{"ip":"164.52.198.63","exported_at":"2026-06-18T10:33:39+00:00","period_days":30,"metrics":{"events7d":0,"distinct_ports":0,"distinct_classifications":0,"max_severity":null,"last_sensor_id":"paris-1","max_waf_score":null,"max_risk_score":100,"attack_stage":null,"attack_chain_stage":null,"threat_family":[],"recommended_action":null,"confidence":null,"risk_breakdown":[],"mitre_tactics":[],"mitre_technique":null,"top_mitre_technique":null,"top_mitre_count":null,"executive_one_liner_fr":"risque 33\/100","campaign_hint_fr":null,"confidence_breakdown":[],"persona_hostname":null,"correlation_flags":[],"correlation_flags_labels_fr":[],"confidence_pct":null,"confidence_hint_fr":null,"sensor_role_label_fr":null,"tags_summary_labels_fr":[],"tags_summary":[],"attack_vector":null,"protocol_details":[],"protocol_summary_fr":null,"evidence_snippet":null,"target_port_label":null,"emulator_service":null,"confidence_reason":null,"classification_reason":null,"classification_reason_label_fr":null,"confidence_factors_fr":null,"payload_preview":null},"events":[{"id":7787048,"ip":"164.52.198.63","ts":"2026-05-27 10:08:53.000000","proto":"tcp","src_port":52952,"dst_port":2087,"service":"tls","classification":"tls_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022tls_ja3_hash\u0022: \u00222079bcc000c9a54e0784733c0142d140\u0022, \u0022tls_sni\u0022: null, \u0022bytes_in\u0022: 263, \u0022payload_entropy\u0022: 5.714525723716398, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022282, Sector 19\u0022, \u0022service\u0022: \u0022tls\u0022, \u0022app_proto\u0022: \u0022tls\u0022, \u0022asn\u0022: 132420, \u0022country\u0022: \u0022IN\u0022, \u0022tag_count\u0022: 2, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 33, \u0022campaign_key\u0022: \u0022b5743cfb75853cf1e83e77fde101dbbdf9f38dd2\u0022, \u0022event_fingerprint\u0022: \u002248a1f0a9849104a5c435e1a4ff8525d2de560619\u0022, \u0022tags_list\u0022: [\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]}","tls_sni":null,"tls_ja3_hash":"2079bcc000c9a54e0784733c0142d140","tls_ja3":"771,49195-49199-49196-49200-52393-52392-49161-49171-49162-49172-49170-4865-4866-4867,11-65281-23-18-5-10-13-50-43-51,29-23-24-25,0","http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]","anomalies":"[]","severity":2,"bytes_in":263},{"id":7755661,"ip":"164.52.198.63","ts":"2026-05-26 15:18:49.000000","proto":"tcp","src_port":48030,"dst_port":2087,"service":"http","classification":"web_attack","waf_score":16,"waf_tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","http_method":"GET","http_target":"\/","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 4, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u00225002ada1c05fac60ce2af638d5f54066641d121c\u0022, \u0022http_host_hash\u0022: \u0022f632b4de18b92074e4c6a166d9c86de50717ec9c\u0022, \u0022http_target_hash\u0022: \u002242099b4af021e53fd8fd4e056c2568d7c2e3ffa8\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 185, \u0022payload_entropy\u0022: 5.363290281051377, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022282, Sector 19\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 132420, \u0022country\u0022: \u0022IN\u0022, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u00221d540436e2d6aa9427c2ed81ae6896a758daf914\u0022, \u0022event_fingerprint\u0022: \u00221ba90455c247b39020c65ad05e6912a1c19fe71b\u0022, \u0022tags_list\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:2087","http_user_agent":"Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36","http_referer":null,"tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","anomalies":"[]","severity":8,"bytes_in":185},{"id":7695372,"ip":"164.52.198.63","ts":"2026-05-25 05:15:12.000000","proto":"tcp","src_port":40562,"dst_port":2087,"service":"tls","classification":"tls_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022tls_ja3_hash\u0022: \u00222079bcc000c9a54e0784733c0142d140\u0022, \u0022tls_sni\u0022: null, \u0022bytes_in\u0022: 263, \u0022payload_entropy\u0022: 5.7014698731969835, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022282, Sector 19\u0022, \u0022service\u0022: \u0022tls\u0022, \u0022app_proto\u0022: \u0022tls\u0022, \u0022asn\u0022: 132420, \u0022country\u0022: \u0022IN\u0022, \u0022tag_count\u0022: 2, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 33, \u0022campaign_key\u0022: \u0022b5743cfb75853cf1e83e77fde101dbbdf9f38dd2\u0022, \u0022event_fingerprint\u0022: \u002248a1f0a9849104a5c435e1a4ff8525d2de560619\u0022, \u0022tags_list\u0022: [\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]}","tls_sni":null,"tls_ja3_hash":"2079bcc000c9a54e0784733c0142d140","tls_ja3":"771,49195-49199-49196-49200-52393-52392-49161-49171-49162-49172-49170-4865-4866-4867,11-65281-23-18-5-10-13-50-43-51,29-23-24-25,0","http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]","anomalies":"[]","severity":2,"bytes_in":263},{"id":7695373,"ip":"164.52.198.63","ts":"2026-05-25 