{"ip":"124.198.131.22","exported_at":"2026-06-17T07:02:35+00:00","period_days":30,"metrics":{"events7d":0,"distinct_ports":0,"distinct_classifications":0,"max_severity":null,"last_sensor_id":"paris-1","max_waf_score":null,"max_risk_score":100,"attack_stage":null,"attack_chain_stage":null,"threat_family":[],"recommended_action":null,"confidence":null,"risk_breakdown":[],"mitre_tactics":[],"mitre_technique":null,"top_mitre_technique":null,"top_mitre_count":null,"executive_one_liner_fr":"risque 100\/100","campaign_hint_fr":null,"confidence_breakdown":[],"persona_hostname":null,"correlation_flags":[],"correlation_flags_labels_fr":[],"confidence_pct":null,"confidence_hint_fr":null,"sensor_role_label_fr":null,"tags_summary_labels_fr":[],"tags_summary":[],"attack_vector":null,"protocol_details":[],"protocol_summary_fr":null,"evidence_snippet":null,"target_port_label":null,"emulator_service":null,"confidence_reason":null,"classification_reason":null,"classification_reason_label_fr":null,"confidence_factors_fr":null,"payload_preview":null},"events":[{"id":7937642,"ip":"124.198.131.22","ts":"2026-05-29 12:21:56.000000","proto":"tcp","src_port":48070,"dst_port":3000,"service":"http","classification":"web_attack","waf_score":38,"waf_tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022]","http_method":"POST","http_target":"\/_next","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 7, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u002246f5955a67387b75de712e640b0687c888a438e5\u0022, \u0022http_target_hash\u0022: \u0022afd9bdeafd8c657f6b493ada03c51e348516227b\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 953, \u0022payload_entropy\u0022: 5.477328163409766, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 8, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022c0da2de6402b95e491d6fb944a5be5e204ceba08\u0022, \u0022event_fingerprint\u0022: \u0022c5bdee8ada8d10d23c51954cc145e572e92ee340\u0022, \u0022tags_list\u0022: [\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:3000","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]","anomalies":"[]","severity":10,"bytes_in":953},{"id":7929680,"ip":"124.198.131.22","ts":"2026-05-29 09:12:23.000000","proto":"tcp","src_port":43414,"dst_port":3000,"service":"http","classification":"web_attack","waf_score":42,"waf_tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022]","http_method":"POST","http_target":"\/api","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 7, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u002246f5955a67387b75de712e640b0687c888a438e5\u0022, \u0022http_target_hash\u0022: \u0022ada91241341ae792ecf0a59cad28616a77bab856\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 951, \u0022payload_entropy\u0022: 5.477458672522051, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 10, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022e49195bce497c65c06941e6ef27785bb42dafe40\u0022, \u0022event_fingerprint\u0022: \u00228f28b75b15a449a81db05f356f3f02b57bdaf25d\u0022, \u0022tags_list\u0022: [\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022, \u0022http_probe_api\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:3000","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022, \u0022http_probe_api\u0022]","anomalies":"[]","severity":10,"bytes_in":951},{"id":7929064,"ip":"124.198.131.22","ts":"2026-05-29 08:57:45.000000","proto":"tcp","src_port":59204,"dst_port":8080,"service":"http","classification":"web_attack","waf_score":41,"waf_tags":"[\u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950335:rce-2\u0022, \u0022950347:rce-5\u0022, \u0022950407:ssrf-3\u0022, \u0022950471:nosqli-3\u0022]","http_method":"POST","http_target":"\/tmUnblock.cgi","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 6, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: \u0022cgi\u0022, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u0022c9908f9a31aefa5902e21ee9fa132cbe056c536d\u0022, \u0022http_target_hash\u0022: \u00226cff281bfb0055f2e5c6afc1d923500419949544\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 382, \u0022payload_entropy\u0022: 5.454099199504813, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 7, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022cc13924fce73fe7ffe42096010cdb85ae7490c9a\u0022, \u0022event_fingerprint\u0022: \u002297fceacd435ac6fbd3ffa80bcd61aaea2c82cd79\u0022, \u0022tags_list\u0022: [\u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950335:rce-2\u0022, \u0022950347:rce-5\u0022, \u0022950407:ssrf-3\u0022, \u0022950471:nosqli-3\u0022, \u0022http_jwt_body\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:8080","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950335:rce-2\u0022, \u0022950347:rce-5\u0022, \u0022950407:ssrf-3\u0022, \u0022950471:nosqli-3\u0022, \u0022http_jwt_body\u0022]","anomalies":"[]","severity":10,"bytes_in":382},{"id":7929065,"ip":"124.198.131.22","ts":"2026-05-29 08:57:45.000000","proto":"tcp","src_port":59214,"dst_port":8080,"service":"http","classification":"web_attack","waf_score":47,"waf_tags":"[\u0022950019:sqli-4\u0022, \u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950347:rce-5\u0022, \u0022950407:ssrf-3\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022]","http_method":"POST","http_target":"\/goform\/set_LimitClient_cfg","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 7, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 2, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u0022c9908f9a31aefa5902e21ee9fa132cbe056c536d\u0022, \u0022http_target_hash\u0022: \u002211e5f78f4036aff2c472248972fe32123c6ace43\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 354, \u0022payload_entropy\u0022: 5.361772559132838, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 10, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022abbdf3e68cf80eaf1b9a861318ccf00d74512f1e\u0022, \u0022event_fingerprint\u0022: \u002211e0ab521c07a0034bc0b4c05903e76baeecc0fd\u0022, \u0022tags_list\u0022: [\u0022950019:sqli-4\u0022, \u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950347:rce-5\u0022, \u0022950407:ssrf-3\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022http_jwt_body\u0022, \u0022http_probe_goform\u0022, \u0022http_sensitive_path\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:8080","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950019:sqli-4\u0022, \u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950347:rce-5\u0022, \u0022950407:ssrf-3\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022http_jwt_body\u0022, \u0022http_probe_goform\u0022, \u0022http_sensitive_path\u0022]","anomalies":"[]","severity":10,"bytes_in":354},{"id":7926700,"ip":"124.198.131.22","ts":"2026-05-29 07:47:49.000000","proto":"tcp","src_port":38170,"dst_port":8088,"service":"http","classification":"web_attack","waf_score":53,"waf_tags":"[\u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950335:rce-2\u0022, \u0022950347:rce-5\u0022, \u0022950406:ssrf-3\u0022, \u0022950407:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950471:nosqli-3\u0022]","http_method":"POST","http_target":"\/apply.cgi","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 9, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: \u0022cgi\u0022, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u00225af561107125d8ccc4aac442a3b8b5dee6769a85\u0022, \u0022http_target_hash\u0022: \u002231402cc48ac7ac052e1d50fc94349665a12c2c45\u0022, \u0022http_referer_hash\u0022: \u00226c9a85e19b48ee7bc090955b4a30836f92b398b3\u0022, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 586, \u0022payload_entropy\u0022: 5.5270711744927405, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 12, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u002210dc2871c1cba3d975dd2fb9983ec8869486de83\u0022, \u0022event_fingerprint\u0022: \u0022e230c8d6502b49facf567d595be91913490875a9\u0022, \u0022tags_list\u0022: [\u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950335:rce-2\u0022, \u0022950347:rce-5\u0022, \u0022950406:ssrf-3\u0022, \u0022950407:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022http_auth_header_token\u0022, \u0022http_basic_auth\u0022, \u0022http_basic_auth_header\u0022, \u0022http_jwt_body\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:8088","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":"http:\/\/62.3.50.33:8088\/apply.cgi","tags":"[\u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950335:rce-2\u0022, \u0022950347:rce-5\u0022, \u0022950406:ssrf-3\u0022, \u0022950407:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022http_auth_header_token\u0022, \u0022http_basic_auth\u0022, \u0022http_basic_auth_header\u0022, \u0022http_jwt_body\u0022]","anomalies":"[]","severity":10,"bytes_in":586},{"id":7926701,"ip":"124.198.131.22","ts":"2026-05-29 07:47:49.000000","proto":"tcp","src_port":38176,"dst_port":8088,"service":"http","classification":"web_attack","waf_score":46,"waf_tags":"[\u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950347:rce-5\u0022, \u0022950406:ssrf-3\u0022, \u0022950407:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950471:nosqli-3\u0022]","http_method":"POST","http_target":"\/apply.cgi","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 9, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: \u0022cgi\u0022, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u00225af561107125d8ccc4aac442a3b8b5dee6769a85\u0022, \u0022http_target_hash\u0022: \u002231402cc48ac7ac052e1d50fc94349665a12c2c45\u0022, \u0022http_referer_hash\u0022: \u00226c9a85e19b48ee7bc090955b4a30836f92b398b3\u0022, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 527, \u0022payload_entropy\u0022: 5.5290084570180955, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 11, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022c462123b86055af1f088af29d93b9f739404af06\u0022, \u0022event_fingerprint\u0022: \u0022e230c8d6502b49facf567d595be91913490875a9\u0022, \u0022tags_list\u0022: [\u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950347:rce-5\u0022, \u0022950406:ssrf-3\u0022, \u0022950407:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022http_auth_header_token\u0022, \u0022http_basic_auth\u0022, \u0022http_basic_auth_header\u0022, \u0022http_jwt_body\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:8088","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":"http:\/\/62.3.50.33:8088\/apply.cgi","tags":"[\u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950347:rce-5\u0022, \u0022950406:ssrf-3\u0022, \u0022950407:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022http_auth_header_token\u0022, \u0022http_basic_auth\u0022, \u0022http_basic_auth_header\u0022, \u0022http_jwt_body\u0022]","anomalies":"[]","severity":10,"bytes_in":527},{"id":7925873,"ip":"124.198.131.22","ts":"2026-05-29 07:25:35.000000","proto":"tcp","src_port":45394,"dst_port":3000,"service":"http","classification":"web_attack","waf_score":44,"waf_tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022]","http_method":"POST","http_target":"\/_next\/server","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 7, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 2, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u002246f5955a67387b75de712e640b0687c888a438e5\u0022, \u0022http_target_hash\u0022: \u0022bef481449499f499a0b29ed75c9630076205b04f\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 960, \u0022payload_entropy\u0022: 5.476719753805595, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 9, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022b2cc074b4e27a1918ace1473f7a43da1f30cb064\u0022, \u0022event_fingerprint\u0022: \u00229db61e8e4d6fa7ec30de8a565cc70439b5f61dca\u0022, \u0022tags_list\u0022: [\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:3000","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]","anomalies":"[]","severity":10,"bytes_in":960},{"id":7925542,"ip":"124.198.131.22","ts":"2026-05-29 07:19:07.000000","proto":"tcp","src_port":45958,"dst_port":3000,"service":"http","classification":"web_attack","waf_score":38,"waf_tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022]","http_method":"POST","http_target":"\/app","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 7, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u002246f5955a67387b75de712e640b0687c888a438e5\u0022, \u0022http_target_hash\u0022: \u00220c35eebf403cf91fe77a64921d76aa1ca6411d20\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 951, \u0022payload_entropy\u0022: 5.477789822834032, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 8, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022c0da2de6402b95e491d6fb944a5be5e204ceba08\u0022, \u0022event_fingerprint\u0022: \u00229434400c4aecded381b24d5a44d87483e1bc631c\u0022, \u0022tags_list\u0022: [\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:3000","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]","anomalies":"[]","severity":10,"bytes_in":951},{"id":7924538,"ip":"124.198.131.22","ts":"2026-05-29 06:52:53.000000","proto":"tcp","src_port":34542,"dst_port":8088,"service":"http","classification":"web_attack","waf_score":53,"waf_tags":"[\u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950335:rce-2\u0022, \u0022950347:rce-5\u0022, \u0022950406:ssrf-3\u0022, \u0022950407:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950471:nosqli-3\u0022]","http_method":"POST","http_target":"\/apply.cgi","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 9, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: \u0022cgi\u0022, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u00225af561107125d8ccc4aac442a3b8b5dee6769a85\u0022, \u0022http_target_hash\u0022: \u002231402cc48ac7ac052e1d50fc94349665a12c2c45\u0022, \u0022http_referer_hash\u0022: \u00226c9a85e19b48ee7bc090955b4a30836f92b398b3\u0022, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 586, \u0022payload_entropy\u0022: 5.5270711744927405, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 12, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u002210dc2871c1cba3d975dd2fb9983ec8869486de83\u0022, \u0022event_fingerprint\u0022: \u0022e230c8d6502b49facf567d595be91913490875a9\u0022, \u0022tags_list\u0022: [\u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950335:rce-2\u0022, \u0022950347:rce-5\u0022, \u0022950406:ssrf-3\u0022, \u0022950407:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022http_auth_header_token\u0022, \u0022http_basic_auth\u0022, \u0022http_basic_auth_header\u0022, \u0022http_jwt_body\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:8088","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":"http:\/\/62.3.50.33:8088\/apply.cgi","tags":"[\u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950335:rce-2\u0022, \u0022950347:rce-5\u0022, \u0022950406:ssrf-3\u0022, \u0022950407:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022http_auth_header_token\u0022, \u0022http_basic_auth\u0022, \u0022http_basic_auth_header\u0022, \u0022http_jwt_body\u0022]","anomalies":"[]","severity":10,"bytes_in":586},{"id":7924539,"ip":"124.198.131.22","ts":"2026-05-29 06:52:53.000000","proto":"tcp","src_port":34548,"dst_port":8088,"service":"http","classification":"web_attack","waf_score":46,"waf_tags":"[\u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950347:rce-5\u0022, \u0022950406:ssrf-3\u0022, \u0022950407:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950471:nosqli-3\u0022]","http_method":"POST","http_target":"\/apply.cgi","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 9, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: \u0022cgi\u0022, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u00225af561107125d8ccc4aac442a3b8b5dee6769a85\u0022, \u0022http_target_hash\u0022: \u002231402cc48ac7ac052e1d50fc94349665a12c2c45\u0022, \u0022http_referer_hash\u0022: \u00226c9a85e19b48ee7bc090955b4a30836f92b398b3\u0022, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 