diff options
| author | hrbrmstr <bob@rud.is> | 2026-09-07 06:03:32 -0400 |
|---|---|---|
| committer | hrbrmstr <bob@rud.is> | 2026-09-07 06:23:41 -0400 |
| commit | de4c2e99a969eb10708b02d8f2b6f31495eacce8 (patch) | |
| tree | ff5be97683e9dbf19ec0387f3a03a90282477dd2 /kevlar/2026-09-07/honeylabs/ioc-lookups.json | |
| parent | c283bcc507b0a7946a8660677a04da6f53cc77e1 (diff) | |
Diffstat (limited to 'kevlar/2026-09-07/honeylabs/ioc-lookups.json')
| -rw-r--r-- | kevlar/2026-09-07/honeylabs/ioc-lookups.json | 1175 |
1 files changed, 1175 insertions, 0 deletions
diff --git a/kevlar/2026-09-07/honeylabs/ioc-lookups.json b/kevlar/2026-09-07/honeylabs/ioc-lookups.json new file mode 100644 index 0000000..252b936 --- /dev/null +++ b/kevlar/2026-09-07/honeylabs/ioc-lookups.json @@ -0,0 +1,1175 @@ +[ + { + "asn": "AS57043", + "name": "HOSTKEY-AS", + "ip": "163.5.16.6", + "event_count": 8, + "lookup": { + "total_events": 8, + "first_seen": "2026-09-02T21:02:40", + "last_seen": "2026-09-02T21:19:46", + "asn_number": 57043, + "asn_org": "Hostkey B.v.", + "country_name": "United Kingdom", + "country_code": "GB", + "ports_targeted": [ + 19571, + 42481, + 5070, + 14603, + 44981, + 20271 + ], + "ports_targeted_count": 6, + "tls_event_count": 0, + "top_http_methods": [], + "top_user_agents": [], + "top_url_paths": [], + "top_ja4_fingerprints": [], + "top_ja3_fingerprints": [], + "top_hassh_fingerprints": [], + "client_cert_event_count": 0, + "client_cert_subjects": [], + "rdns": "", + "loader_hits": 0, + "exploit_hits": 0, + "bytes_sent": 152, + "unique_source_ips": 1, + "ioc": "163.5.16.6", + "window": "last 7 days", + "query_type": "ip", + "scanner": null, + "verdict_key": "probing", + "verdict": "Low-level probing", + "verdict_why": [ + "8 event(s), fewer than 10 distinct ports, no exploit payloads.", + "Not in any known-scanner range." + ], + "verdict_confidence": "low", + "cve_probes": [] + } + }, + { + "asn": "AS57043", + "name": "HOSTKEY-AS", + "ip": "82.39.165.100", + "event_count": 4, + "lookup": { + "total_events": 4, + "first_seen": "2026-08-31T15:39:39", + "last_seen": "2026-09-03T03:47:57", + "asn_number": 57043, + "asn_org": "Hostkey B.v.", + "country_name": "Germany", + "country_code": "DE", + "ports_targeted": [ + 22 + ], + "ports_targeted_count": 1, + "tls_event_count": 0, + "top_http_methods": [], + "top_user_agents": [], + "top_url_paths": [], + "top_ja4_fingerprints": [], + "top_ja3_fingerprints": [], + "top_hassh_fingerprints": [ + "98ddc5604ef6a1006a2b49a58759fbe6" + ], + "client_cert_event_count": 0, + "client_cert_subjects": [], + "rdns": "", + "loader_hits": 0, + "exploit_hits": 0, + "bytes_sent": 3248, + "unique_source_ips": 1, + "ioc": "82.39.165.100", + "window": "last 7 days", + "query_type": "ip", + "scanner": null, + "verdict_key": "probing", + "verdict": "Low-level probing", + "verdict_why": [ + "4 event(s), fewer than 10 distinct ports, no exploit payloads.", + "Not in any known-scanner range." + ], + "verdict_confidence": "low", + "cve_probes": [] + } + }, + { + "asn": "AS210644", + "name": "AEZA-AS", + "ip": "185.246.217.150", + "event_count": 51, + "lookup": { + "total_events": 51, + "first_seen": "2026-08-31T22:44:34", + "last_seen": "2026-09-02T15:29:27", + "asn_number": 210644, + "asn_org": "Aeza Group LLC", + "country_name": "The