{"ip":"104.221.131.162","total_events":2,"verdict":{"verdict":"probing","label":"Low-level probing","detail":null,"confidence":"low","network_type":null,"why":["2 event(s), fewer than 10 distinct ports, no exploit payloads.","Not in any known-scanner range."],"engagement":{"level":"request","label":"Request traffic","detail":"449 bytes sent","bytes_sent":449,"session_seconds":0,"persistent":false}},"first_seen":"2026-08-20T22:10:36","last_seen":"2026-08-21T00:22:23","events_24h":2,"events_7d":2,"geo":{"country_code":"US","country_name":"United States","region":"","city":"","lat":37.751,"lon":-97.822,"asn":22552,"org":"eSited Solutions"},"source_domain":null,"known_scanners":[],"scanner_tag":null,"cve_matches":[{"cve_id":"CVE-2026-19900","title":"LB-LINK Routers - Unauthenticated Command Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/goform/set_cmd"}],"malware":[],"top_ports":[{"port":8081,"proto":"tcp","label":"","count":2}],"fingerprints":{"ssh_hassh":[],"tls_ja4":[],"tls_ja3":[],"ja4h":["po11cn0600_4de96570f19e"]},"fingerprint_peers":{"po11cn0600_4de96570f19e":2},"user_agents":["Python-urllib/3.10"],"timeline":[{"date":"2026-08-20","count":1},{"date":"2026-08-21","count":1}],"recent_events":[{"timestamp":"2026-08-21T00:22:23","port":8081,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"identity\",\"connection\":\"close\",\"content-length\":\"7\",\"content-type\":\"application/x-www-form-urlencoded\",\"cookie\":\"x=1\",\"host\":\"<HONEYPOT>:8081\",\"user-agent\":\"Python-urllib/3.10\"}","body":"cmd=pwd","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/goform/set_cmd","summary":"","payload_hex":"504f5354202f676f666f726d2f7365745f636d6420485454502f312e310d0a4163636570742d456e636f64696e673a206964656e746974790d0a436f6e74656e742d4c656e6774683a20370d0a486f73743a20<HONEYPOT>3a383038310d0a557365722d4167656e743a20507974686f6e2d75726c6c69622f332e31300d0a436f6e74656e742d547970653a206170706c69636174696f6e2f782d7777772d666f726d2d75726c656e636f6465640d0a436f6f6b69653a20783d310d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a636d643d707764","method":"POST","user_agent":"Python-urllib/3.10","ja3":"","session":"c6c8a6bc-5602-4832-8bfc-26e866441dad","seq":1,"duration_ms":100,"bytes_in":225,"bytes_out":80},{"timestamp":"2026-08-20T22:10:36","port":8081,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"identity\",\"connection\":\"close\",\"content-length\":\"7\",\"content-type\":\"application/x-www-form-urlencoded\",\"cookie\":\"x=1\",\"host\":\"<HONEYPOT>:8081\",\"user-agent\":\"Python-urllib/3.10\"}","body":"cmd=pwd","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/goform/set_cmd","summary":"","payload_hex":"504f5354202f676f666f726d2f7365745f636d6420485454502f312e310d0a4163636570742d456e636f64696e673a206964656e746974790d0a436f6e74656e742d4c656e6774683a20370d0a486f73743a20<HONEYPOT>3a383038310d0a557365722d4167656e743a20507974686f6e2d75726c6c69622f332e31300d0a436f6e74656e742d547970653a206170706c69636174696f6e2f782d7777772d666f726d2d75726c656e636f6465640d0a436f6f6b69653a20783d310d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a636d643d707764","method":"POST","user_agent":"Python-urllib/3.10","ja3":"","session":"23300a30-91d4-4554-87a1-55d9dc2d76cd","seq":1,"duration_ms":100,"bytes_in":224,"bytes_out":80}],"http_methods":[{"method":"POST","count":2}],"distinct_ports_total":1,"top_paths":[{"path":"/goform/set_cmd","count":2,"ports":1}],"distinct_paths_total":1,"top_snis":[],"top_hosts":[],"top_alpns":[],"banners":[],"credentials":[],"header_profile":{"signature":["Accept-Encoding","Connection","Content-Length","Content-Type","Cookie","Host","User-Agent"],"representative":[{"name":"Accept-Encoding","value":"identity","notable":false},{"name":"Connection","value":"close","notable":false},{"name":"Content-Length","value":"7","notable":false},{"name":"Content-Type","value":"application/x-www-form-urlencoded","notable":true},{"name":"Cookie","value":"x=1","notable":true},{"name":"Host","value":"<HONEYPOT>:8081","notable":false},{"name":"User-Agent","value":"Python-urllib/3.10","notable":false}],"distinct_sets":1,"events_with_headers":2},"tags":[{"tag_id":"CVE-2026-19900","tag_type":"cve","title":"LB-LINK Routers - Unauthenticated Command Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/goform/set_cmd","reference_urls":["https://github.com/glkfc/IoT-Vulnerability/blob/main/LB-LINK/LB-LINK_cmd%20Indicates%20the%20unauthorized%20command%20injection/The%20LB-LINK_cmd%20command%20is%20used%20to%20inject%20information.md","https://nvd.nist.gov/vuln/detail/CVE-2026-19900"]}],"data_as_of":"2026-08-21T00:31:50.968597+00:00"}