Returning 10 result(s) out of 11,629 in 0.050 second(s)

  • 90.147.44.198:1000 (tcp/http) - last seen on 2024-11-07 at 05:34:57 UTC

    • IP
      90.147.44.198
      Network
      90.147.0.0/16
      Device

      <enterprise field>: device.class

      URL

      http://193.205.131.1:1000/fgtauth?034a84668f56749e 200

      HTTP Title
      Firewall Authentication
      ASN
      AS137
      Organization
      Consortium GARR
      Protocol
      http
      Source
      urlscan::redirect
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      c6eb65e92aacb2c3c5d7a4be042310dc
      HTTP Header MD5
      e2075400d0db00256ee037a5b80ae1f7
      HTTP Body MD5
      5ac3a5b131bfebcf54a184950f30ee33
    • HTTP/1.1 200 OK
      Content-Length: 3427
      Connection: close
      Cache-Control: no-cache
      Content-Type: text/html
      X-Frame-Options: SAMEORIGIN
      
      <!DOCTYPE html><html lang="en"> <head> <meta charset="UTF-8"> <meta http-equiv="X-UA-Compatible" content="IE=8; IE=EDGE"> <meta name="viewport" content="width=device-width, initial-scale=1"> <link href="https://fonts.googleapis.com/css?family=Roboto&display=swap" rel="stylesheet"> <style type="text/css"> body { height: 100%; font-family: Roboto, Helvetica, Arial, sans-serif; color: #6a6a6a; margin: 0; display: flex; align-items: center; justify-content: center; } input[type=date], input[type=email], input[type=number], input[type=password], input[type=search], input[type=tel], input[type=text], input[type=time], input[type=url], select, textarea { color: #262626; vertical-align: baseline; margin: .2em; border-style: solid; border-width: 1px; border-color: #a9a9a9; background-color: #fff; box-sizing: border-box; padding: 2px .5em; appearance: none; border-radius: 0; } input:focus { border-color: #646464; box-shadow: 0 0 1px 0 #a2a2a2; outline: 0; } button { padding: .5em 1em; border: 1px solid; border-radius: 3px; min-width: 6em; font-weight: 400; font-size: .8em; cursor: pointer; } button.primary { color: #fff; background-color: #c1092a; border-color: rgb(34, 103, 173); } .message-container { height: 500px; width: 600px; padding: 0; margin: 10px; } .logo { background: url(/XX/YY/ZZ/CI/MEPGHGPGPFFHOGJGGHAHNG) no-repeat left center; height: 267px; object-fit: contain; } table { background-color: #fff; border-spacing: 0; margin: 1em; } table > tbody > tr > td:first-of-type:not([colspan]) { white-space: nowrap; color: rgba(0,0,0,.5); } table > tbody > tr > td:first-of-type { vertical-align: top; } table > tbody > tr > td { padding: .3em .3em; } .field { display: table-row; } .field > :first-child { display: table-cell; width: 20%; } .field.single > :first-child { display: inline; } .field > :not(:first-child) { width: auto; max-width: 100%; display: inline-flex; align-items: baseline; virtical-align: top; box-sizing: border-box; margin: .3em; } .field > :not(:first-child) > input { width: 230px; } .form-footer { display: inline-flex; justify-content: flex-start; } .form-footer > * { margin: 1em; } .text-scrollable { overflow: auto; height: 150px; border: 1px solid rgb(200, 200, 200); padding: 5px; font-size: 1em; } .text-centered { text-align: center; } .text-container { margin: 1em 1.5em; } .flex-container { display: flex; } .flex-container.column { flex-direction: column; } </style> <title> Firewall Authentication </title> </head> <body> <div class="message-container"> <div class="logo"> </div> <h1> Autenticazione Richiesta </h1> <form action="/" method="post"> <input type="hidden" name="4Tredir" value="http://193.205.131.1:1000/fgtauth?034a84668f56749e"> <input type="hidden" name="magic" value="0246d3ce82043c44"> <input type="hidden" name="" value=""> <p> Inserisci le credenziali per accedere ad Internet </br> Se riscontri dei problemi contatta l'ufficio reti </br> <a href="mailto:ict.network@sm.univpm.it"> ict.network@sm.univpm.it </a> </p> <div class="field"> <label for="ft_un"> Username </label> <div> <input name="username" id="ft_un" type="text" autocorrect="off" autocapitalize="off"> </div> </div> <div class="field"> <label for="ft_pd"> Password </label> <div> <input name="password" id="ft_pd" type="password" autocomplete="off"> </div> </div> <div class="form-footer"> <button class="primary" type="submit"> Continue </button> </div> </form></div></body></html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:34:57.000Z",
         "app" : {
            "extract" : {
               "domain" : [
                  "googleapis.com"
               ],
               "hostname" : [
                  "fonts.googleapis.com"
               ],
               "ip" : [
                  "193.205.131.1"
               ],
               "url" : [
                  "http://193.205.131.1:1000/fgtauth?034a84668f56749e",
                  "https://fonts.googleapis.com/css?family=Roboto&display=swap"
               ]
            },
            "http" : {
               "bodymd5" : "5ac3a5b131bfebcf54a184950f30ee33",
               "bodymmh3" : 517928208,
               "headermd5" : "e2075400d0db00256ee037a5b80ae1f7",
               "headermmh3" : -923971862,
               "title" : "Firewall Authentication"
            },
            "length" : 3566
         },
         "asn" : "AS137",
         "city" : "Pavia",
         "country" : "IT",
         "data" : "HTTP/1.1 200 OK\r\nContent-Length: 3427\r\nConnection: close\r\nCache-Control: no-cache\r\nContent-Type: text/html\r\nX-Frame-Options: SAMEORIGIN\r\n\r\n<!DOCTYPE html><html lang=\"en\"> <head> <meta charset=\"UTF-8\"> <meta http-equiv=\"X-UA-Compatible\" content=\"IE=8; IE=EDGE\"> <meta name=\"viewport\" content=\"width=device-width, initial-scale=1\"> <link href=\"https://fonts.googleapis.com/css?family=Roboto&display=swap\" rel=\"stylesheet\"> <style type=\"text/css\"> body { height: 100%; font-family: Roboto, Helvetica, Arial, sans-serif; color: #6a6a6a; margin: 0; display: flex; align-items: center; justify-content: center; } input[type=date], input[type=email], input[type=number], input[type=password], input[type=search], input[type=tel], input[type=text], input[type=time], input[type=url], select, textarea { color: #262626; vertical-align: baseline; margin: .2em; border-style: solid; border-width: 1px; border-color: #a9a9a9; background-color: #fff; box-sizing: border-box; padding: 2px .5em; appearance: none; border-radius: 0; } input:focus { border-color: #646464; box-shadow: 0 0 1px 0 #a2a2a2; outline: 0; } button { padding: .5em 1em; border: 1px solid; border-radius: 3px; min-width: 6em; font-weight: 400; font-size: .8em; cursor: pointer; } button.primary { color: #fff; background-color: #c1092a; border-color: rgb(34, 103, 173); } .message-container { height: 500px; width: 600px; padding: 0; margin: 10px; } .logo { background: url(/XX/YY/ZZ/CI/MEPGHGPGPFFHOGJGGHAHNG) no-repeat left center; height: 267px; object-fit: contain; } table { background-color: #fff; border-spacing: 0; margin: 1em; } table > tbody > tr > td:first-of-type:not([colspan]) { white-space: nowrap; color: rgba(0,0,0,.5); } table > tbody > tr > td:first-of-type { vertical-align: top; } table > tbody > tr > td { padding: .3em .3em; } .field { display: table-row; } .field > :first-child { display: table-cell; width: 20%; } .field.single > :first-child { display: inline; } .field > :not(:first-child) { width: auto; max-width: 100%; display: inline-flex; align-items: baseline; virtical-align: top; box-sizing: border-box; margin: .3em; } .field > :not(:first-child) > input { width: 230px; } .form-footer { display: inline-flex; justify-content: flex-start; } .form-footer > * { margin: 1em; } .text-scrollable { overflow: auto; height: 150px; border: 1px solid rgb(200, 200, 200); padding: 5px; font-size: 1em; } .text-centered { text-align: center; } .text-container { margin: 1em 1.5em; } .flex-container { display: flex; } .flex-container.column { flex-direction: column; } </style> <title> Firewall Authentication </title> </head> <body> <div class=\"message-container\"> <div class=\"logo\"> </div> <h1> Autenticazione Richiesta </h1> <form action=\"/\" method=\"post\"> <input type=\"hidden\" name=\"4Tredir\" value=\"http://193.205.131.1:1000/fgtauth?034a84668f56749e\"> <input type=\"hidden\" name=\"magic\" value=\"0246d3ce82043c44\"> <input type=\"hidden\" name=\"\" value=\"\"> <p> Inserisci le credenziali per accedere ad Internet </br> Se riscontri dei problemi contatta l'ufficio reti </br> <a href=\"mailto:ict.network@sm.univpm.it\"> ict.network@sm.univpm.it </a> </p> <div class=\"field\"> <label for=\"ft_un\"> Username </label> <div> <input name=\"username\" id=\"ft_un\" type=\"text\" autocorrect=\"off\" autocapitalize=\"off\"> </div> </div> <div class=\"field\"> <label for=\"ft_pd\"> Password </label> <div> <input name=\"password\" id=\"ft_pd\" type=\"password\" autocomplete=\"off\"> </div> </div> <div class=\"form-footer\"> <button class=\"primary\" type=\"submit\"> Continue </button> </div> </form></div></body></html>\r\n",
         "datamd5" : "c6eb65e92aacb2c3c5d7a4be042310dc",
         "datammh3" : 1813863497,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "forward" : "193.205.131.1",
         "geolocus" : {
            "asn" : "AS137",
            "continent" : "EU",
            "continentname" : "Europe",
            "country" : "IT",
            "countryname" : "Italy",
            "domain" : [
               "garr.it",
               "uniurb.it"
            ],
            "isineu" : "true",
            "latitude" : "41.87194",
            "location" : "41.87194,12.56738",
            "longitude" : "12.56738",
            "netname" : "UNI-URB07",
            "organization" : "Universita' degli Studi di Urbino Carlo Bo",
            "subnet" : "90.147.0.0/18"
         },
         "hostname" : [
            "193.205.131.1"
         ],
         "ip" : "90.147.44.198",
         "ipv6" : "false",
         "latitude" : "45.1976",
         "location" : "45.1976,9.1578",
         "longitude" : "9.1578",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "Consortium GARR",
         "port" : 1000,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "OK",
         "seen_date" : "2024-11-07",
         "source" : "urlscan::redirect",
         "status" : 200,
         "subnet" : "90.147.0.0/16",
         "tag" : "<enterprise field>: tag",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/fgtauth?034a84668f56749e"
      }
      
  • 90.147.45.190:1000 (tcp/http) - last seen on 2024-11-07 at 05:34:57 UTC

    • IP
      90.147.45.190
      Network
      90.147.0.0/16
      Device

      <enterprise field>: device.class

      URL

      http://193.205.131.1:1000/fgtauth?0046ddbc5b425484 200

      HTTP Title
      Firewall Authentication
      ASN
      AS137
      Organization
      Consortium GARR
      Protocol
      http
      Source
      urlscan::redirect
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      9ed513150a16b578a709fec392988740
      HTTP Header MD5
      e2075400d0db00256ee037a5b80ae1f7
      HTTP Body MD5
      5ac3a5b131bfebcf54a184950f30ee33
    • HTTP/1.1 200 OK
      Content-Length: 3427
      Connection: close
      Cache-Control: no-cache
      Content-Type: text/html
      X-Frame-Options: SAMEORIGIN
      
