{"ip":"94.154.43.222","total_events":7,"verdict":{"verdict":"scanning","label":"Scanning for known vulnerabilities","detail":"1 exploit-path probe(s)","confidence":"medium","network_type":null,"why":["1 request(s) matched a known exploit path.","Only GET/HEAD seen, no request body: scanning for the vulnerability, not delivering a payload.","Not in any known-scanner range."],"engagement":{"level":"request","label":"Request traffic","detail":"827 bytes sent","bytes_sent":827,"session_seconds":0,"persistent":false}},"first_seen":"2026-09-17T00:09:03","last_seen":"2026-09-17T13:01:33","events_24h":0,"events_7d":7,"geo":{"country_code":"NL","country_name":"The Netherlands","region":"North Holland","city":"Amsterdam","lat":52.3716,"lon":4.8883,"asn":null,"org":""},"source_domain":null,"known_scanners":[],"scanner_tag":null,"cve_matches":[{"cve_id":"CVE-2024-3272","title":"D-Link Network Attached Storage - Backdoor Account","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/cgi-bin/nas_sharing.cgi?user=messagebus&passwd=&cmd=15&system=aWQ="},{"cve_id":"CVE-2020-13945","title":"Apache APISIX - Insufficiently Protected Credentials","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/apisix/admin/routes"}],"malware":[],"top_ports":[{"port":9180,"proto":"tcp","label":"","count":3},{"port":1880,"proto":"tcp","label":"","count":3},{"port":80,"proto":"tcp","label":"HTTP","count":1}],"fingerprints":{"ssh_hassh":[],"tls_ja4":[],"tls_ja3":[],"ja4h":["ge11nn0400_2f942d8d336b","ge11nn0200_f24fcf356134","ge11nn0300_0db47b7d240d"]},"fingerprint_peers":{"ge11nn0400_2f942d8d336b":1,"ge11nn0200_f24fcf356134":58,"ge11nn0300_0db47b7d240d":4929},"user_agents":["Go-http-client/1.1","Mozilla/5.0"],"timeline":[{"date":"2026-09-17","count":7}],"recent_events":[{"timestamp":"2026-09-17T13:01:33","port":1880,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"connection\":\"close\",\"host\":\"<HONEYPOT>:1880\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/settings","summary":"","payload_hex":"474554202f73657474696e677320485454502f312e310d0a486f73743a20<HONEYPOT>3a313838300d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a","method":"GET","user_agent":"","ja3":"","session":"77363b88-f91c-40a0-a1da-27b30e9348b9","seq":1,"duration_ms":100,"bytes_in":70,"bytes_out":78},{"timestamp":"2026-09-17T13:00:26","port":1880,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"connection\":\"close\",\"host\":\"<HONEYPOT>:1880\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/settings","summary":"","payload_hex":"474554202f73657474696e677320485454502f312e310d0a486f73743a20<HONEYPOT>3a313838300d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a","method":"GET","user_agent":"","ja3":"","session":"2e1f3a79-b0d9-4194-a83c-93793b8b0673","seq":1,"duration_ms":100,"bytes_in":70,"bytes_out":78},{"timestamp":"2026-09-17T12:58:05","port":1880,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"connection\":\"close\",\"host\":\"<HONEYPOT>:1880\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/settings","summary":"","payload_hex":"474554202f73657474696e677320485454502f312e310d0a486f73743a20<HONEYPOT>3a313838300d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a","method":"GET","user_agent":"","ja3":"","session":"c786294b-a48b-43d5-9885-a1320ddf1e2f","seq":1,"duration_ms":100,"bytes_in":71,"bytes_out":78},{"timestamp":"2026-09-17T11:52:47","port":9180,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"connection\":\"close\",\"host\":\"<HONEYPOT>:9180\",\"user-agent\":\"Mozilla/5.0\",\"x-api-key\":\"edd1c9f034335f136f87ad84b625c8f1\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/apisix/admin/routes","summary":"","payload_hex":"474554202f6170697369782f61646d696e2f726f7574657320485454502f312e310d0a486f73743a20<HONEYPOT>3a393138300d0a557365722d4167656e743a204d6f7a696c6c612f352e300d0a582d4170692d4b65793a2065646431633966303334333335663133366638376164383462363235633866310d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a","method":"GET","user_agent":"Mozilla/5.0","ja3":"","session":"28982dbf-2a20-4377-a5db-20718d2e0800","seq":1,"duration_ms":100,"bytes_in":152,"bytes_out":78