{
 "night": "2026-10-03",
 "window": {
  "start": "2026-10-02T18:00:00+02:00",
  "end": "2026-10-03T06:00:00+02:00"
 },
 "target": {
  "label": "Johannesburg, ZA",
  "lat": -26.2041,
  "lon": 28.0473
 },
 "generated_at": "2026-10-07T11:35:12Z",
 "totals": {
  "attacks": 2584,
  "edge_attacks": 2254,
  "edge_new_bans": 46,
  "new_bans": 76,
  "requests": 71871,
  "blocked_at_edge": 584,
  "active_bans": 19,
  "sensors": 4
 },
 "sensors": [
  {
   "id": "edge",
   "kind": "edge",
   "attacks": 2254,
   "new_bans": 46,
   "attacks_24h": 5232,
   "active_bans": 16,
   "categories": {
    "cms-probe": 1738,
    "secret-probe": 458,
    "code-injection": 22,
    "traversal": 17,
    "protocol": 16
   }
  },
  {
   "id": "web-1",
   "kind": "web",
   "attacks": 130,
   "new_bans": 13,
   "attacks_24h": 286,
   "active_bans": 1,
   "categories": {
    "cms-probe": 73,
    "secret-probe": 37,
    "protocol": 9,
    "code-injection": 6,
    "scanner": 5
   }
  },
  {
   "id": "web-2",
   "kind": "web",
   "attacks": 75,
   "new_bans": 7,
   "attacks_24h": 198,
   "active_bans": 0,
   "categories": {
    "cms-probe": 37,
    "secret-probe": 22,
    "protocol": 8,
    "scanner": 5,
    "code-injection": 3
   }
  },
  {
   "id": "web-3",
   "kind": "web",
   "attacks": 125,
   "new_bans": 10,
   "attacks_24h": 346,
   "active_bans": 2,
   "categories": {
    "secret-probe": 95,
    "cms-probe": 18,
    "scanner": 8,
    "code-injection": 2,
    "protocol": 2
   }
  }
 ],
 "categories": {
  "cms-probe": 1866,
  "secret-probe": 612,
  "protocol": 35,
  "code-injection": 33,
  "scanner": 18,
  "traversal": 17
 },
 "findings": [
  {
   "severity": "critical",
   "rule": "Secret or VCS file probe",
   "rule_id": "BW-SEC-01",
   "type": "secret-probe",
   "requests": 409,
   "addresses": 40,
   "sensor": "edge",
   "first": "2026-10-02T18:02:00+02:00",
   "method": "GET",
   "path": "/.env",
   "ip": "96.126.130.210"
  },
  {
   "severity": "critical",
   "rule": "Credential, state or dump file probe",
   "rule_id": "BW-SEC-02",
   "type": "credential-probe",
   "requests": 49,
   "addresses": 6,
   "sensor": "edge",
   "first": "2026-10-02T19:09:00+02:00",
   "method": "GET",
   "path": "/wp-config.php",
   "ip": "45.156.87.186"
  },
  {
   "severity": "critical",
   "rule": "PHP or shell payload",
   "rule_id": "BW-RCE-03",
   "type": "rce-payload",
   "requests": 22,
   "addresses": 7,
   "sensor": "edge",
   "first": "2026-10-02T19:22:00+02:00",
   "method": "POST",
   "path": "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
   "ip": "170.64.182.167"
  },
  {
   "severity": "critical",
   "rule": "Traversal to a system file",
   "rule_id": "BW-TRV-01",
   "type": "path-traversal",
   "requests": 13,
   "addresses": 2,
   "sensor": "edge",
   "first": "2026-10-03T00:01:00+02:00",
   "method": "GET",
   "path": "/[@]fs/proc/self/environ?import&raw??",
   "ip": "34.19.75.177"
  },
  {
   "severity": "high",
   "rule": "Deep directory traversal",
   "rule_id": "BW-TRV-02",
   "type": "path-traversal",
   "requests": 4,
   "addresses": 2,
   "sensor": "edge",
   "first": "2026-10-03T00:01:00+02:00",
   "method": "GET",
   "path": "/_image?href=/../../../.env",
   "ip": "34.19.75.177"
  },
  {
   "severity": "critical",
   "rule": "Secret or VCS file probe",
   "rule_id": "BW-SEC-01",
   "type": "secret-probe",
   "requests": 35,
   "addresses": 8,
   "sensor": "web-1",
   "first": "2026-10-02T18:54:00+02:00",
   "method": "GET",
   "path": "/.env",
   "ip": "170.64.196.141"
  },
  {
   "severity": "critical",
   "rule": "PHP or shell payload",
   "rule_id": "BW-RCE-03",
   "type": "rce-payload",
   "requests": 6,
   "addresses": 2,
   "sensor": "web-1",
   "first": "2026-10-02T20:41:00+02:00",
   "method": "POST",
   "path": "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
   "ip": "170.64.196.141"
  },
  {
   "severity": "critical",
   "rule": "Credential, state or dump file probe",
   "rule_id": "BW-SEC-02",
   "type": "credential-probe",
   "requests": 2,
   "addresses": 1,
   "sensor": "web-1",
   "first": "2026-10-02T21:53:00+02:00",
   "method": "GET",
   "path": "/wp-config.php",
   "ip": "45.156.87.186"
  },
  {
   "severity": "high",
   "rule": "Attack tool user agent",
   "rule_id": "BW-UA-01",
   "type": "attack-tool",
   "requests": 5,
   "addresses": 4,
   "sensor": "web-1",
   "first": "2026-10-02T20:10:00+02:00",
   "method": "GET",
   "path": "/",
   "ip": "20.65.202.209"
  },
  {
   "severity": "medium",
   "rule": "CMS, admin or appliance probe",
   "rule_id": "BW-CMS-01",
   "type": "cms-probe",
   "requests": 54,
   "addresses": 5,
   "sensor": "web-1",
   "first": "2026-10-02T20:41:00+02:00",
   "method": "GET",
   "path": "/_ignition/execute-solution",
   "ip": "170.64.196.141"
  },
  {
   "severity": "critical",
   "rule": "Secret or VCS file probe",
   "rule_id": "BW-SEC-01",
   "type": "secret-probe",
   "requests": 21,
   "addresses": 4,
   "sensor": "web-2",
   "first": "2026-10-02T19:23:00+02:00",
   "method": "GET",
   "path": "/.env",
   "ip": "170.64.182.167"
  },
  {
   "severity": "critical",
   "rule": "PHP or shell payload",
   "rule_id": "BW-RCE-03",
   "type": "rce-payload",
   "requests": 3,
   "addresses": 2,
   "sensor": "web-2",
   "first": "2026-10-02T23:43:00+02:00",
   "method": "POST",
   "path": "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh",
   "ip": "14.117.192.81"
  },
  {
   "severity": "critical",
   "rule": "Credential, state or dump file probe",
   "rule_id": "BW-SEC-02",
   "type": "credential-probe",
   "requests": 1,
   "addresses": 1,
   "sensor": "web-2",
   "first": "2026-10-03T01:10:00+02:00",
   "method": "GET",
   "path": "/id_rsa",
   "ip": "209.99.185.60"
  },
  {
   "severity": "high",
   "rule": "Attack tool user agent",
   "rule_id": "BW-UA-01",
   "type": "attack-tool",
   "requests": 5,
   "addresses": 5,
   "sensor": "web-2",
   "first": "2026-10-02T20:16:00+02:00",
   "method": "GET",
   "path": "/",
   "ip": "20.80.111.73"
  },
  {
   "severity": "medium",
   "rule": "CMS, admin or appliance probe",
   "rule_id": "BW-CMS-01",
   "type": "cms-probe",
   "requests": 26,
   "addresses": 4,
   "sensor": "web-2",
   "first": "2026-10-02T18:23:00+02:00",
   "method": "GET",
   "path": "//wp-includes/wlwmanifest.xml",
   "ip": "203.159.90.72"
  },
  {
   "severity": "critical",
   "rule": "Secret or VCS file probe",
   "rule_id": "BW-SEC-01",
   "type": "secret-probe",
   "requests": 81,
   "addresses": 8,
   "sensor": "web-3",
   "first": "2026-10-02T19:02:00+02:00",
   "method": "GET",
   "path": "/.git/config",
   "ip": "104.23.239.80"
  },
  {
   "severity": "critical",
   "rule": "Credential, state or dump file probe",
   "rule_id": "BW-SEC-02",
   "type": "credential-probe",
   "requests": 14,
   "addresses": 2,
   "sensor": "web-3",
   "first": "2026-10-02T19:19:00+02:00",
   "method": "GET",
   "path": "/wp-config.php.bak",
   "ip": "45.138.12.25"
  },
  {
   "severity": "critical",
   "rule": "PHP or shell payload",
   "rule_id": "BW-RCE-03",
   "type": "rce-payload",
   "requests": 2,
   "addresses": 2,
   "sensor": "web-3",
   "first": "2026-10-02T22:54:00+02:00",
   "method": "POST",
   "path": "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh",
   "ip": "103.216.170.129"
  },
  {
   "severity": "high",
   "rule": "Attack tool user agent",
   "rule_id": "BW-UA-01",
   "type": "attack-tool",
   "requests": 8,
   "addresses": 7,
   "sensor": "web-3",
   "first": "2026-10-02T19:19:00+02:00",
   "method": "GET",
   "path": "/owa/auth/logon.aspx",
   "ip": "172.202.106.156"
  },
  {
   "severity": "medium",
   "rule": "PHP script probe",
   "rule_id": "BW-PHP-01",
   "type": "php-probe",
   "requests": 10,
   "addresses": 4,
   "sensor": "web-3",
   "first": "2026-10-02T19:19:00+02:00",
   "method": "GET",
   "path": "/phpinfo.php",
   "ip": "45.138.12.25"
  }
 ],
 "events": [
  {
   "t": "2026-10-02T18:02:00+02:00",
   "ip": "96.126.130.210",
   "type": "secret-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/.env",
   "sensor": "edge"
  },
  {
   "t": "2026-10-02T18:18:00+02:00",
   "ip": "104.23.223.8",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-02T18:23:00+02:00",
   "ip": "34.178.138.173",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-02T18:23:00+02:00",
   "ip": "203.159.90.72",
   "type": "cms-probe",
   "kind": "finding",
   "severity": "medium",
   "path": "//wp-includes/wlwmanifest.xml",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-02T18:43:00+02:00",