      <!DOCTYPE html><html lang="en"> <head> <meta charset="UTF-8"> <meta http-equiv="X-UA-Compatible" content="IE=8; IE=EDGE"> <meta name="viewport" content="width=device-width, initial-scale=1"> <link href="https://fonts.googleapis.com/css?family=Roboto&display=swap" rel="stylesheet"> <style type="text/css"> body { height: 100%; font-family: Roboto, Helvetica, Arial, sans-serif; color: #6a6a6a; margin: 0; display: flex; align-items: center; justify-content: center; } input[type=date], input[type=email], input[type=number], input[type=password], input[type=search], input[type=tel], input[type=text], input[type=time], input[type=url], select, textarea { color: #262626; vertical-align: baseline; margin: .2em; border-style: solid; border-width: 1px; border-color: #a9a9a9; background-color: #fff; box-sizing: border-box; padding: 2px .5em; appearance: none; border-radius: 0; } input:focus { border-color: #646464; box-shadow: 0 0 1px 0 #a2a2a2; outline: 0; } button { padding: .5em 1em; border: 1px solid; border-radius: 3px; min-width: 6em; font-weight: 400; font-size: .8em; cursor: pointer; } button.primary { color: #fff; background-color: #c1092a; border-color: rgb(34, 103, 173); } .message-container { height: 500px; width: 600px; padding: 0; margin: 10px; } .logo { background: url(/XX/YY/ZZ/CI/MEPGHGPGPFFHOGJGGHAHNG) no-repeat left center; height: 267px; object-fit: contain; } table { background-color: #fff; border-spacing: 0; margin: 1em; } table > tbody > tr > td:first-of-type:not([colspan]) { white-space: nowrap; color: rgba(0,0,0,.5); } table > tbody > tr > td:first-of-type { vertical-align: top; } table > tbody > tr > td { padding: .3em .3em; } .field { display: table-row; } .field > :first-child { display: table-cell; width: 20%; } .field.single > :first-child { display: inline; } .field > :not(:first-child) { width: auto; max-width: 100%; display: inline-flex; align-items: baseline; virtical-align: top; box-sizing: border-box; margin: .3em; } .field > :not(:first-child) > input { width: 230px; } .form-footer { display: inline-flex; justify-content: flex-start; } .form-footer > * { margin: 1em; } .text-scrollable { overflow: auto; height: 150px; border: 1px solid rgb(200, 200, 200); padding: 5px; font-size: 1em; } .text-centered { text-align: center; } .text-container { margin: 1em 1.5em; } .flex-container { display: flex; } .flex-container.column { flex-direction: column; } </style> <title> Firewall Authentication </title> </head> <body> <div class="message-container"> <div class="logo"> </div> <h1> Autenticazione Richiesta </h1> <form action="/" method="post"> <input type="hidden" name="4Tredir" value="http://193.205.131.1:1000/fgtauth?0046ddbc5b425484"> <input type="hidden" name="magic" value="0041d3c5860a24b5"> <input type="hidden" name="" value=""> <p> Inserisci le credenziali per accedere ad Internet </br> Se riscontri dei problemi contatta l'ufficio reti </br> <a href="mailto:ict.network@sm.univpm.it"> ict.network@sm.univpm.it </a> </p> <div class="field"> <label for="ft_un"> Username </label> <div> <input name="username" id="ft_un" type="text" autocorrect="off" autocapitalize="off"> </div> </div> <div class="field"> <label for="ft_pd"> Password </label> <div> <input name="password" id="ft_pd" type="password" autocomplete="off"> </div> </div> <div class="form-footer"> <button class="primary" type="submit"> Continue </button> </div> </form></div></body></html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:34:57.000Z",
         "app" : {
            "extract" : {
               "domain" : [
                  "googleapis.com"
               ],
               "hostname" : [
                  "fonts.googleapis.com"
               ],
               "ip" : [
                  "193.205.131.1"
               ],
               "url" : [
                  "http://193.205.131.1:1000/fgtauth?0046ddbc5b425484",
                  "https://fonts.googleapis.com/css?family=Roboto&display=swap"
               ]
            },
            "http" : {
               "bodymd5" : "5ac3a5b131bfebcf54a184950f30ee33",
               "bodymmh3" : 522661287,
               "headermd5" : "e2075400d0db00256ee037a5b80ae1f7",
               "headermmh3" : -923971862,
               "title" : "Firewall Authentication"
            },
            "length" : 3566
         },
         "asn" : "AS137",
         "city" : "Pavia",
         "country" : "IT",
         "data" : "HTTP/1.1 200 OK\r\nContent-Length: 3427\r\nConnection: close\r\nCache-Control: no-cache\r\nContent-Type: text/html\r\nX-Frame-Options: SAMEORIGIN\r\n\r\n<!DOCTYPE html><html lang=\"en\"> <head> <meta charset=\"UTF-8\"> <meta http-equiv=\"X-UA-Compatible\" content=\"IE=8; IE=EDGE\"> <meta name=\"viewport\" content=\"width=device-width, initial-scale=1\"> <link href=\"https://fonts.googleapis.com/css?family=Roboto&display=swap\" rel=\"stylesheet\"> <style type=\"text/css\"> body { height: 100%; font-family: Roboto, Helvetica, Arial, sans-serif; color: #6a6a6a; margin: 0; display: flex; align-items: center; justify-content: center; } input[type=date], input[type=email], input[type=number], input[type=password], input[type=search], input[type=tel], input[type=text], input[type=time], input[type=url], select, textarea { color: #262626; vertical-align: baseline; margin: .2em; border-style: solid; border-width: 1px; border-color: #a9a9a9; background-color: #fff; box-sizing: border-box; padding: 2px .5em; appearance: none; border-radius: 0; } input:focus { border-color: #646464; box-shadow: 0 0 1px 0 #a2a2a2; outline: 0; } button { padding: .5em 1em; border: 1px solid; border-radius: 3px; min-width: 6em; font-weight: 400; font-size: .8em; cursor: pointer; } button.primary { color: #fff; background-color: #c1092a; border-color: rgb(34, 103, 173); } .message-container { height: 500px; width: 600px; padding: 0; margin: 10px; } .logo { background: url(/XX/YY/ZZ/CI/MEPGHGPGPFFHOGJGGHAHNG) no-repeat left center; height: 267px; object-fit: contain; } table { background-color: #fff; border-spacing: 0; margin: 1em; } table > tbody > tr > td:first-of-type:not([colspan]) { white-space: nowrap; color: rgba(0,0,0,.5); } table > tbody > tr > td:first-of-type { vertical-align: top; } table > tbody > tr > td { padding: .3em .3em; } .field { display: table-row; } .field > :first-child { display: table-cell; width: 20%; } .field.single > :first-child { display: inline; } .field > :not(:first-child) { width: auto; max-width: 100%; display: inline-flex; align-items: baseline; virtical-align: top; box-sizing: border-box; margin: .3em; } .field > :not(:first-child) > input { width: 230px; } .form-footer { display: inline-flex; justify-content: flex-start; } .form-footer > * { margin: 1em; } .text-scrollable { overflow: auto; height: 150px; border: 1px solid rgb(200, 200, 200); padding: 5px; font-size: 1em; } .text-centered { text-align: center; } .text-container { margin: 1em 1.5em; } .flex-container { display: flex; } .flex-container.column { flex-direction: column; } </style> <title> Firewall Authentication </title> </head> <body> <div class=\"message-container\"> <div class=\"logo\"> </div> <h1> Autenticazione Richiesta </h1> <form action=\"/\" method=\"post\"> <input type=\"hidden\" name=\"4Tredir\" value=\"http://193.205.131.1:1000/fgtauth?0046ddbc5b425484\"> <input type=\"hidden\" name=\"magic\" value=\"0041d3c5860a24b5\"> <input type=\"hidden\" name=\"\" value=\"\"> <p> Inserisci le credenziali per accedere ad Internet </br> Se riscontri dei problemi contatta l'ufficio reti </br> <a href=\"mailto:ict.network@sm.univpm.it\"> ict.network@sm.univpm.it </a> </p> <div class=\"field\"> <label for=\"ft_un\"> Username </label> <div> <input name=\"username\" id=\"ft_un\" type=\"text\" autocorrect=\"off\" autocapitalize=\"off\"> </div> </div> <div class=\"field\"> <label for=\"ft_pd\"> Password </label> <div> <input name=\"password\" id=\"ft_pd\" type=\"password\" autocomplete=\"off\"> </div> </div> <div class=\"form-footer\"> <button class=\"primary\" type=\"submit\"> Continue </button> </div> </form></div></body></html>\r\n",
         "datamd5" : "9ed513150a16b578a709fec392988740",
         "datammh3" : 876137111,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "forward" : "193.205.131.1",
         "geolocus" : {
            "asn" : "AS137",
            "continent" : "EU",
            "continentname" : "Europe",
            "country" : "IT",
            "countryname" : "Italy",
            "domain" : [
               "garr.it",
               "uniurb.it"
            ],
            "isineu" : "true",
            "latitude" : "41.87194",
            "location" : "41.87194,12.56738",
            "longitude" : "12.56738",
            "netname" : "UNI-URB07",
            "organization" : "Universita' degli Studi di Urbino Carlo Bo",
            "subnet" : "90.147.0.0/18"
         },
         "hostname" : [
            "193.205.131.1"
         ],
         "ip" : "90.147.45.190",
         "ipv6" : "false",
         "latitude" : "45.1976",
         "location" : "45.1976,9.1578",
         "longitude" : "9.1578",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "Consortium GARR",
         "port" : 1000,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "OK",
         "seen_date" : "2024-11-07",
         "source" : "urlscan::redirect",
         "status" : 200,
         "subnet" : "90.147.0.0/16",
         "tag" : "<enterprise field>: tag",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/fgtauth?0046ddbc5b425484"
      }
      
  • 90.147.47.93:1000 (tcp/http) - last seen on 2024-11-07 at 05:34:57 UTC

    • IP
      90.147.47.93
      Network
      90.147.0.0/16
      Device

      <enterprise field>: device.class

      URL

      http://193.205.131.1:1000/fgtauth?0640846713cb9b3b 200

      HTTP Title
      Firewall Authentication
      ASN
      AS137
      Organization
      Consortium GARR
      Protocol
      http
      Source
      urlscan::redirect
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      54f805b5cb1ca97c1591aeb3378a80a3
      HTTP Header MD5
      e2075400d0db00256ee037a5b80ae1f7
      HTTP Body MD5
      5ac3a5b131bfebcf54a184950f30ee33
    • HTTP/1.1 200 OK
      Content-Length: 3427
      Connection: close
      Cache-Control: no-cache
      Content-Type: text/html
      X-Frame-Options: SAMEORIGIN
      