Netherlands", + "country_code": "NL", + "ports_targeted": [ + 443, + 2222, + 2375 + ], + "ports_targeted_count": 3, + "tls_event_count": 49, + "top_http_methods": [ + "GET", + "POST" + ], + "top_user_agents": [ + "libredtail-http" + ], + "top_url_paths": [ + "/containers/json", + "/crm/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php", + "/cms/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php", + "/demo/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php", + "/yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php", + "/api/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php", + "/testing/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php", + "/ws/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php", + "/ws/ec/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php", + "/test/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" + ], + "top_ja4_fingerprints": [ + "t13i170900_5b57614c22b0_78e6aca7449b" + ], + "top_ja3_fingerprints": [ + "052a5e65c3a64e860e1706b1de3c46a9" + ], + "top_hassh_fingerprints": [ + "19532158b559096b89b1a5f7d17175b2" + ], + "client_cert_event_count": 0, + "client_cert_subjects": [], + "rdns": "", + "loader_hits": 2, + "exploit_hits": 45, + "bytes_sent": 610617, + "unique_source_ips": 1, + "ioc": "185.246.217.150", + "window": "last 7 days", + "query_type": "ip", + "scanner": null, + "verdict_key": "malicious", + "verdict": "Exploit attempts observed", + "verdict_why": [ + "45 request(s) matched a known exploit path.", + "Exploit-path hits present; HTTP verb mix unknown, so read cautiously.", + "5+ hits raise confidence to high.", + "Not in any known-scanner range.", + "Sent 610,617 bytes: sustained payload delivery, not a single opportunistic request." + ], + "verdict_confidence": "high", + "cve_probes": [ + { + "cve_id": "CVE-2017-9841", + "title": "PHPUnit - Remote Code Execution", + "severity": "critical", + "actively_exploited": true + }, + { + "cve_id": "CVE-2021-42013", + "title": "Apache 2.4.49/2.4.50 - Path Traversal and Remote Code Execution", + "severity": "critical", + "actively_exploited": true + } + ] + } + }, + { + "asn": "AS14956", + "name": "ROUTERHOSTING", + "ip": "45.61.157.82", + "event_count": 32, + "lookup": { + "total_events": 32, + "first_seen": "2026-09-04T01:15:12", + "last_seen": "2026-09-04T06:30:09", + "asn_number": 14956, + "asn_org": "RouterHosting LLC", + "country_name": "United States", + "country_code": "US", + "ports_targeted": [ + 445 + ], + "ports_targeted_count": 1, + "tls_event_count": 0, + "top_http_methods": [], + "top_user_agents": [], + "top_url_paths": [], + "top_ja4_fingerprints": [], + "top_ja3_fingerprints": [], + "top_hassh_fingerprints": [], + "client_cert_event_count": 0, + "client_cert_subjects": [], + "rdns": "82.157.61.45.static.cloudzy.com", + "loader_hits": 0, + "exploit_hits": 0, + "bytes_sent": 8684, + "unique_source_ips": 1, + "ioc": "45.61.157.82", + "window": "last 7 days", + "query_type": "ip", + "scanner": null, + "verdict_key": "probing", + "verdict": "Low-level probing", + "verdict_why": [ + "32 event(s), fewer than 10 distinct ports, no exploit payloads.", + "Not in any known-scanner range.", + "Sent 8,684 bytes despite few ports and no known exploit path: focused interaction with one service, worth a