   "ip": "194.61.40.98",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-02T18:54:00+02:00",
   "ip": "170.64.196.141",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-02T18:54:00+02:00",
   "ip": "170.64.196.141",
   "type": "secret-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/.env",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-02T19:02:00+02:00",
   "ip": "104.23.239.80",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-02T19:02:00+02:00",
   "ip": "104.23.239.80",
   "type": "secret-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/.git/config",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-02T19:07:00+02:00",
   "ip": "45.138.12.10",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-02T19:08:00+02:00",
   "ip": "172.71.15.24",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-02T19:09:00+02:00",
   "ip": "45.156.87.186",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-02T19:09:00+02:00",
   "ip": "45.156.87.186",
   "type": "credential-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/wp-config.php",
   "sensor": "edge"
  },
  {
   "t": "2026-10-02T19:10:00+02:00",
   "ip": "172.70.250.57",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-02T19:19:00+02:00",
   "ip": "45.138.12.25",
   "type": "credential-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/wp-config.php.bak",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-02T19:19:00+02:00",
   "ip": "172.202.106.156",
   "type": "attack-tool",
   "kind": "finding",
   "severity": "high",
   "path": "/owa/auth/logon.aspx",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-02T19:19:00+02:00",
   "ip": "45.138.12.25",
   "type": "php-probe",
   "kind": "finding",
   "severity": "medium",
   "path": "/phpinfo.php",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-02T19:21:00+02:00",
   "ip": "104.23.223.154",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-02T19:22:00+02:00",
   "ip": "170.64.182.167",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-02T19:22:00+02:00",
   "ip": "170.64.182.167",
   "type": "rce-payload",
   "kind": "finding",
   "severity": "critical",
   "path": "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
   "sensor": "edge"
  },
  {
   "t": "2026-10-02T19:23:00+02:00",
   "ip": "170.64.182.167",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-02T19:23:00+02:00",
   "ip": "170.64.182.167",
   "type": "secret-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/.env",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-02T19:26:00+02:00",
   "ip": "172.68.213.54",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-02T19:30:00+02:00",
   "ip": "193.36.224.245",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-02T19:30:00+02:00",
   "ip": "193.36.224.249",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-02T19:30:00+02:00",
   "ip": "193.36.224.218",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-02T19:39:00+02:00",
   "ip": "54.94.85.181",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-02T19:44:00+02:00",
   "ip": "34.12.94.35",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-02T19:45:00+02:00",
   "ip": "45.138.12.25",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-02T19:48:00+02:00",
   "ip": "45.138.12.9",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-02T19:51:00+02:00",
   "ip": "172.70.240.180",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-02T20:10:00+02:00",
   "ip": "20.65.202.209",
   "type": "attack-tool",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-02T20:10:00+02:00",
   "ip": "20.65.202.209",
   "type": "attack-tool",
   "kind": "finding",
   "severity": "high",
   "path": "/",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-02T20:12:00+02:00",
   "ip": "170.64.131.170",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-02T20:16:00+02:00",
   "ip": "20.80.111.73",
   "type": "attack-tool",
   "kind": "finding",
   "severity": "high",
   "path": "/",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-02T20:18:00+02:00",
   "ip": "31.171.130.154",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-02T20:18:00+02:00",
   "ip": "31.171.130.160",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-02T20:28:00+02:00",
   "ip": "37.120.213.13",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-02T20:41:00+02:00",
   "ip": "170.64.196.141",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-02T20:41:00+02:00",
   "ip": "170.64.196.141",
   "type": "rce-payload",
   "kind": "finding",
   "severity": "critical",
   "path": "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-02T20:41:00+02:00",
   "ip": "170.64.196.141",
   "type": "cms-probe",
   "kind": "finding",
   "severity": "medium",
   "path": "/_ignition/execute-solution",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-02T20:44:00+02:00",
   "ip": "172.68.194.182",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-02T20:44:00+02:00",
   "ip": "162.158.110.254",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-02T20:52:00+02:00",
   "ip": "172.69.150.71",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-02T21:13:00+02:00",
   "ip": "31.171.130.110",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-02T21:19:00+02:00",
   "ip": "134.199.164.71",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-02T21:53:00+02:00",
   "ip": "45.156.87.186",
   "type": "credential-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-02T21:53:00+02:00",
   "ip": "45.156.87.186",
   "type": "credential-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/wp-config.php",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-02T22:11:00+02:00",
   "ip": "170.64.214.139",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-02T22:11:00+02:00",
   "ip": "45.138.12.45",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-02T22:15:00+02:00",
   "ip": "34.23.78.56",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-02T22:21:00+02:00",
   "ip": "172.70.247.113",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-02T22:29:00+02:00",
   "ip": "170.64.197.162",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-02T22:34:00+02:00",
   "ip": "81.171.72.135",
   "type": "credential-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-02T22:54:00+02:00",
   "ip": "103.216.170.129",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-02T22:54:00+02:00",
   "ip": "103.216.170.129",
   "type": "rce-payload",
   "kind": "finding",
   "severity": "critical",
   "path": "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-02T23:00:00+02:00",
   "ip": "170.64.197.162",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-02T23:02:00+02:00",
   "ip": "195.178.110.28",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-02T23:04:00+02:00",
   "ip": "209.141.51.90",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-02T23:07:00+02:00",
   "ip": "35.225.6.63",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-02T23:23:00+02:00",
   "ip": "159.223.180.252",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-02T23:43:00+02:00",
   "ip": "14.117.192.81",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-02T23:43:00+02:00",
   "ip": "14.117.192.81",
   "type": "rce-payload",
   "kind": "finding",
   "severity": "critical",
   "path": "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-02T23:46:00+02:00",
   "ip": "35.222.122.52",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-02T23:46:00+02:00",
   "ip": "20.210.186.186",
   "type": "php-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T00:01:00+02:00",
   "ip": "34.19.75.177",
   "type": "path-traversal",
   "kind": "finding",
   "severity": "critical",
   "path": "/[@]fs/proc/self/environ?import&raw??",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T00:01:00+02:00",
   "ip": "34.19.75.177",
   "type": "path-traversal",
   "kind": "finding",
   "severity": "high",
   "path": "/_image?href=/../../../.env",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T00:28:00+02:00",
   "ip": "35.185.17.194",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T00:31:00+02:00",
   "ip": "91.148.244.131",
   "type": "credential-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-03T00:55:00+02:00",
   "ip": "159.89.98.12",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T01:00:00+02:00",
   "ip": "185.19.40.62",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-03T01:10:00+02:00",
   "ip": "209.99.185.60",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-03T01:10:00+02:00",
