{"ip":"159.223.26.113","total_events":7,"verdict":{"verdict":"malicious","label":"Exploit attempts observed","detail":"1 exploit-path hits","confidence":"medium","network_type":"CDN","why":["1 request(s) matched a known exploit path.","Body-carrying methods (POST/PUT/PATCH/DELETE) seen: payload delivery, not just recon.","Under 5 hits, so confidence is medium.","Not in any known-scanner range."],"engagement":{"level":"request","label":"Request traffic","detail":"1,338 bytes sent","bytes_sent":1338,"session_seconds":0,"persistent":false}},"first_seen":"2026-09-22T17:35:47","last_seen":"2026-09-23T12:08:02","events_24h":7,"events_7d":7,"geo":{"country_code":"DE","country_name":"Germany","region":"Hesse","city":"Frankfurt am Main","lat":50.1169,"lon":8.6837,"asn":14061,"org":"DigitalOcean, LLC"},"source_domain":null,"known_scanners":[],"scanner_tag":{"key":"peeringdb:as14061","label":"DigitalOcean","category":"cdn","url":"https://www.peeringdb.com/asn/14061"},"cve_matches":[{"cve_id":"CVE-2026-27771","title":"Gitea Container Registry - Unauthorized Private Image Access","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/v2/_catalog"}],"malware":[],"top_ports":[{"port":1911,"proto":"tcp","label":"","count":3},{"port":5060,"proto":"tcp","label":"SIP","count":2},{"port":9042,"proto":"tcp","label":"Cassandra","count":1},{"port":5000,"proto":"tcp","label":"Web-alt","count":1}],"fingerprints":{"ssh_hassh":[],"tls_ja4":["t13i191000_9dc949149365_e5728521abd4"],"tls_client_hello":"160301010c010001080303884dd8ddac81181e1029cda9c570862d6467062af26eda2c9c8ab2f075082fae20649342c050f47de34ed0e842ea7b7889b7c7675097a66725517bd4329849c4e20026c02bc02fc02cc030cca9cca8c009c013c00ac014009c009d002f0035c012000a13011302130301000099000b00020100ff010001000017000000120000000500050100000000000a000a0008001d001700180019000d001a00180804040308070805080604010501060105030603020102030032001a0018080404030807080508060401050106010503060302010203002b00050403040303003300260024001d002088524fa761b2a6c29fd70c9c056198e7418a5b42e1b1a0b040654638","tls_ja3":["96458b3de39df5d47bc5c4a9f10f8f26"],"http_akin":["a11cun030_0000004a_c91eaf54","a11cun040_0000004d_aa48e2c8","a11cuq061_0000064a_ffe60107"]},"fingerprint_peers":{"t13i191000_9dc949149365_e5728521abd4":196,"a11cun030_0000004a_c91eaf54":67,"a11cun040_0000004d_aa48e2c8":1513,"a11cuq061_0000064a_ffe60107":14},"akin_families":{"a11cun030_0000004a_c91eaf54":{"head":"a11cun030_0000004a_c91eaf54","shapes":2,"ips":67},"a11cun040_0000004d_aa48e2c8":{"head":"a11cun040_0000004d_aa48e2c8","shapes":4,"ips":1525}},"user_agents":["Go-http-client/1.1","Mozilla/5.0 (compatible; Odin; https://docs.getodin.com/)"],"timeline":[{"date":"2026-09-22","count":2},{"date":"2026-09-23","count":5}],"recent_events":[{"timestamp":"2026-09-23T12:08:02","port":9042,"proto":"tcp","app_proto":"","app_protocol":"http","host":"185.228.81.201","headers":"{\"connection\":\"close\",\"host\":\"185.228.81.201:9042\",\"user-agent\":\"Go-http-client/1.1\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/cgi-bin/authLogin.cgi","summary":"","payload_hex":"474554202f6367692d62696e2f617574684c6f67696e2e63676920485454502f312e310d0a486f73743a203138352e3232382e38312e3230313a393034320d0a557365722d4167656e743a20476f2d687474702d636c69656e742f312e310d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a","method":"GET","user_agent":"Go-http-client/1.1","ja3":"","session":"29df6494-a1cd-42c9-918e-570cdf9fd7bd","seq":1,"duration_ms":100,"bytes_in":117,"bytes_out":79},{"timestamp":"2026-09-23T12:05:47","port":5060,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"connection\":\"close\",\"content-length\":\"475\",\"content-type\":\"application/xml\",\"host\":\"<HONEYPOT>:5060\",\"user-agent\":\"Go-http-client/1.1\",\"x-aggregate-auth\":\"1\"}","body":"<?xml version=\"1.0\" encoding=\"UTF-8\"?