System Note
$ cat /proc/ai-disclosure
本記事の構成および論理分析にはAI(人工知能)を使用しています。情報の正確性は、システム管理者(UNIXユーザー)による手動検証済みです。
* 当サイトでは、コンテンツの一部に広告を掲載しています。
本記事の構成および論理分析にはAI(人工知能)を使用しています。情報の正確性は、システム管理者(UNIXユーザー)による手動検証済みです。

2026年5月より、セキュリティ日報の掲載フォーマットを見直しました。これまでのインシデントログ中心の形式から、当日に新規隔離したIPと継続隔離中のIPを分かりやすく整理した、SOC運用向けの一覧形式へ変更しています。
新しい形式では、WHOIS情報、攻撃種別、遮断状況を中心に、必要な情報を簡潔に確認できる構成に統一しました。また、記事内では個別サイト名や内部運用向けの詳細パラメータは掲載せず、複数サイトにまたがるアクセスは「複数の管理環境」として表記する運用に変更しています。
この見直しにより、日々の観測傾向や継続的な不審アクセスの把握を、以前より短時間で確認しやすくなりました。
[2026-08-06 SOC運用向け]
### Aug 06, 2026 | 2 New IPs Quarantined
本日の新規隔離は 2 件でした。2026-08-06 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 136.107.61.91
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (2 hits)
- 20.100.201.54
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (180 hits)
継続隔離中
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-08-06 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は .git/config 露出確認 1 件、不審 PHP 探索 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、再出現の可能性がある
[2026-08-05 SOC運用向け]
### Aug 05, 2026 | 6 New IPs Quarantined
本日の新規隔離は 6 件でした。2026-08-05 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 4.225.203.22
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (267 hits)
- 20.215.185.25
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (90 hits)
- 35.252.228.242
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (90 hits)
- 20.203.208.191
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (43 hits)
- 20.218.73.95
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (90 hits)
- 4.184.238.149
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (100 hits)
継続隔離中
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-08-05 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 5 件、.env 露出確認 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、再出現の可能性がある
[2026-08-04 SOC運用向け]
### Aug 04, 2026 | 2 New IPs Quarantined
本日の新規隔離は 2 件でした。2026-08-04 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 47.85.160.47
WHOIS Info: Alibaba Cloud LLC (AL-3), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (1 hits)
- 20.100.172.153
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (249 hits)
継続隔離中
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-08-04 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は .env 露出確認 1 件、不審 PHP 探索 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、再出現の可能性がある
[2026-08-03 SOC運用向け]
### Aug 03, 2026 | 2 New IPs Quarantined
本日の新規隔離は 2 件でした。2026-08-03 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 34.129.78.245
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (19 hits)
- 104.198.24.37
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Allocated
Comment: [Fingerprinting] probing for .git/config exposure
Status: Blacklisted (1 hits)
継続隔離中
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-08-03 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は .env 露出確認 1 件、.git/config 露出確認 1 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、再出現の可能性がある
[2026-08-02 SOC運用向け]
### Aug 02, 2026 | 6 New IPs Quarantined
本日の新規隔離は 6 件でした。2026-08-02 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 34.39.255.194
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (10 hits)
- 136.108.18.165
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (10 hits)
- 158.158.54.131
WHOIS Info: Asia Pacific Network Information Centre (APNIC), AU, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (41 hits)
- 77.83.39.233
WHOIS Info: LANEDONET, NL, Abuse Contact, Allocated
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (1 hits)
- 35.203.109.116
WHOIS Info: Google LLC (GOOGL-2), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (10 hits)
- 74.248.33.65
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Allocated
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (39 hits)
継続隔離中
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-08-02 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は .env 露出確認 4 件、不審 PHP 探索 2 件で、探索初動の整理が中心でした
- 当日新規では複数の管理環境にまたがる横断的な活動は確認されず、単独環境への試行が主体と考えられる
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、再出現の可能性がある
[2026-08-01 SOC運用向け]
### Aug 01, 2026 | 5 New IPs Quarantined
本日の新規隔離は 5 件でした。2026-08-01 時点で当日日報内に再犯または要確認として確認できた継続隔離中のIPは 4 件です。
本日新規隔離
- 20.251.48.208
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (416 hits across multiple environments)
- 144.172.94.198
WHOIS Info: FranTech Solutions (SYNDI-5), US, Abuse Contact, Legacy
Comment: [Fingerprinting] probing for .env and related exposed files
Status: Blacklisted (12 hits)
- 20.220.203.117
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (95 hits)
- 20.52.217.208
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (68 hits)
- 102.220.160.239
WHOIS Info: Internet, SI, Abuse Contact, Allocated
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Blacklisted (24 hits)
継続隔離中
- 20.78.158.176
WHOIS Info: Microsoft Corporation (Azure), US, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 135.119.47.58
WHOIS Info: RIPE Network Coordination Centre (RIPE), NL, Abuse Contact, Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 94.143.139.248
WHOIS Info: arsys.es, ES, Abuse Contact, Allocated
Comment: [WordPress Recon] probing for wp-config backup and exposed configuration paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
- 51.116.233.22
WHOIS Info: Microsoft Corporation (Azure), DE, Unknown (Unresolved), Legacy
Comment: [Web Shell Probe] probing for suspicious PHP files and backdoor paths
Status: Runtime Quarantine Only
Decision: 現時点では runtime quarantine 継続。common_security.txt 更新対象ではありません。
common_security.txt 更新判断
- static deny 済み: なし
- common_security.txt 追記候補: なし
- runtime quarantine 継続
- 20.78.158.176
- 135.119.47.58
- 94.143.139.248
- 51.116.233.22
運用補足
- runtime deny は当日新規だけでなく、継続隔離中のIPを含む累積反映です
- common_security.txt に反映済みの static deny IP は日報から除外しています
- 本日新規隔離は 2026-08-01 の日次集計結果を基準に判定しています
- 継続隔離中は当日日報内で再犯、継続遮断、または要確認アラートとして確認できたIPのみ記載しています
- 複数の管理環境にまたがるIPは、横断的な自動化スキャンとして扱います
分析メモ
- 本日新規隔離は 不審 PHP 探索 4 件、.env 露出確認 1 件で、探索初動の整理が中心でした
- 20.251.48.208 は複数の管理環境を横断しており、自動化された横断スキャンである可能性が高い
- 継続隔離中の 4 IP はWordPress 設定露出探索と不審 PHP 探索の継続観察対象であり、再出現の可能性がある
UNIX Cafe フロア案内(ハブページ)
アクセスログの「200 0」は危険?WordPressで不審なPHPアクセスを調査した記録 | UNIX Cafe
ターミナルタイピングRPG「クムドールの試練」 v0.6.0|敵セリフと状態異常を強化 | UNIX Cafe