Returning 10 result(s) out of 58,999 in 0.056 second(s)

  • 110.67.240.32:4117 (tcp/ftp) - last seen on 2024-11-07 at 03:35:55 UTC

    • IP
      110.67.240.32
      Network
      110.66.0.0/15
      Domain(s)
      nuro.jp
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      Reverse DNS
      fp6e43f020.tkyc414.ap.nuro.jp
      ASN
      AS2527
      Organization
      Sony Network Communications Inc.
      Protocol
      ftp
      Source
      datascan
    • Operating System
      Linux Linux Kernel
      Product
      ProFTPD ProFTPD 1.3.5
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      8ed40849be95d72f43d4ade8dbee3513
    • 220 ProFTPD 1.3.5 Server (landisk-5d1324) [::ffff:192.168.11.23]
      500 GET not understood
      500 HOST: not understood
      500 CONNECTION: not understood
      500 USER-AGENT: not understood
      550 text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8: Forbidden command argument
      500 ACCEPT-LANGUAGE: not understood
      500 Invalid command: try being more creative
      331 Anonymous login ok, send your complete email address as your password
      230 Anonymous access granted, restrictions apply
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T03:35:55.000Z",
         "app" : {
            "ftp" : {
               "anonymous" : "true"
            },
            "length" : 483
         },
         "asn" : "AS2527",
         "city" : "Ushiku",
         "country" : "JP",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "220 ProFTPD 1.3.5 Server (landisk-5d1324) [::ffff:192.168.11.23]\r\n500 GET not understood\r\n500 HOST: not understood\r\n500 CONNECTION: not understood\r\n500 USER-AGENT: not understood\r\n550 text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8: Forbidden command argument\r\n500 ACCEPT-LANGUAGE: not understood\r\n500 Invalid command: try being more creative\r\n331 Anonymous login ok, send your complete email address as your password\n230 Anonymous access granted, restrictions apply\n",
         "datamd5" : "8ed40849be95d72f43d4ade8dbee3513",
         "datammh3" : 625993973,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "nuro.jp"
         ],
         "geolocus" : {
            "asn" : "AS2527",
            "continent" : "AS",
            "continentname" : "Asia",
            "country" : "JP",
            "countryname" : "Japan",
            "domain" : [
               "nic.ad.jp",
               "so-net.ne.jp"
            ],
            "isineu" : "false",
            "latitude" : "36.204824",
            "location" : "36.204824,138.252924",
            "longitude" : "138.252924",
            "netname" : "So-net",
            "organization" : "Sony Network Communications Inc.",
            "subnet" : "110.66.0.0/15"
         },
         "host" : [
            "fp6e43f020"
         ],
         "hostname" : [
            "fp6e43f020.tkyc414.ap.nuro.jp"
         ],
         "ip" : "110.67.240.32",
         "ipv6" : "false",
         "latitude" : "35.9968",
         "location" : "35.9968,140.1384",
         "longitude" : "140.1384",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "Sony Network Communications Inc.",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 4117,
         "product" : "ProFTPD",
         "productvendor" : "ProFTPD",
         "productversion" : "1.3.5",
         "protocol" : "ftp",
         "reverse" : [
            "fp6e43f020.tkyc414.ap.nuro.jp"
         ],
         "seen_date" : "2024-11-07",
         "source" : "datascan",
         "subdomains" : [
            "ap.nuro.jp",
            "tkyc414.ap.nuro.jp"
         ],
         "subnet" : "110.66.0.0/15",
         "tag" : "<enterprise field>: tag",
         "tld" : [
            "jp"
         ],
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 87.138.120.34:4117 (tcp/http) - last seen on 2024-11-07 at 03:35:50 UTC

    • IP
      87.138.120.34
      Network
      87.136.0.0/13
      Domain(s)
      t-ipconnect.de
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      URL

      http://87.138.120.34:4117/ 400

      HTTP Title
      400 The plain HTTP request was sent to HTTPS port
      Reverse DNS
      p578a7822.dip0.t-ipconnect.de
      ASN
      AS3320
      Organization
      Deutsche Telekom AG
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      3d80e9f3e3a9b62fb00891b6667e65a3
      HTTP Header MD5
      9fc3241261775979292948ded259e174
      HTTP Body MD5
      2daa306c05fdeb1709f1c39db5a000c8
    • HTTP/1.1 400 Bad Request
      Date: Thu, 07 Nov 2024 03:35:50 GMT
      Content-Type: text/html
      Content-Length: 236
      Connection: close
      X-XSS-Protection: 1; mode=block
      X-Content-Type-Options: nosniff
      Strict-Transport-Security: max-age=31536000
      Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; connect-src 'self'; font-src 'self'; object-src 'self'; media-src 'self'; child-src 'self'
      X-Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; connect-src 'self'; font-src 'self'; object-src 'self'; media-src 'self'; child-src 'self'
      X-Webkit-CSP: default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; connect-src 'self'; font-src 'self'; object-src 'self'; media-src 'self'; child-src 'self'
      
