{"ip":"46.19.142.226","total_events":6,"verdict":{"verdict":"probing","label":"Low-level probing","detail":null,"confidence":"low","network_type":"nsp","why":["6 event(s), fewer than 10 distinct ports, no exploit payloads.","Not in any known-scanner range."],"engagement":{"level":"request","label":"Request traffic","detail":"944 bytes sent","bytes_sent":944,"session_seconds":0,"persistent":false}},"first_seen":"2026-09-04T18:34:20","last_seen":"2026-09-04T19:27:10","events_24h":0,"events_7d":0,"geo":{"country_code":"CH","country_name":"Switzerland","region":"","city":"","lat":47.1449,"lon":8.1551,"asn":51852,"org":"Private Layer INC"},"source_domain":"hostedby.privatelayer.com","known_scanners":[],"scanner_tag":{"key":"peeringdb:as51852","label":"Phase Layer Global Networks","category":"isp","url":"https://www.peeringdb.com/asn/51852"},"cve_matches":[{"cve_id":"CVE-2026-41940","title":"cPanel & WHM - Authentication Bypass via Session-File CRLF Injection","severity":"CRITICAL","actively_exploited":true,"match_field":"url_path","matched_pattern":"/login/?login_only=1"}],"malware":[],"top_ports":[{"port":2087,"proto":"tcp","label":"","count":6}],"fingerprints":{"ssh_hassh":[],"tls_ja4":["t13i190800_9dc949149365_97f8aa674fd9"],"tls_client_hello":"","tls_ja3":["19e29534fd49dd27d09234e639c4057e"],"http_akin":["b11cun030_00040012_13ee3d34","b11cuq050_00040813_2619b3ac"]},"fingerprint_peers":{"t13i190800_9dc949149365_97f8aa674fd9":3152,"b11cun030_00040012_13ee3d34":5047,"b11cuq050_00040813_2619b3ac":21},"akin_families":{"b11cuq050_00040813_2619b3ac":{"head":"b11cuq050_00040813_2619b3ac","shapes":2,"ips":21}},"user_agents":["Mozilla/5.0 (Windows NT 10.0; Win64; x64)","Mozilla/5.0"],"timeline":[{"date":"2026-09-04","count":6}],"recent_events":[{"timestamp":"2026-09-04T19:27:10","port":2087,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:2087\",\"user-agent\":\"Mozilla/5.0\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/openid_connect/cpanelid","summary":"","payload_hex":"474554202f6f70656e69645f636f6e6e6563742f6370616e656c696420485454502f312e310d0a486f73743a20<HONEYPOT>3a323038370d0a557365722d4167656e743a204d6f7a696c6c612f352e300d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0","ja3":"19e29534fd49dd27d09234e639c4057e","session":"58284d32-335d-4c17-a679-d3ebfa7345af","seq":1,"duration_ms":100,"bytes_in":114,"bytes_out":78},{"timestamp":"2026-09-04T19:27:10","port":2087,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip\",\"connection\":\"close\",\"content-length\":\"20\",\"host\":\"<HONEYPOT>:2087\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64)\"}","body":"pass=wrong&user=root","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/login/?login_only=1","summary":"","payload_hex":"504f5354202f6c6f67696e2f3f6c6f67696e5f6f6e6c793d3120485454502f312e310d0a486f73743a20<HONEYPOT>3a323038370d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b20783634290d0a436f6e74656e742d4c656e6774683a2032300d0a436f6e6e656374696f6e3a20636c6f73650d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a706173733d77726f6e6726757365723d726f6f74","method":"POST","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64)","ja3":"19e29534fd49dd27d09234e639c4057e","session":"e3bf526d-779d-4d55-9f3c-2118cb5a6d7e","seq":1,"duration_ms":100,"bytes_in":200,"bytes_out":78},{"timestamp":"2026-09-04T18:34:59","port":2087,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:2087\",\"user-agent\":\"Mozilla/5.0\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/openid_connect/cpanelid","summary":"","payload_hex":"474554202f6f70656e69645f636f6e6e6563742f6370616e656c696420485454502f312e310d0a486f73743a20<HONEYPOT>3a323038370d0a557365722d4167656e743a204d6f7a696c6c612f352e300d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0","ja3":"19e29534fd49dd27d09234e639c4057e","session":"d5daae92-0aab-434a-b263-8120b3659ace","seq":1,"duration_ms":100,"bytes_in":115,"bytes_out":78},{"timestamp":"2026-09-04T18:34:59","port":2087,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip\",\"connection\":\"close\",\"content-length\":\"20\",\"host\":\"<HONEYPOT>:2087\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64)\"}","body":"pass=wrong&user=root","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/login/?login_only=1","summary":"","payload_hex":"504f5354202f6c6f67696e2f3f6c6f67696e5f6f6e6c793d3120485454502f312e310d0a486f73743a20<HONEYPOT>3a323038370d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b20783634290d0a436f6e74656e742d4c656e6774683a2032300d0a436f6e6e656374696f6e3a20636c6f73650d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a706173733d77726f6e6726757365723d726f6f74","method":"POST","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64)","ja3":"19e29534fd49dd27d09234e639c4057e","session":"b1cbfc26-7468-4d58-b4a9-d9f0d93cc47b","seq":1,"duration_ms":100,"bytes_in":201,"bytes_out":78},{"timestamp":"2026-09-04T18:34:20","port":2087,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:2087\",\"user-agent\":\"Mozilla/5.0\"}","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/openid_connect/cpanelid","summary":"","payload_hex":"474554202f6f70656e69645f636f6e6e6563742f6370616e656c696420485454502f312e310d0a486f73743a20<HONEYPOT>3a323038370d0a557365722d4167656e743a204d6f7a696c6c612f352e300d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0","ja3":"19e29534fd49dd27d09234e639c4057e","session":"7983218d-b32a-4de8-a85c-a2204b7a20bd","seq":1,"duration_ms":100,"bytes_in":114,"bytes_out":78},{"timestamp":"2026-09-04T18:34:20","port":2087,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip\",\"connection\":\"close\",\"content-length\":\"20\",\"host\":\"<HONEYPOT>:2087\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64)\"}","body":"pass=wrong&user=root","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/login/?login_only=1","summary":"","payload_hex":"504f5354202f6c6f67696e2f3f6c6f67696e5f6f6e6c793d3120485454502f312e310d0a486f73743a20<HONEYPOT>3a323038370d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b20783634290d0a436f6e74656e742d4c656e6774683a2032300d0a436f6e6e656374696f6e3a20636c6f73650d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a706173733d77726f6e6726757365723d726f6f74","method":"POST","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64)","ja3":"19e29534fd49dd27d09234e639c4057e","session":"4829ffac-a4a5-4d99-8003-e0fef24fb7d3","seq":1,"duration_ms":101,"bytes_in":200,"bytes_out":78}],"http_methods":[{"method":"GET","count":3},{"method":"POST","count":3}],"distinct_ports_total":1,"top_paths":[{"path":"/login/?login_only=1","count":3,"ports":1},{"path":"/openid_connect/cpanelid","count":3,"ports":1}],"distinct_paths_total":2,"top_snis":[],"top_hosts":[],"top_alpns":[],"banners":[],"credentials":[{"username":"root","password":"wrong","count":3}],"header_profile":{"signature":["Accept-Encoding","Connection","Content-Length","Host","User-Agent"],"representative":[{"name":"Accept-Encoding","value":"gzip","notable":false},{"name":"Connection","value":"close","notable":false},{"name":"Content-Length","value":"20","notable":false},{"name":"Host","value":"<HONEYPOT>:2087","notable":false},{"name":"User-Agent","value":"Mozilla/5.0 (Windows NT 10.0; Win64; x64)","notable":false}],"distinct_sets":2,"events_with_headers":6},"tags":[{"tag_id":"CVE-2026-41940","tag_type":"cve","title":"cPanel & WHM - Authentication Bypass via Session-File CRLF Injection","severity":"CRITICAL","actively_exploited":true,"match_field":"url_path","matched_pattern":"/login/?login_only=1","reference_urls":[]}],"data_as_of":"2026-09-30T19:07:12.902836+00:00"}