{"ip":"167.172.205.210","total_events":237,"verdict":{"verdict":"scanner","label":"Recognized scanner","detail":"binaryedge","confidence":"high","network_type":"CDN","why":["Source IP is in a known scanner range (binaryedge).","Known research and commercial scanners are labelled as such, not as threats."],"engagement":{"level":"payload","label":"Sustained payload","detail":"32,118 bytes sent","bytes_sent":32118,"session_seconds":0,"persistent":false}},"first_seen":"2026-08-25T23:11:29","last_seen":"2026-09-02T12:38:45","events_24h":0,"events_7d":0,"geo":{"country_code":"US","country_name":"United States","region":"California","city":"Santa Clara","lat":37.3486,"lon":-121.9732,"asn":14061,"org":"DigitalOcean, LLC"},"source_domain":"sfo2-59.boron.do.prod.binaryedge.ninja","known_scanners":["binaryedge","BinaryEdge"],"scanner_tag":{"key":"binaryedge","label":"BinaryEdge","category":"commercial","url":"https://www.binaryedge.io/"},"cve_matches":[{"cve_id":"CVE-2018-13379","title":"Fortinet FortiOS SSL VPN path traversal","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/remote/fgt_lang"},{"cve_id":"CVE-2022-40684","title":"Fortinet - Authentication Bypass","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/v2/cmdb/system/admin"},{"cve_id":"CVE-2023-40044","title":"WS_FTP Server - Insecure Deserialization","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/AHT/AHT_UI/public/js/app.min.js"},{"cve_id":"CVE-2024-0012","title":"PAN-OS Management Web Interface - Authentication Bypass","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/php/ztp_gate.php/.js.map"},{"cve_id":"CVE-2025-0282","title":"Ivanti Connect Secure - Stack-based Buffer Overflow","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/dana-na/auth/url_default/welcome.cgi"},{"cve_id":"CVE-2026-1340","title":"Ivanti EPMM < 12.8.0.0 - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/mifs/user/login.jsp"},{"cve_id":"CVE-2020-3452","title":"Cisco Adaptive Security Appliance (ASA)/Firepower Threat Defense (FTD) - Local File Inclusion","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/+CSCOT+/oem-customization?app=AnyConnect&type=oem&platform=..&resource-type=..&name=%2bCSCOE%2b/portal_inc.lua"},{"cve_id":"CVE-2017-5983","title":"JIRA Workflow Designer Plugin in Atlassian JIRA Server > 6.3.0 - Remote Code Execution (XXE)","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/jira/secure/Dashboard.jspa"},{"cve_id":"CVE-2007-4556","title":"OpenSymphony XWork/Apache Struts2 - Remote Code Execution","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/login.action"}],"malware":[],"top_ports":[{"port":4443,"proto":"tcp","label":"","count":79},{"port":50050,"proto":"tcp","label":"","count":47},{"port":135,"proto":"tcp","label":"MSRPC","count":47},{"port":4991,"proto":"tcp","label":"","count":46},{"port":44818,"proto":"tcp","label":"","count":18}],"fingerprints":{"ssh_hassh":[],"tls_ja4":["t13i311000_e8f1e7e78f70_d41ae481755e","t13i3112h1_e8f1e7e78f70_d339722ba4af"],"tls_client_hello":"","tls_ja3":["c12b4ccd5320bbb380ca1a9df90f771d","48eb9b1182293f55c0710654b7b12fc6"],"http_akin":[]},"fingerprint_peers":{"t13i3112h1_e8f1e7e78f70_d339722ba4af":45,"t13i311000_e8f1e7e78f70_d41ae481755e":885},"user_agents":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36"],"timeline":[{"date":"2026-08-25","count":79},{"date":"2026-08-27","count":47},{"date":"2026-08-28","count":47},{"date":"2026-08-30","count":46},{"date":"2026-09-02","count":18}],"recent_events":[{"timestamp":"2026-09-02T12:38:45","port":44818,"proto":"tcp","app_proto":"tls","app_protocol":"rdp","host":"","headers":"","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"","summary":"\u0003\u0000\u0000*%�\u0000\u0000\u0000\u0000\u0000Cookie: mstshash=beio\r\n\u0001\u0000\b\u0000\u0003\u0000\u0000\u0000","payload_hex":"0300002a25e00000000000436f6f6b69653a206d737473686173683d6265696f0d0a0100080003000000","method":"","user_agent":"","ja3":"c12b4ccd5320bbb380ca1a9df90f771d","session":"7536a3e0-54a9-4309-822e-cc01f7efbe47","seq":1,"duration_ms":254,"bytes_in":42,"bytes_out":15,"enriched":{"digest":"1c1633a9aa337eda","label":"RDP (X.224)","strings":["Cookie: mstshash=beio"]}},{"timestamp":"2026-09-02T12:38:43","port":44818,"proto":"tcp","app_proto":"tls","app_protocol":"tls","host":"","headers":"","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"","summary":"\u0016\u0003\u0000\u0000S\u0001\u0000\u0000O\u0003\u0000?G���,���`~�\u0000��{�Ֆ�w����<=�o�\u0010n\u0000\u0000(\u0000\u0016\u0000\u0013\u0000\n\u0000f\u0000\u0005\u0000\u0004\u0000e\u0000d\u0000c\u0000b\u0000a\u0000`\u0000\u0015\u0000\u0012\u0000\t\u0000\u0014\u0000\u0011\u0000\b\u0000\u0006\u0000\u0003\u0001\u0000","payload_hex":"16030000530100004f03003f47d7f7ba2ceeeab2607ef300fd827bb9d596c8779be6c4db3c3ddb6fef106e00002800160013000a006600050004006500640063006200610060001500120009001400110008000600030100","method":"","user_agent":"","ja3":"c12b4ccd5320bbb380ca1a9df90f771d","session":"a745eab4-31f9-43c7-8f9c-60a38005e3d7","seq":1,"duration_ms":253,"bytes_in":88,"bytes_out":15,"enriched":{"digest":"28bd7217cbe4629c","label":"TLS/SSL","strings":["edcba`"]}},{"timestamp":"2026-09-02T12:38:41","port":44818,"proto":"tcp","app_proto":"tls","app_protocol":"tls","host":"","headers":"","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"","summary":"HELP\r\n","payload_hex":"48454c500d0a","method":"","user_agent":"","ja3":"c12b4ccd5320bbb380ca1a9df90f771d","session":"7abf65e7-7a41-4184-a34f-7d03614072b4","seq":1,"duration_ms":256,"bytes_in":6,"bytes_out":15,"enriched":{"digest":"d6616dd899abc961","strings":["HELP"]}},{"timestamp":"2026-09-02T12:38:39","port":44818,"proto":"tcp","app_proto":"tls","app_protocol":"tls","host":"","headers":"","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"","summary":"\u0000\f\u0000\u0000\u0010\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000","payload_hex":"000c000010000000000000000000","method":"","user_agent":"","ja3":"c12b4ccd5320bbb380ca1a9df90f771d","session":"70632c44-696e-4676-8a01-b41a0619b0ef","seq":1,"duration_ms":253,"bytes_in":14,"bytes_out":15},{"timestamp":"2026-09-02T12:38:36","port":44818,"proto":"tcp","app_proto":"tls","app_protocol":"tls","host":"","headers":"","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"","summary":"\u0000\u001e\u0000\u0006\u0001\u0000\u0000\u0001\u0000\u0000\u0000\u0000\u0000\u0000\u0007version\u0004bind\u0000\u0000\u0010\u0000\u0003","payload_hex":"001e0006010000010000000000000776657273696f6e0462696e640000100003","method":"","user_agent":"","ja3":"c12b4ccd5320bbb380ca1a9df90f771d","session":"027691f4-bbee-479a-8dbd-0f04c6eca09c","seq":1,"duration_ms":256,"bytes_in":32,"bytes_out":15,"enriched":{"digest":"75f479f7d331db45","strings":["version","bind"]}},{"timestamp":"2026-09-02T12:38:34","port":44818,"proto":"tcp","app_proto":"tls","app_protocol":"tls","host":"","headers":"","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"","summary":"�\u0000\u0000(r�\u001d\u0013\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0002\u0000\u0001��\u0000\u0001�|\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000","payload_hex":"8000002872fe1d130000000000000002000186a00001977c0000000000000000000000000000000000000000","method":"","user_agent":"","ja3":"c12b4ccd5320bbb380ca1a9df90f771d","session":"57bce2d8-722c-492a-83f9-ef1e0a27fb75","seq":1,"duration_ms":254,"bytes_in":44,"bytes_out":15},{"timestamp":"2026-09-02T12:38:32","port":44818,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"","headers":"","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"","summary":"OPTIONS / RTSP/1.0\r\n\r\n","payload_hex":"4f5054494f4e53202f20525453502f312e300d0a0d0a","method":"","user_agent":"","ja3":"c12b4ccd5320bbb380ca1a9df90f771d","session":"960a1251-2623-461a-b222-e20b2be2d06d","seq":1,"duration_ms":254,"bytes_in":22,"bytes_out":80,"enriched":{"digest":"b6bc3f9a3eb2980d","label":"HTTP","strings":["OPTIONS / RTSP/1.0"]}},{"timestamp":"2026-09-02T12:38:30","port":44818,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"","headers":"","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/","summary":"","payload_hex":"4f5054494f4e53202f20485454502f312e300d0a0d0a","method":"OPTIONS","user_agent":"","ja3":"c12b4ccd5320bbb380ca1a9df90f771d","session":"8605d457-efab-45fa-9f73-e893183ec132","seq":1,"duration_ms":253,"bytes_in":22,"bytes_out":80},{"timestamp":"2026-09-02T12:38:27","port":44818,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"","headers":"","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/","summary":"","payload_hex":"474554202f20485454502f312e300d0a0d0a","method":"GET","user_agent":"","ja3":"c12b4ccd5320bbb380ca1a9df90f771d","session":"234dce9d-c4db-457b-a406-e357d80296b6","seq":1,"duration_ms":256,"bytes_in":18,"bytes_out":80},{"timestamp":"2026-09-02T12:38:25","port":44818,"proto":"tcp","app_proto":"tls","app_protocol":"tls","host":"","headers":"","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"","summary":"\r\n\r\n","payload_hex":"0d0a0d0a","method":"","user_agent":"","ja3":"c12b4ccd5320bbb380ca1a9df90f771d","session":"7cc6ae1f-fedb-4b18-84e5-c93bad5aa750","seq":1,"duration_ms":254,"bytes_in":4,"bytes_out":15}],"http_methods":[{"method":"GET","count":90},{"method":"OPTIONS","count":8}],"distinct_ports_total":5,"top_paths":[{"path":"/","count":17,"ports":5},{"path":"/nice%20ports%2C/Tri%6Eity.txt%2ebak","count":3,"ports":3},{"path":"/client","count":1,"ports":1},{"path":"/api/v2/cmdb/system/admin/admin","count":1,"ports":1},{"path":"/login","count":1,"ports":1},{"path":"/.env","count":1,"ports":1},{"path":"/rdweb","count":1,"ports":1},{"path":"/admin","count":1,"ports":1},{"path":"/mftp","count":1,"ports":1},{"path":"/webui/","count":1,"ports":1},{"path":"/wsman","count":1,"ports":1},{"path":"/Login.jsp","count":1,"ports":1},{"path":"/configurations","count":1,"ports":1},{"path":"/login.action","count":1,"ports":1},{"path":"/human.aspx","count":1,"ports":1}],"distinct_paths_total":80,"top_snis":[],"top_hosts":[],"top_alpns":[{"value":"http/1.1","count":79}],"banners":[],"credentials":[],"header_profile":null,"tags":[{"tag_id":"CVE-2018-13379","tag_type":"cve","title":"Fortinet FortiOS SSL VPN path traversal","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/remote/fgt_lang","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2018-13379"]},{"tag_id":"CVE-2022-40684","tag_type":"cve","title":"Fortinet - Authentication Bypass","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/v2/cmdb/system/admin","reference_urls":["https://github.com/horizon3ai/CVE-2022-40684/blob/master/CVE-2022-40684.py","https://securityonline.info/researchers-have-developed-cve-2022-40684-poc-exploit-code/","https://socradar.io/what-do-you-need-to-know-about-fortinet-critical-authentication-bypass-vulnerability-cve-2022-40684/","https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-40684","https://nvd.nist.gov/vuln/detail/CVE-2022-40684"]},{"tag_id":"CVE-2023-40044","tag_type":"cve","title":"WS_FTP