Profil de menace
Activité suspecte — risque 60/100 (Moyen) — MITRE T1046 — confiance 100 % — via HTTP — multi-protocole (3 protocoles · 5 min)
Période analysée : 2026-06-27 → 2026-07-27
Activité suspecte — risque 60/100 (Moyen) — MITRE T1046 — confiance 100 % — via HTTP — multi-protocole (3 protocoles · 5 min)
Campagne multi-ports détectée sur une fenêtre courte
Activité suspecte — risque 60/100 (Moyen) — MITRE T1046 — confiance 100 % — via HTTP — multi-protocole (3 protocoles · 5 min)
Synthèse décisionnelle honeypot — seuil de listing maintenu à 1 événement qualifié.
Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance 100 % — Score WAF 100 · Bonus corrélation +14 · 5 tag(s) WAF
ASN 23470 · 185.243.5.0/24 · RIPENCC — 8 pair(s) ASN/FAI listé(s) — activité locale élevée vs pairs · 331 événements sur la période pour cette IP.
Même FAI ReliableSite.Net LLC — corrélation indicative.
Cette IP touche plusieurs services simulés (pas seulement le web).
Origine réseau déclarée
Opérateur et dernière activité ban
Score capteur — surveiller, investiguer ou bloquer.
Les dates De/À priment sur la période. Affinez protocole, port, service et classification.
331 événements filtrés — activité quotidienne
Top ports ciblés sur les dernières 24 heures
SSH 22, RDP 3389, HTTP alternatifs…
Web, SSH, SAP, scans…
Intensité par jour et heure (UTC capteur)
331 événement(s) — page 1/7
| Horodatage | Proto | Port | Service | Classification | Sévérité | Risque | Actions |
|---|---|---|---|---|---|---|---|
| TCP | 5079 · HTTP | http | Scan de ports port scan syn · via HTTP:5079 · (reconnaissance) · → sip:62.3.50.33 | Élevée | Moyen · 60 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
OPTIONS sip:62.3.50.33 UA Avaya One-X Deskphone
Émulateur
HTTP
WAF
34
Recommandation
Investiguer
Tags
Cible HTTP
OPTIONS
sip:62.3.50.33
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
OPTIONS
Port
5079
Chemin / cible
sip:62.3.50.33
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +14
Risque capteur
Moyen
· 60
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
SSRF Localhost SSRF
SIP protocol
Ligne de requête
User-Agent
Avaya One-X Deskphone
Règles WAF
lfi-14
rce-0
rce-14
ssrf-2
nosqli-3
Payload (extrait)
OPTIONS sip:62.3.50.33 SIP/2.0 Via: SIP/2.0/TCP 127.0.0.1:5079;branch=z9hG4bK4b020819 To: <sip:62.3.50.33> From: <sip:scanner
Requête brute (extrait)
OPTIONS sip:62.3.50.33 SIP/2.0 Via: SIP/2.0/TCP 127.0.0.1:5079;branch=z9hG4bK4b020819 To: <sip:62.3.50.33> From: <sip:scanner@sip.com>;tag=ef6a7 Call-ID: 6528085afd2140709e6125207bc9c2e2 CSeq: 1 OPTIONS User-Agent: Avaya One-X Deskphone Accept: appl |
|||||||
| TCP | 5078 · HTTP | http | Scan de ports port scan syn · via HTTP:5078 · (reconnaissance) · → sip:62.3.50.33 | Élevée | Moyen · 60 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
OPTIONS sip:62.3.50.33 UA Zoiper rv2.15.53
Émulateur
HTTP
WAF
34
Recommandation
