{"ip":"108.165.123.63","total_events":4,"verdict":{"verdict":"probing","label":"Low-level probing","detail":null,"confidence":"low","network_type":"CDN","why":["4 event(s), fewer than 10 distinct ports, no exploit payloads.","Not in any known-scanner range."],"engagement":{"level":"request","label":"Request traffic","detail":"280 bytes sent","bytes_sent":280,"session_seconds":0,"persistent":false}},"first_seen":"2026-08-14T16:27:05","last_seen":"2026-08-14T16:27:51","events_24h":0,"events_7d":4,"geo":{"country_code":"US","country_name":"United States","region":"","city":"","lat":37.751,"lon":-97.822,"asn":399646,"org":"Snaju Development"},"source_domain":"mail.tryviralityto.com","known_scanners":[],"scanner_tag":{"key":"peeringdb:as399646","label":"DartNode.com","category":"cdn","url":"https://www.peeringdb.com/asn/399646"},"cve_matches":[{"cve_id":"CVE-2020-13945","title":"Apache APISIX - Insufficiently Protected Credentials","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/apisix/admin/routes"}],"malware":[],"top_ports":[{"port":9080,"proto":"tcp","label":"","count":2},{"port":2379,"proto":"tcp","label":"","count":2}],"fingerprints":{"ssh_hassh":[],"tls_ja4":[],"tls_ja3":[],"ja4h":["ge11nn0200_f24fcf356134"]},"fingerprint_peers":{"ge11nn0200_f24fcf356134":45},"user_agents":[],"timeline":[{"date":"2026-08-14","count":4}],"recent_events":[{"timestamp":"2026-08-14T16:27:51","port":9080,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"connection\":\"close\",\"host\":\"<HONEYPOT>\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/apisix/admin/routes","summary":"","payload_hex":"474554202f6170697369782f61646d696e2f726f7574657320485454502f312e310d0a486f73743a20<HONEYPOT>0d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a","method":"GET","user_agent":"","ja3":"","session":"c888b56c-e609-4db3-a8aa-d11f75dd3675","seq":1,"duration_ms":101,"bytes_in":76,"bytes_out":79},{"timestamp":"2026-08-14T16:27:46","port":9080,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"connection\":\"close\",\"host\":\"<HONEYPOT>\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/apisix/admin/routes","summary":"","payload_hex":"474554202f6170697369782f61646d696e2f726f7574657320485454502f312e310d0a486f73743a20<HONEYPOT>0d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a","method":"GET","user_agent":"","ja3":"","session":"79dae76e-11de-498a-9fc4-31cbe5a142bb","seq":1,"duration_ms":100,"bytes_in":76,"bytes_out":79},{"timestamp":"2026-08-14T16:27:13","port":2379,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"connection\":\"close\",\"host\":\"<HONEYPOT>\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/version","summary":"","payload_hex":"474554202f76657273696f6e20485454502f312e310d0a486f73743a20<HONEYPOT>0d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a","method":"GET","user_agent":"","ja3":"","session":"8c205fc1-514c-46b4-82a3-c25007e0bfea","seq":1,"duration_ms":100,"bytes_in":64,"bytes_out":79},{"timestamp":"2026-08-14T16:27:05","port":2379,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"connection\":\"close\",\"host\":\"<HONEYPOT>\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/version","summary":"","payload_hex":"474554202f76657273696f6e20485454502f312e310d0a486f73743a20<HONEYPOT>0d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a","method":"GET","user_agent":"","ja3":"","session":"1e2c125c-e585-4ec6-bb82-4f1e9e841ce8","seq":1,"duration_ms":100,"bytes_in":64,"bytes_out":79}],"http_methods":[{"method":"GET","count":4}],"distinct_ports_total":2,"top_paths":[{"path":"/version","count":2,"ports":1},{"path":"/apisix/admin/routes","count":2,"ports":1}],"distinct_paths_total":2,"top_snis":[],"top_hosts":[],"top_alpns":[],"banners":[],"credentials":[],"header_profile":{"signature":["Connection","Host"],"representative":[{"name":"Connection","value":"close","notable":false},{"name":"Host","value":"<HONEYPOT>","notable":false}],"distinct_sets":1,"events_with_headers":4},"tags":[{"tag_id":"CVE-2020-13945","tag_type":"cve","title":"Apache APISIX - Insufficiently Protected Credentials","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/apisix/admin/routes","reference_urls":["https://github.com/vulhub/vulhub/tree/master/apisix/CVE-2020-13945","https://lists.apache.org/thread.html/r792feb29964067a4108f53e8579a1e9bd1c8b5b9bc95618c814faf2f%40%3Cdev.apisix.apache.org%3E","http://packetstormsecurity.com/files/166228/Apache-APISIX-Remote-Code-Execution.html","https://nvd.nist.gov/vuln/detail/CVE-2020-13945","https://github.com/ARPSyndicate/cvemon"]}],"data_as_of":"2026-08-20T22:11:54.626274+00:00"}