   "ip": "209.99.185.60",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-03T01:10:00+02:00",
   "ip": "209.99.185.60",
   "type": "credential-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/id_rsa",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-03T01:12:00+02:00",
   "ip": "43.157.211.165",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-03T01:27:00+02:00",
   "ip": "71.62.11.39",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T01:29:00+02:00",
   "ip": "34.21.135.165",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T01:56:00+02:00",
   "ip": "134.199.157.29",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T02:11:00+02:00",
   "ip": "91.92.241.196",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T02:27:00+02:00",
   "ip": "172.86.81.110",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T02:28:00+02:00",
   "ip": "45.148.10.8",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-03T02:37:00+02:00",
   "ip": "27.102.121.33",
   "type": "php-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-03T03:09:00+02:00",
   "ip": "134.199.175.94",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T04:33:00+02:00",
   "ip": "138.201.135.150",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-03T04:38:00+02:00",
   "ip": "45.138.12.6",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T04:48:00+02:00",
   "ip": "68.69.177.112",
   "type": "attack-tool",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-03T04:51:00+02:00",
   "ip": "195.178.110.106",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T04:59:00+02:00",
   "ip": "104.28.245.161",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-03T05:09:00+02:00",
   "ip": "43.136.79.172",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-03T05:18:00+02:00",
   "ip": "128.199.182.152",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T05:18:00+02:00",
   "ip": "164.90.228.79",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T05:21:00+02:00",
   "ip": "206.81.12.187",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T05:24:00+02:00",
   "ip": "45.138.12.53",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-03T05:36:00+02:00",
   "ip": "184.105.139.69",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-03T05:42:00+02:00",
   "ip": "20.198.74.230",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-03T05:50:00+02:00",
   "ip": "203.159.90.72",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "web-1"
  }
 ],
 "attackers": [
  {
   "ip": "20.210.186.186",
   "country": "Japan",
   "cc": "JP",
   "city": "Osaka",
   "lat": 34.6937,
   "lon": 135.502,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "php-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 184,
   "first_seen": "2026-10-02T23:46:00+02:00",
   "last_seen": "2026-10-02T23:46:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [
    "banned until Sat 22:26"
   ],
   "tags": [
    "hosting-provider",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-04",
    "2026-10-05"
   ]
  },
  {
   "ip": "20.198.74.230",
   "country": "India",
   "cc": "IN",
   "city": "Pune",
   "lat": 18.5204,
   "lon": 73.8567,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 183,
   "first_seen": "2026-10-03T05:42:00+02:00",
   "last_seen": "2026-10-03T05:42:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [
    "ban expired Sat 06:42"
   ],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "35.229.36.226",
   "country": "United States",
   "cc": "US",
   "city": "North Charleston",
   "lat": 32.8769,
   "lon": -80.0114,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "226.36.229.35.bc.googleusercontent.com",
   "types": [],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": 152,
   "first_seen": null,
   "last_seen": null,
   "sensors": [
    "edge"
   ],
   "notes": [
    "spared: shared address"
   ],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Unattributed automated probe",
    "confidence": "low",
    "evidence": []
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "45.138.12.25",
   "country": "Hong Kong",
   "cc": "HK",
   "city": "Sheung Wan",
   "lat": 22.286,
   "lon": 114.152,
   "asn": 218785,
   "org": "TC DATACENTER LIMITED",
   "ptr": null,
   "types": [
    "secret-probe",
    "credential-probe",
    "php-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 74,
   "first_seen": "2026-10-02T19:19:00+02:00",
   "last_seen": "2026-10-02T19:45:00+02:00",
   "sensors": [
    "edge",
    "web-3"
   ],
   "notes": [
    "spared: shared address"
   ],
   "tags": [
    "abuse-prone-hosting",
    "cluster:45.138.12.0/24"
   ],
   "paths": [
    "/phpinfo.php",
    "/wp-config.php.bak"
   ],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "AS218785 TC DATACENTER (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "7 addresses from 45.138.12.0/24 (AS218785) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "45.138.12.43",
   "country": "Hong Kong",
   "cc": "HK",
   "city": "Sheung Wan",
   "lat": 22.286,
   "lon": 114.152,
   "asn": 218785,
   "org": "TC DATACENTER LIMITED",
   "ptr": null,
   "types": [],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": 42,
   "first_seen": null,
   "last_seen": null,
   "sensors": [
    "web-1"
   ],
   "notes": [
    "spared: shared address"
   ],
   "tags": [
    "abuse-prone-hosting",
    "cluster:45.138.12.0/24",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Known-bad scanning infrastructure",
    "confidence": "medium",
    "evidence": [
     "AS218785 TC DATACENTER (abuse-prone hosting)",
     "7 addresses from 45.138.12.0/24 (AS218785) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-05"
   ]
  },
  {
   "ip": "91.148.244.131",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Haarlem (Oude Stad)",
   "lat": 52.3894,
   "lon": 4.63245,
   "asn": 34343,
   "org": "Eweka Internet Services B.V.",
   "ptr": null,
   "types": [
    "credential-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 23,
   "first_seen": "2026-10-03T00:31:00+02:00",
   "last_seen": "2026-10-03T00:31:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [
    "ban expired 01:31"
   ],
   "tags": [
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-04",
    "2026-10-05"
   ]
  },
  {
   "ip": "209.99.185.60",
   "country": "United States",
   "cc": "US",
   "city": "San Francisco",
   "lat": 37.7749,
   "lon": -122.419,
   "asn": 402253,
   "org": "SKN Subnet & Telecom Ltd",
   "ptr": null,
   "types": [
    "secret-probe",
    "credential-probe"
   ],
   "bans": 2,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 20,
   "first_seen": "2026-10-03T01:10:00+02:00",
   "last_seen": "2026-10-03T01:10:00+02:00",
   "sensors": [
    "web-1",
    "web-2"
   ],
   "notes": [
    "ban expired 02:10"
   ],
   "tags": [
    "spamhaus-drop",
    "firehol-level1"
   ],
   "paths": [
    "/id_rsa"
   ],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "45.156.87.186",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Amsterdam",
   "lat": 52.3676,
   "lon": 4.90414,
   "asn": 197170,
   "org": "TechTies Inc.",
   "ptr": null,
   "types": [
    "credential-probe",
    "secret-probe"
   ],
   "bans": 2,
   "max_offence": 2,
   "ban_state": "expired",
   "requests_known": 12,
   "first_seen": "2026-10-02T19:09:00+02:00",
   "last_seen": "2026-10-02T21:53:00+02:00",
   "sensors": [
    "edge",
    "web-1"
   ],
   "notes": [
    "ban expired 22:53"
   ],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "repeat-offender",
    "multi-night"
   ],
   "paths": [
    "/wp-config.php"
   ],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-04"
   ]
  },
  {
   "ip": "45.138.12.53",
   "country": "Hong Kong",
   "cc": "HK",
   "city": "Sheung Wan",
   "lat": 22.286,
   "lon": 114.152,
   "asn": 218785,
   "org": "TC DATACENTER LIMITED",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 8,
   "first_seen": "2026-10-03T05:24:00+02:00",
   "last_seen": "2026-10-03T05:24:00+02:00",
   "sensors": [
    "web-1",
    "web-2"
   ],
   "notes": [
    "spared: shared address"
   ],
   "tags": [
    "abuse-prone-hosting",
    "cluster:45.138.12.0/24"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "AS218785 TC DATACENTER (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "7 addresses from 45.138.12.0/24 (AS218785) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "27.102.121.33",
   "country": "South Korea",
   "cc": "KR",
   "city": "Seongnam-si (Geumto-ro)",
   "lat": 37.4078,
   "lon": 127.079,
   "asn": 45996,