527, \u0022payload_entropy\u0022: 5.5290084570180955, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 11, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022c462123b86055af1f088af29d93b9f739404af06\u0022, \u0022event_fingerprint\u0022: \u0022e230c8d6502b49facf567d595be91913490875a9\u0022, \u0022tags_list\u0022: [\u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950347:rce-5\u0022, \u0022950406:ssrf-3\u0022, \u0022950407:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022http_auth_header_token\u0022, \u0022http_basic_auth\u0022, \u0022http_basic_auth_header\u0022, \u0022http_jwt_body\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:8088","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":"http:\/\/62.3.50.33:8088\/apply.cgi","tags":"[\u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950347:rce-5\u0022, \u0022950406:ssrf-3\u0022, \u0022950407:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022http_auth_header_token\u0022, \u0022http_basic_auth\u0022, \u0022http_basic_auth_header\u0022, \u0022http_jwt_body\u0022]","anomalies":"[]","severity":10,"bytes_in":527},{"id":7919847,"ip":"124.198.131.22","ts":"2026-05-29 04:21:33.000000","proto":"tcp","src_port":49670,"dst_port":8080,"service":"http","classification":"web_attack","waf_score":41,"waf_tags":"[\u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950335:rce-2\u0022, \u0022950347:rce-5\u0022, \u0022950407:ssrf-3\u0022, \u0022950471:nosqli-3\u0022]","http_method":"POST","http_target":"\/tmUnblock.cgi","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 6, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: \u0022cgi\u0022, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u0022c9908f9a31aefa5902e21ee9fa132cbe056c536d\u0022, \u0022http_target_hash\u0022: \u00226cff281bfb0055f2e5c6afc1d923500419949544\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 382, \u0022payload_entropy\u0022: 5.454099199504813, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 7, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022cc13924fce73fe7ffe42096010cdb85ae7490c9a\u0022, \u0022event_fingerprint\u0022: \u002297fceacd435ac6fbd3ffa80bcd61aaea2c82cd79\u0022, \u0022tags_list\u0022: [\u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950335:rce-2\u0022, \u0022950347:rce-5\u0022, \u0022950407:ssrf-3\u0022, \u0022950471:nosqli-3\u0022, \u0022http_jwt_body\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:8080","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950335:rce-2\u0022, \u0022950347:rce-5\u0022, \u0022950407:ssrf-3\u0022, \u0022950471:nosqli-3\u0022, \u0022http_jwt_body\u0022]","anomalies":"[]","severity":10,"bytes_in":382},{"id":7919848,"ip":"124.198.131.22","ts":"2026-05-29 04:21:33.000000","proto":"tcp","src_port":49676,"dst_port":8080,"service":"http","classification":"web_attack","waf_score":47,"waf_tags":"[\u0022950019:sqli-4\u0022, \u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950347:rce-5\u0022, \u0022950407:ssrf-3\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022]","http_method":"POST","http_target":"\/goform\/set_LimitClient_cfg","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 7, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 2, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u0022c9908f9a31aefa5902e21ee9fa132cbe056c536d\u0022, \u0022http_target_hash\u0022: \u002211e5f78f4036aff2c472248972fe32123c6ace43\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 354, \u0022payload_entropy\u0022: 5.361772559132838, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 10, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022abbdf3e68cf80eaf1b9a861318ccf00d74512f1e\u0022, \u0022event_fingerprint\u0022: \u002211e0ab521c07a0034bc0b4c05903e76baeecc0fd\u0022, \u0022tags_list\u0022: [\u0022950019:sqli-4\u0022, \u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950347:rce-5\u0022, \u0022950407:ssrf-3\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022http_jwt_body\u0022, \u0022http_probe_goform\u0022, \u0022http_sensitive_path\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:8080","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950019:sqli-4\u0022, \u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950347:rce-5\u0022, \u0022950407:ssrf-3\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022http_jwt_body\u0022, \u0022http_probe_goform\u0022, \u0022http_sensitive_path\u0022]","anomalies":"[]","severity":10,"bytes_in":354},{"id":7915420,"ip":"124.198.131.22","ts":"2026-05-29 01:49:30.000000","proto":"tcp","src_port":48976,"dst_port":8088,"service":"http","classification":"web_attack","waf_score":53,"waf_tags":"[\u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950335:rce-2\u0022, \u0022950347:rce-5\u0022, \u0022950406:ssrf-3\u0022, \u0022950407:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950471:nosqli-3\u0022]","http_method":"POST","http_target":"\/apply.cgi","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 9, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: \u0022cgi\u0022, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u00225af561107125d8ccc4aac442a3b8b5dee6769a85\u0022, \u0022http_target_hash\u0022: \u002231402cc48ac7ac052e1d50fc94349665a12c2c45\u0022, \u0022http_referer_hash\u0022: \u00226c9a85e19b48ee7bc090955b4a30836f92b398b3\u0022, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 586, \u0022payload_entropy\u0022: 5.5270711744927405, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 12, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u002210dc2871c1cba3d975dd2fb9983ec8869486de83\u0022, \u0022event_fingerprint\u0022: \u0022e230c8d6502b49facf567d595be91913490875a9\u0022, \u0022tags_list\u0022: [\u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950335:rce-2\u0022, \u0022950347:rce-5\u0022, \u0022950406:ssrf-3\u0022, \u0022950407:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022http_auth_header_token\u0022, \u0022http_basic_auth\u0022, \u0022http_basic_auth_header\u0022, \u0022http_jwt_body\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:8088","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":"http:\/\/62.3.50.33:8088\/apply.cgi","tags":"[\u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950335:rce-2\u0022, \u0022950347:rce-5\u0022, \u0022950406:ssrf-3\u0022, \u0022950407:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022http_auth_header_token\u0022, \u0022http_basic_auth\u0022, \u0022http_basic_auth_header\u0022, \u0022http_jwt_body\u0022]","anomalies":"[]","severity":10,"bytes_in":586},{"id":7915421,"ip":"124.198.131.22","ts":"2026-05-29 01:49:30.000000","proto":"tcp","src_port":48992,"dst_port":8088,"service":"http","classification":"web_attack","waf_score":46,"waf_tags":"[\u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950347:rce-5\u0022, \u0022950406:ssrf-3\u0022, \u0022950407:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950471:nosqli-3\u0022]","http_method":"POST","http_target":"\/apply.cgi","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 9, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: \u0022cgi\u0022, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u00225af561107125d8ccc4aac442a3b8b5dee6769a85\u0022, \u0022http_target_hash\u0022: \u002231402cc48ac7ac052e1d50fc94349665a12c2c45\u0022, \u0022http_referer_hash\u0022: \u00226c9a85e19b48ee7bc090955b4a30836f92b398b3\u0022, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 527, \u0022payload_entropy\u0022: 5.5290084570180955, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 11, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022c462123b86055af1f088af29d93b9f739404af06\u0022, \u0022event_fingerprint\u0022: \u0022e230c8d6502b49facf567d595be91913490875a9\u0022, \u0022tags_list\u0022: [\u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950347:rce-5\u0022, \u0022950406:ssrf-3\u0022, \u0022950407:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022http_auth_header_token\u0022, \u0022http_basic_auth\u0022, \u0022http_basic_auth_header\u0022, \u0022http_jwt_body\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:8088","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":"http:\/\/62.3.50.33:8088\/apply.cgi","tags":"[\u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950347:rce-5\u0022, \u0022950406:ssrf-3\u0022, \u0022950407:ssrf-3\u0022, \u0022950470:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022http_auth_header_token\u0022, \u0022http_basic_auth\u0022, \u0022http_basic_auth_header\u0022, \u0022http_jwt_body\u0022]","anomalies":"[]","severity":10,"bytes_in":527},{"id":7914223,"ip":"124.198.131.22","ts":"2026-05-29 01:13:04.000000","proto":"tcp","src_port":56894,"dst_port":8080,"service":"http","classification":"web_attack","waf_score":41,"waf_tags":"[\u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950335:rce-2\u0022, \u0022950347:rce-5\u0022, \u0022950407:ssrf-3\u0022, \u0022950471:nosqli-3\u0022]","http_method":"POST","http_target":"\/tmUnblock.cgi","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 6, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: \u0022cgi\u0022, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u0022c9908f9a31aefa5902e21ee9fa132cbe056c536d\u0022, \u0022http_target_hash\u0022: \u00226cff281bfb0055f2e5c6afc1d923500419949544\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 382, \u0022payload_entropy\u0022: 5.454099199504813, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 7, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022cc13924fce73fe7ffe42096010cdb85ae7490c9a\u0022, \u0022event_fingerprint\u0022: \u002297fceacd435ac6fbd3ffa80bcd61aaea2c82cd79\u0022, \u0022tags_list\u0022: [\u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950335:rce-2\u0022, \u0022950347:rce-5\u0022, \u0022950407:ssrf-3\u0022, \u0022950471:nosqli-3\u0022, \u0022http_jwt_body\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:8080","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950335:rce-2\u0022, \u0022950347:rce-5\u0022, \u0022950407:ssrf-3\u0022, \u0022950471:nosqli-3\u0022, \u0022http_jwt_body\u0022]","anomalies":"[]","severity":10,"bytes_in":382},{"id":7914224,"ip":"124.198.131.22","ts":"2026-05-29 01:13:04.000000","proto":"tcp","src_port":56906,"dst_port":8080,"service":"http","classification":"web_attack","waf_score":47,"waf_tags":"[\u0022950019:sqli-4\u0022, \u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950347:rce-5\u0022, \u0022950407:ssrf-3\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022]","http_method":"POST","http_target":"\/goform\/set_LimitClient_cfg","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 7, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 2, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u0022c9908f9a31aefa5902e21ee9fa132cbe056c536d\u0022, \u0022http_target_hash\u0022: \u002211e5f78f4036aff2c472248972fe32123c6ace43\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 354, \u0022payload_entropy\u0022: 5.361772559132838, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 10, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022abbdf3e68cf80eaf1b9a861318ccf00d74512f1e\u0022, \u0022event_fingerprint\u0022: \u002211e0ab521c07a0034bc0b4c05903e76baeecc0fd\u0022, \u0022tags_list\u0022: [\u0022950019:sqli-4\u0022, \u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950347:rce-5\u0022, \u0022950407:ssrf-3\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022http_jwt_body\u0022, \u0022http_probe_goform\u0022, \u0022http_sensitive_path\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:8080","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950019:sqli-4\u0022, \u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950347:rce-5\u0022, \u0022950407:ssrf-3\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022http_jwt_body\u0022, \u0022http_probe_goform\u0022, \u0022http_sensitive_path\u0022]","anomalies":"[]","severity":10,"bytes_in":354},{"id":7911330,"ip":"124.198.131.22","ts":"2026-05-28 23:33:24.000000","proto":"tcp","src_port":37812,"dst_port":2525,"service":"http","classification":"web_attack","waf_score":41,"waf_tags":"[\u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950335:rce-2\u0022, \u0022950347:rce-5\u0022, \u0022950407:ssrf-3\u0022, \u0022950471:nosqli-3\u0022]","http_method":"POST","http_target":"\/tmUnblock.cgi","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 6, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: \u0022cgi\u0022, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u0022c9908f9a31aefa5902e21ee9fa132cbe056c536d\u0022, \u0022http_target_hash\u0022: \u00226cff281bfb0055f2e5c6afc1d923500419949544\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 382, \u0022payload_entropy\u0022: 5.454099199504813, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 7, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u00224f6480fc5ed2b7bed817070e8d628ab16b794bf9\u0022, \u0022event_fingerprint\u0022: \u0022b3a8b4d820bd7d5adb8f6f11b3e869ddf0758d7b\u0022, \u0022tags_list\u0022: [\u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950335:rce-2\u0022, \u0022950347:rce-5\u0022, \u0022950407:ssrf-3\u0022, \u0022950471:nosqli-3\u0022, \u0022http_jwt_body\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:8080","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950311:lfi-12\u0022, \u0022950327:rce-0\u0022, \u0022950335:rce-2\u0022, \u0022950347:rce-5\u0022, \u0022950407:ssrf-3\u0022, \u0022950471:nosqli-3\u0022, \u0022http_jwt_body\u0022]","anomalies":"[]","severity":10,"bytes_in":382},{"id":7904725,"ip":"124.198.131.22","ts":"2026-05-28 20:07:47.000000","proto":"tcp","src_port":60600,"dst_port":8022,"service":null,"classification":"botnet_attack","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 178, \u0022payload_entropy\u0022: 4.9408842760739855, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: null, \u0022app_proto\u0022: null, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 1, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 91, \u0022campaign_key\u0022: \u00229da3ae2f4411403cc6c6bbb9f1f2c55e9dbfc37d\u0022, \u0022event_fingerprint\u0022: \u002233d5ca7a5c248de0d43e8514895a4f4e21ccabdd\u0022, \u0022tags_list\u0022: [\u0022botnet_c2\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022botnet_c2\u0022]","anomalies":"[]","severity":7,"bytes_in":178},{"id":7894804,"ip":"124.198.131.22","ts":"2026-05-28 18:46:41.000000","proto":"tcp","src_port":55162,"dst_port":8021,"service":null,"classification":"botnet_attack","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 178, \u0022payload_entropy\u0022: 4.9408842760739855, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: null, \u0022app_proto\u0022: null, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 1, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 91, \u0022campaign_key\u0022: \u0022f1be25d341c23808e8f03c99b9e78723a14973b0\u0022, \u0022event_fingerprint\u0022: \u00227cdd4152ce13704ee08f8f053cb26caf6a3a7a23\u0022, \u0022tags_list\u0022: [\u0022botnet_c2\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022botnet_c2\u0022]","anomalies":"[]","severity":7,"bytes_in":178},{"id":7894803,"ip":"124.198.131.22","ts":"2026-05-28 18:46:40.000000","proto":"tcp","src_port":55154,"dst_port":8021,"service":null,"classification":"botnet_attack","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 178, \u0022payload_entropy\u0022: 4.9408842760739855, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: null, \u0022app_proto\u0022: null, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 1, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 91, \u0022campaign_key\u0022: \u0022f1be25d341c23808e8f03c99b9e78723a14973b0\u0022, \u0022event_fingerprint\u0022: \u00227cdd4152ce13704ee08f8f053cb26caf6a3a7a23\u0022, \u0022tags_list\u0022: [\u0022botnet_c2\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022botnet_c2\u0022]","anomalies":"[]","severity":7,"bytes_in":178},{"id":7894075,"ip":"124.198.131.22","ts":"2026-05-28 18:27:08.000000","proto":"tcp","src_port":59426,"dst_port":3000,"service":"http","classification":"web_attack","waf_score":42,"waf_tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022]","http_method":"POST","http_target":"\/api","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 7, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u002246f5955a67387b75de712e640b0687c888a438e5\u0022, \u0022http_target_hash\u0022: \u0022ada91241341ae792ecf0a59cad28616a77bab856\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 951, \u0022payload_entropy\u0022: 5.477458672522051, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 10, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022e49195bce497c65c06941e6ef27785bb42dafe40\u0022, \u0022event_fingerprint\u0022: \u00228f28b75b15a449a81db05f356f3f02b57bdaf25d\u0022, \u0022tags_list\u0022: [\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022, \u0022http_probe_api\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:3000","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022, \u0022http_probe_api\u0022]","anomalies":"[]","severity":10,"bytes_in":951},{"id":7890483,"ip":"124.198.131.22","ts":"2026-05-28 17:03:23.000000","proto":"tcp","src_port":41110,"dst_port":3000,"service":"http","classification":"web_attack","waf_score":38,"waf_tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022]","http_method":"POST","http_target":"\/_next","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 7, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u002246f5955a67387b75de712e640b0687c888a438e5\u0022, \u0022http_target_hash\u0022: \u0022afd9bdeafd8c657f6b493ada03c51e348516227b\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 953, \u0022payload_entropy\u0022: 5.477328163409766, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 8, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022c0da2de6402b95e491d6fb944a5be5e204ceba08\u0022, \u0022event_fingerprint\u0022: \u0022c5bdee8ada8d10d23c51954cc145e572e92ee340\u0022, \u0022tags_list\u0022: [\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:3000","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]","anomalies":"[]","severity":10,"bytes_in":953},{"id":7890442,"ip":"124.198.131.22","ts":"2026-05-28 17:02:22.000000","proto":"tcp","src_port":42118,"dst_port":8022,"service":null,"classification":"botnet_attack","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 178, \u0022payload_entropy\u0022: 4.9408842760739855, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: null, \u0022app_proto\u0022: null, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 1, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 91, \u0022campaign_key\u0022: \u00229da3ae2f4411403cc6c6bbb9f1f2c55e9dbfc37d\u0022, \u0022event_fingerprint\u0022: \u002233d5ca7a5c248de0d43e8514895a4f4e21ccabdd\u0022, \u0022tags_list\u0022: [\u0022botnet_c2\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022botnet_c2\u0022]","anomalies":"[]","severity":7,"bytes_in":178},{"id":7887075,"ip":"124.198.131.22","ts":"2026-05-28 15:43:02.000000","proto":"tcp","src_port":37342,"dst_port":8021,"service":null,"classification":"botnet_attack","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 178, \u0022payload_entropy\u0022: 4.9408842760739855, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: null, \u0022app_proto\u0022: null, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 1, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 91, \u0022campaign_key\u0022: \u0022f1be25d341c23808e8f03c99b9e78723a14973b0\u0022, \u0022event_fingerprint\u0022: \u00227cdd4152ce13704ee08f8f053cb26caf6a3a7a23\u0022, \u0022tags_list\u0022: [\u0022botnet_c2\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022botnet_c2\u0022]","anomalies":"[]","severity":7,"bytes_in":178},{"id":7879377,"ip":"124.198.131.22","ts":"2026-05-28 12:10:13.000000","proto":"tcp","src_port":51004,"dst_port":8022,"service":null,"classification":"botnet_attack","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 178, \u0022payload_entropy\u0022: 4.9408842760739855, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: null, \u0022app_proto\u0022: null, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 1, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 91, \u0022campaign_key\u0022: \u00229da3ae2f4411403cc6c6bbb9f1f2c55e9dbfc37d\u0022, \u0022event_fingerprint\u0022: \u002233d5ca7a5c248de0d43e8514895a4f4e21ccabdd\u0022, \u0022tags_list\u0022: [\u0022botnet_c2\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022botnet_c2\u0022]","anomalies":"[]","severity":7,"bytes_in":178},{"id":7877566,"ip":"124.198.131.22","ts":"2026-05-28 11:03:42.000000","proto":"tcp","src_port":43308,"dst_port":8021,"service":null,"classification":"botnet_attack","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 178, \u0022payload_entropy\u0022: 4.9408842760739855, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: null, \u0022app_proto\u0022: null, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 1, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 91, \u0022campaign_key\u0022: \u0022f1be25d341c23808e8f03c99b9e78723a14973b0\u0022, \u0022event_fingerprint\u0022: \u00227cdd4152ce13704ee08f8f053cb26caf6a3a7a23\u0022, \u0022tags_list\u0022: [\u0022botnet_c2\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022botnet_c2\u0022]","anomalies":"[]","severity":7,"bytes_in":178},{"id":7874793,"ip":"124.198.131.22","ts":"2026-05-28 09:37:10.000000","proto":"tcp","src_port":47208,"dst_port":8021,"service":null,"classification":"botnet_attack","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 178, \u0022payload_entropy\u0022: 4.9408842760739855, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: null, \u0022app_proto\u0022: null, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 1, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 91, \u0022campaign_key\u0022: \u0022f1be25d341c23808e8f03c99b9e78723a14973b0\u0022, \u0022event_fingerprint\u0022: \u00227cdd4152ce13704ee08f8f053cb26caf6a3a7a23\u0022, \u0022tags_list\u0022: [\u0022botnet_c2\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022botnet_c2\u0022]","anomalies":"[]","severity":7,"bytes_in":178},{"id":7873220,"ip":"124.198.131.22","ts":"2026-05-28 08:48:27.000000","proto":"tcp","src_port":42844,"dst_port":8022,"service":null,"classification":"botnet_attack","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 178, \u0022payload_entropy\u0022: 4.9408842760739855, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: null, \u0022app_proto\u0022: null, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 1, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 91, \u0022campaign_key\u0022: \u00229da3ae2f4411403cc6c6bbb9f1f2c55e9dbfc37d\u0022, \u0022event_fingerprint\u0022: \u002233d5ca7a5c248de0d43e8514895a4f4e21ccabdd\u0022, \u0022tags_list\u0022: [\u0022botnet_c2\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022botnet_c2\u0022]","anomalies":"[]","severity":7,"bytes_in":178},{"id":7872498,"ip":"124.198.131.22","ts":"2026-05-28 08:20:50.000000","proto":"tcp","src_port":36404,"dst_port":8021,"service":null,"classification":"botnet_attack","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 178, \u0022payload_entropy\u0022: 4.9408842760739855, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: null, \u0022app_proto\u0022: null, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 1, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 91, \u0022campaign_key\u0022: \u0022f1be25d341c23808e8f03c99b9e78723a14973b0\u0022, \u0022event_fingerprint\u0022: \u00227cdd4152ce13704ee08f8f053cb26caf6a3a7a23\u0022, \u0022tags_list\u0022: [\u0022botnet_c2\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022botnet_c2\u0022]","anomalies":"[]","severity":7,"bytes_in":178},{"id":7869313,"ip":"124.198.131.22","ts":"2026-05-28 