{"ip":"185.141.60.128","total_events":481,"verdict":{"verdict":"malicious","label":"Exploit attempts observed","detail":"5 exploit-path hits","confidence":"high","network_type":"CDN","why":["5 request(s) matched a known exploit path.","Body-carrying methods (POST/PUT/PATCH/DELETE) seen: payload delivery, not just recon.","5+ hits raise confidence to high.","Not in any known-scanner range.","Sent 5,525,318 bytes: sustained payload delivery, not a single opportunistic request."],"engagement":{"level":"payload","label":"Sustained payload","detail":"5,525,318 bytes sent","bytes_sent":5525318,"session_seconds":35,"persistent":false}},"first_seen":"2026-09-23T23:05:54","last_seen":"2026-09-23T23:07:23","events_24h":481,"events_7d":481,"geo":{"country_code":"BG","country_name":"Bulgaria","region":"","city":"","lat":42.696,"lon":23.332,"asn":44901,"org":"Belcloud LTD"},"source_domain":null,"known_scanners":[],"scanner_tag":{"key":"peeringdb:as44901","label":"BelCloud Ltd.","category":"cdn","url":"https://www.peeringdb.com/asn/44901"},"cve_matches":[{"cve_id":"CVE-2020-2551","title":"Oracle WebLogic Server - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/console/login/LoginForm.jsp"},{"cve_id":"CVE-2021-35587","title":"Oracle Access Manager - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/oam/server/opensso/sessionservice"},{"cve_id":"CVE-2022-26143","title":"Mitel MiCollab - Information Disclosure & Denial of Service","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/ucs/micollab/version.json"},{"cve_id":"CVE-2024-1709","title":"ConnectWise ScreenConnect 23.9.7 - Authentication Bypass","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/SetupWizard.aspx"},{"cve_id":"CVE-2025-0282","title":"Ivanti Connect Secure - Stack-based Buffer Overflow","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/dana-na/auth/url_default/welcome.cgi"},{"cve_id":"CVE-2020-14864","title":"Oracle Fusion - Directory Traversal/Local File Inclusion","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/analytics/saw.dll"},{"cve_id":"CVE-2023-38646","title":"Metabase < 0.46.6.1 - Remote Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/session/properties"},{"cve_id":"CVE-2024-23917","title":"JetBrains TeamCity > 2023.11.3 - Authentication Bypass","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/app/rest/server"},{"cve_id":"CVE-2024-25723","title":"ZenML ZenML Server - Improper Authentication","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/v1/info"},{"cve_id":"CVE-2024-30569","title":"Netgear R6850 - Information Disclosure","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/currentsetting.htm"},{"cve_id":"CVE-2026-25892","title":"Adminer 4.6.2 - 5.4.1 Unauthenticated Persistent DoS","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/adminer.php"},{"cve_id":"CVE-2026-35029","title":"LiteLLM - Arbitrary File Read","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/health/liveliness"},{"cve_id":"CVE-2007-4556","title":"OpenSymphony XWork/Apache Struts2 - Remote Code Execution","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/login.action"},{"cve_id":"CVE-2025-2129","title":"Mage AI - Insecure Default Authentication Setup","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/kernels"}],"malware":[],"top_ports":[{"port":10001,"proto":"tcp","label":"","count":481}],"fingerprints":{"ssh_hassh":[],"tls_ja4":["t13i131000_f57a46bbacb6_f50d94e863eb","t13i251000_b78ed14e2fd0_f50d94e863eb"],"tls_client_hello":"16030105ee010005ea030388864e56464cb3a5a9bdf22a87271cfd4e5ddba84b1f5b8176b523706c26573920ed5a5634ad50148bdb77b27834449ea19e6808d08262c4247cf7ec1df15fb2660032cca9cca8c02bc02fc02cc030c009c013c00ac014009c009d002f0035c012000ac023c027003cc007c01100051303130113020100056f000b00020100ff010001000017000000120000000500050100000000000a0010000e