look." + ], + "verdict_confidence": "low", + "cve_probes": [] + } + }, + { + "asn": "AS14956", + "name": "ROUTERHOSTING", + "ip": "144.172.108.79", + "event_count": 24, + "lookup": { + "total_events": 24, + "first_seen": "2026-09-04T20:02:59", + "last_seen": "2026-09-05T02:54:19", + "asn_number": 14956, + "asn_org": "RouterHosting LLC", + "country_name": "United States", + "country_code": "US", + "ports_targeted": [ + 445 + ], + "ports_targeted_count": 1, + "tls_event_count": 0, + "top_http_methods": [], + "top_user_agents": [], + "top_url_paths": [], + "top_ja4_fingerprints": [], + "top_ja3_fingerprints": [], + "top_hassh_fingerprints": [], + "client_cert_event_count": 0, + "client_cert_subjects": [], + "rdns": "79.108.172.144.static.cloudzy.com", + "loader_hits": 0, + "exploit_hits": 0, + "bytes_sent": 6513, + "unique_source_ips": 1, + "ioc": "144.172.108.79", + "window": "last 7 days", + "query_type": "ip", + "scanner": null, + "verdict_key": "probing", + "verdict": "Low-level probing", + "verdict_why": [ + "24 event(s), fewer than 10 distinct ports, no exploit payloads.", + "Not in any known-scanner range.", + "Sent 6,513 bytes despite few ports and no known exploit path: focused interaction with one service, worth a look." + ], + "verdict_confidence": "low", + "cve_probes": [] + } + }, + { + "asn": "AS14956", + "name": "ROUTERHOSTING", + "ip": "144.172.99.200", + "event_count": 16, + "lookup": { + "total_events": 16, + "first_seen": "2026-09-01T07:55:37", + "last_seen": "2026-09-01T08:57:36", + "asn_number": 14956, + "asn_org": "RouterHosting LLC", + "country_name": "United States", + "country_code": "US", + "ports_targeted": [ + 445 + ], + "ports_targeted_count": 1, + "tls_event_count": 0, + "top_http_methods": [], + "top_user_agents": [], + "top_url_paths": [], + "top_ja4_fingerprints": [], + "top_ja3_fingerprints": [], + "top_hassh_fingerprints": [], + "client_cert_event_count": 0, + "client_cert_subjects": [], + "rdns": "200.99.172.144.static.cloudzy.com", + "loader_hits": 0, + "exploit_hits": 0, + "bytes_sent": 4342, + "unique_source_ips": 1, + "ioc": "144.172.99.200", + "window": "last 7 days", + "query_type": "ip", + "scanner": null, + "verdict_key": "probing", + "verdict": "Low-level probing", + "verdict_why": [ + "16 event(s), fewer than 10 distinct ports, no exploit payloads.", + "Not in any known-scanner range.", + "Sent 4,342 bytes despite few ports and no known exploit path: focused interaction with one service, worth a look." + ], + "verdict_confidence": "low", + "cve_probes": [] + } + }, + { + "asn": "AS51852", + "name": "PLI-AS", + "ip": "179.43.150.26", + "event_count": 16, + "lookup": { + "total_events": 16, + "first_seen": "2026-08-31T15:32:52", + "last_seen": "2026-08-31T16:49:55", + "asn_number": 51852, + "asn_org": "Private Layer INC", + "country_name": "Switzerland", + "country_code": "CH", + "ports_targeted": [ + 8443 + ], + "ports_targeted_count": 1, + "tls_event_count": 0, + "top_http_methods": [ + "GET" + ], + "top_user_agents": [ + "Mozilla/5.0" + ], + "top_url_paths": [ + "/.env", + "/z1356", + "/s/1974", + "/.e199", + "/z1891", + "/s/1688", + "/.e3448", + "/z945", + "/s/7694", + "/s/6254" + ], + "top_ja4_fingerprints": [], + "top_ja3_fingerprints": [], + "top_hassh_fingerprints": [], + "client_cert_event_count": 0, + "client_cert_subjects": [], + "rdns": "hostedby.privatelayer.com", + "loader_hits": 