20.100.201.54
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (180 hits)
継続隔離中
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-08-06 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は .git/config 露出確認 1 件、不審 PHP 探索 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、再出現の可能性がある
[2026-08-05 SOC運用向け]
### Aug 05, 2026 | 6 New IPs Quarantined
本日の新規隔離は 6 件でした。2026-08-05 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 4.225.203.22
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (267 hits)
- 20.215.185.25
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (90 hits)
- 35.252.228.242
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (90 hits)
- 20.203.208.191
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (43 hits)
- 20.218.73.95
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (90 hits)
- 4.184.238.149
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (100 hits)
継続隔離中
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-08-05 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 5 件、.env 露出確認 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、再出現の可能性がある
[2026-08-04 SOC運用向け]
### Aug 04, 2026 | 2 New IPs Quarantined
本日の新規隔離は 2 件でした。2026-08-04 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 47.85.160.47
WHOIS Info: Alibaba Cloud LLC (AL-3), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (1 hits)
- 20.100.172.153
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (249 hits)
継続隔離中
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-08-04 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は .env 露出確認 1 件、不審 PHP 探索 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、再出現の可能性がある
[2026-08-03 SOC運用向け]
### Aug 03, 2026 | 2 New IPs Quarantined
本日の新規隔離は 2 件でした。2026-08-03 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 34.129.78.245
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (19 hits)
- 104.198.24.37
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Allocated
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (1 hits)
継続隔離中
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-08-03 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は .env 露出確認 1 件、.git/config 露出確認 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、再出現の可能性がある
[2026-08-02 SOC運用向け]
### Aug 02, 2026 | 6 New IPs Quarantined
本日の新規隔離は 6 件でした。2026-08-02 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 34.39.255.194
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (10 hits)
- 136.108.18.165
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (10 hits)
- 158.158.54.131
WHOIS Info: Asia Pacific Network Information Centre (APNIC), AU, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (41 hits)
- 77.83.39.233
WHOIS Info: LANEDONET, NL, Abuse Contact, Allocated
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (1 hits)
- 35.203.109.116
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (10 hits)
- 74.248.33.65
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Allocated
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (39 hits)
継続隔離中
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-08-02 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は .env 露出確認 4 件、不審 PHP 探索 2 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、再出現の可能性がある
[2026-08-01 SOC運用向け]
### Aug 01, 2026 | 5 New IPs Quarantined
本日の新規隔離は 5 件でした。2026-08-01 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 20.251.48.208
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (416 hits across multiple environments)
- 144.172.94.198
WHOIS Info: FranTech Solutions (SYNDI-5), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (12 hits)
- 20.220.203.117
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (95 hits)
- 20.52.217.208
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (68 hits)
- 102.220.160.239
WHOIS Info: Internet, SI, Abuse Contact, Allocated
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (24 hits)
継続隔離中
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-08-01 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 4 件、.env 露出確認 1 件で、探索初動の整理が中心でした
- 20.251.48.208 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、再出現の可能性がある
UNIX Cafe フロア案内(ハブページ)