Returning 10 result(s) out of 344,911 in 0.144 second(s)

  • 170.85.8.179:22222 (tcp/http) - last seen on 2024-11-07 at 05:51:37 UTC

    • IP
      170.85.8.179
      Network
      170.85.8.0/21
      Device

      <enterprise field>: device.class

      Operating System
      FreeBSD FreeBSD
      URL

      http://170.85.8.179:22222/ 307

      ASN
      AS22616
      Organization
      ZSCALER-SJC1
      Protocol
      http
      Source
      datascan
    • Operating System
      FreeBSD FreeBSD
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      91c42e83ef36fcf9b99ac154f8459623
      HTTP Header MD5
      f7b937b1b60e46e3ba60a8d8e663398d
      HTTP Body MD5
      d41d8cd98f00b204e9800998ecf8427e
    • HTTP/1.1 307 Temporary Redirect
      Content-Length: 0
      Access-Control-Allow-Origin: *
      Location: https://gateway.zscalertwo.net:443/auD?origurl=http%3A%2F%2F170%2e85%2e8%2e179%3a22222%2f&_ordtok=rZZ3WVFFS2V3Pv5QkPzsPZv0Qs
      Content-Type: text/html
      P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTR STP IND DEM"
      Set-Cookie: _sm_au_d=1;SameSite=LAX;path=/;domain=<ip>
      
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:51:37.000Z",
         "app" : {
            "extract" : {
               "domain" : [
                  "zscalertwo.net"
               ],
               "hostname" : [
                  "gateway.zscalertwo.net"
               ],
               "url" : [
                  "https://gateway.zscalertwo.net:443/auD?origurl=http%3A%2F%2F170%2e85%2e8%2e179%3a22222%2f&_ordtok=rZZ3WVFFS2V3Pv5QkPzsPZv0Qs"
               ]
            },
            "http" : {
               "bodymd5" : "d41d8cd98f00b204e9800998ecf8427e",
               "bodymmh3" : -1,
               "headermd5" : "f7b937b1b60e46e3ba60a8d8e663398d",
               "headermmh3" : -1935697967
            },
            "length" : 359
         },
         "asn" : "AS22616",
         "city" : "Chicago",
         "country" : "US",
         "data" : "HTTP/1.1 307 Temporary Redirect\r\nContent-Length: 0\r\nAccess-Control-Allow-Origin: *\r\nLocation: https://gateway.zscalertwo.net:443/auD?origurl=http%3A%2F%2F170%2e85%2e8%2e179%3a22222%2f&_ordtok=rZZ3WVFFS2V3Pv5QkPzsPZv0Qs\r\nContent-Type: text/html\r\nP3P: CP=\"NOI ADM DEV PSAi COM NAV OUR OTR STP IND DEM\"\r\nSet-Cookie: _sm_au_d=1;SameSite=LAX;path=/;domain=<ip>\r\n\r\n",
         "datamd5" : "91c42e83ef36fcf9b99ac154f8459623",
         "datammh3" : 769736127,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS22616",
            "continent" : "NA",
            "continentname" : "North America",
            "country" : "US",
            "countryname" : "United States",
            "domain" : [
               "zscaler.com"
            ],
            "isineu" : "false",
            "latitude" : "37.09024",
            "location" : "37.09024,-95.712891",
            "longitude" : "-95.712891",
            "netname" : "ZSCALER-CHI2",
            "organization" : "ZSCALER, INC.",
            "subnet" : "170.85.8.0/21"
         },
         "ip" : "170.85.8.179",
         "ipv6" : "false",
         "latitude" : "41.8874",
         "location" : "41.8874,-87.6318",
         "longitude" : "-87.6318",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "ZSCALER-SJC1",
         "os" : "FreeBSD",
         "osvendor" : "FreeBSD",
         "port" : 22222,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Temporary Redirect",
         "seen_date" : "2024-11-07",
         "source" : "datascan",
         "status" : 307,
         "subnet" : "170.85.8.0/21",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 138.197.1.122:22222 (tcp/http) - last seen on 2024-11-07 at 05:51:20 UTC