   "org": "DAOU TECHNOLOGY",
   "ptr": null,
   "types": [
    "php-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 7,
   "first_seen": "2026-10-03T02:37:00+02:00",
   "last_seen": "2026-10-03T02:37:00+02:00",
   "sensors": [
    "web-1",
    "web-2",
    "web-3"
   ],
   "notes": [
    "ban expired 03:37",
    "not banned"
   ],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "45.138.12.45",
   "country": "Hong Kong",
   "cc": "HK",
   "city": "Sheung Wan",
   "lat": 22.286,
   "lon": 114.152,
   "asn": 218785,
   "org": "TC DATACENTER LIMITED",
   "ptr": null,
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 5,
   "first_seen": "2026-10-02T22:11:00+02:00",
   "last_seen": "2026-10-02T22:11:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [
    "ban expired 23:11"
   ],
   "tags": [
    "abuse-prone-hosting",
    "cluster:45.138.12.0/24",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Known-bad scanning infrastructure",
    "confidence": "medium",
    "evidence": [
     "AS218785 TC DATACENTER (abuse-prone hosting)",
     "7 addresses from 45.138.12.0/24 (AS218785) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-04"
   ]
  },
  {
   "ip": "167.250.224.25",
   "country": "Brazil",
   "cc": "BR",
   "city": "Campo Maior",
   "lat": -4.82778,
   "lon": -42.1686,
   "asn": 265210,
   "org": "OSCAR M DE CARVALHO - ME",
   "ptr": null,
   "types": [],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": 4,
   "first_seen": null,
   "last_seen": null,
   "sensors": [
    "web-2"
   ],
   "notes": [
    "not banned"
   ],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Unattributed automated probe",
    "confidence": "low",
    "evidence": []
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "152.42.141.52",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Amsterdam",
   "lat": 52.3563,
   "lon": 4.95714,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": null,
   "types": [],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": 2,
   "first_seen": null,
   "last_seen": null,
   "sensors": [
    "web-3"
   ],
   "notes": [
    "not banned"
   ],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Unattributed automated probe",
    "confidence": "low",
    "evidence": []
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "167.71.105.201",
   "country": "United States",
   "cc": "US",
   "city": "Clifton",
   "lat": 40.8302,
   "lon": -74.1299,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": null,
   "types": [],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": 2,
   "first_seen": null,
   "last_seen": null,
   "sensors": [
    "web-3"
   ],
   "notes": [
    "not banned"
   ],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Unattributed automated probe",
    "confidence": "low",
    "evidence": []
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "170.64.182.167",
   "country": "Australia",
   "cc": "AU",
   "city": "Alexandria",
   "lat": -33.9088,
   "lon": 151.196,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": null,
   "types": [
    "secret-probe",
    "rce-payload"
   ],
   "bans": 2,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T19:22:00+02:00",
   "last_seen": "2026-10-02T19:23:00+02:00",
   "sensors": [
    "edge",
    "web-2"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [
    "/.env",
    "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"
   ],
   "actor": {
    "label": "Suspected Androxgh0st-style Laravel/PHPUnit exploitation",
    "confidence": "low",
    "evidence": [
     "probes PHPUnit eval-stdin.php (CVE-2017-9841), a technique documented in CISA AA24-016A",
     "no request bodies are logged, so the malware family cannot be confirmed"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "170.64.196.141",
   "country": "Australia",
   "cc": "AU",
   "city": "Alexandria",
   "lat": -33.9088,
   "lon": 151.196,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": null,
   "types": [
    "secret-probe",
    "rce-payload",
    "cms-probe"
   ],
   "bans": 2,
   "max_offence": 2,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T18:54:00+02:00",
   "last_seen": "2026-10-02T20:41:00+02:00",
   "sensors": [
    "web-1"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "repeat-offender"
   ],
   "paths": [
    "/.env",
    "/_ignition/execute-solution",
    "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"
   ],
   "actor": {
    "label": "Suspected Androxgh0st-style Laravel/PHPUnit exploitation",
    "confidence": "low",
    "evidence": [
     "probes PHPUnit eval-stdin.php (CVE-2017-9841), a technique documented in CISA AA24-016A",
     "no request bodies are logged, so the malware family cannot be confirmed"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "170.64.197.162",
   "country": "Australia",
   "cc": "AU",
   "city": "Alexandria",
   "lat": -33.9088,
   "lon": 151.196,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 2,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T22:29:00+02:00",
   "last_seen": "2026-10-02T23:00:00+02:00",
   "sensors": [
    "edge",
    "web-2"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "103.216.170.129",
   "country": "India",
   "cc": "IN",
   "city": "Mumbai (Navjeevan Society)",
   "lat": 18.9681,
   "lon": 72.8239,
   "asn": 135198,
   "org": "Bombay Bullion Commmunication",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T22:54:00+02:00",
   "last_seen": "2026-10-02T22:54:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "multi-night"
   ],
   "paths": [
    "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh"
   ],
   "actor": {
    "label": "Suspected Mirai-style IoT botnet",
    "confidence": "medium",
    "evidence": [
     "IoT/router exploit path with a downloader typical of Mirai-family loaders"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "104.23.223.154",
   "country": "Sweden",
   "cc": "SE",
   "city": "Stockholm",
   "lat": 59.3327,
   "lon": 18.0656,
   "asn": 13335,
   "org": "Cloudflare, Inc.",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T19:21:00+02:00",
   "last_seen": "2026-10-02T19:21:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "cdn-edge"
   ],
   "paths": [],
   "actor": {
    "label": "CDN edge relaying an attack (true origin hidden)",
    "confidence": "high",
    "evidence": [
     "AS13335 Cloudflare is a CDN; the real client is behind it"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "104.23.223.8",
   "country": "Sweden",
   "cc": "SE",
   "city": "Stockholm",
   "lat": 59.3327,
   "lon": 18.0656,
   "asn": 13335,
   "org": "Cloudflare, Inc.",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T18:18:00+02:00",
   "last_seen": "2026-10-02T18:18:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "cdn-edge"
   ],
   "paths": [],
   "actor": {
    "label": "CDN edge relaying an attack (true origin hidden)",
    "confidence": "high",
    "evidence": [
     "AS13335 Cloudflare is a CDN; the real client is behind it"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "104.23.239.80",
   "country": "Germany",
   "cc": "DE",
   "city": "Frankfurt am Main",
   "lat": 50.1109,
   "lon": 8.68213,
   "asn": 13335,
   "org": "Cloudflare, Inc.",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T19:02:00+02:00",
   "last_seen": "2026-10-02T19:02:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "cdn-edge"
   ],
   "paths": [
    "/.git/config"
   ],
   "actor": {
    "label": "CDN edge relaying an attack (true origin hidden)",
    "confidence": "high",
    "evidence": [
     "AS13335 Cloudflare is a CDN; the real client is behind it"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "104.28.245.161",
   "country": "Egypt",
   "cc": "EG",
   "city": "Shubr\u0101 al Khaymah",
   "lat": 30.1234,
   "lon": 31.2609,
   "asn": 13335,
   "org": "Cloudflare, Inc.",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T04:59:00+02:00",
   "last_seen": "2026-10-03T04:59:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "cdn-edge"
   ],
   "paths": [],
   "actor": {
    "label": "CDN edge relaying an attack (true origin hidden)",
    "confidence": "high",
    "evidence": [
     "AS13335 Cloudflare is a CDN; the real client is behind it"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "128.199.182.152",
   "country": "Singapore",
   "cc": "SG",
   "city": "Singapore (Pioneer)",
   "lat": 1.32123,
   "lon": 103.695,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": "cdffb2c5b1.scan.leakix.org",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T05:18:00+02:00",