      <!DOCTYPE html><html lang="en"> <head> <meta charset="UTF-8"> <meta http-equiv="X-UA-Compatible" content="IE=8; IE=EDGE"> <meta name="viewport" content="width=device-width, initial-scale=1"> <link href="https://fonts.googleapis.com/css?family=Roboto&display=swap" rel="stylesheet"> <style type="text/css"> body { height: 100%; font-family: Roboto, Helvetica, Arial, sans-serif; color: #6a6a6a; margin: 0; display: flex; align-items: center; justify-content: center; } input[type=date], input[type=email], input[type=number], input[type=password], input[type=search], input[type=tel], input[type=text], input[type=time], input[type=url], select, textarea { color: #262626; vertical-align: baseline; margin: .2em; border-style: solid; border-width: 1px; border-color: #a9a9a9; background-color: #fff; box-sizing: border-box; padding: 2px .5em; appearance: none; border-radius: 0; } input:focus { border-color: #646464; box-shadow: 0 0 1px 0 #a2a2a2; outline: 0; } button { padding: .5em 1em; border: 1px solid; border-radius: 3px; min-width: 6em; font-weight: 400; font-size: .8em; cursor: pointer; } button.primary { color: #fff; background-color: #c1092a; border-color: rgb(34, 103, 173); } .message-container { height: 500px; width: 600px; padding: 0; margin: 10px; } .logo { background: url(/XX/YY/ZZ/CI/MEPGHGPGPFFHOGJGGHAHNG) no-repeat left center; height: 267px; object-fit: contain; } table { background-color: #fff; border-spacing: 0; margin: 1em; } table > tbody > tr > td:first-of-type:not([colspan]) { white-space: nowrap; color: rgba(0,0,0,.5); } table > tbody > tr > td:first-of-type { vertical-align: top; } table > tbody > tr > td { padding: .3em .3em; } .field { display: table-row; } .field > :first-child { display: table-cell; width: 20%; } .field.single > :first-child { display: inline; } .field > :not(:first-child) { width: auto; max-width: 100%; display: inline-flex; align-items: baseline; virtical-align: top; box-sizing: border-box; margin: .3em; } .field > :not(:first-child) > input { width: 230px; } .form-footer { display: inline-flex; justify-content: flex-start; } .form-footer > * { margin: 1em; } .text-scrollable { overflow: auto; height: 150px; border: 1px solid rgb(200, 200, 200); padding: 5px; font-size: 1em; } .text-centered { text-align: center; } .text-container { margin: 1em 1.5em; } .flex-container { display: flex; } .flex-container.column { flex-direction: column; } </style> <title> Firewall Authentication </title> </head> <body> <div class="message-container"> <div class="logo"> </div> <h1> Autenticazione Richiesta </h1> <form action="/" method="post"> <input type="hidden" name="4Tredir" value="http://193.205.131.1:1000/fgtauth?0640846713cb9b3b"> <input type="hidden" name="magic" value="034bd4ca840e386c"> <input type="hidden" name="" value=""> <p> Inserisci le credenziali per accedere ad Internet </br> Se riscontri dei problemi contatta l'ufficio reti </br> <a href="mailto:ict.network@sm.univpm.it"> ict.network@sm.univpm.it </a> </p> <div class="field"> <label for="ft_un"> Username </label> <div> <input name="username" id="ft_un" type="text" autocorrect="off" autocapitalize="off"> </div> </div> <div class="field"> <label for="ft_pd"> Password </label> <div> <input name="password" id="ft_pd" type="password" autocomplete="off"> </div> </div> <div class="form-footer"> <button class="primary" type="submit"> Continue </button> </div> </form></div></body></html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:34:57.000Z",
         "app" : {
            "extract" : {
               "domain" : [
                  "googleapis.com"
               ],
               "hostname" : [
                  "fonts.googleapis.com"
               ],
               "ip" : [
                  "193.205.131.1"
               ],
               "url" : [
                  "http://193.205.131.1:1000/fgtauth?0640846713cb9b3b",
                  "https://fonts.googleapis.com/css?family=Roboto&display=swap"
               ]
            },
            "http" : {
               "bodymd5" : "5ac3a5b131bfebcf54a184950f30ee33",
               "bodymmh3" : 978500131,
               "headermd5" : "e2075400d0db00256ee037a5b80ae1f7",
               "headermmh3" : -923971862,
               "title" : "Firewall Authentication"
            },
            "length" : 3566
         },
         "asn" : "AS137",
         "city" : "Pavia",
         "country" : "IT",
         "data" : "HTTP/1.1 200 OK\r\nContent-Length: 3427\r\nConnection: close\r\nCache-Control: no-cache\r\nContent-Type: text/html\r\nX-Frame-Options: SAMEORIGIN\r\n\r\n<!DOCTYPE html><html lang=\"en\"> <head> <meta charset=\"UTF-8\"> <meta http-equiv=\"X-UA-Compatible\" content=\"IE=8; IE=EDGE\"> <meta name=\"viewport\" content=\"width=device-width, initial-scale=1\"> <link href=\"https://fonts.googleapis.com/css?family=Roboto&display=swap\" rel=\"stylesheet\"> <style type=\"text/css\"> body { height: 100%; font-family: Roboto, Helvetica, Arial, sans-serif; color: #6a6a6a; margin: 0; display: flex; align-items: center; justify-content: center; } input[type=date], input[type=email], input[type=number], input[type=password], input[type=search], input[type=tel], input[type=text], input[type=time], input[type=url], select, textarea { color: #262626; vertical-align: baseline; margin: .2em; border-style: solid; border-width: 1px; border-color: #a9a9a9; background-color: #fff; box-sizing: border-box; padding: 2px .5em; appearance: none; border-radius: 0; } input:focus { border-color: #646464; box-shadow: 0 0 1px 0 #a2a2a2; outline: 0; } button { padding: .5em 1em; border: 1px solid; border-radius: 3px; min-width: 6em; font-weight: 400; font-size: .8em; cursor: pointer; } button.primary { color: #fff; background-color: #c1092a; border-color: rgb(34, 103, 173); } .message-container { height: 500px; width: 600px; padding: 0; margin: 10px; } .logo { background: url(/XX/YY/ZZ/CI/MEPGHGPGPFFHOGJGGHAHNG) no-repeat left center; height: 267px; object-fit: contain; } table { background-color: #fff; border-spacing: 0; margin: 1em; } table > tbody > tr > td:first-of-type:not([colspan]) { white-space: nowrap; color: rgba(0,0,0,.5); } table > tbody > tr > td:first-of-type { vertical-align: top; } table > tbody > tr > td { padding: .3em .3em; } .field { display: table-row; } .field > :first-child { display: table-cell; width: 20%; } .field.single > :first-child { display: inline; } .field > :not(:first-child) { width: auto; max-width: 100%; display: inline-flex; align-items: baseline; virtical-align: top; box-sizing: border-box; margin: .3em; } .field > :not(:first-child) > input { width: 230px; } .form-footer { display: inline-flex; justify-content: flex-start; } .form-footer > * { margin: 1em; } .text-scrollable { overflow: auto; height: 150px; border: 1px solid rgb(200, 200, 200); padding: 5px; font-size: 1em; } .text-centered { text-align: center; } .text-container { margin: 1em 1.5em; } .flex-container { display: flex; } .flex-container.column { flex-direction: column; } </style> <title> Firewall Authentication </title> </head> <body> <div class=\"message-container\"> <div class=\"logo\"> </div> <h1> Autenticazione Richiesta </h1> <form action=\"/\" method=\"post\"> <input type=\"hidden\" name=\"4Tredir\" value=\"http://193.205.131.1:1000/fgtauth?0640846713cb9b3b\"> <input type=\"hidden\" name=\"magic\" value=\"034bd4ca840e386c\"> <input type=\"hidden\" name=\"\" value=\"\"> <p> Inserisci le credenziali per accedere ad Internet </br> Se riscontri dei problemi contatta l'ufficio reti </br> <a href=\"mailto:ict.network@sm.univpm.it\"> ict.network@sm.univpm.it </a> </p> <div class=\"field\"> <label for=\"ft_un\"> Username </label> <div> <input name=\"username\" id=\"ft_un\" type=\"text\" autocorrect=\"off\" autocapitalize=\"off\"> </div> </div> <div class=\"field\"> <label for=\"ft_pd\"> Password </label> <div> <input name=\"password\" id=\"ft_pd\" type=\"password\" autocomplete=\"off\"> </div> </div> <div class=\"form-footer\"> <button class=\"primary\" type=\"submit\"> Continue </button> </div> </form></div></body></html>\r\n",
         "datamd5" : "54f805b5cb1ca97c1591aeb3378a80a3",
         "datammh3" : -221076367,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "forward" : "193.205.131.1",
         "geolocus" : {
            "asn" : "AS137",
            "continent" : "EU",
            "continentname" : "Europe",
            "country" : "IT",
            "countryname" : "Italy",
            "domain" : [
               "garr.it",
               "uniurb.it"
            ],
            "isineu" : "true",
            "latitude" : "41.87194",
            "location" : "41.87194,12.56738",
            "longitude" : "12.56738",
            "netname" : "UNI-URB07",
            "organization" : "Universita' degli Studi di Urbino Carlo Bo",
            "subnet" : "90.147.0.0/18"
         },
         "hostname" : [
            "193.205.131.1"
         ],
         "ip" : "90.147.47.93",
         "ipv6" : "false",
         "latitude" : "45.1976",
         "location" : "45.1976,9.1578",
         "longitude" : "9.1578",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "Consortium GARR",
         "port" : 1000,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "OK",
         "seen_date" : "2024-11-07",
         "source" : "urlscan::redirect",
         "status" : 200,
         "subnet" : "90.147.0.0/16",
         "tag" : "<enterprise field>: tag",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/fgtauth?0640846713cb9b3b"
      }
      
  • 137.63.70.242:1000 (tcp/http) - last seen on 2024-11-07 at 05:34:57 UTC

    • IP
      137.63.70.242
      Network
      137.63.70.0/24
      Domain(s)
      sunnyvisit.com
      Device

      <enterprise field>: device.class

      URL

      http://38.122.68.226:1000/fgtauth?04011468af38104c 200

      HTTP Title
      Firewall Authentication
      Reverse DNS
      invoice.sunnyvisit.com
      ASN
      AS32489
      Organization
      AMANAHA-NEW
      Protocol
      http
      Source
      urlscan::redirect
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      c58253e58b89d2956db3b6575a0b8042
      HTTP Header MD5
      e2075400d0db00256ee037a5b80ae1f7
      HTTP Body MD5
      bfd6813115942cbf95b5e50e758fa96a
    • HTTP/1.1 200 OK
      Content-Length: 3377
      Connection: close
      Cache-Control: no-cache
      Content-Type: text/html
      X-Frame-Options: SAMEORIGIN
      
      <!DOCTYPE html><html lang="en"> <head> <meta charset="UTF-8"> <meta http-equiv="X-UA-Compatible" content="IE=8; IE=EDGE"> <meta name="viewport" content="width=device-width, initial-scale=1"> <link href="https://fonts.googleapis.com/css?family=Roboto&display=swap" rel="stylesheet"> <style type="text/css"> body { height: 100%; font-family: Roboto, Helvetica, Arial, sans-serif; color: #6a6a6a; margin: 0; display: flex; align-items: center; justify-content: center; } input[type=date], input[type=email], input[type=number], input[type=password], input[type=search], input[type=tel], input[type=text], input[type=time], input[type=url], select, textarea { color: #262626; vertical-align: baseline; margin: .2em; border-style: solid; border-width: 1px; border-color: #a9a9a9; background-color: #fff; box-sizing: border-box; padding: 2px .5em; appearance: none; border-radius: 0; } input:focus { border-color: #646464; box-shadow: 0 0 1px 0 #a2a2a2; outline: 0; } button { padding: .5em 1em; border: 1px solid; border-radius: 3px; min-width: 6em; font-weight: 400; font-size: .8em; cursor: pointer; } button.primary { color: #fff; background-color: rgb(47, 113, 178); border-color: rgb(34, 103, 173); } .message-container { height: 500px; width: 600px; padding: 0; margin: 10px; } .logo { background: url(/XX/YY/ZZ/CI/BGNGMGPGHGPG) no-repeat left center; height: 267px; object-fit: contain; } table { background-color: #fff; border-spacing: 0; margin: 1em; } table > tbody > tr > td:first-of-type:not([colspan]) { white-space: nowrap; color: rgba(0,0,0,.5); } table > tbody > tr > td:first-of-type { vertical-align: top; } table > tbody > tr > td { padding: .3em .3em; } .field { display: table-row; } .field > :first-child { display: table-cell; width: 20%; } .field.single > :first-child { display: inline; } .field > :not(:first-child) { width: auto; max-width: 100%; display: inline-flex; align-items: baseline; virtical-align: top; box-sizing: border-box; margin: .3em; } .field > :not(:first-child) > input { width: 230px; } .form-footer { display: inline-flex; justify-content: flex-start; } .form-footer > * { margin: 1em; } .text-scrollable { overflow: auto; height: 150px; border: 1px solid rgb(200, 200, 200); padding: 5px; font-size: 1em; } .text-centered { text-align: center; } .text-container { margin: 1em 1.5em; } .flex-container { display: flex; } .flex-container.column { flex-direction: column; } </style> <title> Firewall Authentication </title> </head> <body> <div class="message-container"> <div class="logo"> </div> <h1> <b> Remote Console Access </b> </h1> <h2> Authentication Required </h2> <form action="/" method="post"> <input type="hidden" name="4Tredir" value="http://38.122.68.226:1000/fgtauth?04011468af38104c"> <input type="hidden" name="magic" value="01071b7e1476d55e"> <input type="hidden" name="" value=""> <p> Please enter your username and password to continue. </p> <div class="field"> <label for="ft_un"> Username </label> <div> <input name="username" id="ft_un" type="text" autocorrect="off" autocapitalize="off"> </div> </div> <div class="field"> <label for="ft_pd"> Password </label> <div> <input name="password" id="ft_pd" type="password" autocomplete="off"> </div> </div> <div class="form-footer"> <button class="primary" type="submit"> Continue </button> </div> </form> Please contact support for any issues. </div> </body></html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:34:57.000Z",
         "app" : {
            "extract" : {
               "domain" : [
                  "googleapis.com"
               ],
               "hostname" : [
                  "fonts.googleapis.com"
               ],
               "ip" : [
                  "38.122.68.226"
               ],
               "url" : [
                  "http://38.122.68.226:1000/fgtauth?04011468af38104c",
                  "https://fonts.googleapis.com/css?family=Roboto&display=swap"
               ]
            },
            "http" : {
               "bodymd5" : "bfd6813115942cbf95b5e50e758fa96a",
               "bodymmh3" : 1578310904,
               "headermd5" : "e2075400d0db00256ee037a5b80ae1f7",
               "headermmh3" : -1448931244,
               "title" : "Firewall Authentication"
            },
            "length" : 3516
         },
         "asn" : "AS32489",
         "country" : "SC",
         "data" : "HTTP/1.1 200 OK\r\nContent-Length: 3377\r\nConnection: close\r\nCache-Control: no-cache\r\nContent-Type: text/html\r\nX-Frame-Options: SAMEORIGIN\r\n\r\n<!DOCTYPE html><html lang=\"en\"> <head> <meta charset=\"UTF-8\"> <meta http-equiv=\"X-UA-Compatible\" content=\"IE=8; IE=EDGE\"> <meta name=\"viewport\" content=\"width=device-width, initial-scale=1\"> <link href=\"https://fonts.googleapis.com/css?family=Roboto&display=swap\" rel=\"stylesheet\"> <style type=\"text/css\"> body { height: 100%; font-family: Roboto, Helvetica, Arial, sans-serif; color: #6a6a6a; margin: 0; display: flex; align-items: center; justify-content: center; } input[type=date], input[type=email], input[type=number], input[type=password], input[type=search], input[type=tel], input[type=text], input[type=time], input[type=url], select, textarea { color: #262626; vertical-align: baseline; margin: .2em; border-style: solid; border-width: 1px; border-color: #a9a9a9; background-color: #fff; box-sizing: border-box; padding: 2px .5em; appearance: none; border-radius: 0; } input:focus { border-color: #646464; box-shadow: 0 0 1px 0 #a2a2a2; outline: 0; } button { padding: .5em 1em; border: 1px solid; border-radius: 3px; min-width: 6em; font-weight: 400; font-size: .8em; cursor: pointer; } button.primary { color: #fff; background-color: rgb(47, 113, 178); border-color: rgb(34, 103, 173); } .message-container { height: 500px; width: 600px; padding: 0; margin: 10px; } .logo { background: url(/XX/YY/ZZ/CI/BGNGMGPGHGPG) no-repeat left center; height: 267px; object-fit: contain; } table { background-color: #fff; border-spacing: 0; margin: 1em; } table > tbody > tr > td:first-of-type:not([colspan]) { white-space: nowrap; color: rgba(0,0,0,.5); } table > tbody > tr > td:first-of-type { vertical-align: top; } table > tbody > tr > td { padding: .3em .3em; } .field { display: table-row; } .field > :first-child { display: table-cell; width: 20%; } .field.single > :first-child { display: inline; } .field > :not(:first-child) { width: auto; max-width: 100%; display: inline-flex; align-items: baseline; virtical-align: top; box-sizing: border-box; margin: .3em; } .field > :not(:first-child) > input { width: 230px; } .form-footer { display: inline-flex; justify-content: flex-start; } .form-footer > * { margin: 1em; } .text-scrollable { overflow: auto; height: 150px; border: 1px solid rgb(200, 200, 200); padding: 5px; font-size: 1em; } .text-centered { text-align: center; } .text-container { margin: 1em 1.5em; } .flex-container { display: flex; } .flex-container.column { flex-direction: column; } </style> <title> Firewall Authentication </title> </head> <body> <div class=\"message-container\"> <div class=\"logo\"> </div> <h1> <b> Remote Console Access </b> </h1> <h2> Authentication Required </h2> <form action=\"/\" method=\"post\"> <input type=\"hidden\" name=\"4Tredir\" value=\"http://38.122.68.226:1000/fgtauth?04011468af38104c\"> <input type=\"hidden\" name=\"magic\" value=\"01071b7e1476d55e\"> <input type=\"hidden\" name=\"\" value=\"\"> <p> Please enter your username and password to continue. </p> <div class=\"field\"> <label for=\"ft_un\"> Username </label> <div> <input name=\"username\" id=\"ft_un\" type=\"text\" autocorrect=\"off\" autocapitalize=\"off\"> </div> </div> <div class=\"field\"> <label for=\"ft_pd\"> Password </label> <div> <input name=\"password\" id=\"ft_pd\" type=\"password\" autocomplete=\"off\"> </div> </div> <div class=\"form-footer\"> <button class=\"primary\" type=\"submit\"> Continue </button> </div> </form> Please contact support for any issues. </div> </body></html>\r\n",
         "datamd5" : "c58253e58b89d2956db3b6575a0b8042",
         "datammh3" : 798979027,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "sunnyvisit.com"
         ],
         "forward" : "38.122.68.226",
         "geolocus" : {
            "asn" : "AS32489",
            "continent" : "AF",
            "continentname" : "Africa",
            "country" : "SC",
            "countryname" : "Seychelles",
            "isineu" : "false",
            "latitude" : "-4.679574",
            "location" : "-4.679574,55.491977",
            "longitude" : "55.491977",
            "netname" : "AFRITEL-NET",
            "organization" : "Afritel Network",
            "subnet" : "137.63.68.0/22"
         },
         "host" : [
            "invoice"
         ],
         "hostname" : [
            "38.122.68.226",
            "invoice.sunnyvisit.com"
         ],
         "ip" : "137.63.70.242",
         "ipv6" : "false",
         "latitude" : "-4.5833",
         "location" : "-4.5833,55.6667",
         "longitude" : "55.6667",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "AMANAHA-NEW",
         "port" : 1000,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "OK",
         "reverse" : [
            "invoice.sunnyvisit.com"
         ],
         "seen_date" : "2024-11-07",
         "source" : "urlscan::redirect",
         "status" : 200,
         "subnet" : "137.63.70.0/24",
         "tag" : "<enterprise field>: tag",
         "tld" : [
            "com"
         ],
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/fgtauth?04011468af38104c"
      }
      
