{"ip":"20.14.88.130","total_events":4,"verdict":{"verdict":"scanner","label":"Recognized scanner","detail":"Stretchoid","confidence":"high","network_type":"CDN","why":["Source IP is in a known scanner range (Stretchoid).","Known research and commercial scanners are labelled as such, not as threats."],"engagement":{"level":"request","label":"Request traffic","detail":"886 bytes sent","bytes_sent":886,"session_seconds":1,"persistent":false}},"first_seen":"2026-09-15T18:20:42","last_seen":"2026-09-23T09:32:03","events_24h":0,"events_7d":3,"geo":{"country_code":"US","country_name":"United States","region":"Arizona","city":"Phoenix","lat":33.4532,"lon":-112.0748,"asn":8075,"org":"Microsoft Corporation"},"source_domain":"azpdweq3ryc2.stretchoid.com","known_scanners":["Stretchoid"],"scanner_tag":{"key":"stretchoid","label":"Stretchoid","category":"commercial","url":"https://stretchoid.com"},"cve_matches":[{"cve_id":"CVE-2021-26855","title":"Microsoft Exchange Server SSRF Vulnerability","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/owa/auth/x.js"}],"malware":[],"top_ports":[{"port":443,"proto":"tcp","label":"HTTPS","count":4}],"fingerprints":{"ssh_hassh":[],"tls_ja4":["t13i1909h2_9dc949149365_97f8aa674fd9"],"tls_client_hello":"1603010100010000fc03037481b620267da2b4c4360a93dd0aff01c8dd7e5e6e984749cf1a24634166cdc120c5b69c4b96aa4c385d08d6d7cfc7bcc0ea4d354e26fbfd15037a0a5940d2098e0026cca8cca9c02fc030c02bc02cc013c009c014c00a009c009d002f0035c012000a1303130113020100008d000500050100000000000a000a0008001d001700180019000b00020100000d001a0018080404030807080508060401050106010503060302010203ff010001000010000e000c02683208687474702f312e3100120000002b0009080304030303020301003300260024001d002046580e0addb2d9bc6ed1eaf8aedc2829d87c16955e6ea19c1ca1914cbfef902f","tls_ja3":["7c1e207beb00684bbbe144f1b0abe1d5"],"http_akin":["a11cun051_0000004d_6289c865"]},"fingerprint_peers":{"t13i1909h2_9dc949149365_97f8aa674fd9":637,"a11cun051_0000004d_6289c865":7},"akin_families":{},"user_agents":["Mozilla/5.0 zgrab/0.x"],"timeline":[{"date":"2026-09-15","count":1},{"date":"2026-09-18","count":1},{"date":"2026-09-20","count":1},{"date":"2026-09-23","count":1}],"recent_events":[{"timestamp":"2026-09-23T09:32:03","port":443,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"185.228.81.201","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"cookie\":\"X-AnonResource=true; X-AnonResource-Backend=localhost/ecp/default.flt?~3; X-BEResource=localhost/owa/auth/logon.aspx?~3;\",\"host\":\"185.228.81.201\",\"user-agent\":\"Mozilla/5.0 zgrab/0.x\"}","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":["h2","http/1.1"],"url_path":"/owa/auth/x.js","summary":"","payload_hex":"474554202f6f77612f617574682f782e6a7320485454502f312e310d0a486f73743a203138352e3232382e38312e3230310d0a557365722d4167656e743a204d6f7a696c6c612f352e30207a677261622f302e780d0a4163636570743a202a2f2a0d0a436f6f6b69653a20582d416e6f6e5265736f757263653d747275653b20582d416e6f6e5265736f757263652d4261636b656e643d6c6f63616c686f73742f6563702f64656661756c742e666c743f7e333b20582d42455265736f757263653d6c6f63616c686f73742f6f77612f617574682f6c6f676f6e2e617370783f7e333b0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 zgrab/0.x","ja3":"7c1e207beb00684bbbe144f1b0abe1d5","session":"308c93b5-93df-4025-8e0d-2597182aed2f","seq":1,"duration_ms":101,"bytes_in":254,"bytes_out":77},{"timestamp":"2026-09-20T00:30:47","port":443,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"cookie\":\"X-AnonResource=true; X-AnonResource-Backend=localhost/ecp/default.flt?~3; X-BEResource=localhost/owa/auth/logon.aspx?