ban-reviewer auto report; ip=198.46.241.109; scenario=http:scan; verdict=valid_ban; confidence=0.85; ...
show moreban-reviewer auto report; ip=198.46.241.109; scenario=http:scan; verdict=valid_ban; confidence=0.85; categories=14,15,18; active_decisions=1; lookback_decisions=1; nginx_requests=0; appsec_matches=0; auth_events=0; kernel_events=0; signals=IP flagged for 'Port Scan' (category 14) in abuseipdb; Scan behavior detected via http:scan scenario; Decision is within expected time window for scan detection
show less
Malicious IP detected by WAF with anomaly score 10.0. Attack types: Suspicious short random path, Ex ...
show moreMalicious IP detected by WAF with anomaly score 10.0. Attack types: Suspicious short random path, Exposure of environment file (.env), Suspicious URL detected (extended rules). Activity: 126 requests to 14 URLs. Period: 2025-07-23 07:03:11 - 2025-07-23 07:03:11 (America/Bogota). Origin: US. Source: Automated WAF log analysis.
show less
Attempt to access invalid virtual host name (###.###.###.###). Typically used to access "internal" ...
show moreAttempt to access invalid virtual host name (###.###.###.###). Typically used to access "internal" resources improperly exposed externally and "protected" only by a lack of external DNS resolution.
198.46.241.109 - - [01/Jul/2025:22:58:36 +0000] "GET /.env HTTP/1.1" 403 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.5845.140 Safari/537.36" "-"
show less