   "last_seen": "2026-10-03T05:18:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS cdffb2c5b1.scan.leakix.org"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "134.199.157.29",
   "country": "Australia",
   "cc": "AU",
   "city": "Alexandria",
   "lat": -33.9088,
   "lon": 151.196,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T01:56:00+02:00",
   "last_seen": "2026-10-03T01:56:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-04"
   ]
  },
  {
   "ip": "134.199.164.71",
   "country": "Australia",
   "cc": "AU",
   "city": "Alexandria",
   "lat": -33.9088,
   "lon": 151.196,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T21:19:00+02:00",
   "last_seen": "2026-10-02T21:19:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "134.199.175.94",
   "country": "Australia",
   "cc": "AU",
   "city": "Alexandria",
   "lat": -33.9088,
   "lon": 151.196,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": null,
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T03:09:00+02:00",
   "last_seen": "2026-10-03T03:09:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "138.201.135.150",
   "country": "Germany",
   "cc": "DE",
   "city": "Falkenstein",
   "lat": 50.4754,
   "lon": 12.3683,
   "asn": 24940,
   "org": "Hetzner Online GmbH",
   "ptr": "static.150.135.201.138.clients.your-server.de",
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T04:33:00+02:00",
   "last_seen": "2026-10-03T04:33:00+02:00",
   "sensors": [
    "web-1"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "14.117.192.81",
   "country": "China",
   "cc": "CN",
   "city": "Guangzhou",
   "lat": 23.1317,
   "lon": 113.266,
   "asn": 136199,
   "org": "CHINANET Guangdong province Yuedong MAN network",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T23:43:00+02:00",
   "last_seen": "2026-10-02T23:43:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [],
   "tags": [],
   "paths": [
    "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh"
   ],
   "actor": {
    "label": "Suspected Mirai-style IoT botnet",
    "confidence": "medium",
    "evidence": [
     "IoT/router exploit path with a downloader typical of Mirai-family loaders"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "159.223.180.252",
   "country": "United States",
   "cc": "US",
   "city": "North Bergen",
   "lat": 40.8054,
   "lon": -74.0241,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T23:23:00+02:00",
   "last_seen": "2026-10-02T23:23:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "159.89.98.12",
   "country": "Germany",
   "cc": "DE",
   "city": "Freiburg im Breisgau",
   "lat": 47.9959,
   "lon": 7.85222,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T00:55:00+02:00",
   "last_seen": "2026-10-03T00:55:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "162.158.110.254",
   "country": "Germany",
   "cc": "DE",
   "city": "Frankfurt am Main",
   "lat": 50.1109,
   "lon": 8.68213,
   "asn": 13335,
   "org": "Cloudflare, Inc.",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T20:44:00+02:00",
   "last_seen": "2026-10-02T20:44:00+02:00",
   "sensors": [
    "web-1"
   ],
   "notes": [],
   "tags": [
    "cdn-edge"
   ],
   "paths": [],
   "actor": {
    "label": "CDN edge relaying an attack (true origin hidden)",
    "confidence": "high",
    "evidence": [
     "AS13335 Cloudflare is a CDN; the real client is behind it"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "164.90.228.79",
   "country": "Germany",
   "cc": "DE",
   "city": "Frankfurt am Main",
   "lat": 50.1109,
   "lon": 8.68213,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": "fee8d5bfdc.scan.leakix.org",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T05:18:00+02:00",
   "last_seen": "2026-10-03T05:18:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS fee8d5bfdc.scan.leakix.org"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "170.64.131.170",
   "country": "Australia",
   "cc": "AU",
   "city": "Alexandria",
   "lat": -33.9088,
   "lon": 151.196,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T20:12:00+02:00",
   "last_seen": "2026-10-02T20:12:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-04"
   ]
  },
  {
   "ip": "170.64.214.139",
   "country": "Australia",
   "cc": "AU",
   "city": "Alexandria",
   "lat": -33.9088,
   "lon": 151.196,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T22:11:00+02:00",
   "last_seen": "2026-10-02T22:11:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-04"
   ]
  },
  {
   "ip": "172.68.194.182",
   "country": "Germany",
   "cc": "DE",
   "city": "Frankfurt am Main",
   "lat": 50.1109,
   "lon": 8.68213,
   "asn": 13335,
   "org": "Cloudflare, Inc.",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T20:44:00+02:00",
   "last_seen": "2026-10-02T20:44:00+02:00",
   "sensors": [
    "web-1"
   ],
   "notes": [],
   "tags": [
    "cdn-edge"
   ],
   "paths": [],
   "actor": {
    "label": "CDN edge relaying an attack (true origin hidden)",
    "confidence": "high",
    "evidence": [
     "AS13335 Cloudflare is a CDN; the real client is behind it"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "172.68.213.54",
   "country": "Czechia",
   "cc": "CZ",
   "city": "Prague",
   "lat": 50.0755,
   "lon": 14.4378,
   "asn": 13335,
   "org": "Cloudflare, Inc.",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T19:26:00+02:00",
   "last_seen": "2026-10-02T19:26:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "cdn-edge"
   ],
   "paths": [],
   "actor": {
    "label": "CDN edge relaying an attack (true origin hidden)",
    "confidence": "high",
    "evidence": [
     "AS13335 Cloudflare is a CDN; the real client is behind it"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "172.69.150.71",
   "country": "Germany",
   "cc": "DE",
   "city": "Frankfurt am Main",
   "lat": 50.1109,
   "lon": 8.68213,
   "asn": 13335,
   "org": "Cloudflare, Inc.",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T20:52:00+02:00",
   "last_seen": "2026-10-02T20:52:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "cdn-edge"
   ],
   "paths": [],
   "actor": {
    "label": "CDN edge relaying an attack (true origin hidden)",
    "confidence": "high",
    "evidence": [
     "AS13335 Cloudflare is a CDN; the real client is behind it"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "172.70.240.180",
   "country": "Germany",
   "cc": "DE",
   "city": "Frankfurt am Main",
   "lat": 50.1109,
   "lon": 8.68213,
   "asn": 13335,
   "org": "Cloudflare, Inc.",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T19:51:00+02:00",
   "last_seen": "2026-10-02T19:51:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "cdn-edge"
   ],
   "paths": [],
   "actor": {
    "label": "CDN edge relaying an attack (true origin hidden)",
    "confidence": "high",
    "evidence": [
     "AS13335 Cloudflare is a CDN; the real client is behind it"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "172.70.247.113",
   "country": "Germany",
   "cc": "DE",
   "city": "Frankfurt am Main",
   "lat": 50.1109,
   "lon": 8.68213,
   "asn": 13335,
   "org": "Cloudflare, Inc.",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T22:21:00+02:00",
   "last_seen": "2026-10-02T22:21:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "cdn-edge"
   ],
   "paths": [],
   "actor": {
    "label": "CDN edge relaying an attack (true origin hidden)",
    "confidence": "high",
    "evidence": [
     "AS13335 Cloudflare is a CDN; the real client is behind it"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "172.70.250.57",
   "country": "Germany",
   "cc": "DE",
   "city": "Frankfurt am Main",
   "lat": 50.1109,
   "lon": 8.68213,
   "asn": 13335,
   "org": "Cloudflare, Inc.",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T19:10:00+02:00",
   "last_seen": "2026-10-02T19:10:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "cdn-edge"
   ],
   "paths": [],
   "actor": {
    "label": "CDN edge relaying an attack (true origin hidden)",
    "confidence": "high",
    "evidence": [
     "AS13335 Cloudflare is a CDN; the real client is behind it"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "172.71.15.24",
   "country": "Czechia",
   "cc": "CZ",
   "city": "Prague",
   "lat": 50.0755,
   "lon": 14.4378,
   "asn": 13335,
   "org": "Cloudflare, Inc.",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T19:08:00+02:00",
   "last_seen": "2026-10-02T19:08:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "cdn-edge"
   ],