~3;\",\"host\":\"<HONEYPOT>\",\"user-agent\":\"Mozilla/5.0 zgrab/0.x\"}","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":["h2","http/1.1"],"url_path":"/owa/auth/x.js","summary":"","payload_hex":"474554202f6f77612f617574682f782e6a7320485454502f312e310d0a486f73743a20<HONEYPOT>0d0a557365722d4167656e743a204d6f7a696c6c612f352e30207a677261622f302e780d0a4163636570743a202a2f2a0d0a436f6f6b69653a20582d416e6f6e5265736f757263653d747275653b20582d416e6f6e5265736f757263652d4261636b656e643d6c6f63616c686f73742f6563702f64656661756c742e666c743f7e333b20582d42455265736f757263653d6c6f63616c686f73742f6f77612f617574682f6c6f676f6e2e617370783f7e333b0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 zgrab/0.x","ja3":"7c1e207beb00684bbbe144f1b0abe1d5","session":"7293e850-f97e-42b8-8986-9132c1fb3b97","seq":1,"duration_ms":634,"bytes_in":252,"bytes_out":77},{"timestamp":"2026-09-18T15:25:59","port":443,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>\",\"user-agent\":\"Mozilla/5.0 zgrab/0.x\"}","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":["h2","http/1.1"],"url_path":"/owa/auth/logon.aspx","summary":"","payload_hex":"474554202f6f77612f617574682f6c6f676f6e2e6173707820485454502f312e310d0a486f73743a20<HONEYPOT>0d0a557365722d4167656e743a204d6f7a696c6c612f352e30207a677261622f302e780d0a4163636570743a202a2f2a0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 zgrab/0.x","ja3":"7c1e207beb00684bbbe144f1b0abe1d5","session":"2c7d72e5-91a8-4bb4-8e0b-046e7d63b42d","seq":1,"duration_ms":101,"bytes_in":128,"bytes_out":77},{"timestamp":"2026-09-15T18:20:42","port":443,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"cookie\":\"X-AnonResource=true; X-AnonResource-Backend=localhost/ecp/default.flt?~3; X-BEResource=localhost/owa/auth/logon.aspx?~3;\",\"host\":\"<HONEYPOT>\",\"user-agent\":\"Mozilla/5.0 zgrab/0.x\"}","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":["h2","http/1.1"],"url_path":"/owa/auth/x.js","summary":"","payload_hex":"474554202f6f77612f617574682f782e6a7320485454502f312e310d0a486f73743a20<HONEYPOT>0d0a557365722d4167656e743a204d6f7a696c6c612f352e30207a677261622f302e780d0a4163636570743a202a2f2a0d0a436f6f6b69653a20582d416e6f6e5265736f757263653d747275653b20582d416e6f6e5265736f757263652d4261636b656e643d6c6f63616c686f73742f6563702f64656661756c742e666c743f7e333b20582d42455265736f757263653d6c6f63616c686f73742f6f77612f617574682f6c6f676f6e2e617370783f7e333b0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 zgrab/0.x","ja3":"7c1e207beb00684bbbe144f1b0abe1d5","session":"b34d52e4-1157-425f-ad0c-7b68885d9c3c","seq":1,"duration_ms":208,"bytes_in":252,"bytes_out":77}],"http_methods":[{"method":"GET","count":4}],"distinct_ports_total":1,"top_paths":[{"path":"/owa/auth/x.js","count":3,"ports":1},{"path":"/owa/auth/logon.aspx","count":1,"ports":1}],"distinct_paths_total":2,"top_snis":[],"top_hosts":[{"value":"185.228.81.201","count":1}],"top_alpns":[{"value":"h2, http/1.1","count":4}],"banners":[],"credentials":[],"header_profile":{"signature":["Accept","Accept-Encoding","Cookie","Host","User-Agent"],"representative":[{"name":"Accept","value":"*/*","notable":false},{"name":"Accept-Encoding","value":"gzip","notable":false},{"name":"Cookie","value":"X-AnonResource=true; X-AnonResource-Backend=localhost/ecp/default.flt?~3; X-BEResource=localhost/owa/auth/logon.aspx?~3;","notable":true},{"name":"Host","value":"185.228.81.201","notable":false},{"name":"User-Agent","value":"Mozilla/5.0 zgrab/0.x","notable":false}],"distinct_sets":2,"events_with_headers":4},"tags":[{"tag_id":"CVE-2021-26855","tag_type":"cve","title":"Microsoft Exchange Server SSRF Vulnerability","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/owa/auth/x.js","reference_urls":["https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-26855","https://proxylogon.com/#timeline","https://web.archive.org/web/20210306113850/https://raw.githubusercontent.com/microsoft/CSS-Exchange/main/Security/http-vuln-cve2021-26855.nse","https://gist.github.com/testanull/324546bffab2fe4916d0f9d1f03ffa09","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26855"]}],"data_as_of":"2026-09-24T14:47:40.212832+00:00"}