>INFO:OpenVPN Management Interface Version 1 -- type 'help' for more info\x0d
ERROR: unknown command, enter 'help' for more options\x0d
ERROR: unknown command, enter 'help' for more options\x0d
ERROR: unknown command, enter 'help' for more options\x0d
ERROR: unknown command, enter 'help' for more options\x0d
ERROR: unknown command, enter 'help' for more options\x0d
ERROR: unknown command, enter 'help' for more options\x0d
>CLIENT:ESTABLISHED,3413\x0d
>CLIENT:ENV,n_clients=252\x0d
>CLIENT:ENV,time_unix=1730957615\x0d
>CLIENT:ENV,time_ascii=Thu Nov 7 12:33:35 2024\x0d
>CLIENT:ENV,ifconfig_pool_netmask=255.255.252.0\x0d
>CLIENT:ENV,ifconfig_pool_remote_ip=10.8.0.18\x0d
>CLIENT:ENV,trusted_port=51124\x0d
>CLIENT:ENV,trusted_ip=127.0.0.1\x0d
>CLIENT:ENV,common_name=username\x0d
>CLIENT:ENV,auth_control_file=/tmp/openvpn_acf_1b128d310cf976f630a6cea4a5c12934.tmp\x0d
>CLIENT:ENV,untrusted_port=51124\x0d
>CLIENT:ENV,untrusted_ip=127.0.0.1\x0d
>CLIENT:ENV,username=username\x0d
>CLIENT:ENV,IV_COMP_STUBv2=1\x0d
>CLIENT:ENV,IV_COMP_STUB=1\x0d
>CLIENT:ENV,IV_LZO_STUB=1\x0d
>CLIENT:ENV,IV_PROTO=2\x0d
>CLIENT:ENV,IV_TCPNL=1\x0d
>CLIENT:ENV,IV_NCP=2\x0d
>CLIENT:ENV,IV_PLAT=android\x0d
>CLIENT:ENV,IV_VER=3.1.2\x0d
>CLIENT:ENV,IV_GUI_VER=net.openvpn.connect.android_1.2.6-28\x0d
>CLIENT:ENV,tls_serial_hex_0=03\x0d
>CLIENT:ENV,tls_serial_0=3\x0d
>CLIENT:ENV,tls_digest_sha256_0=3c:2a:98:40:40:91:4e:69:c6:ac:60:f7:b1:78:45:d8:5f:e3:2c:7f:5b:5a:16:f4:dc:54:8b:01:4f:42:00:b8\x0d
>CLIENT:ENV,tls_digest_0=53:d3:ec:c5:23:64:ab:16:24:24:31:df:81:03:58:60:0e:ea:92:9d\x0d
>CLIENT:ENV,tls_id_0=CN=OpenVPN-Client\x0d
>CLIENT:ENV,X509_0_CN=OpenVPN-Client\x0d
>CLIENT:ENV,tls_serial_hex_1=ab:4d:91:7a:2e:64:8f:18\x0d
>CLIENT:ENV,tls_serial_1=12343682107642777368\x0d
>CLIENT:ENV,tls_digest_sha256_1=da:0a:e9:a8:b5:da:78:2f:8b:7b:24:29:d5:97:fc:7a:cf:87:d0:af:db:9b:61:bc:78:06:03:ee:17:55:26:51\x0d
>CLIENT:ENV,tls_digest_1=ac:90:e4:bc:fe:e1:97:0a:c0:3d:79:67:6b:0e:c6:37:31:94:ec:34\x0d
>CLIENT:ENV,tls_id_1=CN=Smile-vpn.net\x0d
>CLIENT:ENV,X509_1_CN=Smile-vpn.net\x0d
>CLIENT:ENV,remote_port_1=443\x0d
>CLIENT:ENV,local_port_1=443\x0d
>CLIENT:ENV,proto_1=tcp-server\x0d
>CLIENT:ENV,daemon_pid=599\x0d
>CLIENT:ENV,daemon_start_time=1730925069\x0d
>CLIENT:ENV,daemon_log_redirect=0\x0d
>CLIENT:ENV,daemon=1\x0d
>CLIENT:ENV,verb=3\x0d
>CLIENT:ENV,config=/etc/openvpn/server.conf\x0d
>CLIENT:ENV,ifconfig_local=10.8.0.1\x0d
>CLIENT:ENV,ifconfig_netmask=255.255.252.0\x0d
>CLIENT:ENV,ifconfig_broadcast=10.8.3.255\x0d
>CLIENT:ENV,script_context=init\x0d
>CLIENT:ENV,tun_mtu=1500\x0d
>CLIENT:ENV,link_mtu=1624\x0d
>CLIENT:ENV,dev=tun0\x0d
>CLIENT:ENV,dev_type=tun\x0d
>CLIENT:ENV,redirect_gateway=0\x0d
>CLIENT:ENV,END\x0d
{
"@category" : "datascan",
"@timestamp" : "2024-11-07T05:33:46.000Z",
"app" : {
"extract" : {
"ip" : [
"10.8.0.18",
"10.8.3.255",
"10.8.0.1",
"127.0.0.1",
"255.255.252.0"
]
},
"length" : 2532
},
"asn" : "AS141995",
"city" : "Singapore",
"country" : "SG",
"cpe" : "<enterprise field>: cpe",
"cpecount" : "<enterprise field>: cpecount",
"data" : ">INFO:OpenVPN Management Interface Version 1 -- type 'help' for more info\\x0d\nERROR: unknown command, enter 'help' for more options\\x0d\nERROR: unknown command, enter 'help' for more options\\x0d\nERROR: unknown command, enter 'help' for more options\\x0d\nERROR: unknown command, enter 'help' for more options\\x0d\nERROR: unknown command, enter 'help' for more options\\x0d\nERROR: unknown command, enter 'help' for more options\\x0d\n>CLIENT:ESTABLISHED,3413\\x0d\n>CLIENT:ENV,n_clients=252\\x0d\n>CLIENT:ENV,time_unix=1730957615\\x0d\n>CLIENT:ENV,time_ascii=Thu Nov 7 12:33:35 2024\\x0d\n>CLIENT:ENV,ifconfig_pool_netmask=255.255.252.0\\x0d\n>CLIENT:ENV,ifconfig_pool_remote_ip=10.8.0.18\\x0d\n>CLIENT:ENV,trusted_port=51124\\x0d\n>CLIENT:ENV,trusted_ip=127.0.0.1\\x0d\n>CLIENT:ENV,common_name=username\\x0d\n>CLIENT:ENV,auth_control_file=/tmp/openvpn_acf_1b128d310cf976f630a6cea4a5c12934.tmp\\x0d\n>CLIENT:ENV,untrusted_port=51124\\x0d\n>CLIENT:ENV,untrusted_ip=127.0.0.1\\x0d\n>CLIENT:ENV,username=username\\x0d\n>CLIENT:ENV,IV_COMP_STUBv2=1\\x0d\n>CLIENT:ENV,IV_COMP_STUB=1\\x0d\n>CLIENT:ENV,IV_LZO_STUB=1\\x0d\n>CLIENT:ENV,IV_PROTO=2\\x0d\n>CLIENT:ENV,IV_TCPNL=1\\x0d\n>CLIENT:ENV,IV_NCP=2\\x0d\n>CLIENT:ENV,IV_PLAT=android\\x0d\n>CLIENT:ENV,IV_VER=3.1.2\\x0d\n>CLIENT:ENV,IV_GUI_VER=net.openvpn.connect.android_1.2.6-28\\x0d\n>CLIENT:ENV,tls_serial_hex_0=03\\x0d\n>CLIENT:ENV,tls_serial_0=3\\x0d\n>CLIENT:ENV,tls_digest_sha256_0=3c:2a:98:40:40:91:4e:69:c6:ac:60:f7:b1:78:45:d8:5f:e3:2c:7f:5b:5a:16:f4:dc:54:8b:01:4f:42:00:b8\\x0d\n>CLIENT:ENV,tls_digest_0=53:d3:ec:c5:23:64:ab:16:24:24:31:df:81:03:58:60:0e:ea:92:9d\\x0d\n>CLIENT:ENV,tls_id_0=CN=OpenVPN-Client\\x0d\n>CLIENT:ENV,X509_0_CN=OpenVPN-Client\\x0d\n>CLIENT:ENV,tls_serial_hex_1=ab:4d:91:7a:2e:64:8f:18\\x0d\n>CLIENT:ENV,tls_serial_1=12343682107642777368\\x0d\n>CLIENT:ENV,tls_digest_sha256_1=da:0a:e9:a8:b5:da:78:2f:8b:7b:24:29:d5:97:fc:7a:cf:87:d0:af:db:9b:61:bc:78:06:03:ee:17:55:26:51\\x0d\n>CLIENT:ENV,tls_digest_1=ac:90:e4:bc:fe:e1:97:0a:c0:3d:79:67:6b:0e:c6:37:31:94:ec:34\\x0d\n>CLIENT:ENV,tls_id_1=CN=Smile-vpn.net\\x0d\n>CLIENT:ENV,X509_1_CN=Smile-vpn.net\\x0d\n>CLIENT:ENV,remote_port_1=443\\x0d\n>CLIENT:ENV,local_port_1=443\\x0d\n>CLIENT:ENV,proto_1=tcp-server\\x0d\n>CLIENT:ENV,daemon_pid=599\\x0d\n>CLIENT:ENV,daemon_start_time=1730925069\\x0d\n>CLIENT:ENV,daemon_log_redirect=0\\x0d\n>CLIENT:ENV,daemon=1\\x0d\n>CLIENT:ENV,verb=3\\x0d\n>CLIENT:ENV,config=/etc/openvpn/server.conf\\x0d\n>CLIENT:ENV,ifconfig_local=10.8.0.1\\x0d\n>CLIENT:ENV,ifconfig_netmask=255.255.252.0\\x0d\n>CLIENT:ENV,ifconfig_broadcast=10.8.3.255\\x0d\n>CLIENT:ENV,script_context=init\\x0d\n>CLIENT:ENV,tun_mtu=1500\\x0d\n>CLIENT:ENV,link_mtu=1624\\x0d\n>CLIENT:ENV,dev=tun0\\x0d\n>CLIENT:ENV,dev_type=tun\\x0d\n>CLIENT:ENV,redirect_gateway=0\\x0d\n>CLIENT:ENV,END\\x0d\n",
"datamd5" : "438135df5e6449ff19f2c9145dd71016",
"datammh3" : -1424862291,
"device" : {
"class" : "<enterprise field>: device.class"
},
"domain" : [
"contaboserver.net"
],
"geolocus" : {
"asn" : "AS141995",
"continent" : "AS",
"continentname" : "Asia",
"country" : "SG",
"countryname" : "Singapore",
"domain" : [
"contabo.de",
"contabo.net"
],
"isineu" : "false",
"latitude" : "1.352083",
"location" : "1.352083,103.819836",
"longitude" : "103.819836",
"netname" : "CONTABO-ASIA-20210409-04",
"organization" : "Contabo Asia Private Limited",
"subnet" : "194.233.76.0/22"
},
"host" : [
"vmi1400721"
],
"hostname" : [
"vmi1400721.contaboserver.net"
],
"ip" : "194.233.76.78",
"ipv6" : "false",
"latitude" : "1.3552",
"location" : "1.3552,103.8859",
"longitude" : "103.8859",
"node" : {
"country" : "<enterprise field>: node.country",
"groupid" : "<enterprise field>: node.groupid",
"id" : "<enterprise field>: node.id",
"physicalcountry" : "<enterprise field>: node.physicalcountry"
},
"organization" : "Contabo Asia Private Limited",
"os" : "Linux Kernel",
"osvendor" : "Linux",
"port" : 2222,
"protocol" : "unknown",
"reverse" : [
"vmi1400721.contaboserver.net"
],
"seen_date" : "2024-11-07",
"source" : "datascan",
"subnet" : "194.233.64.0/19",
"tld" : [
"net"
],
"tls" : "false",
"transport" : "tcp",
"url" : "/"
}