{"ip":"172.105.109.85","total_events":53,"verdict":{"verdict":"malicious","label":"Exploit attempts observed","detail":"16 exploit-path hits","confidence":"high","network_type":"CDN","why":["16 request(s) matched a known exploit path.","Body-carrying methods (POST/PUT/PATCH/DELETE) seen: payload delivery, not just recon.","5+ hits raise confidence to high.","Not in any known-scanner range.","Sent 13,535 bytes: sustained payload delivery, not a single opportunistic request."],"engagement":{"level":"payload","label":"Sustained payload","detail":"13,535 bytes sent","bytes_sent":13535,"session_seconds":0,"persistent":false}},"first_seen":"2026-10-02T18:01:49","last_seen":"2026-10-02T18:07:51","events_24h":0,"events_7d":53,"geo":{"country_code":"CA","country_name":"Canada","region":"Ontario","city":"Toronto","lat":43.709,"lon":-79.4057,"asn":63949,"org":"Akamai Connected Cloud"},"source_domain":"172-105-109-85.ip.linodeusercontent.com","known_scanners":[],"scanner_tag":{"key":"linode","label":"Linode (Akamai)","category":"hosting_provider","url":"https://www.linode.com/"},"cve_matches":[{"cve_id":"CVE-2020-4427","title":"IBM Data Risk Manager - Authentication Bypass via SAML","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/albatross/saml/idpSelection"},{"cve_id":"CVE-2020-25078","title":"D-Link DCS-2530L/DCS-2670L - Administrator Password Disclosure","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/config/getuser"},{"cve_id":"CVE-2023-23752","title":"Joomla! Webservice - Password Disclosure","severity":"medium","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/index.php/v1/config/application"},{"cve_id":"CVE-2026-21643","title":"Fortinet FortiClientEMS 7.4.4 - SQL Injection","severity":"CRITICAL","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/v1/init_consts"},{"cve_id":"CVE-2026-35616","title":"FortiClient EMS - Authentication Bypass","severity":"HIGH","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/v1/fabric_device_auth/fortigate/init"},{"cve_id":"CVE-2014-9618","title":"Netsweeper - Authentication Bypass","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/webadmin/clientlogin"},{"cve_id":"CVE-2020-10532","title":"WatchGuard Fireware AD Helper Component - Credentials Disclosure","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/rest/domains/list"},{"cve_id":"CVE-2020-2733","title":"JD Edwards EnterpriseOne Tools 9.2 - Information Disclosure","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/manage/fileDownloader"},{"cve_id":"CVE-2020-5777","title":"Magento Mass Importer  <0.7.24 - Remote Auth Bypass","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/index.php/catalogsearch/advanced/result"},{"cve_id":"CVE-2026-33032","title":"Nginx UI - Broken Access Control","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/mcp_message"},{"cve_id":"CVE-2018-20608","title":"Imcat 4.4 - Phpinfo Configuration","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/imcat/root/tools/adbug/binfo.php"},{"cve_id":"CVE-2020-9315","title":"Oracle iPlanet Web Server 7.0.x - Authentication Bypass","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/admingui/version/serverConfigurationsGeneral"},{"cve_id":"CVE-2021-37305","title":"Jeecg Boot <= 2.4.5 - Sensitive Information Disclosure","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/jeecg-boot/sys/user/querySysUser"},{"cve_id":"CVE-2022-24288","title":"Apache Airflow OS Command Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/admin/airflow/code"},{"cve_id":"CVE-2022-34046","title":"WAVLINK WN533A8 - Improper Access Control","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/sysinit.shtml"},{"cve_id":"CVE-2026-1207","title":"Django RasterField - SQL Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/raster/search/?band=1)%20AND%201=CAST((SELECT%20version())%20AS%20INT)--"},{"cve_id":"CVE-2026-23550","title":"Modular DS - Broken Access