{"ip":"174.172.60.127","total_events":1,"verdict":{"verdict":"probing","label":"Low-level probing","detail":null,"confidence":"low","network_type":"residential ISP","why":["1 event(s), fewer than 10 distinct ports, no exploit payloads.","Not in any known-scanner range."],"engagement":{"level":"request","label":"Request traffic","detail":"85 bytes sent","bytes_sent":85,"session_seconds":0,"persistent":false}},"first_seen":"2026-09-05T11:15:17","last_seen":"2026-09-05T11:15:17","events_24h":0,"events_7d":1,"geo":{"country_code":"US","country_name":"United States","region":"Maryland","city":"Baltimore","lat":39.3407,"lon":-76.6753,"asn":7922,"org":"Comcast Cable Communications, LLC"},"source_domain":"c-174-172-60-127.hsd1.md.comcast.net","known_scanners":[],"scanner_tag":{"key":"peeringdb:as7922","label":"Comcast","category":"isp","url":"https://www.peeringdb.com/asn/7922"},"cve_matches":[{"cve_id":"CVE-2026-5027","title":"Langflow <= 1.8.4 - Path Traversal to RCE via File Upload","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/v1/auto_login"}],"malware":[],"top_ports":[{"port":7860,"proto":"tcp","label":"","count":1}],"fingerprints":{"ssh_hassh":[],"tls_ja4":[],"tls_ja3":[],"ja4h":["ge11nn0200_f24fcf356134"]},"fingerprint_peers":{"ge11nn0200_f24fcf356134":58},"user_agents":[],"timeline":[{"date":"2026-09-05","count":1}],"recent_events":[{"timestamp":"2026-09-05T11:15:17","port":7860,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"connection\":\"keep-alive\",\"host\":\"<HONEYPOT>:7860\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/api/v1/auto_login","summary":"","payload_hex":"474554202f6170692f76312f6175746f5f6c6f67696e20485454502f312e310d0a486f73743a20<HONEYPOT>3a373836300d0a436f6e6e656374696f6e3a206b6565702d616c6976650d0a0d0a","method":"GET","user_agent":"","ja3":"","session":"dd3933b5-8333-42a9-a41a-40c786c4b913","seq":1,"duration_ms":100,"bytes_in":85,"bytes_out":79}],"http_methods":[{"method":"GET","count":1}],"distinct_ports_total":1,"top_paths":[{"path":"/api/v1/auto_login","count":1,"ports":1}],"distinct_paths_total":1,"top_snis":[],"top_hosts":[],"top_alpns":[],"banners":[],"credentials":[],"header_profile":{"signature":["Connection","Host"],"representative":[{"name":"Connection","value":"keep-alive","notable":false},{"name":"Host","value":"<HONEYPOT>:7860","notable":false}],"distinct_sets":1,"events_with_headers":1},"tags":[{"tag_id":"CVE-2026-5027","tag_type":"cve","title":"Langflow <= 1.8.4 - Path Traversal to RCE via File Upload","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/v1/auto_login","reference_urls":["https://github.com/langflow-ai/langflow/pull/12227","https://github.com/0xBlackash/CVE-2026-5027","https://github.com/langflow-ai/langflow/security/advisories/GHSA-g2j9-7rj2-gm6c"]}],"data_as_of":"2026-09-11T08:09:14.736058+00:00"}