  • 184.75.219.229:1000 (tcp/http) - last seen on 2024-11-07 at 05:34:57 UTC

    • IP
      184.75.219.229
      Network
      184.75.219.0/24
      Domain(s)
      amanah.com
      Device

      <enterprise field>: device.class

      URL

      http://38.122.68.226:1000/fgtauth?060b1d6286d9e372 200

      HTTP Title
      Firewall Authentication
      Reverse DNS
      184-75-219-229.amanah.com
      ASN
      AS32489
      Organization
      AMANAHA-NEW
      Protocol
      http
      Source
      urlscan::redirect
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      0b4249af40fcb156bf1f149d981ac43e
      HTTP Header MD5
      e2075400d0db00256ee037a5b80ae1f7
      HTTP Body MD5
      bfd6813115942cbf95b5e50e758fa96a
    • HTTP/1.1 200 OK
      Content-Length: 3377
      Connection: close
      Cache-Control: no-cache
      Content-Type: text/html
      X-Frame-Options: SAMEORIGIN
      
      <!DOCTYPE html><html lang="en"> <head> <meta charset="UTF-8"> <meta http-equiv="X-UA-Compatible" content="IE=8; IE=EDGE"> <meta name="viewport" content="width=device-width, initial-scale=1"> <link href="https://fonts.googleapis.com/css?family=Roboto&display=swap" rel="stylesheet"> <style type="text/css"> body { height: 100%; font-family: Roboto, Helvetica, Arial, sans-serif; color: #6a6a6a; margin: 0; display: flex; align-items: center; justify-content: center; } input[type=date], input[type=email], input[type=number], input[type=password], input[type=search], input[type=tel], input[type=text], input[type=time], input[type=url], select, textarea { color: #262626; vertical-align: baseline; margin: .2em; border-style: solid; border-width: 1px; border-color: #a9a9a9; background-color: #fff; box-sizing: border-box; padding: 2px .5em; appearance: none; border-radius: 0; } input:focus { border-color: #646464; box-shadow: 0 0 1px 0 #a2a2a2; outline: 0; } button { padding: .5em 1em; border: 1px solid; border-radius: 3px; min-width: 6em; font-weight: 400; font-size: .8em; cursor: pointer; } button.primary { color: #fff; background-color: rgb(47, 113, 178); border-color: rgb(34, 103, 173); } .message-container { height: 500px; width: 600px; padding: 0; margin: 10px; } .logo { background: url(/XX/YY/ZZ/CI/BGNGMGPGHGPG) no-repeat left center; height: 267px; object-fit: contain; } table { background-color: #fff; border-spacing: 0; margin: 1em; } table > tbody > tr > td:first-of-type:not([colspan]) { white-space: nowrap; color: rgba(0,0,0,.5); } table > tbody > tr > td:first-of-type { vertical-align: top; } table > tbody > tr > td { padding: .3em .3em; } .field { display: table-row; } .field > :first-child { display: table-cell; width: 20%; } .field.single > :first-child { display: inline; } .field > :not(:first-child) { width: auto; max-width: 100%; display: inline-flex; align-items: baseline; virtical-align: top; box-sizing: border-box; margin: .3em; } .field > :not(:first-child) > input { width: 230px; } .form-footer { display: inline-flex; justify-content: flex-start; } .form-footer > * { margin: 1em; } .text-scrollable { overflow: auto; height: 150px; border: 1px solid rgb(200, 200, 200); padding: 5px; font-size: 1em; } .text-centered { text-align: center; } .text-container { margin: 1em 1.5em; } .flex-container { display: flex; } .flex-container.column { flex-direction: column; } </style> <title> Firewall Authentication </title> </head> <body> <div class="message-container"> <div class="logo"> </div> <h1> <b> Remote Console Access </b> </h1> <h2> Authentication Required </h2> <form action="/" method="post"> <input type="hidden" name="4Tredir" value="http://38.122.68.226:1000/fgtauth?060b1d6286d9e372"> <input type="hidden" name="magic" value="02051576187cd284"> <input type="hidden" name="" value=""> <p> Please enter your username and password to continue. </p> <div class="field"> <label for="ft_un"> Username </label> <div> <input name="username" id="ft_un" type="text" autocorrect="off" autocapitalize="off"> </div> </div> <div class="field"> <label for="ft_pd"> Password </label> <div> <input name="password" id="ft_pd" type="password" autocomplete="off"> </div> </div> <div class="form-footer"> <button class="primary" type="submit"> Continue </button> </div> </form> Please contact support for any issues. </div> </body></html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:34:57.000Z",
         "app" : {
            "extract" : {
               "domain" : [
                  "googleapis.com"
               ],
               "hostname" : [
                  "fonts.googleapis.com"
               ],
               "ip" : [
                  "38.122.68.226"
               ],
               "url" : [
                  "http://38.122.68.226:1000/fgtauth?060b1d6286d9e372",
                  "https://fonts.googleapis.com/css?family=Roboto&display=swap"
               ]
            },
            "http" : {
               "bodymd5" : "bfd6813115942cbf95b5e50e758fa96a",
               "bodymmh3" : 1758469126,
               "headermd5" : "e2075400d0db00256ee037a5b80ae1f7",
               "headermmh3" : -1448931244,
               "title" : "Firewall Authentication"
            },
            "length" : 3516
         },
         "asn" : "AS32489",
         "city" : "Whitby",
         "country" : "CA",
         "data" : "HTTP/1.1 200 OK\r\nContent-Length: 3377\r\nConnection: close\r\nCache-Control: no-cache\r\nContent-Type: text/html\r\nX-Frame-Options: SAMEORIGIN\r\n\r\n<!DOCTYPE html><html lang=\"en\"> <head> <meta charset=\"UTF-8\"> <meta http-equiv=\"X-UA-Compatible\" content=\"IE=8; IE=EDGE\"> <meta name=\"viewport\" content=\"width=device-width, initial-scale=1\"> <link href=\"https://fonts.googleapis.com/css?family=Roboto&display=swap\" rel=\"stylesheet\"> <style type=\"text/css\"> body { height: 100%; font-family: Roboto, Helvetica, Arial, sans-serif; color: #6a6a6a; margin: 0; display: flex; align-items: center; justify-content: center; } input[type=date], input[type=email], input[type=number], input[type=password], input[type=search], input[type=tel], input[type=text], input[type=time], input[type=url], select, textarea { color: #262626; vertical-align: baseline; margin: .2em; border-style: solid; border-width: 1px; border-color: #a9a9a9; background-color: #fff; box-sizing: border-box; padding: 2px .5em; appearance: none; border-radius: 0; } input:focus { border-color: #646464; box-shadow: 0 0 1px 0 #a2a2a2; outline: 0; } button { padding: .5em 1em; border: 1px solid; border-radius: 3px; min-width: 6em; font-weight: 400; font-size: .8em; cursor: pointer; } button.primary { color: #fff; background-color: rgb(47, 113, 178); border-color: rgb(34, 103, 173); } .message-container { height: 500px; width: 600px; padding: 0; margin: 10px; } .logo { background: url(/XX/YY/ZZ/CI/BGNGMGPGHGPG) no-repeat left center; height: 267px; object-fit: contain; } table { background-color: #fff; border-spacing: 0; margin: 1em; } table > tbody > tr > td:first-of-type:not([colspan]) { white-space: nowrap; color: rgba(0,0,0,.5); } table > tbody > tr > td:first-of-type { vertical-align: top; } table > tbody > tr > td { padding: .3em .3em; } .field { display: table-row; } .field > :first-child { display: table-cell; width: 20%; } .field.single > :first-child { display: inline; } .field > :not(:first-child) { width: auto; max-width: 100%; display: inline-flex; align-items: baseline; virtical-align: top; box-sizing: border-box; margin: .3em; } .field > :not(:first-child) > input { width: 230px; } .form-footer { display: inline-flex; justify-content: flex-start; } .form-footer > * { margin: 1em; } .text-scrollable { overflow: auto; height: 150px; border: 1px solid rgb(200, 200, 200); padding: 5px; font-size: 1em; } .text-centered { text-align: center; } .text-container { margin: 1em 1.5em; } .flex-container { display: flex; } .flex-container.column { flex-direction: column; } </style> <title> Firewall Authentication </title> </head> <body> <div class=\"message-container\"> <div class=\"logo\"> </div> <h1> <b> Remote Console Access </b> </h1> <h2> Authentication Required </h2> <form action=\"/\" method=\"post\"> <input type=\"hidden\" name=\"4Tredir\" value=\"http://38.122.68.226:1000/fgtauth?060b1d6286d9e372\"> <input type=\"hidden\" name=\"magic\" value=\"02051576187cd284\"> <input type=\"hidden\" name=\"\" value=\"\"> <p> Please enter your username and password to continue. </p> <div class=\"field\"> <label for=\"ft_un\"> Username </label> <div> <input name=\"username\" id=\"ft_un\" type=\"text\" autocorrect=\"off\" autocapitalize=\"off\"> </div> </div> <div class=\"field\"> <label for=\"ft_pd\"> Password </label> <div> <input name=\"password\" id=\"ft_pd\" type=\"password\" autocomplete=\"off\"> </div> </div> <div class=\"form-footer\"> <button class=\"primary\" type=\"submit\"> Continue </button> </div> </form> Please contact support for any issues. </div> </body></html>\r\n",
         "datamd5" : "0b4249af40fcb156bf1f149d981ac43e",
         "datammh3" : 1549612081,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "amanah.com"
         ],
         "forward" : "38.122.68.226",
         "geolocus" : {
            "asn" : "AS32489",
            "continent" : "NA",
            "continentname" : "North America",
            "country" : "CA",
            "countryname" : "Canada",
            "domain" : [
               "amanah.com"
            ],
            "isineu" : "false",
            "latitude" : "56.130366",
            "location" : "56.130366,-106.346771",
            "longitude" : "-106.346771",
            "netname" : "AMS4-NTBLK2",
            "organization" : "Amanah Tech Inc.",
            "subnet" : "184.75.219.0/24"
         },
         "host" : [
            "184-75-219-229"
         ],
         "hostname" : [
            "184-75-219-229.amanah.com",
            "38.122.68.226"
         ],
         "ip" : "184.75.219.229",
         "ipv6" : "false",
         "latitude" : "43.9228",
         "location" : "43.9228,-78.9412",
         "longitude" : "-78.9412",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "AMANAHA-NEW",
         "port" : 1000,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "OK",
         "reverse" : [
            "184-75-219-229.amanah.com"
         ],
         "seen_date" : "2024-11-07",
         "source" : "urlscan::redirect",
         "status" : 200,
         "subnet" : "184.75.219.0/24",
         "tag" : "<enterprise field>: tag",
         "tld" : [
            "com"
         ],
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/fgtauth?060b1d6286d9e372"
      }
      
