aboutsummaryrefslogtreecommitdiff
path: root/kevlar/2026-09-07/honeylabs/ioc-lookups.json
diff options
context:
space:
mode:
authorhrbrmstr <bob@rud.is>2026-09-07 06:03:32 -0400
committerhrbrmstr <bob@rud.is>2026-09-07 06:23:41 -0400
commitde4c2e99a969eb10708b02d8f2b6f31495eacce8 (patch)
treeff5be97683e9dbf19ec0387f3a03a90282477dd2 /kevlar/2026-09-07/honeylabs/ioc-lookups.json
parentc283bcc507b0a7946a8660677a04da6f53cc77e1 (diff)
chore: weekly BPH updateHEADmain
Diffstat (limited to 'kevlar/2026-09-07/honeylabs/ioc-lookups.json')
-rw-r--r--kevlar/2026-09-07/honeylabs/ioc-lookups.json1175
1 files changed, 1175 insertions, 0 deletions
diff --git a/kevlar/2026-09-07/honeylabs/ioc-lookups.json b/kevlar/2026-09-07/honeylabs/ioc-lookups.json
new file mode 100644
index 0000000..252b936
--- /dev/null
+++ b/kevlar/2026-09-07/honeylabs/ioc-lookups.json
@@ -0,0 +1,1175 @@
+[
+ {
+ "asn": "AS57043",
+ "name": "HOSTKEY-AS",
+ "ip": "163.5.16.6",
+ "event_count": 8,
+ "lookup": {
+ "total_events": 8,
+ "first_seen": "2026-09-02T21:02:40",
+ "last_seen": "2026-09-02T21:19:46",
+ "asn_number": 57043,
+ "asn_org": "Hostkey B.v.",
+ "country_name": "United Kingdom",
+ "country_code": "GB",
+ "ports_targeted": [
+ 19571,
+ 42481,
+ 5070,
+ 14603,
+ 44981,
+ 20271
+ ],
+ "ports_targeted_count": 6,
+ "tls_event_count": 0,
+ "top_http_methods": [],
+ "top_user_agents": [],
+ "top_url_paths": [],
+ "top_ja4_fingerprints": [],
+ "top_ja3_fingerprints": [],
+ "top_hassh_fingerprints": [],
+ "client_cert_event_count": 0,
+ "client_cert_subjects": [],
+ "rdns": "",
+ "loader_hits": 0,
+ "exploit_hits": 0,
+ "bytes_sent": 152,
+ "unique_source_ips": 1,
+ "ioc": "163.5.16.6",
+ "window": "last 7 days",
+ "query_type": "ip",
+ "scanner": null,
+ "verdict_key": "probing",
+ "verdict": "Low-level probing",
+ "verdict_why": [
+ "8 event(s), fewer than 10 distinct ports, no exploit payloads.",
+ "Not in any known-scanner range."
+ ],
+ "verdict_confidence": "low",
+ "cve_probes": []
+ }
+ },
+ {
+ "asn": "AS57043",
+ "name": "HOSTKEY-AS",
+ "ip": "82.39.165.100",
+ "event_count": 4,
+ "lookup": {
+ "total_events": 4,
+ "first_seen": "2026-08-31T15:39:39",
+ "last_seen": "2026-09-03T03:47:57",
+ "asn_number": 57043,
+ "asn_org": "Hostkey B.v.",
+ "country_name": "Germany",
+ "country_code": "DE",
+ "ports_targeted": [
+ 22
+ ],
+ "ports_targeted_count": 1,
+ "tls_event_count": 0,
+ "top_http_methods": [],
+ "top_user_agents": [],
+ "top_url_paths": [],
+ "top_ja4_fingerprints": [],
+ "top_ja3_fingerprints": [],
+ "top_hassh_fingerprints": [
+ "98ddc5604ef6a1006a2b49a58759fbe6"
+ ],
+ "client_cert_event_count": 0,
+ "client_cert_subjects": [],
+ "rdns": "",
+ "loader_hits": 0,
+ "exploit_hits": 0,
+ "bytes_sent": 3248,
+ "unique_source_ips": 1,
+ "ioc": "82.39.165.100",
+ "window": "last 7 days",
+ "query_type": "ip",
+ "scanner": null,
+ "verdict_key": "probing",
+ "verdict": "Low-level probing",
+ "verdict_why": [
+ "4 event(s), fewer than 10 distinct ports, no exploit payloads.",
+ "Not in any known-scanner range."