      <html>
      <head><title>400 The plain HTTP request was sent to HTTPS port</title></head>
      <body bgcolor="white">
      <center><h1>400 Bad Request</h1></center>
      <center>The plain HTTP request was sent to HTTPS port</center>
      </body>
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T03:35:50.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "2daa306c05fdeb1709f1c39db5a000c8",
               "bodymmh3" : -1586337783,
               "headermd5" : "9fc3241261775979292948ded259e174",
               "headermmh3" : 270651949,
               "title" : "400 The plain HTTP request was sent to HTTPS port"
            },
            "length" : 1194
         },
         "asn" : "AS3320",
         "city" : "Berlin",
         "country" : "DE",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 400 Bad Request\r\nDate: Thu, 07 Nov 2024 03:35:50 GMT\r\nContent-Type: text/html\r\nContent-Length: 236\r\nConnection: close\r\nX-XSS-Protection: 1; mode=block\r\nX-Content-Type-Options: nosniff\r\nStrict-Transport-Security: max-age=31536000\r\nContent-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; connect-src 'self'; font-src 'self'; object-src 'self'; media-src 'self'; child-src 'self'\r\nX-Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; connect-src 'self'; font-src 'self'; object-src 'self'; media-src 'self'; child-src 'self'\r\nX-Webkit-CSP: default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; connect-src 'self'; font-src 'self'; object-src 'self'; media-src 'self'; child-src 'self'\r\n\r\n<html>\r\n<head><title>400 The plain HTTP request was sent to HTTPS port</title></head>\r\n<body bgcolor=\"white\">\r\n<center><h1>400 Bad Request</h1></center>\r\n<center>The plain HTTP request was sent to HTTPS port</center>\r\n</body>\r\n</html>\r\n",
         "datamd5" : "3d80e9f3e3a9b62fb00891b6667e65a3",
         "datammh3" : -793051156,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "t-ipconnect.de"
         ],
         "host" : [
            "p578a7822"
         ],
         "hostname" : [
            "p578a7822.dip0.t-ipconnect.de"
         ],
         "ip" : "87.138.120.34",
         "ipv6" : "false",
         "latitude" : "52.4880",
         "location" : "52.4880,13.2413",
         "longitude" : "13.2413",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "Deutsche Telekom AG",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 4117,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Bad Request",
         "reverse" : [
            "p578a7822.dip0.t-ipconnect.de"
         ],
         "seen_date" : "2024-11-07",
         "source" : "datascan",
         "status" : 400,
         "subdomains" : [
            "dip0.t-ipconnect.de"
         ],
         "subnet" : "87.136.0.0/13",
         "tld" : [
            "de"
         ],
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 190.13.179.219:4117 (tcp/http) - last seen on 2024-11-07 at 03:35:48 UTC

    • IP
      190.13.179.219
      Network
      190.13.128.0/18
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      URL

      http://190.13.179.219:4117/ 400

      HTTP Title
      400 The plain HTTP request was sent to HTTPS port
      ASN
      AS14117
      Organization
      Telefonica del Sur S.A.
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      2e3015527e99ab4730fabffdb9797a89
      HTTP Header MD5
      470a9635da086f31b68019aaddc44c99
      HTTP Body MD5
      2daa306c05fdeb1709f1c39db5a000c8
    • HTTP/1.1 400 Bad Request
      Date: Thu, 07 Nov 2024 03:35:48 GMT
      Content-Type: text/html
      Content-Length: 236
      Connection: close
      
      <html>
      <head><title>400 The plain HTTP request was sent to HTTPS port</title></head>
      <body bgcolor="white">
      <center><h1>400 Bad Request</h1></center>
      <center>The plain HTTP request was sent to HTTPS port</center>
      </body>
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T03:35:48.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "2daa306c05fdeb1709f1c39db5a000c8",
               "bodymmh3" : -1586337783,
               "headermd5" : "470a9635da086f31b68019aaddc44c99",
               "headermmh3" : -1143220548,
               "title" : "400 The plain HTTP request was sent to HTTPS port"
            },
            "length" : 366
         },
         "asn" : "AS14117",
         "city" : "Concepci\u00f3n",
         "country" : "CL",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 400 Bad Request\r\nDate: Thu, 07 Nov 2024 03:35:48 GMT\r\nContent-Type: text/html\r\nContent-Length: 236\r\nConnection: close\r\n\r\n<html>\r\n<head><title>400 The plain HTTP request was sent to HTTPS port</title></head>\r\n<body bgcolor=\"white\">\r\n<center><h1>400 Bad Request</h1></center>\r\n<center>The plain HTTP request was sent to HTTPS port</center>\r\n</body>\r\n</html>\r\n",
         "datamd5" : "2e3015527e99ab4730fabffdb9797a89",
         "datammh3" : -248319603,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS14117",
            "continent" : "SA",
            "continentname" : "South America",
            "country" : "CL",
            "countryname" : "Chile",
            "domain" : [
               "grupogtd.com",
               "gtdinternet.com"
            ],
            "isineu" : "false",
            "latitude" : "-35.675147",
            "location" : "-35.675147,-71.542969",
            "longitude" : "-71.542969",
            "netname" : "CL-TSSA-LACNIC",
            "organization" : "Telefonica del Sur S.A.",
            "subnet" : "190.13.160.0/19"
         },
         "ip" : "190.13.179.219",
         "ipv6" : "false",
         "latitude" : "-36.8335",
         "location" : "-36.8335,-73.0487",
         "longitude" : "-73.0487",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "Telefonica del Sur S.A.",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 4117,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Bad Request",
         "seen_date" : "2024-11-07",
         "source" : "datascan",
         "status" : 400,
         "subnet" : "190.13.128.0/18",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 188.14.248.33:4117 (tcp/http) - last seen on 2024-11-07 at 03:35:45 UTC