0, + "exploit_hits": 4, + "bytes_sent": 3470, + "unique_source_ips": 1, + "ioc": "179.43.150.26", + "window": "last 7 days", + "query_type": "ip", + "scanner": null, + "verdict_key": "malicious", + "verdict": "Exploit attempts observed", + "verdict_why": [ + "4 request(s) matched a known exploit path.", + "Exploit-path hits present; HTTP verb mix unknown, so read cautiously.", + "Under 5 hits, so confidence is medium.", + "Not in any known-scanner range." + ], + "verdict_confidence": "medium", + "cve_probes": [] + } + }, + { + "asn": "AS51852", + "name": "PLI-AS", + "ip": "46.19.142.226", + "event_count": 6, + "lookup": { + "total_events": 6, + "first_seen": "2026-09-04T18:34:20", + "last_seen": "2026-09-04T19:27:10", + "asn_number": 51852, + "asn_org": "Private Layer INC", + "country_name": "Switzerland", + "country_code": "CH", + "ports_targeted": [ + 2087 + ], + "ports_targeted_count": 1, + "tls_event_count": 6, + "top_http_methods": [ + "GET", + "POST" + ], + "top_user_agents": [ + "Mozilla/5.0", + "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" + ], + "top_url_paths": [ + "/openid_connect/cpanelid", + "/login/?login_only=1" + ], + "top_ja4_fingerprints": [ + "t13i190800_9dc949149365_97f8aa674fd9" + ], + "top_ja3_fingerprints": [ + "19e29534fd49dd27d09234e639c4057e" + ], + "top_hassh_fingerprints": [], + "client_cert_event_count": 0, + "client_cert_subjects": [], + "rdns": "hostedby.privatelayer.com", + "loader_hits": 0, + "exploit_hits": 0, + "bytes_sent": 944, + "unique_source_ips": 1, + "ioc": "46.19.142.226", + "window": "last 7 days", + "query_type": "ip", + "scanner": null, + "verdict_key": "probing", + "verdict": "Low-level probing", + "verdict_why": [ + "6 event(s), fewer than 10 distinct ports, no exploit payloads.", + "Not in any known-scanner range." + ], + "verdict_confidence": "low", + "cve_probes": [ + { + "cve_id": "CVE-2026-41940", + "title": "cPanel & WHM - Authentication Bypass via Session-File CRLF Injection", + "severity": "CRITICAL", + "actively_exploited": true + } + ] + } + }, + { + "asn": "AS51852", + "name": "PLI-AS", + "ip": "141.255.165.66", + "event_count": 5, + "lookup": { + "total_events": 5, + "first_seen": "2026-09-03T20:48:30", + "last_seen": "2026-09-04T11:46:33", + "asn_number": 51852, + "asn_org": "Private Layer INC", + "country_name": "Switzerland", + "country_code": "CH", + "ports_targeted": [ + 1723 + ], + "ports_targeted_count": 1, + "tls_event_count": 0, + "top_http_methods": [], + "top_user_agents": [], + "top_url_paths": [], + "top_ja4_fingerprints": [], + "top_ja3_fingerprints": [], + "top_hassh_fingerprints": [], + "client_cert_event_count": 0, + "client_cert_subjects": [], + "rdns": "4soho.com", + "loader_hits": 0, + "exploit_hits": 0, + "bytes_sent": 780, + "unique_source_ips": 1, + "ioc": "141.255.165.66", + "window": "last 7 days", + "query_type": "ip", + "scanner": null, + "verdict_key": "probing", + "verdict": "Low-level probing", + "verdict_why": [ + "5 event(s), fewer than 10 distinct ports, no exploit payloads.", + "Not in any known-scanner range." + ], + "verdict_confidence": "low", + "cve_probes": [] + } + }, + { + "asn": "AS51396", + "name": "PFCLOUD", + "ip": "204.76.203.222", + "event_count": 1159, + "lookup": { + "total_events": 