{"ip":"193.26.115.53","exported_at":"2026-06-17T05:55:50+00:00","period_days":30,"metrics":{"events7d":0,"distinct_ports":0,"distinct_classifications":0,"max_severity":null,"last_sensor_id":"paris-1","max_waf_score":null,"max_risk_score":100,"attack_stage":null,"attack_chain_stage":null,"threat_family":[],"recommended_action":null,"confidence":null,"risk_breakdown":[],"mitre_tactics":[],"mitre_technique":null,"top_mitre_technique":null,"top_mitre_count":null,"executive_one_liner_fr":"risque 100\/100","campaign_hint_fr":null,"confidence_breakdown":[],"persona_hostname":null,"correlation_flags":[],"correlation_flags_labels_fr":[],"confidence_pct":null,"confidence_hint_fr":null,"sensor_role_label_fr":null,"tags_summary_labels_fr":[],"tags_summary":[],"attack_vector":null,"protocol_details":[],"protocol_summary_fr":null,"evidence_snippet":null,"target_port_label":null,"emulator_service":null,"confidence_reason":null,"classification_reason":null,"classification_reason_label_fr":null,"confidence_factors_fr":null,"payload_preview":null},"events":[{"id":7475779,"ip":"193.26.115.53","ts":"2026-05-21 21:19:17.000000","proto":"tcp","src_port":54976,"dst_port":3000,"service":"http","classification":"web_attack","waf_score":48,"waf_tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022]","http_method":"POST","http_target":"\/api\/route","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 7, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 2, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u002246f5955a67387b75de712e640b0687c888a438e5\u0022, \u0022http_target_hash\u0022: \u00221a9b2c3dbe8a713bfc0c240bb1a6ea2141b55601\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 957, \u0022payload_entropy\u0022: 5.474723686374105, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 11, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022467de5788c88bb68076b2f0fbfe0feb7c4e5dd6f\u0022, \u0022event_fingerprint\u0022: \u0022c49c13ab95b8dcb466553405b9993e7e27e55cdb\u0022, \u0022tags_list\u0022: [\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022, \u0022http_probe_api\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:3000","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022, \u0022http_probe_api\u0022]","anomalies":"[]","severity":10,"bytes_in":957},{"id":7471817,"ip":"193.26.115.53","ts":"2026-05-21 19:44:50.000000","proto":"tcp","src_port":45024,"dst_port":3000,"service":"http","classification":"web_attack","waf_score":42,"waf_tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022]","http_method":"POST","http_target":"\/api","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 7, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u002246f5955a67387b75de712e640b0687c888a438e5\u0022, \u0022http_target_hash\u0022: \u0022ada91241341ae792ecf0a59cad28616a77bab856\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 951, \u0022payload_entropy\u0022: 5.477458672522051, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 10, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022e49195bce497c65c06941e6ef27785bb42dafe40\u0022, \u0022event_fingerprint\u0022: \u00228f28b75b15a449a81db05f356f3f02b57bdaf25d\u0022, \u0022tags_list\u0022: [\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022, \u0022http_probe_api\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:3000","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022, \u0022http_probe_api\u0022]","anomalies":"[]","severity":10,"bytes_in":951},{"id":7470439,"ip":"193.26.115.53","ts":"2026-05-21 19:26:46.000000","proto":"tcp","src_port":35734,"dst_port":3000,"service":"http","classification":"web_attack","waf_score":44,"waf_tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022]","http_method":"POST","http_target":"\/_next\/server","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 7, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 2, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u002246f5955a67387b75de712e640b0687c888a438e5\u0022, \u0022http_target_hash\u0022: \u0022bef481449499f499a0b29ed75c9630076205b04f\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 960, \u0022payload_entropy\u0022: 5.476719753805595, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 9, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022b2cc074b4e27a1918ace1473f7a43da1f30cb064\u0022, \u0022event_fingerprint\u0022: \u00229db61e8e4d6fa7ec30de8a565cc70439b5f61dca\u0022, \u0022tags_list\u0022: [\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:3000","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022]","anomalies":"[]","severity":10,"bytes_in":960},{"id":7468482,"ip":"193.26.115.53","ts":"2026-05-21 19:02:23.000000","proto":"tcp","src_port":37166,"dst_port":3000,"service":"http","classification":"web_attack","waf_score":42,"waf_tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022]","http_method":"POST","http_target":"\/api","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 7, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u002246f5955a67387b75de712e640b0687c888a438e5\u0022, \u0022http_target_hash\u0022: \u0022ada91241341ae792ecf0a59cad28616a77bab856\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 951, \u0022payload_entropy\u0022: 5.477458672522051, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 10, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022e49195bce497c65c06941e6ef27785bb42dafe40\u0022, \u0022event_fingerprint\u0022: \u00228f28b75b15a449a81db05f356f3f02b57bdaf25d\u0022, \u0022tags_list\u0022: [\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022, \u0022http_probe_api\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:3000","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022, \u0022http_probe_api\u0022]","anomalies":"[]","severity":10,"bytes_in":951},{"id":7416905,"ip":"193.26.115.53","ts":"2026-05-20 20:31:56.000000","proto":"tcp","src_port":44550,"dst_port":3000,"service":"http","classification":"web_attack","waf_score":48,"waf_tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022]","http_method":"POST","http_target":"\/api\/route","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 7, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 2, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022eba3844e9fd20716239bb97530c41d30bf39a871\u0022, \u0022http_host_hash\u0022: \u002246f5955a67387b75de712e640b0687c888a438e5\u0022, \u0022http_target_hash\u0022: \u00221a9b2c3dbe8a713bfc0c240bb1a6ea2141b55601\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 957, \u0022payload_entropy\u0022: 5.474723686374105, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 11, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u0022467de5788c88bb68076b2f0fbfe0feb7c4e5dd6f\u0022, \u0022event_fingerprint\u0022: \u0022c49c13ab95b8dcb466553405b9993e7e27e55cdb\u0022, \u0022tags_list\u0022: [\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022, \u0022http_probe_api\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:3000","http_user_agent":"Mozilla\/5.0 (rondo2012@atomicmail.io)","http_referer":null,"tags":"[\u0022950019:sqli-4\u0022, \u0022950326:rce-0\u0022, \u0022950327:rce-0\u0022, \u0022950468:nosqli-3\u0022, \u0022950471:nosqli-3\u0022, \u0022950493:proto-0\u0022, \u0022950549:upload-0\u0022, \u0022950600:k8s-api\u0022, \u0022http_contenttype_attack_surface\u0022, \u0022http_jwt_body\u0022, \u0022http_probe_api\u0022]","anomalies":"[]","severity":10,"bytes_in":957},{"id":7279404,"ip":"193.26.115.53","ts":"2026-05-19 01:41:43.000000","proto":"tcp","src_port":47032,"dst_port":8021,"service":null,"classification":"botnet_attack","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 178, \u0022payload_entropy\u0022: 4.9408842760739855, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u00221337 Services GmbH\u0022, \u0022service\u0022: null, \u0022app_proto\u0022: null, \u0022asn\u0022: 210558, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 1, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 91, \u0022campaign_key\u0022: \u0022f1be25d341c23808e8f03c99b9e78723a14973b0\u0022, \u0022event_fingerprint\u0022: \u00227cdd4152ce13704ee08f8f053cb26caf6a3a7a23\u0022, \u0022tags_list\u0022: [\u0022botnet_c2\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022botnet_c2\u0022]","anomalies":"[]","severity":7,"bytes_in":178}],"total_events":6}