{"ip":"165.154.173.60","exported_at":"2026-06-18T15:51:28+00:00","period_days":30,"metrics":{"events7d":0,"distinct_ports":0,"distinct_classifications":0,"max_severity":null,"last_sensor_id":"paris-1","max_waf_score":null,"max_risk_score":100,"attack_stage":null,"attack_chain_stage":null,"threat_family":[],"recommended_action":null,"confidence":null,"risk_breakdown":[],"mitre_tactics":[],"mitre_technique":null,"top_mitre_technique":null,"top_mitre_count":null,"executive_one_liner_fr":null,"campaign_hint_fr":null,"confidence_breakdown":[],"persona_hostname":null,"correlation_flags":[],"correlation_flags_labels_fr":[],"confidence_pct":null,"confidence_hint_fr":null,"sensor_role_label_fr":null,"tags_summary_labels_fr":[],"tags_summary":[],"attack_vector":null,"protocol_details":[],"protocol_summary_fr":null,"evidence_snippet":null,"target_port_label":null,"emulator_service":null,"confidence_reason":null,"classification_reason":null,"classification_reason_label_fr":null,"confidence_factors_fr":null,"payload_preview":null},"events":[{"id":7812598,"ip":"165.154.173.60","ts":"2026-05-27 17:39:07.000000","proto":"tcp","src_port":33356,"dst_port":123,"service":"tls","classification":"tls_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022tls_ja3_hash\u0022: \u0022871a754af286dfb70c1b53c6887c62e0\u0022, \u0022tls_sni\u0022: \u002262.3.50.33\u0022, \u0022bytes_in\u0022: 213, \u0022payload_entropy\u0022: 5.081447264217886, \u0022port_category\u0022: \u0022well_known\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY HK LIMITED\u0022, \u0022service\u0022: \u0022tls\u0022, \u0022app_proto\u0022: \u0022tls\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 2, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 45, \u0022campaign_key\u0022: \u00222eedb74047d7e9b0173b5e7cc99b041348010ecf\u0022, \u0022event_fingerprint\u0022: \u0022bc0e3cdc04e10d9d10087c4ec8f27d0b347af335\u0022, \u0022tags_list\u0022: [\u0022tls_ja3\u0022, \u0022tls_sni_ip\u0022]}","tls_sni":"62.3.50.33","tls_ja3_hash":"871a754af286dfb70c1b53c6887c62e0","tls_ja3":"771,49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47-255,0-11-10-35-22-23-13,29-23-30-25-24,0-1-2","http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_ja3\u0022, \u0022tls_sni_ip\u0022]","anomalies":"[]","severity":3,"bytes_in":213},{"id":7812599,"ip":"165.154.173.60","ts":"2026-05-27 17:39:07.000000","proto":"tcp","src_port":33352,"dst_port":123,"service":null,"classification":"port_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 0, \u0022payload_entropy\u0022: 0.0, \u0022port_category\u0022: \u0022well_known\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY HK LIMITED\u0022, \u0022service\u0022: null, \u0022app_proto\u0022: null, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 0, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 0, \u0022campaign_key\u0022: \u0022d9157f98e1eef2a8b02e4b7db9a9a882fa092b1a\u0022, \u0022event_fingerprint\u0022: \u002239e52b8cd8eb5a0c2c4617532ec32902c77f6bcc\u0022}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[]","anomalies":"[]","severity":0,"bytes_in":0},{"id":7812596,"ip":"165.154.173.60","ts":"2026-05-27 17:39:06.000000","proto":"tcp","src_port":33334,"dst_port":123,"service":"tls","classification":"tls_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022tls_ja3_hash\u0022: \u00229b72665518dedb3531426284fdec8237\u0022, \u0022tls_sni\u0022: null, \u0022bytes_in\u0022: 1481, \u0022payload_entropy\u0022: 7.7368524810373485, \u0022port_category\u0022: \u0022well_known\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY HK LIMITED\u0022, \u0022service\u0022: \u0022tls\u0022, \u0022app_proto\u0022: \u0022tls\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 2, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 33, \u0022campaign_key\u0022: \u0022f65cc4b9d418a180289601c4defd40904614b6ff\u0022, \u0022event_fingerprint\u0022: \u00228a02422e8ea10b454f7b8e8996c499a352eb3959\u0022, \u0022tags_list\u0022: [\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]}","tls_sni":null,"tls_ja3_hash":"9b72665518dedb3531426284fdec8237","tls_ja3":"771,49195-49199-49196-49200-52393-52392-49161-49171-49162-49172-156-157-47-53-49170-10-49187-49191-60-49159-49169-5-4865-4866-4867,11-65281-23-18-5-10-13-43-51,4588-29-23-24-25,0","http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]","anomalies":"[]","severity":2,"bytes_in":1481},{"id":7812597,"ip":"165.154.173.60","ts":"2026-05-27 17:39:06.000000","proto":"tcp","src_port":33342,"dst_port":123,"service":"tls","classification":"tls_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022tls_ja3_hash\u0022: \u0022d986cabed948528e83118d62e6f671d3\u0022, \u0022tls_sni\u0022: \u002262.3.50.33\u0022, \u0022bytes_in\u0022: 225, \u0022payload_entropy\u0022: 5.0566559028605, \u0022port_category\u0022: \u0022well_known\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY HK LIMITED\u0022, \u0022service\u0022: \u0022tls\u0022, \u0022app_proto\u0022: \u0022tls\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 2, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 45, \u0022campaign_key\u0022: \u00222eedb74047d7e9b0173b5e7cc99b041348010ecf\u0022, \u0022event_fingerprint\u0022: \u002216f88c70998d4bbf79d43b36a715a27d2b313fb1\u0022, \u0022tags_list\u0022: [\u0022tls_ja3\u0022, \u0022tls_sni_ip\u0022]}","tls_sni":"62.3.50.33","tls_ja3_hash":"d986cabed948528e83118d62e6f671d3","tls_ja3":"771,49170-50-103-158-57-49188-107-8-49191-159-49161-49200-49162-49159-20-49199-18-56-49172-52392-21-49187-25-52393-60-49195-51-49169-3-17-61-52394-6-49171-49192-49160-22-23-163-5-47-49196-19-4-157-106-102-64-156-10-53-162,0-5-10-11-13-65281,23-24-25,0","http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_ja3\u0022, \u0022tls_sni_ip\u0022]","anomalies":"[]","severity":3,"bytes_in":225},{"id":7812591,"ip":"165.154.173.60","ts":"2026-05-27 17:38:45.000000","proto":"tcp","src_port":40690,"dst_port":123,"service":"http","classification":"web_attack","waf_score":16,"waf_tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","http_method":"GET","http_target":"\/","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 5, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022ffb5a44339ab606975e895798095e71569dcec5d\u0022, \u0022http_host_hash\u0022: \u0022b14fe786bb14ed67103dd0a51a445c5b20cf75da\u0022, \u0022http_target_hash\u0022: \u002242099b4af021e53fd8fd4e056c2568d7c2e3ffa8\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 220, \u0022payload_entropy\u0022: 5.406065171591144, \u0022port_category\u0022: \u0022well_known\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY HK LIMITED\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022af58e85e33ddf915a379000f2f0175697d53bf77\u0022, \u0022event_fingerprint\u0022: \u0022b551e4ca23964f3f30e4404f7fe97d7ea5d401c3\u0022, \u0022tags_list\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:123","http_user_agent":"Mozilla\/5.0 (X11; Linux x86_64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/135.0.0.0 Safari\/537.36","http_referer":null,"tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","anomalies":"[]","severity":8,"bytes_in":220},{"id":7812587,"ip":"165.154.173.60","ts":"2026-05-27 17:38:44.000000","proto":"tcp","src_port":40680,"dst_port":123,"service":"http","classification":"web_attack","waf_score":16,"waf_tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","http_method":"GET","http_target":"\/","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 5, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022ffb5a44339ab606975e895798095e71569dcec5d\u0022, \u0022http_host_hash\u0022: \u0022b14fe786bb14ed67103dd0a51a445c5b20cf75da\u0022, \u0022http_target_hash\u0022: \u002242099b4af021e53fd8fd4e056c2568d7c2e3ffa8\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 220, \u0022payload_entropy\u0022: 5.406065171591144, \u0022port_category\u0022: \u0022well_known\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY HK LIMITED\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022af58e85e33ddf915a379000f2f0175697d53bf77\u0022, \u0022event_fingerprint\u0022: \u0022b551e4ca23964f3f30e4404f7fe97d7ea5d401c3\u0022, \u0022tags_list\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:123","http_user_agent":"Mozilla\/5.0 (X11; Linux x86_64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/135.0.0.0 Safari\/537.36","http_referer":null,"tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","anomalies":"[]","severity":8,"bytes_in":220},{"id":7812585,"ip":"165.154.173.60","ts":"2026-05-27 17:38:43.000000","proto":"tcp","src_port":40668,"dst_port":123,"service":"tls","classification":"tls_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022tls_ja3_hash\u0022: \u00229b72665518dedb3531426284fdec8237\u0022, \u0022tls_sni\u0022: null, \u0022bytes_in\u0022: 1481, \u0022payload_entropy\u0022: 7.749354568011422, \u0022port_category\u0022: \u0022well_known\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY HK LIMITED\u0022, \u0022service\u0022: \u0022tls\u0022, \u0022app_proto\u0022: \u0022tls\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 2, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 33, \u0022campaign_key\u0022: \u0022f65cc4b9d418a180289601c4defd40904614b6ff\u0022, \u0022event_fingerprint\u0022: \u00228a02422e8ea10b454f7b8e8996c499a352eb3959\u0022, \u0022tags_list\u0022: [\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]}","tls_sni":null,"tls_ja3_hash":"9b72665518dedb3531426284fdec8237","tls_ja3":"771,49195-49199-49196-49200-52393-52392-49161-49171-49162-49172-156-157-47-53-49170-10-49187-49191-60-49159-49169-5-4865-4866-4867,11-65281-23-18-5-10-13-43-51,4588-29-23-24-25,0","http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]","anomalies":"[]","severity":2,"bytes_in":1481},{"id":7812583,"ip":"165.154.173.60","ts":"2026-05-27 17:38:42.000000","proto":"tcp","src_port":40662,"dst_port":123,"service":"tls","classification":"tls_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022tls_ja3_hash\u0022: \u00229b72665518dedb3531426284fdec8237\u0022, \u0022tls_sni\u0022: null, \u0022bytes_in\u0022: 1481, \u0022payload_entropy\u0022: 7.695964116362167, \u0022port_category\u0022: \u0022well_known\u0022, \u0022org\u0022: \u0022UCLOUD INFORMATION TECHNOLOGY HK LIMITED\u0022, \u0022service\u0022: \u0022tls\u0022, \u0022app_proto\u0022: \u0022tls\u0022, \u0022asn\u0022: 135377, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 2, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 33, \u0022campaign_key\u0022: \u0022f65cc4b9d418a180289601c4defd40904614b6ff\u0022, \u0022event_fingerprint\u0022: \u00228a02422e8ea10b454f7b8e8996c499a352eb3959\u0022, \u0022tags_list\u0022: [\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]}","tls_sni":null,"tls_ja3_hash":"9b72665518dedb3531426284fdec8237","tls_ja3":"771,49195-49199-49196-49200-52393-52392-49161-49171-49162-49172-156-157-47-53-49170-10-49187-49191-60-49159-49169-5-4865-4866-4867,11-65281-23-18-5-10-13-43-51,4588-29-23-24-25,0","http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_ja3\u0022, \u0022tls_no_sni\u0022]","anomalies":"[]","severity":2,"bytes_in":1481}],"total_events":8}