[ { "asn": "AS57043", "name": "HOSTKEY-AS", "ip": "163.5.16.6", "event_count": 8, "lookup": { "total_events": 8, "first_seen": "2026-09-02T21:02:40", "last_seen": "2026-09-02T21:19:46", "asn_number": 57043, "asn_org": "Hostkey B.v.", "country_name": "United Kingdom", "country_code": "GB", "ports_targeted": [ 19571, 42481, 5070, 14603, 44981, 20271 ], "ports_targeted_count": 6, "tls_event_count": 0, "top_http_methods": [], "top_user_agents": [], "top_url_paths": [], "top_ja4_fingerprints": [], "top_ja3_fingerprints": [], "top_hassh_fingerprints": [], "client_cert_event_count": 0, "client_cert_subjects": [], "rdns": "", "loader_hits": 0, "exploit_hits": 0, "bytes_sent": 152, "unique_source_ips": 1, "ioc": "163.5.16.6", "window": "last 7 days", "query_type": "ip", "scanner": null, "verdict_key": "probing", "verdict": "Low-level probing", "verdict_why": [ "8 event(s), fewer than 10 distinct ports, no exploit payloads.", "Not in any known-scanner range." ], "verdict_confidence": "low", "cve_probes": [] } }, { "asn": "AS57043", "name": "HOSTKEY-AS", "ip": "82.39.165.100", "event_count": 4, "lookup": { "total_events": 4, "first_seen": "2026-08-31T15:39:39", "last_seen": "2026-09-03T03:47:57", "asn_number": 57043, "asn_org": "Hostkey B.v.", "country_name": "Germany", "country_code": "DE", "ports_targeted": [ 22 ], "ports_targeted_count": 1, "tls_event_count": 0, "top_http_methods": [], "top_user_agents": [], "top_url_paths": [], "top_ja4_fingerprints": [], "top_ja3_fingerprints": [], "top_hassh_fingerprints": [ "98ddc5604ef6a1006a2b49a58759fbe6" ], "client_cert_event_count": 0, "client_cert_subjects": [], "rdns": "", "loader_hits": 0, "exploit_hits": 0, "bytes_sent": 3248, "unique_source_ips": 1, "ioc": "82.39.165.100", "window": "last 7 days", "query_type": "ip", "scanner": null, "verdict_key": "probing", "verdict": "Low-level probing", "verdict_why": [ "4 event(s), fewer than 10 distinct ports, no exploit payloads.", "Not in any known-scanner range." ], "verdict_confidence": "low", "cve_probes": [] } }, { "asn": "AS210644", "name": "AEZA-AS", "ip": "185.246.217.150", "event_count": 51, "lookup": { "total_events": 51, "first_seen": "2026-08-31T22:44:34", "last_seen": "2026-09-02T15:29:27", "asn_number": 210644, "asn_org": "Aeza Group LLC", "country_name": "The Netherlands", "country_code": "NL", "ports_targeted": [ 443, 2222, 2375 ], "ports_targeted_count": 3, "tls_event_count": 49, "top_http_methods": [ "GET", "POST" ], "top_user_agents": [ "libredtail-http" ], "top_url_paths": [ "/containers/json", "/crm/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php", "/cms/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php", "/demo/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php", "/yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php", "/api/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php", "/testing/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php", "/ws/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php", "/ws/ec/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php", "/test/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" ], "top_ja4_fingerprints": [ "t13i170900_5b57614c22b0_78e6aca7449b" ], "top_ja3_fingerprints": [ "052a5e65c3a64e860e1706b1de3c46a9" ], "top_hassh_fingerprints": [ "19532158b559096b89b1a5f7d17175b2" ], "client_cert_event_count": 