{"ip":"40.124.80.46","total_events":4,"verdict":{"verdict":"probing","label":"Low-level probing","detail":null,"confidence":"low","network_type":"CDN","why":["4 event(s), fewer than 10 distinct ports, no exploit payloads.","Not in any known-scanner range."],"engagement":{"level":"request","label":"Request traffic","detail":"874 bytes sent","bytes_sent":874,"session_seconds":0,"persistent":false}},"first_seen":"2026-09-20T18:33:19","last_seen":"2026-09-30T06:56:10","events_24h":1,"events_7d":3,"geo":{"country_code":"US","country_name":"United States","region":"Texas","city":"San Antonio","lat":29.4227,"lon":-98.4927,"asn":8075,"org":"Microsoft Corporation"},"source_domain":null,"known_scanners":[],"scanner_tag":{"key":"peeringdb:as8075","label":"Microsoft","category":"cdn","url":"https://www.peeringdb.com/asn/8075"},"cve_matches":[{"cve_id":"CVE-2021-26855","title":"Microsoft Exchange Server SSRF Vulnerability","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/owa/auth/x.js"}],"malware":[],"top_ports":[{"port":443,"proto":"tcp","label":"HTTPS","count":4}],"fingerprints":{"ssh_hassh":[],"tls_ja4":["t13i1909h2_9dc949149365_97f8aa674fd9","t13i1909h1_9dc949149365_97f8aa674fd9"],"tls_client_hello":"16030100fd010000f90303abc2185610a593527476e08a056502c9611d4041858a25c24554b13970520b5b20f3c4cb3b481711d92df1d0169a21fdc0c5e75aa891e499158a0cb58437dd8c230026cca8cca9c02fc030c02bc02cc013c009c014c00a009c009d002f0035c012000a1303130113020100008a000500050100000000000a000a0008001d001700180019000b00020100000d001a0018080404030807080508060401050106010503060302010203ff010001000010000b000908687474702f312e3100120000002b0009080304030303020301003300260024001d0020641c2b46ce6ba2fc320cf957275d04a51fe0a0eb0b074dde5e688a","tls_ja3":["7c1e207beb00684bbbe144f1b0abe1d5"],"http_akin":["b11cun050_08040016_6289c865","b11cun040_00040016_aa48e2c8"]},"fingerprint_peers":{"t13i1909h2_9dc949149365_97f8aa674fd9":631,"t13i1909h1_9dc949149365_97f8aa674fd9":394,"b11cun050_08040016_6289c865":20,"b11cun040_00040016_aa48e2c8":6194},"akin_families":{"b11cun040_00040016_aa48e2c8":{"head":"b11cun040_00040016_aa48e2c8","shapes":4,"ips":6193}},"user_agents":["Mozilla/5.0 zgrab/0.x"],"timeline":[{"date":"2026-09-20","count":1},{"date":"2026-09-24","count":2},{"date":"2026-09-30","count":1}],"recent_events":[{"timestamp":"2026-09-30T06:56:10","port":443,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"cookie\":\"X-AnonResource=true; X-AnonResource-Backend=localhost/ecp/default.flt?~3; X-BEResource=localhost/owa/auth/logon.aspx?~3;\",\"host\":\"<HONEYPOT>\",\"user-agent\":\"Mozilla/5.0 zgrab/0.x\"}","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":["http/1.1"],"url_path":"/owa/auth/x.js","summary":"","payload_hex":"474554202f6f77612f617574682f782e6a7320485454502f312e310d0a486f73743a20<HONEYPOT>0d0a557365722d4167656e743a204d6f7a696c6c612f352e30207a677261622f302e780d0a4163636570743a202a2f2a0d0a436f6f6b69653a20582d416e6f6e5265736f757263653d747275653b20582d416e6f6e5265736f757263652d4261636b656e643d6c6f63616c686f73742f6563702f64656661756c742e666c743f7e333b20582d42455265736f757263653d6c6f63616c686f73742f6f77612f617574682f6c6f676f6e2e617370783f7e333b0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 zgrab/0.x","ja3":"7c1e207beb00684bbbe144f1b0abe1d5","session":"fbfe7fcd-2fa0-4256-b130-e996b757d793","seq":1,"duration_ms":208,"bytes_in":252,"bytes_out":77},{"timestamp":"2026-09-24T21:58:58","port":443,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"cookie\":\"X-AnonResource=true; X-AnonResource-Backend=localhost/ecp/default.flt?~3; X-BEResource=localhost/owa/auth/logon.aspx?