Returning 10 result(s) out of 73,283 in 0.068 second(s)

  • 213.176.59.30:20547 (tcp/http) - last seen on 2024-11-21 at 08:51:18 UTC

    • IP
      213.176.59.30
      Network
      213.176.32.0/19
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      URL

      http://213.176.59.30:20547/ 400

      HTTP Title
      400 The plain HTTP request was sent to HTTPS port
      ASN
      AS142578
      Organization
      E-Large HongKong
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      3b40fcd13ec4c48698cf15e0d2ba5977
      HTTP Header MD5
      7de09592d0cc3062011d73fa292680b0
      HTTP Body MD5
      77bd43987adf27926b335fbe22b67813
    • HTTP/1.1 400 Bad Request
      Server: WAF
      Date: Thu, 21 Nov 2024 08:51:18 GMT
      Content-Type: text/html
      Content-Length: 262
      Connection: close
      
      <html>
      <head><title>400 The plain HTTP request was sent to HTTPS port</title></head>
      <body bgcolor="white">
      <center><h1>400 Bad Request</h1></center>
      <center>The plain HTTP request was sent to HTTPS port</center>
      <hr><center>WAF</center>
      </body>
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-21T08:51:18.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "77bd43987adf27926b335fbe22b67813",
               "bodymmh3" : -2135056736,
               "headermd5" : "7de09592d0cc3062011d73fa292680b0",
               "headermmh3" : 445760042,
               "title" : "400 The plain HTTP request was sent to HTTPS port"
            },
            "length" : 405
         },
         "asn" : "AS142578",
         "country" : "US",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 400 Bad Request\r\nServer: WAF\r\nDate: Thu, 21 Nov 2024 08:51:18 GMT\r\nContent-Type: text/html\r\nContent-Length: 262\r\nConnection: close\r\n\r\n<html>\r\n<head><title>400 The plain HTTP request was sent to HTTPS port</title></head>\r\n<body bgcolor=\"white\">\r\n<center><h1>400 Bad Request</h1></center>\r\n<center>The plain HTTP request was sent to HTTPS port</center>\r\n<hr><center>WAF</center>\r\n</body>\r\n</html>\r\n",
         "datamd5" : "3b40fcd13ec4c48698cf15e0d2ba5977",
         "datammh3" : 401141661,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS142578",
            "continent" : "AS",
            "continentname" : "Asia",
            "country" : "IR",
            "countryname" : "Iran",
            "domain" : [
               "gmail.com"
            ],
            "isineu" : "false",
            "latitude" : "32.427908",
            "location" : "32.427908,53.688046",
            "longitude" : "53.688046",
            "netname" : "hk-ipv4superhub-1",
            "organization" : "hk-ipv4superhub-1",
            "subnet" : "213.176.56.0/22"
         },
         "ip" : "213.176.59.30",
         "ipv6" : "false",
         "latitude" : "34.0544",
         "location" : "34.0544,-118.2440",
         "longitude" : "-118.2440",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "E-Large HongKong",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 20547,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Bad Request",
         "seen_date" : "2024-11-21",
         "source" : "datascan",
         "status" : 400,
         "subnet" : "213.176.32.0/19",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 23.26.185.138:20547 (tcp/http) - last seen on 2024-11-21 at 08:51:17 UTC

    • IP
      23.26.185.138
      Network
      23.26.176.0/20
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      URL

      http://23.26.185.138:20547/ 400

      HTTP Title
      400 The plain HTTP request was sent to HTTPS port
      ASN
      AS134729
      Organization
      JOINT POWER TECHNOLOGY LIMITED
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      3b40fcd13ec4c48698cf15e0d2ba5977
      HTTP Header MD5
      7de09592d0cc3062011d73fa292680b0
      HTTP Body MD5
      77bd43987adf27926b335fbe22b67813
    • HTTP/1.1 400 Bad Request
      Server: WAF
      Date: Thu, 21 Nov 2024 08:51:17 GMT
      Content-Type: text/html
      Content-Length: 262
      Connection: close
      