    • IP
      138.197.1.122
      Network
      138.197.0.0/20
      Domain(s)
      donyc.s1
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      URL

      http://138.197.1.122:22222/ 302

      HTTP Title
      302 Found
      Reverse DNS
      ac20316.gsn.donyc.s1
      ASN
      AS14061
      Organization
      DIGITALOCEAN-ASN
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
      Product
      F5 Nginx
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      ea85cfe24b92d04d9a6d1377770135bc
      HTTP Header MD5
      37e02e0514aa78a57a9c207a013625aa
      HTTP Body MD5
      29b5f7615598c74df0019844c163d80c
    • HTTP/1.1 302 Moved Temporarily
      Server: nginx
      Date: Thu, 07 Nov 2024 05:51:19 GMT
      Content-Type: text/html
      Content-Length: 138
      Connection: close
      Location: https://<ip>:22222/
      X-Powered-By: Agius.Cloud 1.2.0
      X-XSS-Protection: 1; mode=block
      X-Content-Type-Options: nosniff
      
      <html>
      <head><title>302 Found</title></head>
      <body>
      <center><h1>302 Found</h1></center>
      <hr><center>nginx</center>
      </body>
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:51:20.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "29b5f7615598c74df0019844c163d80c",
               "bodymmh3" : -23674247,
               "headermd5" : "37e02e0514aa78a57a9c207a013625aa",
               "headermmh3" : -510452066,
               "title" : "302 Found"
            },
            "length" : 419
         },
         "asn" : "AS14061",
         "city" : "Clifton",
         "country" : "US",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 302 Moved Temporarily\r\nServer: nginx\r\nDate: Thu, 07 Nov 2024 05:51:19 GMT\r\nContent-Type: text/html\r\nContent-Length: 138\r\nConnection: close\r\nLocation: https://<ip>:22222/\r\nX-Powered-By: Agius.Cloud 1.2.0\r\nX-XSS-Protection: 1; mode=block\r\nX-Content-Type-Options: nosniff\r\n\r\n<html>\r\n<head><title>302 Found</title></head>\r\n<body>\r\n<center><h1>302 Found</h1></center>\r\n<hr><center>nginx</center>\r\n</body>\r\n</html>\r\n",
         "datamd5" : "ea85cfe24b92d04d9a6d1377770135bc",
         "datammh3" : -191074903,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "donyc.s1"
         ],
         "geolocus" : {
            "asn" : "AS14061",
            "continent" : "NA",
            "continentname" : "North America",
            "country" : "US",
            "countryname" : "United States",
            "domain" : [
               "digitalocean.com"
            ],
            "isineu" : "false",
            "latitude" : "37.09024",
            "location" : "37.09024,-95.712891",
            "longitude" : "-95.712891",
            "netname" : "DIGITALOCEAN-138-197-0-0",
            "organization" : "DigitalOcean, LLC",
            "subnet" : "138.197.0.0/17"
         },
         "host" : [
            "ac20316"
         ],
         "hostname" : [
            "ac20316.gsn.donyc.s1"
         ],
         "ip" : "138.197.1.122",
         "ipv6" : "false",
         "latitude" : "40.8364",
         "location" : "40.8364,-74.1403",
         "longitude" : "-74.1403",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "DIGITALOCEAN-ASN",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 22222,
         "product" : "Nginx",
         "productvendor" : "F5",
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Moved Temporarily",
         "reverse" : [
            "ac20316.gsn.donyc.s1"
         ],
         "seen_date" : "2024-11-07",
         "source" : "datascan",
         "status" : 302,
         "subdomains" : [
            "gsn.donyc.s1"
         ],
         "subnet" : "138.197.0.0/20",
         "tag" : "<enterprise field>: tag",
         "tld" : [
            "s1"
         ],
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 165.225.234.188:22222 (tcp/http) - last seen on 2024-11-07 at 05:51:10 UTC

    • IP
      165.225.234.188
      Network
      165.225.232.0/22
      Device

      <enterprise field>: device.class

      Operating System
      FreeBSD FreeBSD
      URL

      http://165.225.234.188:22222/ 307

      ASN
      AS53813
      Organization
      ZSCALER-INC
      Protocol
      http
      Source
      datascan
    • Operating System
      FreeBSD FreeBSD
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      c97949417c63fcf7b6bc941e5d4ef0e5
      HTTP Header MD5
      f7b937b1b60e46e3ba60a8d8e663398d
      HTTP Body MD5
      d41d8cd98f00b204e9800998ecf8427e
    • HTTP/1.1 307 Temporary Redirect
      Content-Length: 0
      Access-Control-Allow-Origin: *
      Location: https://gateway.zscalertwo.net:443/auD?origurl=http%3A%2F%2F165%2e225%2e234%2e188%3a22222%2f&_ordtok=j343WV34J05NNDf6577g6Wfgmr
      Content-Type: text/html
      P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTR STP IND DEM"
      Set-Cookie: _sm_au_d=1;SameSite=LAX;path=/;domain=<ip>
      