~3;\",\"host\":\"<HONEYPOT>\",\"user-agent\":\"Mozilla/5.0 zgrab/0.x\"}","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":["http/1.1"],"url_path":"/owa/auth/x.js","summary":"","payload_hex":"474554202f6f77612f617574682f782e6a7320485454502f312e310d0a486f73743a20<HONEYPOT>0d0a557365722d4167656e743a204d6f7a696c6c612f352e30207a677261622f302e780d0a4163636570743a202a2f2a0d0a436f6f6b69653a20582d416e6f6e5265736f757263653d747275653b20582d416e6f6e5265736f757263652d4261636b656e643d6c6f63616c686f73742f6563702f64656661756c742e666c743f7e333b20582d42455265736f757263653d6c6f63616c686f73742f6f77612f617574682f6c6f676f6e2e617370783f7e333b0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 zgrab/0.x","ja3":"7c1e207beb00684bbbe144f1b0abe1d5","session":"ea4cf26a-b0c0-418f-8d1b-2f7b201caee6","seq":1,"duration_ms":190,"bytes_in":252,"bytes_out":77},{"timestamp":"2026-09-24T03:54:36","port":443,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>\",\"user-agent\":\"Mozilla/5.0 zgrab/0.x\"}","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":["h2","http/1.1"],"url_path":"/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application","summary":"","payload_hex":"474554202f6563702f43757272656e742f6578706f7274746f6f6c2f6d6963726f736f66742e65786368616e67652e65646973636f766572792e6578706f7274746f6f6c2e6170706c69636174696f6e20485454502f312e310d0a486f73743a20<HONEYPOT>0d0a557365722d4167656e743a204d6f7a696c6c612f352e30207a677261622f302e780d0a4163636570743a202a2f2a0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 zgrab/0.x","ja3":"7c1e207beb00684bbbe144f1b0abe1d5","session":"419421d1-979b-478c-b3b7-ac1160f2f58e","seq":1,"duration_ms":163,"bytes_in":186,"bytes_out":77},{"timestamp":"2026-09-20T18:33:19","port":443,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>\",\"user-agent\":\"Mozilla/5.0 zgrab/0.x\"}","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":["h2","http/1.1"],"url_path":"/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application","summary":"","payload_hex":"474554202f6563702f43757272656e742f6578706f7274746f6f6c2f6d6963726f736f66742e65786368616e67652e65646973636f766572792e6578706f7274746f6f6c2e6170706c69636174696f6e20485454502f312e310d0a486f73743a20<HONEYPOT>0d0a557365722d4167656e743a204d6f7a696c6c612f352e30207a677261622f302e780d0a4163636570743a202a2f2a0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 zgrab/0.x","ja3":"7c1e207beb00684bbbe144f1b0abe1d5","session":"098f98cf-8cac-4edb-ae89-efb64fc8e963","seq":1,"duration_ms":254,"bytes_in":184,"bytes_out":77}],"http_methods":[{"method":"GET","count":4}],"distinct_ports_total":1,"top_paths":[{"path":"/owa/auth/x.js","count":2,"ports":1},{"path":"/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application","count":2,"ports":1}],"distinct_paths_total":2,"top_snis":[],"top_hosts":[],"top_alpns":[{"value":"http/1.1","count":2},{"value":"h2, http/1.1","count":2}],"banners":[],"credentials":[],"header_profile":{"signature":["Accept","Accept-Encoding","Cookie","Host","User-Agent"],"representative":[{"name":"Accept","value":"*/*","notable":false},{"name":"Accept-Encoding","value":"gzip","notable":false},{"name":"Cookie","value":"X-AnonResource=true; X-AnonResource-Backend=localhost/ecp/default.flt?~3; X-BEResource=localhost/owa/auth/logon.aspx?~3;","notable":true},{"name":"Host","value":"<HONEYPOT>","notable":false},{"name":"User-Agent","value":"Mozilla/5.0 zgrab/0.x","notable":false}],"distinct_sets":2,"events_with_headers":4},"tags":[{"tag_id":"CVE-2021-26855","tag_type":"cve","title":"Microsoft Exchange Server SSRF Vulnerability","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/owa/auth/x.js","reference_urls":["https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-26855","https://proxylogon.com/#timeline","https://web.archive.org/web/20210306113850/https://raw.githubusercontent.com/microsoft/CSS-Exchange/main/Security/http-vuln-cve2021-26855.nse","https://gist.github.com/testanull/324546bffab2fe4916d0f9d1f03ffa09","https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26855"]}],"data_as_of":"2026-09-30T16:08:11.644168+00:00"}