1331, + "first_seen": "2026-09-02T09:47:23", + "last_seen": "2026-09-07T09:45:33", + "asn_number": 51396, + "asn_org": "Pfcloud UG (haftungsbeschrankt)", + "country_name": "The Netherlands", + "country_code": "NL", + "ports_targeted": [ + 5151, + 10118, + 11517, + 2222, + 10080, + 50009, + 7375, + 52120, + 50032, + 11004, + 11338, + 2018, + 8004, + 11238, + 8084, + 10803, + 6666, + 13292, + 9000, + 6652, + 9443, + 11148, + 5477, + 56789, + 10165, + 30006, + 10023, + 30011, + 10001, + 5001, + 2026, + 11635, + 11435, + 11409, + 2030, + 6128, + 11415, + 6969, + 20999, + 8095, + 9252, + 13509, + 5212, + 8045, + 50007, + 9054, + 12367, + 32536, + 3389, + 9098 + ], + "ports_targeted_count": 879, + "tls_event_count": 0, + "top_http_methods": [], + "top_user_agents": [], + "top_url_paths": [], + "top_ja4_fingerprints": [], + "top_ja3_fingerprints": [], + "top_hassh_fingerprints": [], + "client_cert_event_count": 0, + "client_cert_subjects": [], + "rdns": "204.76.203.222.ptr.pfcloud.network", + "loader_hits": 0, + "exploit_hits": 0, + "bytes_sent": 49337, + "unique_source_ips": 1, + "ioc": "204.76.203.222", + "window": "last 7 days", + "query_type": "ip", + "scanner": null, + "verdict_key": "scanning", + "verdict": "Unrecognized scanner", + "verdict_why": [ + "No exploit payloads observed.", + "Swept 879 distinct ports (threshold for a sweep is 10).", + "Not in any known-scanner range." + ], + "verdict_confidence": "medium", + "cve_probes": [] + } + }, + { + "asn": "AS51396", + "name": "PFCLOUD", + "ip": "204.76.203.221", + "event_count": 1154, + "lookup": { + "total_events": 1332, + "first_seen": "2026-09-02T09:47:23", + "last_seen": "2026-09-07T09:47:47", + "asn_number": 51396, + "asn_org": "Pfcloud UG (haftungsbeschrankt)", + "country_name": "The Netherlands", + "country_code": "NL", + "ports_targeted": [ + 5477, + 11617, + 11918, + 10080, + 11587, + 10231, + 5918, + 6588, + 11416, + 11000, + 20898, + 5507, + 31280, + 11181, + 9258, + 20274, + 9040, + 20132, + 1083, + 20621, + 11081, + 11111, + 11528, + 20023, + 6685, + 10031, + 20038, + 10023, + 3129, + 50008, + 11338, + 1080, + 10109, + 50028, + 8225, + 10000, + 50019, + 10157, + 9898, + 5513, + 1058, + 9999, + 18505, + 5108, + 10034, + 11404, + 9422, + 8045, + 10432, + 32260 + ], + "ports_targeted_count": 890, + "tls_event_count": 0, + "top_http_methods": [], + "top_user_agents": [], + "top_url_paths": [], + "top_ja4_fingerprints": [], + "top_ja3_fingerprints": [], + "top_hassh_fingerprints": [], + "client_cert_event_count": 0, + "client_cert_subjects": [], + "rdns": "204.76.203.221.ptr.pfcloud.network", + "loader_hits": 0, + "exploit_hits": 0, + "bytes_sent": 47840, + "unique_source_ips": 1, + "ioc": "204.76.203.221", + "window": "last 7 days", + "query_type": "ip", + "scanner": null, + "verdict_key": "scanning", + "verdict": "Unrecognized scanner", + "verdict_why": [ + "No exploit payloads observed.", + "Swept 890 distinct ports (threshold for a sweep is 10).", + "Not in any known-scanner range." + ], + "verdict_confidence": "medium", + "cve_probes": [] + } + }, + { + "asn": "AS51396", + "name": "PFCLOUD", + "ip": "204.76.203.213", + "event_count": 1123, + "lookup": { + "total_events": 1286, + "first_seen": "2026-09-02T09:53:18", + "last_seen": "2026-09-07T09:39:49", + "asn_number": 51396, + "asn_org": "Pfcloud UG (haftungsbeschrankt)", + "country_name": "The