   "paths": [],
   "actor": {
    "label": "CDN edge relaying an attack (true origin hidden)",
    "confidence": "high",
    "evidence": [
     "AS13335 Cloudflare is a CDN; the real client is behind it"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "172.86.81.110",
   "country": "Singapore",
   "cc": "SG",
   "city": "Singapore",
   "lat": 1.35208,
   "lon": 103.82,
   "asn": 14956,
   "org": "RouterHosting LLC",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 3,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-03T02:27:00+02:00",
   "last_seen": "2026-10-03T02:27:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "184.105.139.69",
   "country": "United States",
   "cc": "US",
   "city": "Chicago",
   "lat": 41.8781,
   "lon": -87.6298,
   "asn": 6939,
   "org": "Hurricane Electric LLC",
   "ptr": "scan-03.shadowserver.io",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T05:36:00+02:00",
   "last_seen": "2026-10-03T05:36:00+02:00",
   "sensors": [
    "web-1"
   ],
   "notes": [],
   "tags": [
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS scan-03.shadowserver.io"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "185.19.40.62",
   "country": "Germany",
   "cc": "DE",
   "city": "Frankfurt am Main",
   "lat": 50.1109,
   "lon": 8.68213,
   "asn": 210558,
   "org": "1337 Services GmbH",
   "ptr": null,
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T01:00:00+02:00",
   "last_seen": "2026-10-03T01:00:00+02:00",
   "sensors": [
    "web-1"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Known-bad scanning infrastructure",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "193.36.224.218",
   "country": "United States",
   "cc": "US",
   "city": "Ormond Beach",
   "lat": 29.2858,
   "lon": -81.0559,
   "asn": 206092,
   "org": "F.N.S. HOLDINGS LIMITED",
   "ptr": null,
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T19:30:00+02:00",
   "last_seen": "2026-10-02T19:30:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "cluster:193.36.224.0/24"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "medium",
    "evidence": [
     "CMS, admin panel or PHP script probing",
     "3 addresses from 193.36.224.0/24 (AS206092) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "193.36.224.245",
   "country": "United States",
   "cc": "US",
   "city": "Ormond Beach",
   "lat": 29.2858,
   "lon": -81.0559,
   "asn": 206092,
   "org": "F.N.S. HOLDINGS LIMITED",
   "ptr": null,
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T19:30:00+02:00",
   "last_seen": "2026-10-02T19:30:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "cluster:193.36.224.0/24"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "medium",
    "evidence": [
     "CMS, admin panel or PHP script probing",
     "3 addresses from 193.36.224.0/24 (AS206092) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "193.36.224.249",
   "country": "United States",
   "cc": "US",
   "city": "Ormond Beach",
   "lat": 29.2858,
   "lon": -81.0559,
   "asn": 206092,
   "org": "F.N.S. HOLDINGS LIMITED",
   "ptr": null,
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T19:30:00+02:00",
   "last_seen": "2026-10-02T19:30:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "cluster:193.36.224.0/24"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "medium",
    "evidence": [
     "CMS, admin panel or PHP script probing",
     "3 addresses from 193.36.224.0/24 (AS206092) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "194.61.40.98",
   "country": "India",
   "cc": "IN",
   "city": "New Delhi",
   "lat": 28.6139,
   "lon": 77.2088,
   "asn": 137409,
   "org": "GSL Networks Pty LTD",
   "ptr": null,
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T18:43:00+02:00",
   "last_seen": "2026-10-02T18:43:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "195.178.110.106",
   "country": "Andorra",
   "cc": "AD",
   "city": "Andorra la Vella",
   "lat": 42.5063,
   "lon": 1.52184,
   "asn": 48090,
   "org": "TECHOFF SRV LIMITED",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T04:51:00+02:00",
   "last_seen": "2026-10-03T04:51:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "abuse-prone-hosting",
    "cluster:195.178.110.0/24"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "AS48090 TECHOFF SRV (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "2 addresses from 195.178.110.0/24 (AS48090) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "195.178.110.28",
   "country": "Andorra",
   "cc": "AD",
   "city": "Andorra la Vella",
   "lat": 42.5063,
   "lon": 1.52184,
   "asn": 48090,
   "org": "TECHOFF SRV LIMITED",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T23:02:00+02:00",
   "last_seen": "2026-10-02T23:02:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "abuse-prone-hosting",
    "cluster:195.178.110.0/24",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "AS48090 TECHOFF SRV (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "2 addresses from 195.178.110.0/24 (AS48090) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-04"
   ]
  },
  {
   "ip": "20.65.202.209",
   "country": "United States",
   "cc": "US",
   "city": "San Antonio",
   "lat": 29.4252,
   "lon": -98.4946,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "attack-tool"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T20:10:00+02:00",
   "last_seen": "2026-10-02T20:10:00+02:00",
   "sensors": [
    "web-1"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [
    "/"
   ],
   "actor": {
    "label": "Automated attack tool",
    "confidence": "low",
    "evidence": [
     "request carried a known attack-tool user agent"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "203.159.90.72",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Lelystad",
   "lat": 52.5143,
   "lon": 5.48791,
   "asn": 210558,
   "org": "1337 Services GmbH",
   "ptr": null,
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 3,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-02T18:23:00+02:00",
   "last_seen": "2026-10-03T05:50:00+02:00",
   "sensors": [
    "web-1",
    "web-2"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "repeat-offender"
   ],
   "paths": [
    "//wp-includes/wlwmanifest.xml"
   ],
   "actor": {
    "label": "Known-bad scanning infrastructure",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "206.81.12.187",
   "country": "United States",
   "cc": "US",
   "city": "North Bergen",
   "lat": 40.8054,
   "lon": -74.0241,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": "bf99e5305e.scan.leakix.org",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T05:21:00+02:00",
   "last_seen": "2026-10-03T05:21:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "research-scanner",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS bf99e5305e.scan.leakix.org"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-06"
   ]
  },
  {
   "ip": "209.141.51.90",
   "country": "United States",
   "cc": "US",
   "city": "Las Vegas",
   "lat": 36.0765,
   "lon": -115.153,
   "asn": 53667,
   "org": "FranTech Solutions",
   "ptr": "bzfnice.co.uk",
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T23:04:00+02:00",
   "last_seen": "2026-10-02T23:04:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "31.171.130.110",
   "country": "United Kingdom",
   "cc": "GB",
   "city": "London",
   "lat": 51.6042,
   "lon": -0.0675738,
   "asn": 206092,
   "org": "F.N.S. HOLDINGS LIMITED",
   "ptr": null,
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T21:13:00+02:00",
   "last_seen": "2026-10-02T21:13:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "cluster:31.171.130.0/24"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "medium",
    "evidence": [
     "CMS, admin panel or PHP script probing",
     "3 addresses from 31.171.130.0/24 (AS206092) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "31.171.130.154",
   "country": "United Kingdom",
   "cc": "GB",
   "city": "London",
   "lat": 51.6042,
   "lon": -0.0675738,
   "asn": 206092,
   "org": "F.N.S. HOLDINGS LIMITED",
   "ptr": null,
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T20:18:00+02:00",
   "last_seen": "2026-10-02T20:18:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "cluster:31.171.130.0/24"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "medium",
    "evidence": [
     "CMS, admin panel or PHP script probing",
     "3 addresses from 31.171.130.0/24 (AS206092) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "31.171.130.160",
   "country": "United Kingdom",
   "cc": "GB",
   "city": "London",
   "lat": 51.6042,
   "lon": -0.0675738,
   "asn": 206092,
   "org": "F.N.S. HOLDINGS LIMITED",
   "ptr": null,
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T20:18:00+02:00",
   "last_seen": "2026-10-02T20:18:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "cluster:31.171.130.0/24"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "medium",
    "evidence": [
     "CMS, admin panel or PHP script probing",
     "3 addresses from 31.171.130.0/24 (AS206092) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "34.12.94.35",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Groningen",
   "lat": 53.2194,
   "lon": 6.5665,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "35.94.12.34.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T19:44:00+02:00",
   "last_seen": "2026-10-02T19:44:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "34.178.138.173",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Groningen",
   "lat": 53.2194,
   "lon": 6.5665,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "173.138.178.34.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T18:23:00+02:00",
   "last_seen": "2026-10-02T18:23:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "34.21.135.165",
   "country": "Singapore",
   "cc": "SG",
   "city": "Singapore",
   "lat": 1.35208,
   "lon": 103.82,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "165.135.21.34.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T01:29:00+02:00",
   "last_seen": "2026-10-03T01:29:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "34.23.78.56",
   "country": "United States",
   "cc": "US",
   "city": "North Charleston",
   "lat": 32.8769,
   "lon": -80.0114,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "56.78.23.34.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T22:15:00+02:00",
   "last_seen": "2026-10-02T22:15:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "35.185.17.194",
   "country": "United States",
   "cc": "US",
   "city": "North Charleston",
   "lat": 32.8769,
   "lon": -80.0114,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "194.17.185.35.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T00:28:00+02:00",
   "last_seen": "2026-10-03T00:28:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "35.222.122.52",
   "country": "United States",
   "cc": "US",
   "city": "Council Bluffs",
   "lat": 41.2619,
   "lon": -95.8608,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "52.122.222.35.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T23:46:00+02:00",
   "last_seen": "2026-10-02T23:46:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-05"
   ]
  },
  {
   "ip": "35.225.6.63",
   "country": "United States",
   "cc": "US",
   "city": "Council Bluffs",
   "lat": 41.2619,
   "lon": -95.8608,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "63.6.225.35.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T23:07:00+02:00",
   "last_seen": "2026-10-02T23:07:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "37.120.213.13",
   "country": "Switzerland",
   "cc": "CH",
   "city": "Zurich",
   "lat": 47.3667,
   "lon": 8.55,
   "asn": 9009,
   "org": "M247 Europe SRL",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T20:28:00+02:00",
   "last_seen": "2026-10-02T20:28:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "43.136.79.172",
   "country": "China",
   "cc": "CN",
   "city": "Guangzhou",
   "lat": 23.1291,
   "lon": 113.264,
   "asn": 45090,
   "org": "Shenzhen Tencent Computer Systems Company Limited",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T05:09:00+02:00",
   "last_seen": "2026-10-03T05:09:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "43.157.211.165",
   "country": "Indonesia",
   "cc": "ID",
   "city": "Jakarta",
   "lat": -6.20876,
   "lon": 106.846,
   "asn": 132203,
   "org": "Shenzhen Tencent Computer Systems Company Limited",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T01:12:00+02:00",
   "last_seen": "2026-10-03T01:12:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "45.138.12.10",
   "country": "Hong Kong",
   "cc": "HK",
   "city": "Sheung Wan",
   "lat": 22.286,
   "lon": 114.152,
   "asn": 218785,
   "org": "TC DATACENTER LIMITED",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T19:07:00+02:00",
   "last_seen": "2026-10-02T19:07:00+02:00",
   "sensors": [
    "web-1"
   ],
   "notes": [],
   "tags": [
    "abuse-prone-hosting",
    "repeat-offender",
    "cluster:45.138.12.0/24",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "AS218785 TC DATACENTER (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "7 addresses from 45.138.12.0/24 (AS218785) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "45.138.12.6",
   "country": "Hong Kong",
   "cc": "HK",
   "city": "Sheung Wan",
   "lat": 22.286,
   "lon": 114.152,
   "asn": 218785,
   "org": "TC DATACENTER LIMITED",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T04:38:00+02:00",
   "last_seen": "2026-10-03T04:38:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "abuse-prone-hosting",
    "cluster:45.138.12.0/24",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "AS218785 TC DATACENTER (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "7 addresses from 45.138.12.0/24 (AS218785) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "45.138.12.9",
   "country": "Hong Kong",
   "cc": "HK",
   "city": "Sheung Wan",
   "lat": 22.286,
   "lon": 114.152,
   "asn": 218785,
   "org": "TC DATACENTER LIMITED",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T19:48:00+02:00",
   "last_seen": "2026-10-02T19:48:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "abuse-prone-hosting",
    "cluster:45.138.12.0/24",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "AS218785 TC DATACENTER (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "7 addresses from 45.138.12.0/24 (AS218785) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-05"
   ]
  },
  {
   "ip": "45.148.10.8",
   "country": "Andorra",
   "cc": "AD",
   "city": "Andorra la Vella",
   "lat": 42.5063,
   "lon": 1.52184,
   "asn": 48090,
   "org": "TECHOFF SRV LIMITED",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T02:28:00+02:00",
   "last_seen": "2026-10-03T02:28:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "abuse-prone-hosting"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "AS48090 TECHOFF SRV (abuse-prone hosting)",
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "54.94.85.181",
   "country": "Brazil",
   "cc": "BR",
   "city": "S\u00e3o Paulo",
   "lat": -23.5558,
   "lon": -46.6396,
   "asn": 16509,
   "org": "Amazon.com, Inc.",
   "ptr": "ec2-54-94-85-181.sa-east-1.compute.amazonaws.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T19:39:00+02:00",
   "last_seen": "2026-10-02T19:39:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-06"
   ]
  },
  {
   "ip": "68.69.177.112",
   "country": "United States",
   "cc": "US",
   "city": "Hollis",
   "lat": 42.7425,
   "lon": -71.5895,
   "asn": 402226,
   "org": "OnlyScans LLC",
   "ptr": "d5f757a6.scanners.onlyscans.net",
   "types": [
    "attack-tool"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T04:48:00+02:00",
   "last_seen": "2026-10-03T04:48:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "research-scanner",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "medium",
    "evidence": [
     "reverse DNS d5f757a6.scanners.onlyscans.net"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "71.62.11.39",
   "country": "United States",
   "cc": "US",
   "city": "Charlottesville",
   "lat": 38.0293,
   "lon": -78.4767,
   "asn": 7922,
   "org": "Comcast Cable Communications, LLC",
   "ptr": "c-71-62-11-39.hsd1.va.comcast.net",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T01:27:00+02:00",
   "last_seen": "2026-10-03T01:27:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "81.171.72.135",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Haarlem (Oude Stad)",
   "lat": 52.3894,
   "lon": 4.63245,
   "asn": 34343,
   "org": "Eweka Internet Services B.V.",
   "ptr": null,
   "types": [
    "credential-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-02T22:34:00+02:00",
   "last_seen": "2026-10-02T22:34:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-05",
    "2026-10-07"
   ]
  },
  {
   "ip": "91.92.241.196",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Amsterdam",
   "lat": 52.3734,
   "lon": 4.89406,
   "asn": 202412,
   "org": "Omegatech LTD",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-03T02:11:00+02:00",
