{"ip":"172.202.106.156","total_events":1,"verdict":{"verdict":"scanner","label":"Recognized scanner","detail":"Stretchoid","confidence":"high","network_type":"CDN","why":["Source IP is in a known scanner range (Stretchoid).","Known research and commercial scanners are labelled as such, not as threats."],"engagement":{"level":"request","label":"Request traffic","detail":"253 bytes sent","bytes_sent":253,"session_seconds":0,"persistent":false}},"first_seen":"2026-09-23T12:06:38","last_seen":"2026-09-23T12:06:38","events_24h":0,"events_7d":1,"geo":{"country_code":"US","country_name":"United States","region":"Iowa","city":"Des Moines","lat":41.6015,"lon":-93.6127,"asn":8075,"org":"Microsoft Corporation"},"source_domain":"azpdcejpa08n.stretchoid.com","known_scanners":["Stretchoid"],"scanner_tag":{"key":"stretchoid","label":"Stretchoid","category":"commercial","url":"https://stretchoid.com"},"cve_matches":[{"cve_id":"CVE-2021-26855","title":"Microsoft Exchange Server SSRF Vulnerability","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/owa/auth/x.js"}],"malware":[],"top_ports":[{"port":443,"proto":"tcp","label":"HTTPS","count":1}],"fingerprints":{"ssh_hassh":[],"tls_ja4":["t13i1909h2_9dc949149365_97f8aa674fd9"],"tls_client_hello":"1603010100010000fc0303b85f5cda3dc231e0bfac377174b1ec838927d3291000656de00e2f228adefeff2017b5628a63e17a59d08198b9b6eecb0a0d46c79715f833c558e6309594ae43c30026cca8cca9c02fc030c02bc02cc013c009c014c00a009c009d002f0035c012000a1303130113020100008d000500050100000000000a000a0008001d001700180019000b00020100000d001a0018080404030807080508060401050106010503060302010203ff010001000010000e000c02683208687474702f312e3100120000002b0009080304030303020301003300260024001d002001475284d742d6017d535813be61e715b17b8a18eb2a32b48fd3d5db574e3a40","tls_ja3":["7c1e207beb00684bbbe144f1b0abe1d5"],"http_akin":["a11cun051_0000004d_6289c865"]},"fingerprint_peers":{"t13i1909h2_9dc949149365_97f8aa674fd9":637,"a11cun051_0000004d_6289c865":7},"akin_families":{},"user_agents":["Mozilla/5.0 zgrab/0.x"],"timeline":[{"date":"2026-09-23","count":1}],"recent_events":[{"timestamp":"2026-09-23T12:06:38","port":443,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"192.3.118.146","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"cookie\":\"X-AnonResource=true; X-AnonResource-Backend=localhost/ecp/default.flt?~3; X-BEResource=localhost/owa/auth/logon.aspx?~3;\",\"host\":\"192.3.118.146\",\"user-agent\":\"Mozilla/5.0 zgrab/0.x\"}","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":["h2","http/1.1"],"url_path":"/owa/auth/x.js","summary":"","payload_hex":"474554202f6f77612f617574682f782e6a7320485454502f312e310d0a486f73743a203139322e332e3131382e3134360d0a557365722d4167656e743a204d6f7a696c6c612f352e30207a677261622f302e780d0a4163636570743a202a2f2a0d0a436f6f6b69653a20582d416e6f6e5265736f757263653d747275653b20582d416e6f6e5265736f757263652d4261636b656e643d6c6f63616c686f73742f6563702f64656661756c742e666c743f7e333b20582d42455265736f757263653d6c6f63616c686f73742f6f77612f617574682f6c6f676f6e2e617370783f7e333b0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 zgrab/0.x","ja3":"7c1e207beb00684bbbe144f1b0abe1d5","session":"9cdf603d-ca06-4ae9-9145-4bd40d2e7548","seq":1,"duration_ms":129,"bytes_in":253,"bytes_out":80}],"http_methods":[{"method":"GET","count":1}],"distinct_ports_total":1,"top_paths":[{"path":"/owa/auth/x.js","count":1,"ports":1}],"distinct_paths_total":1,"top_snis":[],"top_hosts":[{"value":"192.3.118.146","count":1}],"top_alpns":[{"value":"h2, http/1.1","count":1}],"banners":[],"credentials":[],"header_profile":{"signature":["Accept","Accept-Encoding","Cookie","Host","User-Agent"],"representative":[{"name":"Accept","value":"*/*","notable":false},{"name":"Accept-Encoding","value":"gzip","notable":false},{"name":"Cookie","value":"X-AnonResource=true; X-AnonResource-Backend=localhost/ecp/default.flt?~3; X-BEResource=localhost/owa/auth/logon.aspx?~3;","notable":true},{"name":"Host","value":"192.3.118.146","notable":false},{"name":"User-Agent","value":"Mozilla/5.0 zgrab/0.x","notable":false}],"distinct_sets":1,"events_with_headers":1},"tags":[{"tag_id":"CVE-2021-26855","tag_type":"cve","title":"Microsoft Exchange Server SSRF Vulnerability","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/owa/auth/x.js","reference_urls":["https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-26855","https://proxylogon.com/#timeline","https://web.archive.org/web/20210306113850/https://raw.githubusercontent.com/microsoft/CSS-Exchange/main/Security/http-vuln-cve2021-26855.nse","https://gist.github.com/testanull/324546bffab2fe4916d0f9d1f03ffa09","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26855"]}],"data_as_of":"2026-09-24T14:48:07.426903+00:00"}