Netherlands", + "country_code": "NL", + "ports_targeted": [ + 11000, + 5518, + 20009, + 5112, + 11537, + 20035, + 11008, + 50029, + 56789, + 31460, + 4219, + 2028, + 3385, + 1112, + 10027, + 10140, + 5918, + 11918, + 10101, + 4544, + 20104, + 10033, + 30000, + 10109, + 10801, + 9898, + 20390, + 8891, + 10041, + 11322, + 10075, + 25412, + 49532, + 34491, + 50012, + 17891, + 50008, + 20015, + 20248, + 11644, + 33128, + 9002, + 1065, + 6724, + 18080, + 10137, + 11508, + 10821, + 20132, + 31526 + ], + "ports_targeted_count": 872, + "tls_event_count": 0, + "top_http_methods": [], + "top_user_agents": [], + "top_url_paths": [], + "top_ja4_fingerprints": [], + "top_ja3_fingerprints": [], + "top_hassh_fingerprints": [], + "client_cert_event_count": 0, + "client_cert_subjects": [], + "rdns": "204.76.203.213.ptr.pfcloud.network", + "loader_hits": 0, + "exploit_hits": 0, + "bytes_sent": 46038, + "unique_source_ips": 1, + "ioc": "204.76.203.213", + "window": "last 7 days", + "query_type": "ip", + "scanner": null, + "verdict_key": "scanning", + "verdict": "Unrecognized scanner", + "verdict_why": [ + "No exploit payloads observed.", + "Swept 872 distinct ports (threshold for a sweep is 10).", + "Not in any known-scanner range." + ], + "verdict_confidence": "medium", + "cve_probes": [] + } + }, + { + "asn": "AS216246", + "name": "RU-AEZA-AS", + "ip": "176.124.222.61", + "event_count": 1, + "lookup": { + "total_events": 1, + "first_seen": "2026-08-31T13:15:24", + "last_seen": "2026-08-31T13:15:24", + "asn_number": 216246, + "asn_org": "Aeza Group LLC", + "country_name": "Russia", + "country_code": "RU", + "ports_targeted": [ + 5432 + ], + "ports_targeted_count": 1, + "tls_event_count": 0, + "top_http_methods": [], + "top_user_agents": [], + "top_url_paths": [], + "top_ja4_fingerprints": [], + "top_ja3_fingerprints": [], + "top_hassh_fingerprints": [], + "client_cert_event_count": 0, + "client_cert_subjects": [], + "rdns": "", + "loader_hits": 0, + "exploit_hits": 0, + "bytes_sent": 8, + "unique_source_ips": 1, + "ioc": "176.124.222.61", + "window": "last 7 days", + "query_type": "ip", + "scanner": null, + "verdict_key": "probing", + "verdict": "Low-level probing", + "verdict_why": [ + "1 event(s), fewer than 10 distinct ports, no exploit payloads.", + "Not in any known-scanner range." + ], + "verdict_confidence": "low", + "cve_probes": [] + } + }, + { + "asn": "AS216246", + "name": "RU-AEZA-AS", + "ip": "45.151.101.38", + "event_count": 1, + "lookup": { + "total_events": 1, + "first_seen": "2026-09-03T20:05:03", + "last_seen": "2026-09-03T20:05:03", + "asn_number": 216246, + "asn_org": "Aeza Group LLC", + "country_name": "Russia", + "country_code": "RU", + "ports_targeted": [ + 8006 + ], + "ports_targeted_count": 1, + "tls_event_count": 1, + "top_http_methods": [ + "POST" + ], + "top_user_agents": [ + "Python-urllib/3.10" + ], + "top_url_paths": [ + "/api2/json/access/ticket" + ], + "top_ja4_fingerprints": [ + "t13i181000_85036bcba153_d41ae481755e" + ], + "top_ja3_fingerprints": [ + "8a9d5d0f12f7d43ee3af1c51d2998d99" + ], + "top_hassh_fingerprints": [], + "client_cert_event_count": 0, + "client_cert_subjects": [], + "rdns": "", + "loader_hits": 0, + "exploit_hits": 0, + "bytes_sent": 263, + "unique_source_ips": 1, + "ioc": "45.151.101.38", + "window": "last 7 