{"ip":"147.182.171.19","total_events":175,"verdict":{"verdict":"scanner","label":"Recognized scanner","detail":"binaryedge","confidence":"high","network_type":"CDN","why":["Source IP is in a known scanner range (binaryedge).","Known research and commercial scanners are labelled as such, not as threats."]},"first_seen":"2026-07-09T14:38:20","last_seen":"2026-07-17T20:40:23","events_24h":0,"events_7d":0,"geo":{"country_code":"US","country_name":"United States","region":"New Jersey","city":"North Bergen","lat":40.7964,"lon":-74.0203,"asn":14061,"org":"DigitalOcean, LLC"},"source_domain":"prod-fluorine-nyc1-12.do.binaryedge.ninja","known_scanners":["binaryedge","BinaryEdge"],"scanner_tag":{"key":"binaryedge","label":"BinaryEdge","category":"commercial","url":"https://www.binaryedge.io/"},"cve_matches":[{"cve_id":"CVE-2018-13379","title":"Fortinet FortiOS - Credentials Disclosure","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession"},{"cve_id":"CVE-2021-22205","title":"GitLab CE/EE - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/users/sign_in"},{"cve_id":"CVE-2022-40684","title":"Fortinet - Authentication Bypass","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/v2/cmdb/system/admin"},{"cve_id":"CVE-2023-40044","title":"WS_FTP Server - Insecure Deserialization","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/AHT/AHT_UI/public/js/app.min.js"},{"cve_id":"CVE-2024-0012","title":"PAN-OS Management Web Interface - Authentication Bypass","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/php/ztp_gate.php/.js.map"},{"cve_id":"CVE-2024-4040","title":"CrushFTP VFS - Sandbox Escape LFR","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/WebInterface"},{"cve_id":"CVE-2025-0282","title":"Ivanti Connect Secure - Stack-based Buffer Overflow","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/dana-na/auth/url_default/welcome.cgi"},{"cve_id":"CVE-2020-3452","title":"Cisco Adaptive Security Appliance (ASA)/Firepower Threat Defense (FTD) - Local File Inclusion","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/+CSCOT+/oem-customization?app=AnyConnect&type=oem&platform=..&resource-type=..&name=%2bCSCOE%2b/portal_inc.lua"},{"cve_id":"CVE-2023-7028","title":"GitLab - Account Takeover via Password Reset","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/users/sign_in"},{"cve_id":"CVE-2017-5983","title":"JIRA Workflow Designer Plugin in Atlassian JIRA Server > 6.3.0 - Remote Code Execution (XXE)","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/jira/secure/Dashboard.jspa"},{"cve_id":"CVE-2022-0735","title":"GitLab CE/EE - Information Disclosure","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/users/sign_in"},{"cve_id":"CVE-2022-1162","title":"GitLab CE/EE - Hard-Coded Credentials","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/users/sign_in"},{"cve_id":"CVE-2023-43177","title":"CrushFTP < 10.5.1 - Unauthenticated Remote Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/WebInterface"},{"cve_id":"CVE-2020-2036","title":"Palo Alto Networks PAN-OS Web Interface - Cross Site-Scripting","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/global-protect/login.esp"},{"cve_id":"CVE-2022-2185","title":"GitLab CE/EE - Remote Code Execution","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/users/sign_in"},{"cve_id":"CVE-2023-2825","title":"GitLab 16.0.0 - Path Traversal","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/users/sign_in"},{"cve_id":"CVE-2007-4556","title":"OpenSymphony XWork/Apache Struts2 - Remote Code Execution","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/login.action"},{"cve_id":"CVE-2019-11507","title":"Pulse Secure Pulse Connect Secure - Cross-Site Scripting (Reflected)","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/dana-na/auth/url_default/welcome.cgi"}],"malware":[],"top_ports":[{"port":443,"proto":"tcp","label":"HTTPS","count":78},{"port":85,"proto":"tcp","label":"","count":47},{"port":800,"proto":"tcp","label":"","count":46},{"port":3331,"proto":"tcp","label":"","count":3},{"port":587,"proto":"tcp","label":"SMTP","count":1}],"fingerprints":{"ssh_hassh":[],"tls_ja4":["t13i311000_e8f1e7e78f70_d41ae481755e","t13i3112h1_e8f1e7e78f70_d339722ba4af","t13i250800_b78ed14e2fd0_97f8aa674fd9"],"tls_ja3":["368c3a81b611306a0ee544d7aedaa231","c12b4ccd5320bbb380ca1a9df90f771d","48eb9b1182293f55c0710654b7b12fc6"],"ja4h":["ge10nn0000_000000000000","op10nn0000_000000000000","ge11nn0300_dedeb29cc523"]},"fingerprint_peers":{"t13i250800_b78ed14e2fd0_97f8aa674fd9":13,"t13i3112h1_e8f1e7e78f70_d339722ba4af":36,"t13i311000_e8f1e7e78f70_d41ae481755e":1032,"ge10nn0000_000000000000":2242,"op10nn0000_000000000000":1423,"ge11nn0300_dedeb29cc523":85},"user_agents":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36"],"timeline":[{"date":"2026-07-09","count":78},{"date":"2026-07-14","count":4},{"date":"2026-07-16","count":47},{"date":"2026-07-17","count":46}],"recent_events":[{"timestamp":"2026-07-17T20:40:23","port":800,"proto":"tcp","app_proto":"tls","app_protocol":"tls","host":"","headers":"","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"","summary":"\u0001I20100\n","payload_hex":"014932303130300a","method":"","user_agent":"","community_id":"1:ZwgV4Rc6j9jOV76eZyo4Z5XsCX4=","ja3":"c12b4ccd5320bbb380ca1a9df90f771d","session":"cb54f0b0-47e8-4471-b369-4faa56461b2a","seq":1,"duration_ms":120,"bytes_in":8,"bytes_out":14,"enriched":{"digest":"14b0bf5196552d7e","strings":["I20100"]}},{"timestamp":"2026-07-17T20:40:22","port":800,"proto":"tcp","app_proto":"tls","app_protocol":"tls","host":"","headers":"","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"","summary":"\u0000\u0000\u0000\u0000\u0000","payload_hex":"0000000000","method":"","user_agent":"","community_id":"1:f0sIC2BeJ3cIOuCXLkzT3tupXwA=","ja3":"c12b4ccd5320bbb380ca1a9df90f771d","session":"e91cdae5-b425-4318-9a13-86910692edb9","seq":1,"duration_ms":121,"bytes_in":5,"bytes_out":14},{"timestamp":"2026-07-17T20:40:20","port":800,"proto":"tcp","app_proto":"tls","app_protocol":"rdp","host":"","headers":"","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"","summary":"\u0003\u0000\u0000,'�\u0000\u0000\u0000\u0000\u0000Cookie: mstshash=Administrator\r\n\u0001\u0000\b\u0000\u0000\u0000\u0000\u0000","payload_hex":"0300002c27e00000000000436f6f6b69653a206d737473686173683d41646d696e6973747261746f720d0a0100080000000000","method":"","user_agent":"","community_id":"1:9kuvhtcuNTqe+dnicGvxOz5Z4qc=","ja3":"c12b4ccd5320bbb380ca1a9df90f771d","session":"1ee14597-1a49-403e-8a48-917a814b831e","seq":1,"duration_ms":121,"bytes_in":51,"bytes_out":14,"enriched":{"digest":"56a8af4f4fb4faa0","label":"RDP (X.224)","strings":["Cookie: mstshash=Administrator"]}},{"timestamp":"2026-07-17T20:40:18","port":800,"proto":"tcp","app_proto":"tls","app_protocol":"cassandra","host":"","headers":"","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"","summary":"\u0001\u0000\u0000\u0000\u0000�\u0000\u0001\u0000\u0000ANY-SCP\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000FINDSCU\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0010\u0000\u0000\u00151.2.840.10008.3.1.1.1 \u0000\u0000.\u0001\u0000\u0000\u00000\u0000\u0000\u00111.2.840.10008.1.1@\u0000\u0000\u00111.2.840.10008.1.2P\u0000\u0000:Q\u0000\u0000\u0004\u0000\u0000@\u0000R\u0000\u0000\u001e1.2.826.0.1.3680043.2.1396.999U\u0000\u0000\fCharruaVista","payload_hex":"0100000000cd00010000414e592d53435000000000000000000046494e44534355000000000000000000000000000000000000000000000000000000000000000000000000000000000010000015312e322e3834302e31303030382e332e312e312e312000002e0100000030000011312e322e3834302e31303030382e312e3140000011312e322e3834302e31303030382e312e325000003a51000004000040005200001e312e322e3832362e302e312e333638303034332e322e313339362e3939395500000c436861727275615669737461","method":"","user_agent":"","community_id":"1:nadMriLhuB2Uy2yRDLO2RGJ3DUw=","ja3":"c12b4ccd5320bbb380ca1a9df90f771d","session":"d1d6147d-7205-473f-9e0a-b0e63788a0e1","seq":1,"duration_ms":121,"bytes_in":211,"bytes_out":14,"enriched":{"digest":"14f9c94d13e59316","label":"DICOM","strings":["ANY-SCP","FINDSCU","1.2.840.10008.3.1.1.1","1.2.840.10008.1.1@","1.2.840.10008.1.2P","1.2.826.0.1.3680043.2.1396.999U","CharruaVista","ANY-SCPFINDSCU","1.2.840.10008.3.1.1.1 .","1.2.840.10008.1.2P:Q"]}},{"timestamp":"2026-07-17T20:40:17","port":800,"proto":"tcp","app_proto":"tls","app_protocol":"iscsi","host":"","headers":"","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"","summary":"\u0003�\u0000\u0000\u0000\u0000\u0000_@\u0000\u00017\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0001\u0000\u0001\u0000\u0000\u0000\u0000\u0000\u0001\u0000\u0000\u0000\u0001\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000InitiatorName=iqn.1991-05.com.microsoft:beio-iscsi-probe\u0000SessionType=Discovery\u0000AuthMethod=None\u0000\u0000","payload_hex":"038100000000005f40000137000000000000000100010000000000010000000100000000000000000000000000000000496e69746961746f724e616d653d69716e2e313939312d30352e636f6d2e6d6963726f736f66743a6265696f2d69736373692d70726f62650053657373696f6e547970653d446973636f7665727900417574684d6574686f643d4e6f6e650000","method":"","user_agent":"","community_id":"1:NVeYQlWi4pp+CnWiVZvFZPYMcO0=","ja3":"c12b4ccd5320bbb380ca1a9df90f771d","session":"de5213d5-e490-4918-8b21-cb637a948b5b","seq":1,"duration_ms":121,"bytes_in":144,"bytes_out":14,"enriched":{"digest":"482810f8d0264f72","label":"iSCSI","strings":["InitiatorName=iqn.1991-05.com.microsoft:beio-iscsi-probe","SessionType=Discovery","AuthMethod=None","InitiatorName=iqn.1991-05.com.microsoft:beio-iscsi-probeSessionType=DiscoveryAut…"],"iocs":{"domains":["iqn.1991-05.com.microsoft"]}}},{"timestamp":"2026-07-17T20:40:15","port":800,"proto":"tcp","app_proto":"tls","app_protocol":"tls","host":"","headers":"","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"","summary":"\u0000\u0000\u0000\u0001\u0000\u0000\u0000\u0001\u0000\u0000\u0000\u0004\u0000\u0000\u0000\b\u0000\u0000\u0000\u0001\u0000\u0000\u0000\u0000","payload_hex":"000000010000000100000004000000080000000100000000","method":"","user_agent":"","community_id":"1:CWDbkjbBkXdcbjJ8XitIqhTGkw4=","ja3":"c12b4ccd5320bbb380ca1a9df90f771d","session":"1ee9faa7-bb7d-4825-a772-f2a933662ca5","seq":1,"duration_ms":120,"bytes_in":24,"bytes_out":14},{"timestamp":"2026-07-17T20:40:13","port":800,"proto":"tcp","app_proto":"tls","app_protocol":"pptp","host":"","headers":"","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"","summary":"\u0000�\u0000\u0001\u001a+<M\u0000\u0001\u0000\u0000\u0001\u0000\u0000\u0000\u0000\u0000\u0000\u0001\u0000\u0000\u0000\u0001��\u0000\u0001none\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000beio\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000","payload_hex":"009c00011a2b3c4d00010000010000000000000100000001ffff00016e6f6e650000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000006265696f000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000","method":"","user_agent":"","community_id":"1:775Fkl9+r7yFrYz3CdTnGoUaC/s=","ja3":"c12b4ccd5320bbb380ca1a9df90f771d","session":"4629fefb-41c0-4f58-b754-8a1a25e427dc","seq":1,"duration_ms":126,"bytes_in":156,"bytes_out":14,"enriched":{"digest":"3415c4d31123c5ba","strings":["none","beio","nonebeio"]}},{"timestamp":"2026-07-17T20:40:11","port":800,"proto":"tcp","app_proto":"tls","app_protocol":"tls","host":"","headers":"","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"","summary":"\u0010\u0000\u0003\u0000LIORL\t\u0000\u0000����\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000c��d\u0001\u0000\u0000\u0000\u0001\u001c \u0002`\u0000h\u0000t\u0000t\u0000p\u0000:\u0000/\u0000/\u00001\u00009\u00002\u0000.\u00001\u00006\u00008\u0000.\u00001\u00000\u0000.\u00001\u00000\u00000\u0000/\u0000m\u0000s\u0000m\u0000q\u0000/\u0000p\u0000r\u0000i\u0000v\u0000a\u0000t\u0000e\u0000$\u0000/\u0000q\u0000u\u0000e\u0000u\u0000e\u0000j\u0000u\u0000m\u0000p\u0000e\u0000r\u0000\u0000\u0000\u0000\u0000\u0000\u0004\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000p\u0000o\u0000c\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u001b\u0002\u0000\u0000<\u0000s\u0000e\u0000:\u0000E\u0000n\u0000v\u0000e\u0000l\u0000o\u0000p\u0000e\u0000 \u0000x\u0000m\u0000l\u0000n\u0000s\u0000:\u0000s\u0000e\u0000=\u0000\"\u0000h\u0000t\u0000t\u0000p\u0000:\u0000/\u0000/\u0000s\u0000c\u0000h\u0000e\u0000m\u0000a\u0000s\u0000.\u0000x\u0000m\u0000l\u0000s\u0000o\u0000a\u0000p\u0000.\u0000o\u0000r\u0000g\u0000/\u0000s\u0000o\u0000a\u0000p\u0000/\u0000e\u0000n\u0000v\u0000e\u0000l\u0000o\u0000p\u0000e\u0000/\u0000\"\u0000 \u0000\r\u0000\n\u0000x\u0000m\u0000l\u0000n\u0000s\u0000=\u0000\"\u0000h\u0000t\u0000t\u0000p\u0000:\u0000/\u0000/\u0000s\u0000c\u0000h\u0000e\u0000m\u0000a\u0000s\u0000.\u0000x\u0000m\u0000l\u0000s\u0000o\u0000a\u0000p\u0000.\u0000o\u0000r\u0000g\u0000/\u0000s\u0000r\u0000m\u0000p\u0000/\u0000\"\u0000>\u0000\r\u0000\n\u0000<\u0000s\u0000e\u0000:\u0000H\u0000e\u0000a\u0000d\u0000e\u0000r\u0000>\u0000\r\u0000\n\u0000 \u0000<\u0000p\u0000a\u0000t\u0000h\u0000 \u0000x\u0000m\u0000l\u0000n\u0000s\u0000=\u0000\"\u0000h\u0000t\u0000t\u0000p\u0000:\u0000/\u0000/\u0000s\u0000c\u0000h\u0000e\u0000m\u0000a\u0000s\u0000.\u0000x\u0000m\u0000l\u0000s\u0000o\u0000a\u0000p\u0000.\u0000o\u0000r\u0000g\u0000/\u0000r\u0000p\u0000/\u0000\"\u0000 \u0000s\u0000e\u0000:\u0000m\u0000u\u0000s\u0000t\u0000U\u0000n\u0000d\u0000e\u0000r\u0000s\u0000t\u0000a\u0000n\u0000d\u0000=\u0000\"\u00001\u0000\"\u0000>\u0000\r\u0000\n\u0000 \u0000 \u0000 \u0000<\u0000a\u0000c\u0000t\u0000i\u0000o\u0000n\u0000>\u0000M\u0000S\u0000M\u0000Q\u0000:\u0000p\u0000o\u0000c\u0000<\u0000/\u0000a\u0000c\u0000t\u0000i\u0000o\u0000n\u0000>\u0000\r\u0000\n\u0000 \u0000 \u0000 \u0000<\u0000t\u0000o\u0000>\u0000h\u0000t\u0000t\u0000p\u0000:\u0000/\u0000/\u00001\u00009\u00002\u0000.\u00001\u00006\u00008\u0000.\u00001\u00000\u0000.\u00001\u00000\u00000\u0000/\u0000m\u0000s\u0000m\u0000q\u0000/\u0000p\u0000r\u0000i\u0000v\u0000a\u0000t\u0000e\u0000$\u0000/\u0000q\u0000u\u0000e\u0000u\u0000e\u0000j\u0000u\u0000m\u0000p\u0000e\u0000r\u0000<\u0000/\u0000t\u0000o\u0000>\u0000\r\u0000\n\u0000 \u0000 \u0000 \u0000<\u0000i\u0000d\u0000>\u0000u\u0000u\u0000i\u0000d\u0000:\u00001\u0000@\u00000\u00000\u00000\u00000\u00000\u00000\u00000\u00000\u0000-\u00000\u00000\u00000\u00000\u0000-\u00000\u00000\u00000\u00000\u0000-\u00000\u00000\u00000\u00000\u0000-\u00000\u00000\u00000\u00000\u00000\u00000\u00000\u00000\u00000\u00000\u00000\u00000\u0000<\u0000/\u0000i\u0000d\u0000>\u0000\r\u0000\n\u0000 \u0000<\u0000/\u0000p\u0000a\u0000t\u0000h\u0000>\u0000\r\u0000\n\u0000 \u0000<\u0000p\u0000r\u0000o\u0000p\u0000e\u0000r\u0000t\u0000i\u0000e\u0000s\u0000 \u0000s\u0000e\u0000:\u0000m\u0000u\u0000s\u0000t\u0000U\u0000n\u0000d\u0000e\u0000r\u0000s\u0000t\u0000a\u0000n\u0000d\u0000=\u0000\"\u00001\u0000\"\u0000>\u0000\r\u0000\n\u0000 \u0000 \u0000 \u0000<\u0000e\u0000x\u0000p\u0000i\u0000r\u0000e\u0000s\u0000A\u0000t\u0000>\u00002\u00000\u00006\u00000\u00000\u00006\u00000\u00009\u0000T\u00001\u00006\u00004\u00004\u00001\u00009\u0000<\u0000/\u0000e\u0000x\u0000p\u0000i\u0000r\u0000e\u0000s\u0000A\u0000t\u0000>\u0000\r\u0000\n\u0000 \u0000 \u0000 \u0000<\u0000s\u0000e\u0000n\u0000t\u0000A\u0000t\u0000>\u00002\u00000\u00002\u00003\u00000\u00007\u00002\u00004\u0000T\u00001\u00006\u00004\u00004\u00001\u00009\u0000<\u0000/\u0000s\u0000e\u0000n\u0000t\u0000A\u0000t\u0000>\u0000\r\u0000\n\u0000 \u0000<\u0000/\u0000p\u0000r\u0000o\u0000p\u0000e\u0000r\u0000t\u0000i\u0000e\u0000s\u0000>\u0000\r\u0000\n\u0000<\u0000/\u0000s\u0000e\u0000:\u0000H\u0000e\u0000a\u0000d\u0000e\u0000r\u0000>\u0000\r\u0000\n\u0000<\u0000s\u0000e\u0000:\u0000B\u0000o\u0000d\u0000y\u0000>\u0000<\u0000/\u0000s\u0000e\u0000:\u0000B\u0000o\u0000d\u0000y\u0000>\u0000\r\u0000\n\u0000<\u0000/\u0000s\u0000e\u0000:\u0000E\u0000n\u0000v\u0000e\u0000l\u0000o\u0000p\u0000e\u0000>\u0000\r\u0000\n\u0000\r\u0000\n\u0000\u0000\u0000\u0000\u0000�\u0001\u0000\u0000\f\u0004\u0000\u0000\u0007\u0000\u0000\u0000�\u0003\u0000\u0000POST /msmq HTTP/1.1\r\nContent-Length: 816\r\nContent-Type: multipart/related; boundary=\"MSMQ - SOAP boundary, 53287\"; type=text/xml\r\nHost: 192.168.10.100\r\nSOAPAction: \"MSMQMessage\"\r\nProxy-Accept: NonInteractiveClient\r\n\r\n--MSMQ - SOAP boundary, 53287\r\nContent-Type: text/xml; charset=UTF-8\r\nContent-Length: 606\r\n\r\n<se:Envelope xmlns:se=\"http://schemas.xmlsoap.org/soap/envelope/\" \r\nxmlns=\"http://schemas.xmlsoap.org/srmp/\">\r\n<se:Header>\r\n <path xmlns=\"http://schemas.xmlsoap.org/rp/\" se:mustUnderstand=\"1\">\r\n   <action>MSMQ:poc</action>\r\n   <to>http://192.168.10.100/msmq/private$/queuejumper</to>\r\n   <id>uuid:1@00000000-0000-0000-0000-000000000000</id>\r\n </path>\r\n <properties se:mustUnderstand=\"1\">\r\n   <expiresAt>20600609T164419</expiresAt>\r\n   <sentAt>20230724T164419</sentAt>\r\n </properties>\r\n</se:Header>\r\n<se:Body></se:Body>\r\n</se:Envelope>\r\n\r\n--MSMQ - SOAP boundary, 53287\r\nContent-Type: application/octet-stream\r\nContent-Length: 7\r\nContent-Id: body@ff3af301-3196-497a-a918-72147c871a13\r\n\r\nMessage\r\n--MSMQ - SOAP boundary, 53287--\u0000\f\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000","payload_hex":"100003004c494f524c090000ffffffff00000000000000000000000000000000000000000000000000000000000000000000000063aabe6401000000011c2002600068007400740070003a002f002f003100390032002e003100360038002e00310030002e003100300030002f006d0073006d0071002f00700072006900760061007400650024002f00710075006500750065006a0075006d0070006500720000000000000400000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000070006f0063000000000000001b0200003c00730065003a0045006e00760065006c006f0070006500200078006d006c006e0073003a00730065003d00220068007400740070003a002f002f0073006300680065006d00610073002e0078006d006c0073006f00610070002e006f00720067002f0073006f00610070002f0065006e00760065006c006f00700065002f00220020000d000a0078006d006c006e0073003d00220068007400740070003a002f002f0073006300680065006d00610073002e0078006d006c0073006f00610070002e006f00720067002f00730072006d0070002f0022003e000d000a003c00730065003a004800650061006400650072003e000d000a0020003c007000610074006800200078006d006c006e0073003d00220068007400740070003a002f002f0073006300680065006d00610073002e0078006d006c0073006f00610070002e006f00720067002f00720070002f0022002000730065003a006d0075007300740055006e006400650072007300740061006e0064003d002200310022003e000d000a002000200020003c0061006300740069006f006e003e004d0053004d0051003a0070006f0063003c002f0061006300740069006f006e003e000d000a002000200020003c0074006f003e0068007400740070003a002f002f003100390032002e003100360038002e00310030002e003100300030002f006d0073006d0071002f00700072006900760061007400650024002f00710075006500750065006a0075006d007000650072003c002f0074006f003e000d000a002000200020003c00690064003e0075007500690064003a0031004000300030003000300030003000300030002d0030003000300030002d0030003000300030002d0030003000300030002d003000300030003000300030003000300030003000300030003c002f00690064003e000d000a0020003c002f0070006100740068003e000d000a0020003c00700072006f0070006500720074006900650073002000730065003a006d0075007300740055006e006400650072007300740061006e0064003d002200310022003e000d000a002000200020003c006500780070006900720065007300410074003e003200300036003000300036003000390054003100360034003400310039003c002f006500780070006900720065007300410074003e000d000a002000200020003c00730065006e007400410074003e003200300032003300300037003200340054003100360034003400310039003c002f00730065006e007400410074003e000d000a0020003c002f00700072006f0070006500720074006900650073003e000d000a003c002f00730065003a004800650061006400650072003e000d000a003c00730065003a0042006f00640079003e003c002f00730065003a0042006f00640079003e000d000a003c002f00730065003a0045006e00760065006c006f00700065003e000d000a000d000a0000000000f40100000c04000007000000e3030000504f5354202f6d736d7120485454502f312e310d0a436f6e74656e742d4c656e6774683a203831360d0a436f6e74656e742d547970653a206d756c7469706172742f72656c617465643b20626f756e646172793d224d534d51202d20534f415020626f756e646172792c203533323837223b20747970653d746578742f786d6c0d0a486f73743a203139322e3136382e31302e3130300d0a534f4150416374696f6e3a20224d534d514d657373616765220d0a50726f78792d4163636570743a204e6f6e496e746572616374697665436c69656e740d0a0d0a2d2d4d534d51202d20534f415020626f756e646172792c2035333238370d0a436f6e74656e742d547970653a20746578742f786d6c3b20636861727365743d5554462d380d0a436f6e74656e742d4c656e6774683a203630360d0a0d0a3c73653a456e76656c6f706520786d6c6e733a73653d22687474703a2f2f736368656d61732e786d6c736f61702e6f72672f736f61702f656e76656c6f70652f22200d0a786d6c6e733d22687474703a2f2f736368656d61732e786d6c736f61702e6f72672f73726d702f223e0d0a3c73653a4865616465723e0d0a203c7061746820786d6c6e733d22687474703a2f2f736368656d61732e786d6c736f61702e6f72672f72702f222073653a6d757374556e6465727374616e643d2231223e0d0a2020203c616374696f6e3e4d534d513a706f633c2f616374696f6e3e0d0a2020203c746f3e687474703a2f2f3139322e3136382e31302e3130302f6d736d712f70726976617465242f71756575656a756d7065723c2f746f3e0d0a2020203c69643e757569643a314030303030303030302d303030302d303030302d303030302d3030303030303030303030303c2f69643e0d0a203c2f706174683e0d0a203c70726f706572746965732073653a6d757374556e6465727374616e643d2231223e0d0a2020203c6578706972657341743e3230363030363039543136343431393c2f6578706972657341743e0d0a2020203c73656e7441743e3230323330373234543136343431393c2f73656e7441743e0d0a203c2f70726f706572746965733e0d0a3c2f73653a4865616465723e0d0a3c73653a426f64793e3c2f73653a426f64793e0d0a3c2f73653a456e76656c6f70653e0d0a0d0a2d2d4d534d51202d20534f415020626f756e646172792c2035333238370d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6f637465742d73747265616d0d0a436f6e74656e742d4c656e6774683a20370d0a436f6e74656e742d49643a20626f64794066663361663330312d333139362d343937612d613931382d3732313437633837316131330d0a0d0a4d6573736167650d0a2d2d4d534d51202d20534f415020626f756e646172792c2035333238372d2d000c0000000000000000000000","method":"","user_agent":"","community_id":"1:eLRp7HLK/dITyRJoOZgafnUpqPs=","ja3":"c12b4ccd5320bbb380ca1a9df90f771d","session":"956c06f4-19b6-4e45-9c64-1d7f14a5cd01","seq":1,"duration_ms":120,"bytes_in":2380,"bytes_out":14,"enriched":{"digest":"45c6f72bb5aeb522","strings":["LIORL","POST /msmq HTTP/1.1","Content-Length: 816","Content-Type: multipart/related; boundary=\"MSMQ - SOAP boundary, 53287\"; type=te…","Host: 192.168.10.100","SOAPAction: \"MSMQMessage\"","Proxy-Accept: NonInteractiveClient","--MSMQ - SOAP boundary, 53287","Content-Type: text/xml; charset=UTF-8","Content-Length: 606"],"iocs":{"ips":["192.168.10.100"]}}},{"timestamp":"2026-07-17T20:40:10","port":800,"proto":"tcp","app_proto":"tls","app_protocol":"tls","host":"","headers":"","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"","summary":"\u0000\u000e87�&\b�\u001b��\u0000\u0000\u0000\u0000\u0000","payload_hex":"000e3837a52608a21ba0b10000000000","method":"","user_agent":"","community_id":"1:s+eymBAq699SBvU4a2Fqo4RMMhQ=","ja3":"c12b4ccd5320bbb380ca1a9df90f771d","session":"9546c859-40a3-4dfc-b000-bd6757678ff3","seq":1,"duration_ms":123,"bytes_in":16,"bytes_out":14},{"timestamp":"2026-07-17T20:40:08","port":800,"proto":"tcp","app_proto":"tls","app_protocol":"corba","host":"","headers":"","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"","summary":"GIOP\u0001\u0000\u0001\u0000$\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0001\u0000\u0000\u0000\u0001\u0000\u0000\u0000\u0006\u0000\u0000\u0000abcdef\u0000\u0000\u0004\u0000\u0000\u0000get\u0000\u0000\u0000\u0000\u0000","payload_hex":"47494f500100010024000000000000000100000001000000060000006162636465660000040000006765740000000000","method":"","user_agent":"","community_id":"1:OZndVo2D5rCLhunPEyZIvQvuNzs=","ja3":"c12b4ccd5320bbb380ca1a9df90f771d","session":"83303c85-8b3b-414b-87e7-28b63a5bfc5e","seq":1,"duration_ms":121,"bytes_in":48,"bytes_out":14,"enriched":{"digest":"2172ddff8435bc68","label":"CORBA (GIOP)","strings":["GIOP","abcdef"]}}],"http_methods":[{"method":"GET","count":85},{"method":"OPTIONS","count":4}],"distinct_ports_total":5,"top_paths":[{"path":"/","count":8,"ports":2},{"path":"/nice%20ports%2C/Tri%6Eity.txt%2ebak","count":3,"ports":2},{"path":"/client","count":1,"ports":1},{"path":"/api/v2/cmdb/system/admin/admin","count":1,"ports":1},{"path":"/login","count":1,"ports":1},{"path":"/.env","count":1,"ports":1},{"path":"/rdweb","count":1,"ports":1},{"path":"/admin","count":1,"ports":1},{"path":"/mftp","count":1,"ports":1},{"path":"/webui/","count":1,"ports":1},{"path":"/wsman","count":1,"ports":1},{"path":"/Login.jsp","count":1,"ports":1},{"path":"/configurations","count":1,"ports":1},{"path":"/login.action","count":1,"ports":1},{"path":"/human.aspx","count":1,"ports":1}],"distinct_paths_total":80,"top_snis":[],"top_hosts":[],"top_alpns":[{"value":"http/1.1","count":78}],"banners":[],"credentials":[],"header_profile":null,"tags":[{"tag_id":"CVE-2018-13379","tag_type":"cve","title":"Fortinet FortiOS - Credentials Disclosure","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession","reference_urls":["https://fortiguard.com/advisory/FG-IR-18-384","https://www.fortiguard.com/psirt/FG-IR-20-233","https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-13379"]},{"tag_id":"CVE-2021-22205","tag_type":"cve","title":"GitLab CE/EE - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/users/sign_in","reference_urls":["https://gitlab.com/gitlab-com/gl-security/security-operations/gl-redteam/red-team-research/cve-2021-22205-hash-generator","https://gitlab.com/gitlab-com/gl-security/security-operations/gl-redteam/red-team-operations/-/issues/196","https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22205.json","https://censys.io/blog/cve-2021-22205-it-was-a-gitlab-smash/","https://security.humanativaspa.it/gitlab-ce-cve-2021-22205-in-the-wild/"]},{"tag_id":"CVE-2022-40684","tag_type":"cve","title":"Fortinet - Authentication Bypass","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/v2/cmdb/system/admin","reference_urls":["https://github.com/horizon3ai/CVE-2022-40684/blob/master/CVE-2022-40684.py","https://securityonline.info/researchers-have-developed-cve-2022-40684-poc-exploit-code/","https://socradar.io/what-do-you-need-to-know-about-fortinet-critical-authentication-bypass-vulnerability-cve-2022-40684/","https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-40684","https://nvd.nist.gov/vuln/detail/CVE-2022-40684"]},{"tag_id":"CVE-2023-40044","tag_type":"cve","title":"WS_FTP Server - Insecure Deserialization","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/AHT/AHT_UI/public/js/app.min.js","reference_urls":["https://attackerkb.com/topics/bn32f9sNax/cve-2023-40044","https://censys.com/cve-2023-40044/","https://www.progress.com/ws_ftp","https://www.rapid7.com/blog/post/2023/09/29/etr-critical-vulnerabilities-in-ws_ftp-server/","https://www.theregister.com/2023/10/02/ws_ftp_update/"]},{"tag_id":"CVE-2024-0012","tag_type":"cve","title":"PAN-OS Management Web Interface - Authentication Bypass","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/php/ztp_gate.php/.js.map","reference_urls":["https://security.paloaltonetworks.com/CVE-2024-0012","https://labs.watchtowr.com/pots-and-pans-aka-an-sslvpn-palo-alto-pan-os-cve-2024-0012-and-cve-2024-9474/","https://nvd.nist.gov/vuln/detail/CVE-2024-0012"]},{"tag_id":"CVE-2024-4040","tag_type":"cve","title":"CrushFTP VFS - Sandbox Escape LFR","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/WebInterface","reference_urls":["https://www.bleepingcomputer.com/news/security/crushftp-warns-users-to-patch-exploited-zero-day-immediately/","https://www.crushftp.com/crush10wiki/Wiki.jsp?page=Update","https://www.reddit.com/r/crowdstrike/comments/1c88788/situational_awareness_20240419_crushftp_virtual/","https://www.reddit.com/r/cybersecurity/comments/1c850i2/all_versions_of_crush_ftp_are_vulnerable/"]},{"tag_id":"CVE-2025-0282","tag_type":"cve","title":"Ivanti Connect Secure - Stack-based Buffer Overflow","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/dana-na/auth/url_default/welcome.cgi","reference_urls":["https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-0282-CVE-2025-0283","https://labs.watchtowr.com/exploitation-walkthrough-and-techniques-ivanti-connect-secure-rce-cve-2025-0282/","https://cloud.google.com/blog/topics/threat-intelligence/ivanti-connect-secure-vpn-zero-day","https://nvd.nist.gov/vuln/detail/CVE-2025-0282"]},{"tag_id":"CVE-2020-3452","tag_type":"cve","title":"Cisco Adaptive Security Appliance (ASA)/Firepower Threat Defense (FTD) - Local File Inclusion","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/+CSCOT+/oem-customization?app=AnyConnect&type=oem&platform=..&resource-type=..&name=%2bCSCOE%2b/portal_inc.lua","reference_urls":["https://twitter.com/aboul3la/status/1286012324722155525","http://packetstormsecurity.com/files/158646/Cisco-ASA-FTD-Remote-File-Disclosure.html","http://packetstormsecurity.com/files/158647/Cisco-Adaptive-Security-Appliance-Software-9.11-Local-File-Inclusion.html","http://packetstormsecurity.com/files/159523/Cisco-ASA-FTD-9.6.4.42-Path-Traversal.html","http://packetstormsecurity.com/files/160497/Cisco-ASA-9.14.1.10-FTD-6.6.0.1-Path-Traversal.html"]},{"tag_id":"CVE-2023-7028","tag_type":"cve","title":"GitLab - Account Takeover via Password Reset","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/users/sign_in","reference_urls":["https://about.gitlab.com/releases/2024/01/11/critical-security-release-gitlab-16-7-2-released/","https://x.com/rwincey/status/1745659710089437368?s=20","https://gitlab.com/gitlab-org/gitlab/-/issues/436084","https://hackerone.com/reports/2293343","https://github.com/V1lu0/CVE-2023-7028"]},{"tag_id":"CVE-2017-5983","tag_type":"cve","title":"JIRA Workflow Designer Plugin in Atlassian JIRA Server > 6.3.0 - Remote Code Execution (XXE)","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/jira/secure/Dashboard.jspa","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2017-5983","https://code-white.com/blog/2017-04-amf/"]},{"tag_id":"CVE-2022-0735","tag_type":"cve","title":"GitLab CE/EE - Information Disclosure","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/users/sign_in","reference_urls":["https://gitlab.com/gitlab-com/gl-security/threatmanagement/redteam/redteam-public/cve-hash-harvester","https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0735.json","https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0735","https://nvd.nist.gov/vuln/detail/cve-2022-0735","https://gitlab.com/gitlab-org/gitlab/-/issues/353529"]},{"tag_id":"CVE-2022-1162","tag_type":"cve","title":"GitLab CE/EE - Hard-Coded Credentials","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/users/sign_in","reference_urls":["https://gitlab.com/gitlab-com/gl-security/threatmanagement/redteam/redteam-public/cve-hash-harvester","https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1162.json","https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1162","http://packetstormsecurity.com/files/166828/Gitlab-14.9-Authentication-Bypass.html","https://nvd.nist.gov/vuln/detail/cve-2022-1162"]},{"tag_id":"CVE-2023-43177","tag_type":"cve","title":"CrushFTP < 10.5.1 - Unauthenticated Remote Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/WebInterface","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2023-43177","https://convergetp.com/2023/11/16/crushftp-zero-day-cve-2023-43177-discovered/","https://blog.projectdiscovery.io/crushftp-rce/","https://github.com/the-emmons/CVE-Disclosures/blob/main/Pending/CrushFTP-2023-1.md","https://github.com/nomi-sec/PoC-in-GitHub"]},{"tag_id":"CVE-2020-2036","tag_type":"cve","title":"Palo Alto Networks PAN-OS Web Interface - Cross Site-Scripting","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/global-protect/login.esp","reference_urls":["https://swarm.ptsecurity.com/swarm-of-palo-alto-pan-os-vulnerabilities/","https://security.paloaltonetworks.com/CVE-2020-2036","https://nvd.nist.gov/vuln/detail/CVE-2020-2036","https://github.com/404notf0und/CVE-Flow","https://github.com/ARPSyndicate/kenzer-templates"]},{"tag_id":"CVE-2022-2185","tag_type":"cve","title":"GitLab CE/EE - Remote Code Execution","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/users/sign_in","reference_urls":["https://gitlab.com/gitlab-com/gl-security/threatmanagement/redteam/redteam-public/cve-hash-harvester","https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2185.json","https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2185","https://nvd.nist.gov/vuln/detail/CVE-2022-2185","https://gitlab.com/gitlab-org/gitlab/-/issues/366088"]},{"tag_id":"CVE-2023-2825","tag_type":"cve","title":"GitLab 16.0.0 - Path Traversal","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/users/sign_in","reference_urls":["https://about.gitlab.com/releases/2023/05/23/critical-security-release-gitlab-16-0-1-released/","https://github.com/Occamsec/CVE-2023-2825","https://labs.watchtowr.com/gitlab-arbitrary-file-read-gitlab-cve-2023-2825-analysis/","https://nvd.nist.gov/vuln/detail/CVE-2023-2825","https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-2825.json"]},{"tag_id":"CVE-2007-4556","tag_type":"cve","title":"OpenSymphony XWork/Apache Struts2 - Remote Code Execution","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/login.action","reference_urls":["https://www.guildhab.top/?p=2326","https://nvd.nist.gov/vuln/detail/CVE-2007-4556","https://cwiki.apache.org/confluence/display/WW/S2-001","http://forums.opensymphony.com/ann.jspa?annID=54","http://issues.apache.org/struts/browse/WW-2030"]},{"tag_id":"CVE-2019-11507","tag_type":"cve","title":"Pulse Secure Pulse Connect Secure - Cross-Site Scripting (Reflected)","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/dana-na/auth/url_default/welcome.cgi","reference_urls":["https://devco.re/blog/2019/09/02/attacking-ssl-vpn-part-3-the-golden-Pulse-Secure-ssl-vpn-rce-chain-with-Twitter-as-case-study/","https://nvd.nist.gov/vuln/detail/CVE-2019-11507"]}],"data_as_of":"2026-07-26T15:27:07.916104+00:00"}