Investiguer
Tags
Cible HTTP
OPTIONS
sip:62.3.50.33
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
OPTIONS
Port
5078
Chemin / cible
sip:62.3.50.33
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +14
Risque capteur
Moyen
· 60
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
SSRF Localhost SSRF
SIP protocol
Ligne de requête
User-Agent
Zoiper rv2.15.53
Règles WAF
lfi-14
rce-0
rce-14
ssrf-2
nosqli-3
Payload (extrait)
OPTIONS sip:62.3.50.33 SIP/2.0 Via: SIP/2.0/TCP 127.0.0.1:5078;branch=z9hG4bK9a2ca8a1 To: <sip:62.3.50.33> From: <sip:scanner
Requête brute (extrait)
OPTIONS sip:62.3.50.33 SIP/2.0 Via: SIP/2.0/TCP 127.0.0.1:5078;branch=z9hG4bK9a2ca8a1 To: <sip:62.3.50.33> From: <sip:scanner@sip.com>;tag=1c1f9 Call-ID: b15987afbc7549619d933651d0b071d3 CSeq: 1 OPTIONS User-Agent: Zoiper rv2.15.53 Accept: applicati |
|||||||
| TCP | 5075 · HTTP | http | Scan de ports port scan syn · via HTTP:5075 · (reconnaissance) · → sip:62.3.50.33 | Élevée | Moyen · 60 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
OPTIONS sip:62.3.50.33 UA Avaya One-X Deskphone
Émulateur
HTTP
WAF
34
Recommandation
Investiguer
Tags
Cible HTTP
OPTIONS
sip:62.3.50.33
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
OPTIONS
Port
5075
Chemin / cible
sip:62.3.50.33
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +14
Risque capteur
Moyen
· 60
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
SSRF Localhost SSRF
SIP protocol
Ligne de requête
User-Agent
Avaya One-X Deskphone
Règles WAF
lfi-14
rce-0
rce-14
ssrf-2
nosqli-3
Payload (extrait)
OPTIONS sip:62.3.50.33 SIP/2.0 Via: SIP/2.0/TCP 127.0.0.1:5075;branch=z9hG4bK13ea4984 To: <sip:62.3.50.33> From: <sip:scanner
Requête brute (extrait)
OPTIONS sip:62.3.50.33 SIP/2.0 Via: SIP/2.0/TCP 127.0.0.1:5075;branch=z9hG4bK13ea4984 To: <sip:62.3.50.33> From: <sip:scanner@sip.com>;tag=ea639 Call-ID: caa3a94d4aa44eaf95e13bb9dd53c067 CSeq: 1 OPTIONS User-Agent: Avaya One-X Deskphone Accept: appl |
|||||||
| TCP | 5074 · HTTP | http | Scan de ports port scan syn · via HTTP:5074 · (reconnaissance) · → sip:62.3.50.33 | Élevée | Moyen · 60 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
OPTIONS sip:62.3.50.33 UA Zoiper rv2.15.53
Émulateur
HTTP
WAF
34
Recommandation
Investiguer
Tags
Cible HTTP
OPTIONS
sip:62.3.50.33
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
OPTIONS
Port
5074
Chemin / cible
sip:62.3.50.33
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +14
Risque capteur
Moyen
· 60
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
SSRF Localhost SSRF
SIP protocol
Ligne de requête
User-Agent
Zoiper rv2.15.53
Règles WAF
lfi-14
rce-0
rce-14
ssrf-2
nosqli-3
Payload (extrait)
OPTIONS sip:62.3.50.33 SIP/2.0 Via: SIP/2.0/TCP 127.0.0.1:5074;branch=z9hG4bK5641f716 To: <sip:62.3.50.33> From: <sip:scanner
Requête brute (extrait)
