1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
|
{
"total_events": 148,
"first_seen": "2026-08-20T14:44:13",
"last_seen": "2026-08-25T23:21:07",
"asn_number": 14956,
"asn_org": "RouterHosting LLC",
"country_name": "The Netherlands",
"country_code": "NL",
"ports_targeted": [
80,
2375
],
"ports_targeted_count": 2,
"tls_event_count": 0,
"top_http_methods": [
"GET",
"POST"
],
"top_user_agents": [
"libredtail-http"
],
"top_url_paths": [
"/containers/json",
"/crm/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
"/cms/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
"/demo/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
"/ws/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
"/testing/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
"/test/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
"/api/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
"/zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
"/tests/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"
],
"top_ja4_fingerprints": [],
"top_ja3_fingerprints": [],
"top_hassh_fingerprints": [],
"client_cert_event_count": 0,
"client_cert_subjects": [],
"rdns": "103.26.189.107.static.cloudzy.com",
"loader_hits": 6,
"exploit_hits": 135,
"bytes_sent": 1826936,
"unique_source_ips": 1,
"ioc": "107.189.26.103",
"window": "all retained data (no time filter)",
"query_type": "ip",
"scanner": null,
"verdict_key": "malicious",
"verdict": "Exploit attempts observed",
"verdict_why": [
"135 request(s) matched a known exploit path.",
"Exploit-path hits present; HTTP verb mix unknown, so read cautiously.",
"5+ hits raise confidence to high.",
"Not in any known-scanner range.",
"Sent 1,826,936 bytes: sustained payload delivery, not a single opportunistic request."
],
"verdict_confidence": "high",
"cve_probes": [
{
"cve_id": "CVE-2017-9841",
"title": "PHPUnit - Remote Code Execution",
"severity": "critical",
"actively_exploited": true
},
{
"cve_id": "CVE-2021-42013",
"title": "Apache 2.4.49/2.4.50 - Path Traversal and Remote Code Execution",
"severity": "critical",
"actively_exploited": true
}
]
}
|