11ec11eb11ed001d001700180019000d001c001a090409050906080404030807080508060401050106010503060300320020001e090409050906080404030807080508060401050106010503060302010203002b0009080304030303020301003304ea04e811ec04c05a528e7b1b5b42451df6530ff7f662beb16ef1758410c920df7910d8728224f15e2fec1866fb69aec31a5ac70ba6078f7cd5486ac8798540b9030038103a32ec090c4477881205c6b34a72829a91a7923e4fa9597d0011d15a173a327883861183b49e6254b1b2b7221ac6b164360a7ec644f91445a5899f1fd7afc6845057f4971dabc1e03590652b4dbe4b053668351c336ca4185a60d27e0c81ad0f537f4bab8e8d1b09b2bc7f9cbacf3565b01fd916a0a24ec1d2a866e2c7ca84839ee10fa4fa32a6135bfc2bb9c2433f9a5361753ab417e4bcbcfc4d24a333c1e83a64f59912d3625c451b1ba4739062ae36d73e38eb3ff93a977506827b3396d30160a1114c9f142059fb600dcbba544b5cd83c1476169bb4473112918bfd14672561378e0116029149b56c5bcb6214a0f3a17320983d32ca08e9367134008218135f442ffe265170e3b1ab4cbecbebb1464b57a6e78152924d25c389376a54645a355f8222aba9a7149370e5d4a8efe06333b8c0d3c289e2673765d247c23a2c0af67c8a10609f24c857c60431b47dfa168c713ac152c86110202675464809320f90327ed111018ecc7a20b31dad73cf753309f9e740ae30188b14397a9ab9c783bc8122c4eca0cea8d615f4713a9c5a9b76c139f2d67c286ab0144347fb05103f9a9fc148b54a003ed1ac282c368532ebc5214951dd49b92bd3ad493a6f2b708c6525c8d8e80904668742a710a423b6621a0641300955229e5937ce5bb7ab99e695eac163533890c2a20dd05ca223c87c897ab595c14d8b282104e45f1dd63f82b4bbbdba8b50a8c2dde705121a91be141ef8e0a636393d59fc1fba1a2a91a1b99a19044209a81823b959f77e71092dc407be3f47b6e4da2bd51b11779697db235d89433f3c4319ca840e61a060eaca2765ca489a278acc3634f934513f467b6e038ea3ac8ed3b26af2eb75dcbbbfe0a47544d350376024de26867dba8923f7779e45375c58c228042627b88b32f09992b89d53a84af8797d4c1ba55152ac37a51ee54772552415c576c114e05486a252aae99ca8c16a6608c9e119597e0a96c58449cd6a5daba328d3c29fd6991320301a6994491af9acff750b07fa0afa905e99fa6983b5ce544bc406f8b32b758f77bb12cd12a857cb851c8aaef683035e1343c6e21c16e6179c371ae13191c1ab8d4908084e8a5d22277097fbc94669bc19b8570d78beed43182a651290f4ca341432e1960c3fb06ed0e5b8849a180e417ae6921db53513d09851b2d3bbf3c38eed291c0a45b0d5c8a031336b5c11aa5dd37cf12c3e58688abc81bdb290ba4e69893dba3706db740900b2f08c91f451905e5a01ace390f8a082d3572ec8c5669dda24b8f48f310544a01c5225d2a6eb66b334c797448b8a16918afd553d779236a37158e108ab36c9147a449899e6971418a55a0a981dcb9f2239c24468199fd821e9e742dfd6a1fb33a82d535579ec0fa865138f628b28ba76799a5ddf435b420b4acd396222ec82de484f1178c05e4bc117706c6b7211ce570f81e43d531017cc3434b7f7611c35bd6cd86e497484a0280122b52ab4a21145b2b573c43cb0b8c455d068d2e55cf91b3a73f1c4827cb2e2c326817a9c18d0b891f0be95c823538d2a136324d0e07d324c5e79ad959bf2d21a601756f3864849169b3e395e5df02843e17095d7070a37588ecb706f6ffe487325001d00201756f3864849169b3e395e5df02843e17095d7070a37588ecb706f6f","tls_ja3":["9404b4852d44353f69b8b33aaff15be4","56b0f6febc953849f7ace70c5a2ae34d"],"http_akin":["a11cuq061_0000064a_ffe60107","a11cun040_0000004d_50f90888","a11cun030_0000000b_4c75231d","a11cun030_0000004c_13ee3d34"]},"fingerprint_peers":{"t13i131000_f57a46bbacb6_f50d94e863eb":2565,"t13i251000_b78ed14e2fd0_f50d94e863eb":13,"a11cuq061_0000064a_ffe60107":22,"a11cun040_0000004d_50f90888":6,"a11cun030_0000000b_4c75231d":2,"a11cun030_0000004c_13ee3d34":2223},"akin_families":{"a11cun040_0000004d_50f90888":{"head":"a11cun040_0000004d_aa48e2c8","shapes":5,"ips":2056},"a11cun030_0000004c_13ee3d34":{"head":"a11cun030_0000004c_13ee3d34","shapes":3,"ips":2226}},"user_agents":["nerva/1.0","Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"],"timeline":[{"date":"2026-09-23","count":481}],"recent_events":[{"timestamp":"2026-09-23T23:07:23","port":10001,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"192.3.118.146","headers":"{\"accept\":\"application/json\",\"accept-encoding\":\"gzip\",\"host\":\"192.3.118.146:10001\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/status","summary":"","payload