OPTIONS sip:62.3.50.33 SIP/2.0 Via: SIP/2.0/TCP 127.0.0.1:5074;branch=z9hG4bK5641f716 To: <sip:62.3.50.33> From: <sip:scanner@sip.com>;tag=a6e62 Call-ID: 53b64c5acf854a759eb829a39f11891c CSeq: 1 OPTIONS User-Agent: Zoiper rv2.15.53 Accept: applicati |
|||||||
| TCP | 5073 · HTTP | http | Scan de ports port scan syn · via HTTP:5073 · (reconnaissance) · → sip:62.3.50.33 | Élevée | Moyen · 59 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
OPTIONS sip:62.3.50.33 UA Cisco-CP7841/11.5.1
Émulateur
HTTP
WAF
34
Recommandation
Investiguer
Tags
Cible HTTP
OPTIONS
sip:62.3.50.33
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
OPTIONS
Port
5073
Chemin / cible
sip:62.3.50.33
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +14
Risque capteur
Moyen
· 59
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
SSRF Localhost SSRF
SIP protocol
Ligne de requête
User-Agent
Cisco-CP7841/11.5.1
Règles WAF
lfi-14
rce-0
rce-14
ssrf-2
nosqli-3
Payload (extrait)
OPTIONS sip:62.3.50.33 SIP/2.0 Via: SIP/2.0/TCP 127.0.0.1:5073;branch=z9hG4bKa3f54d84 To: <sip:62.3.50.33> From: <sip:scanner
Requête brute (extrait)
OPTIONS sip:62.3.50.33 SIP/2.0 Via: SIP/2.0/TCP 127.0.0.1:5073;branch=z9hG4bKa3f54d84 To: <sip:62.3.50.33> From: <sip:scanner@sip.com>;tag=4c779 Call-ID: 2975a162cde84db0bafb487b99ae5c48 CSeq: 1 OPTIONS User-Agent: Cisco-CP7841/11.5.1 Accept: applic |
|||||||
| TCP | 5072 · HTTP | http | Scan de ports port scan syn · via HTTP:5072 · (reconnaissance) · → sip:62.3.50.33 | Élevée | Moyen · 59 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
OPTIONS sip:62.3.50.33 UA Asterisk PBX 18.2.0
Émulateur
HTTP
WAF
34
Recommandation
Investiguer
Tags
Cible HTTP
OPTIONS
sip:62.3.50.33
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
OPTIONS
Port
5072
Chemin / cible
sip:62.3.50.33
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +14
Risque capteur
Moyen
· 59
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
SSRF Localhost SSRF
SIP protocol
Ligne de requête
User-Agent
Asterisk PBX 18.2.0
Règles WAF
lfi-14
rce-0
rce-14
ssrf-2
nosqli-3
Payload (extrait)
OPTIONS sip:62.3.50.33 SIP/2.0 Via: SIP/2.0/TCP 127.0.0.1:5072;branch=z9hG4bK5abaf4c7 To: <sip:62.3.50.33> From: <sip:scanner
Requête brute (extrait)
OPTIONS sip:62.3.50.33 SIP/2.0 Via: SIP/2.0/TCP 127.0.0.1:5072;branch=z9hG4bK5abaf4c7 To: <sip:62.3.50.33> From: <sip:scanner@sip.com>;tag=3833e Call-ID: 5c224b8783f8406a8b3a18f54680a97b CSeq: 1 OPTIONS User-Agent: Asterisk PBX 18.2.0 Accept: applic |
|||||||
| TCP | 5071 · HTTP | http | Scan de ports port scan syn · via HTTP:5071 · (reconnaissance) · → sip:62.3.50.33 | Élevée | Moyen · 59 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
OPTIONS sip:62.3.50.33 UA Cisco-CP7841/11.5.1
Émulateur
HTTP
WAF
34
Recommandation
Investiguer
Tags
Cible HTTP
OPTIONS
sip:62.3.50.33
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
OPTIONS
Port
5071
Chemin / cible
sip:62.3.50.33
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +14
Risque capteur
