{"ip":"23.144.160.130","total_events":1,"verdict":{"verdict":"scanner","label":"Recognized scanner","detail":"SB United States","confidence":"high","network_type":"educational/research","why":["Source IP is in a known scanner range (SB United States).","Known research and commercial scanners are labelled as such, not as threats."],"engagement":{"level":"request","label":"Request traffic","detail":"134 bytes sent","bytes_sent":134,"session_seconds":0,"persistent":false}},"first_seen":"2026-09-10T05:43:06","last_seen":"2026-09-10T05:43:06","events_24h":1,"events_7d":1,"geo":{"country_code":"US","country_name":"United States","region":"California","city":"","lat":34.0544,"lon":-118.244,"asn":32727,"org":"SB Professional Services"},"source_domain":null,"known_scanners":["SB United States"],"scanner_tag":{"key":"peeringdb:as32727","label":"SB United States","category":"research","url":"https://www.peeringdb.com/asn/32727"},"cve_matches":[{"cve_id":"CVE-2026-35029","title":"LiteLLM - Arbitrary File Read","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/health/liveliness"}],"malware":[],"top_ports":[{"port":9090,"proto":"tcp","label":"Prometheus","count":1}],"fingerprints":{"ssh_hassh":[],"tls_ja4":[],"tls_ja3":[],"ja4h":["ge11nn0400_ef4d07580f66"]},"fingerprint_peers":{"ge11nn0400_ef4d07580f66":2739},"user_agents":["Go-http-client/1.1"],"timeline":[{"date":"2026-09-10","count":1}],"recent_events":[{"timestamp":"2026-09-10T05:43:06","port":9090,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip\",\"connection\":\"close\",\"host\":\"<HONEYPOT>:9090\",\"user-agent\":\"Go-http-client/1.1\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/health/liveliness","summary":"","payload_hex":"474554202f6865616c74682f6c6976656c696e65737320485454502f312e310d0a486f73743a20<HONEYPOT>3a393039300d0a557365722d4167656e743a20476f2d687474702d636c69656e742f312e310d0a436f6e6e656374696f6e3a20636c6f73650d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Go-http-client/1.1","ja3":"","session":"34e1ccab-7032-4118-9295-0834ee1a8999","seq":1,"duration_ms":100,"bytes_in":134,"bytes_out":79}],"http_methods":[{"method":"GET","count":1}],"distinct_ports_total":1,"top_paths":[{"path":"/health/liveliness","count":1,"ports":1}],"distinct_paths_total":1,"top_snis":[],"top_hosts":[],"top_alpns":[],"banners":[],"credentials":[],"header_profile":{"signature":["Accept-Encoding","Connection","Host","User-Agent"],"representative":[{"name":"Accept-Encoding","value":"gzip","notable":false},{"name":"Connection","value":"close","notable":false},{"name":"Host","value":"<HONEYPOT>:9090","notable":false},{"name":"User-Agent","value":"Go-http-client/1.1","notable":false}],"distinct_sets":1,"events_with_headers":1},"tags":[{"tag_id":"CVE-2026-35029","tag_type":"cve","title":"LiteLLM - Arbitrary File Read","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/health/liveliness","reference_urls":["https://github.com/BerriAI/litellm","https://sec-consult.com/vulnerability-lab/advisory/broken-access-control-in-config-endpoint-in-litellm/","https://nvd.nist.gov/vuln/detail/CVE-2026-35029"]}],"data_as_of":"2026-09-10T21:19:37.629955+00:00"}