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:51:10.000Z",
         "app" : {
            "extract" : {
               "domain" : [
                  "zscalertwo.net"
               ],
               "hostname" : [
                  "gateway.zscalertwo.net"
               ],
               "url" : [
                  "https://gateway.zscalertwo.net:443/auD?origurl=http%3A%2F%2F165%2e225%2e234%2e188%3a22222%2f&_ordtok=j343WV34J05NNDf6577g6Wfgmr"
               ]
            },
            "http" : {
               "bodymd5" : "d41d8cd98f00b204e9800998ecf8427e",
               "bodymmh3" : -1,
               "headermd5" : "f7b937b1b60e46e3ba60a8d8e663398d",
               "headermmh3" : 1936436465
            },
            "length" : 362
         },
         "asn" : "AS53813",
         "city" : "Hong Kong",
         "country" : "HK",
         "data" : "HTTP/1.1 307 Temporary Redirect\r\nContent-Length: 0\r\nAccess-Control-Allow-Origin: *\r\nLocation: https://gateway.zscalertwo.net:443/auD?origurl=http%3A%2F%2F165%2e225%2e234%2e188%3a22222%2f&_ordtok=j343WV34J05NNDf6577g6Wfgmr\r\nContent-Type: text/html\r\nP3P: CP=\"NOI ADM DEV PSAi COM NAV OUR OTR STP IND DEM\"\r\nSet-Cookie: _sm_au_d=1;SameSite=LAX;path=/;domain=<ip>\r\n\r\n",
         "datamd5" : "c97949417c63fcf7b6bc941e5d4ef0e5",
         "datammh3" : -1689277670,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS53813",
            "continent" : "NA",
            "continentname" : "North America",
            "country" : "US",
            "countryname" : "United States",
            "domain" : [
               "zscaler.com"
            ],
            "isineu" : "false",
            "latitude" : "37.09024",
            "location" : "37.09024,-95.712891",
            "longitude" : "-95.712891",
            "netname" : "ZSCALER-HKG3",
            "organization" : "ZSCALER, INC.",
            "subnet" : "165.225.234.0/23"
         },
         "ip" : "165.225.234.188",
         "ipv6" : "false",
         "latitude" : "22.2842",
         "location" : "22.2842,114.1759",
         "longitude" : "114.1759",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "ZSCALER-INC",
         "os" : "FreeBSD",
         "osvendor" : "FreeBSD",
         "port" : 22222,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Temporary Redirect",
         "seen_date" : "2024-11-07",
         "source" : "datascan",
         "status" : 307,
         "subnet" : "165.225.232.0/22",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 147.161.247.101:22222 (tcp/http) - last seen on 2024-11-07 at 05:51:05 UTC

    • IP
      147.161.247.101
      Network
      147.161.244.0/22
      Device

      <enterprise field>: device.class

      Operating System
      FreeBSD FreeBSD
      URL

      http://147.161.247.101:22222/ 307

      ASN
      AS62044
      Organization
      Zscaler Switzerland GmbH
      Protocol
      http
      Source
      datascan
    • Operating System
      FreeBSD FreeBSD
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      893393784f80cc7da396b1e95ab0056a
      HTTP Header MD5
      f7b937b1b60e46e3ba60a8d8e663398d
      HTTP Body MD5
      d41d8cd98f00b204e9800998ecf8427e
    • HTTP/1.1 307 Temporary Redirect
      Content-Length: 0
      Access-Control-Allow-Origin: *
      Location: https://gateway.zscloud.net:443/auD?origurl=http%3A%2F%2F147%2e161%2e247%2e101%3a22222%2f&_ordtok=5j43WVRmKbZjqM75MjQPM75njj
      Content-Type: text/html
      P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTR STP IND DEM"
      Set-Cookie: _sm_au_d=1;SameSite=LAX;path=/;domain=<ip>
      
