{
  "Event": {
    "analysis": "1",
    "date": "2026-02-01",
    "extends_uuid": "",
    "info": "KRVTZ-NET IDS alerts for 2026-02-01",
    "publish_timestamp": "1769983549",
    "published": true,
    "threat_level_id": "3",
    "timestamp": "1769983548",
    "uuid": "48f1499f-4919-497d-b770-4055b0b71795",
    "Orgc": {
      "name": "Krawczyk Industries Limited",
      "uuid": "593e9fc8-be28-4cb2-a79b-43f8950d210f"
    },
    "Tag": [
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#00ce5f",
        "local": false,
        "name": "misp:event-type=\"observation\"",
        "relationship_type": ""
      },
      {
        "colour": "#50003a",
        "local": false,
        "name": "kill-chain:Reconnaissance",
        "relationship_type": ""
      },
      {
        "colour": "#009042",
        "local": false,
        "name": "misp:automation-level=\"unsupervised\"",
        "relationship_type": ""
      },
      {
        "colour": "#edbfa2",
        "local": false,
        "name": "type:OSINT', 'osint:lifetime=\"perpetual\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "Network activity",
        "comment": "ET EXPLOIT Fortigate VPN - Repeated GET Requests to /remote/logincheck (CVE-2023-27997)",
        "deleted": false,
        "disable_correlation": false,
        "last_seen": "2026-02-01T02:11:19.978512+00:00",
        "timestamp": "1769911881",
        "to_ids": true,
        "type": "ip-src",
        "uuid": "20ac68ca-df6e-4e57-b12c-064d9bf23ff3",
        "value": "2001:470:1:fb5:199c:a492:95cd:399c",
        "Tag": [
          {
            "colour": "#008a3f",
            "local": false,
            "name": "misp:threat-level=\"high-risk\"",
            "relationship_type": ""
          },
          {
            "colour": "#a80079",
            "local": false,
            "name": "kill-chain:Exploitation",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "ET INFO Request to Hidden Environment File - Inbound",
        "deleted": false,
        "disable_correlation": false,
        "last_seen": "2026-02-01T03:06:07.708785+00:00",
        "timestamp": "1769915169",
        "to_ids": true,
        "type": "ip-src",
        "uuid": "40156d0b-a6a4-4ad3-bf78-2a95eb0174d9",
        "value": "45.155.68.149",
        "Tag": [
          {
            "colour": "#00833c",
            "local": false,
            "name": "misp:threat-level=\"medium-risk\"",
            "relationship_type": ""
          },
          {
            "colour": "#a80079",
            "local": false,
            "name": "kill-chain:Exploitation",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "ET EXPLOIT Fortigate VPN - Repeated GET Requests to /remote/logincheck (CVE-2023-27997)",
        "deleted": false,
        "disable_correlation": false,
        "last_seen": "2026-02-01T03:33:30.941855+00:00",
        "timestamp": "1769916812",
        "to_ids": true,
        "type": "ip-src",
        "uuid": "f4830abb-5773-4d6a-b2ab-5b6c9fb25a4b",
        "value": "2001:470:1:fb5:6ae2:a7b6:537e:b854",
        "Tag": [
          {
            "colour": "#008a3f",
            "local": false,
            "name": "misp:threat-level=\"high-risk\"",
            "relationship_type": ""
          },
          {
            "colour": "#a80079",
            "local": false,
            "name": "kill-chain:Exploitation",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "ET SCAN Web Scanner - Fuzz Faster U Fool (Inbound)",
        "deleted": false,
        "disable_correlation": false,
        "last_seen": "2026-02-01T08:05:21.923967+00:00",
        "timestamp": "1769933123",
        "to_ids": true,
        "type": "ip-src",
        "uuid": "0d52b3b8-179c-4cf8-95a8-0f6add2e6518",
        "value": "103.58.75.88",
        "Tag": [
          {
            "colour": "#00833c",
            "local": false,
            "name": "misp:threat-level=\"medium-risk\"",
            "relationship_type": ""
          },
          {
            "colour": "#a80079",
            "local": false,
            "name": "kill-chain:Exploitation",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "- i Censys - HTTP User-Agent Scanner",
        "deleted": false,
        "disable_correlation": false,
        "last_seen": "2026-02-01T11:21:44.251667+00:00",
        "timestamp": "1769944906",
        "to_ids": true,
        "type": "ip-src",
        "uuid": "2ce5d684-59a5-4de4-9d69-c0b77b83c5b9",
        "value": "199.45.154.130",
        "Tag": [
          {
            "colour": "#00833c",
            "local": false,
            "name": "misp:threat-level=\"medium-risk\"",
            "relationship_type": ""
          },
          {
            "colour": "#a80079",
            "local": false,
            "name": "kill-chain:Exploitation",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "ET INFO Request to Hidden Environment File - Inbound",
        "deleted": false,
        "disable_correlation": false,
        "last_seen": "2026-02-01T18:58:34.444065+00:00",
        "timestamp": "1769972316",
        "to_ids": true,
        "type": "ip-src",
        "uuid": "cbc1aa84-1886-450a-b4c3-62f9a2a298d8",
        "value": "34.97.110.4",
        "Tag": [
          {
            "colour": "#00833c",
            "local": false,
            "name": "misp:threat-level=\"medium-risk\"",
            "relationship_type": ""
          },
          {
            "colour": "#a80079",
            "local": false,
            "name": "kill-chain:Exploitation",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "ET INFO Request to Hidden Environment File - Inbound",
        "deleted": false,
        "disable_correlation": false,
        "last_seen": "2026-02-01T21:55:43.223097+00:00",
        "timestamp": "1769982944",
        "to_ids": true,
        "type": "ip-src",
        "uuid": "b963ac45-9c50-4b96-bc6f-bfd370661a9f",
        "value": "168.110.202.196",
        "Tag": [
          {
            "colour": "#00833c",
            "local": false,
            "name": "misp:threat-level=\"medium-risk\"",
            "relationship_type": ""
          },
          {
            "colour": "#a80079",
            "local": false,
            "name": "kill-chain:Exploitation",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "- i Censys - HTTP User-Agent Scanner",
        "deleted": false,
        "disable_correlation": false,
        "last_seen": "2026-02-01T22:05:47.023876+00:00",
        "timestamp": "1769983548",
        "to_ids": true,
        "type": "ip-src",
        "uuid": "1c49ab17-74b2-4b71-b6fa-ad84ec3fdb9c",
        "value": "167.94.138.36",
        "Tag": [
          {
            "colour": "#00833c",
            "local": false,
            "name": "misp:threat-level=\"medium-risk\"",
            "relationship_type": ""
          },
          {
            "colour": "#a80079",
            "local": false,
            "name": "kill-chain:Exploitation",
            "relationship_type": ""
          }
        ]
      }
    ]
  }
}