      <html>
      <head><title>400 The plain HTTP request was sent to HTTPS port</title></head>
      <body bgcolor="white">
      <center><h1>400 Bad Request</h1></center>
      <center>The plain HTTP request was sent to HTTPS port</center>
      <hr><center>WAF</center>
      </body>
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-21T08:51:17.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "77bd43987adf27926b335fbe22b67813",
               "bodymmh3" : -2135056736,
               "headermd5" : "7de09592d0cc3062011d73fa292680b0",
               "headermmh3" : 1834578419,
               "title" : "400 The plain HTTP request was sent to HTTPS port"
            },
            "length" : 405
         },
         "asn" : "AS134729",
         "country" : "US",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 400 Bad Request\r\nServer: WAF\r\nDate: Thu, 21 Nov 2024 08:51:17 GMT\r\nContent-Type: text/html\r\nContent-Length: 262\r\nConnection: close\r\n\r\n<html>\r\n<head><title>400 The plain HTTP request was sent to HTTPS port</title></head>\r\n<body bgcolor=\"white\">\r\n<center><h1>400 Bad Request</h1></center>\r\n<center>The plain HTTP request was sent to HTTPS port</center>\r\n<hr><center>WAF</center>\r\n</body>\r\n</html>\r\n",
         "datamd5" : "3b40fcd13ec4c48698cf15e0d2ba5977",
         "datammh3" : 401141661,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS134729",
            "continent" : "NA",
            "continentname" : "North America",
            "country" : "US",
            "countryname" : "United States",
            "domain" : [
               "acedatacenter.com",
               "ipxo.com"
            ],
            "isineu" : "false",
            "latitude" : "37.09024",
            "location" : "37.09024,-95.712891",
            "longitude" : "-95.712891",
            "netname" : "23-26-160-0-19",
            "organization" : "IPXO LLC",
            "subnet" : "23.26.176.0/20"
         },
         "ip" : "23.26.185.138",
         "ipv6" : "false",
         "latitude" : "37.7510",
         "location" : "37.7510,-97.8220",
         "longitude" : "-97.8220",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "JOINT POWER TECHNOLOGY LIMITED",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 20547,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Bad Request",
         "seen_date" : "2024-11-21",
         "source" : "datascan",
         "status" : 400,
         "subnet" : "23.26.176.0/20",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 38.47.159.238:20547 (tcp/http) - last seen on 2024-11-21 at 08:51:07 UTC

    • IP
      38.47.159.238
      Network
      38.47.128.0/19
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      URL

      http://38.47.159.238:20547/ 400

      HTTP Title
      400 The plain HTTP request was sent to HTTPS port
      ASN
      AS147019
      Organization
      jiii
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      3b40fcd13ec4c48698cf15e0d2ba5977
      HTTP Header MD5
      7de09592d0cc3062011d73fa292680b0
      HTTP Body MD5
      77bd43987adf27926b335fbe22b67813
    • HTTP/1.1 400 Bad Request
      Server: WAF
      Date: Thu, 21 Nov 2024 08:51:07 GMT
      Content-Type: text/html
      Content-Length: 262
      Connection: close
      
      <html>
      <head><title>400 The plain HTTP request was sent to HTTPS port</title></head>
      <body bgcolor="white">
      <center><h1>400 Bad Request</h1></center>
      <center>The plain HTTP request was sent to HTTPS port</center>
      <hr><center>WAF</center>
      </body>
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-21T08:51:07.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "77bd43987adf27926b335fbe22b67813",
               "bodymmh3" : -2135056736,
               "headermd5" : "7de09592d0cc3062011d73fa292680b0",
               "headermmh3" : 494056025,
               "title" : "400 The plain HTTP request was sent to HTTPS port"
            },
            "length" : 405
         },
         "asn" : "AS147019",
         "country" : "US",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 400 Bad Request\r\nServer: WAF\r\nDate: Thu, 21 Nov 2024 08:51:07 GMT\r\nContent-Type: text/html\r\nContent-Length: 262\r\nConnection: close\r\n\r\n<html>\r\n<head><title>400 The plain HTTP request was sent to HTTPS port</title></head>\r\n<body bgcolor=\"white\">\r\n<center><h1>400 Bad Request</h1></center>\r\n<center>The plain HTTP request was sent to HTTPS port</center>\r\n<hr><center>WAF</center>\r\n</body>\r\n</html>\r\n",
         "datamd5" : "3b40fcd13ec4c48698cf15e0d2ba5977",
         "datammh3" : 401141661,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS147019",
            "continent" : "NA",
            "continentname" : "North America",
            "country" : "US",
            "countryname" : "United States",
            "domain" : [
               "cogentco.com"
            ],
            "isineu" : "false",
            "latitude" : "37.09024",
            "location" : "37.09024,-95.712891",
            "longitude" : "-95.712891",
            "netname" : "COGENT-A",
            "organization" : "PSINet, Inc.",
            "subnet" : "38.47.128.0/19"
         },
         "ip" : "38.47.159.238",
         "ipv6" : "false",
         "latitude" : "37.7510",
         "location" : "37.7510,-97.8220",
         "longitude" : "-97.8220",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "jiii",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 20547,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Bad Request",
         "seen_date" : "2024-11-21",
         "source" : "datascan",
         "status" : 400,
         "subnet" : "38.47.128.0/19",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 66.180.233.20:20547 (tcp/http) - last seen on 2024-11-21 at 08:51:04 UTC