    • IP
      188.14.248.33
      Network
      188.8.0.0/13
      Domain(s)
      telecomitalia.it
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      URL

      http://188.14.248.33:4117/ 400

      HTTP Title
      400 The plain HTTP request was sent to HTTPS port
      Reverse DNS
      host-188-14-248-33.business.telecomitalia.it
      ASN
      AS3269
      Organization
      TIM
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      2e3015527e99ab4730fabffdb9797a89
      HTTP Header MD5
      470a9635da086f31b68019aaddc44c99
      HTTP Body MD5
      2daa306c05fdeb1709f1c39db5a000c8
    • HTTP/1.1 400 Bad Request
      Date: Thu, 07 Nov 2024 03:35:45 GMT
      Content-Type: text/html
      Content-Length: 236
      Connection: close
      
      <html>
      <head><title>400 The plain HTTP request was sent to HTTPS port</title></head>
      <body bgcolor="white">
      <center><h1>400 Bad Request</h1></center>
      <center>The plain HTTP request was sent to HTTPS port</center>
      </body>
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T03:35:45.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "2daa306c05fdeb1709f1c39db5a000c8",
               "bodymmh3" : -1586337783,
               "headermd5" : "470a9635da086f31b68019aaddc44c99",
               "headermmh3" : -1672475312,
               "title" : "400 The plain HTTP request was sent to HTTPS port"
            },
            "length" : 366
         },
         "asn" : "AS3269",
         "city" : "Lancenigo-Villorba",
         "country" : "IT",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 400 Bad Request\r\nDate: Thu, 07 Nov 2024 03:35:45 GMT\r\nContent-Type: text/html\r\nContent-Length: 236\r\nConnection: close\r\n\r\n<html>\r\n<head><title>400 The plain HTTP request was sent to HTTPS port</title></head>\r\n<body bgcolor=\"white\">\r\n<center><h1>400 Bad Request</h1></center>\r\n<center>The plain HTTP request was sent to HTTPS port</center>\r\n</body>\r\n</html>\r\n",
         "datamd5" : "2e3015527e99ab4730fabffdb9797a89",
         "datammh3" : -248319603,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "telecomitalia.it"
         ],
         "geolocus" : {
            "asn" : "AS3269",
            "continent" : "EU",
            "continentname" : "Europe",
            "country" : "IT",
            "countryname" : "Italy",
            "domain" : [
               "telecomitalia.it"
            ],
            "isineu" : "true",
            "latitude" : "41.87194",
            "location" : "41.87194,12.56738",
            "longitude" : "12.56738",
            "netname" : "IT-TIIPTV-20090205",
            "organization" : "Telecom Italia S.p.A.",
            "subnet" : "188.14.0.0/16"
         },
         "host" : [
            "host-188-14-248-33"
         ],
         "hostname" : [
            "host-188-14-248-33.business.telecomitalia.it"
         ],
         "ip" : "188.14.248.33",
         "ipv6" : "false",
         "latitude" : "45.7103",
         "location" : "45.7103,12.2612",
         "longitude" : "12.2612",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "TIM",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 4117,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Bad Request",
         "reverse" : [
            "host-188-14-248-33.business.telecomitalia.it"
         ],
         "seen_date" : "2024-11-07",
         "source" : "datascan",
         "status" : 400,
         "subdomains" : [
            "business.telecomitalia.it"
         ],
         "subnet" : "188.8.0.0/13",
         "tag" : "<enterprise field>: tag",
         "tld" : [
            "it"
         ],
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 18.142.140.84:4117 (tcp/http) - last seen on 2024-11-07 at 03:35:27 UTC

    • IP
      18.142.140.84
      Network
      18.140.0.0/14
      Domain(s)
      amazonaws.com
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      URL

      http://18.142.140.84:4117/ 200

      Reverse DNS
      ec2-18-142-140-84.ap-southeast-1.compute.amazonaws.com
      ASN
      AS16509
      Organization
      AMAZON-02
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
      Product
      F5 Nginx
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      97f64c9c6bf158d0d05d3f05372b5a7a
      HTTP Header MD5
      9f060a9cb1b31c417a3a68e629ae97e3
      HTTP Body MD5
      c25cbaf569d22e9f526ff69fe9e61bbf
    • HTTP/1.1 200 OK
      Connection: close
      Date: Thu, 07 Nov 2024 03:35:27 GMT
      Server: nginx
      Content-Length: 583
      Content-Type: text/html
      