+ ],
+ "verdict_confidence": "low",
+ "cve_probes": []
+ }
+ },
+ {
+ "asn": "AS210644",
+ "name": "AEZA-AS",
+ "ip": "185.246.217.150",
+ "event_count": 51,
+ "lookup": {
+ "total_events": 51,
+ "first_seen": "2026-08-31T22:44:34",
+ "last_seen": "2026-09-02T15:29:27",
+ "asn_number": 210644,
+ "asn_org": "Aeza Group LLC",
+ "country_name": "The Netherlands",
+ "country_code": "NL",
+ "ports_targeted": [
+ 443,
+ 2222,
+ 2375
+ ],
+ "ports_targeted_count": 3,
+ "tls_event_count": 49,
+ "top_http_methods": [
+ "GET",
+ "POST"
+ ],
+ "top_user_agents": [
+ "libredtail-http"
+ ],
+ "top_url_paths": [
+ "/containers/json",
+ "/crm/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
+ "/cms/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
+ "/demo/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
+ "/yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
+ "/api/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
+ "/testing/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
+ "/ws/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
+ "/ws/ec/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
+ "/test/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"
+ ],
+ "top_ja4_fingerprints": [
+ "t13i170900_5b57614c22b0_78e6aca7449b"
+ ],
+ "top_ja3_fingerprints": [
+ "052a5e65c3a64e860e1706b1de3c46a9"
+ ],
+ "top_hassh_fingerprints": [
+ "19532158b559096b89b1a5f7d17175b2"
+ ],
+ "client_cert_event_count": 0,
+ "client_cert_subjects": [],
+ "rdns": "",
+ "loader_hits": 2,
+ "exploit_hits": 45,
+ "bytes_sent": 610617,
+ "unique_source_ips": 1,
+ "ioc": "185.246.217.150",
+ "window": "last 7 days",
+ "query_type": "ip",
+ "scanner": null,
+ "verdict_key": "malicious",
+ "verdict": "Exploit attempts observed",
+ "verdict_why": [
+ "45 request(s) matched a known exploit path.",
+ "Exploit-path hits present; HTTP verb mix unknown, so read cautiously.",
+ "5+ hits raise confidence to high.",
+ "Not in any known-scanner range.",
+ "Sent 610,617 bytes: sustained payload delivery, not a single opportunistic request."
+ ],
+ "verdict_confidence": "high",
+ "cve_probes": [
+ {
+ "cve_id": "CVE-2017-9841",
+ "title": "PHPUnit - Remote Code Execution",
+ "severity": "critical",
+ "actively_exploited": true
+ },
+ {
+ "cve_id": "CVE-2021-42013",
+ "title": "Apache 2.4.49/2.4.50 - Path Traversal and Remote Code Execution",
+ "severity": "critical",
+ "actively_exploited": true
+ }
+ ]
+ }
+ },
+ {
+ "asn": "AS14956",
+ "name": "ROUTERHOSTING",
+ "ip": "45.61.157.82",
+ "event_count": 32,
+ "lookup": {
+ "total_events": 32,
+ "first_seen": "2026-09-04T01:15:12",
+ "last_seen": "2026-09-04T06:30:09",
+ "asn_number": 14956,
+ "asn_org": "RouterHosting LLC",
+ "country_name": "United States",
+ "country_code": "US",
+ "ports_targeted": [
+ 445
+ ],
+ "ports_targeted_count": 1,
+ "tls_event_count": 0,
+ "top_http_methods": [],
+ "top_user_agents": [],
+ "top_url_paths": [],
+ "top_ja4_fingerprints": [],
+ "top_ja3_fingerprints": [],
+ "top_hassh_fingerprints": [],
+ "client_cert_event_count": 0,
+ "client_cert_subjects": [],
+ "rdns": "82.157.61.45.static.cloudzy.com",
+ "loader_hits": 0,
+ "exploit_hits": 0,
+ "bytes_sent": 8684,
+ "unique_source_ips": 1,
+ "ioc": "45.61.157.82",
+ "window": "last 7 days",
+ "query_type": "ip",
+ "scanner": null,
+ "verdict_key": "probing",
+ "verdict": "Low-level probing",
+ "verdict_why": [
+ "32 event(s), fewer than 10 distinct ports, no exploit payloads.",
+ "Not in any known-scanner range.",
+ "Sent 8,684 bytes despite few ports and no known exploit path: focused interaction with one service, worth a look."
