{"ip":"74.249.179.230","total_events":5,"verdict":{"verdict":"probing","label":"Low-level probing","detail":null,"confidence":"low","network_type":"CDN","why":["5 event(s), fewer than 10 distinct ports, no exploit payloads.","Not in any known-scanner range."],"engagement":{"level":"request","label":"Request traffic","detail":"334 bytes sent","bytes_sent":334,"session_seconds":0,"persistent":false}},"first_seen":"2026-09-16T21:52:39","last_seen":"2026-09-21T08:23:36","events_24h":0,"events_7d":5,"geo":{"country_code":"US","country_name":"United States","region":"Iowa","city":"Des Moines","lat":41.6015,"lon":-93.6127,"asn":8075,"org":"Microsoft Corporation"},"source_domain":null,"known_scanners":[],"scanner_tag":{"key":"peeringdb:as8075","label":"Microsoft","category":"cdn","url":"https://www.peeringdb.com/asn/8075"},"cve_matches":[{"cve_id":"CVE-2025-31324","title":"SAP NetWeaver Visual Composer Metadata Uploader - Deserialization","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/developmentserver/metadatauploader"}],"malware":[],"top_ports":[{"port":1270,"proto":"tcp","label":"","count":2},{"port":2323,"proto":"tcp","label":"","count":1},{"port":8945,"proto":"tcp","label":"","count":1},{"port":443,"proto":"tcp","label":"HTTPS","count":1}],"fingerprints":{"ssh_hassh":[],"tls_ja4":["t13i190800_9dc949149365_97f8aa674fd9"],"tls_client_hello":"","tls_ja3":["35fa0a83e466acbec1cfbb9016d550ab"],"http_akin":[]},"fingerprint_peers":{"t13i190800_9dc949149365_97f8aa674fd9":2948},"akin_families":{},"user_agents":["Mozilla/5.0 zgrab/0.x"],"timeline":[{"date":"2026-09-16","count":1},{"date":"2026-09-19","count":2},{"date":"2026-09-20","count":1},{"date":"2026-09-21","count":1}],"recent_events":[{"timestamp":"2026-09-21T08:23:36","port":443,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>\",\"user-agent\":\"Mozilla/5.0 zgrab/0.x\"}","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/developmentserver/metadatauploader","summary":"","payload_hex":"474554202f646576656c6f706d656e747365727665722f6d6574616461746175706c6f6164657220485454502f312e310d0a486f73743a20<HONEYPOT>0d0a557365722d4167656e743a204d6f7a696c6c612f352e30207a677261622f302e780d0a4163636570743a202a2f2a0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 zgrab/0.x","ja3":"35fa0a83e466acbec1cfbb9016d550ab","session":"3c9b7e67-1731-4fbd-94c5-b697467d1194","seq":1,"duration_ms":160,"bytes_in":144,"bytes_out":79},{"timestamp":"2026-09-20T15:44:36","port":8945,"proto":"tcp","app_proto":"","app_protocol":"","host":"","headers":"","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"","summary":"MGLNDD_<HONEYPOT>_8945\n","payload_hex":"4d474c4e44445f<HONEYPOT>5f383934350a","method":"","user_agent":"","ja3":"","session":"e760fb2e-79fb-4338-83ab-1feed57ca0df","seq":1,"duration_ms":100,"bytes_in":25,"bytes_out":14,"enriched":{"digest":"6849680bc8d35e8a","strings":["MGLNDD_<HONEYPOT>_8945"]}},{"timestamp":"2026-09-19T20:12:40","port":1270,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:1270\",\"user-agent\":\"Mozilla/5.0 zgrab/0.x\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/","summary":"","payload_hex":"474554202f20485454502f312e310d0a486f73743a20<HONEYPOT>3a313237300d0a557365722d4167656e743a204d6f7a696c6c612f352e30207a677261622f302e780d0a4163636570743a202a2f2a0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 zgrab/0.x","ja3":"","session":"c435c3f1-7cb5-4267-aca7-5d3381e53873","seq":1,"duration_ms":101,"bytes_in":114,"bytes_out":79},{"timestamp":"2026-09-19T20:12:40","port":1270,"proto":"tcp","app_proto":"","app_protocol":"","host":"","headers":"","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"","summary":"MGLNDD_<HONEYPOT>_1270\n","payload_hex":"4d474c4e44445f<HONEYPOT>5f313237300a","method":"","user_agent":"","ja3":"","session":"ec588ca6-f28d-4e63-935e-5bb8617a19a6","seq":1,"duration_ms":100,"bytes_in":25,"bytes_out":14,"enriched":{"digest":"92fc869af0734c12","strings":["MGLNDD_<HONEYPOT>_1270"]}},{"timestamp":"2026-09-16T21:52:39","port":2323,"proto":"tcp","app_proto":"","app_protocol":"","host":"","headers":"","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"","summary":"MGLNDD_<HONEYPOT>_2323\n","payload_hex":"4d474c4e44445f<HONEYPOT>5f323332330a","method":"","user_agent":"","ja3":"","session":"3399ca1c-fea8-4786-a616-99f8171e46b1","seq":1,"duration_ms":100,"bytes_in":26,"bytes_out":12,"enriched":{"digest":"eee2fe7951b5b9c4","strings":["MGLNDD_<HONEYPOT>_2323"]}}],"http_methods":[{"method":"GET","count":2}],"distinct_ports_total":4,"top_paths":[{"path":"/","count":1,"ports":1},{"path":"/developmentserver/metadatauploader","count":1,"ports":1}],"distinct_paths_total":2,"top_snis":[],"top_hosts":[],"top_alpns":[],"banners":[],"credentials":[],"header_profile":{"signature":["Accept","Accept-Encoding","Host","User-Agent"],"representative":[{"name":"Accept","value":"*/*","notable":false},{"name":"Accept-Encoding","value":"gzip","notable":false},{"name":"Host","value":"<HONEYPOT>","notable":false},{"name":"User-Agent","value":"Mozilla/5.0 zgrab/0.x","notable":false}],"distinct_sets":1,"events_with_headers":2},"tags":[{"tag_id":"CVE-2025-31324","tag_type":"cve","title":"SAP NetWeaver Visual Composer Metadata Uploader - Deserialization","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/developmentserver/metadatauploader","reference_urls":["https://www.bleepingcomputer.com/news/security/sap-fixes-suspected-netweaver-zero-day-exploited-in-attacks/","https://www.theregister.com/2025/04/25/sap_netweaver_patch/","https://me.sap.com/notes/3594142","https://url.sap/sapsecuritypatchday"]}],"data_as_of":"2026-09-23T17:01:16.374872+00:00"}