    • IP
      66.180.233.20
      Network
      66.180.224.0/20
      Domain(s)
      lowcountry.com
      Device

      <enterprise field>: device.class

      URL

      http://66.180.233.20:20547/ 301

      HTTP Title
      Moved Permanently
      Reverse DNS
      dynamic-66-180-233-20.lowcountry.com
      ASN
      AS18671
      Organization
      PRTC-SC
      Protocol
      http
      Source
      datascan::redirect::3
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      ca9d7d1b6f85c6c6922f08083e4e96e7
      HTTP Header MD5
      2c561ce2561b7f6113f96cf56b362b57
      HTTP Body MD5
      6d74b20c6fa245a96aa940816c13f6ff
    • HTTP/1.1 301 Moved Permanently
      Access-Control-Allow-Origin: *
      Content-Length: 98
      Content-Type: text/html; charset=utf-8
      Date: Thu, 21 Nov 2024 08:51:03 GMT
      Location: https://<ip>:20547/
      
      <HTML><HEAD><TITLE>Moved Permanently</TITLE></HEAD><BODY><H1>301 Moved Permanently -- </H1></BODY>
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-21T08:51:04.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "6d74b20c6fa245a96aa940816c13f6ff",
               "bodymmh3" : -2097937471,
               "headermd5" : "2c561ce2561b7f6113f96cf56b362b57",
               "headermmh3" : 834499833,
               "title" : "Moved Permanently"
            },
            "length" : 292
         },
         "asn" : "AS18671",
         "city" : "Walterboro",
         "country" : "US",
         "data" : "HTTP/1.1 301 Moved Permanently\r\nAccess-Control-Allow-Origin: *\r\nContent-Length: 98\r\nContent-Type: text/html; charset=utf-8\r\nDate: Thu, 21 Nov 2024 08:51:03 GMT\r\nLocation: https://<ip>:20547/\r\n\r\n<HTML><HEAD><TITLE>Moved Permanently</TITLE></HEAD><BODY><H1>301 Moved Permanently -- </H1></BODY>",
         "datamd5" : "ca9d7d1b6f85c6c6922f08083e4e96e7",
         "datammh3" : -295421703,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "lowcountry.com"
         ],
         "forward" : "66.180.233.20",
         "geolocus" : {
            "asn" : "AS18671",
            "continent" : "NA",
            "continentname" : "North America",
            "country" : "US",
            "countryname" : "United States",
            "domain" : [
               "lowcountry.com",
               "prtc.coop",
               "prtc.us"
            ],
            "isineu" : "false",
            "latitude" : "37.09024",
            "location" : "37.09024,-95.712891",
            "longitude" : "-95.712891",
            "netname" : "PRTC-BLK1",
            "organization" : "PRTC",
            "subnet" : "66.180.224.0/20"
         },
         "host" : [
            "dynamic-66-180-233-20"
         ],
         "hostname" : [
            "66.180.233.20",
            "dynamic-66-180-233-20.lowcountry.com"
         ],
         "ip" : "66.180.233.20",
         "ipv6" : "false",
         "latitude" : "32.9080",
         "location" : "32.9080,-80.6671",
         "longitude" : "-80.6671",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "PRTC-SC",
         "port" : 20547,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Moved Permanently",
         "reverse" : [
            "dynamic-66-180-233-20.lowcountry.com"
         ],
         "seen_date" : "2024-11-21",
         "source" : "datascan::redirect::3",
         "status" : 301,
         "subnet" : "66.180.224.0/20",
         "tld" : [
            "com"
         ],
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 213.176.107.139:20547 (tcp/http) - last seen on 2024-11-21 at 08:50:54 UTC