05:15:12.000000","proto":"tcp","src_port":40556,"dst_port":2087,"service":"http","classification":"web_attack","waf_score":16,"waf_tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","http_method":"GET","http_target":"\/","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 4, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u00225002ada1c05fac60ce2af638d5f54066641d121c\u0022, \u0022http_host_hash\u0022: \u0022f632b4de18b92074e4c6a166d9c86de50717ec9c\u0022, \u0022http_target_hash\u0022: \u002242099b4af021e53fd8fd4e056c2568d7c2e3ffa8\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 185, \u0022payload_entropy\u0022: 5.363290281051377, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022282, Sector 19\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 132420, \u0022country\u0022: \u0022IN\u0022, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u00221d540436e2d6aa9427c2ed81ae6896a758daf914\u0022, \u0022event_fingerprint\u0022: \u00221ba90455c247b39020c65ad05e6912a1c19fe71b\u0022, \u0022tags_list\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:2087","http_user_agent":"Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36","http_referer":null,"tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","anomalies":"[]","severity":8,"bytes_in":185},{"id":7647312,"ip":"164.52.198.63","ts":"2026-05-24 07:17:57.000000","proto":"tcp","src_port":58070,"dst_port":2087,"service":"http","classification":"web_attack","waf_score":16,"waf_tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","http_method":"GET","http_target":"\/","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 4, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u00225002ada1c05fac60ce2af638d5f54066641d121c\u0022, \u0022http_host_hash\u0022: \u0022f632b4de18b92074e4c6a166d9c86de50717ec9c\u0022, \u0022http_target_hash\u0022: \u002242099b4af021e53fd8fd4e056c2568d7c2e3ffa8\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 185, \u0022payload_entropy\u0022: 5.363290281051377, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022282, Sector 19\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 132420, \u0022country\u0022: \u0022IN\u0022, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u00221d540436e2d6aa9427c2ed81ae6896a758daf914\u0022, \u0022event_fingerprint\u0022: \u00221ba90455c247b39020c65ad05e6912a1c19fe71b\u0022, \u0022tags_list\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:2087","http_user_agent":"Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36","http_referer":null,"tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","anomalies":"[]","severity":8,"bytes_in":185},{"id":7647313,"ip":"164.52.198.63","ts":"2026-05-24 07:17:57.000000","proto":"tcp","src_port":58086,"dst_port":2087,"service":"tls","classification":"tls_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022tls_ja3_hash\u0022: \u00222079bcc000c9a54e0784733c0142d140\u0022, \u0022tls_sni\u0022: null, \u0022bytes_in\u0022: 263, \u0022payload_entropy\u0022: 5.756759498027839, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022282, Sector 19\u0022, \u0022service\u0022: \u0022tls\u0022, \u0022app_proto\u0022: \u0022tls\u0022, \u0022asn\u0022: 132420, \u0022country\u0022: \u0022IN\u0022, \u0022tag_count\u0022: 2, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 33, \u0022campaign_key\u0022: \u0022b5743cfb75853cf1e83e77fde101dbbdf9f38dd2\u0022, \u0022event_fingerprint\u0022: \u002248a1f0a9849104a5c435e1a4ff8525d2de560619\u0022, \u0022tags_list\u0022: [\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]}","tls_sni":null,"tls_ja3_hash":"2079bcc000c9a54e0784733c0142d140","tls_ja3":"771,49195-49199-49196-49200-52393-52392-49161-49171-49162-49172-49170-4865-4866-4867,11-65281-23-18-5-10-13-50-43-51,29-23-24-25,0","http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]","anomalies":"[]","severity":2,"bytes_in":263},{"id":7576376,"ip":"164.52.198.63","ts":"2026-05-23 05:54:50.000000","proto":"tcp","src_port":57794,"dst_port":2087,"service":"tls","classification":"tls_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022tls_ja3_hash\u0022: \u00222079bcc000c9a54e0784733c0142d140\u0022, \u0022tls_sni\u0022: null, \u0022bytes_in\u0022: 263, \u0022payload_entropy\u0022: 5.753401000696935, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022282, Sector 19\u0022, \u0022service\u0022: \u0022tls\u0022, \u0022app_proto\u0022: \u0022tls\u0022, \u0022asn\u0022: 132420, \u0022country\u0022: \u0022IN\u0022, \u0022tag_count\u0022: 2, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 33, \u0022campaign_key\u0022: \u0022b5743cfb75853cf1e83e77fde101dbbdf9f38dd2\u0022, \u0022event_fingerprint\u0022: \u002248a1f0a9849104a5c435e1a4ff8525d2de560619\u0022, \u0022tags_list\u0022: [\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]}","tls_sni":null,"tls_ja3_hash":"2079bcc000c9a54e0784733c0142d140","tls_ja3":"771,49195-49199-49196-49200-52393-52392-49161-49171-49162-49172-49170-4865-4866-4867,11-65281-23-18-5-10-13-50-43-51,29-23-24-25,0","http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]","anomalies":"[]","severity":2,"bytes_in":263}],"total_events":7}