days", + "query_type": "ip", + "scanner": null, + "verdict_key": "probing", + "verdict": "Low-level probing", + "verdict_why": [ + "1 event(s), fewer than 10 distinct ports, no exploit payloads.", + "Not in any known-scanner range." + ], + "verdict_confidence": "low", + "cve_probes": [ + { + "cve_id": "CVE-2023-54391", + "title": "Proxmox VE - Default Credentials with TFA Bypass", + "severity": "critical", + "actively_exploited": false + } + ] + } + }, + { + "asn": "AS200651", + "name": "FLOKINET", + "ip": "185.100.87.136", + "event_count": 24, + "lookup": { + "total_events": 22, + "first_seen": "2026-09-01T12:25:00", + "last_seen": "2026-09-07T09:47:19", + "asn_number": 200651, + "asn_org": "FlokiNET ehf", + "country_name": "Romania", + "country_code": "RO", + "ports_targeted": [ + 443, + 8443 + ], + "ports_targeted_count": 2, + "tls_event_count": 7, + "top_http_methods": [ + "GET", + "POST" + ], + "top_user_agents": [ + "SPARK COMMIT: 08059e95dacafe0bf6e5782f8e2c8ec9cd8c5a17", + "Mozilla/5.0 (Windows NT 10.0; Win64; x64)", + "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:104.71.6212.24) Gecko/25.2.4212.671 Firefox/2.0", + "Mozilla/5.0 (Android 12; Mobile; rv:117.0) Gecko/117.0 Focus/117.0" + ], + "top_url_paths": [ + "/api/checkin", + "/", + "/api/client/update?arch=amd64&commit=08059e95dacafe0bf6e5782f8e2c8ec9cd8c5a17&os=windows", + "/eventmanager", + "/images/transparentpix.gif" + ], + "top_ja4_fingerprints": [ + "t13i1909h2_9dc949149365_97f8aa674fd9" + ], + "top_ja3_fingerprints": [ + "7c1e207beb00684bbbe144f1b0abe1d5" + ], + "top_hassh_fingerprints": [], + "client_cert_event_count": 0, + "client_cert_subjects": [], + "rdns": "", + "loader_hits": 0, + "exploit_hits": 0, + "bytes_sent": 4631, + "unique_source_ips": 1, + "ioc": "185.100.87.136", + "window": "last 7 days", + "query_type": "ip", + "scanner": null, + "verdict_key": "probing", + "verdict": "Low-level probing", + "verdict_why": [ + "22 event(s), fewer than 10 distinct ports, no exploit payloads.", + "Not in any known-scanner range.", + "Sent 4,631 bytes despite few ports and no known exploit path: focused interaction with one service, worth a look." + ], + "verdict_confidence": "low", + "cve_probes": [] + } + }, + { + "asn": "AS198953", + "name": "PROTON66", + "ip": "176.120.22.61", + "event_count": 1597, + "lookup": { + "total_events": 1634, + "first_seen": "2026-08-31T11:36:25", + "last_seen": "2026-09-07T09:23:19", + "asn_number": 198953, + "asn_org": "Proton66 OOO", + "country_name": "Russia", + "country_code": "RU", + "ports_targeted": [ + 11433, + 5433, + 2433, + 15366, + 2017, + 22020, + 35366, + 23341, + 1002, + 13433, + 37628, + 5539, + 7433, + 1434, + 7788, + 5000, + 5678, + 40501, + 1433, + 14330, + 2866, + 9001, + 18433, + 41433, + 1438, + 55366, + 3433, + 1501, + 1800, + 15774, + 8989, + 9999, + 1455, + 42130, + 6000, + 5005, + 21433, + 8888, + 7366, + 4433, + 5368, + 1444, + 16433, + 22433, + 19433, + 1456, + 6602, + 51234, + 6240, + 2468 + ], + "ports_targeted_count": 270, + "tls_event_count": 0, + "top_http_methods": [], + "top_user_agents": [], + "top_url_paths": [], + "top_ja4_fingerprints": [], + "top_ja3_fingerprints": [], + "top_hassh_fingerprints": [], + "client_cert_event_count": 0, + "client_cert_subjects": [], + "rdns": "", + "loader_hits": 0, + "exploit_hits": 