      <html style="background:#007cef">
      <head>
      <meta http-equiv="expires" content="0">
      <script type='text/javascript'>
      pr=(document.location.protocol == 'https:') ? 'https' : 'http';
      pt=(location.port == '') ? '' : ':' + location.port;
      redirect_suffix = "/redirect.html?count="+Math.random();
      if(location.hostname.indexOf(':') == -1)
      {
      location.href=pr+"://"+location.hostname+pt+redirect_suffix;
      }
      else    //could be ipv6 addr
      {
      var url = "";
      url=pr+"://["+ location.hostname.replace(/[\[\]]/g, '') +"]"+pt+redirect_suffix;
      location.href = url;
      }
      </script>
      </head>
      <body>
      </body>
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T03:35:27.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "c25cbaf569d22e9f526ff69fe9e61bbf",
               "bodymmh3" : 2073015905,
               "headermd5" : "9f060a9cb1b31c417a3a68e629ae97e3",
               "headermmh3" : -1949839345
            },
            "length" : 719
         },
         "asn" : "AS16509",
         "city" : "Singapore",
         "country" : "SG",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 200 OK\r\nConnection: close\r\nDate: Thu, 07 Nov 2024 03:35:27 GMT\r\nServer: nginx\r\nContent-Length: 583\r\nContent-Type: text/html\r\n\r\n<html style=\"background:#007cef\">\n<head>\n<meta http-equiv=\"expires\" content=\"0\">\n<script type='text/javascript'>\npr=(document.location.protocol == 'https:') ? 'https' : 'http';\npt=(location.port == '') ? '' : ':' + location.port;\nredirect_suffix = \"/redirect.html?count=\"+Math.random();\nif(location.hostname.indexOf(':') == -1)\n{\nlocation.href=pr+\"://\"+location.hostname+pt+redirect_suffix;\n}\nelse    //could be ipv6 addr\n{\nvar url = \"\";\nurl=pr+\"://[\"+ location.hostname.replace(/[\\[\\]]/g, '') +\"]\"+pt+redirect_suffix;\nlocation.href = url;\n}\n</script>\n</head>\n<body>\n</body>\n</html>\n",
         "datamd5" : "97f64c9c6bf158d0d05d3f05372b5a7a",
         "datammh3" : 1079192638,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "amazonaws.com"
         ],
         "geolocus" : {
            "asn" : "AS16509",
            "continent" : "AS",
            "continentname" : "Asia",
            "country" : "SG",
            "countryname" : "Singapore",
            "domain" : [
               "amazon.com",
               "amazonaws.com",
               "aws.com"
            ],
            "isineu" : "false",
            "latitude" : "1.352083",
            "location" : "1.352083,103.819836",
            "longitude" : "103.819836",
            "netname" : "AMAZON-SIN",
            "organization" : "Amazon Data Services Singapore",
            "subnet" : "18.142.0.0/15"
         },
         "host" : [
            "ec2-18-142-140-84"
         ],
         "hostname" : [
            "ec2-18-142-140-84.ap-southeast-1.compute.amazonaws.com"
         ],
         "ip" : "18.142.140.84",
         "ipv6" : "false",
         "latitude" : "1.2868",
         "location" : "1.2868,103.8503",
         "longitude" : "103.8503",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "AMAZON-02",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 4117,
         "product" : "Nginx",
         "productvendor" : "F5",
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "OK",
         "reverse" : [
            "ec2-18-142-140-84.ap-southeast-1.compute.amazonaws.com"
         ],
         "seen_date" : "2024-11-07",
         "source" : "datascan",
         "status" : 200,
         "subdomains" : [
            "ap-southeast-1.compute.amazonaws.com",
            "compute.amazonaws.com"
         ],
         "subnet" : "18.140.0.0/14",
         "tag" : "<enterprise field>: tag",
         "tld" : [
            "com"
         ],
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 190.7.201.171:4117 (tcp/http) - last seen on 2024-11-07 at 03:35:21 UTC

    • IP
      190.7.201.171
      Network
      190.7.192.0/19
      Domain(s)
      americandatanetworks.com
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      URL

      http://190.7.201.171:4117/ 400

      HTTP Title
      400 The plain HTTP request was sent to HTTPS port
      Reverse DNS
      171-201-7-190.americandatanetworks.com
      ASN
      AS27876
      Organization
      American Data Networks
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      3d80e9f3e3a9b62fb00891b6667e65a3
      HTTP Header MD5
      9fc3241261775979292948ded259e174
      HTTP Body MD5
      2daa306c05fdeb1709f1c39db5a000c8
    • HTTP/1.1 400 Bad Request
      Date: Thu, 07 Nov 2024 03:35:21 GMT
      Content-Type: text/html
      Content-Length: 236
      Connection: close
      X-XSS-Protection: 1; mode=block
      X-Content-Type-Options: nosniff
      Strict-Transport-Security: max-age=31536000
      Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; connect-src 'self'; font-src 'self'; object-src 'self'; media-src 'self'; child-src 'self'
      X-Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; connect-src 'self'; font-src 'self'; object-src 'self'; media-src 'self'; child-src 'self'
      X-Webkit-CSP: default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; connect-src 'self'; font-src 'self'; object-src 'self'; media-src 'self'; child-src 'self'
      