Moyen
· 59
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
SSRF Localhost SSRF
SIP protocol
Ligne de requête
User-Agent
Cisco-CP7841/11.5.1
Règles WAF
lfi-14
rce-0
rce-14
ssrf-2
nosqli-3
Payload (extrait)
OPTIONS sip:62.3.50.33 SIP/2.0 Via: SIP/2.0/TCP 127.0.0.1:5071;branch=z9hG4bKcf021e05 To: <sip:62.3.50.33> From: <sip:scanner
Requête brute (extrait)
OPTIONS sip:62.3.50.33 SIP/2.0 Via: SIP/2.0/TCP 127.0.0.1:5071;branch=z9hG4bKcf021e05 To: <sip:62.3.50.33> From: <sip:scanner@sip.com>;tag=f3031 Call-ID: b70a7e436a3a4eb0be7239930f417e7a CSeq: 1 OPTIONS User-Agent: Cisco-CP7841/11.5.1 Accept: applic |
|||||||
| TCP | 5069 · HTTP | http | Scan de ports port scan syn · via HTTP:5069 · (reconnaissance) · → sip:62.3.50.33 | Élevée | Moyen · 59 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
OPTIONS sip:62.3.50.33 UA Asterisk PBX 18.2.0
Émulateur
HTTP
WAF
34
Recommandation
Investiguer
Tags
Cible HTTP
OPTIONS
sip:62.3.50.33
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
OPTIONS
Port
5069
Chemin / cible
sip:62.3.50.33
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +14
Risque capteur
Moyen
· 59
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
SSRF Localhost SSRF
SIP protocol
Ligne de requête
User-Agent
Asterisk PBX 18.2.0
Règles WAF
lfi-14
rce-0
rce-14
ssrf-2
nosqli-3
Payload (extrait)
OPTIONS sip:62.3.50.33 SIP/2.0 Via: SIP/2.0/TCP 127.0.0.1:5069;branch=z9hG4bKacc65b61 To: <sip:62.3.50.33> From: <sip:scanner
Requête brute (extrait)
OPTIONS sip:62.3.50.33 SIP/2.0 Via: SIP/2.0/TCP 127.0.0.1:5069;branch=z9hG4bKacc65b61 To: <sip:62.3.50.33> From: <sip:scanner@sip.com>;tag=314b1 Call-ID: fbb47d2f3cf34c95bf3b57c49efffd78 CSeq: 1 OPTIONS User-Agent: Asterisk PBX 18.2.0 Accept: applic |
|||||||
| TCP | 5068 · HTTP | http | Scan de ports port scan syn · via HTTP:5068 · (reconnaissance) · → sip:62.3.50.33 | Élevée | Moyen · 59 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
OPTIONS sip:62.3.50.33 UA Avaya One-X Deskphone
Émulateur
HTTP
WAF
34
Recommandation
Investiguer
Tags
Cible HTTP
OPTIONS
sip:62.3.50.33
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
OPTIONS
Port
5068
Chemin / cible
sip:62.3.50.33
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +14
Risque capteur
Moyen
· 59
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
SSRF Localhost SSRF
SIP protocol
Ligne de requête
User-Agent
Avaya One-X Deskphone
Règles WAF
lfi-14
rce-0
rce-14
ssrf-2
nosqli-3
Payload (extrait)
OPTIONS sip:62.3.50.33 SIP/2.0 Via: SIP/2.0/TCP 127.0.0.1:5068;branch=z9hG4bK5c21a310 To: <sip:62.3.50.33> From: <sip:scanner
Requête brute (extrait)
OPTIONS sip:62.3.50.33 SIP/2.0 Via: SIP/2.0/TCP 127.0.0.1:5068;branch=z9hG4bK5c21a310 To: <sip:62.3.50.33> From: <sip:scanner@sip.com>;tag=d7451 Call-ID: 23117d1478864d119fa2dedd2dd4a6e5 CSeq: 1 OPTIONS User-Agent: Avaya One-X Deskphone Accept: appl |
|||||||