    • IP
      213.176.107.139
      Network
      213.176.96.0/20
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      URL

      http://213.176.107.139:20547/ 400

      HTTP Title
      400 The plain HTTP request was sent to HTTPS port
      ASN
      AS142578
      Organization
      E-Large HongKong
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      3b40fcd13ec4c48698cf15e0d2ba5977
      HTTP Header MD5
      7de09592d0cc3062011d73fa292680b0
      HTTP Body MD5
      77bd43987adf27926b335fbe22b67813
    • HTTP/1.1 400 Bad Request
      Server: WAF
      Date: Thu, 21 Nov 2024 08:50:54 GMT
      Content-Type: text/html
      Content-Length: 262
      Connection: close
      
      <html>
      <head><title>400 The plain HTTP request was sent to HTTPS port</title></head>
      <body bgcolor="white">
      <center><h1>400 Bad Request</h1></center>
      <center>The plain HTTP request was sent to HTTPS port</center>
      <hr><center>WAF</center>
      </body>
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-21T08:50:54.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "77bd43987adf27926b335fbe22b67813",
               "bodymmh3" : -2135056736,
               "headermd5" : "7de09592d0cc3062011d73fa292680b0",
               "headermmh3" : 1813691228,
               "title" : "400 The plain HTTP request was sent to HTTPS port"
            },
            "length" : 405
         },
         "asn" : "AS142578",
         "country" : "HK",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 400 Bad Request\r\nServer: WAF\r\nDate: Thu, 21 Nov 2024 08:50:54 GMT\r\nContent-Type: text/html\r\nContent-Length: 262\r\nConnection: close\r\n\r\n<html>\r\n<head><title>400 The plain HTTP request was sent to HTTPS port</title></head>\r\n<body bgcolor=\"white\">\r\n<center><h1>400 Bad Request</h1></center>\r\n<center>The plain HTTP request was sent to HTTPS port</center>\r\n<hr><center>WAF</center>\r\n</body>\r\n</html>\r\n",
         "datamd5" : "3b40fcd13ec4c48698cf15e0d2ba5977",
         "datammh3" : 401141661,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS142578",
            "continent" : "AS",
            "continentname" : "Asia",
            "country" : "IR",
            "countryname" : "Iran",
            "domain" : [
               "gmail.com"
            ],
            "isineu" : "false",
            "latitude" : "32.427908",
            "location" : "32.427908,53.688046",
            "longitude" : "53.688046",
            "netname" : "us-sammu-1",
            "organization" : "us-sammu-1",
            "subnet" : "213.176.96.0/20"
         },
         "ip" : "213.176.107.139",
         "ipv6" : "false",
         "latitude" : "22.2578",
         "location" : "22.2578,114.1657",
         "longitude" : "114.1657",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "E-Large HongKong",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 20547,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Bad Request",
         "seen_date" : "2024-11-21",
         "source" : "datascan",
         "status" : 400,
         "subnet" : "213.176.96.0/20",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 45.194.58.116:20547 (tcp/http) - last seen on 2024-11-21 at 08:50:28 UTC

    • IP
      45.194.58.116
      Network
      45.194.56.0/21
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      URL

      http://45.194.58.116:20547/ 400

      HTTP Title
      400 The plain HTTP request was sent to HTTPS port
      ASN
      AS147019
      Organization
      jiii
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      3b40fcd13ec4c48698cf15e0d2ba5977
      HTTP Header MD5
      7de09592d0cc3062011d73fa292680b0
      HTTP Body MD5
      77bd43987adf27926b335fbe22b67813
    • HTTP/1.1 400 Bad Request
      Server: WAF
      Date: Thu, 21 Nov 2024 08:50:28 GMT
      Content-Type: text/html
      Content-Length: 262
      Connection: close
      