0, + "bytes_sent": 129048, + "unique_source_ips": 1, + "ioc": "176.120.22.61", + "window": "last 7 days", + "query_type": "ip", + "scanner": null, + "verdict_key": "scanning", + "verdict": "Unrecognized scanner", + "verdict_why": [ + "No exploit payloads observed.", + "Swept 270 distinct ports (threshold for a sweep is 10).", + "Not in any known-scanner range." + ], + "verdict_confidence": "medium", + "cve_probes": [] + } + }, + { + "asn": "AS198953", + "name": "PROTON66", + "ip": "176.120.22.240", + "event_count": 45, + "lookup": { + "total_events": 60, + "first_seen": "2026-09-01T05:50:24", + "last_seen": "2026-09-07T03:25:20", + "asn_number": 198953, + "asn_org": "Proton66 OOO", + "country_name": "Russia", + "country_code": "RU", + "ports_targeted": [ + 4443, + 8443, + 10443, + 500, + 1701, + 443, + 3799, + 8013, + 47, + 1812, + 1813, + 4500, + 8014, + 1443, + 2443, + 11443 + ], + "ports_targeted_count": 16, + "tls_event_count": 60, + "top_http_methods": [ + "GET" + ], + "top_user_agents": [ + "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:74.0) Gecko/20100101 Firefox/74.0 - github.com/anasbousselham/)" + ], + "top_url_paths": [ + "/remote/login?lang=en", + "/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession" + ], + "top_ja4_fingerprints": [ + "t12i210600_76e208dd3e22_f28add8e7af0", + "t13i190800_9dc949149365_97f8aa674fd9" + ], + "top_ja3_fingerprints": [ + "c12f54a3f91dc7bafd92cb59fe009a35", + "89be98bbd4f065fe510fca4893cf8d9b" + ], + "top_hassh_fingerprints": [], + "client_cert_event_count": 0, + "client_cert_subjects": [], + "rdns": "", + "loader_hits": 0, + "exploit_hits": 0, + "bytes_sent": 8294, + "unique_source_ips": 1, + "ioc": "176.120.22.240", + "window": "last 7 days", + "query_type": "ip", + "scanner": null, + "verdict_key": "scanning", + "verdict": "Unrecognized scanner", + "verdict_why": [ + "No exploit payloads observed.", + "Swept 16 distinct ports (threshold for a sweep is 10).", + "Not in any known-scanner range." + ], + "verdict_confidence": "medium", + "cve_probes": [ + { + "cve_id": "CVE-2018-13379", + "title": "Fortinet FortiOS SSL VPN path traversal", + "severity": "critical", + "actively_exploited": true + } + ] + } + }, + { + "asn": "AS198953", + "name": "PROTON66", + "ip": "193.143.1.66", + "event_count": 24, + "lookup": { + "total_events": 24, + "first_seen": "2026-08-31T18:27:14", + "last_seen": "2026-09-04T21:27:35", + "asn_number": 198953, + "asn_org": "Proton66 OOO", + "country_name": "Russia", + "country_code": "RU", + "ports_targeted": [ + 3389, + 3384, + 3349, + 33894 + ], + "ports_targeted_count": 4, + "tls_event_count": 0, + "top_http_methods": [], + "top_user_agents": [], + "top_url_paths": [], + "top_ja4_fingerprints": [], + "top_ja3_fingerprints": [], + "top_hassh_fingerprints": [], + "client_cert_event_count": 0, + "client_cert_subjects": [], + "rdns": "", + "loader_hits": 0, + "exploit_hits": 0, + "bytes_sent": 1056, + "unique_source_ips": 1, + "ioc": "193.143.1.66", + "window": "last 7 days", + "query_type": "ip", + "scanner": null, + "verdict_key": "probing", + "verdict": "Low-level probing", + "verdict_why": [ + "24 event(s), fewer than 10 distinct ports, no exploit payloads.", + "Not in any known-scanner range." + ], + "verdict_confidence": "low", + "cve_probes": [] + } + } +]
\ No newline at end of file |