0, "client_cert_subjects": [], "rdns": "", "loader_hits": 2, "exploit_hits": 45, "bytes_sent": 610617, "unique_source_ips": 1, "ioc": "185.246.217.150", "window": "last 7 days", "query_type": "ip", "scanner": null, "verdict_key": "malicious", "verdict": "Exploit attempts observed", "verdict_why": [ "45 request(s) matched a known exploit path.", "Exploit-path hits present; HTTP verb mix unknown, so read cautiously.", "5+ hits raise confidence to high.", "Not in any known-scanner range.", "Sent 610,617 bytes: sustained payload delivery, not a single opportunistic request." ], "verdict_confidence": "high", "cve_probes": [ { "cve_id": "CVE-2017-9841", "title": "PHPUnit - Remote Code Execution", "severity": "critical", "actively_exploited": true }, { "cve_id": "CVE-2021-42013", "title": "Apache 2.4.49/2.4.50 - Path Traversal and Remote Code Execution", "severity": "critical", "actively_exploited": true } ] } }, { "asn": "AS14956", "name": "ROUTERHOSTING", "ip": "45.61.157.82", "event_count": 32, "lookup": { "total_events": 32, "first_seen": "2026-09-04T01:15:12", "last_seen": "2026-09-04T06:30:09", "asn_number": 14956, "asn_org": "RouterHosting LLC", "country_name": "United States", "country_code": "US", "ports_targeted": [ 445 ], "ports_targeted_count": 1, "tls_event_count": 0, "top_http_methods": [], "top_user_agents": [], "top_url_paths": [], "top_ja4_fingerprints": [], "top_ja3_fingerprints": [], "top_hassh_fingerprints": [], "client_cert_event_count": 0, "client_cert_subjects": [], "rdns": "82.157.61.45.static.cloudzy.com", "loader_hits": 0, "exploit_hits": 0, "bytes_sent": 8684, "unique_source_ips": 1, "ioc": "45.61.157.82", "window": "last 7 days", "query_type": "ip", "scanner": null, "verdict_key": "probing", "verdict": "Low-level probing", "verdict_why": [ "32 event(s), fewer than 10 distinct ports, no exploit payloads.", "Not in any known-scanner range.", "Sent 8,684 bytes despite few ports and no known exploit path: focused interaction with one service, worth a look." ], "verdict_confidence": "low", "cve_probes": [] } }, { "asn": "AS14956", "name": "ROUTERHOSTING", "ip": "144.172.108.79", "event_count": 24, "lookup": { "total_events": 24, "first_seen": "2026-09-04T20:02:59", "last_seen": "2026-09-05T02:54:19", "asn_number": 14956, "asn_org": "RouterHosting LLC", "country_name": "United States", "country_code": "US", "ports_targeted": [ 445 ], "ports_targeted_count": 1, "tls_event_count": 0, "top_http_methods": [], "top_user_agents": [], "top_url_paths": [], "top_ja4_fingerprints": [], "top_ja3_fingerprints": [], "top_hassh_fingerprints": [], "client_cert_event_count": 0, "client_cert_subjects": [], "rdns": "79.108.172.144.static.cloudzy.com", "loader_hits": 0, "exploit_hits": 0, "bytes_sent": 6513, "unique_source_ips": 1, "ioc": "144.172.108.79", "window": "last 7 days", "query_type": "ip", "scanner": null, "verdict_key": "probing", "verdict": "Low-level probing", "verdict_why": [ "24 event(s), fewer than 10 distinct ports, no exploit payloads.", "Not in any known-scanner range.", "Sent 6,513 bytes despite few ports and no known exploit path: focused interaction with one service, worth a look." ], "verdict_confidence": "low", "cve_probes": [] } }, { "asn": "AS14956", "name": "ROUTERHOSTING", "ip": "144.172.99.200", "event_count": 16, "lookup": { "total_events": 