ban-reviewer auto report; ip=166.88.83.242; scenario=http:scan; verdict=valid_ban; confidence=0.85; ...
show moreban-reviewer auto report; ip=166.88.83.242; scenario=http:scan; verdict=valid_ban; confidence=0.85; categories=14,15,18,22; active_decisions=1; lookback_decisions=1; nginx_requests=0; appsec_matches=0; auth_events=0; kernel_events=0; signals=IP flagged for 'http:scan' scenario; Port Scan (category 14) is in default categories; Hacking (category 15) is in default categories; Brute-Force (category 18) is in default categories; SSH (category 22) is in default categories
show less
Malicious IP detected by WAF with anomaly score 10.0. Attack types: Suspicious short random path, Ex ...
show moreMalicious IP detected by WAF with anomaly score 10.0. Attack types: Suspicious short random path, Exposure of environment file (.env), Suspicious URL detected (extended rules). Activity: 23 requests to 2 URLs. Period: 2025-07-18 09:09 - 2025-07-18 09:09 UTC. Origin: US. Source: Automated WAF log analysis.
show less
Attempt to access invalid virtual host name (###.###.###.###). Typically used to access "internal" ...
show moreAttempt to access invalid virtual host name (###.###.###.###). Typically used to access "internal" resources improperly exposed externally and "protected" only by a lack of external DNS resolution.
166.88.83.242 - - [21/Jun/2025:03:51:15 +0000] "GET /.env HTTP/1.1" 403 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.5845.140 Safari/537.36" "-"
show less