{"ip":"103.230.85.236","total_events":2,"verdict":{"verdict":"probing","label":"Low-level probing","detail":null,"confidence":"low","network_type":null,"why":["2 event(s), fewer than 10 distinct ports, no exploit payloads.","Not in any known-scanner range."],"engagement":{"level":"request","label":"Request traffic","detail":"368 bytes sent","bytes_sent":368,"session_seconds":0,"persistent":false}},"first_seen":"2026-09-27T21:42:58","last_seen":"2026-09-27T21:42:59","events_24h":0,"events_7d":2,"geo":{"country_code":"IN","country_name":"India","region":"","city":"","lat":21.9974,"lon":79.0011,"asn":132717,"org":"NxtGen Datacenter & Cloud Technologies Pvt. Ltd."},"source_domain":null,"known_scanners":[],"scanner_tag":null,"cve_matches":[{"cve_id":"CVE-2026-41940","title":"cPanel & WHM - Authentication Bypass via Session-File CRLF Injection","severity":"CRITICAL","actively_exploited":true,"match_field":"url_path","matched_pattern":"/login/?login_only=1"}],"malware":[],"top_ports":[{"port":2087,"proto":"tcp","label":"","count":2}],"fingerprints":{"ssh_hassh":[],"tls_ja4":["t13i130900_f57a46bbacb6_e7c285222651"],"tls_client_hello":"16030105a8010005a403038894831f9433ef264d41c48490a1af982c11046383fcc17f0e652764bd16b8a120d52da0bd14c86d6658a5f82bfab8ad165e29c6796a9318942f1b36cf99978bff001ac02bc02fc02cc030cca9cca8c009c013c00ac01413011302130301000541000b00020100ff010001000017000000120000000500050100000000000a000c000a11ec001d001700180019000d001a0018080404030807080508060401050106010503060302010203002b00050403040303003304ea04e811ec04c03e689a94252f47f07f70747eab4848d516752459b393e26d8a52465729bd50198f74062dbae9715ecb9a952c419d63a91bc536c67b1f0e43cba2d700b9569ee30971a53612feb794c3b73f200756b8769cb0ca9161f6b67c7096749194199491f0477f9ac55be96b48da69cef6cba0b9c68d43c83fe242cb9d30306c5a027501531ff887a1124035756c493916fb807212351524b582665b11f59a9e2290aab778b09440458d4bb291a853762a8c822443b073c44f6b8cfd5182ef52b272c1c47ba7a5527b47400b8564007e100282b2e5525bd2bb8aa39cedb0b5bac5ba45124e8bf7028ffa9823411eaec1659b926b87c8a854d59ff3cb9532273a6ef6bad5dc5bcf673f52913236a4b9d15052fb6281d9944c65567fc877138a23cd06c65f50b57f1043659b0892e1a63c9285563c387fc8e3acec98810774cd20b92067a68d545956bd4b891935b2238cb3b30b11d7c124976b1e2d8b3bc12bc45bd6c20a2c2beff795fbc26db0072a2bd100883aa22a52689efc623ed44961f18f9a519e81673882d53b87599f97abc89ab4761e0ba1d82ba6987c8ea825c8ac6050dd55799eda98289c060ae6a9099a40c2ca0b663c9dc7139db477936d85207be4c286b1b758a9aaf2833f4c81941c1420099c28219bb96ae17ba2a86056ca0b76853e3107d0389c766168abcc003034d52a72cccd1385531978974e6ca8ab369ae93802afcb64cf37bbbabb215d5c9a51f66dc7386aaab5b167b2365b98bdff638115d9b64e103882d923124ca329f195e35b51f3dac16d487db05b96504b484ef1272410339935868b84022e683a158bb93cc4246935933d597f0b2411c13b832f47bb119ab567b99410d26309d731abb981a47b7c7867065472acc8908858e11a9e3739d9fb42331106020160237b8493b8c381d29c087808f44b1d899c8f2c41ad3deb542f116fb41406aab3a4f2e3207e48b5041a795a715cf2712c078724adaaa7912a7d9fc7c972a00fe997c936016588141151d50f299c067b633eb8d8870bc441477c8c4ebc9c29b01f5c22357f16328e851ff091897f0abd8780b756487dcd62a30b6a42a627348ca0aaa7b11c8fb657eb2c435fc59a5955afb5395b65e8906bfbc5bb1a7b77412ee58396f34c607b802762622ee3402734c674a2a3b44dc4c82ff8aaaf982329268099312907b0ac00fb6e418613f9ec8ca97752bf550970bbb7769687ba041a42b90d688b62a0889507800716c012cc34aee2364b03782076c3b435824fe316350a68a522d520fd2c398b7035018456f1b7b8c8c4251010bfd98459f9e5827ab23dce3763836b916f302df7a163c460beb70b664a09519e5b76a36b5c313a6b877185fac74e2e190151b31a4c240648c7961e43898ea43a89a57449e11733aa5def2715abd336b8e58f5849726213719c8c0c35715d2a1010f657c77adb39a13055ddec68d4d68e593cb15821b0f3f3c05f5c1d71d42cd74cb5a2a2c53c926e17518b6607024074abd6520c30bb38bb6baa35f78b035c5aaf5875b3c2b994bc312827534b85054ef249a4337f65a19083488c21d77eaf887fbc9197d3f94cc5d583ecd6655a5911443910d2d66b274955c34b96858761c11dbd535e4923a05b45561c33f7e9a9b150246e4f3a3b3a9660c0477deafd47f868d7ba22dd652873947bafead9d5b397ad239feedbac4851f245d5faf40005001d0020f868d7ba22dd652873947bafead9d5b397ad239feedbac4851f245d5faf40005","tls_ja3":["6639916abfac56b9257ca216677085bc"],"http_akin":["a11cuq060_0000064e_be5a5cc7","a11cun040_0000004e_36fbce14"]},"fingerprint_peers":{"t13i130900_f57a46bbacb6_e7c285222651":3839,"a11cun040_0000004e_36fbce14":1907,"a11cuq060_0000064e_be5a5cc7":6},"akin_families":{"a11cun040_0000004e_36fbce14":{"head":"a11cun040_0000004e_36fbce14","shapes":4,"ips":1913}},"user_agents":["Go-http-client/1.1"],"timeline":[{"date":"2026-09-27","count":2}],"recent_events":[{"timestamp":"2026-09-27T21:42:59","port":2087,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip\",\"connection\":\"close\",\"content-length\":\"20\",\"content-type\":\"application/x-www-form-urlencoded\",\"host\":\"<HONEYPOT>:2087\",\"user-agent\":\"Go-http-client/1.1\"}","body":"pass=wrong&user=root","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/login/?login_only=1","summary":"","payload_hex":"504f5354202f6c6f67696e2f3f6c6f67696e5f6f6e6c793d3120485454502f312e310d0a486f73743a20<HONEYPOT>3a323038370d0a557365722d4167656e743a20476f2d687474702d636c69656e742f312e310d0a436f6e74656e742d4c656e6774683a2032300d0a436f6e6e656374696f6e3a20636c6f73650d0a436f6e74656e742d547970653a206170706c69636174696f6e2f782d7777772d666f726d2d75726c656e636f6465640d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a706173733d77726f6e6726757365723d726f6f74","method":"POST","user_agent":"Go-http-client/1.1","ja3":"6639916abfac56b9257ca216677085bc","session":"c912993b-6f4a-4896-855d-701f2c709b7e","seq":1,"duration_ms":100,"bytes_in":227,"bytes_out":79},{"timestamp":"2026-09-27T21:42:58","port":2087,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip\",\"connection\":\"close\",\"host\":\"<HONEYPOT>:2087\",\"user-agent\":\"Go-http-client/1.1\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/openid_connect/cpanelid","summary":"","payload_hex":"474554202f6f70656e69645f636f6e6e6563742f6370616e656c696420485454502f312e310d0a486f73743a20<HONEYPOT>3a323038370d0a557365722d4167656e743a20476f2d687474702d636c69656e742f312e310d0a436f6e6e656374696f6e3a20636c6f73650d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Go-http-client/1.1","ja3":"6639916abfac56b9257ca216677085bc","session":"51586326-3062-4e55-bc9c-b9bc3b7cc0e5","seq":1,"duration_ms":100,"bytes_in":141,"bytes_out":79}],"http_methods":[{"method":"GET","count":1},{"method":"POST","count":1}],"distinct_ports_total":1,"top_paths":[{"path":"/login/?login_only=1","count":1,"ports":1},{"path":"/openid_connect/cpanelid","count":1,"ports":1}],"distinct_paths_total":2,"top_snis":[],"top_hosts":[],"top_alpns":[],"banners":[],"credentials":[{"username":"root","password":"wrong","count":1}],"header_profile":{"signature":["Accept-Encoding","Connection","Content-Length","Content-Type","Host","User-Agent"],"representative":[{"name":"Accept-Encoding","value":"gzip","notable":false},{"name":"Connection","value":"close","notable":false},{"name":"Content-Length","value":"20","notable":false},{"name":"Content-Type","value":"application/x-www-form-urlencoded","notable":true},{"name":"Host","value":"<HONEYPOT>:2087","notable":false},{"name":"User-Agent","value":"Go-http-client/1.1","notable":false}],"distinct_sets":2,"events_with_headers":2},"tags":[{"tag_id":"CVE-2026-41940","tag_type":"cve","title":"cPanel & WHM - Authentication Bypass via Session-File CRLF Injection","severity":"CRITICAL","actively_exploited":true,"match_field":"url_path","matched_pattern":"/login/?login_only=1","reference_urls":[]}],"data_as_of":"2026-09-29T14:11:10.366512+00:00"}