  • 193.205.132.252:1000 (tcp/http) - last seen on 2024-11-07 at 05:34:57 UTC

    • IP
      193.205.132.252
      Network
      193.204.0.0/15
      Device

      <enterprise field>: device.class

      URL

      http://193.205.131.1:1000/fgtauth?04408a6a8855b11b 200

      HTTP Title
      Firewall Authentication
      ASN
      AS137
      Organization
      Consortium GARR
      Protocol
      http
      Source
      urlscan::redirect
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      876facb88f05fbbe7d652e93bd02f5be
      HTTP Header MD5
      e2075400d0db00256ee037a5b80ae1f7
      HTTP Body MD5
      5ac3a5b131bfebcf54a184950f30ee33
    • HTTP/1.1 200 OK
      Content-Length: 3427
      Connection: close
      Cache-Control: no-cache
      Content-Type: text/html
      X-Frame-Options: SAMEORIGIN
      
      <!DOCTYPE html><html lang="en"> <head> <meta charset="UTF-8"> <meta http-equiv="X-UA-Compatible" content="IE=8; IE=EDGE"> <meta name="viewport" content="width=device-width, initial-scale=1"> <link href="https://fonts.googleapis.com/css?family=Roboto&display=swap" rel="stylesheet"> <style type="text/css"> body { height: 100%; font-family: Roboto, Helvetica, Arial, sans-serif; color: #6a6a6a; margin: 0; display: flex; align-items: center; justify-content: center; } input[type=date], input[type=email], input[type=number], input[type=password], input[type=search], input[type=tel], input[type=text], input[type=time], input[type=url], select, textarea { color: #262626; vertical-align: baseline; margin: .2em; border-style: solid; border-width: 1px; border-color: #a9a9a9; background-color: #fff; box-sizing: border-box; padding: 2px .5em; appearance: none; border-radius: 0; } input:focus { border-color: #646464; box-shadow: 0 0 1px 0 #a2a2a2; outline: 0; } button { padding: .5em 1em; border: 1px solid; border-radius: 3px; min-width: 6em; font-weight: 400; font-size: .8em; cursor: pointer; } button.primary { color: #fff; background-color: #c1092a; border-color: rgb(34, 103, 173); } .message-container { height: 500px; width: 600px; padding: 0; margin: 10px; } .logo { background: url(/XX/YY/ZZ/CI/MEPGHGPGPFFHOGJGGHAHNG) no-repeat left center; height: 267px; object-fit: contain; } table { background-color: #fff; border-spacing: 0; margin: 1em; } table > tbody > tr > td:first-of-type:not([colspan]) { white-space: nowrap; color: rgba(0,0,0,.5); } table > tbody > tr > td:first-of-type { vertical-align: top; } table > tbody > tr > td { padding: .3em .3em; } .field { display: table-row; } .field > :first-child { display: table-cell; width: 20%; } .field.single > :first-child { display: inline; } .field > :not(:first-child) { width: auto; max-width: 100%; display: inline-flex; align-items: baseline; virtical-align: top; box-sizing: border-box; margin: .3em; } .field > :not(:first-child) > input { width: 230px; } .form-footer { display: inline-flex; justify-content: flex-start; } .form-footer > * { margin: 1em; } .text-scrollable { overflow: auto; height: 150px; border: 1px solid rgb(200, 200, 200); padding: 5px; font-size: 1em; } .text-centered { text-align: center; } .text-container { margin: 1em 1.5em; } .flex-container { display: flex; } .flex-container.column { flex-direction: column; } </style> <title> Firewall Authentication </title> </head> <body> <div class="message-container"> <div class="logo"> </div> <h1> Autenticazione Richiesta </h1> <form action="/" method="post"> <input type="hidden" name="4Tredir" value="http://193.205.131.1:1000/fgtauth?04408a6a8855b11b"> <input type="hidden" name="magic" value="0344f89a6126c327"> <input type="hidden" name="" value=""> <p> Inserisci le credenziali per accedere ad Internet </br> Se riscontri dei problemi contatta l'ufficio reti </br> <a href="mailto:ict.network@sm.univpm.it"> ict.network@sm.univpm.it </a> </p> <div class="field"> <label for="ft_un"> Username </label> <div> <input name="username" id="ft_un" type="text" autocorrect="off" autocapitalize="off"> </div> </div> <div class="field"> <label for="ft_pd"> Password </label> <div> <input name="password" id="ft_pd" type="password" autocomplete="off"> </div> </div> <div class="form-footer"> <button class="primary" type="submit"> Continue </button> </div> </form></div></body></html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:34:57.000Z",
         "app" : {
            "extract" : {
               "domain" : [
                  "googleapis.com"
               ],
               "hostname" : [
                  "fonts.googleapis.com"
               ],
               "ip" : [
                  "193.205.131.1"
               ],
               "url" : [
                  "http://193.205.131.1:1000/fgtauth?04408a6a8855b11b",
                  "https://fonts.googleapis.com/css?family=Roboto&display=swap"
               ]
            },
            "http" : {
               "bodymd5" : "5ac3a5b131bfebcf54a184950f30ee33",
               "bodymmh3" : 908132976,
               "headermd5" : "e2075400d0db00256ee037a5b80ae1f7",
               "headermmh3" : -923971862,
               "title" : "Firewall Authentication"
            },
            "length" : 3566
         },
         "asn" : "AS137",
         "city" : "Ancona",
         "country" : "IT",
         "data" : "HTTP/1.1 200 OK\r\nContent-Length: 3427\r\nConnection: close\r\nCache-Control: no-cache\r\nContent-Type: text/html\r\nX-Frame-Options: SAMEORIGIN\r\n\r\n<!DOCTYPE html><html lang=\"en\"> <head> <meta charset=\"UTF-8\"> <meta http-equiv=\"X-UA-Compatible\" content=\"IE=8; IE=EDGE\"> <meta name=\"viewport\" content=\"width=device-width, initial-scale=1\"> <link href=\"https://fonts.googleapis.com/css?family=Roboto&display=swap\" rel=\"stylesheet\"> <style type=\"text/css\"> body { height: 100%; font-family: Roboto, Helvetica, Arial, sans-serif; color: #6a6a6a; margin: 0; display: flex; align-items: center; justify-content: center; } input[type=date], input[type=email], input[type=number], input[type=password], input[type=search], input[type=tel], input[type=text], input[type=time], input[type=url], select, textarea { color: #262626; vertical-align: baseline; margin: .2em; border-style: solid; border-width: 1px; border-color: #a9a9a9; background-color: #fff; box-sizing: border-box; padding: 2px .5em; appearance: none; border-radius: 0; } input:focus { border-color: #646464; box-shadow: 0 0 1px 0 #a2a2a2; outline: 0; } button { padding: .5em 1em; border: 1px solid; border-radius: 3px; min-width: 6em; font-weight: 400; font-size: .8em; cursor: pointer; } button.primary { color: #fff; background-color: #c1092a; border-color: rgb(34, 103, 173); } .message-container { height: 500px; width: 600px; padding: 0; margin: 10px; } .logo { background: url(/XX/YY/ZZ/CI/MEPGHGPGPFFHOGJGGHAHNG) no-repeat left center; height: 267px; object-fit: contain; } table { background-color: #fff; border-spacing: 0; margin: 1em; } table > tbody > tr > td:first-of-type:not([colspan]) { white-space: nowrap; color: rgba(0,0,0,.5); } table > tbody > tr > td:first-of-type { vertical-align: top; } table > tbody > tr > td { padding: .3em .3em; } .field { display: table-row; } .field > :first-child { display: table-cell; width: 20%; } .field.single > :first-child { display: inline; } .field > :not(:first-child) { width: auto; max-width: 100%; display: inline-flex; align-items: baseline; virtical-align: top; box-sizing: border-box; margin: .3em; } .field > :not(:first-child) > input { width: 230px; } .form-footer { display: inline-flex; justify-content: flex-start; } .form-footer > * { margin: 1em; } .text-scrollable { overflow: auto; height: 150px; border: 1px solid rgb(200, 200, 200); padding: 5px; font-size: 1em; } .text-centered { text-align: center; } .text-container { margin: 1em 1.5em; } .flex-container { display: flex; } .flex-container.column { flex-direction: column; } </style> <title> Firewall Authentication </title> </head> <body> <div class=\"message-container\"> <div class=\"logo\"> </div> <h1> Autenticazione Richiesta </h1> <form action=\"/\" method=\"post\"> <input type=\"hidden\" name=\"4Tredir\" value=\"http://193.205.131.1:1000/fgtauth?04408a6a8855b11b\"> <input type=\"hidden\" name=\"magic\" value=\"0344f89a6126c327\"> <input type=\"hidden\" name=\"\" value=\"\"> <p> Inserisci le credenziali per accedere ad Internet </br> Se riscontri dei problemi contatta l'ufficio reti </br> <a href=\"mailto:ict.network@sm.univpm.it\"> ict.network@sm.univpm.it </a> </p> <div class=\"field\"> <label for=\"ft_un\"> Username </label> <div> <input name=\"username\" id=\"ft_un\" type=\"text\" autocorrect=\"off\" autocapitalize=\"off\"> </div> </div> <div class=\"field\"> <label for=\"ft_pd\"> Password </label> <div> <input name=\"password\" id=\"ft_pd\" type=\"password\" autocomplete=\"off\"> </div> </div> <div class=\"form-footer\"> <button class=\"primary\" type=\"submit\"> Continue </button> </div> </form></div></body></html>\r\n",
         "datamd5" : "876facb88f05fbbe7d652e93bd02f5be",
         "datammh3" : -533315945,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "forward" : "193.205.131.1",
         "geolocus" : {
            "asn" : "AS137",
            "continent" : "EU",
            "continentname" : "Europe",
            "country" : "IT",
            "countryname" : "Italy",
            "domain" : [
               "garr.it",
               "univpm.it"
            ],
            "isineu" : "true",
            "latitude" : "41.87194",
            "location" : "41.87194,12.56738",
            "longitude" : "12.56738",
            "netname" : "ANCONA-NET",
            "organization" : "Universita' Politecnica delle Marche",
            "subnet" : "193.205.128.0/18"
         },
         "hostname" : [
            "193.205.131.1"
         ],
         "ip" : "193.205.132.252",
         "ipv6" : "false",
         "latitude" : "43.5939",
         "location" : "43.5939,13.5086",
         "longitude" : "13.5086",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "Consortium GARR",
         "port" : 1000,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "OK",
         "seen_date" : "2024-11-07",
         "source" : "urlscan::redirect",
         "status" : 200,
         "subnet" : "193.204.0.0/15",
         "tag" : "<enterprise field>: tag",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/fgtauth?04408a6a8855b11b"
      }
      
  • 137.63.75.93:1000 (tcp/http) - last seen on 2024-11-07 at 05:34:57 UTC

    • IP
      137.63.75.93
      Network
      137.63.75.0/24
      Domain(s)
      keyrist.com
      Device

      <enterprise field>: device.class

      URL

      http://38.122.68.226:1000/fgtauth?000f154b71af04b1 200

      HTTP Title
      Firewall Authentication
      Reverse DNS
      keyrist.com
      ASN
      AS32489
      Organization
      AMANAHA-NEW
      Protocol
      http
      Source
      urlscan::redirect
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      0ff5f2b40e61866545c6f936c90596e7
      HTTP Header MD5
      e2075400d0db00256ee037a5b80ae1f7
      HTTP Body MD5
      bfd6813115942cbf95b5e50e758fa96a
    • HTTP/1.1 200 OK
      Content-Length: 3377
      Connection: close
      Cache-Control: no-cache
      Content-Type: text/html
      X-Frame-Options: SAMEORIGIN
      
