{"ip":"78.173.87.76","total_events":2,"verdict":{"verdict":"probing","label":"Low-level probing","detail":null,"confidence":"low","network_type":"nsp","why":["2 event(s), fewer than 10 distinct ports, no exploit payloads.","Not in any known-scanner range."],"engagement":{"level":"request","label":"Request traffic","detail":"586 bytes sent","bytes_sent":586,"session_seconds":0,"persistent":false}},"first_seen":"2026-09-26T18:19:57","last_seen":"2026-09-26T18:19:57","events_24h":0,"events_7d":2,"geo":{"country_code":"TR","country_name":"Türkiye","region":"Gaziantep","city":"Gaziantep","lat":37.2502,"lon":37.2014,"asn":9121,"org":"Turk Telekom"},"source_domain":"78.173.87.76.dynamic.ttnet.com.tr","known_scanners":[],"scanner_tag":{"key":"peeringdb:as9121","label":"Turk Telekom","category":"isp","url":"https://www.peeringdb.com/asn/9121"},"cve_matches":[{"cve_id":"CVE-2026-41940","title":"cPanel & WHM - Authentication Bypass via Session-File CRLF Injection","severity":"CRITICAL","actively_exploited":true,"match_field":"url_path","matched_pattern":"/login/?login_only=1"}],"malware":[],"top_ports":[{"port":2087,"proto":"tcp","label":"","count":2}],"fingerprints":{"ssh_hassh":[],"tls_ja4":["t13i311000_e8f1e7e78f70_24695f2957a7"],"tls_client_hello":"1603010200010001fc0303fc94a14d04f1ed7a91d3725bd07aee56f20b3b77a274b5889c8e11d3fab6f3c9200b711a30162a367fc0400e1ad22a6aebabcf92d9e6e4d6beb11ba60695367a56003e130213031301c02cc030009fcca9cca8ccaac02bc02f009ec024c028006bc023c0270067c00ac0140039c009c0130033009d009c003d003c0035002f00ff01000175000b000403000102000a000c000a001d0017001e00190018002300000016000000170000000d0030002e040305030603080708080809080a080b080408050806040105010601030302030301020103020202040205020602002b00050403040303002d00020101003300260024001d0020be182e9b136d805002e8aaa50b5ab620b84236b3433432c4f933c0db43025867001500e00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000","tls_ja3":["004556e859f3c26c5d19746b3a957c74"],"http_akin":["a11cun050_0000004f_0ff79011","a11cuq070_0000064f_4a9f3123"]},"fingerprint_peers":{"t13i311000_e8f1e7e78f70_24695f2957a7":512,"a11cuq070_0000064f_4a9f3123":2,"a11cun050_0000004f_0ff79011":4},"akin_families":{},"user_agents":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"],"timeline":[{"date":"2026-09-26","count":2}],"recent_events":[{"timestamp":"2026-09-26T18:19:57","port":2087,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"identity\",\"connection\":\"close\",\"host\":\"<HONEYPOT>:2087\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36\"}","body":"","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/openid_connect/cpanelid","summary":"","payload_hex":"474554202f6f70656e69645f636f6e6e6563742f6370616e656c696420485454502f312e310d0a4163636570742d456e636f64696e673a206964656e746974790d0a486f73743a20<HONEYPOT>3a323038370d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f3134362e302e302e30205361666172692f3533372e33360d0a4163636570743a202a2f2a0d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36","ja3":"004556e859f3c26c5d19746b3a957c74","session":"819d6011-eded-4465-a6cc-6df9e13d2eef","seq":1,"duration_ms":100,"bytes_in":250,"bytes_out":77},{"timestamp":"2026-09-26T18:19:57","port":2087,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"*/*\",\"accept-encoding\":\"identity\",\"connection\":\"close\",\"content-length\":\"20\",\"content-type\":\"application/x-www-form-urlencoded\",\"host\":\"<HONEYPOT>:2087\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36\"}","body":"user=root&pass=wrong","sni":"","tls_cipher":"TLS_CHACHA20_POLY1305_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/login/?login_only=1","summary":"","payload_hex":"504f5354202f6c6f67696e2f3f6c6f67696e5f6f6e6c793d3120485454502f312e310d0a4163636570742d456e636f64696e673a206964656e746974790d0a436f6e74656e742d4c656e6774683a2032300d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b2057696e36343b2078363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f3134362e302e302e30205361666172692f3533372e33360d0a4163636570743a202a2f2a0d0a436f6e6e656374696f6e3a20636c6f73650d0a486f73743a20<HONEYPOT>3a323038370d0a436f6e74656e742d547970653a206170706c69636174696f6e2f782d7777772d666f726d2d75726c656e636f6465640d0a0d0a757365723d726f6f7426706173733d77726f6e67","method":"POST","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36","ja3":"004556e859f3c26c5d19746b3a957c74","session":"9a425ce7-7366-4ba6-a9af-17a5f5a0a46c","seq":1,"duration_ms":100,"bytes_in":336,"bytes_out":77}],"http_methods":[{"method":"GET","count":1},{"method":"POST","count":1}],"distinct_ports_total":1,"top_paths":[{"path":"/login/?login_only=1","count":1,"ports":1},{"path":"/openid_connect/cpanelid","count":1,"ports":1}],"distinct_paths_total":2,"top_snis":[],"top_hosts":[],"top_alpns":[],"banners":[],"credentials":[{"username":"root","password":"wrong","count":1}],"header_profile":{"signature":["Accept","Accept-Encoding","Connection","Content-Length","Content-Type","Host","User-Agent"],"representative":[{"name":"Accept","value":"*/*","notable":false},{"name":"Accept-Encoding","value":"identity","notable":false},{"name":"Connection","value":"close","notable":false},{"name":"Content-Length","value":"20","notable":false},{"name":"Content-Type","value":"application/x-www-form-urlencoded","notable":true},{"name":"Host","value":"<HONEYPOT>:2087","notable":false},{"name":"User-Agent","value":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36","notable":false}],"distinct_sets":2,"events_with_headers":2},"tags":[{"tag_id":"CVE-2026-41940","tag_type":"cve","title":"cPanel & WHM - Authentication Bypass via Session-File CRLF Injection","severity":"CRITICAL","actively_exploited":true,"match_field":"url_path","matched_pattern":"/login/?login_only=1","reference_urls":[]}],"data_as_of":"2026-09-29T14:54:03.045953+00:00"}