Returning 10 result(s) out of 1,903 in 0.090 second(s)

  • 51.255.94.76:50070 (tcp/http) - last seen on 2024-11-07 at 05:10:04 UTC

    • IP
      51.255.94.76
      Network
      51.254.0.0/15
      Domain(s)
      2rock.fr
      Device

      <enterprise field>: device.class

      URL

      http://51.255.94.76:50070/ 302

      Reverse DNS
      mail.2rock.fr
      ASN
      AS16276
      Organization
      OVH SAS
      Protocol
      http
      Source
      urlscan::redirect
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      c39e28d8a85b03cffaed2c886152ddc0
      HTTP Header MD5
      f9434fba64e80d7c044c4cdf72ee9381
      HTTP Body MD5
      d41d8cd98f00b204e9800998ecf8427e
    • HTTP/1.1 302 
      Location: https://<ip>:50070/
      Content-Length: 0
      Date: Thu, 07 Nov 2024 05:10:02 GMT
      Connection: close
      
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:10:04.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "d41d8cd98f00b204e9800998ecf8427e",
               "bodymmh3" : -1,
               "headermd5" : "f9434fba64e80d7c044c4cdf72ee9381",
               "headermmh3" : -1388138115
            },
            "length" : 123
         },
         "asn" : "AS16276",
         "country" : "FR",
         "data" : "HTTP/1.1 302 \r\nLocation: https://<ip>:50070/\r\nContent-Length: 0\r\nDate: Thu, 07 Nov 2024 05:10:02 GMT\r\nConnection: close\r\n\r\n",
         "datamd5" : "c39e28d8a85b03cffaed2c886152ddc0",
         "datammh3" : 733953390,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "2rock.fr"
         ],
         "forward" : "51.255.94.76",
         "geolocus" : {
            "asn" : "AS16276",
            "continent" : "EU",
            "continentname" : "Europe",
            "country" : "FR",
            "countryname" : "France",
            "domain" : [
               "ovh.net"
            ],
            "isineu" : "true",
            "latitude" : "46.227638",
            "location" : "46.227638,2.213749",
            "longitude" : "2.213749",
            "netname" : "FR-OVH-20150522",
            "organization" : "OVH SAS",
            "subnet" : "51.254.0.0/15"
         },
         "host" : [
            "mail"
         ],
         "hostname" : [
            "51.255.94.76",
            "mail.2rock.fr"
         ],
         "ip" : "51.255.94.76",
         "ipv6" : "false",
         "latitude" : "48.8582",
         "location" : "48.8582,2.3387",
         "longitude" : "2.3387",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "OVH SAS",
         "port" : 50070,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reverse" : [
            "mail.2rock.fr"
         ],
         "seen_date" : "2024-11-07",
         "source" : "urlscan::redirect",
         "status" : 302,
         "subnet" : "51.254.0.0/15",
         "tag" : "<enterprise field>: tag",
         "tld" : [
            "fr"
         ],
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 111.251.22.16:50070 (tcp/http) - last seen on 2024-11-07 at 05:04:09 UTC

    • IP
      111.251.22.16
      Network
      111.240.0.0/12
      Domain(s)
      hinet.net
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      URL

      http://111.251.22.16:50070/ 407

      Reverse DNS
      111-251-22-16.dynamic-ip.hinet.net
      ASN
      AS3462
      Organization
      Data Communication Business Group
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      6af1621cf9c3bf6709c2562fddd8fe03
      HTTP Header MD5
      5251af0c5aab125455b43ce4fd6ad553
      HTTP Body MD5
      d41d8cd98f00b204e9800998ecf8427e
    • HTTP/1.1 407 Proxy Authentication Required
      Proxy-Authenticate: Basic realm="proxy"
      