16, "first_seen": "2026-09-01T07:55:37", "last_seen": "2026-09-01T08:57:36", "asn_number": 14956, "asn_org": "RouterHosting LLC", "country_name": "United States", "country_code": "US", "ports_targeted": [ 445 ], "ports_targeted_count": 1, "tls_event_count": 0, "top_http_methods": [], "top_user_agents": [], "top_url_paths": [], "top_ja4_fingerprints": [], "top_ja3_fingerprints": [], "top_hassh_fingerprints": [], "client_cert_event_count": 0, "client_cert_subjects": [], "rdns": "200.99.172.144.static.cloudzy.com", "loader_hits": 0, "exploit_hits": 0, "bytes_sent": 4342, "unique_source_ips": 1, "ioc": "144.172.99.200", "window": "last 7 days", "query_type": "ip", "scanner": null, "verdict_key": "probing", "verdict": "Low-level probing", "verdict_why": [ "16 event(s), fewer than 10 distinct ports, no exploit payloads.", "Not in any known-scanner range.", "Sent 4,342 bytes despite few ports and no known exploit path: focused interaction with one service, worth a look." ], "verdict_confidence": "low", "cve_probes": [] } }, { "asn": "AS51852", "name": "PLI-AS", "ip": "179.43.150.26", "event_count": 16, "lookup": { "total_events": 16, "first_seen": "2026-08-31T15:32:52", "last_seen": "2026-08-31T16:49:55", "asn_number": 51852, "asn_org": "Private Layer INC", "country_name": "Switzerland", "country_code": "CH", "ports_targeted": [ 8443 ], "ports_targeted_count": 1, "tls_event_count": 0, "top_http_methods": [ "GET" ], "top_user_agents": [ "Mozilla/5.0" ], "top_url_paths": [ "/.env", "/z1356", "/s/1974", "/.e199", "/z1891", "/s/1688", "/.e3448", "/z945", "/s/7694", "/s/6254" ], "top_ja4_fingerprints": [], "top_ja3_fingerprints": [], "top_hassh_fingerprints": [], "client_cert_event_count": 0, "client_cert_subjects": [], "rdns": "hostedby.privatelayer.com", "loader_hits": 0, "exploit_hits": 4, "bytes_sent": 3470, "unique_source_ips": 1, "ioc": "179.43.150.26", "window": "last 7 days", "query_type": "ip", "scanner": null, "verdict_key": "malicious", "verdict": "Exploit attempts observed", "verdict_why": [ "4 request(s) matched a known exploit path.", "Exploit-path hits present; HTTP verb mix unknown, so read cautiously.", "Under 5 hits, so confidence is medium.", "Not in any known-scanner range." ], "verdict_confidence": "medium", "cve_probes": [] } }, { "asn": "AS51852", "name": "PLI-AS", "ip": "46.19.142.226", "event_count": 6, "lookup": { "total_events": 6, "first_seen": "2026-09-04T18:34:20", "last_seen": "2026-09-04T19:27:10", "asn_number": 51852, "asn_org": "Private Layer INC", "country_name": "Switzerland", "country_code": "CH", "ports_targeted": [ 2087 ], "ports_targeted_count": 1, "tls_event_count": 6, "top_http_methods": [ "GET", "POST" ], "top_user_agents": [ "Mozilla/5.0", "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" ], "top_url_paths": [ "/openid_connect/cpanelid", "/login/?login_only=1" ], "top_ja4_fingerprints": [ "t13i190800_9dc949149365_97f8aa674fd9" ], "top_ja3_fingerprints": [ "19e29534fd49dd27d09234e639c4057e" ], "top_hassh_fingerprints": [], "client_cert_event_count": 0, "client_cert_subjects": [], "rdns": "hostedby.privatelayer.com", "loader_hits": 0, "exploit_hits": 0, "bytes_sent": 944, "unique_source_ips": 1, "ioc": "46.19.142.226", "window": "last 7 days", "query_type": "ip", "scanner": null, "verdict_key": "probing", "verdict": "Low-level probing", "verdict_why": [ "6 event(s), fewer than 10 distinct ports, no exploit payloads.", "Not in any known-scanner range." ], "verdict_confidence": "low", "cve_probes": [ { "cve_id": "CVE-2026-41940", "title": "cPanel & WHM - Authentication Bypass via Session-File CRLF Injection", "severity": "CRITICAL", "actively_exploited": true } ] } }, { "asn": "AS51852", "name": "PLI-AS", "ip": "141.255.165.66", "event_count": 5, "lookup": { "total_events": 5, "first_seen": "2026-09-03T20:48:30", "last_seen": "2026-09-04T11:46:33", "asn_number": 51852, "asn_org": "Private Layer INC", "country_name": "Switzerland", "country_code": "CH", "ports_targeted": [ 1723 ], "ports_targeted_count": 1, "tls_event_count": 0, "top_http_methods": [], "top_user_agents": [], "top_url_paths": [], "top_ja4_fingerprints": [], "top_ja3_fingerprints": [], "top_hassh_fingerprints": [], "client_cert_event_count": 0, "client_cert_subjects": [], "rdns": "4soho.com", "loader_hits": 0, "exploit_hits": 0, "bytes_sent": 780, "unique_source_ips": 1, "ioc": "141.255.165.66", "window": "last 7 days", "query_type": "ip", "scanner": null, "verdict_key": "probing", "verdict": "Low-level probing", "verdict_why": [ "5 event(s), fewer than 10 distinct ports, no exploit payloads.", "Not in any known-scanner range." ], "verdict_confidence": "low", "cve_probes": [] } }, { "asn": "AS51396", "name": "PFCLOUD", "ip": "204.76.203.222", "event_count": 1159, "lookup": { "total_events": 1331, "first_seen": "2026-09-02T09:47:23", "last_seen": "2026-09-07T09:45:33", "asn_number": 51396, "asn_org": "Pfcloud UG (haftungsbeschrankt)", "country_name": "The Netherlands", "country_code": "NL", "ports_targeted": [ 5151, 10118, 11517, 2222, 10080, 50009, 7375, 52120, 50032, 11004, 11338, 2018, 8004, 11238, 8084, 10803, 6666, 13292, 9000, 6652, 9443, 11148, 5477, 56789, 10165, 30006, 10023, 30011, 10001, 5001, 2026, 11635, 11435, 11409, 2030, 6128, 11415, 6969, 20999, 8095, 9252, 13509, 5212, 8045, 50007, 9054, 12367, 32536, 3389, 9098 ], "ports_targeted_count": 879, "tls_event_count": 0, "top_http_methods": [], "top_user_agents": [], "top_url_paths": [], "top_ja4_fingerprints": [], "top_ja3_fingerprints": [], "top_hassh_fingerprints": [], "client_cert_event_count": 0, "client_cert_subjects": [], "rdns": "204.76.203.222.ptr.pfcloud.network", "loader_hits": 0, "exploit_hits": 0, "bytes_sent": 49337, "unique_source_ips": 1, "ioc": "204.76.203.222", "window": "last 7 days", "query_type": "ip", "scanner": null, "verdict_key": "scanning", "verdict": "Unrecognized scanner", "verdict_why": [ "No exploit payloads observed.", "Swept 879 distinct ports (threshold for a sweep is 10).", "Not in any known-scanner range." ], "verdict_confidence": "medium", "cve_probes": [] } }, { "asn": "AS51396", "name": "PFCLOUD", "ip": "204.76.203.221", "event_count": 1154, "lookup": { "total_events": 1332, "first_seen": "2026-09-02T09:47:23", "last_seen": "2026-09-07T09:47:47", "asn_number": 51396, "asn_org": "Pfcloud UG (haftungsbeschrankt)", "country_name": "The Netherlands", "country_code": "NL", "ports_targeted": [ 5477, 11617, 11918, 10080, 11587, 10231, 5918, 6588, 11416, 11000, 20898, 5507, 31280, 11181, 9258, 20274, 9040, 20132, 1083, 20621, 11081, 11111, 11528, 20023, 6685, 10031, 20038, 10023, 3129, 50008, 11338, 1080, 10109, 50028, 8225, 10000, 50019, 10157, 9898, 5513, 1058, 9999, 18505, 