| TCP | 5067 · HTTP | http | Scan de ports port scan syn · via HTTP:5067 · (reconnaissance) · → sip:62.3.50.33 | Élevée | Moyen · 59 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
OPTIONS sip:62.3.50.33 UA Asterisk PBX 18.2.0
Émulateur
HTTP
WAF
34
Recommandation
Investiguer
Tags
Cible HTTP
OPTIONS
sip:62.3.50.33
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
OPTIONS
Port
5067
Chemin / cible
sip:62.3.50.33
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +14
Risque capteur
Moyen
· 59
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
SSRF Localhost SSRF
SIP protocol
Ligne de requête
User-Agent
Asterisk PBX 18.2.0
Règles WAF
lfi-14
rce-0
rce-14
ssrf-2
nosqli-3
Payload (extrait)
OPTIONS sip:62.3.50.33 SIP/2.0 Via: SIP/2.0/TCP 127.0.0.1:5067;branch=z9hG4bKcefeca8b To: <sip:62.3.50.33> From: <sip:scanner
Requête brute (extrait)
OPTIONS sip:62.3.50.33 SIP/2.0 Via: SIP/2.0/TCP 127.0.0.1:5067;branch=z9hG4bKcefeca8b To: <sip:62.3.50.33> From: <sip:scanner@sip.com>;tag=d7e33 Call-ID: 8ff636c5ecec492ebc1e3c99f293430e CSeq: 1 OPTIONS User-Agent: Asterisk PBX 18.2.0 Accept: applic |
|||||||
| TCP | 5066 · HTTP | http | Scan de ports port scan syn · via HTTP:5066 · (reconnaissance) · → sip:62.3.50.33 | Élevée | Moyen · 58 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
OPTIONS sip:62.3.50.33 UA Cisco-CP7841/11.5.1
Émulateur
HTTP
WAF
34
Recommandation
Investiguer
Tags
Cible HTTP
OPTIONS
sip:62.3.50.33
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
OPTIONS
Port
5066
Chemin / cible
sip:62.3.50.33
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +14
Risque capteur
Moyen
· 58
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
SSRF Localhost SSRF
SIP protocol
Ligne de requête
User-Agent
Cisco-CP7841/11.5.1
Règles WAF
lfi-14
rce-0
rce-14
ssrf-2
nosqli-3
Payload (extrait)
OPTIONS sip:62.3.50.33 SIP/2.0 Via: SIP/2.0/TCP 127.0.0.1:5066;branch=z9hG4bKc9ffa626 To: <sip:62.3.50.33> From: <sip:scanner
Requête brute (extrait)
OPTIONS sip:62.3.50.33 SIP/2.0 Via: SIP/2.0/TCP 127.0.0.1:5066;branch=z9hG4bKc9ffa626 To: <sip:62.3.50.33> From: <sip:scanner@sip.com>;tag=00571 Call-ID: 427d7b40829e46999e462b09727de4a8 CSeq: 1 OPTIONS User-Agent: Cisco-CP7841/11.5.1 Accept: applic |
|||||||
| TCP | 5065 · HTTP | http | Scan de ports port scan syn · via HTTP:5065 · (reconnaissance) · → sip:62.3.50.33 | Élevée | Moyen · 58 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
OPTIONS sip:62.3.50.33 UA Cisco-CP7841/11.5.1
Émulateur
HTTP
WAF
34
Recommandation
Investiguer
Tags
Cible HTTP
OPTIONS
sip:62.3.50.33
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
OPTIONS
Port
5065
Chemin / cible
sip:62.3.50.33
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +14
Risque capteur
Moyen
· 58
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
SSRF Localhost SSRF
SIP protocol
Ligne de requête
User-Agent
Cisco-CP7841/11.5.1
Règles WAF
lfi-14
rce-0
rce-14
ssrf-2
nosqli-3