      <html>
      <head><title>400 The plain HTTP request was sent to HTTPS port</title></head>
      <body bgcolor="white">
      <center><h1>400 Bad Request</h1></center>
      <center>The plain HTTP request was sent to HTTPS port</center>
      </body>
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T03:35:21.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "2daa306c05fdeb1709f1c39db5a000c8",
               "bodymmh3" : -1586337783,
               "headermd5" : "9fc3241261775979292948ded259e174",
               "headermmh3" : 1471024340,
               "title" : "400 The plain HTTP request was sent to HTTPS port"
            },
            "length" : 1194
         },
         "asn" : "AS27876",
         "city" : "San Jos\u00e9",
         "country" : "CR",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 400 Bad Request\r\nDate: Thu, 07 Nov 2024 03:35:21 GMT\r\nContent-Type: text/html\r\nContent-Length: 236\r\nConnection: close\r\nX-XSS-Protection: 1; mode=block\r\nX-Content-Type-Options: nosniff\r\nStrict-Transport-Security: max-age=31536000\r\nContent-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; connect-src 'self'; font-src 'self'; object-src 'self'; media-src 'self'; child-src 'self'\r\nX-Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; connect-src 'self'; font-src 'self'; object-src 'self'; media-src 'self'; child-src 'self'\r\nX-Webkit-CSP: default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; connect-src 'self'; font-src 'self'; object-src 'self'; media-src 'self'; child-src 'self'\r\n\r\n<html>\r\n<head><title>400 The plain HTTP request was sent to HTTPS port</title></head>\r\n<body bgcolor=\"white\">\r\n<center><h1>400 Bad Request</h1></center>\r\n<center>The plain HTTP request was sent to HTTPS port</center>\r\n</body>\r\n</html>\r\n",
         "datamd5" : "3d80e9f3e3a9b62fb00891b6667e65a3",
         "datammh3" : -793051156,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "americandatanetworks.com"
         ],
         "geolocus" : {
            "asn" : "AS27876",
            "continent" : "NA",
            "continentname" : "North America",
            "country" : "CR",
            "countryname" : "Costa Rica",
            "domain" : [
               "americandatanetworks.com",
               "data.cr",
               "visionarygaming.com"
            ],
            "isineu" : "false",
            "latitude" : "9.748917",
            "location" : "9.748917,-83.753428",
            "longitude" : "-83.753428",
            "netname" : "CR-VIIG-LACNIC",
            "organization" : "VISIONARY IGAMMING",
            "subnet" : "190.7.200.0/21"
         },
         "host" : [
            "171-201-7-190"
         ],
         "hostname" : [
            "171-201-7-190.americandatanetworks.com"
         ],
         "ip" : "190.7.201.171",
         "ipv6" : "false",
         "latitude" : "9.9057",
         "location" : "9.9057,-84.0619",
         "longitude" : "-84.0619",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "American Data Networks",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 4117,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Bad Request",
         "reverse" : [
            "171-201-7-190.americandatanetworks.com"
         ],
         "seen_date" : "2024-11-07",
         "source" : "datascan",
         "status" : 400,
         "subnet" : "190.7.192.0/19",
         "tld" : [
            "com"
         ],
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 5.89.7.186:4117 (tcp/http) - last seen on 2024-11-07 at 03:35:06 UTC

    • IP
      5.89.7.186
      Network
      5.88.0.0/13
      Domain(s)
      vodafonedsl.it
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      URL

      http://5.89.7.186:4117/ 400

      HTTP Title
      400 The plain HTTP request was sent to HTTPS port
      Reverse DNS
      net-5-89-7-186.cust.vodafonedsl.it
      ASN
      AS30722
      Organization
      Vodafone Italia S.p.A.
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      3d80e9f3e3a9b62fb00891b6667e65a3
      HTTP Header MD5
      9fc3241261775979292948ded259e174
      HTTP Body MD5
      2daa306c05fdeb1709f1c39db5a000c8
    • HTTP/1.1 400 Bad Request
      Date: Thu, 07 Nov 2024 03:35:05 GMT
      Content-Type: text/html
      Content-Length: 236
      Connection: close
      X-XSS-Protection: 1; mode=block
      X-Content-Type-Options: nosniff
      Strict-Transport-Security: max-age=31536000
      Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; connect-src 'self'; font-src 'self'; object-src 'self'; media-src 'self'; child-src 'self'
      X-Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; connect-src 'self'; font-src 'self'; object-src 'self'; media-src 'self'; child-src 'self'
      X-Webkit-CSP: default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; connect-src 'self'; font-src 'self'; object-src 'self'; media-src 'self'; child-src 'self'
      
      <html>
      <head><title>400 The plain HTTP request was sent to HTTPS port</title></head>
      <body bgcolor="white">
      <center><h1>400 Bad Request</h1></center>
      <center>The plain HTTP request was sent to HTTPS port</center>
      </body>
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T03:35:06.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "2daa306c05fdeb1709f1c39db5a000c8",
               "bodymmh3" : -1586337783,
               "headermd5" : "9fc3241261775979292948ded259e174",
               "headermmh3" : -988651787,
               "title" : "400 The plain HTTP request was sent to HTTPS port"
            },
            "length" : 1194
         },
         "asn" : "AS30722",
         "city" : "Rome",
         "country" : "IT",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 400 Bad Request\r\nDate: Thu, 07 Nov 2024 03:35:05 GMT\r\nContent-Type: text/html\r\nContent-Length: 236\r\nConnection: close\r\nX-XSS-Protection: 1; mode=block\r\nX-Content-Type-Options: nosniff\r\nStrict-Transport-Security: max-age=31536000\r\nContent-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; connect-src 'self'; font-src 'self'; object-src 'self'; media-src 'self'; child-src 'self'\r\nX-Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; connect-src 'self'; font-src 'self'; object-src 'self'; media-src 'self'; child-src 'self'\r\nX-Webkit-CSP: default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; connect-src 'self'; font-src 'self'; object-src 'self'; media-src 'self'; child-src 'self'\r\n\r\n<html>\r\n<head><title>400 The plain HTTP request was sent to HTTPS port</title></head>\r\n<body bgcolor=\"white\">\r\n<center><h1>400 Bad Request</h1></center>\r\n<center>The plain HTTP request was sent to HTTPS port</center>\r\n</body>\r\n</html>\r\n",
         "datamd5" : "3d80e9f3e3a9b62fb00891b6667e65a3",
         "datammh3" : -793051156,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "vodafonedsl.it"
         ],
         "host" : [
            "net-5-89-7-186"
         ],
         "hostname" : [
            "net-5-89-7-186.cust.vodafonedsl.it"
         ],
         "ip" : "5.89.7.186",
         "ipv6" : "false",
         "latitude" : "41.8904",
         "location" : "41.8904,12.5126",
         "longitude" : "12.5126",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "Vodafone Italia S.p.A.",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 4117,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Bad Request",
         "reverse" : [
            "net-5-89-7-186.cust.vodafonedsl.it"
         ],
         "seen_date" : "2024-11-07",
         "source" : "datascan",
         "status" : 400,
         "subdomains" : [
            "cust.vodafonedsl.it"
         ],
         "subnet" : "5.88.0.0/13",
         "tld" : [
            "it"
         ],
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 115.241.86.166:4117 (tcp/http) - last seen on 2024-11-07 at 03:35:01 UTC