      <html>
      <head><title>400 The plain HTTP request was sent to HTTPS port</title></head>
      <body bgcolor="white">
      <center><h1>400 Bad Request</h1></center>
      <center>The plain HTTP request was sent to HTTPS port</center>
      <hr><center>WAF</center>
      </body>
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-21T08:50:28.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "77bd43987adf27926b335fbe22b67813",
               "bodymmh3" : -2135056736,
               "headermd5" : "7de09592d0cc3062011d73fa292680b0",
               "headermmh3" : -384142797,
               "title" : "400 The plain HTTP request was sent to HTTPS port"
            },
            "length" : 405
         },
         "asn" : "AS147019",
         "city" : "Dawan",
         "country" : "TW",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 400 Bad Request\r\nServer: WAF\r\nDate: Thu, 21 Nov 2024 08:50:28 GMT\r\nContent-Type: text/html\r\nContent-Length: 262\r\nConnection: close\r\n\r\n<html>\r\n<head><title>400 The plain HTTP request was sent to HTTPS port</title></head>\r\n<body bgcolor=\"white\">\r\n<center><h1>400 Bad Request</h1></center>\r\n<center>The plain HTTP request was sent to HTTPS port</center>\r\n<hr><center>WAF</center>\r\n</body>\r\n</html>\r\n",
         "datamd5" : "3b40fcd13ec4c48698cf15e0d2ba5977",
         "datammh3" : 401141661,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS147019",
            "continent" : "AS",
            "continentname" : "Asia",
            "country" : "TW",
            "countryname" : "Taiwan",
            "domain" : [
               "cloudinnovation.org"
            ],
            "isineu" : "false",
            "latitude" : "23.69781",
            "location" : "23.69781,120.960515",
            "longitude" : "120.960515",
            "netname" : "HK_Hilite_Limited",
            "organization" : "HK Hilite Limited",
            "subnet" : "45.194.56.0/21"
         },
         "ip" : "45.194.58.116",
         "ipv6" : "false",
         "latitude" : "23.2073",
         "location" : "23.2073,120.1906",
         "longitude" : "120.1906",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "jiii",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 20547,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Bad Request",
         "seen_date" : "2024-11-21",
         "source" : "datascan",
         "status" : 400,
         "subnet" : "45.194.56.0/21",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 213.176.106.196:20547 (tcp/http) - last seen on 2024-11-21 at 08:50:28 UTC

    • IP
      213.176.106.196
      Network
      213.176.96.0/20
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      URL

      http://213.176.106.196:20547/ 400

      HTTP Title
      400 The plain HTTP request was sent to HTTPS port
      ASN
      AS142578
      Organization
      E-Large HongKong
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      3b40fcd13ec4c48698cf15e0d2ba5977
      HTTP Header MD5
      7de09592d0cc3062011d73fa292680b0
      HTTP Body MD5
      77bd43987adf27926b335fbe22b67813
    • HTTP/1.1 400 Bad Request
      Server: WAF
      Date: Thu, 21 Nov 2024 08:50:28 GMT
      Content-Type: text/html
      Content-Length: 262
      Connection: close
      
      <html>
      <head><title>400 The plain HTTP request was sent to HTTPS port</title></head>
      <body bgcolor="white">
      <center><h1>400 Bad Request</h1></center>
      <center>The plain HTTP request was sent to HTTPS port</center>
      <hr><center>WAF</center>
      </body>
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-21T08:50:28.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "77bd43987adf27926b335fbe22b67813",
               "bodymmh3" : -2135056736,
               "headermd5" : "7de09592d0cc3062011d73fa292680b0",
               "headermmh3" : -384142797,
               "title" : "400 The plain HTTP request was sent to HTTPS port"
            },
            "length" : 405
         },
         "asn" : "AS142578",
         "country" : "HK",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 400 Bad Request\r\nServer: WAF\r\nDate: Thu, 21 Nov 2024 08:50:28 GMT\r\nContent-Type: text/html\r\nContent-Length: 262\r\nConnection: close\r\n\r\n<html>\r\n<head><title>400 The plain HTTP request was sent to HTTPS port</title></head>\r\n<body bgcolor=\"white\">\r\n<center><h1>400 Bad Request</h1></center>\r\n<center>The plain HTTP request was sent to HTTPS port</center>\r\n<hr><center>WAF</center>\r\n</body>\r\n</html>\r\n",
         "datamd5" : "3b40fcd13ec4c48698cf15e0d2ba5977",
         "datammh3" : 401141661,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS35372",
            "continent" : "AS",
            "continentname" : "Asia",
            "country" : "IR",
            "countryname" : "Iran",
            "domain" : [
               "irost.org"
            ],
            "isineu" : "false",
            "latitude" : "32.427908",
            "location" : "32.427908,53.688046",
            "longitude" : "53.688046",
            "netname" : "IR-IROST-19991208",
            "organization" : "Iranian Research Organization for Science & Technology",
            "subnet" : "213.176.0.0/17"
         },
         "ip" : "213.176.106.196",
         "ipv6" : "false",
         "latitude" : "22.2578",
         "location" : "22.2578,114.1657",
         "longitude" : "114.1657",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "E-Large HongKong",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 20547,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Bad Request",
         "seen_date" : "2024-11-21",
         "source" : "datascan",
         "status" : 400,
         "subnet" : "213.176.96.0/20",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 185.234.22.139:20547 (tcp/http) - last seen on 2024-11-21 at 08:50:06 UTC