      <!DOCTYPE html><html lang="en"> <head> <meta charset="UTF-8"> <meta http-equiv="X-UA-Compatible" content="IE=8; IE=EDGE"> <meta name="viewport" content="width=device-width, initial-scale=1"> <link href="https://fonts.googleapis.com/css?family=Roboto&display=swap" rel="stylesheet"> <style type="text/css"> body { height: 100%; font-family: Roboto, Helvetica, Arial, sans-serif; color: #6a6a6a; margin: 0; display: flex; align-items: center; justify-content: center; } input[type=date], input[type=email], input[type=number], input[type=password], input[type=search], input[type=tel], input[type=text], input[type=time], input[type=url], select, textarea { color: #262626; vertical-align: baseline; margin: .2em; border-style: solid; border-width: 1px; border-color: #a9a9a9; background-color: #fff; box-sizing: border-box; padding: 2px .5em; appearance: none; border-radius: 0; } input:focus { border-color: #646464; box-shadow: 0 0 1px 0 #a2a2a2; outline: 0; } button { padding: .5em 1em; border: 1px solid; border-radius: 3px; min-width: 6em; font-weight: 400; font-size: .8em; cursor: pointer; } button.primary { color: #fff; background-color: rgb(47, 113, 178); border-color: rgb(34, 103, 173); } .message-container { height: 500px; width: 600px; padding: 0; margin: 10px; } .logo { background: url(/XX/YY/ZZ/CI/BGNGMGPGHGPG) no-repeat left center; height: 267px; object-fit: contain; } table { background-color: #fff; border-spacing: 0; margin: 1em; } table > tbody > tr > td:first-of-type:not([colspan]) { white-space: nowrap; color: rgba(0,0,0,.5); } table > tbody > tr > td:first-of-type { vertical-align: top; } table > tbody > tr > td { padding: .3em .3em; } .field { display: table-row; } .field > :first-child { display: table-cell; width: 20%; } .field.single > :first-child { display: inline; } .field > :not(:first-child) { width: auto; max-width: 100%; display: inline-flex; align-items: baseline; virtical-align: top; box-sizing: border-box; margin: .3em; } .field > :not(:first-child) > input { width: 230px; } .form-footer { display: inline-flex; justify-content: flex-start; } .form-footer > * { margin: 1em; } .text-scrollable { overflow: auto; height: 150px; border: 1px solid rgb(200, 200, 200); padding: 5px; font-size: 1em; } .text-centered { text-align: center; } .text-container { margin: 1em 1.5em; } .flex-container { display: flex; } .flex-container.column { flex-direction: column; } </style> <title> Firewall Authentication </title> </head> <body> <div class="message-container"> <div class="logo"> </div> <h1> <b> Remote Console Access </b> </h1> <h2> Authentication Required </h2> <form action="/" method="post"> <input type="hidden" name="4Tredir" value="http://38.122.68.226:1000/fgtauth?000f154b71af04b1"> <input type="hidden" name="magic" value="030c1e7b1373d9bc"> <input type="hidden" name="" value=""> <p> Please enter your username and password to continue. </p> <div class="field"> <label for="ft_un"> Username </label> <div> <input name="username" id="ft_un" type="text" autocorrect="off" autocapitalize="off"> </div> </div> <div class="field"> <label for="ft_pd"> Password </label> <div> <input name="password" id="ft_pd" type="password" autocomplete="off"> </div> </div> <div class="form-footer"> <button class="primary" type="submit"> Continue </button> </div> </form> Please contact support for any issues. </div> </body></html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:34:57.000Z",
         "app" : {
            "extract" : {
               "domain" : [
                  "googleapis.com"
               ],
               "hostname" : [
                  "fonts.googleapis.com"
               ],
               "ip" : [
                  "38.122.68.226"
               ],
               "url" : [
                  "http://38.122.68.226:1000/fgtauth?000f154b71af04b1",
                  "https://fonts.googleapis.com/css?family=Roboto&display=swap"
               ]
            },
            "http" : {
               "bodymd5" : "bfd6813115942cbf95b5e50e758fa96a",
               "bodymmh3" : -1707834746,
               "headermd5" : "e2075400d0db00256ee037a5b80ae1f7",
               "headermmh3" : -1448931244,
               "title" : "Firewall Authentication"
            },
            "length" : 3516
         },
         "asn" : "AS32489",
         "country" : "SC",
         "data" : "HTTP/1.1 200 OK\r\nContent-Length: 3377\r\nConnection: close\r\nCache-Control: no-cache\r\nContent-Type: text/html\r\nX-Frame-Options: SAMEORIGIN\r\n\r\n<!DOCTYPE html><html lang=\"en\"> <head> <meta charset=\"UTF-8\"> <meta http-equiv=\"X-UA-Compatible\" content=\"IE=8; IE=EDGE\"> <meta name=\"viewport\" content=\"width=device-width, initial-scale=1\"> <link href=\"https://fonts.googleapis.com/css?family=Roboto&display=swap\" rel=\"stylesheet\"> <style type=\"text/css\"> body { height: 100%; font-family: Roboto, Helvetica, Arial, sans-serif; color: #6a6a6a; margin: 0; display: flex; align-items: center; justify-content: center; } input[type=date], input[type=email], input[type=number], input[type=password], input[type=search], input[type=tel], input[type=text], input[type=time], input[type=url], select, textarea { color: #262626; vertical-align: baseline; margin: .2em; border-style: solid; border-width: 1px; border-color: #a9a9a9; background-color: #fff; box-sizing: border-box; padding: 2px .5em; appearance: none; border-radius: 0; } input:focus { border-color: #646464; box-shadow: 0 0 1px 0 #a2a2a2; outline: 0; } button { padding: .5em 1em; border: 1px solid; border-radius: 3px; min-width: 6em; font-weight: 400; font-size: .8em; cursor: pointer; } button.primary { color: #fff; background-color: rgb(47, 113, 178); border-color: rgb(34, 103, 173); } .message-container { height: 500px; width: 600px; padding: 0; margin: 10px; } .logo { background: url(/XX/YY/ZZ/CI/BGNGMGPGHGPG) no-repeat left center; height: 267px; object-fit: contain; } table { background-color: #fff; border-spacing: 0; margin: 1em; } table > tbody > tr > td:first-of-type:not([colspan]) { white-space: nowrap; color: rgba(0,0,0,.5); } table > tbody > tr > td:first-of-type { vertical-align: top; } table > tbody > tr > td { padding: .3em .3em; } .field { display: table-row; } .field > :first-child { display: table-cell; width: 20%; } .field.single > :first-child { display: inline; } .field > :not(:first-child) { width: auto; max-width: 100%; display: inline-flex; align-items: baseline; virtical-align: top; box-sizing: border-box; margin: .3em; } .field > :not(:first-child) > input { width: 230px; } .form-footer { display: inline-flex; justify-content: flex-start; } .form-footer > * { margin: 1em; } .text-scrollable { overflow: auto; height: 150px; border: 1px solid rgb(200, 200, 200); padding: 5px; font-size: 1em; } .text-centered { text-align: center; } .text-container { margin: 1em 1.5em; } .flex-container { display: flex; } .flex-container.column { flex-direction: column; } </style> <title> Firewall Authentication </title> </head> <body> <div class=\"message-container\"> <div class=\"logo\"> </div> <h1> <b> Remote Console Access </b> </h1> <h2> Authentication Required </h2> <form action=\"/\" method=\"post\"> <input type=\"hidden\" name=\"4Tredir\" value=\"http://38.122.68.226:1000/fgtauth?000f154b71af04b1\"> <input type=\"hidden\" name=\"magic\" value=\"030c1e7b1373d9bc\"> <input type=\"hidden\" name=\"\" value=\"\"> <p> Please enter your username and password to continue. </p> <div class=\"field\"> <label for=\"ft_un\"> Username </label> <div> <input name=\"username\" id=\"ft_un\" type=\"text\" autocorrect=\"off\" autocapitalize=\"off\"> </div> </div> <div class=\"field\"> <label for=\"ft_pd\"> Password </label> <div> <input name=\"password\" id=\"ft_pd\" type=\"password\" autocomplete=\"off\"> </div> </div> <div class=\"form-footer\"> <button class=\"primary\" type=\"submit\"> Continue </button> </div> </form> Please contact support for any issues. </div> </body></html>\r\n",
         "datamd5" : "0ff5f2b40e61866545c6f936c90596e7",
         "datammh3" : 1436622029,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "keyrist.com"
         ],
         "forward" : "38.122.68.226",
         "geolocus" : {
            "asn" : "AS32489",
            "continent" : "AF",
            "continentname" : "Africa",
            "country" : "SC",
            "countryname" : "Seychelles",
            "isineu" : "false",
            "latitude" : "-4.679574",
            "location" : "-4.679574,55.491977",
            "longitude" : "55.491977",
            "netname" : "AFRITEL-NET",
            "organization" : "Afritel Network",
            "subnet" : "137.63.74.0/23"
         },
         "hostname" : [
            "38.122.68.226",
            "keyrist.com"
         ],
         "ip" : "137.63.75.93",
         "ipv6" : "false",
         "latitude" : "-4.5833",
         "location" : "-4.5833,55.6667",
         "longitude" : "55.6667",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "AMANAHA-NEW",
         "port" : 1000,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "OK",
         "reverse" : [
            "keyrist.com"
         ],
         "seen_date" : "2024-11-07",
         "source" : "urlscan::redirect",
         "status" : 200,
         "subnet" : "137.63.75.0/24",
         "tag" : "<enterprise field>: tag",
         "tld" : [
            "com"
         ],
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/fgtauth?000f154b71af04b1"
      }
      
  • 90.147.46.137:1000 (tcp/http) - last seen on 2024-11-07 at 05:34:57 UTC

    • IP
      90.147.46.137
      Network
      90.147.0.0/16
      Device

      <enterprise field>: device.class

      URL

      http://193.205.131.1:1000/fgtauth?0046816b8856248f 200

      HTTP Title
      Firewall Authentication
      ASN
      AS137
      Organization
      Consortium GARR
      Protocol
      http
      Source
      urlscan::redirect
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      c72d54a61409db90d7563bc7da3eddf8
      HTTP Header MD5
      e2075400d0db00256ee037a5b80ae1f7
      HTTP Body MD5
      5ac3a5b131bfebcf54a184950f30ee33
    • HTTP/1.1 200 OK
      Content-Length: 3427
      Connection: close
      Cache-Control: no-cache
      Content-Type: text/html
      X-Frame-Options: SAMEORIGIN
      
      <!DOCTYPE html><html lang="en"> <head> <meta charset="UTF-8"> <meta http-equiv="X-UA-Compatible" content="IE=8; IE=EDGE"> <meta name="viewport" content="width=device-width, initial-scale=1"> <link href="https://fonts.googleapis.com/css?family=Roboto&display=swap" rel="stylesheet"> <style type="text/css"> body { height: 100%; font-family: Roboto, Helvetica, Arial, sans-serif; color: #6a6a6a; margin: 0; display: flex; align-items: center; justify-content: center; } input[type=date], input[type=email], input[type=number], input[type=password], input[type=search], input[type=tel], input[type=text], input[type=time], input[type=url], select, textarea { color: #262626; vertical-align: baseline; margin: .2em; border-style: solid; border-width: 1px; border-color: #a9a9a9; background-color: #fff; box-sizing: border-box; padding: 2px .5em; appearance: none; border-radius: 0; } input:focus { border-color: #646464; box-shadow: 0 0 1px 0 #a2a2a2; outline: 0; } button { padding: .5em 1em; border: 1px solid; border-radius: 3px; min-width: 6em; font-weight: 400; font-size: .8em; cursor: pointer; } button.primary { color: #fff; background-color: #c1092a; border-color: rgb(34, 103, 173); } .message-container { height: 500px; width: 600px; padding: 0; margin: 10px; } .logo { background: url(/XX/YY/ZZ/CI/MEPGHGPGPFFHOGJGGHAHNG) no-repeat left center; height: 267px; object-fit: contain; } table { background-color: #fff; border-spacing: 0; margin: 1em; } table > tbody > tr > td:first-of-type:not([colspan]) { white-space: nowrap; color: rgba(0,0,0,.5); } table > tbody > tr > td:first-of-type { vertical-align: top; } table > tbody > tr > td { padding: .3em .3em; } .field { display: table-row; } .field > :first-child { display: table-cell; width: 20%; } .field.single > :first-child { display: inline; } .field > :not(:first-child) { width: auto; max-width: 100%; display: inline-flex; align-items: baseline; virtical-align: top; box-sizing: border-box; margin: .3em; } .field > :not(:first-child) > input { width: 230px; } .form-footer { display: inline-flex; justify-content: flex-start; } .form-footer > * { margin: 1em; } .text-scrollable { overflow: auto; height: 150px; border: 1px solid rgb(200, 200, 200); padding: 5px; font-size: 1em; } .text-centered { text-align: center; } .text-container { margin: 1em 1.5em; } .flex-container { display: flex; } .flex-container.column { flex-direction: column; } </style> <title> Firewall Authentication </title> </head> <body> <div class="message-container"> <div class="logo"> </div> <h1> Autenticazione Richiesta </h1> <form action="/" method="post"> <input type="hidden" name="4Tredir" value="http://193.205.131.1:1000/fgtauth?0046816b8856248f"> <input type="hidden" name="magic" value="0141d1c38107372f"> <input type="hidden" name="" value=""> <p> Inserisci le credenziali per accedere ad Internet </br> Se riscontri dei problemi contatta l'ufficio reti </br> <a href="mailto:ict.network@sm.univpm.it"> ict.network@sm.univpm.it </a> </p> <div class="field"> <label for="ft_un"> Username </label> <div> <input name="username" id="ft_un" type="text" autocorrect="off" autocapitalize="off"> </div> </div> <div class="field"> <label for="ft_pd"> Password </label> <div> <input name="password" id="ft_pd" type="password" autocomplete="off"> </div> </div> <div class="form-footer"> <button class="primary" type="submit"> Continue </button> </div> </form></div></body></html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:34:57.000Z",
         "app" : {
            "extract" : {
               "domain" : [
                  "googleapis.com"
               ],
               "hostname" : [
                  "fonts.googleapis.com"
               ],
               "ip" : [
                  "193.205.131.1"
               ],
               "url" : [
                  "http://193.205.131.1:1000/fgtauth?0046816b8856248f",
                  "https://fonts.googleapis.com/css?family=Roboto&display=swap"
               ]
            },
            "http" : {
               "bodymd5" : "5ac3a5b131bfebcf54a184950f30ee33",
               "bodymmh3" : 1034977168,
               "headermd5" : "e2075400d0db00256ee037a5b80ae1f7",
               "headermmh3" : -923971862,
               "title" : "Firewall Authentication"
            },
            "length" : 3566
         },
         "asn" : "AS137",
         "city" : "Pavia",
         "country" : "IT",
         "data" : "HTTP/1.1 200 OK\r\nContent-Length: 3427\r\nConnection: close\r\nCache-Control: no-cache\r\nContent-Type: text/html\r\nX-Frame-Options: SAMEORIGIN\r\n\r\n<!DOCTYPE html><html lang=\"en\"> <head> <meta charset=\"UTF-8\"> <meta http-equiv=\"X-UA-Compatible\" content=\"IE=8; IE=EDGE\"> <meta name=\"viewport\" content=\"width=device-width, initial-scale=1\"> <link href=\"https://fonts.googleapis.com/css?family=Roboto&display=swap\" rel=\"stylesheet\"> <style type=\"text/css\"> body { height: 100%; font-family: Roboto, Helvetica, Arial, sans-serif; color: #6a6a6a; margin: 0; display: flex; align-items: center; justify-content: center; } input[type=date], input[type=email], input[type=number], input[type=password], input[type=search], input[type=tel], input[type=text], input[type=time], input[type=url], select, textarea { color: #262626; vertical-align: baseline; margin: .2em; border-style: solid; border-width: 1px; border-color: #a9a9a9; background-color: #fff; box-sizing: border-box; padding: 2px .5em; appearance: none; border-radius: 0; } input:focus { border-color: #646464; box-shadow: 0 0 1px 0 #a2a2a2; outline: 0; } button { padding: .5em 1em; border: 1px solid; border-radius: 3px; min-width: 6em; font-weight: 400; font-size: .8em; cursor: pointer; } button.primary { color: #fff; background-color: #c1092a; border-color: rgb(34, 103, 173); } .message-container { height: 500px; width: 600px; padding: 0; margin: 10px; } .logo { background: url(/XX/YY/ZZ/CI/MEPGHGPGPFFHOGJGGHAHNG) no-repeat left center; height: 267px; object-fit: contain; } table { background-color: #fff; border-spacing: 0; margin: 1em; } table > tbody > tr > td:first-of-type:not([colspan]) { white-space: nowrap; color: rgba(0,0,0,.5); } table > tbody > tr > td:first-of-type { vertical-align: top; } table > tbody > tr > td { padding: .3em .3em; } .field { display: table-row; } .field > :first-child { display: table-cell; width: 20%; } .field.single > :first-child { display: inline; } .field > :not(:first-child) { width: auto; max-width: 100%; display: inline-flex; align-items: baseline; virtical-align: top; box-sizing: border-box; margin: .3em; } .field > :not(:first-child) > input { width: 230px; } .form-footer { display: inline-flex; justify-content: flex-start; } .form-footer > * { margin: 1em; } .text-scrollable { overflow: auto; height: 150px; border: 1px solid rgb(200, 200, 200); padding: 5px; font-size: 1em; } .text-centered { text-align: center; } .text-container { margin: 1em 1.5em; } .flex-container { display: flex; } .flex-container.column { flex-direction: column; } </style> <title> Firewall Authentication </title> </head> <body> <div class=\"message-container\"> <div class=\"logo\"> </div> <h1> Autenticazione Richiesta </h1> <form action=\"/\" method=\"post\"> <input type=\"hidden\" name=\"4Tredir\" value=\"http://193.205.131.1:1000/fgtauth?0046816b8856248f\"> <input type=\"hidden\" name=\"magic\" value=\"0141d1c38107372f\"> <input type=\"hidden\" name=\"\" value=\"\"> <p> Inserisci le credenziali per accedere ad Internet </br> Se riscontri dei problemi contatta l'ufficio reti </br> <a href=\"mailto:ict.network@sm.univpm.it\"> ict.network@sm.univpm.it </a> </p> <div class=\"field\"> <label for=\"ft_un\"> Username </label> <div> <input name=\"username\" id=\"ft_un\" type=\"text\" autocorrect=\"off\" autocapitalize=\"off\"> </div> </div> <div class=\"field\"> <label for=\"ft_pd\"> Password </label> <div> <input name=\"password\" id=\"ft_pd\" type=\"password\" autocomplete=\"off\"> </div> </div> <div class=\"form-footer\"> <button class=\"primary\" type=\"submit\"> Continue </button> </div> </form></div></body></html>\r\n",
         "datamd5" : "c72d54a61409db90d7563bc7da3eddf8",
         "datammh3" : 958392845,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "forward" : "193.205.131.1",
         "geolocus" : {
            "asn" : "AS137",
            "continent" : "EU",
            "continentname" : "Europe",
            "country" : "IT",
            "countryname" : "Italy",
            "domain" : [
               "garr.it",
               "uniurb.it"
            ],
            "isineu" : "true",
            "latitude" : "41.87194",
            "location" : "41.87194,12.56738",
            "longitude" : "12.56738",
            "netname" : "UNI-URB07",
            "organization" : "Universita' degli Studi di Urbino Carlo Bo",
            "subnet" : "90.147.0.0/18"
         },
         "hostname" : [
            "193.205.131.1"
         ],
         "ip" : "90.147.46.137",
         "ipv6" : "false",
         "latitude" : "45.1976",
         "location" : "45.1976,9.1578",
         "longitude" : "9.1578",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "Consortium GARR",
         "port" : 1000,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "OK",
         "seen_date" : "2024-11-07",
         "source" : "urlscan::redirect",
         "status" : 200,
         "subnet" : "90.147.0.0/16",
         "tag" : "<enterprise field>: tag",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/fgtauth?0046816b8856248f"
      }
      
  • 90.147.44.250:1000 (tcp/http) - last seen on 2024-11-07 at 05:34:57 UTC

    • IP
      90.147.44.250
      Network
      90.147.0.0/16
      Device

      <enterprise field>: device.class

      URL

      http://193.205.131.1:1000/fgtauth?064f89c78c5d1ecd 200

      HTTP Title
      Firewall Authentication
      ASN
      AS137
      Organization
      Consortium GARR
      Protocol
      http
      Source
      urlscan::redirect
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      5ec160f067ffa01758476a99f2bc310d
      HTTP Header MD5
      e2075400d0db00256ee037a5b80ae1f7
      HTTP Body MD5
      5ac3a5b131bfebcf54a184950f30ee33
    • HTTP/1.1 200 OK
      Content-Length: 3427
      Connection: close
      Cache-Control: no-cache
      Content-Type: text/html
      X-Frame-Options: SAMEORIGIN
      
      <!DOCTYPE html><html lang="en"> <head> <meta charset="UTF-8"> <meta http-equiv="X-UA-Compatible" content="IE=8; IE=EDGE"> <meta name="viewport" content="width=device-width, initial-scale=1"> <link href="https://fonts.googleapis.com/css?family=Roboto&display=swap" rel="stylesheet"> <style type="text/css"> body { height: 100%; font-family: Roboto, Helvetica, Arial, sans-serif; color: #6a6a6a; margin: 0; display: flex; align-items: center; justify-content: center; } input[type=date], input[type=email], input[type=number], input[type=password], input[type=search], input[type=tel], input[type=text], input[type=time], input[type=url], select, textarea { color: #262626; vertical-align: baseline; margin: .2em; border-style: solid; border-width: 1px; border-color: #a9a9a9; background-color: #fff; box-sizing: border-box; padding: 2px .5em; appearance: none; border-radius: 0; } input:focus { border-color: #646464; box-shadow: 0 0 1px 0 #a2a2a2; outline: 0; } button { padding: .5em 1em; border: 1px solid; border-radius: 3px; min-width: 6em; font-weight: 400; font-size: .8em; cursor: pointer; } button.primary { color: #fff; background-color: #c1092a; border-color: rgb(34, 103, 173); } .message-container { height: 500px; width: 600px; padding: 0; margin: 10px; } .logo { background: url(/XX/YY/ZZ/CI/MEPGHGPGPFFHOGJGGHAHNG) no-repeat left center; height: 267px; object-fit: contain; } table { background-color: #fff; border-spacing: 0; margin: 1em; } table > tbody > tr > td:first-of-type:not([colspan]) { white-space: nowrap; color: rgba(0,0,0,.5); } table > tbody > tr > td:first-of-type { vertical-align: top; } table > tbody > tr > td { padding: .3em .3em; } .field { display: table-row; } .field > :first-child { display: table-cell; width: 20%; } .field.single > :first-child { display: inline; } .field > :not(:first-child) { width: auto; max-width: 100%; display: inline-flex; align-items: baseline; virtical-align: top; box-sizing: border-box; margin: .3em; } .field > :not(:first-child) > input { width: 230px; } .form-footer { display: inline-flex; justify-content: flex-start; } .form-footer > * { margin: 1em; } .text-scrollable { overflow: auto; height: 150px; border: 1px solid rgb(200, 200, 200); padding: 5px; font-size: 1em; } .text-centered { text-align: center; } .text-container { margin: 1em 1.5em; } .flex-container { display: flex; } .flex-container.column { flex-direction: column; } </style> <title> Firewall Authentication </title> </head> <body> <div class="message-container"> <div class="logo"> </div> <h1> Autenticazione Richiesta </h1> <form action="/" method="post"> <input type="hidden" name="4Tredir" value="http://193.205.131.1:1000/fgtauth?064f89c78c5d1ecd"> <input type="hidden" name="magic" value="0140867e20ffff7a"> <input type="hidden" name="" value=""> <p> Inserisci le credenziali per accedere ad Internet </br> Se riscontri dei problemi contatta l'ufficio reti </br> <a href="mailto:ict.network@sm.univpm.it"> ict.network@sm.univpm.it </a> </p> <div class="field"> <label for="ft_un"> Username </label> <div> <input name="username" id="ft_un" type="text" autocorrect="off" autocapitalize="off"> </div> </div> <div class="field"> <label for="ft_pd"> Password </label> <div> <input name="password" id="ft_pd" type="password" autocomplete="off"> </div> </div> <div class="form-footer"> <button class="primary" type="submit"> Continue </button> </div> </form></div></body></html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:34:57.000Z",
         "app" : {
            "extract" : {
               "domain" : [
                  "googleapis.com"
               ],
               "hostname" : [
                  "fonts.googleapis.com"
               ],
               "ip" : [
                  "193.205.131.1"
               ],
               "url" : [
                  "http://193.205.131.1:1000/fgtauth?064f89c78c5d1ecd",
                  "https://fonts.googleapis.com/css?family=Roboto&display=swap"
               ]
            },
            "http" : {
               "bodymd5" : "5ac3a5b131bfebcf54a184950f30ee33",
               "bodymmh3" : -1242136055,
               "headermd5" : "e2075400d0db00256ee037a5b80ae1f7",
               "headermmh3" : -923971862,
               "title" : "Firewall Authentication"
            },
            "length" : 3566
         },
         "asn" : "AS137",
         "city" : "Pavia",
         "country" : "IT",
         "data" : "HTTP/1.1 200 OK\r\nContent-Length: 3427\r\nConnection: close\r\nCache-Control: no-cache\r\nContent-Type: text/html\r\nX-Frame-Options: SAMEORIGIN\r\n\r\n<!DOCTYPE html><html lang=\"en\"> <head> <meta charset=\"UTF-8\"> <meta http-equiv=\"X-UA-Compatible\" content=\"IE=8; IE=EDGE\"> <meta name=\"viewport\" content=\"width=device-width, initial-scale=1\"> <link href=\"https://fonts.googleapis.com/css?family=Roboto&display=swap\" rel=\"stylesheet\"> <style type=\"text/css\"> body { height: 100%; font-family: Roboto, Helvetica, Arial, sans-serif; color: #6a6a6a; margin: 0; display: flex; align-items: center; justify-content: center; } input[type=date], input[type=email], input[type=number], input[type=password], input[type=search], input[type=tel], input[type=text], input[type=time], input[type=url], select, textarea { color: #262626; vertical-align: baseline; margin: .2em; border-style: solid; border-width: 1px; border-color: #a9a9a9; background-color: #fff; box-sizing: border-box; padding: 2px .5em; appearance: none; border-radius: 0; } input:focus { border-color: #646464; box-shadow: 0 0 1px 0 #a2a2a2; outline: 0; } button { padding: .5em 1em; border: 1px solid; border-radius: 3px; min-width: 6em; font-weight: 400; font-size: .8em; cursor: pointer; } button.primary { color: #fff; background-color: #c1092a; border-color: rgb(34, 103, 173); } .message-container { height: 500px; width: 600px; padding: 0; margin: 10px; } .logo { background: url(/XX/YY/ZZ/CI/MEPGHGPGPFFHOGJGGHAHNG) no-repeat left center; height: 267px; object-fit: contain; } table { background-color: #fff; border-spacing: 0; margin: 1em; } table > tbody > tr > td:first-of-type:not([colspan]) { white-space: nowrap; color: rgba(0,0,0,.5); } table > tbody > tr > td:first-of-type { vertical-align: top; } table > tbody > tr > td { padding: .3em .3em; } .field { display: table-row; } .field > :first-child { display: table-cell; width: 20%; } .field.single > :first-child { display: inline; } .field > :not(:first-child) { width: auto; max-width: 100%; display: inline-flex; align-items: baseline; virtical-align: top; box-sizing: border-box; margin: .3em; } .field > :not(:first-child) > input { width: 230px; } .form-footer { display: inline-flex; justify-content: flex-start; } .form-footer > * { margin: 1em; } .text-scrollable { overflow: auto; height: 150px; border: 1px solid rgb(200, 200, 200); padding: 5px; font-size: 1em; } .text-centered { text-align: center; } .text-container { margin: 1em 1.5em; } .flex-container { display: flex; } .flex-container.column { flex-direction: column; } </style> <title> Firewall Authentication </title> </head> <body> <div class=\"message-container\"> <div class=\"logo\"> </div> <h1> Autenticazione Richiesta </h1> <form action=\"/\" method=\"post\"> <input type=\"hidden\" name=\"4Tredir\" value=\"http://193.205.131.1:1000/fgtauth?064f89c78c5d1ecd\"> <input type=\"hidden\" name=\"magic\" value=\"0140867e20ffff7a\"> <input type=\"hidden\" name=\"\" value=\"\"> <p> Inserisci le credenziali per accedere ad Internet </br> Se riscontri dei problemi contatta l'ufficio reti </br> <a href=\"mailto:ict.network@sm.univpm.it\"> ict.network@sm.univpm.it </a> </p> <div class=\"field\"> <label for=\"ft_un\"> Username </label> <div> <input name=\"username\" id=\"ft_un\" type=\"text\" autocorrect=\"off\" autocapitalize=\"off\"> </div> </div> <div class=\"field\"> <label for=\"ft_pd\"> Password </label> <div> <input name=\"password\" id=\"ft_pd\" type=\"password\" autocomplete=\"off\"> </div> </div> <div class=\"form-footer\"> <button class=\"primary\" type=\"submit\"> Continue </button> </div> </form></div></body></html>\r\n",
         "datamd5" : "5ec160f067ffa01758476a99f2bc310d",
         "datammh3" : 64603448,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "forward" : "193.205.131.1",
         "geolocus" : {
            "asn" : "AS137",
            "continent" : "EU",
            "continentname" : "Europe",
            "country" : "IT",
            "countryname" : "Italy",
            "domain" : [
               "garr.it",
               "uniurb.it"
            ],
            "isineu" : "true",
            "latitude" : "41.87194",
            "location" : "41.87194,12.56738",
            "longitude" : "12.56738",
            "netname" : "UNI-URB07",
            "organization" : "Universita' degli Studi di Urbino Carlo Bo",
            "subnet" : "90.147.0.0/18"
         },
         "hostname" : [
            "193.205.131.1"
         ],
         "ip" : "90.147.44.250",
         "ipv6" : "false",
         "latitude" : "45.1976",
         "location" : "45.1976,9.1578",
         "longitude" : "9.1578",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "Consortium GARR",
         "port" : 1000,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "OK",
         "seen_date" : "2024-11-07",
         "source" : "urlscan::redirect",
         "status" : 200,
         "subnet" : "90.147.0.0/16",
         "tag" : "<enterprise field>: tag",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/fgtauth?064f89c78c5d1ecd"
      }
      
  • 193.205.132.243:1000 (tcp/http) - last seen on 2024-11-07 at 05:34:57 UTC

    • IP
      193.205.132.243
      Network
      193.204.0.0/15
      Device

      <enterprise field>: device.class

      URL

      http://193.205.131.1:1000/fgtauth?074df988b44366c3 200

      HTTP Title
      Firewall Authentication
      ASN
      AS137
      Organization
      Consortium GARR
      Protocol
      http
      Source
      urlscan::redirect
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      6604b06b23ba76c69bf5073547936fb8
      HTTP Header MD5
      e2075400d0db00256ee037a5b80ae1f7
      HTTP Body MD5
      5ac3a5b131bfebcf54a184950f30ee33
    • HTTP/1.1 200 OK
      Content-Length: 3427
      Connection: close
      Cache-Control: no-cache
      Content-Type: text/html
      X-Frame-Options: SAMEORIGIN
      
      <!DOCTYPE html><html lang="en"> <head> <meta charset="UTF-8"> <meta http-equiv="X-UA-Compatible" content="IE=8; IE=EDGE"> <meta name="viewport" content="width=device-width, initial-scale=1"> <link href="https://fonts.googleapis.com/css?family=Roboto&display=swap" rel="stylesheet"> <style type="text/css"> body { height: 100%; font-family: Roboto, Helvetica, Arial, sans-serif; color: #6a6a6a; margin: 0; display: flex; align-items: center; justify-content: center; } input[type=date], input[type=email], input[type=number], input[type=password], input[type=search], input[type=tel], input[type=text], input[type=time], input[type=url], select, textarea { color: #262626; vertical-align: baseline; margin: .2em; border-style: solid; border-width: 1px; border-color: #a9a9a9; background-color: #fff; box-sizing: border-box; padding: 2px .5em; appearance: none; border-radius: 0; } input:focus { border-color: #646464; box-shadow: 0 0 1px 0 #a2a2a2; outline: 0; } button { padding: .5em 1em; border: 1px solid; border-radius: 3px; min-width: 6em; font-weight: 400; font-size: .8em; cursor: pointer; } button.primary { color: #fff; background-color: #c1092a; border-color: rgb(34, 103, 173); } .message-container { height: 500px; width: 600px; padding: 0; margin: 10px; } .logo { background: url(/XX/YY/ZZ/CI/MEPGHGPGPFFHOGJGGHAHNG) no-repeat left center; height: 267px; object-fit: contain; } table { background-color: #fff; border-spacing: 0; margin: 1em; } table > tbody > tr > td:first-of-type:not([colspan]) { white-space: nowrap; color: rgba(0,0,0,.5); } table > tbody > tr > td:first-of-type { vertical-align: top; } table > tbody > tr > td { padding: .3em .3em; } .field { display: table-row; } .field > :first-child { display: table-cell; width: 20%; } .field.single > :first-child { display: inline; } .field > :not(:first-child) { width: auto; max-width: 100%; display: inline-flex; align-items: baseline; virtical-align: top; box-sizing: border-box; margin: .3em; } .field > :not(:first-child) > input { width: 230px; } .form-footer { display: inline-flex; justify-content: flex-start; } .form-footer > * { margin: 1em; } .text-scrollable { overflow: auto; height: 150px; border: 1px solid rgb(200, 200, 200); padding: 5px; font-size: 1em; } .text-centered { text-align: center; } .text-container { margin: 1em 1.5em; } .flex-container { display: flex; } .flex-container.column { flex-direction: column; } </style> <title> Firewall Authentication </title> </head> <body> <div class="message-container"> <div class="logo"> </div> <h1> Autenticazione Richiesta </h1> <form action="/" method="post"> <input type="hidden" name="4Tredir" value="http://193.205.131.1:1000/fgtauth?074df988b44366c3"> <input type="hidden" name="magic" value="01458dd3a88f0928"> <input type="hidden" name="" value=""> <p> Inserisci le credenziali per accedere ad Internet </br> Se riscontri dei problemi contatta l'ufficio reti </br> <a href="mailto:ict.network@sm.univpm.it"> ict.network@sm.univpm.it </a> </p> <div class="field"> <label for="ft_un"> Username </label> <div> <input name="username" id="ft_un" type="text" autocorrect="off" autocapitalize="off"> </div> </div> <div class="field"> <label for="ft_pd"> Password </label> <div> <input name="password" id="ft_pd" type="password" autocomplete="off"> </div> </div> <div class="form-footer"> <button class="primary" type="submit"> Continue </button> </div> </form></div></body></html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:34:57.000Z",
         "app" : {
            "extract" : {
               "domain" : [
                  "googleapis.com"
               ],
               "hostname" : [
                  "fonts.googleapis.com"
               ],
               "ip" : [
                  "193.205.131.1"
               ],
               "url" : [
                  "http://193.205.131.1:1000/fgtauth?074df988b44366c3",
                  "https://fonts.googleapis.com/css?family=Roboto&display=swap"
               ]
            },
            "http" : {
               "bodymd5" : "5ac3a5b131bfebcf54a184950f30ee33",
               "bodymmh3" : 1410444536,
               "headermd5" : "e2075400d0db00256ee037a5b80ae1f7",
               "headermmh3" : -923971862,
               "title" : "Firewall Authentication"
            },
            "length" : 3566
         },
         "asn" : "AS137",
         "city" : "Ancona",
         "country" : "IT",
         "data" : "HTTP/1.1 200 OK\r\nContent-Length: 3427\r\nConnection: close\r\nCache-Control: no-cache\r\nContent-Type: text/html\r\nX-Frame-Options: SAMEORIGIN\r\n\r\n<!DOCTYPE html><html lang=\"en\"> <head> <meta charset=\"UTF-8\"> <meta http-equiv=\"X-UA-Compatible\" content=\"IE=8; IE=EDGE\"> <meta name=\"viewport\" content=\"width=device-width, initial-scale=1\"> <link href=\"https://fonts.googleapis.com/css?family=Roboto&display=swap\" rel=\"stylesheet\"> <style type=\"text/css\"> body { height: 100%; font-family: Roboto, Helvetica, Arial, sans-serif; color: #6a6a6a; margin: 0; display: flex; align-items: center; justify-content: center; } input[type=date], input[type=email], input[type=number], input[type=password], input[type=search], input[type=tel], input[type=text], input[type=time], input[type=url], select, textarea { color: #262626; vertical-align: baseline; margin: .2em; border-style: solid; border-width: 1px; border-color: #a9a9a9; background-color: #fff; box-sizing: border-box; padding: 2px .5em; appearance: none; border-radius: 0; } input:focus { border-color: #646464; box-shadow: 0 0 1px 0 #a2a2a2; outline: 0; } button { padding: .5em 1em; border: 1px solid; border-radius: 3px; min-width: 6em; font-weight: 400; font-size: .8em; cursor: pointer; } button.primary { color: #fff; background-color: #c1092a; border-color: rgb(34, 103, 173); } .message-container { height: 500px; width: 600px; padding: 0; margin: 10px; } .logo { background: url(/XX/YY/ZZ/CI/MEPGHGPGPFFHOGJGGHAHNG) no-repeat left center; height: 267px; object-fit: contain; } table { background-color: #fff; border-spacing: 0; margin: 1em; } table > tbody > tr > td:first-of-type:not([colspan]) { white-space: nowrap; color: rgba(0,0,0,.5); } table > tbody > tr > td:first-of-type { vertical-align: top; } table > tbody > tr > td { padding: .3em .3em; } .field { display: table-row; } .field > :first-child { display: table-cell; width: 20%; } .field.single > :first-child { display: inline; } .field > :not(:first-child) { width: auto; max-width: 100%; display: inline-flex; align-items: baseline; virtical-align: top; box-sizing: border-box; margin: .3em; } .field > :not(:first-child) > input { width: 230px; } .form-footer { display: inline-flex; justify-content: flex-start; } .form-footer > * { margin: 1em; } .text-scrollable { overflow: auto; height: 150px; border: 1px solid rgb(200, 200, 200); padding: 5px; font-size: 1em; } .text-centered { text-align: center; } .text-container { margin: 1em 1.5em; } .flex-container { display: flex; } .flex-container.column { flex-direction: column; } </style> <title> Firewall Authentication </title> </head> <body> <div class=\"message-container\"> <div class=\"logo\"> </div> <h1> Autenticazione Richiesta </h1> <form action=\"/\" method=\"post\"> <input type=\"hidden\" name=\"4Tredir\" value=\"http://193.205.131.1:1000/fgtauth?074df988b44366c3\"> <input type=\"hidden\" name=\"magic\" value=\"01458dd3a88f0928\"> <input type=\"hidden\" name=\"\" value=\"\"> <p> Inserisci le credenziali per accedere ad Internet </br> Se riscontri dei problemi contatta l'ufficio reti </br> <a href=\"mailto:ict.network@sm.univpm.it\"> ict.network@sm.univpm.it </a> </p> <div class=\"field\"> <label for=\"ft_un\"> Username </label> <div> <input name=\"username\" id=\"ft_un\" type=\"text\" autocorrect=\"off\" autocapitalize=\"off\"> </div> </div> <div class=\"field\"> <label for=\"ft_pd\"> Password </label> <div> <input name=\"password\" id=\"ft_pd\" type=\"password\" autocomplete=\"off\"> </div> </div> <div class=\"form-footer\"> <button class=\"primary\" type=\"submit\"> Continue </button> </div> </form></div></body></html>\r\n",
         "datamd5" : "6604b06b23ba76c69bf5073547936fb8",
         "datammh3" : 1670185382,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "forward" : "193.205.131.1",
         "geolocus" : {
            "asn" : "AS137",
            "continent" : "EU",
            "continentname" : "Europe",
            "country" : "IT",
            "countryname" : "Italy",
            "domain" : [
               "garr.it",
               "univpm.it"
            ],
            "isineu" : "true",
            "latitude" : "41.87194",
            "location" : "41.87194,12.56738",
            "longitude" : "12.56738",
            "netname" : "ANCONA-NET",
            "organization" : "Universita' Politecnica delle Marche",
            "subnet" : "193.205.128.0/18"
         },
         "hostname" : [
            "193.205.131.1"
         ],
         "ip" : "193.205.132.243",
         "ipv6" : "false",
         "latitude" : "43.5939",
         "location" : "43.5939,13.5086",
         "longitude" : "13.5086",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "Consortium GARR",
         "port" : 1000,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "OK",
         "seen_date" : "2024-11-07",
         "source" : "urlscan::redirect",
         "status" : 200,
         "subnet" : "193.204.0.0/15",
         "tag" : "<enterprise field>: tag",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/fgtauth?074df988b44366c3"
      }