5108, 10034, 11404, 9422, 8045, 10432, 32260 ], "ports_targeted_count": 890, "tls_event_count": 0, "top_http_methods": [], "top_user_agents": [], "top_url_paths": [], "top_ja4_fingerprints": [], "top_ja3_fingerprints": [], "top_hassh_fingerprints": [], "client_cert_event_count": 0, "client_cert_subjects": [], "rdns": "204.76.203.221.ptr.pfcloud.network", "loader_hits": 0, "exploit_hits": 0, "bytes_sent": 47840, "unique_source_ips": 1, "ioc": "204.76.203.221", "window": "last 7 days", "query_type": "ip", "scanner": null, "verdict_key": "scanning", "verdict": "Unrecognized scanner", "verdict_why": [ "No exploit payloads observed.", "Swept 890 distinct ports (threshold for a sweep is 10).", "Not in any known-scanner range." ], "verdict_confidence": "medium", "cve_probes": [] } }, { "asn": "AS51396", "name": "PFCLOUD", "ip": "204.76.203.213", "event_count": 1123, "lookup": { "total_events": 1286, "first_seen": "2026-09-02T09:53:18", "last_seen": "2026-09-07T09:39:49", "asn_number": 51396, "asn_org": "Pfcloud UG (haftungsbeschrankt)", "country_name": "The Netherlands", "country_code": "NL", "ports_targeted": [ 11000, 5518, 20009, 5112, 11537, 20035, 11008, 50029, 56789, 31460, 4219, 2028, 3385, 1112, 10027, 10140, 5918, 11918, 10101, 4544, 20104, 10033, 30000, 10109, 10801, 9898, 20390, 8891, 10041, 11322, 10075, 25412, 49532, 34491, 50012, 17891, 50008, 20015, 20248, 11644, 33128, 9002, 1065, 6724, 18080, 10137, 11508, 10821, 20132, 31526 ], "ports_targeted_count": 872, "tls_event_count": 0, "top_http_methods": [], "top_user_agents": [], "top_url_paths": [], "top_ja4_fingerprints": [], "top_ja3_fingerprints": [], "top_hassh_fingerprints": [], "client_cert_event_count": 0, "client_cert_subjects": [], "rdns": "204.76.203.213.ptr.pfcloud.network", "loader_hits": 0, "exploit_hits": 0, "bytes_sent": 46038, "unique_source_ips": 1, "ioc": "204.76.203.213", "window": "last 7 days", "query_type": "ip", "scanner": null, "verdict_key": "scanning", "verdict": "Unrecognized scanner", "verdict_why": [ "No exploit payloads observed.", "Swept 872 distinct ports (threshold for a sweep is 10).", "Not in any known-scanner range." ], "verdict_confidence": "medium", "cve_probes": [] } }, { "asn": "AS216246", "name": "RU-AEZA-AS", "ip": "176.124.222.61", "event_count": 1, "lookup": { "total_events": 1, "first_seen": "2026-08-31T13:15:24", "last_seen": "2026-08-31T13:15:24", "asn_number": 216246, "asn_org": "Aeza Group LLC", "country_name": "Russia", "country_code": "RU", "ports_targeted": [ 5432 ], "ports_targeted_count": 1, "tls_event_count": 0, "top_http_methods": [], "top_user_agents": [], "top_url_paths": [], "top_ja4_fingerprints": [], "top_ja3_fingerprints": [], "top_hassh_fingerprints": [], "client_cert_event_count": 0, "client_cert_subjects": [], "rdns": "", "loader_hits": 0, "exploit_hits": 0, "bytes_sent": 8, "unique_source_ips": 1, "ioc": "176.124.222.61", "window": "last 7 days", "query_type": "ip", "scanner": null, "verdict_key": "probing", "verdict": "Low-level probing", "verdict_why": [ "1 event(s), fewer than 10 distinct ports, no exploit payloads.", "Not in any known-scanner range." ], "verdict_confidence": "low", "cve_probes": [] } }, { "asn": "AS216246", "name": "RU-AEZA-AS", "ip": "45.151.101.38", "event_count": 1, "lookup": { "total_events": 1, "first_seen": "2026-09-03T20:05:03", "last_seen": "2026-09-03T20:05:03", "asn_number": 216246, "asn_org": "Aeza Group LLC", "country_name": "Russia", "country_code": "RU", "ports_targeted": [ 8006 ], "ports_targeted_count": 1, "tls_event_count": 1, "top_http_methods": [ "POST" ], "top_user_agents": [ "Python-urllib/3.10" ], "top_url_paths": [ "/api2/json/access/ticket" ], "top_ja4_fingerprints": [ "t13i181000_85036bcba153_d41ae481755e" ], "top_ja3_fingerprints": [ "8a9d5d0f12f7d43ee3af1c51d2998d99" ], "top_hassh_fingerprints": [], "client_cert_event_count": 0, "client_cert_subjects": [], "rdns": "", "loader_hits": 0, "exploit_hits": 0, "bytes_sent": 263, "unique_source_ips": 1, "ioc": "45.151.101.38", "window": "last 7 days", "query_type": "ip", "scanner": null, "verdict_key": "probing", "verdict": "Low-level probing", "verdict_why": [ "1 event(s), fewer than 10 distinct ports, no exploit payloads.", "Not in any known-scanner range." ], "verdict_confidence": "low", "cve_probes": [ { "cve_id": "CVE-2023-54391", "title": "Proxmox VE - Default Credentials with TFA Bypass", "severity": "critical", "actively_exploited": false } ] } }, { "asn": "AS200651", "name": "FLOKINET", "ip": "185.100.87.136", "event_count": 24, "lookup": { "total_events": 22, "first_seen": "2026-09-01T12:25:00", "last_seen": "2026-09-07T09:47:19", "asn_number": 200651, "asn_org": "FlokiNET ehf", "country_name": "Romania", "country_code": "RO", "ports_targeted": [ 443, 8443 ], "ports_targeted_count": 2, "tls_event_count": 7, "top_http_methods": [ "GET", "POST" ], "top_user_agents": [ "SPARK COMMIT: 08059e95dacafe0bf6e5782f8e2c8ec9cd8c5a17", "Mozilla/5.0 (Windows NT 10.0; Win64; x64)", "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:104.71.6212.24) Gecko/25.2.4212.671 Firefox/2.0", "Mozilla/5.0 (Android 12; Mobile; rv:117.0) Gecko/117.0 Focus/117.0" ], "top_url_paths": [ "/api/checkin", "/", "/api/client/update?arch=amd64&commit=08059e95dacafe0bf6e5782f8e2c8ec9cd8c5a17&os=windows", "/eventmanager", "/images/transparentpix.gif" ], "top_ja4_fingerprints": [ "t13i1909h2_9dc949149365_97f8aa674fd9" ], "top_ja3_fingerprints": [ "7c1e207beb00684bbbe144f1b0abe1d5" ], "top_hassh_fingerprints": [], "client_cert_event_count": 0, "client_cert_subjects": [], "rdns": "", "loader_hits": 0, "exploit_hits": 0, "bytes_sent": 4631, "unique_source_ips": 1, "ioc": "185.100.87.136", "window": "last 7 days", "query_type": "ip", "scanner": null, "verdict_key": "probing", "verdict": "Low-level probing", "verdict_why": [ "22 event(s), fewer than 10 distinct ports, no exploit payloads.", "Not in any known-scanner range.", "Sent 4,631 bytes despite few ports and no known exploit path: focused interaction with one service, worth a look." ], "verdict_confidence": "low", "cve_probes": [] } }, { "asn": "AS198953", "name": "PROTON66", "ip": "176.120.22.61", "event_count": 1597, "lookup": { "total_events": 1634, "first_seen": "2026-08-31T11:36:25", "last_seen": "2026-09-07T09:23:19", "asn_number": 198953, "asn_org": "Proton66 OOO", "country_name": "Russia", "country_code": "RU", "ports_targeted": [ 11433, 5433, 2433, 15366, 2017, 22020, 35366, 23341, 1002, 13433, 37628, 5539, 7433, 1434, 7788, 5000, 5678, 40501, 1433, 14330, 2866, 9001, 18433, 41433, 1438, 55366, 3433, 1501, 1800, 15774, 8989, 9999, 1455, 42130, 6000, 5005, 21433, 8888, 7366, 4433, 5368, 1444, 16433, 22433, 19433, 1456, 