    • IP
      185.234.22.139
      Network
      185.234.22.0/24
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      URL

      http://185.234.22.139:20547/ 400

      HTTP Title
      400 The plain HTTP request was sent to HTTPS port
      ASN
      AS209242
      Organization
      Cloudflare London, LLC
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      1c938094de8fd65eaed5c7a22536cb39
      HTTP Header MD5
      7de09592d0cc3062011d73fa292680b0
      HTTP Body MD5
      0c5aeb733c4cb0a76d75e0d5843130be
    • HTTP/1.1 400 Bad Request
      Server: WAF
      Date: Thu, 21 Nov 2024 08:50:05 GMT
      Content-Type: text/html
      Content-Length: 246
      Connection: close
      
      <html>
      <head><title>400 The plain HTTP request was sent to HTTPS port</title></head>
      <body>
      <center><h1>400 Bad Request</h1></center>
      <center>The plain HTTP request was sent to HTTPS port</center>
      <hr><center>WAF</center>
      </body>
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-21T08:50:06.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "0c5aeb733c4cb0a76d75e0d5843130be",
               "bodymmh3" : -1119213180,
               "headermd5" : "7de09592d0cc3062011d73fa292680b0",
               "headermmh3" : -1669042192,
               "title" : "400 The plain HTTP request was sent to HTTPS port"
            },
            "length" : 389
         },
         "asn" : "AS209242",
         "city" : "Frankfurt (Oder)",
         "country" : "DE",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 400 Bad Request\r\nServer: WAF\r\nDate: Thu, 21 Nov 2024 08:50:05 GMT\r\nContent-Type: text/html\r\nContent-Length: 246\r\nConnection: close\r\n\r\n<html>\r\n<head><title>400 The plain HTTP request was sent to HTTPS port</title></head>\r\n<body>\r\n<center><h1>400 Bad Request</h1></center>\r\n<center>The plain HTTP request was sent to HTTPS port</center>\r\n<hr><center>WAF</center>\r\n</body>\r\n</html>\r\n",
         "datamd5" : "1c938094de8fd65eaed5c7a22536cb39",
         "datammh3" : 588676251,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "ip" : "185.234.22.139",
         "ipv6" : "false",
         "latitude" : "52.3484",
         "location" : "52.3484,14.5546",
         "longitude" : "14.5546",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "Cloudflare London, LLC",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 20547,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Bad Request",
         "seen_date" : "2024-11-21",
         "source" : "datascan",
         "status" : 400,
         "subnet" : "185.234.22.0/24",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 45.204.17.113:20547 (tcp/http) - last seen on 2024-11-21 at 08:49:57 UTC

    • IP
      45.204.17.113
      Network
      45.204.16.0/23
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      URL

      http://45.204.17.113:20547/ 302

      HTTP Title
      302 Found
      ASN
      AS55720
      Organization
      Gigabit Hosting Sdn Bhd
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
      Product
      F5 Nginx
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      fec523b9aa4f35bf1e9de0046045ced3
      HTTP Header MD5
      d7becab03a8905d978f0985d2d16182f
      HTTP Body MD5
      29b5f7615598c74df0019844c163d80c
    • HTTP/1.1 302 Moved Temporarily
      Server: nginx
      Date: Thu, 21 Nov 2024 08:48:12 GMT
      Content-Type: text/html
      Content-Length: 138
      Connection: close
      Location: https://<ip>/
      Strict-Transport-Security: max-age=31536000
      