Control","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/modular-connector/login"},{"cve_id":"CVE-2018-10245","title":"AWStats <= 7.5 - Full Path Disclosure","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/awstats/awstats.pl"},{"cve_id":"CVE-2018-11409","title":"Splunk <=7.0.1 - Information Disclosure","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/__raw/services/server/info/server-info"},{"cve_id":"CVE-2018-16670","title":"CirCarLife <4.3 - Improper Authentication","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/services/user/values.xml"},{"cve_id":"CVE-2019-3401","title":"Atlassian Jira <7.13.3/8.0.0-8.1.1 - Incorrect Authorization","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/secure/ManageFilters.jspa?filter=popular&filterView=popular"},{"cve_id":"CVE-2020-20285","title":"ZZcms - Cross-Site Scripting","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/user/login.php"},{"cve_id":"CVE-2021-24997","title":"WordPress Guppy <=1.1 - Information Disclosure","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-json/guppy/v2/load-guppy-users"},{"cve_id":"CVE-2022-31260","title":"ResourceSpace - Metadata Export","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/pages/csv_export_results_metadata.php"},{"cve_id":"CVE-2023-35155","title":"XWiki - Cross-Site Scripting","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/xwiki/bin/view/Main"},{"cve_id":"CVE-2023-50720","title":"XWiki < 4.10.15 - Email Disclosure","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/bin/view/Main/Search"},{"cve_id":"CVE-2024-54764","title":"ipTIME A2004 - Unauthorized Access","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/login/hostinfo2.cgi"},{"cve_id":"CVE-2026-1277","title":"URL Shortify <= 1.12.1 - Open Redirect","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-admin/admin-ajax.php?action=heartbeat&kc_us_dismiss_admin_notice=1&option_name=welcome_offer&redirect_to=https://int"},{"cve_id":"CVE-2026-21445","title":"Langflow - Broken Access Control","severity":"CRITICAL","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/v1/monitor/messages"},{"cve_id":"CVE-2026-4020","title":"Gravity SMTP WordPress Plugin - Sensitive Information Exposure","severity":"HIGH","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings"}],"malware":[],"top_ports":[{"port":80,"proto":"tcp","label":"HTTP","count":53}],"fingerprints":{"ssh_hassh":[],"tls_ja4":[],"tls_client_hello":"","tls_ja3":[],"http_akin":["b11cun050_0004001e_00ecc3a8","b11cun040_00040013_608dab68","b11cun030_00040012_13ee3d34","b11cun040_08040012_cfad16f7","b11cun040_00060011_0e46e402"]},"fingerprint_peers":{"b11cun050_0004001e_00ecc3a8":79,"b11cun040_00040013_608dab68":4397,"b11cun030_00040012_13ee3d34":4863,"b11cun040_08040012_cfad16f7":2,"b11cun040_00060011_0e46e402":9},"akin_families":{"b11cun050_0004001e_00ecc3a8":{"head":"b11cun050_0004001e_00ecc3a8","shapes":2,"ips":79}},"user_agents":["Mozilla/5.0 (Windows NT 6.2; Win64; x64; rv:109.0) Gecko/20100101 Firefox/112.0","Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:135.0) Gecko/20100101 Firefox/135.0","Mozilla/5.0 (X11; Linux x86_64; rv:1.9.6.20) Gecko/ Firefox/9.0","Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.8 Safari/605.1.15","Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36","Mozilla/5.0 (X11; Linux x86_64; rv:1.9.6.20) Gecko/ Firefox/3.8","Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101 Firefox/102.0","Mozilla/5.0 (Knoppix; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.36"],"timeline":[{"date":"2026-10-02","count":53}],"recent_events":[{"timestamp":"2026-10-02T18:07:51","port":80,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"accept-language\":\"en\",\"host\":\"<HONEYPOT>\",\"user-agent\":\"Mozilla/5.0 (ZZ; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/awstats.pl?config=3K9JyKnVSP5I9CUpaegrPclSCTz","summary":"","payload_hex":"474554202f617773746174732e706c3f636f6e6669673d334b394a794b6e5653503549394355706165677250636c5343547a20485454502f312e310d0a486f73743a20<HONEYPOT>0d0a557365722d4167656e743a204d6f7a696c6c612f352e3020285a5a3b204c696e7578206936383629204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f3133352e302e302e30205361666172692f3533372e33360d0a4163636570743a202a2f2a0d0a4163636570742d4c616e67756167653a20656e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (ZZ; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36","ja3":"","session":"d30deca6-7617-48fe-ab11-cc23de64e870","seq":1,"duration_ms":100,"bytes_in":253,"bytes_out":79},{"timestamp":"2026-10-02T18:07:48","port":80,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"accept-language\":\"en-US,en;q=0.5\",\"host\":\"<HONEYPOT>\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/adminer/","summary":"","payload_hex":"474554202f61646d696e65722f20485454502f312e310d0a486f73743a20<HONEYPOT>0d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f36302e302e333131322e313133205361666172692f3533372e33360d0a4163636570743a202a2f2a0d0a4163636570742d4c616e67756167653a20656e2d55532c656e3b713d302e350d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36","ja3":"","session":"6dfa84a5-4955-453e-87f7-a3cc5bcc3842","seq":1,"duration_ms":101,"bytes_in":245,"bytes_out":79},{"timestamp":"2026-10-02T18:07:46","port":80,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"accept-language\":\"en\",\"host\":\"<HONEYPOT>\",\"user-agent\":\"Mozilla/5.0 (Macintosh, Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3.1 Safari/605.1.15\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/api/modular-connector/login/mhmyf?origin=mo&type=foo","summary":"","payload_hex":"474554202f6170692f6d6f64756c61722d636f6e6e6563746f722f6c6f67696e2f6d686d79663f6f726967696e3d6d6f26747970653d666f6f20485454502f312e310d0a486f73743a20<HONEYPOT>0d0a557365722d4167656e743a204d6f7a696c6c612f352e3020284d6163696e746f73682c20496e74656c204d6163204f5320582031305f31355f3729204170706c655765624b69742f3630352e312e313520284b48544d4c2c206c696b65204765636b6f292056657273696f6e2f31382e332e31205361666172692f3630352e312e31350d0a4163636570743a202a2f2a0d0a4163636570742d4c616e67756167653a20656e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Macintosh, Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3.1 Safari/605.1.15","ja3":"","session":"d920bbdb-ba15-48e2-b144-28331cdac47b","seq":1,"duration_ms":100,"bytes_in":281,"bytes_out":79},{"timestamp":"2026-10-02T18:07:45","port":80,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"accept-language\":\"en\",\"host\":\"<HONEYPOT>\",\"user-agent\":\"Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:137.0) Gecko/20100101 Firefox/137.0\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/wp-admin/admin-ajax.php?action=heartbeat&kc_us_dismiss_admin_notice=1&option_name=welcome_offer&redirect_to=https://interact.sh","summary":"","payload_hex":"474554202f77702d61646d696e2f61646d696e2d616a61782e7068703f616374696f6e3d686561727462656174266b635f75735f6469736d6973735f61646d696e5f6e6f746963653d31266f7074696f6e5f6e616d653d77656c636f6d655f6f666665722672656469726563745f746f3d68747470733a2f2f696e7465726163742e736820485454502f312e310d0a486f73743a20<HONEYPOT>0d0a557365722d4167656e743a204d6f7a696c6c612f352e3020284d6163696e746f73683b20496e74656c204d6163204f5320582031302e31353b2072763a3133372e3029204765636b6f2f32303130303130312046697265666f782f3133372e300d0a4163636570743a202a2f2a0d0a4163636570742d4c616e67756167653a20656e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:137.0) Gecko/20100101 Firefox/137.0","ja3":"","session":"e7578022-7c21-4ecf-8402-7d3905cb0c32","seq":1,"duration_ms":100,"bytes_in":321,"bytes_out":79},{"timestamp":"2026-10-02T18:07:45","port":80,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"accept-language\":\"en\",\"host\":\"<HONEYPOT>\",\"user-agent\":\"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.5 