_hex":"474554202f73746174757320485454502f312e310d0a486f73743a203139322e332e3131382e3134363a31303030310d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f3132372e302e302e30205361666172692f3533372e33360d0a4163636570743a206170706c69636174696f6e2f6a736f6e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36","ja3":"9404b4852d44353f69b8b33aaff15be4","session":"3d0e7870-3e0a-4547-b779-062800ecff19","seq":149,"duration_ms":33400,"bytes_in":34489,"bytes_out":11771},{"timestamp":"2026-09-23T23:07:23","port":10001,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"192.3.118.146","headers":"{\"accept\":\"text/plain\",\"accept-encoding\":\"gzip\",\"host\":\"192.3.118.146:10001\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/metrics","summary":"","payload_hex":"474554202f6d65747269637320485454502f312e310d0a486f73743a203139322e332e3131382e3134363a31303030310d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f3132372e302e302e30205361666172692f3533372e33360d0a4163636570743a20746578742f706c61696e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36","ja3":"9404b4852d44353f69b8b33aaff15be4","session":"3d0e7870-3e0a-4547-b779-062800ecff19","seq":148,"duration_ms":33176,"bytes_in":34264,"bytes_out":11692},{"timestamp":"2026-09-23T23:07:23","port":10001,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"192.3.118.146","headers":"{\"accept\":\"application/json\",\"accept-encoding\":\"gzip\",\"host\":\"192.3.118.146:10001\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/realms/master/.well-known/openid-configuration","summary":"","payload_hex":"474554202f7265616c6d732f6d61737465722f2e77656c6c2d6b6e6f776e2f6f70656e69642d636f6e66696775726174696f6e20485454502f312e310d0a486f73743a203139322e332e3131382e3134363a31303030310d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f3132372e302e302e30205361666172692f3533372e33360d0a4163636570743a206170706c69636174696f6e2f6a736f6e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36","ja3":"9404b4852d44353f69b8b33aaff15be4","session":"3d0e7870-3e0a-4547-b779-062800ecff19","seq":147,"duration_ms":32951,"bytes_in":34044,"bytes_out":11613},{"timestamp":"2026-09-23T23:07:23","port":10001,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"192.3.118.146","headers":"{\"accept\":\"application/json\",\"accept-encoding\":\"gzip\",\"host\":\"192.3.118.146:10001\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/WebInterface/","summary":"","payload_hex":"474554202f576562496e746572666163652f20485454502f312e310d0a486f73743a203139322e332e3131382e3134363a31303030310d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f3132372e302e302e30205361666172692f3533372e33360d0a4163636570743a206170706c69636174696f6e2f6a736f6e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36","ja3":"9404b4852d44353f69b8b33aaff15be4","session":"3d0e7870-3e0a-4547-b779-062800ecff19","seq":146,"duration_ms":32727,"bytes_in":33779,"bytes_out":11534},{"timestamp":"2026-09-23T23:07:22","port":10001,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"192.3.118.146","headers":"{\"accept\":\"application/json\",\"accept-encoding\":\"gzip\",\"host\":\"192.3.118.146:10001\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/service/rest/v1/status","summary":"","payload_hex":"474554202f736572766963652f726573742f76312f73746174757320485454502f312e310d0a486f73743a203139322e332e3131382e3134363a31303030310d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f3132372e302e302e30205361666172692f3533372e33360d0a4163636570743a206170706c69636174696f6e2f6a736f6e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36","ja3":"9404b4852d44353f69b8b33aaff15be4","session":"3d0e7870-3e0a-4547-b779-062800ecff19","seq":144,"duration_ms":32277,"bytes_in":33305,"bytes_out":11376},{"timestamp":"2026-09-23T23:07:22","port":10001,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