{"ip":"103.189.235.114","exported_at":"2026-06-17T22:32:46+00:00","period_days":30,"metrics":{"events7d":0,"distinct_ports":0,"distinct_classifications":0,"max_severity":null,"last_sensor_id":"paris-1","max_waf_score":null,"max_risk_score":32,"attack_stage":"probe","attack_chain_stage":null,"threat_family":["scanner"],"recommended_action":"monitor","confidence":1,"risk_breakdown":{"waf":8,"classification":50,"behavior":0,"geo":40,"protocol":36,"novelty":25},"mitre_tactics":["TA0007","TA0001"],"mitre_technique":null,"top_mitre_technique":null,"top_mitre_count":null,"executive_one_liner_fr":"risque 32\/100","campaign_hint_fr":null,"confidence_breakdown":[],"persona_hostname":null,"correlation_flags":[],"correlation_flags_labels_fr":[],"confidence_pct":100,"confidence_hint_fr":null,"sensor_role_label_fr":null,"tags_summary_labels_fr":[],"tags_summary":[],"attack_vector":null,"protocol_details":[],"protocol_summary_fr":null,"evidence_snippet":"SSH-2.0-libssh_0.9.6\r\n\u0000\u0000\u0003\ufffd\u0006\u0014\ufffd\ufffd\ufffd\u02b3\ufffd\u0000\ufffd2\ufffdm\u0002\u001e1#\ufffd\u0000\u0000\u0001(curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nist","target_port_label":"22","emulator_service":null,"confidence_reason":null,"classification_reason":"Type \u00ab ssh_probe \u00bb (signaux protocolaires) \u00b7 confiance 100%","classification_reason_label_fr":"Type \u00ab ssh_probe \u00bb (signaux protocolaires) \u00b7 confiance 100%","confidence_factors_fr":null,"payload_preview":"SSH-2.0-libssh_0.9.6\r\n\u0000\u0000\u0003\ufffd\u0006\u0014\ufffd\ufffd\ufffd\u02b3\ufffd\u0000\ufffd2\ufffdm\u0002\u001e1#\ufffd\u0000\u0000\u0001(curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nist"},"events":[{"id":8388208,"ip":"103.189.235.114","ts":"2026-06-06 12:48:21.000000","proto":"tcp","src_port":40750,"dst_port":22,"service":"ssh","classification":"ssh_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00225353482d322e302d4f70656e5353485f382e397031205562756e74752d347562756e7475302e360d0a\u0022, \u0022emulator_response_len\u0022: 41, \u0022bytes_in\u0022: 998, \u0022payload_entropy\u0022: 4.7796144471522535, \u0022port_category\u0022: \u0022well_known\u0022, \u0022org\u0022: \u0022Cloud Host Pte Ltd\u0022, \u0022service\u0022: \u0022ssh\u0022, \u0022app_proto\u0022: \u0022ssh\u0022, \u0022asn\u0022: 138608, \u0022country\u0022: \u0022ID\u0022, \u0022dst_port\u0022: 22, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 50.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 40.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 50.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 40.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 32, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u00229a91c35ff8553fc24795f9eaf93692ffdae1839c\u0022, \u0022event_fingerprint\u0022: \u0022bc4e3fa786c83e0db7c1c892cb0c288f6b14388f\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab ssh_probe \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 141, \u0022precision_signals\u0022: [\u0022pat-0391\u0022, \u0022pat-0392\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0391\u0022, \u0022pat-0392\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0391\u0022, \u0022pat-0392\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022SSH-2.0 banner RFC4253\u0022, \u0022libssh banner\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0391\u0022, \u0022pat-0392\u0022, \u0022pat-0536\u0022], \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022ID\u0022, \u0022asn\u0022: 138608, \u0022org\u0022: \u0022Cloud Host Pte Ltd\u0022, \u0022is_datacenter\u0022: true, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u002220ef46347aa75c882d7c1393758a2ee4\u0022, \u0022path_pattern_hash\u0022: \u00224368b1c212b6962fb95d1d1144451aca\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 22, \u0022service\u0022: \u0022ssh\u0022}, \u0022payload_preview\u0022: \u0022SSH-2.0-libssh_0.9.6\\r\\n\\u0000\\u0000\\u0003\ufffd\\u0006\\u0014\ufffd\ufffd\ufffd\u02b3\ufffd\\u0000\ufffd2\ufffdm\\u0002\\u001e1#\ufffd\\u0000\\u0000\\u0001(curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nist\u0022, \u0022request_sample\u0022: \u0022SSH-2.0-libssh_0.9.6\\r\\n\\u0000\\u0000\\u0003\ufffd\\u0006\\u0014\ufffd\ufffd\ufffd\u02b3\ufffd\\u0000\ufffd2\ufffdm\\u0002\\u001e1#\ufffd\\u0000\\u0000\\u0001(curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group18-sha512,diffie-hellman-group16-sha512,diffie-hellman-group-exchange-sha256,diffie-\u0022, \u0022payload_snippet\u0022: \u0022SSH-2.0-libssh_0.9.6\\r\\n\\u0000\\u0000\\u0003\ufffd\\u0006\\u0014\ufffd\ufffd\ufffd\u02b3\ufffd\\u0000\ufffd2\ufffdm\\u0002\\u001e1#\ufffd\\u0000\\u0000\\u0001(curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nist\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022SSH-2.0-libssh_0.9.6\\r\\n\\u0000\\u0000\\u0003\ufffd\\u0006\\u0014\ufffd\ufffd\ufffd\u02b3\ufffd\\u0000\ufffd2\ufffdm\\u0002\\u001e1#\ufffd\\u0000\\u0000\\u0001(curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group18-sha512,diffie-hellman-group16-sha512,diffie-hellman-group-exchange-sha256,diffie-\u0022, \u0022payload_snippet\u0022: \u0022SSH-2.0-libssh_0.9.6\\r\\n\\u0000\\u0000\\u0003\ufffd\\u0006\\u0014\ufffd\ufffd\ufffd\u02b3\ufffd\\u0000\ufffd2\ufffdm\\u0002\\u001e1#\ufffd\\u0000\\u0000\\u0001(curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nist\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab ssh_probe \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022d27bf3a6888f522b568d3bb5ba727ab27c543cbf\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022net_ssh_probe\u0022, \u0022ssh_banner\u0022, \u0022ssh_emulated\u0022, \u0022ssh_kex_probe\u0022, \u0022ssh_libssh\u0022], \u0022asn_dc_heuristic\u0022: true}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022net_ssh_probe\u0022, \u0022ssh_banner\u0022, \u0022ssh_emulated\u0022, \u0022ssh_kex_probe\u0022, \u0022ssh_libssh\u0022]","anomalies":"[]","severity":6,"bytes_in":998}],"total_events":1}