Safari/605.1.15 AlohaBrowser/7.6.0\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/awstats/awstats.pl?config=3K9JyKnVSP5I9CUpaegrPclSCTz","summary":"","payload_hex":"474554202f617773746174732f617773746174732e706c3f636f6e6669673d334b394a794b6e5653503549394355706165677250636c5343547a20485454502f312e310d0a486f73743a20<HONEYPOT>0d0a557365722d4167656e743a204d6f7a696c6c612f352e3020284d6163696e746f73683b20496e74656c204d6163204f5320582031305f313529204170706c655765624b69742f3630352e312e313520284b48544d4c2c206c696b65204765636b6f292056657273696f6e2f31382e35205361666172692f3630352e312e313520416c6f686142726f777365722f372e362e300d0a4163636570743a202a2f2a0d0a4163636570742d4c616e67756167653a20656e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.5 Safari/605.1.15 AlohaBrowser/7.6.0","ja3":"","session":"e408c20e-4136-49af-aed1-fb48ea863a63","seq":1,"duration_ms":100,"bytes_in":297,"bytes_out":79},{"timestamp":"2026-10-02T18:07:41","port":80,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"accept-language\":\"en\",\"host\":\"<HONEYPOT>\",\"user-agent\":\"Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:85.0) Gecko/20100101 Firefox/91.0\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/xwiki/bin/view/Main/Search?sort=score&sortOrder=desc&highlight=true&facet=true&r=1&f_locale=en&f_locale&text=objcontent%3Aemail*","summary":"","payload_hex":"474554202f7877696b692f62696e2f766965772f4d61696e2f5365617263683f736f72743d73636f726526736f72744f726465723d6465736326686967686c696768743d747275652666616365743d7472756526723d3126665f6c6f63616c653d656e26665f6c6f63616c6526746578743d6f626a636f6e74656e74253341656d61696c2a20485454502f312e310d0a486f73743a20<HONEYPOT>0d0a557365722d4167656e743a204d6f7a696c6c612f352e3020285831313b205562756e74753b204c696e7578207838365f36343b2072763a38352e3029204765636b6f2f32303130303130312046697265666f782f39312e300d0a4163636570743a202a2f2a0d0a4163636570742d4c616e67756167653a20656e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:85.0) Gecko/20100101 Firefox/91.0","ja3":"","session":"49fb9626-8d4d-4fba-b30d-4fb818096ee1","seq":1,"duration_ms":101,"bytes_in":314,"bytes_out":79},{"timestamp":"2026-10-02T18:07:41","port":80,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"accept-language\":\"en-US,en;q=0.5\",\"host\":\"<HONEYPOT>\",\"user-agent\":\"Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:138.0) Gecko/20100101 Firefox/138.0\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/editor.php","summary":"","payload_hex":"474554202f656469746f722e70687020485454502f312e310d0a486f73743a20<HONEYPOT>0d0a557365722d4167656e743a204d6f7a696c6c612f352e3020285831313b205562756e74753b204c696e7578207838365f36343b2072763a3133382e3029204765636b6f2f32303130303130312046697265666f782f3133382e300d0a4163636570743a202a2f2a0d0a4163636570742d4c616e67756167653a20656e2d55532c656e3b713d302e350d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:138.0) Gecko/20100101 Firefox/138.0","ja3":"","session":"1f191172-814f-4ae3-938c-8ade15ad8132","seq":1,"duration_ms":101,"bytes_in":210,"bytes_out":79},{"timestamp":"2026-10-02T18:07:38","port":80,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"accept-language\":\"en\",\"host\":\"<HONEYPOT>\",\"user-agent\":\"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11) AppleWebKit/601.1.27 (KHTML, like Gecko) Chrome/47.0.2526.106 Safari/601.1.27\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/api/v1/version","summary":"","payload_hex":"474554202f6170692f76312f76657273696f6e20485454502f312e310d0a486f73743a20<HONEYPOT>0d0a557365722d4167656e743a204d6f7a696c6c612f352e3020284d6163696e746f73683b20496e74656c204d6163204f5320582031305f313129204170706c655765624b69742f3630312e312e323720284b48544d4c2c206c696b65204765636b6f29204368726f6d652f34372e302e323532362e313036205361666172692f3630312e312e32370d0a4163636570743a202a2f2a0d0a4163636570742d4c616e67756167653a20656e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11) AppleWebKit/601.1.27 (KHTML, like Gecko) Chrome/47.0.2526.106 Safari/601.1.27","ja3":"","session":"b3c1283c-f160-4cb7-851c-dc8df18f2b56","seq":1,"duration_ms":101,"bytes_in":247,"bytes_out":79},{"timestamp":"2026-10-02T18:07:38","port":80,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"accept-language\":\"en\",\"host\":\"<HONEYPOT>\",\"user-agent\":\"Mozilla/5.0 (X11; Linux x86_64; rv:137.0) Gecko/20100101 Firefox/137.0\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/api/v1/config/application?public=true","summary":"","payload_hex":"474554202f6170692f76312f636f6e6669672f6170706c69636174696f6e3f7075626c69633d7472756520485454502f312e310d0a486f73743a20<HONEYPOT>0d0a557365722d4167656e743a204d6f7a696c6c612f352e3020285831313b204c696e7578207838365f36343b2072763a3133372e3029204765636b6f2f32303130303130312046697265666f782f3133372e300d0a4163636570743a202a2f2a0d0a4163636570742d4c616e67756167653a20656e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (X11; Linux x86_64; rv:137.0) Gecko/20100101 Firefox/137.0","ja3":"","session":"523c530a-7127-4efb-954f-d7ce7fb3e6a8","seq":1,"duration_ms":100,"bytes_in":217,"bytes_out":79},{"timestamp":"2026-10-02T18:07:37","port":80,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"accept-language\":\"en\",\"host\":\"<HONEYPOT>\",\"user-agent\":\"Mozilla/5.0 (Macintosh, Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.1 Safari/605.1.15\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/services/user/values.xml?var=STATUS","summary":"","payload_hex":"474554202f73657276696365732f757365722f76616c7565732e786d6c3f7661723d53544154555320485454502f312e310d0a486f73743a20<HONEYPOT>0d0a557365722d4167656e743a204d6f7a696c6c612f352e3020284d6163696e746f73682c20496e74656c204d6163204f5320582031305f31355f3729204170706c655765624b69742f3630352e312e313520284b48544d4c2c206c696b65204765636b6f292056657273696f6e2f31362e31205361666172692f3630352e312e31350d0a4163636570743a202a2f2a0d0a4163636570742d4c616e67756167653a20656e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Macintosh, Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.1 Safari/605.1.15","ja3":"","session":"fab32e92-4aa2-46aa-a431-f5f0db47f35e","seq":1,"duration_ms":100,"bytes_in":262,"bytes_out":79}],"http_methods":[{"method":"GET","count":50},{"method":"POST","count":2},{"method":"HEAD","count":1}],"distinct_ports_total":1,"top_paths":[{"path":"/","count":3,"ports":1},{"path":"/pages/csv_export_results_metadata.php?k=zulu&personaldata=0&allavailable=true&submit=1","count":1,"ports":1},{"path":"/i18n/component/JS?locale=en-US","count":1,"ports":1},{"path":"/adminer/","count":1,"ports":1},{"path":"/pentaho/Login","count":1,"ports":1},{"path":"/aj.html?a=devi","count":1,"ports":1},{"path":"/editor.php","count":1,"ports":1},{"path":"/user/login.php","count":1,"ports":1},{"path":"/mcp_message","count":1,"ports":1},{"path":"/login.html","count":1,"ports":1},{"path":"/api/v1/version","count":1,"ports":1},{"path":"/index.php?user/login","count":1,"ports":1},{"path":"/api/v1/init_consts","count":1,"ports":1},{"path":"/config/getuser?index=0","count":1,"ports":1},{"path":"/signin","count":1,"ports":1}],"distinct_paths_total":51,"top_snis":[],"top_hosts":[],"top_alpns":[],"banners":[],"credentials":[],"header_profile":{"signature":["Accept","Accept-Encoding","Accept-Language","Host","User-Agent"],"representative":[{"name":"Accept","value":"*/*","notable":false},{"name":"Accept-Encoding","value":"gzip","notable":false},{"name":"Accept-Language","value":"en","notable":false},{"name":"Host","value":"<HONEYPOT>","notable":false},{"name":"User-Agent","value":"Mozilla/5.0 (ZZ; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36","notable":false}],"distinct_sets":1,"events_with_headers":10},"tags":[{"tag_id":"CVE-2020-4427","tag_type":"cve","title":"IBM Data Risk Manager - Authentication