"192.3.118.146","headers":"{\"accept\":\"application/json\",\"accept-encoding\":\"gzip\",\"host\":\"192.3.118.146:10001\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/swagger/v1/swagger.json","summary":"","payload_hex":"474554202f737761676765722f76312f737761676765722e6a736f6e20485454502f312e310d0a486f73743a203139322e332e3131382e3134363a31303030310d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f3132372e302e302e30205361666172692f3533372e33360d0a4163636570743a206170706c69636174696f6e2f6a736f6e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36","ja3":"9404b4852d44353f69b8b33aaff15be4","session":"3d0e7870-3e0a-4547-b779-062800ecff19","seq":145,"duration_ms":32502,"bytes_in":33547,"bytes_out":11455},{"timestamp":"2026-09-23T23:07:22","port":10001,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"192.3.118.146","headers":"{\"accept\":\"application/json\",\"accept-encoding\":\"gzip\",\"host\":\"192.3.118.146:10001\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/currentsetting.htm","summary":"","payload_hex":"474554202f63757272656e7473657474696e672e68746d20485454502f312e310d0a486f73743a203139322e332e3131382e3134363a31303030310d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f3132372e302e302e30205361666172692f3533372e33360d0a4163636570743a206170706c69636174696f6e2f6a736f6e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36","ja3":"9404b4852d44353f69b8b33aaff15be4","session":"3d0e7870-3e0a-4547-b779-062800ecff19","seq":141,"duration_ms":31602,"bytes_in":32594,"bytes_out":11139},{"timestamp":"2026-09-23T23:07:22","port":10001,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"192.3.118.146","headers":"{\"accept\":\"application/json\",\"accept-encoding\":\"gzip\",\"host\":\"192.3.118.146:10001\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/artifactory/api/system/ping","summary":"","payload_hex":"474554202f61727469666163746f72792f6170692f73797374656d2f70696e6720485454502f312e310d0a486f73743a203139322e332e3131382e3134363a31303030310d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f3132372e302e302e30205361666172692f3533372e33360d0a4163636570743a206170706c69636174696f6e2f6a736f6e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36","ja3":"9404b4852d44353f69b8b33aaff15be4","session":"3d0e7870-3e0a-4547-b779-062800ecff19","seq":142,"duration_ms":31827,"bytes_in":32840,"bytes_out":11218},{"timestamp":"2026-09-23T23:07:22","port":10001,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"192.3.118.146","headers":"{\"accept\":\"application/json\",\"accept-encoding\":\"gzip\",\"host\":\"192.3.118.146:10001\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/login","summary":"","payload_hex":"474554202f6c6f67696e20485454502f312e310d0a486f73743a203139322e332e3131382e3134363a31303030310d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f3132372e302e302e30205361666172692f3533372e33360d0a4163636570743a206170706c69636174696f6e2f6a736f6e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36","ja3":"9404b4852d44353f69b8b33aaff15be4","session":"3d0e7870-3e0a-4547-b779-062800ecff19","seq":143,"duration_ms":32052,"bytes_in":33064,"bytes_out":11297},{"timestamp":"2026-09-23T23:07:21","port":10001,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"192.3.118.146","headers":"{\"accept\":\"text/html\",\"accept-encoding\":\"gzip\",\"host\":\"192.3.118.146:10001\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/weblogin.htm","summary":"","payload_hex":"474554202f7765626c6f67696e2e68746d20485454502f312e310d0a486f73743a203139322e332e3131382e3134363a31303030310d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f3132372e302e302e30205361666172692f3533372e33360d0a4163636570743a20746578742f68746d6c0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36","ja3":"9404b4852d44353f69b8b33aaff15be4","session":"3d