# SANS Honeypot Logs Reveal Scanner UA Quirks

Published: 2026-10-04 · Severity: elevated
Canonical: https://vorant.io/reports/550d95f7-0473-5f28-93aa-41a5ca270010/sans-honeypot-logs-reveal-scanner-ua-quirks

> A SANS ISC handler reviews unusual User-Agent strings from honeypot logs, including masscan variants, scanner contact info, and lingering Shellshock exploitation attempts.

This SANS Internet Storm Center diary by Didier Stevens is an informal review of unusual and amusing User Agent Strings (UAS) observed in honeypot traffic rather than a formal threat report. It highlights how various scanning tools identify themselves, including masscan variants, scanners that embed contact URLs or email addresses (including a previously reported Belarusian address), and tools using humorous or self-identifying strings like 'authorized scan' or a 'KGB' variant. It also notes scanners pulling UAS values from public lists without sanitizing them, resulting in malformed strings such as list separator lines being sent as actual User-Agent headers.

Of more technical interest to defenders, the author notes continued sightings of Shellshock (CVE-2014-6271 class) exploitation attempts embedded in User-Agent headers more than a decade after the vulnerability was disclosed, indicating that legacy exploitation attempts against CGI/Bash-based web servers remain part of routine internet background scanning. The diary also flags a less common requestapparently scanning for NTRIP protocol servers (used for streaming GPS correction data), suggesting reconnaissance interest in GNSS/RTK infrastructure.

There is no specific campaign, malware family, or active incident described; this is observational honeypot research intended to illustrate the diversity and sloppiness of internet-wide scanning tools. Defenders can use this as a reminder to monitor and log User-Agent anomalies, retain detection for legacy Shellshock-style injection attempts in request headers, and be aware that unusual protocol scanning (e.g., NTRIP) may appear in broad internet scanning sweeps.

## Mentioned in this report

- Vulnerabilities: CVE-2014-6271 (KEV)
- Malware: Masscan

Source reporting: https://isc.sans.edu/diary/rss/33394

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/550d95f7-0473-5f28-93aa-41a5ca270010/sans-honeypot-logs-reveal-scanner-ua-quirks.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