Bypass via SAML","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/albatross/saml/idpSelection","reference_urls":["https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/ibm_drm_rce.rb","https://seclists.org/fulldisclosure/2020/Apr/33","https://www.ibm.com/support/pages/node/6206875","https://nvd.nist.gov/vuln/detail/CVE-2020-4427"]},{"tag_id":"CVE-2020-25078","tag_type":"cve","title":"D-Link DCS-2530L/DCS-2670L - Administrator Password Disclosure","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/config/getuser","reference_urls":["https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10180","https://twitter.com/Dogonsecurity/status/1273251236167516161","https://nvd.nist.gov/vuln/detail/CVE-2020-25078","https://github.com/pen4uin/vulnerability-research-list","https://github.com/ArrestX/--POC"]},{"tag_id":"CVE-2023-23752","tag_type":"cve","title":"Joomla! Webservice - Password Disclosure","severity":"medium","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/index.php/v1/config/application","reference_urls":["https://unsafe.sh/go-149780.html","https://twitter.com/gov_hack/status/1626471960141238272/photo/1","https://developer.joomla.org/security-centre/894-20230201-core-improper-access-check-in-webservice-endpoints.html","https://nvd.nist.gov/vuln/detail/CVE-2023-23552","https://github.com/20142995/pocsuite3"]},{"tag_id":"CVE-2026-21643","tag_type":"cve","title":"Fortinet FortiClientEMS 7.4.4 - SQL Injection","severity":"CRITICAL","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/v1/init_consts","reference_urls":[]},{"tag_id":"CVE-2026-35616","tag_type":"cve","title":"FortiClient EMS - Authentication Bypass","severity":"HIGH","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/v1/fabric_device_auth/fortigate/init","reference_urls":[]},{"tag_id":"CVE-2014-9618","tag_type":"cve","title":"Netsweeper - Authentication Bypass","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/webadmin/clientlogin","reference_urls":["https://packetstormsecurity.com/files/download/133034/netsweeper-issues.tgz","https://nvd.nist.gov/vuln/detail/CVE-2014-9618","https://www.exploit-db.com/exploits/37933/","http://packetstormsecurity.com/files/133034/Netsweeper-Bypass-XSS-Redirection-SQL-Injection-Execution.html","https://github.com/ARPSyndicate/kenzer-templates"]},{"tag_id":"CVE-2020-10532","tag_type":"cve","title":"WatchGuard Fireware AD Helper Component - Credentials Disclosure","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/rest/domains/list","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-10532","https://www.exploit-db.com/exploits/48203","https://www.watchguard.com/wgrd-blog/tdr-ad-helper-credential-disclosure-vulnerability"]},{"tag_id":"CVE-2020-2733","tag_type":"cve","title":"JD Edwards EnterpriseOne Tools 9.2 - Information Disclosure","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/manage/fileDownloader","reference_urls":["https://redrays.io/cve-2020-2733-jd-edwards/","https://www.oracle.com/security-alerts/cpuapr2020.html","https://nvd.nist.gov/vuln/detail/CVE-2020-2733","https://github.com/ARPSyndicate/cvemon","https://github.com/ARPSyndicate/kenzer-templates"]},{"tag_id":"CVE-2020-5777","tag_type":"cve","title":"Magento Mass Importer  <0.7.24 - Remote Auth Bypass","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/index.php/catalogsearch/advanced/result","reference_urls":["https://github.com/dweeves/magmi-git/blob/18bd9ec905c90bfc9eaed0c2bf2d3525002e33b9/magmi/inc/magmi_auth.php#L35","https://nvd.nist.gov/vuln/detail/CVE-2020-5777","https://www.tenable.com/security/research/tra-2020-51","https://github.com/404notf0und/CVE-Flow","https://github.com/ARPSyndicate/cvemon"]},{"tag_id":"CVE-2026-33032","tag_type":"cve","title":"Nginx UI - Broken Access Control","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/mcp_message","reference_urls":["https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-h6c2-x2m2-mwhf","https://github.com/0xJacky/nginx-ui/commit/413dc631","https://nvd.nist.gov/vuln/detail/CVE-2026-33032"]},{"tag_id":"CVE-2018-20608","tag_type":"cve","title":"Imcat 4.4 - Phpinfo Configuration","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/imcat/root/tools/adbug/binfo.php","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2018-20608","https://github.com/SexyBeast233/SecBooks"]},{"tag_id":"CVE-2020-9315","tag_type":"cve","title":"Oracle iPlanet Web Server 7.0.x - Authentication Bypass","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/admingui/version/serverConfigurationsGeneral","reference_urls":["https://www.cvebase.com/cve/2020/9315","https://www.oracle.com/support/lifetime-support/","https://www.oracle.com/us/assets/lifetime-support-middleware-069163.pdf","https://wwws.nightwatchcybersecurity.com/2020/05/10/two-vulnerabilities-in-oracles-iplanet-web-server-cve-2020-9315-and-cve-2020-9314/","https://nvd.nist.gov/vuln/detail/CVE-2020-9315"]},{"tag_id":"CVE-2021-37305","tag_type":"cve","title":"Jeecg Boot <= 2.4.5 - Sensitive Information Disclosure","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/jeecg-boot/sys/user/querySysUser","reference_urls":["https://github.com/jeecgboot/jeecg-boot/issues/2794","https://nvd.nist.gov/vuln/detail/CVE-2021-37305"]},{"tag_id":"CVE-2022-24288","tag_type":"cve","title":"Apache Airflow OS Command Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/admin/airflow/code","reference_urls":["https://github.com/advisories/GHSA-3v7g-4pg3-7r6j","https://nvd.nist.gov/vuln/detail/CVE-2022-24288","https://lists.apache.org/thread/dbw5ozcmr0h0lhs0yjph7xdc64oht23t","https://github.com/ARPSyndicate/kenzer-templates","https://github.com/Hax0rG1rl/my_cve_and_bounty_poc"]},{"tag_id":"CVE-2022-34046","tag_type":"cve","title":"WAVLINK WN533A8 - Improper Access Control","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/sysinit.shtml","reference_urls":["https://drive.google.com/file/d/18ECQEqZ296LDzZ0wErgqnNfen1jCn0mG/view?usp=sharing","https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-34046","http://packetstormsecurity.com/files/167890/Wavlink-WN533A8-Password-Disclosure.html","https://nvd.nist.gov/vuln/detail/CVE-2022-34046","https://github.com/ARPSyndicate/cvemon"]},{"tag_id":"CVE-2026-1207","tag_type":"cve","title":"Django RasterField - SQL Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/raster/search/?band=1)%20AND%201=CAST((SELECT%20version())%20AS%20INT)--","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-1207","https://www.djangoproject.com/weblog/2026/feb/03/security-releases/","https://github.com/django/django/commit/81aa5292967cd09319c45fe2c1a525ce7b6684d8"]},{"tag_id":"CVE-2026-23550","tag_type":"cve","title":"Modular DS - Broken Access Control","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/modular-connector/login","reference_urls":["https://help.modulards.com/en/article/modular-ds-security-release-modular-connector-252-dm3mv0/","https://patchstack.com/database/wordpress/plugin/modular-connector/vulnerability/wordpress-modular-ds-monitor-update-and-backup-multiple-websites-plugin-2-5-1-privilege-escalation-vulnerability"]},{"tag_id":"CVE-2018-10245","tag_type":"cve","title":"AWStats <= 7.5 - Full Path Disclosure","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/awstats/awstats.pl","reference_urls":["https://github.com/eldy/awstats","https://awstats.sourceforge.io/"]},{"tag_id":"CVE-2018-11409","tag_type":"cve","title":"Splunk <=7.0.1 - Information Disclosure","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/__raw/services/server/info/server-info","reference_urls":["https://github.com/kofa2002/splunk","https://www.exploit-db.com/exploits/44865/","http://web.archive.org/web/20211208114213/https://securitytracker.com/id/1041148","https://nvd.nist.gov/vuln/detail/CVE-2018-11409","http://www.securitytracker.com/id/1041148"]},{"tag_id":"CVE-2018-16670","tag_type":"cve","title":"CirCarLife <4.3 - Improper Authentication","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/services/user/values.xml","reference_urls":["https://www.exploit-db.com/exploits/45384","https://github.com/SadFud/Exploits/tree/master/Real%20World/Suites/cir-pwn-life","https://www.exploit-db.com/exploits/45384/","https://nvd.nist.gov/vuln/detail/CVE-2018-16670","https://github.com/20142995/sectool"]},{"tag_id":"CVE-2019-3401","tag_type":"cve","title":"Atlassian Jira <7.13.3/8.0.0-8.1.1 - Incorrect Authorization","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/secure/ManageFilters.jspa?filter=popular&filterView=popular","reference_urls":["https://jira.atlassian.com/browse/JRASERVER-69244","https://nvd.nist.gov/vuln/detail/CVE-2019-3401"]},{"tag_id":"CVE-2020-20285","tag_type":"cve","title":"ZZcms - Cross-Site Scripting","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/user/login.php","reference_urls":["https://github.com/iohex/ZZCMS/blob/master/zzcms2019_login_xss.md","https://nvd.nist.gov/vuln/detail/CVE-2020-20285","https://github.com/ARPSyndicate/kenzer-templates"]},{"tag_id":"CVE-2021-24997","tag_type":"cve","title":"WordPress Guppy <=1.1 - Information Disclosure","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-json/guppy/v2/load-guppy-users","reference_urls":["https://www.exploit-db.com/exploits/50540","https://patchstack.com/database/vulnerability/wp-guppy/wordpress-wp-guppy-plugin-1-2-sensitive-information-disclosure-vulnerability","https://wpscan.com/vulnerability/747e6c7e-a167-4d82-b6e6-9e8613f0e900","https://nvd.nist.gov/vuln/detail/CVE-2021-24997","https://github.com/ARPSyndicate/cvemon"]},{"tag_id":"CVE-2022-31260","tag_type":"cve","title":"ResourceSpace - Metadata Export","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/pages/csv_export_results_metadata.php","reference_urls":["https://github.com/grymer/CVE/blob/master/CVE-2022-31260.md","https://nvd.nist.gov/vuln/detail/CVE-2022-31260"]},{"tag_id":"CVE-2023-35155","tag_type":"cve","title":"XWiki - Cross-Site Scripting","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/xwiki/bin/view/Main","reference_urls":["https://jira.xwiki.org/browse/XWIKI-20370","https://nvd.nist.gov/vuln/detail/CVE-2023-35155"]},{"tag_id":"CVE-2023-50720","tag_type":"cve","title":"XWiki < 4.10.15 - Email Disclosure","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/bin/view/Main/Search","reference_urls":["https://jira.xwiki.org/browse/XWIKI-20371","https://nvd.nist.gov/vuln/detail/CVE-2023-50720"]},{"tag_id":"CVE-2024-54764","tag_type":"cve","title":"ipTIME A2004 - Unauthorized Access","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/login/hostinfo2.cgi","reference_urls":["https://github.com/Shuanunio/CVE_Requests/blob/main/ipTIME/A2004/ipTIME_A2004_unauthorized_access_vulnerability_second.md","https://nvd.nist.gov/vuln/detail/CVE-2024-54764"]},{"tag_id":"CVE-2026-1277","tag_type":"cve","title":"URL Shortify <= 1.12.1 - Open Redirect","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-admin/admin-ajax.php?action=heartbeat&kc_us_dismiss_admin_notice=1&option_name=welcome_offer&redirect_to=https://int","reference_urls":["https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/url-shortify/url-shortify-1121-unauthenticated-open-redirect-via-redirect-to-parameter","https://nvd.nist.gov/vuln/detail/CVE-2026-1277"]},{"tag_id":"CVE-2026-21445","tag_type":"cve","title":"Langflow - Broken Access Control","severity":"CRITICAL","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/v1/monitor/messages","reference_urls":[]},{"tag_id":"CVE-2026-4020","tag_type":"cve","title":"Gravity SMTP WordPress Plugin - Sensitive Information Exposure","severity":"HIGH","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings","reference_urls":[]}],"data_as_of":"2026-10-04T15:12:13.101762+00:00"}