Server - Insecure Deserialization","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/AHT/AHT_UI/public/js/app.min.js","reference_urls":["https://attackerkb.com/topics/bn32f9sNax/cve-2023-40044","https://censys.com/cve-2023-40044/","https://www.progress.com/ws_ftp","https://www.rapid7.com/blog/post/2023/09/29/etr-critical-vulnerabilities-in-ws_ftp-server/","https://www.theregister.com/2023/10/02/ws_ftp_update/"]},{"tag_id":"CVE-2024-0012","tag_type":"cve","title":"PAN-OS Management Web Interface - Authentication Bypass","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/php/ztp_gate.php/.js.map","reference_urls":["https://security.paloaltonetworks.com/CVE-2024-0012","https://labs.watchtowr.com/pots-and-pans-aka-an-sslvpn-palo-alto-pan-os-cve-2024-0012-and-cve-2024-9474/","https://nvd.nist.gov/vuln/detail/CVE-2024-0012"]},{"tag_id":"CVE-2025-0282","tag_type":"cve","title":"Ivanti Connect Secure - Stack-based Buffer Overflow","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/dana-na/auth/url_default/welcome.cgi","reference_urls":["https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-0282-CVE-2025-0283","https://labs.watchtowr.com/exploitation-walkthrough-and-techniques-ivanti-connect-secure-rce-cve-2025-0282/","https://cloud.google.com/blog/topics/threat-intelligence/ivanti-connect-secure-vpn-zero-day","https://nvd.nist.gov/vuln/detail/CVE-2025-0282"]},{"tag_id":"CVE-2026-1340","tag_type":"cve","title":"Ivanti EPMM < 12.8.0.0 - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/mifs/user/login.jsp","reference_urls":["https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM","https://nvd.nist.gov/vuln/detail/CVE-2026-1340"]},{"tag_id":"CVE-2020-3452","tag_type":"cve","title":"Cisco Adaptive Security Appliance (ASA)/Firepower Threat Defense (FTD) - Local File Inclusion","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/+CSCOT+/oem-customization?app=AnyConnect&type=oem&platform=..&resource-type=..&name=%2bCSCOE%2b/portal_inc.lua","reference_urls":["https://twitter.com/aboul3la/status/1286012324722155525","http://packetstormsecurity.com/files/158646/Cisco-ASA-FTD-Remote-File-Disclosure.html","http://packetstormsecurity.com/files/158647/Cisco-Adaptive-Security-Appliance-Software-9.11-Local-File-Inclusion.html","http://packetstormsecurity.com/files/159523/Cisco-ASA-FTD-9.6.4.42-Path-Traversal.html","http://packetstormsecurity.com/files/160497/Cisco-ASA-9.14.1.10-FTD-6.6.0.1-Path-Traversal.html"]},{"tag_id":"CVE-2017-5983","tag_type":"cve","title":"JIRA Workflow Designer Plugin in Atlassian JIRA Server > 6.3.0 - Remote Code Execution (XXE)","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/jira/secure/Dashboard.jspa","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2017-5983","https://code-white.com/blog/2017-04-amf/"]},{"tag_id":"CVE-2007-4556","tag_type":"cve","title":"OpenSymphony XWork/Apache Struts2 - Remote Code Execution","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/login.action","reference_urls":["https://www.guildhab.top/?p=2326","https://nvd.nist.gov/vuln/detail/CVE-2007-4556","https://cwiki.apache.org/confluence/display/WW/S2-001","http://forums.opensymphony.com/ann.jspa?annID=54","http://issues.apache.org/struts/browse/WW-2030"]}],"data_as_of":"2026-09-23T00:36:25.019039+00:00"}