{"ip":"148.66.135.237","total_events":2,"verdict":{"verdict":"probing","label":"Low-level probing","detail":null,"confidence":"low","network_type":"CDN","why":["2 event(s), fewer than 10 distinct ports, no exploit payloads.","Not in any known-scanner range."],"engagement":{"level":"request","label":"Request traffic","detail":"420 bytes sent","bytes_sent":420,"session_seconds":0,"persistent":false}},"first_seen":"2026-09-22T20:26:30","last_seen":"2026-09-22T20:26:31","events_24h":2,"events_7d":2,"geo":{"country_code":"SG","country_name":"Singapore","region":"","city":"Singapore","lat":1.2872,"lon":103.8507,"asn":26496,"org":"GoDaddy.com, LLC"},"source_domain":"237.135.66.148.host.secureserver.net","known_scanners":[],"scanner_tag":{"key":"peeringdb:as26496","label":"GoDaddy","category":"cdn","url":"https://www.peeringdb.com/asn/26496"},"cve_matches":[{"cve_id":"CVE-2026-41940","title":"cPanel & WHM - Authentication Bypass via Session-File CRLF Injection","severity":"CRITICAL","actively_exploited":true,"match_field":"url_path","matched_pattern":"/login/?login_only=1"}],"malware":[],"top_ports":[{"port":2087,"proto":"tcp","label":"","count":2}],"fingerprints":{"ssh_hassh":[],"tls_ja4":["t13i4311h1_c7886603b240_b26ce05bbdd6"],"tls_client_hello":"1603010200010001fc0303d42e455b52da4afbdd5f482e5b1de273022169df99f906344b0a2b049aa324a32015b88c0c79681df9f029f818c392560897936c100e998d710cb46e58168a2d3d0056130213031301c02cc030c02bc02fcca9cca8009f009eccaac0afc0adc0aec0acc024c028c023c027c00ac014c009c013c0a3c09fc0a2c09e006b006700390033009d009cc0a1c09dc0a0c09c003d003c0035002f00ff0100015d000b000403000102000a00160014001d0017001e00190018010001010102010301040010000b000908687474702f312e31001600000017000000310000000d002a0028040305030603080708080809080a080b080408050806040105010601030303010302040205020602002b00050403040303002d00020101003300260024001d0020ce1009cad624b81d5c9b3694ddd4c9b870b47a31768b481db49418e2bd89a92d001500b500000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000","tls_ja3":["f80d3d09f61892c5846c854dd84ac403"],"http_akin":["a11cun050_0000004f_c2244ae4","a11cuq070_0000064f_8574b2f3"]},"fingerprint_peers":{"t13i4311h1_c7886603b240_b26ce05bbdd6":20,"a11cun050_0000004f_c2244ae4":1,"a11cuq070_0000064f_8574b2f3":1},"akin_families":{},"user_agents":["python-requests/2.25.1"],"timeline":[{"date":"2026-09-22","count":2}],"recent_events":[{"timestamp":"2026-09-22T20:26:31","port":2087,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip, deflate\",\"connection\":\"close\",\"content-length\":\"20\",\"content-type\":\"application/x-www-form-urlencoded\",\"host\":\"<HONEYPOT>:2087\",\"user-agent\":\"python-requests/2.25.1\"}","body":"user=root&pass=wrong","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":["http/1.1"],"url_path":"/login/?login_only=1","summary":"","payload_hex":"504f5354202f6c6f67696e2f3f6c6f67696e5f6f6e6c793d3120485454502f312e310d0a557365722d4167656e743a20707974686f6e2d72657175657374732f322e32352e310d0a4163636570742d456e636f64696e673a20677a69702c206465666c6174650d0a4163636570743a202a2f2a0d0a436f6e6e656374696f6e3a20636c6f73650d0a486f73743a20<HONEYPOT>3a323038370d0a436f6e74656e742d4c656e6774683a2032300d0a436f6e74656e742d547970653a206170706c69636174696f6e2f782d7777772d666f726d2d75726c656e636f6465640d0a0d0a757365723d726f6f7426706173733d77726f6e67","method":"POST","user_agent":"python-requests/2.25.1","ja3":"f80d3d09f61892c5846c854dd84ac403","session":"96577a5a-e128-4866-8038-07402a35c65f","seq":1,"duration_ms":101,"bytes_in":253,"bytes_out":79},{"timestamp":"2026-09-22T20:26:30","port":2087,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip, deflate\",\"connection\":\"close\",\"host\":\"<HONEYPOT>:2087\",\"user-agent\":\"python-requests/2.25.1\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":["http/1.1"],"url_path":"/openid_connect/cpanelid","summary":"","payload_hex":"474554202f6f70656e69645f636f6e6e6563742f6370616e656c696420485454502f312e310d0a486f73743a20<HONEYPOT>3a323038370d0a557365722d4167656e743a20707974686f6e2d72657175657374732f322e32352e310d0a4163636570742d456e636f64696e673a20677a69702c206465666c6174650d0a4163636570743a202a2f2a0d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a","method":"GET","user_agent":"python-requests/2.25.1","ja3":"f80d3d09f61892c5846c854dd84ac403","session":"4d33d79e-c9bf-4e8d-9322-af51576ec88d","seq":1,"duration_ms":101,"bytes_in":167,"bytes_out":79}],"http_methods":[{"method":"GET","count":1},{"method":"POST","count":1}],"distinct_ports_total":1,"top_paths":[{"path":"/login/?login_only=1","count":1,"ports":1},{"path":"/openid_connect/cpanelid","count":1,"ports":1}],"distinct_paths_total":2,"top_snis":[],"top_hosts":[],"top_alpns":[{"value":"http/1.1","count":2}],"banners":[],"credentials":[{"username":"root","password":"wrong","count":1}],"header_profile":{"signature":["Accept","Accept-Encoding","Connection","Content-Length","Content-Type","Host","User-Agent"],"representative":[{"name":"Accept","value":"*/*","notable":false},{"name":"Accept-Encoding","value":"gzip, deflate","notable":false},{"name":"Connection","value":"close","notable":false},{"name":"Content-Length","value":"20","notable":false},{"name":"Content-Type","value":"application/x-www-form-urlencoded","notable":true},{"name":"Host","value":"<HONEYPOT>:2087","notable":false},{"name":"User-Agent","value":"python-requests/2.25.1","notable":false}],"distinct_sets":2,"events_with_headers":2},"tags":[{"tag_id":"CVE-2026-41940","tag_type":"cve","title":"cPanel & WHM - Authentication Bypass via Session-File CRLF Injection","severity":"CRITICAL","actively_exploited":true,"match_field":"url_path","matched_pattern":"/login/?login_only=1","reference_urls":[]}],"data_as_of":"2026-09-23T17:39:11.175900+00:00"}