{"ip":"167.71.51.213","total_events":33,"verdict":{"verdict":"malicious","label":"Exploit attempts observed","detail":"1 exploit-path hits","confidence":"high","network_type":"CDN","why":["1 request(s) matched a known exploit path.","Body-carrying methods (POST/PUT/PATCH/DELETE) seen: payload delivery, not just recon.","Under 5 hits, so confidence is medium.","Not in any known-scanner range.","Sent 5,509 bytes: sustained payload delivery, not a single opportunistic request."],"engagement":{"level":"payload","label":"Sustained payload","detail":"5,509 bytes sent","bytes_sent":5509,"session_seconds":0,"persistent":false}},"first_seen":"2026-07-14T19:33:27","last_seen":"2026-07-17T22:56:00","events_24h":0,"events_7d":0,"geo":{"country_code":"DE","country_name":"Germany","region":"Hesse","city":"Frankfurt am Main","lat":50.1169,"lon":8.6837,"asn":14061,"org":"DigitalOcean, LLC"},"source_domain":null,"known_scanners":[],"scanner_tag":{"key":"peeringdb:as14061","label":"DigitalOcean","category":"cdn","url":"https://www.peeringdb.com/asn/14061"},"cve_matches":[{"cve_id":"CVE-2019-7194","title":"QNAP Photo Station < 6.0.3 - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/cgi-bin/authLogin.cgi"},{"cve_id":"CVE-2019-0193","title":"Apache Solr DataImportHandler <8.2.0 - Remote Code Execution","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/solr/admin/cores"},{"cve_id":"CVE-2019-17558","title":"Apache Solr <=8.3.1 - Remote Code Execution","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/solr/admin/cores"},{"cve_id":"CVE-2017-12629","title":"Apache Solr <= 7.1 - XML Entity Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/solr/admin/cores"},{"cve_id":"CVE-2019-0192","title":"Apache Solr - Deserialization of Untrusted Data","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/solr/admin/cores"},{"cve_id":"CVE-2021-27905","title":"Apache Solr <=8.8.1 - Server-Side Request Forgery","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/solr/admin/cores"},{"cve_id":"CVE-2026-27771","title":"Gitea Container Registry - Unauthorized Private Image Access","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/v2/_catalog"},{"cve_id":"CVE-2026-44825","title":"Apache Solr 9.4.0-9.10.1 / 10.0.0 - Hardcoded Default Credentials","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/solr/admin/cores"}],"malware":[],"top_ports":[{"port":9092,"proto":"tcp","label":"Kafka","count":4},{"port":10250,"proto":"tcp","label":"","count":3},{"port":1911,"proto":"tcp","label":"","count":3},{"port":20000,"proto":"tcp","label":"","count":3},{"port":2525,"proto":"tcp","label":"","count":2},{"port":9042,"proto":"tcp","label":"Cassandra","count":2},{"port":11434,"proto":"tcp","label":"","count":2},{"port":6443,"proto":"tcp","label":"k8s API","count":2},{"port":80,"proto":"tcp","label":"HTTP","count":2},{"port":1234,"proto":"tcp","label":"","count":2},{"port":8080,"proto":"tcp","label":"HTTP-alt","count":1},{"port":18789,"proto":"tcp","label":"","count":1},{"port":5060,"proto":"tcp","label":"SIP","count":1},{"port":8086,"proto":"tcp","label":"InfluxDB","count":1},{"port":22,"proto":"tcp","label":"SSH","count":1}],"fingerprints":{"ssh_hassh":[],"tls_ja4":["t13i191000_9dc949149365_e5728521abd4"],"tls_ja3":["96458b3de39df5d47bc5c4a9f10f8f26"],"ja4h":["ge11nn0300_86b6b04cb9cc","ge11nn0400_88d30a62b7ad","po11nn0600_3f2c5e85e3a2","ge11nn0300_0db47b7d240d"]},"fingerprint_peers":{"t13i191000_9dc949149365_e5728521abd4":140,"ge11nn0300_0db47b7d240d":4930,"po11nn0600_3f2c5e85e3a2":96,"ge11nn0300_86b6b04cb9cc":6062,"ge11nn0400_88d30a62b7ad":4697},"user_agents":["Go-http-client/1.1","Mozilla/5.0 (compatible; Odin; https://docs.getodin.com/)"],"timeline":[{"date":"2026-07-14","count":1},{"date":"2026-07-15","count":8},{"date":"2026-07-16","count":12},{"date":"2026-07-17","count":12}],"recent_events":[{"timestamp":"2026-07-17T22:56:00","port":1911,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:1911\",\"user-agent\":\"Mozilla/5.0 (compatible; Odin; https://docs.getodin.com/)\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/","summary":"","payload_hex":"474554202f20485454502f312e310d0a486f73743a20<HONEYPOT>3a313931310d0a557365722d4167656e743a204d6f7a696c6c612f352e302028636f6d70617469626c653b204f64696e3b2068747470733a2f2f646f63732e6765746f64696e2e636f6d2f290d0a4163636570743a202a2f2a0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (compatible; Odin; https://docs.getodin.com/)","ja3":"","session":"f9fac61f-acd1-459f-8ddb-8b5283e40db6","seq":1,"duration_ms":100,"bytes_in":152,"bytes_out":78},{"timestamp":"2026-07-17T20:56:44","port":6443,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"connection\":\"close\",\"host\":\"<HONEYPOT>:6443\",\"user-agent\":\"Go-http-client/1.1\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/solr/admin/cores?action=STATUS&wt=json","summary":"","payload_hex":"474554202f736f6c722f61646d696e2f636f7265733f616374696f6e3d5354415455532677743d6a736f6e20485454502f312e310d0a486f73743a20<HONEYPOT>3a363434330d0a557365722d4167656e743a20476f2d687474702d636c69656e742f312e310d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a","method":"GET","user_agent":"Go-http-client/1.1","ja3":"","session":"ee525714-a2b5-4a33-a1ed-46fed464a588","seq":1,"duration_ms":100,"bytes_in":133,"bytes_out":78},{"timestamp":"2026-07-17T20:56:44","port":6443,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"connection\":\"close\",\"host\":\"<HONEYPOT>:6443\",\"user-agent\":\"Go-http-client/1.1\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/solr/admin/info/system","summary":"","payload_hex":"474554202f736f6c722f61646d696e2f696e666f2f73797374656d20485454502f312e310d0a486f73743a20<HONEYPOT>3a363434330d0a557365722d4167656e743a20476f2d687474702d636c69656e742f312e310d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a","method":"GET","user_agent":"Go-http-client/1.1","ja3":"","session":"5784c941-3df2-41d9-8eda-e667d476a01e","seq":1,"duration_ms":100,"bytes_in":117,"bytes_out":78},{"timestamp":"2026-07-17T14:48:05","port":1234,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"connection\":\"close\",\"host\":\"<HONEYPOT>:1234\",\"user-agent\":\"Go-http-client/1.1\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/v2/_catalog","summary":"","payload_hex":"474554202f76322f5f636174616c6f6720485454502f312e310d0a486f73743a20<HONEYPOT>3a313233340d0a557365722d4167656e743a20476f2d687474702d636c69656e742f312e310d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a","method":"GET","user_agent":"Go-http-client/1.1","ja3":"","session":"dbafe554-b3a2-4c5a-bd8e-fe50ca78f519","seq":1,"duration_ms":100,"bytes_in":107,"bytes_out":78},{"timestamp":"2026-07-17T08:06:25","port":8086,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"connection\":\"close\",\"host\":\"<HONEYPOT>:8086\",\"user-agent\":\"Go-http-client/1.1\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/v2/_catalog","summary":"","payload_hex":"474554202f76322f5f636174616c6f6720485454502f312e310d0a486f73743a20<HONEYPOT>3a383038360d0a557365722d4167656e743a20476f2d687474702d636c69656e742f312e310d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a","method":"GET","user_agent":"Go-http-client/1.1","ja3":"","session":"0e3b5e80-ef3a-4529-89a6-5e1bb93757df","seq":1,"duration_ms":101,"bytes_in":105,"bytes_out":78},{"timestamp":"2026-07-17T06:52:57","port":10250,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:10250\",\"user-agent\":\"Mozilla/5.0 (compatible; Odin; https://docs.getodin.com/)\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/","summary":"","payload_hex":"474554202f20485454502f312e310d0a486f73743a20<HONEYPOT>3a31303235300d0a557365722d4167656e743a204d6f7a696c6c612f352e302028636f6d70617469626c653b204f64696e3b2068747470733a2f2f646f63732e6765746f64696e2e636f6d2f290d0a4163636570743a202a2f2a0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (compatible; Odin; https://docs.getodin.com/)","ja3":"","session":"4d62913d-b216-43bc-a9cd-71626d2cfee1","seq":1,"duration_ms":100,"bytes_in":153,"bytes_out":78},{"timestamp":"2026-07-17T06:31:44","port":11434,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"connection\":\"close\",\"host\":\"<HONEYPOT>:11434\",\"user-agent\":\"Go-http-client/1.1\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/solr/admin/cores?action=STATUS&wt=json","summary":"","payload_hex":"474554202f736f6c722f61646d696e2f636f7265733f616374696f6e3d5354415455532677743d6a736f6e20485454502f312e310d0a486f73743a20<HONEYPOT>3a31313433340d0a557365722d4167656e743a20476f2d687474702d636c69656e742f312e310d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a","method":"GET","user_agent":"Go-http-client/1.1","ja3":"","session":"6363328c-5007-43ff-86bf-e7883ca1b2f8","seq":1,"duration_ms":101,"bytes_in":135,"bytes_out":78},{"timestamp":"2026-07-17T06:31:44","port":11434,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"connection\":\"close\",\"host\":\"<HONEYPOT>:11434\",\"user-agent\":\"Go-http-client/1.1\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/solr/admin/info/system","summary":"","payload_hex":"474554202f736f6c722f61646d696e2f696e666f2f73797374656d20485454502f312e310d0a486f73743a20<HONEYPOT>3a31313433340d0a557365722d4167656e743a20476f2d687474702d636c69656e742f312e310d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a","method":"GET","user_agent":"Go-http-client/1.1","ja3":"","session":"7270d658-d869-41c6-a597-f90d83a40678","seq":1,"duration_ms":100,"bytes_in":119,"bytes_out":78},{"timestamp":"2026-07-17T06:03:42","port":10250,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"connection\":\"close\",\"host\":\"<HONEYPOT>:10250\",\"user-agent\":\"Go-http-client/1.1\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/solr/admin/cores?action=STATUS&wt=json","summary":"","payload_hex":"474554202f736f6c722f61646d696e2f636f7265733f616374696f6e3d5354415455532677743d6a736f6e20485454502f312e310d0a486f73743a20<HONEYPOT>3a31303235300d0a557365722d4167656e743a20476f2d687474702d636c69656e742f312e310d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a","method":"GET","user_agent":"Go-http-client/1.1","ja3":"","session":"50d29930-3856-4fe9-8171-310722d84f85","seq":1,"duration_ms":100,"bytes_in":135,"bytes_out":78},{"timestamp":"2026-07-17T06:03:42","port":10250,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"connection\":\"close\",\"host\":\"<HONEYPOT>:10250\",\"user-agent\":\"Go-http-client/1.1\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/solr/admin/info/system","summary":"","payload_hex":"474554202f736f6c722f61646d696e2f696e666f2f73797374656d20485454502f312e310d0a486f73743a20<HONEYPOT>3a31303235300d0a557365722d4167656e743a20476f2d687474702d636c69656e742f312e310d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a","method":"GET","user_agent":"Go-http-client/1.1","ja3":"","session":"d8ce8bce-48af-4f9a-acde-592391c849f8","seq":1,"duration_ms":101,"bytes_in":119,"bytes_out":78}],"http_methods":[{"method":"GET","count":30},{"method":"POST","count":3}],"distinct_ports_total":18,"top_paths":[{"path":"/","count":10,"ports":7},{"path":"/solr/admin/info/system","count":5,"ports":5},{"path":"/solr/admin/cores?action=STATUS&wt=json","count":5,"ports":5},{"path":"/query?q=SHOW+DIAGNOSTICS","count":5,"ports":5},{"path":"/v2/_catalog","count":4,"ports":3},{"path":"/cgi-bin/authLogin.cgi","count":4,"ports":4}],"distinct_paths_total":6,"top_snis":[],"top_hosts":[],"top_alpns":[],"banners":[],"credentials":[],"header_profile":{"signature":["Accept","Accept-Encoding","Host","User-Agent"],"representative":[{"name":"Accept","value":"*/*","notable":false},{"name":"Accept-Encoding","value":"gzip","notable":false},{"name":"Host","value":"<HONEYPOT>:1911","notable":false},{"name":"User-Agent","value":"Mozilla/5.0 (compatible; Odin; https://docs.getodin.com/)","notable":false}],"distinct_sets":2,"events_with_headers":10},"tags":[{"tag_id":"CVE-2019-7194","tag_type":"cve","title":"QNAP Photo Station < 6.0.3 - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/cgi-bin/authLogin.cgi","reference_urls":["https://medium.com/bugbountywriteup/qnap-pre-auth-root-rce-affecting-450k-devices-on-the-internet-d55488d28a05"]},{"tag_id":"CVE-2019-0193","tag_type":"cve","title":"Apache Solr DataImportHandler <8.2.0 - Remote Code Execution","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/solr/admin/cores","reference_urls":["https://github.com/vulhub/vulhub/tree/master/solr/CVE-2019-0193","https://paper.seebug.org/1009/","https://issues.apache.org/jira/browse/SOLR-13669","https://nvd.nist.gov/vuln/detail/CVE-2019-0193","https://lists.apache.org/thread.html/1addbb49a1fc0947fb32ca663d76d93cfaade35a4848a76d4b4ded9c@%3Cissues.lucene.apache.org%3E"]},{"tag_id":"CVE-2019-17558","tag_type":"cve","title":"Apache Solr <=8.3.1 - Remote Code Execution","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/solr/admin/cores","reference_urls":["https://issues.apache.org/jira/browse/SOLR-13971","https://nvd.nist.gov/vuln/detail/CVE-2019-17558","https://lists.apache.org/thread.html/rb964fe5c4e3fc05f75e8f74bf6b885f456b7a7750c36e9a8045c627a@%3Cissues.lucene.apache.org%3E","http://packetstormsecurity.com/files/157078/Apache-Solr-8.3.0-Velocity-Template-Remote-Code-Execution.html","https://lists.apache.org/thread.html/r0b7b9d4113e6ec1ae1d3d0898c645f758511107ea44f0f3a1210c5d5@%3Cissues.lucene.apache.org%3E"]},{"tag_id":"CVE-2017-12629","tag_type":"cve","title":"Apache Solr <= 7.1 - XML Entity Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/solr/admin/cores","reference_urls":["https://twitter.com/honoki/status/1298636315613974532","https://github.com/vulhub/vulhub/tree/master/solr/CVE-2017-12629-XXE","https://github.com/vulhub/vulhub/tree/master/solr/CVE-2017-12629-RCE","https://nvd.nist.gov/vuln/detail/CVE-2017-12629","http://mail-archives.us.apache.org/mod_mbox/www-announce/201710.mbox/%3CCAOOKt51UO_6Vy%3Dj8W%3Dx1pMbLW9VJfZyFWz7pAnXJC_OAdSZubA%40mail.gmail.com%3E"]},{"tag_id":"CVE-2019-0192","tag_type":"cve","title":"Apache Solr - Deserialization of Untrusted Data","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/solr/admin/cores","reference_urls":["https://github.com/Imanfeng/Apache-Solr-RCE","https://nvd.nist.gov/vuln/detail/CVE-2019-0192"]},{"tag_id":"CVE-2021-27905","tag_type":"cve","title":"Apache Solr <=8.8.1 - Server-Side Request Forgery","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/solr/admin/cores","reference_urls":["https://www.anquanke.com/post/id/238201","https://ubuntu.com/security/CVE-2021-27905","https://nvd.nist.gov/vuln/detail/CVE-2021-27905","https://nsfocusglobal.com/apache-solr-arbitrary-file-read-and-ssrf-vulnerability-threat-alert/","https://lists.apache.org/thread.html/r0ddc3a82bd7523b1453cb7a5e09eb5559517145425074a42eb326b10%40%3Cannounce.apache.org%3E"]},{"tag_id":"CVE-2026-27771","tag_type":"cve","title":"Gitea Container Registry - Unauthorized Private Image Access","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/v2/_catalog","reference_urls":["https://blog.gitea.com/release-of-1.26.2/","https://github.com/go-gitea/gitea/pull/37290","https://github.com/go-gitea/gitea/pull/37610","https://orca.security/resources/blog/gitea-container-registry-vulnerability/"]},{"tag_id":"CVE-2026-44825","tag_type":"cve","title":"Apache Solr 9.4.0-9.10.1 / 10.0.0 - Hardcoded Default Credentials","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/solr/admin/cores","reference_urls":["https://lists.apache.org/thread/5xg6xr99glocp3zsg9ht2zlbwlrst7ch","http://www.openwall.com/lists/oss-security/2026/05/29/6","https://github.com/shinthink/solrradar","https://nvd.nist.gov/vuln/detail/CVE-2026-44825"]}],"data_as_of":"2026-07-30T17:52:50.129676+00:00"}