{"ip":"146.70.211.67","total_events":1,"verdict":{"verdict":"probing","label":"Low-level probing","detail":null,"confidence":"low","network_type":"nsp","why":["1 event(s), fewer than 10 distinct ports, no exploit payloads.","Not in any known-scanner range."],"engagement":{"level":"request","label":"Request traffic","detail":"137 bytes sent","bytes_sent":137,"session_seconds":0,"persistent":false}},"first_seen":"2026-09-08T23:09:24","last_seen":"2026-09-08T23:09:24","events_24h":0,"events_7d":1,"geo":{"country_code":"US","country_name":"United States","region":"Texas","city":"Dallas","lat":32.7889,"lon":-96.8021,"asn":9009,"org":"M247 Europe SRL"},"source_domain":null,"known_scanners":[],"scanner_tag":{"key":"peeringdb:as9009","label":"M247 Global","category":"isp","url":"https://www.peeringdb.com/asn/9009"},"cve_matches":[{"cve_id":"CVE-2024-25723","title":"ZenML ZenML Server - Improper Authentication","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/v1/info"}],"malware":[],"top_ports":[{"port":11434,"proto":"tcp","label":"","count":1}],"fingerprints":{"ssh_hassh":[],"tls_ja4":[],"tls_ja3":[],"ja4h":["ge11nn0400_ef4d07580f66"]},"fingerprint_peers":{"ge11nn0400_ef4d07580f66":2739},"user_agents":["Go-http-client/1.1"],"timeline":[{"date":"2026-09-08","count":1}],"recent_events":[{"timestamp":"2026-09-08T23:09:24","port":11434,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip\",\"connection\":\"close\",\"host\":\"<HONEYPOT>:11434\",\"user-agent\":\"Go-http-client/1.1\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/api/v1/info/version","summary":"","payload_hex":"474554202f6170692f76312f696e666f2f76657273696f6e20485454502f312e310d0a486f73743a20<HONEYPOT>3a31313433340d0a557365722d4167656e743a20476f2d687474702d636c69656e742f312e310d0a436f6e6e656374696f6e3a20636c6f73650d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Go-http-client/1.1","ja3":"","session":"844bd9ea-4896-4436-9436-b199d058051e","seq":1,"duration_ms":100,"bytes_in":137,"bytes_out":78}],"http_methods":[{"method":"GET","count":1}],"distinct_ports_total":1,"top_paths":[{"path":"/api/v1/info/version","count":1,"ports":1}],"distinct_paths_total":1,"top_snis":[],"top_hosts":[],"top_alpns":[],"banners":[],"credentials":[],"header_profile":{"signature":["Accept-Encoding","Connection","Host","User-Agent"],"representative":[{"name":"Accept-Encoding","value":"gzip","notable":false},{"name":"Connection","value":"close","notable":false},{"name":"Host","value":"<HONEYPOT>:11434","notable":false},{"name":"User-Agent","value":"Go-http-client/1.1","notable":false}],"distinct_sets":1,"events_with_headers":1},"tags":[{"tag_id":"CVE-2024-25723","tag_type":"cve","title":"ZenML ZenML Server - Improper Authentication","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/v1/info","reference_urls":["https://www.zenml.io/blog/critical-security-update-for-zenml-users","https://github.com/zenml-io/zenml","https://github.com/zenml-io/zenml/compare/0.42.1...0.42.2","https://github.com/zenml-io/zenml/compare/0.43.0...0.43.1","https://github.com/zenml-io/zenml/compare/0.44.3...0.44.4"]}],"data_as_of":"2026-09-10T21:19:17.187372+00:00"}