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:04:09.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "d41d8cd98f00b204e9800998ecf8427e",
               "bodymmh3" : -1,
               "headermd5" : "5251af0c5aab125455b43ce4fd6ad553",
               "headermmh3" : 26724135,
               "realm" : "proxy"
            },
            "length" : 87
         },
         "asn" : "AS3462",
         "city" : "Zhongli District",
         "country" : "TW",
         "data" : "HTTP/1.1 407 Proxy Authentication Required\r\nProxy-Authenticate: Basic realm=\"proxy\"\r\n\r\n",
         "datamd5" : "6af1621cf9c3bf6709c2562fddd8fe03",
         "datammh3" : -954790556,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "hinet.net"
         ],
         "geolocus" : {
            "asn" : "AS3462",
            "continent" : "AS",
            "continentname" : "Asia",
            "country" : "TW",
            "countryname" : "Taiwan",
            "domain" : [
               "hinet.net",
               "twnic.net",
               "twnic.net.tw"
            ],
            "isineu" : "false",
            "latitude" : "23.69781",
            "location" : "23.69781,120.960515",
            "longitude" : "120.960515",
            "netname" : "HINET-NET",
            "organization" : "Data Communication Business Group",
            "subnet" : "111.248.0.0/14"
         },
         "host" : [
            "111-251-22-16"
         ],
         "hostname" : [
            "111-251-22-16.dynamic-ip.hinet.net"
         ],
         "ip" : "111.251.22.16",
         "ipv6" : "false",
         "latitude" : "24.9614",
         "location" : "24.9614,121.2437",
         "longitude" : "121.2437",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "Data Communication Business Group",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 50070,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Proxy Authentication Required",
         "reverse" : [
            "111-251-22-16.dynamic-ip.hinet.net"
         ],
         "seen_date" : "2024-11-07",
         "source" : "datascan",
         "status" : 407,
         "subdomains" : [
            "dynamic-ip.hinet.net"
         ],
         "subnet" : "111.240.0.0/12",
         "tag" : "<enterprise field>: tag",
         "tld" : [
            "net"
         ],
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 77.235.221.234:50070 (tcp/http) - last seen on 2024-11-07 at 05:03:53 UTC

    • IP
      77.235.221.234
      Network
      77.235.220.0/22
      Domain(s)
      ptl.ru
      Device

      <enterprise field>: device.class

      URL

      http://77.235.221.234:50070/ 301

      Reverse DNS
      234.221.vlgd.ptl.ru
      ASN
      AS12418
      Organization
      Quantum CJSC
      Protocol
      http
      Source
      urlscan::redirect
    • Product
      Proxmox Virtual Environment 3.0
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      6a2f0502ee313c104c3d3a8b75296335
      HTTP Header MD5
      de2c54cdd1e009b0f283ed93c4545e2b
      HTTP Body MD5
      d41d8cd98f00b204e9800998ecf8427e
    • HTTP/1.1 301 Moved Permanently
      Cache-Control: max-age=0
      Connection: close
      Date: Thu, 07 Nov 2024 05:03:51 GMT
      Pragma: no-cache
      Location: https://<ip>:50070/
      Server: pve-api-daemon/3.0
      Expires: Thu, 07 Nov 2024 05:03:51 GMT
      
