{"valid":true,"found":true,"anonymizedPreview":false,"noindex":false,"ipAddress":"67.209.176.50","identifiedIncidents":0,"indicator":{"id":"cmqmntzif032zlopviwwuf8c4","value":"67.209.176.50","publicSlug":"ip/67.209.176.50","verdict":"threat actor or compromised host","threatLevel":"HIGH","confidence":85,"status":"ACTIVE","suggestedAction":"Temporary Block","firstSeenAt":"2026-06-20T17:57:16.935Z","lastSeenAt":"2026-06-20T17:57:16.915Z","recentWindow":"1 hour","countryCode":null,"countryName":null,"asn":null,"organization":null,"sourceCount":1,"tenantCount":1,"summary":"Source interacted with a Sotiras honeypot decoy. Any contact with a decoy that advertises no legitimate service is unsolicited and treated as malicious.","correctionNote":null,"reviewAfter":"2026-07-04T17:57:16.915Z"},"sourceMix":["HONEYPOT"],"behaviorCategories":["active-aggressors"],"confidenceReasons":["High confidence score from approved Sotiras evidence.","Behavior includes active-aggressors.","Suggested action is Temporary Block.","High threat level after scoring."],"sharedNetwork":{"classification":"unknown","label":"Unknown shared-network context","likelihood":"LOW","score":0,"reasons":["Sotiras has observation evidence, but not enough network context to classify this as shared infrastructure."],"recommendedResponse":"Observe, enrich, and collect more tenant evidence before taking enforcement action.","caveat":"Shared-network classification shapes response; tenant-observed behavior still drives enforcement."},"scores":{"aggressiveness":92,"backgroundNoise":37},"activityTimeline":[{"date":"2026-06-20","observations":1}],"blocklists":[{"key":"active-aggressors","label":"Active aggressors"}],"topSources":[{"label":"Honeypot","count":1}],"topEvents":[{"label":"HTTP probing","count":1}],"topPorts":[{"label":"80/tcp","count":1}],"topSourceCountries":[],"targetedServices":[{"label":"web-route-trap","count":1}],"subnet":{"cidr":"67.209.176.0/24","relatedPublishedIndicators":1}}