},{"timestamp":"2026-09-17T11:51:45","port":9180,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"connection\":\"close\",\"host\":\"<HONEYPOT>:9180\",\"user-agent\":\"Mozilla/5.0\",\"x-api-key\":\"edd1c9f034335f136f87ad84b625c8f1\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/apisix/admin/routes","summary":"","payload_hex":"474554202f6170697369782f61646d696e2f726f7574657320485454502f312e310d0a486f73743a20<HONEYPOT>3a393138300d0a557365722d4167656e743a204d6f7a696c6c612f352e300d0a582d4170692d4b65793a2065646431633966303334333335663133366638376164383462363235633866310d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a","method":"GET","user_agent":"Mozilla/5.0","ja3":"","session":"3237907d-8853-4a19-b3ab-5f0359882f27","seq":1,"duration_ms":100,"bytes_in":151,"bytes_out":78},{"timestamp":"2026-09-17T11:44:55","port":9180,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"connection\":\"close\",\"host\":\"<HONEYPOT>:9180\",\"user-agent\":\"Mozilla/5.0\",\"x-api-key\":\"edd1c9f034335f136f87ad84b625c8f1\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/apisix/admin/routes","summary":"","payload_hex":"474554202f6170697369782f61646d696e2f726f7574657320485454502f312e310d0a486f73743a20<HONEYPOT>3a393138300d0a557365722d4167656e743a204d6f7a696c6c612f352e300d0a582d4170692d4b65793a2065646431633966303334333335663133366638376164383462363235633866310d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a","method":"GET","user_agent":"Mozilla/5.0","ja3":"","session":"c266bfe2-f376-40ea-b1c3-5251efb3d876","seq":1,"duration_ms":101,"bytes_in":151,"bytes_out":78},{"timestamp":"2026-09-17T00:09:03","port":80,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"accept-encoding\":\"gzip\",\"host\":\"<HONEYPOT>:80\",\"user-agent\":\"Go-http-client/1.1\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/cgi-bin/nas_sharing.cgi?user=messagebus&passwd=&cmd=15&system=aWQ=","summary":"","payload_hex":"474554202f6367692d62696e2f6e61735f73686172696e672e6367693f757365723d6d657373616765627573267061737377643d26636d643d31352673797374656d3d6157513d20485454502f312e310d0a486f73743a20<HONEYPOT>3a38300d0a557365722d4167656e743a20476f2d687474702d636c69656e742f312e310d0a4163636570742d456e636f64696e673a20677a69700d0a0d0a","method":"GET","user_agent":"Go-http-client/1.1","ja3":"","session":"fb6ca501-5065-4481-b36a-164f4934b250","seq":1,"duration_ms":100,"bytes_in":162,"bytes_out":78}],"http_methods":[{"method":"GET","count":7}],"distinct_ports_total":3,"top_paths":[{"path":"/settings","count":3,"ports":1},{"path":"/apisix/admin/routes","count":3,"ports":1},{"path":"/cgi-bin/nas_sharing.cgi?user=messagebus&passwd=&cmd=15&system=aWQ=","count":1,"ports":1}],"distinct_paths_total":3,"top_snis":[],"top_hosts":[],"top_alpns":[],"banners":[],"credentials":[],"header_profile":{"signature":["Connection","Host","User-Agent","X-Api-Key"],"representative":[{"name":"Connection","value":"close","notable":false},{"name":"Host","value":"<HONEYPOT>:9180","notable":false},{"name":"User-Agent","value":"Mozilla/5.0","notable":false},{"name":"X-Api-Key","value":"edd1c9f034335f136f87ad84b625c8f1","notable":true}],"distinct_sets":3,"events_with_headers":7},"tags":[{"tag_id":"CVE-2024-3272","tag_type":"cve","title":"D-Link Network Attached Storage - Backdoor Account","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/cgi-bin/nas_sharing.cgi?user=messagebus&passwd=&cmd=15&system=aWQ=","reference_urls":["https://github.com/netsecfish/dlink","https://nvd.nist.gov/vuln/detail/cve-2024-3272"]},{"tag_id":"CVE-2020-13945","tag_type":"cve","title":"Apache APISIX - Insufficiently Protected Credentials","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/apisix/admin/routes","reference_urls":["https://github.com/vulhub/vulhub/tree/master/apisix/CVE-2020-13945","https://lists.apache.org/thread.html/r792feb29964067a4108f53e8579a1e9bd1c8b5b9bc95618c814faf2f%40%3Cdev.apisix.apache.org%3E","http://packetstormsecurity.com/files/166228/Apache-APISIX-Remote-Code-Execution.html","https://nvd.nist.gov/vuln/detail/CVE-2020-13945","https://github.com/ARPSyndicate/cvemon"]}],"data_as_of":"2026-09-19T15:16:34.893372+00:00"}