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:51:05.000Z",
         "app" : {
            "extract" : {
               "domain" : [
                  "zscloud.net"
               ],
               "hostname" : [
                  "gateway.zscloud.net"
               ],
               "url" : [
                  "https://gateway.zscloud.net:443/auD?origurl=http%3A%2F%2F147%2e161%2e247%2e101%3a22222%2f&_ordtok=5j43WVRmKbZjqM75MjQPM75njj"
               ]
            },
            "http" : {
               "bodymd5" : "d41d8cd98f00b204e9800998ecf8427e",
               "bodymmh3" : -1,
               "headermd5" : "f7b937b1b60e46e3ba60a8d8e663398d",
               "headermmh3" : 556067493
            },
            "length" : 359
         },
         "asn" : "AS62044",
         "city" : "Zurich",
         "country" : "CH",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 307 Temporary Redirect\r\nContent-Length: 0\r\nAccess-Control-Allow-Origin: *\r\nLocation: https://gateway.zscloud.net:443/auD?origurl=http%3A%2F%2F147%2e161%2e247%2e101%3a22222%2f&_ordtok=5j43WVRmKbZjqM75MjQPM75njj\r\nContent-Type: text/html\r\nP3P: CP=\"NOI ADM DEV PSAi COM NAV OUR OTR STP IND DEM\"\r\nSet-Cookie: _sm_au_d=1;SameSite=LAX;path=/;domain=<ip>\r\n\r\n",
         "datamd5" : "893393784f80cc7da396b1e95ab0056a",
         "datammh3" : 1511874396,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "ip" : "147.161.247.101",
         "ipv6" : "false",
         "latitude" : "47.3682",
         "location" : "47.3682,8.5671",
         "longitude" : "8.5671",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "Zscaler Switzerland GmbH",
         "os" : "FreeBSD",
         "osvendor" : "FreeBSD",
         "port" : 22222,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Temporary Redirect",
         "seen_date" : "2024-11-07",
         "source" : "datascan",
         "status" : 307,
         "subnet" : "147.161.244.0/22",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 139.59.53.233:22222 (tcp/http) - last seen on 2024-11-07 at 05:50:55 UTC

    • IP
      139.59.53.233
      Network
      139.59.0.0/17
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      URL

      http://139.59.53.233:22222/ 302

      HTTP Title
      302 Found
      ASN
      AS14061
      Organization
      DIGITALOCEAN-ASN
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
      Product
      F5 Nginx
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      624742b3fe4c30dc67a60af898f22634
      HTTP Header MD5
      42ff86e56c8acd4909ab6ea28ea83171
      HTTP Body MD5
      29b5f7615598c74df0019844c163d80c
    • HTTP/1.1 302 Moved Temporarily
      Server: nginx
      Date: Thu, 07 Nov 2024 05:50:55 GMT
      Content-Type: text/html
      Content-Length: 138
      Connection: close
      Location: https://<ip>:22222/
      X-Powered-By: WordOps
      X-Frame-Options: SAMEORIGIN
      X-Xss-Protection: 1; mode=block
      X-Content-Type-Options: nosniff
      Referrer-Policy: no-referrer, strict-origin-when-cross-origin
      X-Download-Options: noopen
      