+ ],
+ "verdict_confidence": "low",
+ "cve_probes": []
+ }
+ },
+ {
+ "asn": "AS14956",
+ "name": "ROUTERHOSTING",
+ "ip": "144.172.108.79",
+ "event_count": 24,
+ "lookup": {
+ "total_events": 24,
+ "first_seen": "2026-09-04T20:02:59",
+ "last_seen": "2026-09-05T02:54:19",
+ "asn_number": 14956,
+ "asn_org": "RouterHosting LLC",
+ "country_name": "United States",
+ "country_code": "US",
+ "ports_targeted": [
+ 445
+ ],
+ "ports_targeted_count": 1,
+ "tls_event_count": 0,
+ "top_http_methods": [],
+ "top_user_agents": [],
+ "top_url_paths": [],
+ "top_ja4_fingerprints": [],
+ "top_ja3_fingerprints": [],
+ "top_hassh_fingerprints": [],
+ "client_cert_event_count": 0,
+ "client_cert_subjects": [],
+ "rdns": "79.108.172.144.static.cloudzy.com",
+ "loader_hits": 0,
+ "exploit_hits": 0,
+ "bytes_sent": 6513,
+ "unique_source_ips": 1,
+ "ioc": "144.172.108.79",
+ "window": "last 7 days",
+ "query_type": "ip",
+ "scanner": null,
+ "verdict_key": "probing",
+ "verdict": "Low-level probing",
+ "verdict_why": [
+ "24 event(s), fewer than 10 distinct ports, no exploit payloads.",
+ "Not in any known-scanner range.",
+ "Sent 6,513 bytes despite few ports and no known exploit path: focused interaction with one service, worth a look."
+ ],
+ "verdict_confidence": "low",
+ "cve_probes": []
+ }
+ },
+ {
+ "asn": "AS14956",
+ "name": "ROUTERHOSTING",
+ "ip": "144.172.99.200",
+ "event_count": 16,
+ "lookup": {
+ "total_events": 16,
+ "first_seen": "2026-09-01T07:55:37",
+ "last_seen": "2026-09-01T08:57:36",
+ "asn_number": 14956,
+ "asn_org": "RouterHosting LLC",
+ "country_name": "United States",
+ "country_code": "US",
+ "ports_targeted": [
+ 445
+ ],
+ "ports_targeted_count": 1,
+ "tls_event_count": 0,
+ "top_http_methods": [],
+ "top_user_agents": [],
+ "top_url_paths": [],
+ "top_ja4_fingerprints": [],
+ "top_ja3_fingerprints": [],
+ "top_hassh_fingerprints": [],
+ "client_cert_event_count": 0,
+ "client_cert_subjects": [],
+ "rdns": "200.99.172.144.static.cloudzy.com",
+ "loader_hits": 0,
+ "exploit_hits": 0,
+ "bytes_sent": 4342,
+ "unique_source_ips": 1,
+ "ioc": "144.172.99.200",
+ "window": "last 7 days",
+ "query_type": "ip",
+ "scanner": null,
+ "verdict_key": "probing",
+ "verdict": "Low-level probing",
+ "verdict_why": [
+ "16 event(s), fewer than 10 distinct ports, no exploit payloads.",
+ "Not in any known-scanner range.",
+ "Sent 4,342 bytes despite few ports and no known exploit path: focused interaction with one service, worth a look."
+ ],
+ "verdict_confidence": "low",
+ "cve_probes": []
+ }
+ },
+ {
+ "asn": "AS51852",
+ "name": "PLI-AS",
+ "ip": "179.43.150.26",
+ "event_count": 16,
+ "lookup": {
+ "total_events": 16,
+ "first_seen": "2026-08-31T15:32:52",
+ "last_seen": "2026-08-31T16:49:55",
+ "asn_number": 51852,
+ "asn_org": "Private Layer INC",
+ "country_name": "Switzerland",
+ "country_code": "CH",
+ "ports_targeted": [
+ 8443
+ ],
+ "ports_targeted_count": 1,
+ "tls_event_count": 0,
+ "top_http_methods": [
+ "GET"
+ ],
+ "top_user_agents": [
+ "Mozilla/5.0"
+ ],
+ "top_url_paths": [
+ "/.env",
+ "/z1356",
+ "/s/1974",
+ "/.e199",
+ "/z1891",
+ "/s/1688",
+ "/.e3448",
+ "/z945",
+ "/s/7694",
+ "/s/6254"
+ ],
+ "top_ja4_fingerprints": [],
+ "top_ja3_fingerprints": [],
+ "top_hassh_fingerprints": [],
+ "client_cert_event_count": 0,
+ "client_cert_subjects": [],
+ "rdns": "hostedby.privatelayer.com",
+ "loader_hits": 0,
+ "exploit_hits": 4,
+ "bytes_sent": 3470,
+ "unique_source_ips": 1,
+ "ioc": "179.43.150.26",
+ "window": "last 7 days",
+ "query_type": "ip",
+ "scanner": null,
+ "verdict_key": "malicious",
+ "verdict": "Exploit attempts observed",
+ "verdict_why": [
+ "4 request(s) matched a known exploit path.",
+ "Exploit-path hits present; HTTP verb mix unknown, so read cautiously.",
+ "Under 5 hits, so confidence is medium.",
+ "Not in any known-scanner range."
+ ],
+ "verdict_confidence": "medium",
+ "cve_probes": []
+ }
+ },
+ {
+ "asn": "AS51852",
+ "name": "PLI-AS",
+ "ip": "46.19.142.226",
+ "event_count": 6,
+ "lookup": {
+ "total_events": 6,
+ "first_seen": "2026-09-04T18:34:20",
+ "last_seen": "2026-09-04T19:27:10",
+ "asn_number": 51852,
+ "asn_org": "Private Layer INC",
+ "country_name": "Switzerland",
+ "country_code": "CH",
+ "ports_targeted": [
+ 2087
+ ],
+ "ports_targeted_count": 1,
+ "tls_event_count": 6,
+ "top_http_methods": [
+ "GET",
+ "POST"
+ ],
+ "top_user_agents": [
+ "Mozilla/5.0",
+ "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
+ ],
+ "top_url_paths": [
+ "/openid_connect/cpanelid",
+ "/login/?login_only=1"
+ ],
+ "top_ja4_fingerprints": [
+ "t13i190800_9dc949149365_97f8aa674fd9"
+ ],
+ "top_ja3_fingerprints": [
+ "19e29534fd49dd27d09234e639c4057e"
+ ],
+ "top_hassh_fingerprints": [],
+ "client_cert_event_count": 0,
+ "client_cert_subjects": [],
+ "rdns": "hostedby.privatelayer.com",
+ "loader_hits": 0,
+ "exploit_hits": 0,
+ "bytes_sent": 944,
+ "unique_source_ips": 1,
+ "ioc": "46.19.142.226",
+ "window": "last 7 days",
+ "query_type": "ip",
+ "scanner": null,
+ "verdict_key": "probing",
+ "verdict": "Low-level probing",
+ "verdict_why": [
+ "6 event(s), fewer than 10 distinct ports, no exploit payloads.",
+ "Not in any known-scanner range."
+ ],
+ "verdict_confidence": "low",
+ "cve_probes": [
+ {
+ "cve_id": "CVE-2026-41940",
+ "title": "cPanel & WHM - Authentication Bypass via Session-File CRLF Injection",
+ "severity": "CRITICAL",
+ "actively_exploited": true
+ }
+ ]
+ }
+ },
+ {
+ "asn": "AS51852",
+ "name": "PLI-AS",
+ "ip": "141.255.165.66",
+ "event_count": 5,
+ "lookup": {
+ "total_events": 5,
+ "first_seen": "2026-09-03T20:48:30",
+ "last_seen": "2026-09-04T11:46:33",
+ "asn_number": 51852,
+ "asn_org": "Private Layer INC",
+ "country_name": "Switzerland",
+ "country_code": "CH",
+ "ports_targeted": [
+ 1723
+ ],
+ "ports_targeted_count": 1,
+ "tls_event_count": 0,
+ "top_http_methods": [],
+ "top_user_agents": [],
+ "top_url_paths": [],
+ "top_ja4_fingerprints": [],
+ "top_ja3_fingerprints": [],
+ "top_hassh_fingerprints": [],
+ "client_cert_event_count": 0,
+ "client_cert_subjects": [],
+ "rdns": "4soho.com",
+ "loader_hits": 0,
+ "exploit_hits": 0,
+ "bytes_sent": 780,
+ "unique_source_ips": 1,
+ "ioc": "141.255.165.66",
+ "window": "last 7 days",
+ "query_type": "ip",
+ "scanner": null,
+ "verdict_key": "probing",
+ "verdict": "Low-level probing",
+ "verdict_why": [
+ "5 event(s), fewer than 10 distinct ports, no exploit payloads.",
+ "Not in any known-scanner range."
+ ],
+ "verdict_confidence": "low",
+ "cve_probes": []
+ }
+ },
+ {
+ "asn": "AS51396",
+ "name": "PFCLOUD",
+ "ip": "204.76.203.222",
+ "event_count": 1159,
+ "lookup": {
+ "total_events": 1331,
+ "first_seen": "2026-09-02T09:47:23",
+ "last_seen": "2026-09-07T09:45:33",
+ "asn_number": 51396,
+ "asn_org": "Pfcloud UG (haftungsbeschrankt)",
+ "country_name": "The Netherlands",
+ "country_code": "NL",
+ "ports_targeted": [
+ 5151,
+ 10118,
+ 11517,
+ 2222,
+ 10080,
+ 50009,
+ 7375,
+ 52120,
+ 50032,
+ 11004,
+ 11338,
+ 2018,
+ 8004,
+ 11238,
+ 8084,
+ 10803,
+ 6666,
+ 13292,
+ 9000,
+ 6652,
+ 9443,
+ 11148,
+ 5477,
+ 56789,
+ 10165,
+ 30006,
+ 10023,
+ 30011,
+ 10001,
+ 5001,
+ 2026,
+ 11635,
+ 11435,
+ 11409,
+ 2030,
+ 6128,
+ 11415,
+ 6969,
+ 20999,
+ 8095,
+ 9252,
+ 13509,
+ 5212,
+ 8045,
+ 50007,
+ 9054,
+ 12367,
+ 32536,
+ 3389,
+ 9098
+ ],
+ "ports_targeted_count": 879,
+ "tls_event_count": 0,
+ "top_http_methods": [],
+ "top_user_agents": [],
+ "top_url_paths": [],
+ "top_ja4_fingerprints": [],
+ "top_ja3_fingerprints": [],
+ "top_hassh_fingerprints": [],
+ "client_cert_event_count": 0,
+ "client_cert_subjects": [],
+ "rdns": "204.76.203.222.ptr.pfcloud.network",
+ "loader_hits": 0,
+ "exploit_hits": 0,
+ "bytes_sent": 49337,
+ "unique_source_ips": 1,
+ "ioc": "204.76.203.222",
+ "window": "last 7 days",
+ "query_type": "ip",
+ "scanner": null,
+ "verdict_key": "scanning",
+ "verdict": "Unrecognized scanner",
+ "verdict_why": [
+ "No exploit payloads observed.",
+ "Swept 879 distinct ports (threshold for a sweep is 10).",
+ "Not in any known-scanner range."
+ ],
+ "verdict_confidence": "medium",
+ "cve_probes": []
+ }
+ },
+ {
+ "asn": "AS51396",
+ "name": "PFCLOUD",
+ "ip": "204.76.203.221",
+ "event_count": 1154,
+ "lookup": {
+ "total_events": 1332,
+ "first_seen": "2026-09-02T09:47:23",
+ "last_seen": "2026-09-07T09:47:47",
+ "asn_number": 51396,
+ "asn_org": "Pfcloud UG (haftungsbeschrankt)",
+ "country_name": "The Netherlands",
+ "country_code": "NL",
+ "ports_targeted": [
+ 5477,
+ 11617,
+ 11918,
+ 10080,
+ 11587,
+ 10231,
+ 5918,
+ 6588,
+ 11416,
+ 11000,
+ 20898,
+ 5507,
+ 31280,
+ 11181,
+ 9258,
+ 20274,
+ 9040,
+ 20132,
+ 1083,
+ 20621,
+ 11081,
+ 11111,
+ 11528,
+ 20023,
+ 6685,
+ 10031,
+ 20038,
+ 10023,
+ 3129,
+ 50008,
+ 11338,
+ 1080,
+ 10109,
+ 50028,
+ 8225,
+ 10000,
+ 50019,
+ 10157,
+ 9898,
+ 5513,
+ 1058,
+ 9999,
+ 18505,
+ 5108,
+ 10034,
+ 11404,
+ 9422,
+ 8045,
+ 10432,
+ 32260
+ ],
+ "ports_targeted_count": 890,
+ "tls_event_count": 0,
+ "top_http_methods": [],
+ "top_user_agents": [],
+ "top_url_paths": [],
+ "top_ja4_fingerprints": [],
+ "top_ja3_fingerprints": [],
+ "top_hassh_fingerprints": [],
+ "client_cert_event_count": 0,
+ "client_cert_subjects": [],
+ "rdns": "204.76.203.221.ptr.pfcloud.network",
+ "loader_hits": 0,
+ "exploit_hits": 0,
+ "bytes_sent": 47840,
+ "unique_source_ips": 1,
+ "ioc": "204.76.203.221",
+ "window": "last 7 days",
+ "query_type": "ip",
+ "scanner": null,
+ "verdict_key": "scanning",
+ "verdict": "Unrecognized scanner",
+ "verdict_why": [
+ "No exploit payloads observed.",
+ "Swept 890 distinct ports (threshold for a sweep is 10).",
+ "Not in any known-scanner range."