    • IP
      115.241.86.166
      Network
      115.240.0.0/13
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      URL

      http://115.241.86.166:4117/ 400

      HTTP Title
      400 The plain HTTP request was sent to HTTPS port
      ASN
      AS55836
      Organization
      Reliance Jio Infocomm Limited
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      2e3015527e99ab4730fabffdb9797a89
      HTTP Header MD5
      470a9635da086f31b68019aaddc44c99
      HTTP Body MD5
      2daa306c05fdeb1709f1c39db5a000c8
    • HTTP/1.1 400 Bad Request
      Date: Thu, 07 Nov 2024 03:35:01 GMT
      Content-Type: text/html
      Content-Length: 236
      Connection: close
      
      <html>
      <head><title>400 The plain HTTP request was sent to HTTPS port</title></head>
      <body bgcolor="white">
      <center><h1>400 Bad Request</h1></center>
      <center>The plain HTTP request was sent to HTTPS port</center>
      </body>
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T03:35:01.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "2daa306c05fdeb1709f1c39db5a000c8",
               "bodymmh3" : -1586337783,
               "headermd5" : "470a9635da086f31b68019aaddc44c99",
               "headermmh3" : -1545805586,
               "title" : "400 The plain HTTP request was sent to HTTPS port"
            },
            "length" : 366
         },
         "asn" : "AS55836",
         "city" : "Delhi",
         "country" : "IN",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 400 Bad Request\r\nDate: Thu, 07 Nov 2024 03:35:01 GMT\r\nContent-Type: text/html\r\nContent-Length: 236\r\nConnection: close\r\n\r\n<html>\r\n<head><title>400 The plain HTTP request was sent to HTTPS port</title></head>\r\n<body bgcolor=\"white\">\r\n<center><h1>400 Bad Request</h1></center>\r\n<center>The plain HTTP request was sent to HTTPS port</center>\r\n</body>\r\n</html>\r\n",
         "datamd5" : "2e3015527e99ab4730fabffdb9797a89",
         "datammh3" : -248319603,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS55836",
            "continent" : "AS",
            "continentname" : "Asia",
            "country" : "IN",
            "countryname" : "India",
            "domain" : [
               "ril.com"
            ],
            "isineu" : "false",
            "latitude" : "20.593684",
            "location" : "20.593684,78.96288",
            "longitude" : "78.96288",
            "netname" : "RELIANCEJIO-IN",
            "organization" : "Reliance Jio Infocomm Limited",
            "subnet" : "115.240.0.0/13"
         },
         "ip" : "115.241.86.166",
         "ipv6" : "false",
         "latitude" : "28.6542",
         "location" : "28.6542,77.2373",
         "longitude" : "77.2373",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "Reliance Jio Infocomm Limited",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 4117,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Bad Request",
         "seen_date" : "2024-11-07",
         "source" : "datascan",
         "status" : 400,
         "subnet" : "115.240.0.0/13",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 125.20.123.155:4117 (tcp/http) - last seen on 2024-11-07 at 03:35:01 UTC

    • IP
      125.20.123.155
      Network
      125.20.0.0/15
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      URL

      http://125.20.123.155:4117/ 400

      HTTP Title
      400 The plain HTTP request was sent to HTTPS port
      ASN
      AS9498
      Organization
      BHARTI Airtel Ltd.
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      2e3015527e99ab4730fabffdb9797a89
      HTTP Header MD5
      470a9635da086f31b68019aaddc44c99
      HTTP Body MD5
      2daa306c05fdeb1709f1c39db5a000c8
    • HTTP/1.1 400 Bad Request
      Date: Thu, 07 Nov 2024 03:35:01 GMT
      Content-Type: text/html
      Content-Length: 236
      Connection: close
      