      <html>
      <head><title>302 Found</title></head>
      <body>
      <center><h1>302 Found</h1></center>
      <hr><center>nginx</center>
      </body>
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:50:55.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "29b5f7615598c74df0019844c163d80c",
               "bodymmh3" : -23674247,
               "headermd5" : "42ff86e56c8acd4909ab6ea28ea83171",
               "headermmh3" : 225712656,
               "title" : "302 Found"
            },
            "length" : 529
         },
         "asn" : "AS14061",
         "city" : "Bengaluru",
         "country" : "IN",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 302 Moved Temporarily\r\nServer: nginx\r\nDate: Thu, 07 Nov 2024 05:50:55 GMT\r\nContent-Type: text/html\r\nContent-Length: 138\r\nConnection: close\r\nLocation: https://<ip>:22222/\r\nX-Powered-By: WordOps\r\nX-Frame-Options: SAMEORIGIN\r\nX-Xss-Protection: 1; mode=block\r\nX-Content-Type-Options: nosniff\r\nReferrer-Policy: no-referrer, strict-origin-when-cross-origin\r\nX-Download-Options: noopen\r\n\r\n<html>\r\n<head><title>302 Found</title></head>\r\n<body>\r\n<center><h1>302 Found</h1></center>\r\n<hr><center>nginx</center>\r\n</body>\r\n</html>\r\n",
         "datamd5" : "624742b3fe4c30dc67a60af898f22634",
         "datammh3" : 1517594746,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS14061",
            "continent" : "AS",
            "continentname" : "Asia",
            "country" : "IN",
            "countryname" : "India",
            "domain" : [
               "digitalocean.com"
            ],
            "isineu" : "false",
            "latitude" : "20.593684",
            "location" : "20.593684,78.96288",
            "longitude" : "78.96288",
            "netname" : "DIGITALOCEAN-AP",
            "organization" : "DigitalOcean, LLC",
            "subnet" : "139.59.0.0/18"
         },
         "ip" : "139.59.53.233",
         "ipv6" : "false",
         "latitude" : "12.9634",
         "location" : "12.9634,77.5855",
         "longitude" : "77.5855",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "DIGITALOCEAN-ASN",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 22222,
         "product" : "Nginx",
         "productvendor" : "F5",
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Moved Temporarily",
         "seen_date" : "2024-11-07",
         "source" : "datascan",
         "status" : 302,
         "subnet" : "139.59.0.0/17",
         "tag" : "<enterprise field>: tag",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 45.194.63.105:22222 (tcp/http) - last seen on 2024-11-07 at 05:50:54 UTC

    • IP
      45.194.63.105
      Network
      45.194.56.0/21
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      URL

      http://45.194.63.105:22222/ 400

      HTTP Title
      400 The plain HTTP request was sent to HTTPS port
      ASN
      AS147019
      Organization
      jiii
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      3b40fcd13ec4c48698cf15e0d2ba5977
      HTTP Header MD5
      7de09592d0cc3062011d73fa292680b0
      HTTP Body MD5
      77bd43987adf27926b335fbe22b67813
    • HTTP/1.1 400 Bad Request
      Server: WAF
      Date: Thu, 07 Nov 2024 05:50:54 GMT
      Content-Type: text/html
      Content-Length: 262
      Connection: close
      
      <html>
      <head><title>400 The plain HTTP request was sent to HTTPS port</title></head>
      <body bgcolor="white">
      <center><h1>400 Bad Request</h1></center>
      <center>The plain HTTP request was sent to HTTPS port</center>
      <hr><center>WAF</center>
      </body>
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:50:54.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "77bd43987adf27926b335fbe22b67813",
               "bodymmh3" : -2135056736,
               "headermd5" : "7de09592d0cc3062011d73fa292680b0",
               "headermmh3" : -970629172,
               "title" : "400 The plain HTTP request was sent to HTTPS port"
            },
            "length" : 405
         },
         "asn" : "AS147019",
         "city" : "Dawan",
         "country" : "TW",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 400 Bad Request\r\nServer: WAF\r\nDate: Thu, 07 Nov 2024 05:50:54 GMT\r\nContent-Type: text/html\r\nContent-Length: 262\r\nConnection: close\r\n\r\n<html>\r\n<head><title>400 The plain HTTP request was sent to HTTPS port</title></head>\r\n<body bgcolor=\"white\">\r\n<center><h1>400 Bad Request</h1></center>\r\n<center>The plain HTTP request was sent to HTTPS port</center>\r\n<hr><center>WAF</center>\r\n</body>\r\n</html>\r\n",
         "datamd5" : "3b40fcd13ec4c48698cf15e0d2ba5977",
         "datammh3" : 401141661,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS147019",
            "continent" : "AS",
            "continentname" : "Asia",
            "country" : "TW",
            "countryname" : "Taiwan",
            "domain" : [
               "cloudinnovation.org"
            ],
            "isineu" : "false",
            "latitude" : "23.69781",
            "location" : "23.69781,120.960515",
            "longitude" : "120.960515",
            "netname" : "HK_Hilite_Limited",
            "organization" : "HK Hilite Limited",
            "subnet" : "45.194.56.0/21"
         },
         "ip" : "45.194.63.105",
         "ipv6" : "false",
         "latitude" : "23.2073",
         "location" : "23.2073,120.1906",
         "longitude" : "120.1906",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "jiii",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 22222,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Bad Request",
         "seen_date" : "2024-11-07",
         "source" : "datascan",
         "status" : 400,
         "subnet" : "45.194.56.0/21",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 38.47.144.162:22222 (tcp/http) - last seen on 2024-11-07 at 05:50:54 UTC