0e7870-3e0a-4547-b779-062800ecff19","seq":138,"duration_ms":30928,"bytes_in":31904,"bytes_out":10902}],"http_methods":[{"method":"GET","count":467},{"method":"POST","count":2}],"distinct_ports_total":1,"top_paths":[{"path":"/","count":18,"ports":1},{"path":"/api/v1/version","count":8,"ports":1},{"path":"/api/version","count":7,"ports":1},{"path":"/version","count":7,"ports":1},{"path":"/login","count":6,"ports":1},{"path":"/api/","count":4,"ports":1},{"path":"/api/overview","count":4,"ports":1},{"path":"/status","count":4,"ports":1},{"path":"/metrics","count":4,"ports":1},{"path":"/+CSCOE+/logon.html","count":3,"ports":1},{"path":"/manifest.json","count":2,"ports":1},{"path":"/ci/about","count":2,"ports":1},{"path":"/nerva-fp-nonexistent-path","count":2,"ports":1},{"path":"/ucs/micollab/version.json","count":2,"ports":1},{"path":"/Telerik.Web.UI.WebResource.axd?type=rau","count":2,"ports":1}],"distinct_paths_total":200,"top_snis":[],"top_hosts":[{"value":"192.3.118.146","count":467}],"top_alpns":[],"banners":[],"credentials":[],"header_profile":{"signature":["Accept","Accept-Encoding","Host","User-Agent"],"representative":[{"name":"Accept","value":"application/json","notable":false},{"name":"Accept-Encoding","value":"gzip","notable":false},{"name":"Host","value":"192.3.118.146:10001","notable":false},{"name":"User-Agent","value":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36","notable":false}],"distinct_sets":1,"events_with_headers":10},"tags":[{"tag_id":"CVE-2020-2551","tag_type":"cve","title":"Oracle WebLogic Server - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/console/login/LoginForm.jsp","reference_urls":["https://github.com/hktalent/CVE-2020-2551","https://nvd.nist.gov/vuln/detail/CVE-2020-2551","https://www.oracle.com/security-alerts/cpujan2020.html","https://github.com/neilzhang1/Chinese-Charts","https://github.com/pjgmonteiro/Pentest-tools"]},{"tag_id":"CVE-2021-35587","tag_type":"cve","title":"Oracle Access Manager - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/oam/server/opensso/sessionservice","reference_urls":["https://testbnull.medium.com/oracle-access-manager-pre-auth-rce-cve-2021-35587-analysis-1302a4542316","https://nvd.nist.gov/vuln/detail/CVE-2021-35587","https://www.oracle.com/security-alerts/cpujan2022.html","https://github.com/ARPSyndicate/kenzer-templates","https://github.com/GrrrDog/Java-Deserialization-Cheat-Sheet"]},{"tag_id":"CVE-2022-26143","tag_type":"cve","title":"Mitel MiCollab - Information Disclosure & Denial of Service","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/ucs/micollab/version.json","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-26143"]},{"tag_id":"CVE-2024-1709","tag_type":"cve","title":"ConnectWise ScreenConnect 23.9.7 - Authentication Bypass","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/SetupWizard.aspx","reference_urls":["https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass","https://github.com/watchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc","https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8","https://nvd.nist.gov/vuln/detail/CVE-2024-1709","https://github.com/rapid7/metasploit-framework/pull/18870"]},{"tag_id":"CVE-2025-0282","tag_type":"cve","title":"Ivanti Connect Secure - Stack-based Buffer Overflow","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/dana-na/auth/url_default/welcome.cgi","reference_urls":["https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-0282-CVE-2025-0283","https://labs.watchtowr.com/exploitation-walkthrough-and-techniques-ivanti-connect-secure-rce-cve-2025-0282/","https://cloud.google.com/blog/topics/threat-intelligence/ivanti-connect-secure-vpn-zero-day","https://nvd.nist.gov/vuln/detail/CVE-2025-0282"]},{"tag_id":"CVE-2020-14864","tag_type":"cve","title":"Oracle Fusion - Directory Traversal/Local File Inclusion","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/analytics/saw.dll","reference_urls":["http://packetstormsecurity.com/files/159748/Oracle-Business-Intelligence-Enterprise-Edition-5.5.0.0.0-12.2.1.3.0-12.2.1.4.0-LFI.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://nvd.nist.gov/vuln/detail/CVE-2020-14864","https://github.com/merlinepedra/nuclei-templates","https://github.com/sobinge/nuclei-templates"]},{"tag_id":"CVE-2023-38646","tag_type":"cve","title":"Metabase < 0.46.6.1 - Remote Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/session/properties","reference_urls":["https://www.metabase.com/blog/security-advisory","https://github.com/metabase/metabase/releases/tag/v0.46.6.1","https://mp.weixin.qq.com/s/ATFwFl-D8k9QfQfzKjZFDg","https://news.ycombinator.com/item?id=36812256","https://blog.assetnote.io/2023/07/22/pre-auth-rce-metabase/"]},{"tag_id":"CVE-2024-23917","tag_type":"cve","title":"JetBrains TeamCity > 2023.11.3 - Authentication Bypass","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/app/rest/server","reference_urls":["https://github.com/fkie-cad/nvd-json-data-feeds","https://www.rapid7.com/db/vulnerabilities/jetbrains-teamcity-cve-2024-23917/"]},{"tag_id":"CVE-2024-25723","tag_type":"cve","title":"ZenML ZenML Server - Improper Authentication","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/v1/info","reference_urls":["https://www.zenml.io/blog/critical-security-update-for-zenml-users","https://github.com/zenml-io/zenml","https://github.com/zenml-io/zenml/compare/0.42.1...0.42.2","https://github.com/zenml-io/zenml/compare/0.43.0...0.43.1","https://github.com/zenml-io/zenml/compare/0.44.3...0.44.4"]},{"tag_id":"CVE-2024-30569","tag_type":"cve","title":"Netgear R6850 - Information Disclosure","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/currentsetting.htm","reference_urls":["https://github.com/funny-mud-peee/IoT-vuls/blob/main/netgear%20R6850/Info%20Leak%20in%20Netgear-R6850%EF%BC%88currentsetting.htm%EF%BC%89.md","https://nvd.nist.gov/vuln/detail/CVE-2024-30569","https://www.netgear.com/about/security/"]},{"tag_id":"CVE-2026-25892","tag_type":"cve","title":"Adminer 4.6.2 - 5.4.1 Unauthenticated Persistent DoS","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/adminer.php","reference_urls":["https://github.com/vrana/adminer/security/advisories/GHSA-q4f2-39gr-45jh","https://github.com/vrana/adminer/commit/21d3a3150388677b18647d68aec93b7850e457d3"]},{"tag_id":"CVE-2026-35029","tag_type":"cve","title":"LiteLLM - Arbitrary File Read","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/health/liveliness","reference_urls":["https://github.com/BerriAI/litellm","https://sec-consult.com/vulnerability-lab/advisory/broken-access-control-in-config-endpoint-in-litellm/","https://nvd.nist.gov/vuln/detail/CVE-2026-35029"]},{"tag_id":"CVE-2007-4556","tag_type":"cve","title":"OpenSymphony XWork/Apache Struts2 - Remote Code Execution","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/login.action","reference_urls":["https://www.guildhab.top/?p=2326","https://nvd.nist.gov/vuln/detail/CVE-2007-4556","https://cwiki.apache.org/confluence/display/WW/S2-001","http://forums.opensymphony.com/ann.jspa?annID=54","http://issues.apache.org/struts/browse/WW-2030"]},{"tag_id":"CVE-2025-2129","tag_type":"cve","title":"Mage AI - Insecure Default Authentication Setup","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/kernels","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-2129","https://github.com/zn9988/publications/blob/main/2.Mage-AI%20-%20Insecure%20Default%20Authentication%20Setup%20Leading%20to%20Zero-Click%20RCE/README.md","https://vuldb.com/?ctiid.299049","https://vuldb.com/?id.299049","https://vuldb.com/?submit.510690"]}],"data_as_of":"2026-09-24T10:59:49.135947+00:00"}