{"ip":"34.145.99.73","total_events":121840,"verdict":{"verdict":"scanning","label":"Scanning for known vulnerabilities","detail":"1 exploit-path probe(s)","confidence":"medium","network_type":null},"first_seen":"2026-06-14T10:52:26","last_seen":"2026-06-14T21:05:58","events_24h":0,"events_7d":57937,"geo":{"country_code":"US","country_name":"United States","region":"Oregon","city":"The Dalles","lat":45.5999,"lon":-121.1871,"asn":396982,"org":"Google LLC"},"source_domain":"73.99.145.34.bc.googleusercontent.com","known_scanners":[],"scanner_tag":{"key":"gcp","label":"Google Cloud","category":"hosting_provider","url":"https://cloud.google.com/"},"cve_matches":[{"cve_id":"CVE-2022-24288","title":"Apache Airflow OS Command Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/code"},{"cve_id":"CVE-2021-28169","title":"Eclipse Jetty ConcatServlet - Information Disclosure","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/static"},{"cve_id":"CVE-2024-36527","title":"Puppeteer Renderer - Directory Traversal","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/html"}],"top_ports":[{"port":3001,"proto":"tcp","label":"","count":60998},{"port":34567,"proto":"tcp","label":"","count":60842}],"fingerprints":{"ssh_hassh":[],"tls_ja4":["t13i1313h2_f57a46bbacb6_fb48f8b98a29","t13i1314h2_f57a46bbacb6_3b244d8fbcc8"],"tls_ja3":["e56c72ec790d5898f89528f5c080ca3b","bbfe3507a810aa6c11c659bd4c7b4cbd"],"ja4h":["ge11nn0400_88d30a62b7ad"]},"fingerprint_peers":{"t13i1313h2_f57a46bbacb6_fb48f8b98a29":699,"t13i1314h2_f57a46bbacb6_3b244d8fbcc8":21,"ge11nn0400_88d30a62b7ad":7424},"user_agents":["Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/124.0 Safari/537.36"],"timeline":[{"date":"2026-06-14","count":121840}],"recent_events":[{"timestamp":"2026-06-14T21:05:58","port":34567,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:34567\",\"user-agent\":\"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/124.0 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":["h2","http/1.1"],"url_path":"/src/sandbox.zip","summary":"","payload_hex":"474554202f7372632f73616e64626f782e7a697020485454502f312e310d0a486f73743a20<HONEYPOT>3a33343536370d0a557365722d4167656e743a204d6f7a696c6c612f352e3020285831313b204c696e7578207838365f363429204170706c655765624b69742f3533372e3336204368726f6d652f3132342e30205361666172692f3533372e33360d0a4163636570743a202a2f2a0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/124.0 Safari/537.36","community_id":"1:zsZtQr1MUscL+bjmGmCVRgzPJHM=","ja3":"bbfe3507a810aa6c11c659bd4c7b4cbd","session":"bbf0a681-7cb5-4b2a-8af1-82d3d131ae60","seq":4327,"duration_ms":2775483,"bytes_in":819962,"bytes_out":333179},{"timestamp":"2026-06-14T21:05:57","port":34567,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:34567\",\"user-agent\":\"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/124.0 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":["h2","http/1.1"],"url_path":"/src/demo.sql","summary":"","payload_hex":"474554202f7372632f64656d6f2e73716c20485454502f312e310d0a486f73743a20<HONEYPOT>3a33343536370d0a557365722d4167656e743a204d6f7a696c6c612f352e3020285831313b204c696e7578207838365f363429204170706c655765624b69742f3533372e3336204368726f6d652f3132342e30205361666172692f3533372e33360d0a4163636570743a202a2f2a0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/124.0 Safari/537.36","community_id":"1:zsZtQr1MUscL+bjmGmCVRgzPJHM=","ja3":"bbfe3507a810aa6c11c659bd4c7b4cbd","session":"bbf0a681-7cb5-4b2a-8af1-82d3d131ae60","seq":4326,"duration_ms":2774795,"bytes_in":819776,"bytes_out":333102},{"timestamp":"2026-06-14T21:05:57","port":3001,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:3001\",\"user-agent\":\"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/124.0 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":["h2","http/1.1"],"url_path":"/src/sandbox.tar","summary":"","payload_hex":"474554202f7372632f73616e64626f782e74617220485454502f312e310d0a486f73743a20<HONEYPOT>3a333030310d0a557365722d4167656e743a204d6f7a696c6c612f352e3020285831313b204c696e7578207838365f363429204170706c655765624b69742f3533372e3336204368726f6d652f3132342e30205361666172692f3533372e33360d0a4163636570743a202a2f2a0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/124.0 Safari/537.36","community_id":"1:o3eqmftMLfxqbXb/IHaV0VpBXyA=","ja3":"bbfe3507a810aa6c11c659bd4c7b4cbd","session":"0c768cc0-b114-4370-b1ec-e0d1dd7cc18a","seq":61053,"duration_ms":36796402,"bytes_in":11464610,"bytes_out":4701081},{"timestamp":"2026-06-14T21:05:57","port":3001,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:3001\",\"user-agent\":\"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/124.0 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":["h2","http/1.1"],"url_path":"/src/sandbox.tgz","summary":"","payload_hex":"474554202f7372632f73616e64626f782e74677a20485454502f312e310d0a486f73743a20<HONEYPOT>3a333030310d0a557365722d4167656e743a204d6f7a696c6c612f352e3020285831313b204c696e7578207838365f363429204170706c655765624b69742f3533372e3336204368726f6d652f3132342e30205361666172692f3533372e33360d0a4163636570743a202a2f2a0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/124.0 Safari/537.36","community_id":"1:o3eqmftMLfxqbXb/IHaV0VpBXyA=","ja3":"bbfe3507a810aa6c11c659bd4c7b4cbd","session":"0c768cc0-b114-4370-b1ec-e0d1dd7cc18a","seq":61052,"duration_ms":36795730,"bytes_in":11464425,"bytes_out":4701004},{"timestamp":"2026-06-14T21:05:56","port":34567,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:34567\",\"user-agent\":\"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/124.0 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":["h2","http/1.1"],"url_path":"/src/demo.sql.bz2","summary":"","payload_hex":"474554202f7372632f64656d6f2e73716c2e627a3220485454502f312e310d0a486f73743a20<HONEYPOT>3a33343536370d0a557365722d4167656e743a204d6f7a696c6c612f352e3020285831313b204c696e7578207838365f363429204170706c655765624b69742f3533372e3336204368726f6d652f3132342e30205361666172692f3533372e33360d0a4163636570743a202a2f2a0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/124.0 Safari/537.36","community_id":"1:zsZtQr1MUscL+bjmGmCVRgzPJHM=","ja3":"bbfe3507a810aa6c11c659bd4c7b4cbd","session":"bbf0a681-7cb5-4b2a-8af1-82d3d131ae60","seq":4325,"duration_ms":2774166,"bytes_in":819593,"bytes_out":333025},{"timestamp":"2026-06-14T21:05:56","port":34567,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:34567\",\"user-agent\":\"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/124.0 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":["h2","http/1.1"],"url_path":"/src/demo.sql.gz","summary":"","payload_hex":"474554202f7372632f64656d6f2e73716c2e677a20485454502f312e310d0a486f73743a20<HONEYPOT>3a33343536370d0a557365722d4167656e743a204d6f7a696c6c612f352e3020285831313b204c696e7578207838365f363429204170706c655765624b69742f3533372e3336204368726f6d652f3132342e30205361666172692f3533372e33360d0a4163636570743a202a2f2a0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/124.0 Safari/537.36","community_id":"1:zsZtQr1MUscL+bjmGmCVRgzPJHM=","ja3":"bbfe3507a810aa6c11c659bd4c7b4cbd","session":"bbf0a681-7cb5-4b2a-8af1-82d3d131ae60","seq":4324,"duration_ms":2773529,"bytes_in":819406,"bytes_out":332948},{"timestamp":"2026-06-14T21:05:56","port":3001,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:3001\",\"user-agent\":\"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/124.0 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":["h2","http/1.1"],"url_path":"/src/sandbox.tar.gz","summary":"","payload_hex":"474554202f7372632f73616e64626f782e7461722e677a20485454502f312e310d0a486f73743a20<HONEYPOT>3a333030310d0a557365722d4167656e743a204d6f7a696c6c612f352e3020285831313b204c696e7578207838365f363429204170706c655765624b69742f3533372e3336204368726f6d652f3132342e30205361666172692f3533372e33360d0a4163636570743a202a2f2a0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/124.0 Safari/537.36","community_id":"1:o3eqmftMLfxqbXb/IHaV0VpBXyA=","ja3":"bbfe3507a810aa6c11c659bd4c7b4cbd","session":"0c768cc0-b114-4370-b1ec-e0d1dd7cc18a","seq":61051,"duration_ms":36795101,"bytes_in":11464240,"bytes_out":4700927},{"timestamp":"2026-06-14T21:05:55","port":34567,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:34567\",\"user-agent\":\"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/124.0 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":["h2","http/1.1"],"url_path":"/src/demo.zst","summary":"","payload_hex":"474554202f7372632f64656d6f2e7a737420485454502f312e310d0a486f73743a20<HONEYPOT>3a33343536370d0a557365722d4167656e743a204d6f7a696c6c612f352e3020285831313b204c696e7578207838365f363429204170706c655765624b69742f3533372e3336204368726f6d652f3132342e30205361666172692f3533372e33360d0a4163636570743a202a2f2a0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/124.0 Safari/537.36","community_id":"1:zsZtQr1MUscL+bjmGmCVRgzPJHM=","ja3":"bbfe3507a810aa6c11c659bd4c7b4cbd","session":"bbf0a681-7cb5-4b2a-8af1-82d3d131ae60","seq":4323,"duration_ms":2772866,"bytes_in":819220,"bytes_out":332871},{"timestamp":"2026-06-14T21:05:55","port":3001,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:3001\",\"user-agent\":\"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/124.0 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":["h2","http/1.1"],"url_path":"/src/sandbox.zip","summary":"","payload_hex":"474554202f7372632f73616e64626f782e7a697020485454502f312e310d0a486f73743a20<HONEYPOT>3a333030310d0a557365722d4167656e743a204d6f7a696c6c612f352e3020285831313b204c696e7578207838365f363429204170706c655765624b69742f3533372e3336204368726f6d652f3132342e30205361666172692f3533372e33360d0a4163636570743a202a2f2a0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/124.0 Safari/537.36","community_id":"1:o3eqmftMLfxqbXb/IHaV0VpBXyA=","ja3":"bbfe3507a810aa6c11c659bd4c7b4cbd","session":"0c768cc0-b114-4370-b1ec-e0d1dd7cc18a","seq":61050,"duration_ms":36794453,"bytes_in":11464052,"bytes_out":4700850},{"timestamp":"2026-06-14T21:05:55","port":3001,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:3001\",\"user-agent\":\"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/124.0 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":["h2","http/1.1"],"url_path":"/src/demo.sql","summary":"","payload_hex":"474554202f7372632f64656d6f2e73716c20485454502f312e310d0a486f73743a20<HONEYPOT>3a333030310d0a557365722d4167656e743a204d6f7a696c6c612f352e3020285831313b204c696e7578207838365f363429204170706c655765624b69742f3533372e3336204368726f6d652f3132342e30205361666172692f3533372e33360d0a4163636570743a202a2f2a0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/124.0 Safari/537.36","community_id":"1:o3eqmftMLfxqbXb/IHaV0VpBXyA=","ja3":"bbfe3507a810aa6c11c659bd4c7b4cbd","session":"0c768cc0-b114-4370-b1ec-e0d1dd7cc18a","seq":61049,"duration_ms":36793784,"bytes_in":11463867,"bytes_out":4700773}],"http_methods":[{"method":"GET","count":121840}],"distinct_ports_total":2,"top_paths":[{"path":"/backups/debug.zip","count":2,"ports":2},{"path":"/api/v2/docroot.gz","count":2,"ports":2},{"path":"/services/app.tgz","count":2,"ports":2},{"path":"/files/secret.rar","count":2,"ports":2},{"path":"/v2/sql_backup.zst","count":2,"ports":2},{"path":"/backend/secret.sql.bz2","count":2,"ports":2},{"path":"/api/postgres.tar","count":2,"ports":2},{"path":"/backup/requirements.tgz","count":2,"ports":2},{"path":"/application/develop.zip","count":2,"ports":2},{"path":"/storage/nuxtjs.tar","count":2,"ports":2},{"path":"/api/v1/trace.sql","count":2,"ports":2},{"path":"/backend/cache.tar.gz","count":2,"ports":2},{"path":"/backend/code.sql","count":2,"ports":2},{"path":"/application/mysql.zip","count":2,"ports":2},{"path":"/frontend/prod.sql.gz","count":2,"ports":2}],"distinct_paths_total":200,"top_snis":[],"top_hosts":[],"top_alpns":[{"value":"h2, http/1.1","count":121840}],"banners":[],"credentials":[],"header_profile":{"signature":["Accept","Accept-Encoding","Host","User-Agent"],"representative":[{"name":"Accept","value":"*/*","notable":false},{"name":"Accept-Encoding","value":"gzip","notable":false},{"name":"Host","value":"<HONEYPOT>:34567","notable":false},{"name":"User-Agent","value":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/124.0 Safari/537.36","notable":false}],"distinct_sets":1,"events_with_headers":10},"tags":[{"tag_id":"CVE-2022-24288","tag_type":"cve","title":"Apache Airflow OS Command Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/code","reference_urls":["https://github.com/advisories/GHSA-3v7g-4pg3-7r6j","https://nvd.nist.gov/vuln/detail/CVE-2022-24288","https://lists.apache.org/thread/dbw5ozcmr0h0lhs0yjph7xdc64oht23t","https://github.com/ARPSyndicate/kenzer-templates","https://github.com/Hax0rG1rl/my_cve_and_bounty_poc"]},{"tag_id":"CVE-2021-28169","tag_type":"cve","title":"Eclipse Jetty ConcatServlet - Information Disclosure","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/static","reference_urls":["https://twitter.com/sec715/status/1406787963569065988","https://github.com/eclipse/jetty.project/security/advisories/GHSA-gwcr-j4wh-j3cq","https://lists.apache.org/thread.html/r2721aba31a8562639c4b937150897e24f78f747cdbda8641c0f659fe@%3Cusers.kafka.apache.org%3E","https://nvd.nist.gov/vuln/detail/CVE-2021-28169","https://lists.apache.org/thread.html/r04a4b4553a23aff26f42635a6ae388c3b162aab30a88d12e59d05168@%3Cjira.kafka.apache.org%3E"]},{"tag_id":"CVE-2024-36527","tag_type":"cve","title":"Puppeteer Renderer - Directory Traversal","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/html","reference_urls":["https://github.com/zenato/puppeteer-renderer/issues/97","https://gist.github.com/7a6163/25fef08f75eed219c8ca21e332d6e911"]}],"data_as_of":"2026-06-21T16:15:41.935760+00:00"}