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:03:53.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "d41d8cd98f00b204e9800998ecf8427e",
               "bodymmh3" : -1,
               "headermd5" : "de2c54cdd1e009b0f283ed93c4545e2b",
               "headermmh3" : 1245313127
            },
            "length" : 233
         },
         "asn" : "AS12418",
         "country" : "RU",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 301 Moved Permanently\r\nCache-Control: max-age=0\r\nConnection: close\r\nDate: Thu, 07 Nov 2024 05:03:51 GMT\r\nPragma: no-cache\r\nLocation: https://<ip>:50070/\r\nServer: pve-api-daemon/3.0\r\nExpires: Thu, 07 Nov 2024 05:03:51 GMT\r\n\r\n",
         "datamd5" : "6a2f0502ee313c104c3d3a8b75296335",
         "datammh3" : 1417157562,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "ptl.ru"
         ],
         "forward" : "77.235.221.234",
         "geolocus" : {
            "asn" : "AS12418",
            "continent" : "EU",
            "continentname" : "Europe",
            "country" : "RU",
            "countryname" : "Russia",
            "domain" : [
               "ptl.ru"
            ],
            "isineu" : "false",
            "latitude" : "61.52401",
            "location" : "61.52401,105.318756",
            "longitude" : "105.318756",
            "netname" : "BARNAUL-NETWORK",
            "organization" : "Prostor Telecomm",
            "subnet" : "77.235.221.0/24"
         },
         "host" : [
            234
         ],
         "hostname" : [
            "234.221.vlgd.ptl.ru",
            "77.235.221.234"
         ],
         "ip" : "77.235.221.234",
         "ipv6" : "false",
         "latitude" : "55.7386",
         "location" : "55.7386,37.6068",
         "longitude" : "37.6068",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "Quantum CJSC",
         "port" : 50070,
         "product" : "Virtual Environment",
         "productvendor" : "Proxmox",
         "productversion" : "3.0",
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Moved Permanently",
         "reverse" : [
            "234.221.vlgd.ptl.ru"
         ],
         "seen_date" : "2024-11-07",
         "source" : "urlscan::redirect",
         "status" : 301,
         "subdomains" : [
            "221.vlgd.ptl.ru",
            "vlgd.ptl.ru"
         ],
         "subnet" : "77.235.220.0/22",
         "tld" : [
            "ru"
         ],
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 92.97.22.8:50070 (tcp/http) - last seen on 2024-11-07 at 05:02:13 UTC

    • IP
      92.97.22.8
      Network
      92.96.0.0/14
      Domain(s)
      alshamil.net.ae
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      URL

      http://92.97.22.8:50070/ 404

      Reverse DNS
      bba-92-97-22-8.alshamil.net.ae
      ASN
      AS5384
      Organization
      Emirates Telecommunications Group Company (etisalat Group) Pjsc
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      4b5b496ff238cb6bc91391c80dbcb192
      HTTP Header MD5
      4b5b496ff238cb6bc91391c80dbcb192
      HTTP Body MD5
      d41d8cd98f00b204e9800998ecf8427e
    • HTTP/1.1 404 Not Found
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:02:13.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "d41d8cd98f00b204e9800998ecf8427e",
               "bodymmh3" : -1,
               "headermd5" : "4b5b496ff238cb6bc91391c80dbcb192",
               "headermmh3" : -2050145619
            },
            "length" : 24
         },
         "asn" : "AS5384",
         "city" : "Dubai",
         "country" : "AE",
         "data" : "HTTP/1.1 404 Not Found\r\n",
         "datamd5" : "4b5b496ff238cb6bc91391c80dbcb192",
         "datammh3" : -1733658736,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "alshamil.net.ae"
         ],
         "host" : [
            "bba-92-97-22-8"
         ],
         "hostname" : [
            "bba-92-97-22-8.alshamil.net.ae"
         ],
         "ip" : "92.97.22.8",
         "ipv6" : "false",
         "latitude" : "25.0731",
         "location" : "25.0731,55.2980",
         "longitude" : "55.2980",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "Emirates Telecommunications Group Company (etisalat Group) Pjsc",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 50070,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Not Found",
         "reverse" : [
            "bba-92-97-22-8.alshamil.net.ae"
         ],
         "seen_date" : "2024-11-07",
         "source" : "datascan",
         "status" : 404,
         "subnet" : "92.96.0.0/14",
         "tld" : [
            "net.ae"
         ],
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 188.234.112.82:50070 (tcp/http) - last seen on 2024-11-07 at 04:59:42 UTC

    • IP
      188.234.112.82
      Network
      188.234.112.0/22
      Domain(s)
      ertelecom.ru
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      URL

      http://188.234.112.82:50070/ 303

      Reverse DNS
      188x234x112x82.static-business.omsk.ertelecom.ru
      ASN
      AS41843
      Organization
      JSC ER-Telecom Holding
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      5e7919e46a845b0900c17f4104c6626c
      HTTP Header MD5
      a7fd46cfa301c507fefc3b5fbfb0fa99
      HTTP Body MD5
      d41d8cd98f00b204e9800998ecf8427e
    • HTTP/1.1 303 See other
      Location: /admin/index.html
      