>\n\t\t\t\t<config-auth client=\"vpn\" type=\"init\" aggregate-auth-version=\"2\">\n\t\t\t\t<version who=\"vpn\">3.1.05160</version>\n\t\t\t\t<device-id device-type=\"iPhone13,1\" platform-version=\"15.0.1\" unique-id=\"ABCDEF1234567890\">iOS</device-id>\n\t\t\t\t<mac-address-list>\n\t\t\t\t\t<mac-address>01:23:45:67:89:AB</mac-address>\n\t\t\t\t</mac-address-list>\n\t\t\t\t<group-select>VPN</group-select>\n\t\t\t\t<group-access>https://<HONEYPOT>:5060</group-access>\n\t\t\t\t</config-auth>","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/","summary":"","payload_hex":"504f5354202f20485454502f312e310d0a486f73743a20<HONEYPOT>3a353036300d0a557365722d4167656e743a20476f2d687474702d636c69656e742f312e310d0a436f6e6e656374696f6e3a20636c6f73650d0a436f6e74656e742d4c656e6774683a203437350d0a436f6e74656e742d547970653a206170706c69636174696f6e2f786d6c0d0a582d4167677265676174652d417574683a20310d0a0d0a3c3f786d6c2076657273696f6e3d22312e302220656e636f64696e673d225554462d38223f3e0a090909093c636f6e6669672d6175746820636c69656e743d2276706e2220747970653d22696e697422206167677265676174652d617574682d76657273696f6e3d2232223e0a090909093c76657273696f6e2077686f3d2276706e223e332e312e30353136303c2f76657273696f6e3e0a090909093c6465766963652d6964206465766963652d747970653d226950686f6e6531332c312220706c6174666f726d2d76657273696f6e3d2231352e302e312220756e697175652d69643d2241424344454631323334353637383930223e694f533c2f6465766963652d69643e0a090909093c6d61632d616464726573732d6c6973743e0a09090909093c6d61632d616464726573733e30313a32333a34353a36373a38393a41423c2f6d61632d616464726573733e0a090909093c2f6d61632d616464726573732d6c6973743e0a090909093c67726f75702d73656c6563743e56504e3c2f67726f75702d73656c6563743e0a090909093c67726f75702d6163636573733e68747470733a2f2f<HONEYPOT>3a353036303c2f67726f75702d6163636573733e0a090909093c2f636f6e6669672d617574683e","method":"POST","user_agent":"Go-http-client/1.1","ja3":"96458b3de39df5d47bc5c4a9f10f8f26","session":"9f2eadd3-1ffe-4187-8a01-7de942c22575","seq":1,"duration_ms":100,"bytes_in":644,"bytes_out":79},{"timestamp":"2026-09-23T11:53:43","port":5060,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"connection\":\"close\",\"host\":\"<HONEYPOT>:5060\",\"user-agent\":\"Go-http-client/1.1\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/query?q=SHOW+DIAGNOSTICS","summary":"","payload_hex":"474554202f71756572793f713d53484f572b444941474e4f535449435320485454502f312e310d0a486f73743a20<HONEYPOT>3a353036300d0a557365722d4167656e743a20476f2d687474702d636c69656e742f312e310d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a","method":"GET","user_agent":"Go-http-client/1.1","ja3":"","session":"647b7006-1255-4381-a36e-48f2b449a7bf","seq":1,"duration_ms":100,"bytes_in":118,"bytes_out":79},{"timestamp":"2026-09-23T11:02:15","port":1911,"proto":"tcp","app_proto":"","app_protocol":"http","host":"185.228.81.201","headers":"{\"connection\":\"close\",\"host\":\"185.228.81.201:1911\",\"user-agent\":\"Go-http-client/1.1\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/v2/_catalog","summary":"","payload_hex":"474554202f76322f5f636174616c6f6720485454502f312e310d0a486f73743a203138352e3232382e38312e3230313a313931310d0a557365722d4167656e743a20476f2d687474702d636c69656e742f312e310d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a","method":"GET","user_agent":"Go-http-client/1.1","ja3":"","session":"4a1284bc-bad6-4e02-adb0-e3438782d65b","seq":1,"duration_ms":100,"bytes_in":107,"bytes_out":79},{"timestamp":"2026-09-23T09:52:42","port":5000,"proto":"tcp","app_proto":"","app_protocol":"http","host":"185.228.81.201","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"host\":\"185.228.81.201:5000\",\"user-agent\":\"Mozilla/5.0 (compatible; Odin; https://docs.getodin.com/)\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/","summary":"","payload_hex":"474554202f20485454502f312e310d0a486f73743a203138352e3232382e38312e3230313a353030300d0a557365722d4167656e743a204d6f7a696c6c612f352e302028636f6d70617469626c653b204f64696e3b2068747470733a2f2f646f63732e6765746f64696e2e636f6d2f290d0a4163636570743a202a2f2a0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (compatible; Odin; https://docs.getodin.com/)","ja3":"","session":"1274ffa3-02fe-4b1c-8710-7020f144c8bb","seq":1,"duration_ms":100,"bytes_in":152,"bytes_out":79},{"timestamp":"2026-09-22T17:35:47","port":1911,"proto":"tcp","app_proto":"","app_protocol":"http","host":"185.228.81.201","headers":"{\"accept-encoding\":\"gzip\",\"host\":\"185.228.81.201:1911\",\"user-agent\":\"Go-http-client/1.1\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/","summary":"","payload_hex":"474554202f20485454502f312e310d0a486f73743a203138352e3232382e38312e3230313a313931310d0a557365722d4167656e743a20476f2d687474702d636c69656e742f312e310d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Go-http-client/1.1","ja3":"","session":"9f12da65-6fa9-4083-9a2b-125b26368532","seq":1,"duration_ms":100,"bytes_in":100,"bytes_out":79},{"timestamp":"2026-09-22T17:35:47","port":1911,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"185.228.81.201","headers":"{\"accept-encoding\":\"gzip\",\"host\":\"185.228.81.201:1911\",\"user-agent\":\"Go-http-client/1.1\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/","summary":"","payload_hex":"474554202f20485454502f312e310d0a486f73743a203138352e3232382e38312e3230313a313931310d0a557365722d4167656e743a20476f2d687474702d636c69656e742f312e310d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Go-http-client/1.1","ja3":"96458b3de39df5d47bc5c4a9f10f8f26","session":"a892b8c3-b92d-44da-89dd-875d3f2f934b","seq":1,"duration_ms":101,"bytes_in":100,"bytes_out":79}],"http_methods":[{"method":"GET","count":6},{"method":"POST","count":1}],"distinct_ports_total":4,"top_paths":[{"path":"/","count":4,"ports":3},{"path":"/v2/_catalog","count":1,"ports":1},{"path":"/cgi-bin/authLogin.cgi","count":1,"ports":1},{"path":"/query?q=SHOW+DIAGNOSTICS","count":1,"ports":1}],"distinct_paths_total":4,"top_snis":[],"top_hosts":[{"value":"185.228.81.201","count":5}],"top_alpns":[],"banners":[],"credentials":[],"header_profile":{"signature":["Connection","Content-Length","Content-Type","Host","User-Agent","X-Aggregate-Auth"],"representative":[{"name":"Connection","value":"close","notable":false},{"name":"Content-Length","value":"475","notable":false},{"name":"Content-Type","value":"application/xml","notable":true},{"name":"Host","value":"<HONEYPOT>:5060","notable":false},{"name":"User-Agent","value":"Go-http-client/1.1","notable":false},{"name":"X-Aggregate-Auth","value":"1","notable":true}],"distinct_sets":4,"events_with_headers":7},"tags":[{"tag_id":"CVE-2026-27771","tag_type":"cve","title":"Gitea Container Registry - Unauthorized Private Image Access","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/v2/_catalog","reference_urls":["https://blog.gitea.com/release-of-1.26.2/","https://github.com/go-gitea/gitea/pull/37290","https://github.com/go-gitea/gitea/pull/37610","https://orca.security/resources/blog/gitea-container-registry-vulnerability/"]}],"data_as_of":"2026-09-23T15:10:34.672575+00:00"}