6602, 51234, 6240, 2468 ], "ports_targeted_count": 270, "tls_event_count": 0, "top_http_methods": [], "top_user_agents": [], "top_url_paths": [], "top_ja4_fingerprints": [], "top_ja3_fingerprints": [], "top_hassh_fingerprints": [], "client_cert_event_count": 0, "client_cert_subjects": [], "rdns": "", "loader_hits": 0, "exploit_hits": 0, "bytes_sent": 129048, "unique_source_ips": 1, "ioc": "176.120.22.61", "window": "last 7 days", "query_type": "ip", "scanner": null, "verdict_key": "scanning", "verdict": "Unrecognized scanner", "verdict_why": [ "No exploit payloads observed.", "Swept 270 distinct ports (threshold for a sweep is 10).", "Not in any known-scanner range." ], "verdict_confidence": "medium", "cve_probes": [] } }, { "asn": "AS198953", "name": "PROTON66", "ip": "176.120.22.240", "event_count": 45, "lookup": { "total_events": 60, "first_seen": "2026-09-01T05:50:24", "last_seen": "2026-09-07T03:25:20", "asn_number": 198953, "asn_org": "Proton66 OOO", "country_name": "Russia", "country_code": "RU", "ports_targeted": [ 4443, 8443, 10443, 500, 1701, 443, 3799, 8013, 47, 1812, 1813, 4500, 8014, 1443, 2443, 11443 ], "ports_targeted_count": 16, "tls_event_count": 60, "top_http_methods": [ "GET" ], "top_user_agents": [ "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:74.0) Gecko/20100101 Firefox/74.0 - github.com/anasbousselham/)" ], "top_url_paths": [ "/remote/login?lang=en", "/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession" ], "top_ja4_fingerprints": [ "t12i210600_76e208dd3e22_f28add8e7af0", "t13i190800_9dc949149365_97f8aa674fd9" ], "top_ja3_fingerprints": [ "c12f54a3f91dc7bafd92cb59fe009a35", "89be98bbd4f065fe510fca4893cf8d9b" ], "top_hassh_fingerprints": [], "client_cert_event_count": 0, "client_cert_subjects": [], "rdns": "", "loader_hits": 0, "exploit_hits": 0, "bytes_sent": 8294, "unique_source_ips": 1, "ioc": "176.120.22.240", "window": "last 7 days", "query_type": "ip", "scanner": null, "verdict_key": "scanning", "verdict": "Unrecognized scanner", "verdict_why": [ "No exploit payloads observed.", "Swept 16 distinct ports (threshold for a sweep is 10).", "Not in any known-scanner range." ], "verdict_confidence": "medium", "cve_probes": [ { "cve_id": "CVE-2018-13379", "title": "Fortinet FortiOS SSL VPN path traversal", "severity": "critical", "actively_exploited": true } ] } }, { "asn": "AS198953", "name": "PROTON66", "ip": "193.143.1.66", "event_count": 24, "lookup": { "total_events": 24, "first_seen": "2026-08-31T18:27:14", "last_seen": "2026-09-04T21:27:35", "asn_number": 198953, "asn_org": "Proton66 OOO", "country_name": "Russia", "country_code": "RU", "ports_targeted": [ 3389, 3384, 3349, 33894 ], "ports_targeted_count": 4, "tls_event_count": 0, "top_http_methods": [], "top_user_agents": [], "top_url_paths": [], "top_ja4_fingerprints": [], "top_ja3_fingerprints": [], "top_hassh_fingerprints": [], "client_cert_event_count": 0, "client_cert_subjects": [], "rdns": "", "loader_hits": 0, "exploit_hits": 0, "bytes_sent": 1056, "unique_source_ips": 1, "ioc": "193.143.1.66", "window": "last 7 days", "query_type": "ip", "scanner": null, "verdict_key": "probing", "verdict": "Low-level probing", "verdict_why": [ "24 event(s), fewer than 10 distinct ports, no exploit payloads.", "Not in any known-scanner range." ], "verdict_confidence": "low", "cve_probes": [] } } ]