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T04:59:42.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "d41d8cd98f00b204e9800998ecf8427e",
               "bodymmh3" : -1,
               "headermd5" : "a7fd46cfa301c507fefc3b5fbfb0fa99",
               "headermmh3" : 6636726
            },
            "length" : 55
         },
         "asn" : "AS41843",
         "country" : "RU",
         "data" : "HTTP/1.1 303 See other\r\nLocation: /admin/index.html\r\n\r\n",
         "datamd5" : "5e7919e46a845b0900c17f4104c6626c",
         "datammh3" : 697907055,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "ertelecom.ru"
         ],
         "geolocus" : {
            "asn" : "AS41843",
            "continent" : "EU",
            "continentname" : "Europe",
            "country" : "RU",
            "countryname" : "Russia",
            "domain" : [
               "domru.ru",
               "ertelecom.ru"
            ],
            "isineu" : "false",
            "latitude" : "61.52401",
            "location" : "61.52401,105.318756",
            "longitude" : "105.318756",
            "netname" : "ERTH-OMSK-PPPOE-32-NET",
            "organization" : "JSC \"ER-Telecom Holding\" Omsk Branch",
            "subnet" : "188.234.112.0/22"
         },
         "host" : [
            "188x234x112x82"
         ],
         "hostname" : [
            "188x234x112x82.static-business.omsk.ertelecom.ru"
         ],
         "ip" : "188.234.112.82",
         "ipv6" : "false",
         "latitude" : "55.7386",
         "location" : "55.7386,37.6068",
         "longitude" : "37.6068",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "JSC ER-Telecom Holding",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 50070,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "See other",
         "reverse" : [
            "188x234x112x82.static-business.omsk.ertelecom.ru"
         ],
         "seen_date" : "2024-11-07",
         "source" : "datascan",
         "status" : 303,
         "subdomains" : [
            "static-business.omsk.ertelecom.ru",
            "omsk.ertelecom.ru"
         ],
         "subnet" : "188.234.112.0/22",
         "tag" : "<enterprise field>: tag",
         "tld" : [
            "ru"
         ],
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 59.75.40.155:50070 (tcp/http) - last seen on 2024-11-07 at 03:30:48 UTC

    • IP
      59.75.40.155
      Network
      59.64.0.0/12
      Device

      <enterprise field>: device.class

      URL

      http://59.75.40.155:50070/ 302

      ASN
      AS4538
      Organization
      China Education and Research Network Center
      Protocol
      http
      Source
      datascan
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      96d7aced4477a5334c7de4616620bcc7
      HTTP Header MD5
      17494da67b263d49a356f29516833bab
      HTTP Body MD5
      d41d8cd98f00b204e9800998ecf8427e
    • HTTP/1.1 302 Moved Temporarily
      Server: DrcomServer1.0
      Location: http://192.168.254.3
      Cache-Control: no-cache
      Content-Length: 0
      Connection: close
      
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T03:30:48.000Z",
         "app" : {
            "extract" : {
               "ip" : [
                  "192.168.254.3"
               ],
               "url" : [
                  "http://192.168.254.3"
               ]
            },
            "http" : {
               "bodymd5" : "d41d8cd98f00b204e9800998ecf8427e",
               "bodymmh3" : -1,
               "headermd5" : "17494da67b263d49a356f29516833bab",
               "headermmh3" : 1664562682
            },
            "length" : 153
         },
         "asn" : "AS4538",
         "country" : "CN",
         "data" : "HTTP/1.1 302 Moved Temporarily\r\nServer: DrcomServer1.0\r\nLocation: http://192.168.254.3\r\nCache-Control: no-cache\r\nContent-Length: 0\r\nConnection: close\r\n\r\n",
         "datamd5" : "96d7aced4477a5334c7de4616620bcc7",
         "datammh3" : 1446480259,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS4538",
            "continent" : "AS",
            "continentname" : "Asia",
            "country" : "CN",
            "countryname" : "China",
            "domain" : [
               "cernet.edu.cn"
            ],
            "isineu" : "false",
            "latitude" : "35.86166",
            "location" : "35.86166,104.195397",
            "longitude" : "104.195397",
            "netname" : "XAR-CERNET",
            "organization" : "China Education and Research Network",
            "subnet" : "59.75.40.128/25"
         },
         "ip" : "59.75.40.155",
         "ipv6" : "false",
         "latitude" : "34.7732",
         "location" : "34.7732,113.7220",
         "longitude" : "113.7220",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "China Education and Research Network Center",
         "port" : 50070,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Moved Temporarily",
         "seen_date" : "2024-11-07",
         "source" : "datascan",
         "status" : 302,
         "subnet" : "59.64.0.0/12",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 92.243.93.152:50070 (tcp/http) - last seen on 2024-11-07 at 03:28:40 UTC

    • IP
      92.243.93.152
      Network
      92.243.93.0/24
      Device

      <enterprise field>: device.class

      URL

      http://92.243.93.152:50070/ 301

      ASN
      AS202422
      Organization
      G-Core Labs S.A.
      Protocol
      http
      Source
      datascan
    • Product
      Apache HTTP Server
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      433fd4199a3d308ad34b27bca550fea1
      HTTP Header MD5
      1596025e1d1eb4b7aaf8a70fe8f5fcfb
      HTTP Body MD5
      d41d8cd98f00b204e9800998ecf8427e
    • HTTP/1.1 301 Moved Permanently
      Location: /admin/login.html
      Content-Type: text/html; charset=UTF-8
      Server: Apache
      Content-Length: 0
      Set-Cookie: idA4029=1aaa2101; max-age=2592000;
      Connection: keep-alive
      
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T03:28:40.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "d41d8cd98f00b204e9800998ecf8427e",
               "bodymmh3" : -1636538602,
               "headermd5" : "1596025e1d1eb4b7aaf8a70fe8f5fcfb",
               "headermmh3" : -91651005
            },
            "length" : 210
         },
         "asn" : "AS202422",
         "city" : "Frankfurt am Main",
         "country" : "DE",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 301 Moved Permanently\r\nLocation: /admin/login.html\r\nContent-Type: text/html; charset=UTF-8\r\nServer: Apache\r\nContent-Length: 0\r\nSet-Cookie: idA4029=1aaa2101; max-age=2592000;\r\nConnection: keep-alive\r\n\r\n",
         "datamd5" : "433fd4199a3d308ad34b27bca550fea1",
         "datammh3" : -1934269793,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS202422",
            "country" : "EU",
            "domain" : [
               "gcore.lu"
            ],
            "isineu" : "true",
            "netname" : "LU-GCORELABS-20080115",
            "organization" : "G-Core Labs S.A.",
            "subnet" : "92.243.93.0/24"
         },
         "ip" : "92.243.93.152",
         "ipv6" : "false",
         "latitude" : "50.1187",
         "location" : "50.1187,8.6842",
         "longitude" : "8.6842",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "G-Core Labs S.A.",
         "port" : 50070,
         "product" : "HTTP Server",
         "productvendor" : "Apache",
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Moved Permanently",
         "seen_date" : "2024-11-07",
         "source" : "datascan",
         "status" : 301,
         "subnet" : "92.243.93.0/24",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 13.208.161.50:50070 (tcp/http) - last seen on 2024-11-07 at 02:00:20 UTC

    • IP
      13.208.161.50
      Network
      13.208.0.0/13
      Domain(s)
      amazonaws.com
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      URL

      http://13.208.161.50:50070/ 301

      Reverse DNS
      ec2-13-208-161-50.ap-northeast-3.compute.amazonaws.com
      ASN
      AS16509
      Organization
      AMAZON-02
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
      Product
      F5 Nginx
      HTTP Component(s)
      Oracle Java Atlassian Confluence
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      53c52550df4ad0a57e3cecd3812158d5
      HTTP Header MD5
      588421e6ee6cc1654016e9e4a93ae98f
      HTTP Body MD5
      d41d8cd98f00b204e9800998ecf8427e
    • HTTP/1.1 301 Moved Permanently
      Connection: keep-alive
      Date: Thu, 07 Nov 2024 02:00:19 GMT
      Server: nginx
      X-Confluence-Request-Time: 1730944819
      Content-Type: text/html;charset=UTF-8
      Cache-Control: no-cache, must-revalidate
      Expires: Thu, 01 Jan 1970 00:00:00 GMT
      Set-Cookie: JSESSIONID=de0bh7c2k0to5iaaz9o1ewlsoomdy7nq; Path=/; Secure; HttpOnly
      X-XSS-Protection: 1; mode=block
      X-Content-Type-Options: nosniff
      X-Frame-Options: SAMEORIGIN
      Content-Security-Policy: frame-ancestors 'self'
      Strict-Transport-Security: max-age=63072000
      Location: ./login.action
      Content-Length: 0
      
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T02:00:20.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "d41d8cd98f00b204e9800998ecf8427e",
               "bodymmh3" : -1636538602,
               "component" : [
                  {
                     "product" : "Java",
                     "productvendor" : "Oracle"
                  },
                  {
                     "product" : "Confluence",
                     "productvendor" : "Atlassian"
                  }
               ],
               "headermd5" : "588421e6ee6cc1654016e9e4a93ae98f",
               "headermmh3" : -1338093258
            },
            "length" : 587
         },
         "asn" : "AS16509",
         "city" : "Osaka",
         "country" : "JP",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 301 Moved Permanently\r\nConnection: keep-alive\r\nDate: Thu, 07 Nov 2024 02:00:19 GMT\r\nServer: nginx\r\nX-Confluence-Request-Time: 1730944819\r\nContent-Type: text/html;charset=UTF-8\r\nCache-Control: no-cache, must-revalidate\r\nExpires: Thu, 01 Jan 1970 00:00:00 GMT\r\nSet-Cookie: JSESSIONID=de0bh7c2k0to5iaaz9o1ewlsoomdy7nq; Path=/; Secure; HttpOnly\r\nX-XSS-Protection: 1; mode=block\r\nX-Content-Type-Options: nosniff\r\nX-Frame-Options: SAMEORIGIN\r\nContent-Security-Policy: frame-ancestors 'self'\r\nStrict-Transport-Security: max-age=63072000\r\nLocation: ./login.action\r\nContent-Length: 0\r\n\r\n",
         "datamd5" : "53c52550df4ad0a57e3cecd3812158d5",
         "datammh3" : 76341212,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "amazonaws.com"
         ],
         "geolocus" : {
            "asn" : "AS16509",
            "continent" : "AS",
            "continentname" : "Asia",
            "country" : "JP",
            "countryname" : "Japan",
            "domain" : [
               "amazon.com",
               "amazonaws.com",
               "aws.com"
            ],
            "isineu" : "false",
            "latitude" : "36.204824",
            "location" : "36.204824,138.252924",
            "longitude" : "138.252924",
            "netname" : "AMAZON-KIX",
            "organization" : "Amazon Data Services Osaka",
            "subnet" : "13.208.0.0/16"
         },
         "host" : [
            "ec2-13-208-161-50"
         ],
         "hostname" : [
            "ec2-13-208-161-50.ap-northeast-3.compute.amazonaws.com"
         ],
         "ip" : "13.208.161.50",
         "ipv6" : "false",
         "latitude" : "34.6946",
         "location" : "34.6946,135.5021",
         "longitude" : "135.5021",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "AMAZON-02",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 50070,
         "product" : "Nginx",
         "productvendor" : "F5",
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Moved Permanently",
         "reverse" : [
            "ec2-13-208-161-50.ap-northeast-3.compute.amazonaws.com"
         ],
         "seen_date" : "2024-11-07",
         "source" : "datascan",
         "status" : 301,
         "subdomains" : [
            "ap-northeast-3.compute.amazonaws.com",
            "compute.amazonaws.com"
         ],
         "subnet" : "13.208.0.0/13",
         "tag" : "<enterprise field>: tag",
         "tld" : [
            "com"
         ],
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 59.75.41.119:50070 (tcp/http) - last seen on 2024-11-07 at 01:58:52 UTC

    • IP
      59.75.41.119
      Network
      59.64.0.0/12
      Device

      <enterprise field>: device.class

      URL

      http://59.75.41.119:50070/ 302

      ASN
      AS4538
      Organization
      China Education and Research Network Center
      Protocol
      http
      Source
      datascan
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      96d7aced4477a5334c7de4616620bcc7
      HTTP Header MD5
      17494da67b263d49a356f29516833bab
      HTTP Body MD5
      d41d8cd98f00b204e9800998ecf8427e
    • HTTP/1.1 302 Moved Temporarily
      Server: DrcomServer1.0
      Location: http://192.168.254.3
      Cache-Control: no-cache
      Content-Length: 0
      Connection: close
      
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T01:58:52.000Z",
         "app" : {
            "extract" : {
               "ip" : [
                  "192.168.254.3"
               ],
               "url" : [
                  "http://192.168.254.3"
               ]
            },
            "http" : {
               "bodymd5" : "d41d8cd98f00b204e9800998ecf8427e",
               "bodymmh3" : -1,
               "headermd5" : "17494da67b263d49a356f29516833bab",
               "headermmh3" : 1664562682
            },
            "length" : 153
         },
         "asn" : "AS4538",
         "country" : "CN",
         "data" : "HTTP/1.1 302 Moved Temporarily\r\nServer: DrcomServer1.0\r\nLocation: http://192.168.254.3\r\nCache-Control: no-cache\r\nContent-Length: 0\r\nConnection: close\r\n\r\n",
         "datamd5" : "96d7aced4477a5334c7de4616620bcc7",
         "datammh3" : 1446480259,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS4538",
            "continent" : "AS",
            "continentname" : "Asia",
            "country" : "CN",
            "countryname" : "China",
            "domain" : [
               "cernet.edu.cn"
            ],
            "isineu" : "false",
            "latitude" : "35.86166",
            "location" : "35.86166,104.195397",
            "longitude" : "104.195397",
            "netname" : "XAR-CERNET",
            "organization" : "China Education and Research Network",
            "subnet" : "59.75.41.0/24"
         },
         "ip" : "59.75.41.119",
         "ipv6" : "false",
         "latitude" : "34.7732",
         "location" : "34.7732,113.7220",
         "longitude" : "113.7220",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "China Education and Research Network Center",
         "port" : 50070,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Moved Temporarily",
         "seen_date" : "2024-11-07",
         "source" : "datascan",
         "status" : 302,
         "subnet" : "59.64.0.0/12",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 62.204.37.76:50070 (tcp/http) - last seen on 2024-11-07 at 01:57:23 UTC

    • IP
      62.204.37.76
      Network
      62.204.37.0/24
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      URL

      http://62.204.37.76:50070/ 407

      ASN
      AS198231
      Organization
      Sixnet Operation Ltd
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      78585a31a9923f851fd7498cc40b6a44
      HTTP Header MD5
      ec1a9c7961fed7d88fbabb0196599217
      HTTP Body MD5
      d41d8cd98f00b204e9800998ecf8427e
    • HTTP/1.1 407 Proxy Authentication Required
      proxy-authenticate: Basic
      connection: close
      
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T01:57:23.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "d41d8cd98f00b204e9800998ecf8427e",
               "bodymmh3" : -1,
               "headermd5" : "ec1a9c7961fed7d88fbabb0196599217",
               "headermmh3" : 1542279371
            },
            "length" : 92
         },
         "asn" : "AS198231",
         "country" : "CY",
         "data" : "HTTP/1.1 407 Proxy Authentication Required\r\nproxy-authenticate: Basic\r\nconnection: close\r\n\r\n",
         "datamd5" : "78585a31a9923f851fd7498cc40b6a44",
         "datammh3" : 1547380673,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "ip" : "62.204.37.76",
         "ipv6" : "false",
         "latitude" : "35.0077",
         "location" : "35.0077,32.9882",
         "longitude" : "32.9882",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "Sixnet Operation Ltd",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 50070,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Proxy Authentication Required",
         "seen_date" : "2024-11-07",
         "source" : "datascan",
         "status" : 407,
         "subnet" : "62.204.37.0/24",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }