{"ip":"49.47.140.117","exported_at":"2026-06-17T18:29:24+00:00","period_days":30,"metrics":{"events7d":0,"distinct_ports":0,"distinct_classifications":0,"max_severity":null,"last_sensor_id":"paris-1","max_waf_score":null,"max_risk_score":55,"attack_stage":null,"attack_chain_stage":null,"threat_family":[],"recommended_action":null,"confidence":null,"risk_breakdown":[],"mitre_tactics":[],"mitre_technique":null,"top_mitre_technique":null,"top_mitre_count":null,"executive_one_liner_fr":"risque 55\/100","campaign_hint_fr":null,"confidence_breakdown":[],"persona_hostname":null,"correlation_flags":[],"correlation_flags_labels_fr":[],"confidence_pct":null,"confidence_hint_fr":null,"sensor_role_label_fr":null,"tags_summary_labels_fr":[],"tags_summary":[],"attack_vector":null,"protocol_details":[],"protocol_summary_fr":null,"evidence_snippet":null,"target_port_label":null,"emulator_service":null,"confidence_reason":null,"classification_reason":null,"classification_reason_label_fr":null,"confidence_factors_fr":null,"payload_preview":null},"events":[{"id":7889172,"ip":"49.47.140.117","ts":"2026-05-28 16:35:03.000000","proto":"tcp","src_port":65282,"dst_port":5985,"service":"http","classification":"web_probe","waf_score":7,"waf_tags":"[\u0022950326:rce-0\u0022]","http_method":"POST","http_target":"\/wsman","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 7, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u00220fddcce29f70e8e19a3485eb26ecc659557dcbb1\u0022, \u0022http_host_hash\u0022: \u0022ddb03e7308adcf12471acab96763196d66ec0139\u0022, \u0022http_target_hash\u0022: \u0022f7f785f0382ee40d458513e78b6bfa3405678b3d\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: false, \u0022bytes_in\u0022: 218, \u0022payload_entropy\u0022: 5.2114727746049665, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Reliance Jio Infocomm Limited\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 55836, \u0022country\u0022: \u0022IN\u0022, \u0022tag_count\u0022: 1, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 55, \u0022campaign_key\u0022: \u002259e13ec2ad7f1c389bd6a3cf7cf660e59ac178c1\u0022, \u0022event_fingerprint\u0022: \u00225205a0122b3babf4233011e900caf0c0c94556d5\u0022, \u0022tags_list\u0022: [\u0022950326:rce-0\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:5985","http_user_agent":"Python WinRM client","http_referer":null,"tags":"[\u0022950326:rce-0\u0022]","anomalies":"[]","severity":4,"bytes_in":218},{"id":7681675,"ip":"49.47.140.117","ts":"2026-05-24 23:13:01.000000","proto":"tcp","src_port":64799,"dst_port":5985,"service":"http","classification":"web_probe","waf_score":7,"waf_tags":"[\u0022950326:rce-0\u0022]","http_method":"POST","http_target":"\/wsman","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 7, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 1, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u00220fddcce29f70e8e19a3485eb26ecc659557dcbb1\u0022, \u0022http_host_hash\u0022: \u0022ddb03e7308adcf12471acab96763196d66ec0139\u0022, \u0022http_target_hash\u0022: \u0022f7f785f0382ee40d458513e78b6bfa3405678b3d\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022POST\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: false, \u0022bytes_in\u0022: 218, \u0022payload_entropy\u0022: 5.2114727746049665, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022Reliance Jio Infocomm Limited\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 55836, \u0022country\u0022: \u0022IN\u0022, \u0022tag_count\u0022: 1, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 55, \u0022campaign_key\u0022: \u002259e13ec2ad7f1c389bd6a3cf7cf660e59ac178c1\u0022, \u0022event_fingerprint\u0022: \u00225205a0122b3babf4233011e900caf0c0c94556d5\u0022, \u0022tags_list\u0022: [\u0022950326:rce-0\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:5985","http_user_agent":"Python WinRM client","http_referer":null,"tags":"[\u0022950326:rce-0\u0022]","anomalies":"[]","severity":4,"bytes_in":218}],"total_events":2}