   "last_seen": "2026-10-03T02:11:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "172.202.106.156",
   "country": "United States",
   "cc": "US",
   "city": "Des Moines",
   "lat": 41.5868,
   "lon": -93.625,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "attack-tool"
   ],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": null,
   "first_seen": "2026-10-02T19:19:00+02:00",
   "last_seen": "2026-10-02T19:19:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [
    "/owa/auth/logon.aspx"
   ],
   "actor": {
    "label": "Automated attack tool",
    "confidence": "low",
    "evidence": [
     "request carried a known attack-tool user agent"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "20.80.111.73",
   "country": "United States",
   "cc": "US",
   "city": "Des Moines",
   "lat": 41.5868,
   "lon": -93.625,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "attack-tool"
   ],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": null,
   "first_seen": "2026-10-02T20:16:00+02:00",
   "last_seen": "2026-10-02T20:16:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "multi-night"
   ],
   "paths": [
    "/"
   ],
   "actor": {
    "label": "Automated attack tool",
    "confidence": "low",
    "evidence": [
     "request carried a known attack-tool user agent"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-06"
   ]
  },
  {
   "ip": "34.19.75.177",
   "country": "United States",
   "cc": "US",
   "city": "The Dalles",
   "lat": 45.6018,
   "lon": -121.185,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "177.75.19.34.bc.googleusercontent.com",
   "types": [
    "path-traversal"
   ],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": null,
   "first_seen": "2026-10-03T00:01:00+02:00",
   "last_seen": "2026-10-03T00:01:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [
    "/[@]fs/proc/self/environ?import&raw??",
    "/_image?href=/../../../.env"
   ],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-03"
   ]
  },
  {
   "ip": "96.126.130.210",
   "country": "Japan",
   "cc": "JP",
   "city": "Osaka",
   "lat": 34.6954,
   "lon": 135.491,
   "asn": 149440,
   "org": "Evoxt Sdn. Bhd.",
   "ptr": "96-126-130-210.aceips.com",
   "types": [
    "secret-probe"
   ],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": null,
   "first_seen": "2026-10-02T18:02:00+02:00",
   "last_seen": "2026-10-02T18:02:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "multi-night"
   ],
   "paths": [
    "/.env"
   ],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-04"
   ]
  }
 ],
 "iocs": [],
 "actors": [
  {
   "label": "Suspected credential/secret-harvesting campaign",
   "confidence": "medium",
   "addresses": 32,
   "ips": [
    "45.138.12.25",
    "91.148.244.131",
    "209.99.185.60",
    "45.156.87.186",
    "45.138.12.53",
    "170.64.197.162",
    "134.199.157.29",
    "134.199.164.71",
    "159.223.180.252",
    "159.89.98.12",
    "170.64.131.170",
    "170.64.214.139",
    "172.86.81.110",
    "195.178.110.106",
    "195.178.110.28",
    "34.12.94.35",
    "34.178.138.173",
    "34.21.135.165",
    "34.23.78.56",
    "35.185.17.194",
    "35.222.122.52",
    "35.225.6.63",
    "45.138.12.10",
    "45.138.12.6",
    "45.138.12.9",
    "45.148.10.8",
    "54.94.85.181",
    "71.62.11.39",
    "81.171.72.135",
    "91.92.241.196",
    "34.19.75.177",
    "96.126.130.210"
   ],
   "top_countries": {
    "US": 8,
    "NL": 6,
    "HK": 5,
    "AU": 5,
    "AD": 3
   },
   "types": {
    "secret-probe": 29,
    "credential-probe": 5,
    "php-probe": 1,
    "path-traversal": 1
   },
   "evidence": [
    "hunts for .env, VCS or credential files",
    "listed on Spamhaus DROP",
    "listed on FireHOL level 1",
    "AS218785 TC DATACENTER (abuse-prone hosting)",
    "7 addresses from 45.138.12.0/24 (AS218785) attacked the same night",
    "AS48090 TECHOFF SRV (abuse-prone hosting)"
   ]
  },
  {
   "label": "CDN edge relaying an attack (true origin hidden)",
   "confidence": "high",
   "addresses": 12,
   "ips": [
    "104.23.223.154",
    "104.23.223.8",
    "104.23.239.80",
    "104.28.245.161",
    "162.158.110.254",
    "172.68.194.182",
    "172.68.213.54",
    "172.69.150.71",
    "172.70.240.180",
    "172.70.247.113",
    "172.70.250.57",
    "172.71.15.24"
   ],
   "top_countries": {
    "DE": 7,
    "SE": 2,
    "CZ": 2,
    "EG": 1
   },
   "types": {
    "secret-probe": 12
   },
   "evidence": [
    "AS13335 Cloudflare is a CDN; the real client is behind it"
   ]
  },
  {
   "label": "Suspected CMS exploitation bot",
   "confidence": "medium",
   "addresses": 11,
   "ips": [
    "20.210.186.186",
    "20.198.74.230",
    "27.102.121.33",
    "134.199.175.94",
    "193.36.224.218",
    "193.36.224.245",
    "193.36.224.249",
    "194.61.40.98",
    "31.171.130.110",
    "31.171.130.154",
    "31.171.130.160"
   ],
   "top_countries": {
    "US": 3,
    "GB": 3,
    "IN": 2,
    "JP": 1,
    "KR": 1
   },
   "types": {
    "cms-probe": 9,
    "php-probe": 2
   },
   "evidence": [
    "CMS, admin panel or PHP script probing",
    "3 addresses from 193.36.224.0/24 (AS206092) attacked the same night",
    "3 addresses from 31.171.130.0/24 (AS206092) attacked the same night"
   ]
  },
  {
   "label": "Internet research scanner (benign)",
   "confidence": "high",
   "addresses": 5,
   "ips": [
    "128.199.182.152",
    "164.90.228.79",
    "184.105.139.69",
    "206.81.12.187",
    "68.69.177.112"
   ],
   "top_countries": {
    "US": 3,
    "SG": 1,
    "DE": 1
   },
   "types": {
    "secret-probe": 4,
    "attack-tool": 1
   },
   "evidence": [
    "reverse DNS cdffb2c5b1.scan.leakix.org",
    "reverse DNS fee8d5bfdc.scan.leakix.org",
    "reverse DNS scan-03.shadowserver.io",
    "reverse DNS bf99e5305e.scan.leakix.org",
    "reverse DNS d5f757a6.scanners.onlyscans.net"
   ]
  },
  {
   "label": "Suspected exploit/RCE bot",
   "confidence": "low",
   "addresses": 5,
   "ips": [
    "138.201.135.150",
    "209.141.51.90",
    "37.120.213.13",
    "43.136.79.172",
    "43.157.211.165"
   ],
   "top_countries": {
    "DE": 1,
    "US": 1,
    "CH": 1,
    "CN": 1,
    "ID": 1
   },
   "types": {
    "rce-payload": 5
   },
   "evidence": [
    "sent a shell or PHP payload"
   ]
  },
  {
   "label": "Unattributed automated probe",
   "confidence": "low",
   "addresses": 4,
   "ips": [
    "35.229.36.226",
    "167.250.224.25",
    "152.42.141.52",
    "167.71.105.201"
   ],
   "top_countries": {
    "US": 2,
    "BR": 1,
    "NL": 1
   },
   "types": {},
   "evidence": []
  },
  {
   "label": "Known-bad scanning infrastructure",
   "confidence": "medium",
   "addresses": 4,
   "ips": [
    "45.138.12.43",
    "45.138.12.45",
    "185.19.40.62",
    "203.159.90.72"
   ],
   "top_countries": {
    "HK": 2,
    "DE": 1,
    "NL": 1
   },
   "types": {
    "cms-probe": 3
   },
   "evidence": [
    "AS218785 TC DATACENTER (abuse-prone hosting)",
    "7 addresses from 45.138.12.0/24 (AS218785) attacked the same night",
    "listed on Spamhaus DROP",
    "listed on FireHOL level 1"
   ]
  },
  {
   "label": "Automated attack tool",
   "confidence": "low",
   "addresses": 3,
   "ips": [
    "20.65.202.209",
    "172.202.106.156",
    "20.80.111.73"
   ],
   "top_countries": {
    "US": 3
   },
   "types": {
    "attack-tool": 3
   },
   "evidence": [
    "request carried a known attack-tool user agent"
   ]
  },
  {
   "label": "Suspected Androxgh0st-style Laravel/PHPUnit exploitation",
   "confidence": "low",
   "addresses": 2,
   "ips": [
    "170.64.182.167",
    "170.64.196.141"
   ],
   "top_countries": {
    "AU": 2
   },
   "types": {
    "secret-probe": 2,
    "rce-payload": 2,
    "cms-probe": 1
   },
   "evidence": [
    "probes PHPUnit eval-stdin.php (CVE-2017-9841), a technique documented in CISA AA24-016A",
    "no request bodies are logged, so the malware family cannot be confirmed"
   ]
  },
  {
   "label": "Suspected Mirai-style IoT botnet",
   "confidence": "medium",
   "addresses": 2,
   "ips": [
    "103.216.170.129",
    "14.117.192.81"
   ],
   "top_countries": {
    "IN": 1,
    "CN": 1
   },
   "types": {
    "rce-payload": 2
   },
   "evidence": [
    "IoT/router exploit path with a downloader typical of Mirai-family loaders"
   ]
  }
 ],
 "banned_identifiers": {
  "ip_addresses": 71,
  "ban_actions": 76,
  "email_addresses": 0,
  "other": 0,
  "note": "The WAF bans network addresses only; no e-mail or account identifiers appear in the source."
 }
}