    • IP
      38.47.144.162
      Network
      38.47.128.0/19
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      URL

      http://38.47.144.162:22222/ 400

      HTTP Title
      400 The plain HTTP request was sent to HTTPS port
      ASN
      AS147019
      Organization
      jiii
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      3b40fcd13ec4c48698cf15e0d2ba5977
      HTTP Header MD5
      7de09592d0cc3062011d73fa292680b0
      HTTP Body MD5
      77bd43987adf27926b335fbe22b67813
    • HTTP/1.1 400 Bad Request
      Server: WAF
      Date: Thu, 07 Nov 2024 05:50:54 GMT
      Content-Type: text/html
      Content-Length: 262
      Connection: close
      
      <html>
      <head><title>400 The plain HTTP request was sent to HTTPS port</title></head>
      <body bgcolor="white">
      <center><h1>400 Bad Request</h1></center>
      <center>The plain HTTP request was sent to HTTPS port</center>
      <hr><center>WAF</center>
      </body>
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:50:54.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "77bd43987adf27926b335fbe22b67813",
               "bodymmh3" : -2135056736,
               "headermd5" : "7de09592d0cc3062011d73fa292680b0",
               "headermmh3" : -970629172,
               "title" : "400 The plain HTTP request was sent to HTTPS port"
            },
            "length" : 405
         },
         "asn" : "AS147019",
         "country" : "US",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 400 Bad Request\r\nServer: WAF\r\nDate: Thu, 07 Nov 2024 05:50:54 GMT\r\nContent-Type: text/html\r\nContent-Length: 262\r\nConnection: close\r\n\r\n<html>\r\n<head><title>400 The plain HTTP request was sent to HTTPS port</title></head>\r\n<body bgcolor=\"white\">\r\n<center><h1>400 Bad Request</h1></center>\r\n<center>The plain HTTP request was sent to HTTPS port</center>\r\n<hr><center>WAF</center>\r\n</body>\r\n</html>\r\n",
         "datamd5" : "3b40fcd13ec4c48698cf15e0d2ba5977",
         "datammh3" : 401141661,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS147019",
            "continent" : "NA",
            "continentname" : "North America",
            "country" : "US",
            "countryname" : "United States",
            "domain" : [
               "cogentco.com"
            ],
            "isineu" : "false",
            "latitude" : "37.09024",
            "location" : "37.09024,-95.712891",
            "longitude" : "-95.712891",
            "netname" : "COGENT-A",
            "organization" : "PSINet, Inc.",
            "subnet" : "38.47.128.0/19"
         },
         "ip" : "38.47.144.162",
         "ipv6" : "false",
         "latitude" : "37.7510",
         "location" : "37.7510,-97.8220",
         "longitude" : "-97.8220",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "jiii",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 22222,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Bad Request",
         "seen_date" : "2024-11-07",
         "source" : "datascan",
         "status" : 400,
         "subnet" : "38.47.128.0/19",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 167.172.132.120:22222 (tcp/http) - last seen on 2024-11-07 at 05:50:53 UTC

    • IP
      167.172.132.120
      Network
      167.172.128.0/17
      Domain(s)
      ac16859.clmselect2022
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      URL

      http://167.172.132.120:22222/ 302

      HTTP Title
      302 Found
      Reverse DNS
      ac16859.clmselect2022
      ASN
      AS14061
      Organization
      DIGITALOCEAN-ASN
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
      Product
      F5 Nginx
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      ea85cfe24b92d04d9a6d1377770135bc
      HTTP Header MD5
      37e02e0514aa78a57a9c207a013625aa
      HTTP Body MD5
      29b5f7615598c74df0019844c163d80c
    • HTTP/1.1 302 Moved Temporarily
      Server: nginx
      Date: Thu, 07 Nov 2024 05:50:53 GMT
      Content-Type: text/html
      Content-Length: 138
      Connection: close
      Location: https://<ip>:22222/
      X-Powered-By: Agius.Cloud 1.2.0
      X-XSS-Protection: 1; mode=block
      X-Content-Type-Options: nosniff
      