      <html>
      <head><title>400 The plain HTTP request was sent to HTTPS port</title></head>
      <body bgcolor="white">
      <center><h1>400 Bad Request</h1></center>
      <center>The plain HTTP request was sent to HTTPS port</center>
      </body>
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T03:35:01.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "2daa306c05fdeb1709f1c39db5a000c8",
               "bodymmh3" : -1586337783,
               "headermd5" : "470a9635da086f31b68019aaddc44c99",
               "headermmh3" : -1545805586,
               "title" : "400 The plain HTTP request was sent to HTTPS port"
            },
            "length" : 366
         },
         "asn" : "AS9498",
         "city" : "Ghaziabad",
         "country" : "IN",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 400 Bad Request\r\nDate: Thu, 07 Nov 2024 03:35:01 GMT\r\nContent-Type: text/html\r\nContent-Length: 236\r\nConnection: close\r\n\r\n<html>\r\n<head><title>400 The plain HTTP request was sent to HTTPS port</title></head>\r\n<body bgcolor=\"white\">\r\n<center><h1>400 Bad Request</h1></center>\r\n<center>The plain HTTP request was sent to HTTPS port</center>\r\n</body>\r\n</html>\r\n",
         "datamd5" : "2e3015527e99ab4730fabffdb9797a89",
         "datammh3" : -248319603,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS9498",
            "continent" : "AS",
            "continentname" : "Asia",
            "country" : "IN",
            "countryname" : "India",
            "domain" : [
               "airtel.com",
               "techdemocracy.com"
            ],
            "isineu" : "false",
            "latitude" : "20.593684",
            "location" : "20.593684,78.96288",
            "longitude" : "78.96288",
            "netname" : "COTEL-3438758-Hyderabad",
            "organization" : "BHARTI-IN",
            "subnet" : "125.20.96.0/19"
         },
         "ip" : "125.20.123.155",
         "ipv6" : "false",
         "latitude" : "28.6650",
         "location" : "28.6650,77.4477",
         "longitude" : "77.4477",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "BHARTI Airtel Ltd.",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 4117,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Bad Request",
         "seen_date" : "2024-11-07",
         "source" : "datascan",
         "status" : 400,
         "subnet" : "125.20.0.0/15",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 189.73.233.176:4117 (tcp/http) - last seen on 2024-11-07 at 03:27:32 UTC

    • IP
      189.73.233.176
      Network
      189.72.0.0/14
      Domain(s)
      net.br
      Device

      <enterprise field>: device.class

      Operating System
      Microsoft Windows
      URL

      http://189.73.233.176:4117/ 200

      HTTP Title
      Index of /
      Reverse DNS
      189-73-233-176.user3p.v-tal.net.br
      ASN
      AS8167
      Organization
      V tal
      Protocol
      http
      Source
      datascan
    • Operating System
      Microsoft Windows
      Product
      Apache HTTP Server 2.2.8
      HTTP Component(s)
      PHP PHP 5.2.6
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      f442ff936cf2a6d685051c1ebfcf4364
      HTTP Header MD5
      86c2bea2cf93d42b4b12a23610a302a9
      HTTP Body MD5
      98796a8808d685ce29f7a9cf54b13c30
      Summary MD5
      4749b8cf09a2ae063555704b59a9aa81
    • Index of /
      2121_wave_cafe/
      ORIGINAL/
      SITES/
      php/
      real-estate-html-template/
      siteperfarn/
    • HTTP/1.1 200 OK
      Date: Thu, 07 Nov 2024 02:28:19 GMT
      Server: Apache/2.2.8 (Win32) PHP/5.2.6
      Content-Length: 1749
      Connection: close
      Content-Type: text/html;charset=UTF-8
      
      <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN">
      <html>
       <head>
        <title>Index of /</title>
       </head>
       <body>
      <h1>Index of /</h1>
      <table><tr><th><img src="/icons/blank.gif" alt="[ICO]"></th><th><a href="?C=N;O=D">Name</a></th><th><a href="?C=M;O=A">Last modified</a></th><th><a href="?C=S;O=A">Size</a></th><th><a href="?C=D;O=A">Description</a></th></tr><tr><th colspan="5"><hr></th></tr>
      <tr><td valign="top"><img src="/icons/folder.gif" alt="[DIR]"></td><td><a href="2121_wave_cafe/">2121_wave_cafe/</a>        </td><td align="right">13-Jan-2024 07:25  </td><td align="right">  - </td></tr>
      <tr><td valign="top"><img src="/icons/folder.gif" alt="[DIR]"></td><td><a href="ORIGINAL/">ORIGINAL/</a>              </td><td align="right">13-Jan-2024 07:42  </td><td align="right">  - </td></tr>
      <tr><td valign="top"><img src="/icons/folder.gif" alt="[DIR]"></td><td><a href="SITES/">SITES/</a>                 </td><td align="right">05-May-2018 07:35  </td><td align="right">  - </td></tr>
      <tr><td valign="top"><img src="/icons/folder.gif" alt="[DIR]"></td><td><a href="php/">php/</a>                   </td><td align="right">12-Jan-2024 15:18  </td><td align="right">  - </td></tr>
      <tr><td valign="top"><img src="/icons/folder.gif" alt="[DIR]"></td><td><a href="real-estate-html-template/">real-estate-html-tem..&gt;</a></td><td align="right">10-Jan-2022 12:50  </td><td align="right">  - </td></tr>
      <tr><td valign="top"><img src="/icons/folder.gif" alt="[DIR]"></td><td><a href="siteperfarn/">siteperfarn/</a>           </td><td align="right">11-Jan-2024 18:38  </td><td align="right">  - </td></tr>
      <tr><th colspan="5"><hr></th></tr>
      </table>
      <address>Apache/2.2.8 (Win32) PHP/5.2.6 Server at <ip> Port 4117</address>
      </body></html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T03:27:32.000Z",
         "app" : {
            "browse" : {
               "file" : [
                  "?C=N;O=D",
                  "?C=M;O=A",
                  "?C=S;O=A",
                  "?C=D;O=A",
                  "2121_wave_cafe/",
                  "ORIGINAL/",
                  "SITES/",
                  "php/",
                  "real-estate-html-template/",
                  "siteperfarn/"
               ],
               "name" : "Index of /",
               "type" : "webdirectory"
            },
            "http" : {
               "bodymd5" : "98796a8808d685ce29f7a9cf54b13c30",
               "bodymmh3" : -1306204705,
               "component" : [
                  {
                     "product" : "PHP",
                     "productversion" : "5.2.6",
                     "productvendor" : "PHP"
                  }
               ],
               "headermd5" : "86c2bea2cf93d42b4b12a23610a302a9",
               "headermmh3" : 1890371144,
               "title" : "Index of /"
            },
            "length" : 1915
         },
         "asn" : "AS8167",
         "city" : "Campo Grande",
         "country" : "BR",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 200 OK\r\nDate: Thu, 07 Nov 2024 02:28:19 GMT\r\nServer: Apache/2.2.8 (Win32) PHP/5.2.6\r\nContent-Length: 1749\r\nConnection: close\r\nContent-Type: text/html;charset=UTF-8\r\n\r\n<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 3.2 Final//EN\">\n<html>\n <head>\n  <title>Index of /</title>\n </head>\n <body>\n<h1>Index of /</h1>\n<table><tr><th><img src=\"/icons/blank.gif\" alt=\"[ICO]\"></th><th><a href=\"?C=N;O=D\">Name</a></th><th><a href=\"?C=M;O=A\">Last modified</a></th><th><a href=\"?C=S;O=A\">Size</a></th><th><a href=\"?C=D;O=A\">Description</a></th></tr><tr><th colspan=\"5\"><hr></th></tr>\n<tr><td valign=\"top\"><img src=\"/icons/folder.gif\" alt=\"[DIR]\"></td><td><a href=\"2121_wave_cafe/\">2121_wave_cafe/</a>        </td><td align=\"right\">13-Jan-2024 07:25  </td><td align=\"right\">  - </td></tr>\n<tr><td valign=\"top\"><img src=\"/icons/folder.gif\" alt=\"[DIR]\"></td><td><a href=\"ORIGINAL/\">ORIGINAL/</a>              </td><td align=\"right\">13-Jan-2024 07:42  </td><td align=\"right\">  - </td></tr>\n<tr><td valign=\"top\"><img src=\"/icons/folder.gif\" alt=\"[DIR]\"></td><td><a href=\"SITES/\">SITES/</a>                 </td><td align=\"right\">05-May-2018 07:35  </td><td align=\"right\">  - </td></tr>\n<tr><td valign=\"top\"><img src=\"/icons/folder.gif\" alt=\"[DIR]\"></td><td><a href=\"php/\">php/</a>                   </td><td align=\"right\">12-Jan-2024 15:18  </td><td align=\"right\">  - </td></tr>\n<tr><td valign=\"top\"><img src=\"/icons/folder.gif\" alt=\"[DIR]\"></td><td><a href=\"real-estate-html-template/\">real-estate-html-tem..&gt;</a></td><td align=\"right\">10-Jan-2022 12:50  </td><td align=\"right\">  - </td></tr>\n<tr><td valign=\"top\"><img src=\"/icons/folder.gif\" alt=\"[DIR]\"></td><td><a href=\"siteperfarn/\">siteperfarn/</a>           </td><td align=\"right\">11-Jan-2024 18:38  </td><td align=\"right\">  - </td></tr>\n<tr><th colspan=\"5\"><hr></th></tr>\n</table>\n<address>Apache/2.2.8 (Win32) PHP/5.2.6 Server at <ip> Port 4117</address>\n</body></html>\n",
         "datamd5" : "f442ff936cf2a6d685051c1ebfcf4364",
         "datammh3" : -217592618,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "net.br"
         ],
         "geolocus" : {
            "asn" : "AS8167",
            "continent" : "SA",
            "continentname" : "South America",
            "country" : "BR",
            "countryname" : "Brazil",
            "domain" : [
               "cert.br",
               "net.br",
               "vtal.com"
            ],
            "isineu" : "false",
            "latitude" : "-14.235004",
            "location" : "-14.235004,-51.92528",
            "longitude" : "-51.92528",
            "netname" : "02.041.460/0001-93",
            "organization" : "V tal",
            "subnet" : "189.72.0.0/14"
         },
         "host" : [
            "189-73-233-176"
         ],
         "hostname" : [
            "189-73-233-176.user3p.v-tal.net.br"
         ],
         "ip" : "189.73.233.176",
         "ipv6" : "false",
         "latitude" : "-20.4428",
         "location" : "-20.4428,-54.6464",
         "longitude" : "-54.6464",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "V tal",
         "os" : "Windows",
         "osbits" : 32,
         "osvendor" : "Microsoft",
         "port" : 4117,
         "product" : "HTTP Server",
         "productvendor" : "Apache",
         "productversion" : "2.2.8",
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "OK",
         "reverse" : [
            "189-73-233-176.user3p.v-tal.net.br"
         ],
         "seen_date" : "2024-11-07",
         "source" : "datascan",
         "status" : 200,
         "subdomains" : [
            "user3p.v-tal.net.br",
            "v-tal.net.br"
         ],
         "subnet" : "189.72.0.0/14",
         "summary" : "Index of /\n2121_wave_cafe/\nORIGINAL/\nSITES/\nphp/\nreal-estate-html-template/\nsiteperfarn/",
         "summarymd5" : "4749b8cf09a2ae063555704b59a9aa81",
         "tag" : "<enterprise field>: tag",
         "tld" : [
            "br"
         ],
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }