diff options
| author | hrbrmstr <bob@rud.is> | 2026-08-31 07:56:38 -0400 |
|---|---|---|
| committer | hrbrmstr <bob@rud.is> | 2026-08-31 07:56:38 -0400 |
| commit | e93e7f67d4f70177c3ab5a34e8cc5b24fa2dde6d (patch) | |
| tree | e02486c0af8f5f8bf64600f0a1a2b4904c4c123a /kevlar/2026-08-31/honeylabs/ioc-::ffff:107.189.26.103.json | |
| parent | 1d9b78adfc083d1120c55e403e6b3d6317a1171f (diff) | |
add: bph report iocs
Diffstat (limited to 'kevlar/2026-08-31/honeylabs/ioc-::ffff:107.189.26.103.json')
| -rw-r--r-- | kevlar/2026-08-31/honeylabs/ioc-::ffff:107.189.26.103.json | 72 |
1 files changed, 72 insertions, 0 deletions
diff --git a/kevlar/2026-08-31/honeylabs/ioc-::ffff:107.189.26.103.json b/kevlar/2026-08-31/honeylabs/ioc-::ffff:107.189.26.103.json new file mode 100644 index 0000000..b60ba3d --- /dev/null +++ b/kevlar/2026-08-31/honeylabs/ioc-::ffff:107.189.26.103.json @@ -0,0 +1,72 @@ +{ + "total_events": 148, + "first_seen": "2026-08-20T14:44:13", + "last_seen": "2026-08-25T23:21:07", + "asn_number": 14956, + "asn_org": "RouterHosting LLC", + "country_name": "The Netherlands", + "country_code": "NL", + "ports_targeted": [ + 80, + 2375 + ], + "ports_targeted_count": 2, + "tls_event_count": 0, + "top_http_methods": [ + "GET", + "POST" + ], + "top_user_agents": [ + "libredtail-http" + ], + "top_url_paths": [ + "/containers/json", + "/crm/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php", + "/cms/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php", + "/demo/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php", + "/ws/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php", + "/testing/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php", + "/test/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php", + "/api/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php", + "/zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php", + "/tests/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" + ], + "top_ja4_fingerprints": [], + "top_ja3_fingerprints": [], + "top_hassh_fingerprints": [], + "client_cert_event_count": 0, + "client_cert_subjects": [], + "rdns": "103.26.189.107.static.cloudzy.com", + "loader_hits": 6, + "exploit_hits": 135, + "bytes_sent": 1826936, + "unique_source_ips": 1, + "ioc": "::ffff:107.189.26.103", + "window": "all retained data (no time filter)", + "query_type": "ip", + "scanner": null, + "verdict_key": "malicious", + "verdict": "Exploit attempts observed", + "verdict_why": [ + "135 request(s) matched a known exploit path.", + "Exploit-path hits present; HTTP verb mix unknown, so read cautiously.", + "5+ hits raise confidence to high.", + "Not in any known-scanner range.", + "Sent 1,826,936 bytes: sustained payload delivery, not a single opportunistic request." + ], + "verdict_confidence": "high", + "cve_probes": [ + { + "cve_id": "CVE-2017-9841", + "title": "PHPUnit - Remote Code Execution", + "severity": "critical", + "actively_exploited": true + }, + { + "cve_id": "CVE-2021-42013", + "title": "Apache 2.4.49/2.4.50 - Path Traversal and Remote Code Execution", + "severity": "critical", + "actively_exploited": true + } + ] +}
\ No newline at end of file |
