{"ip":"91.224.92.87","exported_at":"2026-06-20T01:02:38+00:00","period_days":30,"metrics":{"events7d":0,"distinct_ports":0,"distinct_classifications":0,"max_severity":null,"last_sensor_id":"paris-1","max_waf_score":null,"max_risk_score":100,"attack_stage":null,"attack_chain_stage":null,"threat_family":[],"recommended_action":null,"confidence":null,"risk_breakdown":[],"mitre_tactics":[],"mitre_technique":null,"top_mitre_technique":null,"top_mitre_count":null,"executive_one_liner_fr":"risque 45\/100","campaign_hint_fr":null,"confidence_breakdown":[],"persona_hostname":null,"correlation_flags":[],"correlation_flags_labels_fr":[],"confidence_pct":null,"confidence_hint_fr":null,"sensor_role_label_fr":null,"tags_summary_labels_fr":[],"tags_summary":[],"attack_vector":null,"protocol_details":[],"protocol_summary_fr":null,"evidence_snippet":null,"target_port_label":null,"emulator_service":null,"confidence_reason":null,"classification_reason":null,"classification_reason_label_fr":null,"confidence_factors_fr":null,"payload_preview":null},"events":[{"id":7875044,"ip":"91.224.92.87","ts":"2026-05-28 09:44:14.000000","proto":"tcp","src_port":56963,"dst_port":8111,"service":"tls","classification":"tls_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022tls_ja3_hash\u0022: \u0022b22b3950835f7eba2f3be0917e4f949e\u0022, \u0022tls_sni\u0022: \u002262.3.50.33\u0022, \u0022bytes_in\u0022: 326, \u0022payload_entropy\u0022: 5.136699144873847, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UAB Host Baltic\u0022, \u0022service\u0022: \u0022tls\u0022, \u0022app_proto\u0022: \u0022tls\u0022, \u0022asn\u0022: 209605, \u0022country\u0022: \u0022GB\u0022, \u0022tag_count\u0022: 2, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 45, \u0022campaign_key\u0022: \u00224e3a777a925eaaad0e8efa5a1f4d54c0e91ffdcb\u0022, \u0022event_fingerprint\u0022: \u0022e550adf39927f73564e750c088043fc4d9fe578e\u0022, \u0022tags_list\u0022: [\u0022tls_ja3\u0022, \u0022tls_sni_ip\u0022]}","tls_sni":"62.3.50.33","tls_ja3_hash":"b22b3950835f7eba2f3be0917e4f949e","tls_ja3":"771,49200-49196-49192-49188-49172-49162-165-163-161-159-107-106-105-104-57-56-55-54-49202-49198-49194-49190-49167-49157-157-61-53-136-135-134-133-132-49199-49195-49191-49187-49171-49161-164-162-160-158-103-64-63-62-51-50-49-48-49201-49197-49193-49189-49166-49156-156-60-47-154-153-152-151-69-68-67-66-150-65-7-49169-49159-49164-49154-5-4-49170-49160-22-19-16-13-49165-49155-10-255,0-11-10-35-13-15,23-25-28-27-24-26-22-14-13-11-12-9-10,0-1-2","http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_ja3\u0022, \u0022tls_sni_ip\u0022]","anomalies":"[]","severity":3,"bytes_in":326},{"id":7875045,"ip":"91.224.92.87","ts":"2026-05-28 09:44:14.000000","proto":"tcp","src_port":57048,"dst_port":8111,"service":"tls","classification":"tls_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022tls_ja3_hash\u0022: \u0022b22b3950835f7eba2f3be0917e4f949e\u0022, \u0022tls_sni\u0022: \u002262.3.50.33\u0022, \u0022bytes_in\u0022: 326, \u0022payload_entropy\u0022: 5.130404649336282, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UAB Host Baltic\u0022, \u0022service\u0022: \u0022tls\u0022, \u0022app_proto\u0022: \u0022tls\u0022, \u0022asn\u0022: 209605, \u0022country\u0022: \u0022GB\u0022, \u0022tag_count\u0022: 2, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 45, \u0022campaign_key\u0022: \u00224e3a777a925eaaad0e8efa5a1f4d54c0e91ffdcb\u0022, \u0022event_fingerprint\u0022: \u0022e550adf39927f73564e750c088043fc4d9fe578e\u0022, \u0022tags_list\u0022: [\u0022tls_ja3\u0022, \u0022tls_sni_ip\u0022]}","tls_sni":"62.3.50.33","tls_ja3_hash":"b22b3950835f7eba2f3be0917e4f949e","tls_ja3":"771,49200-49196-49192-49188-49172-49162-165-163-161-159-107-106-105-104-57-56-55-54-49202-49198-49194-49190-49167-49157-157-61-53-136-135-134-133-132-49199-49195-49191-49187-49171-49161-164-162-160-158-103-64-63-62-51-50-49-48-49201-49197-49193-49189-49166-49156-156-60-47-154-153-152-151-69-68-67-66-150-65-7-49169-49159-49164-49154-5-4-49170-49160-22-19-16-13-49165-49155-10-255,0-11-10-35-13-15,23-25-28-27-24-26-22-14-13-11-12-9-10,0-1-2","http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_ja3\u0022, \u0022tls_sni_ip\u0022]","anomalies":"[]","severity":3,"bytes_in":326},{"id":7875039,"ip":"91.224.92.87","ts":"2026-05-28 09:44:13.000000","proto":"tcp","src_port":56388,"dst_port":8111,"service":null,"classification":"port_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022bytes_in\u0022: 0, \u0022payload_entropy\u0022: 0.0, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UAB Host Baltic\u0022, \u0022service\u0022: null, \u0022app_proto\u0022: null, \u0022asn\u0022: 209605, \u0022country\u0022: \u0022GB\u0022, \u0022tag_count\u0022: 0, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 0, \u0022campaign_key\u0022: \u0022f36527e76f95b067b194a0717f723bea1802a02a\u0022, \u0022event_fingerprint\u0022: \u002280808f7dece7ae894bcc3148c5f4266da3414b1f\u0022}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[]","anomalies":"[]","severity":0,"bytes_in":0},{"id":7875040,"ip":"91.224.92.87","ts":"2026-05-28 09:44:13.000000","proto":"tcp","src_port":56445,"dst_port":8111,"service":"http","classification":"web_attack","waf_score":16,"waf_tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","http_method":"GET","http_target":"\/","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 5, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022ff892f0781e777be7f9959b2f50f62f85fca33de\u0022, \u0022http_host_hash\u0022: \u002205aaaea8c60196500007fa123476d8c38f46b8ed\u0022, \u0022http_target_hash\u0022: \u002242099b4af021e53fd8fd4e056c2568d7c2e3ffa8\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 276, \u0022payload_entropy\u0022: 5.412132752051373, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UAB Host Baltic\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 209605, \u0022country\u0022: \u0022GB\u0022, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u002299411f375cad8e71405c8bc1da85a5e1ba56fabb\u0022, \u0022event_fingerprint\u0022: \u002264c944bcf51bc8c1b9d4f69e55528dc0c4fcec2b\u0022, \u0022tags_list\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:8111","http_user_agent":"Mozilla\/5.0 (Windows NT 5.1; rv:9.0.1) Gecko\/20100101 Firefox\/9.0.1","http_referer":null,"tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","anomalies":"[]","severity":8,"bytes_in":276},{"id":7875041,"ip":"91.224.92.87","ts":"2026-05-28 09:44:13.000000","proto":"tcp","src_port":56677,"dst_port":8111,"service":"http","classification":"web_attack","waf_score":16,"waf_tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","http_method":"GET","http_target":"\/","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 5, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022ff892f0781e777be7f9959b2f50f62f85fca33de\u0022, \u0022http_host_hash\u0022: \u002205aaaea8c60196500007fa123476d8c38f46b8ed\u0022, \u0022http_target_hash\u0022: \u002242099b4af021e53fd8fd4e056c2568d7c2e3ffa8\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 276, \u0022payload_entropy\u0022: 5.412132752051373, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UAB Host Baltic\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 209605, \u0022country\u0022: \u0022GB\u0022, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u002299411f375cad8e71405c8bc1da85a5e1ba56fabb\u0022, \u0022event_fingerprint\u0022: \u002264c944bcf51bc8c1b9d4f69e55528dc0c4fcec2b\u0022, \u0022tags_list\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:8111","http_user_agent":"Mozilla\/5.0 (Windows NT 5.1; rv:9.0.1) Gecko\/20100101 Firefox\/9.0.1","http_referer":null,"tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","anomalies":"[]","severity":8,"bytes_in":276},{"id":7875042,"ip":"91.224.92.87","ts":"2026-05-28 09:44:13.000000","proto":"tcp","src_port":56780,"dst_port":8111,"service":"http","classification":"web_attack","waf_score":16,"waf_tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","http_method":"GET","http_target":"\/","sensor_id":"paris-1","meta":"{\u0022http_header_count\u0022: 5, \u0022http_query_params\u0022: 0, \u0022http_path_depth\u0022: 0, \u0022http_path_ext\u0022: null, \u0022http_ua_hash\u0022: \u0022ff892f0781e777be7f9959b2f50f62f85fca33de\u0022, \u0022http_host_hash\u0022: \u002205aaaea8c60196500007fa123476d8c38f46b8ed\u0022, \u0022http_target_hash\u0022: \u002242099b4af021e53fd8fd4e056c2568d7c2e3ffa8\u0022, \u0022http_referer_hash\u0022: null, \u0022http_method\u0022: \u0022GET\u0022, \u0022http_ua_is_cli\u0022: false, \u0022http_ua_is_browser\u0022: true, \u0022bytes_in\u0022: 276, \u0022payload_entropy\u0022: 5.412132752051373, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UAB Host Baltic\u0022, \u0022service\u0022: \u0022http\u0022, \u0022app_proto\u0022: \u0022http\u0022, \u0022asn\u0022: 209605, \u0022country\u0022: \u0022GB\u0022, \u0022tag_count\u0022: 3, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 100, \u0022campaign_key\u0022: \u002299411f375cad8e71405c8bc1da85a5e1ba56fabb\u0022, \u0022event_fingerprint\u0022: \u002264c944bcf51bc8c1b9d4f69e55528dc0c4fcec2b\u0022, \u0022tags_list\u0022: [\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]}","tls_sni":null,"tls_ja3_hash":null,"tls_ja3":null,"http_version":"HTTP\/1.1","http_host":"62.3.50.33:8111","http_user_agent":"Mozilla\/5.0 (Windows NT 5.1; rv:9.0.1) Gecko\/20100101 Firefox\/9.0.1","http_referer":null,"tags":"[\u0022950326:rce-0\u0022, \u0022950470:nosqli-3\u0022, \u0022950734:sap-sapcontrol-path\u0022]","anomalies":"[]","severity":8,"bytes_in":276},{"id":7875043,"ip":"91.224.92.87","ts":"2026-05-28 09:44:13.000000","proto":"tcp","src_port":56868,"dst_port":8111,"service":"tls","classification":"tls_probe","waf_score":null,"waf_tags":null,"http_method":null,"http_target":null,"sensor_id":"paris-1","meta":"{\u0022tls_ja3_hash\u0022: \u0022b22b3950835f7eba2f3be0917e4f949e\u0022, \u0022tls_sni\u0022: \u002262.3.50.33\u0022, \u0022bytes_in\u0022: 326, \u0022payload_entropy\u0022: 5.171840332601813, \u0022port_category\u0022: \u0022registered\u0022, \u0022org\u0022: \u0022UAB Host Baltic\u0022, \u0022service\u0022: \u0022tls\u0022, \u0022app_proto\u0022: \u0022tls\u0022, \u0022asn\u0022: 209605, \u0022country\u0022: \u0022GB\u0022, \u0022tag_count\u0022: 2, \u0022anomaly_count\u0022: 0, \u0022risk_score\u0022: 45, \u0022campaign_key\u0022: \u00224e3a777a925eaaad0e8efa5a1f4d54c0e91ffdcb\u0022, \u0022event_fingerprint\u0022: \u0022e550adf39927f73564e750c088043fc4d9fe578e\u0022, \u0022tags_list\u0022: [\u0022tls_ja3\u0022, \u0022tls_sni_ip\u0022]}","tls_sni":"62.3.50.33","tls_ja3_hash":"b22b3950835f7eba2f3be0917e4f949e","tls_ja3":"771,49200-49196-49192-49188-49172-49162-165-163-161-159-107-106-105-104-57-56-55-54-49202-49198-49194-49190-49167-49157-157-61-53-136-135-134-133-132-49199-49195-49191-49187-49171-49161-164-162-160-158-103-64-63-62-51-50-49-48-49201-49197-49193-49189-49166-49156-156-60-47-154-153-152-151-69-68-67-66-150-65-7-49169-49159-49164-49154-5-4-49170-49160-22-19-16-13-49165-49155-10-255,0-11-10-35-13-15,23-25-28-27-24-26-22-14-13-11-12-9-10,0-1-2","http_version":null,"http_host":null,"http_user_agent":null,"http_referer":null,"tags":"[\u0022tls_ja3\u0022, \u0022tls_sni_ip\u0022]","anomalies":"[]","severity":3,"bytes_in":326}],"total_events":7}