{
  "Event": {
    "analysis": "1",
    "date": "2026-03-26",
    "extends_uuid": "",
    "info": "KRVTZ-NET IDS alerts for 2026-03-26",
    "publish_timestamp": "1774556226",
    "published": true,
    "threat_level_id": "3",
    "timestamp": "1774556226",
    "uuid": "dfb24218-0b28-4a3f-9947-2b4bf68f7768",
    "Orgc": {
      "name": "Krawczyk Industries Limited",
      "uuid": "593e9fc8-be28-4cb2-a79b-43f8950d210f"
    },
    "Tag": [
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#00ce5f",
        "local": false,
        "name": "misp:event-type=\"observation\"",
        "relationship_type": ""
      },
      {
        "colour": "#50003a",
        "local": false,
        "name": "kill-chain:Reconnaissance",
        "relationship_type": ""
      },
      {
        "colour": "#009042",
        "local": false,
        "name": "misp:automation-level=\"unsupervised\"",
        "relationship_type": ""
      },
      {
        "colour": "#edbfa2",
        "local": false,
        "name": "type:OSINT', 'osint:lifetime=\"perpetual\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "Network activity",
        "comment": "ET WEB_SPECIFIC_APPS Joolma Simple File Upload Plugin Remote Code Execution (CVE-2011-5148)",
        "deleted": false,
        "disable_correlation": false,
        "last_seen": "2026-03-26T04:39:37.096332+00:00",
        "timestamp": "1774499978",
        "to_ids": true,
        "type": "ip-src",
        "uuid": "bff6c785-bf2b-430e-a69e-887d7b79db00",
        "value": "20.219.0.216",
        "Tag": [
          {
            "colour": "#00833c",
            "local": false,
            "name": "misp:threat-level=\"medium-risk\"",
            "relationship_type": ""
          },
          {
            "colour": "#a80079",
            "local": false,
            "name": "kill-chain:Exploitation",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "ET EXPLOIT Fortigate VPN - Repeated GET Requests to /remote/logincheck (CVE-2023-27997)",
        "deleted": false,
        "disable_correlation": false,
        "last_seen": "2026-03-26T05:38:13.273061+00:00",
        "timestamp": "1774503494",
        "to_ids": true,
        "type": "ip-src",
        "uuid": "17cb40e9-b011-471c-bf3f-94e68cdd9040",
        "value": "2001:470:2cc:1::25f",
        "Tag": [
          {
            "colour": "#008a3f",
            "local": false,
            "name": "misp:threat-level=\"high-risk\"",
            "relationship_type": ""
          },
          {
            "colour": "#a80079",
            "local": false,
            "name": "kill-chain:Exploitation",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "ET WEB_SPECIFIC_APPS Joolma Simple File Upload Plugin Remote Code Execution (CVE-2011-5148)",
        "deleted": false,
        "disable_correlation": false,
        "last_seen": "2026-03-26T10:24:01.192936+00:00",
        "timestamp": "1774520642",
        "to_ids": true,
        "type": "ip-src",
        "uuid": "083a15da-128d-423c-9afc-79c303c5de06",
        "value": "20.212.32.151",
        "Tag": [
          {
            "colour": "#00833c",
            "local": false,
            "name": "misp:threat-level=\"medium-risk\"",
            "relationship_type": ""
          },
          {
            "colour": "#a80079",
            "local": false,
            "name": "kill-chain:Exploitation",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "ET SCAN WordPress Scanner Performing Multiple Requests to Windows Live Writer XML",
        "deleted": false,
        "disable_correlation": false,
        "last_seen": "2026-03-26T11:11:20.543983+00:00",
        "timestamp": "1774523482",
        "to_ids": true,
        "type": "ip-src",
        "uuid": "4ed1ee7a-1b8c-435a-852e-f029fe7e245e",
        "value": "45.149.173.217",
        "Tag": [
          {
            "colour": "#00833c",
            "local": false,
            "name": "misp:threat-level=\"medium-risk\"",
            "relationship_type": ""
          },
          {
            "colour": "#a80079",
            "local": false,
            "name": "kill-chain:Exploitation",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "ET WEB_SPECIFIC_APPS Joolma Simple File Upload Plugin Remote Code Execution (CVE-2011-5148)",
        "deleted": false,
        "disable_correlation": false,
        "last_seen": "2026-03-26T20:17:03.684862+00:00",
        "timestamp": "1774556226",
        "to_ids": true,
        "type": "ip-src",
        "uuid": "bece861d-271b-4fe8-930c-d9c31112f4c5",
        "value": "20.151.201.236",
        "Tag": [
          {
            "colour": "#00833c",
            "local": false,
            "name": "misp:threat-level=\"medium-risk\"",
            "relationship_type": ""
          },
          {
            "colour": "#a80079",
            "local": false,
            "name": "kill-chain:Exploitation",
            "relationship_type": ""
          }
        ]
      }
    ]
  }
}