      <html>
      <head><title>302 Found</title></head>
      <body>
      <center><h1>302 Found</h1></center>
      <hr><center>nginx</center>
      </body>
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-21T08:49:57.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "29b5f7615598c74df0019844c163d80c",
               "bodymmh3" : -23674247,
               "headermd5" : "d7becab03a8905d978f0985d2d16182f",
               "headermmh3" : -254327692,
               "title" : "302 Found"
            },
            "length" : 359
         },
         "asn" : "AS55720",
         "country" : "US",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 302 Moved Temporarily\r\nServer: nginx\r\nDate: Thu, 21 Nov 2024 08:48:12 GMT\r\nContent-Type: text/html\r\nContent-Length: 138\r\nConnection: close\r\nLocation: https://<ip>/\r\nStrict-Transport-Security: max-age=31536000\r\n\r\n<html>\r\n<head><title>302 Found</title></head>\r\n<body>\r\n<center><h1>302 Found</h1></center>\r\n<hr><center>nginx</center>\r\n</body>\r\n</html>\r\n",
         "datamd5" : "fec523b9aa4f35bf1e9de0046045ced3",
         "datammh3" : 576449098,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS55720",
            "continent" : "AS",
            "continentname" : "Asia",
            "country" : "HK",
            "countryname" : "Hong Kong",
            "domain" : [
               "cloudinnovation.org"
            ],
            "isineu" : "false",
            "latitude" : "22.396428",
            "location" : "22.396428,114.109497",
            "longitude" : "114.109497",
            "netname" : "Data_Center_Network_Limited",
            "organization" : "Data Center Network Limited",
            "subnet" : "45.204.16.0/23"
         },
         "ip" : "45.204.17.113",
         "ipv6" : "false",
         "latitude" : "37.7510",
         "location" : "37.7510,-97.8220",
         "longitude" : "-97.8220",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "Gigabit Hosting Sdn Bhd",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 20547,
         "product" : "Nginx",
         "productvendor" : "F5",
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Moved Temporarily",
         "seen_date" : "2024-11-21",
         "source" : "datascan",
         "status" : 302,
         "subnet" : "45.204.16.0/23",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 185.24.11.34:20547 (tcp/http) - last seen on 2024-11-21 at 08:49:56 UTC

    • IP
      185.24.11.34
      Network
      185.24.8.0/22
      Domain(s)
      datapacket.com
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      URL

      http://185.24.11.34:20547/ 407

      Reverse DNS
      unn-185-24-11-34.datapacket.com
      ASN
      AS60068
      Organization
      Datacamp Limited
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      778cc01c214ef8c8f8a9fb0b6e167356
      HTTP Header MD5
      89ca6f53c2874945a0405d5d264770e9
      HTTP Body MD5
      89f6f645d68f5ab924dc181c664f38bc
    • HTTP/1.1 407 Proxy Authentication Required
      Proxy-Authenticate: Basic realm="Invalid proxy credentials or missing IP Authorization."
      Proxy-Connection: close
      Date: Thu, 21 Nov 2024 08:49:56 GMT
      Content-Length: 121
      Content-Type: text/plain; charset=utf-8
      Connection: close
      
      Not authenticated or invalid authentication credentials. Make sure to update your proxy address, proxy username and port.
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-21T08:49:56.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "89f6f645d68f5ab924dc181c664f38bc",
               "bodymmh3" : -1513989279,
               "headermd5" : "89ca6f53c2874945a0405d5d264770e9",
               "headermmh3" : 1116677895,
               "realm" : "Invalid proxy credentials or missing IP Authorization."
            },
            "length" : 400
         },
         "asn" : "AS60068",
         "city" : "Vienna",
         "country" : "AT",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 407 Proxy Authentication Required\r\nProxy-Authenticate: Basic realm=\"Invalid proxy credentials or missing IP Authorization.\"\r\nProxy-Connection: close\r\nDate: Thu, 21 Nov 2024 08:49:56 GMT\r\nContent-Length: 121\r\nContent-Type: text/plain; charset=utf-8\r\nConnection: close\r\n\r\nNot authenticated or invalid authentication credentials. Make sure to update your proxy address, proxy username and port.",
         "datamd5" : "778cc01c214ef8c8f8a9fb0b6e167356",
         "datammh3" : 9920105,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "datapacket.com"
         ],
         "host" : [
            "unn-185-24-11-34"
         ],
         "hostname" : [
            "unn-185-24-11-34.datapacket.com"
         ],
         "ip" : "185.24.11.34",
         "ipv6" : "false",
         "latitude" : "48.2049",
         "location" : "48.2049,16.3662",
         "longitude" : "16.3662",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "Datacamp Limited",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 20547,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Proxy Authentication Required",
         "reverse" : [
            "unn-185-24-11-34.datapacket.com"
         ],
         "seen_date" : "2024-11-21",
         "source" : "datascan",
         "status" : 407,
         "subnet" : "185.24.8.0/22",
         "tld" : [
            "com"
         ],
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }