{"ip":"20.106.18.245","total_events":2,"verdict":{"verdict":"probing","label":"Low-level probing","detail":null,"confidence":"low","network_type":"CDN","why":["2 event(s), fewer than 10 distinct ports, no exploit payloads.","Not in any known-scanner range."],"engagement":{"level":"request","label":"Request traffic","detail":"437 bytes sent","bytes_sent":437,"session_seconds":0,"persistent":false}},"first_seen":"2026-09-19T00:48:31","last_seen":"2026-09-23T11:36:21","events_24h":0,"events_7d":2,"geo":{"country_code":"US","country_name":"United States","region":"Iowa","city":"Des Moines","lat":41.6015,"lon":-93.6127,"asn":8075,"org":"Microsoft Corporation"},"source_domain":null,"known_scanners":[],"scanner_tag":{"key":"peeringdb:as8075","label":"Microsoft","category":"cdn","url":"https://www.peeringdb.com/asn/8075"},"cve_matches":[{"cve_id":"CVE-2021-26855","title":"Microsoft Exchange Server SSRF Vulnerability","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/owa/auth/x.js"}],"malware":[],"top_ports":[{"port":443,"proto":"tcp","label":"HTTPS","count":2}],"fingerprints":{"ssh_hassh":[],"tls_ja4":["t13i1909h2_9dc949149365_97f8aa674fd9"],"tls_client_hello":"1603010100010000fc0303a46b8beac4283482a61944ad0f111c77ce3d9e238fba8ec9f7f4b59b03fc4efd20ad27a0deb90b49d617c66292ea03675faf9076509c8c9f7fd54abc843ceac33c0026cca8cca9c02fc030c02bc02cc013c009c014c00a009c009d002f0035c012000a1303130113020100008d000500050100000000000a000a0008001d001700180019000b00020100000d001a0018080404030807080508060401050106010503060302010203ff010001000010000e000c02683208687474702f312e3100120000002b0009080304030303020301003300260024001d00202eefdf66f6585985ba93b0e90b5cbf8577747769936dc3001df8e44a8f63de79","tls_ja3":["7c1e207beb00684bbbe144f1b0abe1d5"],"http_akin":["a11cun051_0000004d_6289c865"]},"fingerprint_peers":{"t13i1909h2_9dc949149365_97f8aa674fd9":637,"a11cun051_0000004d_6289c865":7},"akin_families":{},"user_agents":["Mozilla/5.0 zgrab/0.x"],"timeline":[{"date":"2026-09-19","count":1},{"date":"2026-09-23","count":1}],"recent_events":[{"timestamp":"2026-09-23T11:36:21","port":443,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"cookie\":\"X-AnonResource=true; X-AnonResource-Backend=localhost/ecp/default.flt?~3; X-BEResource=localhost/owa/auth/logon.aspx?~3;\",\"host\":\"<HONEYPOT>\",\"user-agent\":\"Mozilla/5.0 zgrab/0.x\"}","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":["h2","http/1.1"],"url_path":"/owa/auth/x.js","summary":"","payload_hex":"474554202f6f77612f617574682f782e6a7320485454502f312e310d0a486f73743a20<HONEYPOT>0d0a557365722d4167656e743a204d6f7a696c6c612f352e30207a677261622f302e780d0a4163636570743a202a2f2a0d0a436f6f6b69653a20582d416e6f6e5265736f757263653d747275653b20582d416e6f6e5265736f757263652d4261636b656e643d6c6f63616c686f73742f6563702f64656661756c742e666c743f7e333b20582d42455265736f757263653d6c6f63616c686f73742f6f77612f617574682f6c6f676f6e2e617370783f7e333b0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 zgrab/0.x","ja3":"7c1e207beb00684bbbe144f1b0abe1d5","session":"25a6fab5-6b63-4a84-961b-00f458486d3c","seq":1,"duration_ms":180,"bytes_in":252,"bytes_out":78},{"timestamp":"2026-09-19T00:48:31","port":443,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>\",\"user-agent\":\"Mozilla/5.0 zgrab/0.x\"}","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":["h2","http/1.1"],"url_path":"/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application","summary":"","payload_hex":"474554202f6563702f43757272656e742f6578706f7274746f6f6c2f6d6963726f736f66742e65786368616e67652e65646973636f766572792e6578706f7274746f6f6c2e6170706c69636174696f6e20485454502f312e310d0a486f73743a20<HONEYPOT>0d0a557365722d4167656e743a204d6f7a696c6c612f352e30207a677261622f302e780d0a4163636570743a202a2f2a0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 zgrab/0.x","ja3":"7c1e207beb00684bbbe144f1b0abe1d5","session":"75c3aa74-ef0a-4cbc-b3fd-088ebf979800","seq":1,"duration_ms":242,"bytes_in":185,"bytes_out":78}],"http_methods":[{"method":"GET","count":2}],"distinct_ports_total":1,"top_paths":[{"path":"/owa/auth/x.js","count":1,"ports":1},{"path":"/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application","count":1,"ports":1}],"distinct_paths_total":2,"top_snis":[],"top_hosts":[],"top_alpns":[{"value":"h2, http/1.1","count":2}],"banners":[],"credentials":[],"header_profile":{"signature":["Accept","Accept-Encoding","Cookie","Host","User-Agent"],"representative":[{"name":"Accept","value":"*/*","notable":false},{"name":"Accept-Encoding","value":"gzip","notable":false},{"name":"Cookie","value":"X-AnonResource=true; X-AnonResource-Backend=localhost/ecp/default.flt?~3; X-BEResource=localhost/owa/auth/logon.aspx?~3;","notable":true},{"name":"Host","value":"<HONEYPOT>","notable":false},{"name":"User-Agent","value":"Mozilla/5.0 zgrab/0.x","notable":false}],"distinct_sets":2,"events_with_headers":2},"tags":[{"tag_id":"CVE-2021-26855","tag_type":"cve","title":"Microsoft Exchange Server SSRF Vulnerability","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/owa/auth/x.js","reference_urls":["https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-26855","https://proxylogon.com/#timeline","https://web.archive.org/web/20210306113850/https://raw.githubusercontent.com/microsoft/CSS-Exchange/main/Security/http-vuln-cve2021-26855.nse","https://gist.github.com/testanull/324546bffab2fe4916d0f9d1f03ffa09","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26855"]}],"data_as_of":"2026-09-24T14:48:07.162555+00:00"}