      <html>
      <head><title>302 Found</title></head>
      <body>
      <center><h1>302 Found</h1></center>
      <hr><center>nginx</center>
      </body>
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:50:53.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "29b5f7615598c74df0019844c163d80c",
               "bodymmh3" : -23674247,
               "headermd5" : "37e02e0514aa78a57a9c207a013625aa",
               "headermmh3" : 904759406,
               "title" : "302 Found"
            },
            "length" : 419
         },
         "asn" : "AS14061",
         "city" : "North Bergen",
         "country" : "US",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 302 Moved Temporarily\r\nServer: nginx\r\nDate: Thu, 07 Nov 2024 05:50:53 GMT\r\nContent-Type: text/html\r\nContent-Length: 138\r\nConnection: close\r\nLocation: https://<ip>:22222/\r\nX-Powered-By: Agius.Cloud 1.2.0\r\nX-XSS-Protection: 1; mode=block\r\nX-Content-Type-Options: nosniff\r\n\r\n<html>\r\n<head><title>302 Found</title></head>\r\n<body>\r\n<center><h1>302 Found</h1></center>\r\n<hr><center>nginx</center>\r\n</body>\r\n</html>\r\n",
         "datamd5" : "ea85cfe24b92d04d9a6d1377770135bc",
         "datammh3" : -191074903,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "ac16859.clmselect2022"
         ],
         "geolocus" : {
            "asn" : "AS14061",
            "continent" : "NA",
            "continentname" : "North America",
            "country" : "US",
            "countryname" : "United States",
            "domain" : [
               "digitalocean.com"
            ],
            "isineu" : "false",
            "latitude" : "37.09024",
            "location" : "37.09024,-95.712891",
            "longitude" : "-95.712891",
            "netname" : "DigitalOcean",
            "organization" : "DigitalOcean, LLC",
            "subnet" : "167.172.0.0/16"
         },
         "hostname" : [
            "ac16859.clmselect2022"
         ],
         "ip" : "167.172.132.120",
         "ipv6" : "false",
         "latitude" : "40.7924",
         "location" : "40.7924,-74.0096",
         "longitude" : "-74.0096",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "DIGITALOCEAN-ASN",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 22222,
         "product" : "Nginx",
         "productvendor" : "F5",
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Moved Temporarily",
         "reverse" : [
            "ac16859.clmselect2022"
         ],
         "seen_date" : "2024-11-07",
         "source" : "datascan",
         "status" : 302,
         "subnet" : "167.172.128.0/17",
         "tag" : "<enterprise field>: tag",
         "tld" : [
            "clmselect2022"
         ],
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 213.176.102.228:22222 (tcp/http) - last seen on 2024-11-07 at 05:50:53 UTC

    • IP
      213.176.102.228
      Network
      213.176.96.0/20
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      URL

      http://213.176.102.228:22222/ 400

      HTTP Title
      400 The plain HTTP request was sent to HTTPS port
      ASN
      AS142578
      Organization
      E-Large HongKong
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      3b40fcd13ec4c48698cf15e0d2ba5977
      HTTP Header MD5
      7de09592d0cc3062011d73fa292680b0
      HTTP Body MD5
      77bd43987adf27926b335fbe22b67813
    • HTTP/1.1 400 Bad Request
      Server: WAF
      Date: Thu, 07 Nov 2024 05:50:53 GMT
      Content-Type: text/html
      Content-Length: 262
      Connection: close
      
