{"ip":"50.62.22.47","exported_at":"2026-06-15T21:23:48+00:00","period_days":30,"metrics":{"events7d":0,"distinct_ports":0,"distinct_classifications":0,"max_severity":null,"last_sensor_id":"paris-1","max_waf_score":null,"max_risk_score":76,"attack_stage":"probe","attack_chain_stage":null,"threat_family":["scanner"],"recommended_action":"monitor","confidence":1,"risk_breakdown":{"waf":8,"classification":50,"behavior":0,"geo":0,"protocol":36,"novelty":25},"mitre_tactics":["TA0007","TA0001"],"mitre_technique":null,"top_mitre_technique":null,"top_mitre_count":null,"executive_one_liner_fr":"risque 27\/100","campaign_hint_fr":null,"confidence_breakdown":[],"persona_hostname":null,"correlation_flags":[],"correlation_flags_labels_fr":[],"confidence_pct":100,"confidence_hint_fr":null,"sensor_role_label_fr":null,"tags_summary_labels_fr":[],"tags_summary":[],"attack_vector":null,"protocol_details":[],"protocol_summary_fr":null,"evidence_snippet":"SSH-2.0-libssh_0.9.6\r\n\u0000\u0000\u0003\ufffd\u0006\u0014\ufffdf\ufffd)K`=s\u0012\u0015.\ufffd\ufffd\ufffdW\ufffd\u0000\u0000\u0001(curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nist","target_port_label":"22","emulator_service":null,"confidence_reason":null,"classification_reason":"Type \u00ab ssh_probe \u00bb (signaux protocolaires) \u00b7 confiance 100%","classification_reason_label_fr":"Type \u00ab ssh_probe \u00bb (signaux protocolaires) \u00b7 confiance 100%","confidence_factors_fr":null,"payload_preview":"SSH-2.0-libssh_0.9.6\r\n\u0000\u0000\u0003\ufffd\u0006\u0014\ufffdf\ufffd)K`=s\u0012\u0015.\ufffd\ufffd\ufffdW\ufffd\u0000\u0000\u0001(curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nist"},"events":[{"id":8292691,"ip":"50.62.22.47","ts":"2026-06-05 01:24:34.000000","proto":"tcp","src_port":51308,"dst_port":22,"service":"ssh","classification":"ssh_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022protocol_emulated\u0022: true, \u0022emulator_response\u0022: \u00225353482d322e302d4f70656e5353485f382e397031205562756e74752d347562756e7475302e360d0a\u0022, \u0022emulator_response_len\u0022: 41, \u0022bytes_in\u0022: 998, \u0022payload_entropy\u0022: 4.790595658363384, \u0022port_category\u0022: \u0022well_known\u0022, \u0022org\u0022: \u0022GoDaddy.com, LLC\u0022, \u0022service\u0022: \u0022ssh\u0022, \u0022app_proto\u0022: \u0022ssh\u0022, \u0022asn\u0022: 26496, \u0022country\u0022: \u0022US\u0022, \u0022dst_port\u0022: 22, \u0022risk_waf\u0022: 8.0, \u0022risk_classification\u0022: 50.0, \u0022risk_behavior\u0022: 0.0, \u0022risk_geo\u0022: 0.0, \u0022risk_protocol\u0022: 36.0, \u0022risk_novelty\u0022: 25.0, \u0022risk_boost\u0022: 0, \u0022risk_granularity\u0022: 5.3, \u0022risk_breakdown\u0022: {\u0022waf\u0022: 8.0, \u0022classification\u0022: 50.0, \u0022behavior\u0022: 0.0, \u0022geo\u0022: 0.0, \u0022protocol\u0022: 36.0, \u0022novelty\u0022: 25.0}, \u0022risk_score\u0022: 27, \u0022tag_count\u0022: 5, \u0022anomaly_count\u0022: 0, \u0022campaign_key\u0022: \u00229a91c35ff8553fc24795f9eaf93692ffdae1839c\u0022, \u0022event_fingerprint\u0022: \u0022bc4e3fa786c83e0db7c1c892cb0c288f6b14388f\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab ssh_probe \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022, \u0022confidence\u0022: 1.0, \u0022classification_confidence\u0022: 1.0, \u0022precision_score\u0022: 141, \u0022precision_signals\u0022: [\u0022pat-0391\u0022, \u0022pat-0392\u0022, \u0022INT-upstream\u0022], \u0022kb_rule_ids\u0022: [\u0022pat-0391\u0022, \u0022pat-0392\u0022, \u0022INT-upstream\u0022], \u0022matched_patterns\u0022: [\u0022pat-0391\u0022, \u0022pat-0392\u0022, \u0022pat-0536\u0022], \u0022matched_pattern_names\u0022: [\u0022SSH-2.0 banner RFC4253\u0022, \u0022libssh banner\u0022, \u0022TFTP RRQ\u0022], \u0022pattern_ids\u0022: [\u0022pat-0391\u0022, \u0022pat-0392\u0022, \u0022pat-0536\u0022], \u0022risk_confidence_factor\u0022: 100.0, \u0022city\u0022: null, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false, \u0022geo\u0022: {\u0022country\u0022: \u0022US\u0022, \u0022asn\u0022: 26496, \u0022org\u0022: \u0022GoDaddy.com, LLC\u0022, \u0022is_datacenter\u0022: false, \u0022is_tor_hint\u0022: false}, \u0022fingerprint\u0022: {\u0022payload_hash\u0022: \u0022c2f59483be451109848fdceb1b14c40c\u0022, \u0022path_pattern_hash\u0022: \u00224368b1c212b6962fb95d1d1144451aca\u0022}, \u0022target_context\u0022: {\u0022dst_port\u0022: 22, \u0022service\u0022: \u0022ssh\u0022}, \u0022payload_preview\u0022: \u0022SSH-2.0-libssh_0.9.6\\r\\n\\u0000\\u0000\\u0003\ufffd\\u0006\\u0014\ufffdf\ufffd)K`=s\\u0012\\u0015.\ufffd\ufffd\ufffdW\ufffd\\u0000\\u0000\\u0001(curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nist\u0022, \u0022request_sample\u0022: \u0022SSH-2.0-libssh_0.9.6\\r\\n\\u0000\\u0000\\u0003\ufffd\\u0006\\u0014\ufffdf\ufffd)K`=s\\u0012\\u0015.\ufffd\ufffd\ufffdW\ufffd\\u0000\\u0000\\u0001(curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group18-sha512,diffie-hellman-group16-sha512,diffie-hellman-group-exchange-sha256,diffie-\u0022, \u0022payload_snippet\u0022: \u0022SSH-2.0-libssh_0.9.6\\r\\n\\u0000\\u0000\\u0003\ufffd\\u0006\\u0014\ufffdf\ufffd)K`=s\\u0012\\u0015.\ufffd\ufffd\ufffdW\ufffd\\u0000\\u0000\\u0001(curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nist\u0022, \u0022evidence\u0022: {\u0022request_sample\u0022: \u0022SSH-2.0-libssh_0.9.6\\r\\n\\u0000\\u0000\\u0003\ufffd\\u0006\\u0014\ufffdf\ufffd)K`=s\\u0012\\u0015.\ufffd\ufffd\ufffdW\ufffd\\u0000\\u0000\\u0001(curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group18-sha512,diffie-hellman-group16-sha512,diffie-hellman-group-exchange-sha256,diffie-\u0022, \u0022payload_snippet\u0022: \u0022SSH-2.0-libssh_0.9.6\\r\\n\\u0000\\u0000\\u0003\ufffd\\u0006\\u0014\ufffdf\ufffd)K`=s\\u0012\\u0015.\ufffd\ufffd\ufffdW\ufffd\\u0000\\u0000\\u0001(curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nist\u0022, \u0022classification_reason\u0022: \u0022Type \u00ab ssh_probe \u00bb (signaux protocolaires) \u00b7 confiance 100%\u0022}, \u0022attack_stage\u0022: \u0022probe\u0022, \u0022mitre_tactics\u0022: [\u0022TA0007\u0022, \u0022TA0001\u0022], \u0022threat_family\u0022: [\u0022scanner\u0022], \u0022recommended_client_action\u0022: \u0022monitor\u0022, \u0022policy_mode\u0022: \u0022intelligence\u0022, \u0022sensor_role\u0022: \u0022threat_intelligence\u0022, \u0022event_signature\u0022: \u0022fdcc83615e4b46f76500d634024955ae4d78b37c\u0022, \u0022ban_policy\u0022: \u0022advisory_monitor\u0022, \u0022tags_list\u0022: [\u0022net_ssh_probe\u0022, \u0022ssh_banner\u0022, \u0022ssh_emulated\u0022, \u0022ssh_kex_probe\u0022, \u0022ssh_libssh\u0022], \u0022behavior_alert_count\u0022: 1, \u0022behavior_priority\u0022: 72}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022net_ssh_probe\u0022, \u0022ssh_banner\u0022, \u0022ssh_emulated\u0022, \u0022ssh_kex_probe\u0022, \u0022ssh_libssh\u0022]","anomalies":"[]","severity":6,"bytes_in":998},{"id":7525257,"ip":"50.62.22.47","ts":"2026-05-22 15:49:50.000000","proto":"tcp","src_port":40976,"dst_port":22,"service":"ssh","classification":"ssh_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 22, \u0022payload_entropy\u0022: 3.879664004902593, \u0022port_category\u0022: \u0022well_known\u0022, \u0022org\u0022: \u0022GoDaddy.com, LLC\u0022, \u0022service\u0022: \u0022ssh\u0022, \u0022app_proto\u0022: \u0022ssh\u0022, \u0022asn\u0022: 26496, \u0022country\u0022: \u0022US\u0022, \u0022tag_count\u0022: 2, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 76, \u0022campaign_key\u0022: \u00224b687cfbd2a2f5b43a89ec258bffd822ae9203ba\u0022, \u0022event_fingerprint\u0022: \u0022bc4e3fa786c83e0db7c1c892cb0c288f6b14388f\u0022, \u0022tags_list\u0022: [\u0022ssh_banner\u0022, \u0022ssh_libssh\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022ssh_banner\u0022, \u0022ssh_libssh\u0022]","anomalies":"[]","severity":6,"bytes_in":22}],"total_events":2}