{"ip":"148.66.132.204","exported_at":"2026-06-13T22:20:59+00:00","period_days":90,"metrics":{"events7d":0,"distinct_ports":0,"distinct_classifications":0,"max_severity":null,"last_sensor_id":"paris-1","max_waf_score":null,"max_risk_score":76,"attack_stage":"probe","attack_chain_stage":null,"threat_family":["scanner"],"recommended_action":"monitor","confidence":0.71,"risk_breakdown":{"waf":0,"classification":30,"behavior":0,"geo":0,"protocol":0,"novelty":0},"mitre_tactics":["TA0007","TA0001"],"mitre_technique":null,"top_mitre_technique":null,"top_mitre_count":null,"executive_one_liner_fr":"risque 8\/100","campaign_hint_fr":null,"confidence_breakdown":[],"persona_hostname":null,"correlation_flags":[],"correlation_flags_labels_fr":[],"confidence_pct":71,"confidence_hint_fr":null,"sensor_role_label_fr":null,"tags_summary_labels_fr":[],"tags_summary":[],"attack_vector":null,"protocol_details":[],"protocol_summary_fr":null,"evidence_snippet":"SSH-2.0-libssh_0.9.6","target_port_label":"2525","emulator_service":null,"confidence_reason":null,"classification_reason":null,"classification_reason_label_fr":null,"confidence_factors_fr":null,"payload_preview":"SSH-2.0-libssh_0.9.6"},"events":[{"id":8159860,"ip":"148.66.132.204","ts":"2026-06-02 17:50:23.000000","proto":"tcp","src_port":47722,"dst_port":2525,"service":"ssh","classification":"ssh_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 22, \u0022payload_entropy\u0022: 3.879664004902593, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022GoDaddy.com, LLC\u0022, \u0022service\u0022: \u0022ssh\u0022, \u0022app_proto\u0022: \u0022ssh\u0022, \u0022asn\u0022: 26496, \u0022country\u0022: \u0022SG\u0022, \u0022risk_waf\u0022: 0.0, \u0022risk_classification\u0022: 30.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 0.0, \u0022risk_novelty\u0022: 0.0, \u0022risk_boost\u0022: 0, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 0.0, \u0022classification\u0022: 30.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 0.0, \u0022novelty\u0022: 0.0}, \u0022risk_score\u0022: 8, \u0022tag_count\u0022: 2, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u0022c39e8ccf813c56df4d79c64bebc0b1bc7a1d0d45\u0022, \u0022event_fingerprint\u0022: \u0022fbcd176559a24e0470ce268b04406fa70b0b470d\u0022, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022SG\u0022, \u0022asn\u0022: 26496, \u0022org\u0022: \u0022GoDaddy.com, LLC\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022c6c435cd5755c7361597477daa7a2618\u0022, \u0022path_pattern_hash\u0022: \u00224368b1c212b6962fb95d1d1144451aca\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 2525, \u0022service\u0022: \u0022ssh\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022confidence\u0022: 0.71, \u0022classification_confidence\u0022: 0.71, \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022payload_preview\u0022: \u0022SSH-2.0-libssh_0.9.6\\r\\n\u0022, \u0022event_signature\u0022: \u0022cbaaa78d93645b854e93ac43c1ef29e6706a30ba\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022ssh_banner\u0022, \u0022ssh_libssh\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022ssh_banner\u0022, \u0022ssh_libssh\u0022]","anomalies":"[]","severity":6,"bytes_in":22},{"id":7253913,"ip":"148.66.132.204","ts":"2026-05-18 15:41:23.000000","proto":"tcp","src_port":38410,"dst_port":22,"service":"ssh","classification":"ssh_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 22, \u0022payload_entropy\u0022: 3.879664004902593, \u0022port_category\u0022: \u0022well_known\u0022, \u0022org\u0022: \u0022GoDaddy.com, LLC\u0022, \u0022service\u0022: \u0022ssh\u0022, \u0022app_proto\u0022: \u0022ssh\u0022, \u0022asn\u0022: 26496, \u0022country\u0022: \u0022SG\u0022, \u0022tag_count\u0022: 2, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 76, \u0022campaign_key\u0022: \u00224b687cfbd2a2f5b43a89ec258bffd822ae9203ba\u0022, \u0022event_fingerprint\u0022: \u0022bc4e3fa786c83e0db7c1c892cb0c288f6b14388f\u0022, \u0022tags_list\u0022: [\u0022ssh_banner\u0022, \u0022ssh_libssh\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022ssh_banner\u0022, \u0022ssh_libssh\u0022]","anomalies":"[]","severity":6,"bytes_in":22}],"total_events":2}