+ ],
+ "verdict_confidence": "medium",
+ "cve_probes": []
+ }
+ },
+ {
+ "asn": "AS51396",
+ "name": "PFCLOUD",
+ "ip": "204.76.203.213",
+ "event_count": 1123,
+ "lookup": {
+ "total_events": 1286,
+ "first_seen": "2026-09-02T09:53:18",
+ "last_seen": "2026-09-07T09:39:49",
+ "asn_number": 51396,
+ "asn_org": "Pfcloud UG (haftungsbeschrankt)",
+ "country_name": "The Netherlands",
+ "country_code": "NL",
+ "ports_targeted": [
+ 11000,
+ 5518,
+ 20009,
+ 5112,
+ 11537,
+ 20035,
+ 11008,
+ 50029,
+ 56789,
+ 31460,
+ 4219,
+ 2028,
+ 3385,
+ 1112,
+ 10027,
+ 10140,
+ 5918,
+ 11918,
+ 10101,
+ 4544,
+ 20104,
+ 10033,
+ 30000,
+ 10109,
+ 10801,
+ 9898,
+ 20390,
+ 8891,
+ 10041,
+ 11322,
+ 10075,
+ 25412,
+ 49532,
+ 34491,
+ 50012,
+ 17891,
+ 50008,
+ 20015,
+ 20248,
+ 11644,
+ 33128,
+ 9002,
+ 1065,
+ 6724,
+ 18080,
+ 10137,
+ 11508,
+ 10821,
+ 20132,
+ 31526
+ ],
+ "ports_targeted_count": 872,
+ "tls_event_count": 0,
+ "top_http_methods": [],
+ "top_user_agents": [],
+ "top_url_paths": [],
+ "top_ja4_fingerprints": [],
+ "top_ja3_fingerprints": [],
+ "top_hassh_fingerprints": [],
+ "client_cert_event_count": 0,
+ "client_cert_subjects": [],
+ "rdns": "204.76.203.213.ptr.pfcloud.network",
+ "loader_hits": 0,
+ "exploit_hits": 0,
+ "bytes_sent": 46038,
+ "unique_source_ips": 1,
+ "ioc": "204.76.203.213",
+ "window": "last 7 days",
+ "query_type": "ip",
+ "scanner": null,
+ "verdict_key": "scanning",
+ "verdict": "Unrecognized scanner",
+ "verdict_why": [
+ "No exploit payloads observed.",
+ "Swept 872 distinct ports (threshold for a sweep is 10).",
+ "Not in any known-scanner range."
+ ],
+ "verdict_confidence": "medium",
+ "cve_probes": []
+ }
+ },
+ {
+ "asn": "AS216246",
+ "name": "RU-AEZA-AS",
+ "ip": "176.124.222.61",
+ "event_count": 1,
+ "lookup": {
+ "total_events": 1,
+ "first_seen": "2026-08-31T13:15:24",
+ "last_seen": "2026-08-31T13:15:24",
+ "asn_number": 216246,
+ "asn_org": "Aeza Group LLC",
+ "country_name": "Russia",
+ "country_code": "RU",
+ "ports_targeted": [
+ 5432
+ ],
+ "ports_targeted_count": 1,
+ "tls_event_count": 0,
+ "top_http_methods": [],
+ "top_user_agents": [],
+ "top_url_paths": [],
+ "top_ja4_fingerprints": [],
+ "top_ja3_fingerprints": [],
+ "top_hassh_fingerprints": [],
+ "client_cert_event_count": 0,
+ "client_cert_subjects": [],
+ "rdns": "",
+ "loader_hits": 0,
+ "exploit_hits": 0,
+ "bytes_sent": 8,
+ "unique_source_ips": 1,
+ "ioc": "176.124.222.61",
+ "window": "last 7 days",
+ "query_type": "ip",
+ "scanner": null,
+ "verdict_key": "probing",
+ "verdict": "Low-level probing",
+ "verdict_why": [
+ "1 event(s), fewer than 10 distinct ports, no exploit payloads.",
+ "Not in any known-scanner range."
+ ],
+ "verdict_confidence": "low",
+ "cve_probes": []
+ }
+ },
+ {
+ "asn": "AS216246",
+ "name": "RU-AEZA-AS",
+ "ip": "45.151.101.38",
+ "event_count": 1,
+ "lookup": {
+ "total_events": 1,
+ "first_seen": "2026-09-03T20:05:03",
+ "last_seen": "2026-09-03T20:05:03",
+ "asn_number": 216246,
+ "asn_org": "Aeza Group LLC",
+ "country_name": "Russia",
+ "country_code": "RU",
+ "ports_targeted": [
+ 8006
+ ],
+ "ports_targeted_count": 1,
+ "tls_event_count": 1,
+ "top_http_methods": [
+ "POST"
+ ],
+ "top_user_agents": [
+ "Python-urllib/3.10"
+ ],
+ "top_url_paths": [
+ "/api2/json/access/ticket"
+ ],
+ "top_ja4_fingerprints": [
+ "t13i181000_85036bcba153_d41ae481755e"
+ ],
+ "top_ja3_fingerprints": [
+ "8a9d5d0f12f7d43ee3af1c51d2998d99"
+ ],
+ "top_hassh_fingerprints": [],
+ "client_cert_event_count": 0,
+ "client_cert_subjects": [],
+ "rdns": "",
+ "loader_hits": 0,
+ "exploit_hits": 0,
+ "bytes_sent": 263,
+ "unique_source_ips": 1,
+ "ioc": "45.151.101.38",
+ "window": "last 7 days",
+ "query_type": "ip",
+ "scanner": null,
+ "verdict_key": "probing",
+ "verdict": "Low-level probing",
+ "verdict_why": [
+ "1 event(s), fewer than 10 distinct ports, no exploit payloads.",
+ "Not in any known-scanner range."
+ ],
+ "verdict_confidence": "low",
+ "cve_probes": [
+ {
+ "cve_id": "CVE-2023-54391",
+ "title": "Proxmox VE - Default Credentials with TFA Bypass",
+ "severity": "critical",
+ "actively_exploited": false
+ }
+ ]
+ }
+ },
+ {
+ "asn": "AS200651",
+ "name": "FLOKINET",
+ "ip": "185.100.87.136",
+ "event_count": 24,
+ "lookup": {
+ "total_events": 22,
+ "first_seen": "2026-09-01T12:25:00",
+ "last_seen": "2026-09-07T09:47:19",
+ "asn_number": 200651,
+ "asn_org": "FlokiNET ehf",
+ "country_name": "Romania",
+ "country_code": "RO",
+ "ports_targeted": [
+ 443,
+ 8443
+ ],
+ "ports_targeted_count": 2,
+ "tls_event_count": 7,
+ "top_http_methods": [
+ "GET",
+ "POST"
+ ],
+ "top_user_agents": [
+ "SPARK COMMIT: 08059e95dacafe0bf6e5782f8e2c8ec9cd8c5a17",
+ "Mozilla/5.0 (Windows NT 10.0; Win64; x64)",
+ "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:104.71.6212.24) Gecko/25.2.4212.671 Firefox/2.0",
+ "Mozilla/5.0 (Android 12; Mobile; rv:117.0) Gecko/117.0 Focus/117.0"
+ ],
+ "top_url_paths": [
+ "/api/checkin",
+ "/",
+ "/api/client/update?arch=amd64&commit=08059e95dacafe0bf6e5782f8e2c8ec9cd8c5a17&os=windows",
+ "/eventmanager",
+ "/images/transparentpix.gif"
+ ],
+ "top_ja4_fingerprints": [
+ "t13i1909h2_9dc949149365_97f8aa674fd9"
+ ],
+ "top_ja3_fingerprints": [
+ "7c1e207beb00684bbbe144f1b0abe1d5"
+ ],
+ "top_hassh_fingerprints": [],
+ "client_cert_event_count": 0,
+ "client_cert_subjects": [],
+ "rdns": "",
+ "loader_hits": 0,
+ "exploit_hits": 0,
+ "bytes_sent": 4631,
+ "unique_source_ips": 1,
+ "ioc": "185.100.87.136",
+ "window": "last 7 days",
+ "query_type": "ip",
+ "scanner": null,
+ "verdict_key": "probing",
+ "verdict": "Low-level probing",
+ "verdict_why": [
+ "22 event(s), fewer than 10 distinct ports, no exploit payloads.",
+ "Not in any known-scanner range.",
+ "Sent 4,631 bytes despite few ports and no known exploit path: focused interaction with one service, worth a look."
+ ],
+ "verdict_confidence": "low",
+ "cve_probes": []
+ }
+ },
+ {
+ "asn": "AS198953",
+ "name": "PROTON66",
+ "ip": "176.120.22.61",
+ "event_count": 1597,
+ "lookup": {
+ "total_events": 1634,
+ "first_seen": "2026-08-31T11:36:25",
+ "last_seen": "2026-09-07T09:23:19",
+ "asn_number": 198953,
+ "asn_org": "Proton66 OOO",
+ "country_name": "Russia",
+ "country_code": "RU",
+ "ports_targeted": [
+ 11433,
+ 5433,
+ 2433,
+ 15366,
+ 2017,
+ 22020,
+ 35366,
+ 23341,
+ 1002,
+ 13433,
+ 37628,
+ 5539,
+ 7433,
+ 1434,
+ 7788,
+ 5000,
+ 5678,
+ 40501,
+ 1433,
+ 14330,
+ 2866,
+ 9001,
+ 18433,
+ 41433,
+ 1438,
+ 55366,
+ 3433,
+ 1501,
+ 1800,
+ 15774,
+ 8989,
+ 9999,
+ 1455,
+ 42130,
+ 6000,
+ 5005,
+ 21433,
+ 8888,
+ 7366,
+ 4433,
+ 5368,
+ 1444,
+ 16433,
+ 22433,
+ 19433,
+ 1456,
+ 6602,
+ 51234,
+ 6240,
+ 2468
+ ],
+ "ports_targeted_count": 270,
+ "tls_event_count": 0,
+ "top_http_methods": [],
+ "top_user_agents": [],
+ "top_url_paths": [],
+ "top_ja4_fingerprints": [],
+ "top_ja3_fingerprints": [],
+ "top_hassh_fingerprints": [],
+ "client_cert_event_count": 0,
+ "client_cert_subjects": [],
+ "rdns": "",
+ "loader_hits": 0,
+ "exploit_hits": 0,
+ "bytes_sent": 129048,
+ "unique_source_ips": 1,
+ "ioc": "176.120.22.61",
+ "window": "last 7 days",
+ "query_type": "ip",
+ "scanner": null,
+ "verdict_key": "scanning",
+ "verdict": "Unrecognized scanner",
+ "verdict_why": [
+ "No exploit payloads observed.",
+ "Swept 270 distinct ports (threshold for a sweep is 10).",
+ "Not in any known-scanner range."
