aboutsummaryrefslogtreecommitdiff
path: root/kevlar/2026-08-31/honeylabs/ioc-107.189.26.103.json
blob: 3be0330adadeae3acdbc3a1558532ec46315c2fb (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
{
 "total_events": 148,
 "first_seen": "2026-08-20T14:44:13",
 "last_seen": "2026-08-25T23:21:07",
 "asn_number": 14956,
 "asn_org": "RouterHosting LLC",
 "country_name": "The Netherlands",
 "country_code": "NL",
 "ports_targeted": [
  80,
  2375
 ],
 "ports_targeted_count": 2,
 "tls_event_count": 0,
 "top_http_methods": [
  "GET",
  "POST"
 ],
 "top_user_agents": [
  "libredtail-http"
 ],
 "top_url_paths": [
  "/containers/json",
  "/crm/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
  "/cms/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
  "/demo/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
  "/ws/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
  "/testing/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
  "/test/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
  "/api/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
  "/zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php",
  "/tests/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"
 ],
 "top_ja4_fingerprints": [],
 "top_ja3_fingerprints": [],
 "top_hassh_fingerprints": [],
 "client_cert_event_count": 0,
 "client_cert_subjects": [],
 "rdns": "103.26.189.107.static.cloudzy.com",
 "loader_hits": 6,
 "exploit_hits": 135,
 "bytes_sent": 1826936,
 "unique_source_ips": 1,
 "ioc": "107.189.26.103",
 "window": "all retained data (no time filter)",
 "query_type": "ip",
 "scanner": null,
 "verdict_key": "malicious",
 "verdict": "Exploit attempts observed",
 "verdict_why": [
  "135 request(s) matched a known exploit path.",
  "Exploit-path hits present; HTTP verb mix unknown, so read cautiously.",
  "5+ hits raise confidence to high.",
  "Not in any known-scanner range.",
  "Sent 1,826,936 bytes: sustained payload delivery, not a single opportunistic request."
 ],
 "verdict_confidence": "high",
 "cve_probes": [
  {
   "cve_id": "CVE-2017-9841",
   "title": "PHPUnit - Remote Code Execution",
   "severity": "critical",
   "actively_exploited": true
  },
  {
   "cve_id": "CVE-2021-42013",
   "title": "Apache 2.4.49/2.4.50 - Path Traversal and Remote Code Execution",
   "severity": "critical",
   "actively_exploited": true
  }
 ]
}