06:45:14.000000","proto":"tcp","src_port":60050,"dst_port":3001,"service":"http","classification":"web_attack","waf_score":38,"waf_tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022]","http_method":"POST","http_target":"\/app","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 7, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u002268964bd149320edbceb0d6a222e6bc3e0bdb74e3\u0022, \u0022http_target_hash\u0022: \u00220c35eebf403cf91fe77a64921d76aa1ca6411d20\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 951, \u0022payload_entropy\u0022: 5.478998262080779, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 8, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022dd5a73f35233e426e852ed574c0f966ad5528c5f\u0022, \u0022event_fingerprint\u0022: \u0022784362bc6da70e2cff030bb2a8d729e0f0fe9c3b\u0022, \u0022tags_list\u0022: [\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:3001","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]","anomalies":"[]","severity":10,"bytes_in":951},{"id":7858589,"ip":"124.198.131.22","ts":"2026-05-28 05:34:05.000000","proto":"tcp","src_port":59194,"dst_port":8022,"service":null,"classification":"botnet_attack","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 178, \u0022payload_entropy\u0022: 4.9408842760739855, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: null, \u0022app_proto\u0022: null, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 1, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 91, \u0022campaign_key\u0022: \u00229da3ae2f4411403cc6c6bbb9f1f2c55e9dbfc37d\u0022, \u0022event_fingerprint\u0022: \u002233d5ca7a5c248de0d43e8514895a4f4e21ccabdd\u0022, \u0022tags_list\u0022: [\u0022botnet_c2\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022botnet_c2\u0022]","anomalies":"[]","severity":7,"bytes_in":178},{"id":7857628,"ip":"124.198.131.22","ts":"2026-05-28 05:28:40.000000","proto":"tcp","src_port":55804,"dst_port":8022,"service":null,"classification":"botnet_attack","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 178, \u0022payload_entropy\u0022: 4.9408842760739855, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: null, \u0022app_proto\u0022: null, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 1, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 91, \u0022campaign_key\u0022: \u00229da3ae2f4411403cc6c6bbb9f1f2c55e9dbfc37d\u0022, \u0022event_fingerprint\u0022: \u002233d5ca7a5c248de0d43e8514895a4f4e21ccabdd\u0022, \u0022tags_list\u0022: [\u0022botnet_c2\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022botnet_c2\u0022]","anomalies":"[]","severity":7,"bytes_in":178},{"id":7814131,"ip":"124.198.131.22","ts":"2026-05-27 18:40:06.000000","proto":"tcp","src_port":39766,"dst_port":3000,"service":"http","classification":"web_attack","waf_score":48,"waf_tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022]","http_method":"POST","http_target":"\/api\/route","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 7, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 2, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u002246f5955a67387b75de712e640b0687c888a438e5\u0022, \u0022http_target_hash\u0022: \u00221a9b2c3dbe8a713bfc0c240bb1a6ea2141b55601\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 957, \u0022payload_entropy\u0022: 5.474723686374105, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 11, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022467de5788c88bb68076b2f0fbfe0feb7c4e5dd6f\u0022, \u0022event_fingerprint\u0022: \u0022c49c13ab95b8dcb466553405b9993e7e27e55cdb\u0022, \u0022tags_list\u0022: [\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022, \u0022http_probe_api\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:3000","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022, \u0022http_probe_api\u0022]","anomalies":"[]","severity":10,"bytes_in":957},{"id":7813216,"ip":"124.198.131.22","ts":"2026-05-27 18:02:21.000000","proto":"tcp","src_port":34988,"dst_port":3000,"service":"http","classification":"web_attack","waf_score":38,"waf_tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022]","http_method":"POST","http_target":"\/app","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 7, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u002246f5955a67387b75de712e640b0687c888a438e5\u0022, \u0022http_target_hash\u0022: \u00220c35eebf403cf91fe77a64921d76aa1ca6411d20\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 951, \u0022payload_entropy\u0022: 5.477789822834032, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 8, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022c0da2de6402b95e491d6fb944a5be5e204ceba08\u0022, \u0022event_fingerprint\u0022: \u00229434400c4aecded381b24d5a44d87483e1bc631c\u0022, \u0022tags_list\u0022: [\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:3000","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]","anomalies":"[]","severity":10,"bytes_in":951},{"id":7812771,"ip":"124.198.131.22","ts":"2026-05-27 17:44:38.000000","proto":"tcp","src_port":53614,"dst_port":3000,"service":"http","classification":"web_attack","waf_score":48,"waf_tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022]","http_method":"POST","http_target":"\/api\/route","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 7, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 2, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u002246f5955a67387b75de712e640b0687c888a438e5\u0022, \u0022http_target_hash\u0022: \u00221a9b2c3dbe8a713bfc0c240bb1a6ea2141b55601\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 957, \u0022payload_entropy\u0022: 5.474723686374105, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 11, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022467de5788c88bb68076b2f0fbfe0feb7c4e5dd6f\u0022, \u0022event_fingerprint\u0022: \u0022c49c13ab95b8dcb466553405b9993e7e27e55cdb\u0022, \u0022tags_list\u0022: [\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022, \u0022http_probe_api\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:3000","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022, \u0022http_probe_api\u0022]","anomalies":"[]","severity":10,"bytes_in":957},{"id":7812297,"ip":"124.198.131.22","ts":"2026-05-27 17:25:58.000000","proto":"tcp","src_port":36228,"dst_port":3000,"service":"http","classification":"web_attack","waf_score":48,"waf_tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022]","http_method":"POST","http_target":"\/api\/route","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 7, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 2, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u002246f5955a67387b75de712e640b0687c888a438e5\u0022, \u0022http_target_hash\u0022: \u00221a9b2c3dbe8a713bfc0c240bb1a6ea2141b55601\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 957, \u0022payload_entropy\u0022: 5.474723686374105, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 11, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022467de5788c88bb68076b2f0fbfe0feb7c4e5dd6f\u0022, \u0022event_fingerprint\u0022: \u0022c49c13ab95b8dcb466553405b9993e7e27e55cdb\u0022, \u0022tags_list\u0022: [\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022, \u0022http_probe_api\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:3000","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022, \u0022http_probe_api\u0022]","anomalies":"[]","severity":10,"bytes_in":957},{"id":7811110,"ip":"124.198.131.22","ts":"2026-05-27 16:33:38.000000","proto":"tcp","src_port":40346,"dst_port":3000,"service":"http","classification":"web_attack","waf_score":41,"waf_tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950734:sap-sapcontrol-path\u0022]","http_method":"POST","http_target":"\/","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 7, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u002246f5955a67387b75de712e640b0687c888a438e5\u0022, \u0022http_target_hash\u0022: \u002242099b4af021e53fd8fd4e056c2568d7c2e3ffa8\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 948, \u0022payload_entropy\u0022: 5.478238412114009, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 9, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u002237e6d9b17bed0926d1279d6e3f23985eaeb94dc5\u0022, \u0022event_fingerprint\u0022: \u00220a214565a1a673fa2b423a6100124922e6892757\u0022, \u0022tags_list\u0022: [\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950734:sap-sapcontrol-path\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:3000","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950734:sap-sapcontrol-path\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]","anomalies":"[]","severity":10,"bytes_in":948},{"id":7805495,"ip":"124.198.131.22","ts":"2026-05-27 13:20:02.000000","proto":"tcp","src_port":53070,"dst_port":3000,"service":"http","classification":"web_attack","waf_score":48,"waf_tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022]","http_method":"POST","http_target":"\/api\/route","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 7, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 2, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u002246f5955a67387b75de712e640b0687c888a438e5\u0022, \u0022http_target_hash\u0022: \u00221a9b2c3dbe8a713bfc0c240bb1a6ea2141b55601\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 957, \u0022payload_entropy\u0022: 5.474723686374105, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 11, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022467de5788c88bb68076b2f0fbfe0feb7c4e5dd6f\u0022, \u0022event_fingerprint\u0022: \u0022c49c13ab95b8dcb466553405b9993e7e27e55cdb\u0022, \u0022tags_list\u0022: [\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022, \u0022http_probe_api\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:3000","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022, \u0022http_probe_api\u0022]","anomalies":"[]","severity":10,"bytes_in":957},{"id":7791121,"ip":"124.198.131.22","ts":"2026-05-27 11:31:42.000000","proto":"tcp","src_port":60792,"dst_port":3000,"service":"http","classification":"web_attack","waf_score":44,"waf_tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022]","http_method":"POST","http_target":"\/_next\/server","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 7, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 2, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u002246f5955a67387b75de712e640b0687c888a438e5\u0022, \u0022http_target_hash\u0022: \u0022bef481449499f499a0b29ed75c9630076205b04f\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 960, \u0022payload_entropy\u0022: 5.476719753805595, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 9, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022b2cc074b4e27a1918ace1473f7a43da1f30cb064\u0022, \u0022event_fingerprint\u0022: \u00229db61e8e4d6fa7ec30de8a565cc70439b5f61dca\u0022, \u0022tags_list\u0022: [\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:3000","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]","anomalies":"[]","severity":10,"bytes_in":960},{"id":7789070,"ip":"124.198.131.22","ts":"2026-05-27 10:52:12.000000","proto":"tcp","src_port":51514,"dst_port":3000,"service":"http","classification":"web_attack","waf_score":42,"waf_tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022]","http_method":"POST","http_target":"\/api","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 7, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u002246f5955a67387b75de712e640b0687c888a438e5\u0022, \u0022http_target_hash\u0022: \u0022ada91241341ae792ecf0a59cad28616a77bab856\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 951, \u0022payload_entropy\u0022: 5.477458672522051, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 10, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022e49195bce497c65c06941e6ef27785bb42dafe40\u0022, \u0022event_fingerprint\u0022: \u00228f28b75b15a449a81db05f356f3f02b57bdaf25d\u0022, \u0022tags_list\u0022: [\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022, \u0022http_probe_api\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:3000","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022, \u0022http_probe_api\u0022]","anomalies":"[]","severity":10,"bytes_in":951},{"id":7789067,"ip":"124.198.131.22","ts":"2026-05-27 10:52:11.000000","proto":"tcp","src_port":51502,"dst_port":3000,"service":"http","classification":"web_attack","waf_score":42,"waf_tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022]","http_method":"POST","http_target":"\/api","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 7, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u002246f5955a67387b75de712e640b0687c888a438e5\u0022, \u0022http_target_hash\u0022: \u0022ada91241341ae792ecf0a59cad28616a77bab856\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 951, \u0022payload_entropy\u0022: 5.477458672522051, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 10, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022e49195bce497c65c06941e6ef27785bb42dafe40\u0022, \u0022event_fingerprint\u0022: \u00228f28b75b15a449a81db05f356f3f02b57bdaf25d\u0022, \u0022tags_list\u0022: [\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022, \u0022http_probe_api\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:3000","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022, \u0022http_probe_api\u0022]","anomalies":"[]","severity":10,"bytes_in":951},{"id":7782402,"ip":"124.198.131.22","ts":"2026-05-27 08:42:25.000000","proto":"tcp","src_port":47116,"dst_port":3000,"service":"http","classification":"web_attack","waf_score":41,"waf_tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950734:sap-sapcontrol-path\u0022]","http_method":"POST","http_target":"\/","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 7, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u002246f5955a67387b75de712e640b0687c888a438e5\u0022, \u0022http_target_hash\u0022: \u002242099b4af021e53fd8fd4e056c2568d7c2e3ffa8\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 948, \u0022payload_entropy\u0022: 5.478238412114009, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 9, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u002237e6d9b17bed0926d1279d6e3f23985eaeb94dc5\u0022, \u0022event_fingerprint\u0022: \u00220a214565a1a673fa2b423a6100124922e6892757\u0022, \u0022tags_list\u0022: [\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950734:sap-sapcontrol-path\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:3000","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950734:sap-sapcontrol-path\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]","anomalies":"[]","severity":10,"bytes_in":948},{"id":7782215,"ip":"124.198.131.22","ts":"2026-05-27 08:37:09.000000","proto":"tcp","src_port":48720,"dst_port":3000,"service":"http","classification":"web_attack","waf_score":38,"waf_tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022]","http_method":"POST","http_target":"\/_next","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 7, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u002246f5955a67387b75de712e640b0687c888a438e5\u0022, \u0022http_target_hash\u0022: \u0022afd9bdeafd8c657f6b493ada03c51e348516227b\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 953, \u0022payload_entropy\u0022: 5.477328163409766, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 8, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022c0da2de6402b95e491d6fb944a5be5e204ceba08\u0022, \u0022event_fingerprint\u0022: \u0022c5bdee8ada8d10d23c51954cc145e572e92ee340\u0022, \u0022tags_list\u0022: [\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:3000","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]","anomalies":"[]","severity":10,"bytes_in":953},{"id":7779499,"ip":"124.198.131.22","ts":"2026-05-27 07:08:12.000000","proto":"tcp","src_port":49984,"dst_port":3000,"service":"http","classification":"web_attack","waf_score":44,"waf_tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022]","http_method":"POST","http_target":"\/_next\/server","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 7, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 2, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u002246f5955a67387b75de712e640b0687c888a438e5\u0022, \u0022http_target_hash\u0022: \u0022bef481449499f499a0b29ed75c9630076205b04f\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 960, \u0022payload_entropy\u0022: 5.476719753805595, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 9, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022b2cc074b4e27a1918ace1473f7a43da1f30cb064\u0022, \u0022event_fingerprint\u0022: \u00229db61e8e4d6fa7ec30de8a565cc70439b5f61dca\u0022, \u0022tags_list\u0022: [\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:3000","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]","anomalies":"[]","severity":10,"bytes_in":960},{"id":7777777,"ip":"124.198.131.22","ts":"2026-05-27 06:02:13.000000","proto":"tcp","src_port":58852,"dst_port":3000,"service":"http","classification":"web_attack","waf_score":38,"waf_tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022]","http_method":"POST","http_target":"\/app","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 7, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u002246f5955a67387b75de712e640b0687c888a438e5\u0022, \u0022http_target_hash\u0022: \u00220c35eebf403cf91fe77a64921d76aa1ca6411d20\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 951, \u0022payload_entropy\u0022: 5.477789822834032, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 8, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022c0da2de6402b95e491d6fb944a5be5e204ceba08\u0022, \u0022event_fingerprint\u0022: \u00229434400c4aecded381b24d5a44d87483e1bc631c\u0022, \u0022tags_list\u0022: [\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:3000","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]","anomalies":"[]","severity":10,"bytes_in":951},{"id":7777107,"ip":"124.198.131.22","ts":"2026-05-27 05:34:45.000000","proto":"tcp","src_port":56044,"dst_port":3000,"service":"http","classification":"web_attack","waf_score":38,"waf_tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022]","http_method":"POST","http_target":"\/_next","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 7, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u002246f5955a67387b75de712e640b0687c888a438e5\u0022, \u0022http_target_hash\u0022: \u0022afd9bdeafd8c657f6b493ada03c51e348516227b\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 953, \u0022payload_entropy\u0022: 5.477328163409766, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 8, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022c0da2de6402b95e491d6fb944a5be5e204ceba08\u0022, \u0022event_fingerprint\u0022: \u0022c5bdee8ada8d10d23c51954cc145e572e92ee340\u0022, \u0022tags_list\u0022: [\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:3000","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]","anomalies":"[]","severity":10,"bytes_in":953},{"id":7774101,"ip":"124.198.131.22","ts":"2026-05-27 03:37:15.000000","proto":"tcp","src_port":34844,"dst_port":3000,"service":"http","classification":"web_attack","waf_score":41,"waf_tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950734:sap-sapcontrol-path\u0022]","http_method":"POST","http_target":"\/","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 7, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u002246f5955a67387b75de712e640b0687c888a438e5\u0022, \u0022http_target_hash\u0022: \u002242099b4af021e53fd8fd4e056c2568d7c2e3ffa8\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 948, \u0022payload_entropy\u0022: 5.478238412114009, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 9, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u002237e6d9b17bed0926d1279d6e3f23985eaeb94dc5\u0022, \u0022event_fingerprint\u0022: \u00220a214565a1a673fa2b423a6100124922e6892757\u0022, \u0022tags_list\u0022: [\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950734:sap-sapcontrol-path\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:3000","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950734:sap-sapcontrol-path\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]","anomalies":"[]","severity":10,"bytes_in":948},{"id":7772182,"ip":"124.198.131.22","ts":"2026-05-27 02:44:38.000000","proto":"tcp","src_port":48496,"dst_port":3000,"service":"http","classification":"web_attack","waf_score":41,"waf_tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950734:sap-sapcontrol-path\u0022]","http_method":"POST","http_target":"\/","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 7, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u002246f5955a67387b75de712e640b0687c888a438e5\u0022, \u0022http_target_hash\u0022: \u002242099b4af021e53fd8fd4e056c2568d7c2e3ffa8\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 948, \u0022payload_entropy\u0022: 5.478238412114009, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 9, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u002237e6d9b17bed0926d1279d6e3f23985eaeb94dc5\u0022, \u0022event_fingerprint\u0022: \u00220a214565a1a673fa2b423a6100124922e6892757\u0022, \u0022tags_list\u0022: [\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950734:sap-sapcontrol-path\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:3000","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950734:sap-sapcontrol-path\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]","anomalies":"[]","severity":10,"bytes_in":948},{"id":7771801,"ip":"124.198.131.22","ts":"2026-05-27 02:26:54.000000","proto":"tcp","src_port":54706,"dst_port":3000,"service":"http","classification":"web_attack","waf_score":38,"waf_tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022]","http_method":"POST","http_target":"\/_next","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 7, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u002246f5955a67387b75de712e640b0687c888a438e5\u0022, \u0022http_target_hash\u0022: \u0022afd9bdeafd8c657f6b493ada03c51e348516227b\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 953, \u0022payload_entropy\u0022: 5.477328163409766, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 8, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022c0da2de6402b95e491d6fb944a5be5e204ceba08\u0022, \u0022event_fingerprint\u0022: \u0022c5bdee8ada8d10d23c51954cc145e572e92ee340\u0022, \u0022tags_list\u0022: [\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:3000","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]","anomalies":"[]","severity":10,"bytes_in":953},{"id":7768533,"ip":"124.198.131.22","ts":"2026-05-27 00:07:02.000000","proto":"tcp","src_port":42722,"dst_port":3000,"service":"http","classification":"web_attack","waf_score":41,"waf_tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950734:sap-sapcontrol-path\u0022]","http_method":"POST","http_target":"\/","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 7, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u002246f5955a67387b75de712e640b0687c888a438e5\u0022, \u0022http_target_hash\u0022: \u002242099b4af021e53fd8fd4e056c2568d7c2e3ffa8\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 948, \u0022payload_entropy\u0022: 5.478238412114009, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 9, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u002237e6d9b17bed0926d1279d6e3f23985eaeb94dc5\u0022, \u0022event_fingerprint\u0022: \u00220a214565a1a673fa2b423a6100124922e6892757\u0022, \u0022tags_list\u0022: [\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950734:sap-sapcontrol-path\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:3000","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950734:sap-sapcontrol-path\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]","anomalies":"[]","severity":10,"bytes_in":948}],"total_events":147}