      <html>
      <head><title>400 The plain HTTP request was sent to HTTPS port</title></head>
      <body bgcolor="white">
      <center><h1>400 Bad Request</h1></center>
      <center>The plain HTTP request was sent to HTTPS port</center>
      <hr><center>WAF</center>
      </body>
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:50:53.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "77bd43987adf27926b335fbe22b67813",
               "bodymmh3" : -2135056736,
               "headermd5" : "7de09592d0cc3062011d73fa292680b0",
               "headermmh3" : 1358065514,
               "title" : "400 The plain HTTP request was sent to HTTPS port"
            },
            "length" : 405
         },
         "asn" : "AS142578",
         "country" : "HK",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 400 Bad Request\r\nServer: WAF\r\nDate: Thu, 07 Nov 2024 05:50:53 GMT\r\nContent-Type: text/html\r\nContent-Length: 262\r\nConnection: close\r\n\r\n<html>\r\n<head><title>400 The plain HTTP request was sent to HTTPS port</title></head>\r\n<body bgcolor=\"white\">\r\n<center><h1>400 Bad Request</h1></center>\r\n<center>The plain HTTP request was sent to HTTPS port</center>\r\n<hr><center>WAF</center>\r\n</body>\r\n</html>\r\n",
         "datamd5" : "3b40fcd13ec4c48698cf15e0d2ba5977",
         "datammh3" : 401141661,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS142578",
            "continent" : "AS",
            "continentname" : "Asia",
            "country" : "IR",
            "countryname" : "Iran",
            "domain" : [
               "gmail.com"
            ],
            "isineu" : "false",
            "latitude" : "32.427908",
            "location" : "32.427908,53.688046",
            "longitude" : "53.688046",
            "netname" : "us-sammu-1",
            "organization" : "us-sammu-1",
            "subnet" : "213.176.96.0/20"
         },
         "ip" : "213.176.102.228",
         "ipv6" : "false",
         "latitude" : "22.2578",
         "location" : "22.2578,114.1657",
         "longitude" : "114.1657",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "E-Large HongKong",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 22222,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Bad Request",
         "seen_date" : "2024-11-07",
         "source" : "datascan",
         "status" : 400,
         "subnet" : "213.176.96.0/20",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 213.176.102.168:22222 (tcp/http) - last seen on 2024-11-07 at 05:50:53 UTC

    • IP
      213.176.102.168
      Network
      213.176.96.0/20
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      URL

      http://213.176.102.168:22222/ 400

      HTTP Title
      400 The plain HTTP request was sent to HTTPS port
      ASN
      AS142578
      Organization
      E-Large HongKong
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      3b40fcd13ec4c48698cf15e0d2ba5977
      HTTP Header MD5
      7de09592d0cc3062011d73fa292680b0
      HTTP Body MD5
      77bd43987adf27926b335fbe22b67813
    • HTTP/1.1 400 Bad Request
      Server: WAF
      Date: Thu, 07 Nov 2024 05:50:53 GMT
      Content-Type: text/html
      Content-Length: 262
      Connection: close
      
      <html>
      <head><title>400 The plain HTTP request was sent to HTTPS port</title></head>
      <body bgcolor="white">
      <center><h1>400 Bad Request</h1></center>
      <center>The plain HTTP request was sent to HTTPS port</center>
      <hr><center>WAF</center>
      </body>
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:50:53.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "77bd43987adf27926b335fbe22b67813",
               "bodymmh3" : -2135056736,
               "headermd5" : "7de09592d0cc3062011d73fa292680b0",
               "headermmh3" : 1358065514,
               "title" : "400 The plain HTTP request was sent to HTTPS port"
            },
            "length" : 405
         },
         "asn" : "AS142578",
         "country" : "HK",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 400 Bad Request\r\nServer: WAF\r\nDate: Thu, 07 Nov 2024 05:50:53 GMT\r\nContent-Type: text/html\r\nContent-Length: 262\r\nConnection: close\r\n\r\n<html>\r\n<head><title>400 The plain HTTP request was sent to HTTPS port</title></head>\r\n<body bgcolor=\"white\">\r\n<center><h1>400 Bad Request</h1></center>\r\n<center>The plain HTTP request was sent to HTTPS port</center>\r\n<hr><center>WAF</center>\r\n</body>\r\n</html>\r\n",
         "datamd5" : "3b40fcd13ec4c48698cf15e0d2ba5977",
         "datammh3" : 401141661,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS142578",
            "continent" : "AS",
            "continentname" : "Asia",
            "country" : "IR",
            "countryname" : "Iran",
            "domain" : [
               "gmail.com"
            ],
            "isineu" : "false",
            "latitude" : "32.427908",
            "location" : "32.427908,53.688046",
            "longitude" : "53.688046",
            "netname" : "us-sammu-1",
            "organization" : "us-sammu-1",
            "subnet" : "213.176.96.0/20"
         },
         "ip" : "213.176.102.168",
         "ipv6" : "false",
         "latitude" : "22.2578",
         "location" : "22.2578,114.1657",
         "longitude" : "114.1657",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "E-Large HongKong",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 22222,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Bad Request",
         "seen_date" : "2024-11-07",
         "source" : "datascan",
         "status" : 400,
         "subnet" : "213.176.96.0/20",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }