{"ip":"37.19.221.144","total_events":1,"verdict":{"verdict":"probing","label":"Low-level probing","detail":null,"confidence":"low","network_type":null,"why":["1 event(s), fewer than 10 distinct ports, no exploit payloads.","Not in any known-scanner range."],"engagement":{"level":"request","label":"Request traffic","detail":"137 bytes sent","bytes_sent":137,"session_seconds":0,"persistent":false}},"first_seen":"2026-09-09T21:52:34","last_seen":"2026-09-09T21:52:34","events_24h":1,"events_7d":1,"geo":{"country_code":"US","country_name":"United States","region":"Texas","city":"Houston","lat":29.7646,"lon":-95.3657,"asn":212238,"org":"Datacamp Limited"},"source_domain":"unn-37-19-221-144.datapacket.com","known_scanners":[],"scanner_tag":null,"cve_matches":[{"cve_id":"CVE-2024-25723","title":"ZenML ZenML Server - Improper Authentication","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/v1/info"}],"malware":[],"top_ports":[{"port":21001,"proto":"tcp","label":"","count":1}],"fingerprints":{"ssh_hassh":[],"tls_ja4":[],"tls_ja3":[],"ja4h":["ge11nn0400_ef4d07580f66"]},"fingerprint_peers":{"ge11nn0400_ef4d07580f66":2739},"user_agents":["Go-http-client/1.1"],"timeline":[{"date":"2026-09-09","count":1}],"recent_events":[{"timestamp":"2026-09-09T21:52:34","port":21001,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip\",\"connection\":\"close\",\"host\":\"<HONEYPOT>:21001\",\"user-agent\":\"Go-http-client/1.1\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/api/v1/info/version","summary":"","payload_hex":"474554202f6170692f76312f696e666f2f76657273696f6e20485454502f312e310d0a486f73743a20<HONEYPOT>3a32313030310d0a557365722d4167656e743a20476f2d687474702d636c69656e742f312e310d0a436f6e6e656374696f6e3a20636c6f73650d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Go-http-client/1.1","ja3":"","session":"5cd7ebed-1314-4b43-9303-3d8bd6b6fab3","seq":1,"duration_ms":101,"bytes_in":137,"bytes_out":78}],"http_methods":[{"method":"GET","count":1}],"distinct_ports_total":1,"top_paths":[{"path":"/api/v1/info/version","count":1,"ports":1}],"distinct_paths_total":1,"top_snis":[],"top_hosts":[],"top_alpns":[],"banners":[],"credentials":[],"header_profile":{"signature":["Accept-Encoding","Connection","Host","User-Agent"],"representative":[{"name":"Accept-Encoding","value":"gzip","notable":false},{"name":"Connection","value":"close","notable":false},{"name":"Host","value":"<HONEYPOT>:21001","notable":false},{"name":"User-Agent","value":"Go-http-client/1.1","notable":false}],"distinct_sets":1,"events_with_headers":1},"tags":[{"tag_id":"CVE-2024-25723","tag_type":"cve","title":"ZenML ZenML Server - Improper Authentication","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/api/v1/info","reference_urls":["https://www.zenml.io/blog/critical-security-update-for-zenml-users","https://github.com/zenml-io/zenml","https://github.com/zenml-io/zenml/compare/0.42.1...0.42.2","https://github.com/zenml-io/zenml/compare/0.43.0...0.43.1","https://github.com/zenml-io/zenml/compare/0.44.3...0.44.4"]}],"data_as_of":"2026-09-10T21:19:20.717192+00:00"}