aboutsummaryrefslogtreecommitdiff
path: root/kevlar/2026-08-31/honeylabs/ioc-107.189.26.103.json
diff options
context:
space:
mode:
Diffstat (limited to 'kevlar/2026-08-31/honeylabs/ioc-107.189.26.103.json')
-rw-r--r--kevlar/2026-08-31/honeylabs/ioc-107.189.26.103.json72
1 files changed, 72 insertions, 0 deletions
diff --git a/kevlar/2026-08-31/honeylabs/ioc-107.189.26.103.json b/kevlar/2026-08-31/honeylabs/ioc-107.189.26.103.json
new file mode 100644
index 0000000..3be0330
--- /dev/null
+++ b/kevlar/2026-08-31/honeylabs/ioc-107.189.26.103.json
@@ -0,0 +1,72 @@
+{
+ "total_events": 148,
+ "first_seen": "2026-08-20T14:44:13",
+ "last_seen": "2026-08-25T23:21:07",
+ "asn_number": 14956,
+ "asn_org": "RouterHosting LLC",
+ "country_name": "The Netherlands",
+ "country_code": "NL",
+ "ports_targeted": [
+ 80,
+ 2375
+ ],
+ "ports_targeted_count": 2,
+ "tls_event_count": 0,
+ "top_http_methods": [
+ "GET",
+ "POST"
+ ],
+ "top_user_agents": [
+ "libredtail-http"
+ ],
+ "top_url_paths": [
+ "/containers/json",
+ "/crm/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
+ "/cms/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
+ "/demo/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
+ "/ws/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
+ "/testing/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
+ "/test/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
+ "/api/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
+ "/zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
+ "/tests/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"
+ ],
+ "top_ja4_fingerprints": [],
+ "top_ja3_fingerprints": [],
+ "top_hassh_fingerprints": [],
+ "client_cert_event_count": 0,
+ "client_cert_subjects": [],
+ "rdns": "103.26.189.107.static.cloudzy.com",
+ "loader_hits": 6,
+ "exploit_hits": 135,
+ "bytes_sent": 1826936,
+ "unique_source_ips": 1,
+ "ioc": "107.189.26.103",
+ "window": "all retained data (no time filter)",
+ "query_type": "ip",
+ "scanner": null,
+ "verdict_key": "malicious",
+ "verdict": "Exploit attempts observed",
+ "verdict_why": [
+ "135 request(s) matched a known exploit path.",
+ "Exploit-path hits present; HTTP verb mix unknown, so read cautiously.",
+ "5+ hits raise confidence to high.",
+ "Not in any known-scanner range.",
+ "Sent 1,826,936 bytes: sustained payload delivery, not a single opportunistic request."
+ ],
+ "verdict_confidence": "high",
+ "cve_probes": [
+ {
+ "cve_id": "CVE-2017-9841",
+ "title": "PHPUnit - Remote Code Execution",
+ "severity": "critical",
+ "actively_exploited": true
+ },
+ {
+ "cve_id": "CVE-2021-42013",
+ "title": "Apache 2.4.49/2.4.50 - Path Traversal and Remote Code Execution",
+ "severity": "critical",
+ "actively_exploited": true
+ }
+ ]
+} \ No newline at end of file