User Agent Strings Curiosities, (Sun, Oct 4th)
At a glance
- Severity
- Low
- Used in attacks
- No flaws named
- Reported by
- 1 outlet
Sometimes I have to smile, or my interest is triggered, when I review new User Agent Strings in the honeypot logs.
Like when I see an "authorized" scan:
Or when I'm owned for the umpteenth time:
I regularly see URLs or email addresses for when you want to know more, or get in touch, with the persons behind a scanner:
(around the end of this list, you'll see the Belarus email address we wrote about recently)
Many variants of masscan:
Even a KGB variant.
As you can guess, "scan" is a popular word to include in your UAS:
And some wordplays are thrown in:
And they do not shy away from discrediting:
Sometime complete lists of User Agent Strings are used: the scanner will select a new UAS for each request. They don't always sanitize these list, as you can see with these weird "User Agent Strings":
These lines actually appear in this repository of User Agent Strings, to separate them in groups:
And because of a lack of quality control, these separator lines also get used as UAS in a request.
Of course, there are also attempts to exploit the parsing of a User Agent String. Shellshock may be more than 10 years old, I still see it in User Agent Strings:
And sometimes I think: "Huh, are they scanning for this too?". Like the last one:
Scanning for servers that stream GPS correction data via the NTRIP protocol (a NTRIP header was also included in this request).
Didier Stevens
Senior handler
blog.DidierStevens.com
Originally published by SANS Internet Storm Center. © SANS Internet Storm Center.
Fastnexa security experts
Dealing with this in your own company?
If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-10-04 07:58 UTC
Related stories
- ISC Stormcast For Monday, October 5th, 2026 https://isc.sans.edu/podcastdetail/10122, (Mon, Oct 5th)
SANS Internet Storm Center · 2026-10-05
- TTY Logs and the Data it Captures, (Sun, Oct 4th)
SANS Internet Storm Center · 2026-10-05
- China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
The Hacker News · 2026-10-04
- YARA-X 1.21.0 Release, (Sat, Oct 3rd)
SANS Internet Storm Center · 2026-10-03
- Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
The Hacker News · 2026-10-03