Payload (extrait)
OPTIONS sip:62.3.50.33 SIP/2.0 Via: SIP/2.0/TCP 127.0.0.1:5065;branch=z9hG4bK1e6eda1b To: <sip:62.3.50.33> From: <sip:scanner
Requête brute (extrait)
OPTIONS sip:62.3.50.33 SIP/2.0 Via: SIP/2.0/TCP 127.0.0.1:5065;branch=z9hG4bK1e6eda1b To: <sip:62.3.50.33> From: <sip:scanner@sip.com>;tag=99516 Call-ID: 1f82d8a67fde4a31b6e67142f47c2ba9 CSeq: 1 OPTIONS User-Agent: Cisco-CP7841/11.5.1 Accept: applic |
|||||||
| TCP | 5064 · HTTP | http | Scan de ports port scan syn · via HTTP:5064 · (reconnaissance) · → sip:62.3.50.33 | Élevée | Moyen · 58 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
OPTIONS sip:62.3.50.33 UA Zoiper rv2.15.53
Émulateur
HTTP
WAF
34
Recommandation
Investiguer
Tags
Cible HTTP
OPTIONS
sip:62.3.50.33
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
OPTIONS
Port
5064
Chemin / cible
sip:62.3.50.33
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +14
Risque capteur
Moyen
· 58
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
SSRF Localhost SSRF
SIP protocol
Ligne de requête
User-Agent
Zoiper rv2.15.53
Règles WAF
lfi-14
rce-0
rce-14
ssrf-2
nosqli-3
Payload (extrait)
OPTIONS sip:62.3.50.33 SIP/2.0 Via: SIP/2.0/TCP 127.0.0.1:5064;branch=z9hG4bK062618c3 To: <sip:62.3.50.33> From: <sip:scanner
Requête brute (extrait)
OPTIONS sip:62.3.50.33 SIP/2.0 Via: SIP/2.0/TCP 127.0.0.1:5064;branch=z9hG4bK062618c3 To: <sip:62.3.50.33> From: <sip:scanner@sip.com>;tag=76617 Call-ID: 938e90bffef24c97a74233b4d2c791dd CSeq: 1 OPTIONS User-Agent: Zoiper rv2.15.53 Accept: applicati |
|||||||
| TCP | 5063 · HTTP | http | Scan de ports port scan syn · via HTTP:5063 · (reconnaissance) · → sip:62.3.50.33 | Élevée | Moyen · 58 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
OPTIONS sip:62.3.50.33 UA Avaya One-X Deskphone
Émulateur
HTTP
WAF
34
Recommandation
Investiguer
Tags
Cible HTTP
OPTIONS
sip:62.3.50.33
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
OPTIONS
Port
5063
Chemin / cible
sip:62.3.50.33
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +14
Risque capteur
Moyen
· 58
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Scan Burst
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
SSRF Localhost SSRF
SIP protocol
Ligne de requête
User-Agent
Avaya One-X Deskphone
Règles WAF
lfi-14
rce-0
rce-14
ssrf-2
nosqli-3
Payload (extrait)
OPTIONS sip:62.3.50.33 SIP/2.0 Via: SIP/2.0/TCP 127.0.0.1:5063;branch=z9hG4bK6a39be5d To: <sip:62.3.50.33> From: <sip:scanner
Requête brute (extrait)
OPTIONS sip:62.3.50.33 SIP/2.0 Via: SIP/2.0/TCP 127.0.0.1:5063;branch=z9hG4bK6a39be5d To: <sip:62.3.50.33> From: <sip:scanner@sip.com>;tag=69314 Call-ID: 3fcf9385eb304780b6a58b2809e73bfc CSeq: 1 OPTIONS User-Agent: Avaya One-X Deskphone Accept: appl |
|||||||
| TCP | 5070 · HTTP | http | Scan de ports port scan syn · via HTTP:5070 · (reconnaissance) · → sip:62.3.50.33 | Élevée | Moyen · 59 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
OPTIONS sip:62.3.50.33 UA Asterisk PBX 18.2.0
Émulateur
HTTP
WAF
34
Recommandation
Investiguer
Tags
Cible HTTP
OPTIONS
sip:62.3.50.33
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
OPTIONS
Port
5070
Chemin / cible
sip:62.3.50.33
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +14
Risque capteur
Moyen
· 59
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
SSRF Localhost SSRF
SIP protocol
Ligne de requête
User-Agent
Asterisk PBX 18.2.0
Règles WAF
lfi-14
rce-0
rce-14
ssrf-2
nosqli-3
Payload (extrait)
OPTIONS sip:62.3.50.33 SIP/2.0 Via: SIP/2.0/TCP 127.0.0.1:5070;branch=z9hG4bK5d3eb1ba To: <sip:62.3.50.33> From: <sip:scanner
Requête brute (extrait)
OPTIONS sip:62.3.50.33 SIP/2.0 Via: SIP/2.0/TCP 127.0.0.1:5070;branch=z9hG4bK5d3eb1ba To: <sip:62.3.50.33> From: <sip:scanner@sip.com>;tag=6d869 Call-ID: c51924f1886047e2ae7a9a5ec99216c5 CSeq: 1 OPTIONS User-Agent: Asterisk PBX 18.2.0 Accept: applic |
|||||||
| TCP | 5062 · HTTP | http | Scan de ports port scan syn · via HTTP:5062 · (reconnaissance) · → sip:62.3.50.33 | Élevée | Moyen · 58 |
|
|
|
Étape
Reconnaissance
Chaîne
Reconnaissance
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
T1046
TA0043
Protocole
OPTIONS sip:62.3.50.33 UA Cisco-CP7841/11.5.1
Émulateur
HTTP
WAF
34
Recommandation
Investiguer
Tags
Cible HTTP
OPTIONS
sip:62.3.50.33
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
OPTIONS
Port
5062
Chemin / cible
sip:62.3.50.33
Service
HTTP
Pourquoi cette classification : Type « port_scan_syn » (signaux protocolaires) · confiance 100%
Confiance classification
100%
Corrélation +8
Risque capteur
Moyen
· 58
Confiance : Confiance 100 % — 5 tag(s) WAF
Signaux
MITRE-T1046
SIGMA-net-port-scan
Beh Multi Port 60S
Technique MITRE
T1046
Tactiques MITRE
TA0043
Motifs de détection (base)
SSRF Localhost SSRF
SIP protocol
Ligne de requête
User-Agent
Cisco-CP7841/11.5.1
Règles WAF
lfi-14
rce-0
rce-14
ssrf-2
nosqli-3
Payload (extrait)
OPTIONS sip:62.3.50.33 SIP/2.0 Via: SIP/2.0/TCP 127.0.0.1:5062;branch=z9hG4bKfc3b8f34 To: <sip:62.3.50.33> From: <sip:scanner
Requête brute (extrait)
OPTIONS sip:62.3.50.33 SIP/2.0 Via: SIP/2.0/TCP 127.0.0.1:5062;branch=z9hG4bKfc3b8f34 To: <sip:62.3.50.33> From: <sip:scanner@sip.com>;tag=6e59b Call-ID: c4ac4b88f02445529b1e1c9f57765549 CSeq: 1 OPTIONS User-Agent: Cisco-CP7841/11.5.1 Accept: applic |
|||||||
| TCP | 5061 · SIP TLS | sip-tls | Sonde SIP/VoIP sip voip probe · via SIP TLS:5061 · (sonde / probe) | Élevée | Moyen · 45 |
|
|
|
Étape
Sonde / probe
Chaîne
Découverte
Persona
mail.sensor-1.internal
Rôle capteur
Renseignement menaces
Corrélations
MITRE
TA0007
TA0007
TA0001
Protocole
Émulateur
SIP-TLS
WAF
—
Recommandation
Surveiller
Tags
Cible HTTP
—
TLS SNI
—
Capteur
paris-1
|
|||||||
Preuve / Evidence
Méthode
—
Port
5061
Chemin / cible
—
Service
SIP TLS
Payload
��~�ֻ�Ϊ����[�/��JE�\��p**p+fE� �\?�WEI���"��'����K��#.r� $�,�0�+�/̨̩�$�(�#�' | |||||||