+ ],
+ "verdict_confidence": "medium",
+ "cve_probes": []
+ }
+ },
+ {
+ "asn": "AS198953",
+ "name": "PROTON66",
+ "ip": "176.120.22.240",
+ "event_count": 45,
+ "lookup": {
+ "total_events": 60,
+ "first_seen": "2026-09-01T05:50:24",
+ "last_seen": "2026-09-07T03:25:20",
+ "asn_number": 198953,
+ "asn_org": "Proton66 OOO",
+ "country_name": "Russia",
+ "country_code": "RU",
+ "ports_targeted": [
+ 4443,
+ 8443,
+ 10443,
+ 500,
+ 1701,
+ 443,
+ 3799,
+ 8013,
+ 47,
+ 1812,
+ 1813,
+ 4500,
+ 8014,
+ 1443,
+ 2443,
+ 11443
+ ],
+ "ports_targeted_count": 16,
+ "tls_event_count": 60,
+ "top_http_methods": [
+ "GET"
+ ],
+ "top_user_agents": [
+ "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:74.0) Gecko/20100101 Firefox/74.0 - github.com/anasbousselham/)"
+ ],
+ "top_url_paths": [
+ "/remote/login?lang=en",
+ "/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession"
+ ],
+ "top_ja4_fingerprints": [
+ "t12i210600_76e208dd3e22_f28add8e7af0",
+ "t13i190800_9dc949149365_97f8aa674fd9"
+ ],
+ "top_ja3_fingerprints": [
+ "c12f54a3f91dc7bafd92cb59fe009a35",
+ "89be98bbd4f065fe510fca4893cf8d9b"
+ ],
+ "top_hassh_fingerprints": [],
+ "client_cert_event_count": 0,
+ "client_cert_subjects": [],
+ "rdns": "",
+ "loader_hits": 0,
+ "exploit_hits": 0,
+ "bytes_sent": 8294,
+ "unique_source_ips": 1,
+ "ioc": "176.120.22.240",
+ "window": "last 7 days",
+ "query_type": "ip",
+ "scanner": null,
+ "verdict_key": "scanning",
+ "verdict": "Unrecognized scanner",
+ "verdict_why": [
+ "No exploit payloads observed.",
+ "Swept 16 distinct ports (threshold for a sweep is 10).",
+ "Not in any known-scanner range."
+ ],
+ "verdict_confidence": "medium",
+ "cve_probes": [
+ {
+ "cve_id": "CVE-2018-13379",
+ "title": "Fortinet FortiOS SSL VPN path traversal",
+ "severity": "critical",
+ "actively_exploited": true
+ }
+ ]
+ }
+ },
+ {
+ "asn": "AS198953",
+ "name": "PROTON66",
+ "ip": "193.143.1.66",
+ "event_count": 24,
+ "lookup": {
+ "total_events": 24,
+ "first_seen": "2026-08-31T18:27:14",
+ "last_seen": "2026-09-04T21:27:35",
+ "asn_number": 198953,
+ "asn_org": "Proton66 OOO",
+ "country_name": "Russia",
+ "country_code": "RU",
+ "ports_targeted": [
+ 3389,
+ 3384,
+ 3349,
+ 33894
+ ],
+ "ports_targeted_count": 4,
+ "tls_event_count": 0,
+ "top_http_methods": [],
+ "top_user_agents": [],
+ "top_url_paths": [],
+ "top_ja4_fingerprints": [],
+ "top_ja3_fingerprints": [],
+ "top_hassh_fingerprints": [],
+ "client_cert_event_count": 0,
+ "client_cert_subjects": [],
+ "rdns": "",
+ "loader_hits": 0,
+ "exploit_hits": 0,
+ "bytes_sent": 1056,
+ "unique_source_ips": 1,
+ "ioc": "193.143.1.66",
+ "window": "last 7 days",
+ "query_type": "ip",
+ "scanner": null,
+ "verdict_key": "probing",
+ "verdict": "Low-level probing",
+ "verdict_why": [
+ "24 event(s), fewer than 10 distinct ports, no exploit payloads.",
+ "Not in any known-scanner range."
+ ],
+ "verdict_confidence": "low",
+ "cve_probes": []
+ }
+ }
+] \ No newline at end of file