{"ip":"135.119.38.57","total_events":2,"verdict":{"verdict":"probing","label":"Low-level probing","detail":null,"confidence":"low","network_type":"CDN","why":["2 event(s), fewer than 10 distinct ports, no exploit payloads.","Not in any known-scanner range."],"engagement":{"level":"request","label":"Request traffic","detail":"244 bytes sent","bytes_sent":244,"session_seconds":0,"persistent":false}},"first_seen":"2026-09-08T05:52:50","last_seen":"2026-09-08T05:52:50","events_24h":0,"events_7d":2,"geo":{"country_code":"US","country_name":"United States","region":"Iowa","city":"Des Moines","lat":41.6015,"lon":-93.6127,"asn":8075,"org":"Microsoft Corporation"},"source_domain":null,"known_scanners":[],"scanner_tag":{"key":"peeringdb:as8075","label":"Microsoft","category":"cdn","url":"https://www.peeringdb.com/asn/8075"},"cve_matches":[{"cve_id":"CVE-2026-35029","title":"LiteLLM - Arbitrary File Read","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/health/liveliness"}],"malware":[],"top_ports":[{"port":4000,"proto":"tcp","label":"","count":2}],"fingerprints":{"ssh_hassh":[],"tls_ja4":[],"tls_ja3":[],"ja4h":["ge11nn0400_9c3956fad5da"]},"fingerprint_peers":{"ge11nn0400_9c3956fad5da":1583},"user_agents":["curl/8.18.0"],"timeline":[{"date":"2026-09-08","count":2}],"recent_events":[{"timestamp":"2026-09-08T05:52:50","port":4000,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip\",\"connection\":\"close\",\"host\":\"<HONEYPOT>\",\"user-agent\":\"curl/8.18.0\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/health/liveliness","summary":"","payload_hex":"474554202f6865616c74682f6c6976656c696e65737320485454502f312e310d0a486f73743a20<HONEYPOT>0d0a557365722d4167656e743a206375726c2f382e31382e300d0a4163636570742d456e636f64696e673a20677a69700d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a","method":"GET","user_agent":"curl/8.18.0","ja3":"","session":"ee5e4371-d96c-4da7-95d4-84900cfe46ac","seq":1,"duration_ms":100,"bytes_in":122,"bytes_out":78},{"timestamp":"2026-09-08T05:52:50","port":4000,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip\",\"connection\":\"close\",\"host\":\"<HONEYPOT>\",\"user-agent\":\"curl/8.18.0\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/health/liveliness","summary":"","payload_hex":"474554202f6865616c74682f6c6976656c696e65737320485454502f312e310d0a486f73743a20<HONEYPOT>0d0a557365722d4167656e743a206375726c2f382e31382e300d0a4163636570742d456e636f64696e673a20677a69700d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a","method":"GET","user_agent":"curl/8.18.0","ja3":"","session":"4f911850-96d7-4600-8fbc-c9f39b5d1a21","seq":1,"duration_ms":100,"bytes_in":122,"bytes_out":78}],"http_methods":[{"method":"GET","count":2}],"distinct_ports_total":1,"top_paths":[{"path":"/health/liveliness","count":2,"ports":1}],"distinct_paths_total":1,"top_snis":[],"top_hosts":[],"top_alpns":[],"banners":[],"credentials":[],"header_profile":{"signature":["Accept-Encoding","Connection","Host","User-Agent"],"representative":[{"name":"Accept-Encoding","value":"gzip","notable":false},{"name":"Connection","value":"close","notable":false},{"name":"Host","value":"<HONEYPOT>","notable":false},{"name":"User-Agent","value":"curl/8.18.0","notable":false}],"distinct_sets":1,"events_with_headers":2},"tags":[{"tag_id":"CVE-2026-35029","tag_type":"cve","title":"LiteLLM - Arbitrary File Read","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/health/liveliness","reference_urls":["https://github.com/BerriAI/litellm","https://sec-consult.com/vulnerability-lab/advisory/broken-access-control-in-config-endpoint-in-litellm/","https://nvd.nist.gov/vuln/detail/CVE-2026-35029"]}],"data_as_of":"2026-09-10T21:19:37.618424+00:00"}