Returning 10 result(s) out of 2,941,684 in 0.230 second(s)

  • 140.143.226.128:5985 (tcp/winrm) - last seen on 2024-11-21 at 09:10:32 UTC

    • IP
      140.143.226.128
      Network
      140.143.0.0/16
      Device

      <enterprise field>: device.class

      Operating System
      Microsoft Windows
      ASN
      AS45090
      Organization
      Shenzhen Tencent Computer Systems Company Limited
      Protocol
      winrm
      Source
      datascan
    • Operating System
      Microsoft Windows
      Product
      Microsoft HTTPAPI 2.0
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      e899186f574741b96aebc4929f015b0b
      HTTP Header MD5
      eb8dfa5136702f42e29b01a5ef58d026
      HTTP Body MD5
      d41d8cd98f00b204e9800998ecf8427e
    • HTTP/1.1 401 
      Server: Microsoft-HTTPAPI/2.0
      WWW-Authenticate: Negotiate
      Date: Thu, 21 Nov 2024 09:10:30 GMT
      Connection: close
      Content-Length: 0
      
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-21T09:10:32.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "d41d8cd98f00b204e9800998ecf8427e",
               "bodymmh3" : -1,
               "headermd5" : "eb8dfa5136702f42e29b01a5ef58d026",
               "headermmh3" : -1819367338
            },
            "length" : 152
         },
         "asn" : "AS45090",
         "country" : "CN",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 401 \r\nServer: Microsoft-HTTPAPI/2.0\r\nWWW-Authenticate: Negotiate\r\nDate: Thu, 21 Nov 2024 09:10:30 GMT\r\nConnection: close\r\nContent-Length: 0\r\n\r\n",
         "datamd5" : "e899186f574741b96aebc4929f015b0b",
         "datammh3" : 1821300650,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS45090",
            "continent" : "AS",
            "continentname" : "Asia",
            "country" : "CN",
            "countryname" : "China",
            "domain" : [
               "cnnic.cn",
               "tencent.com"
            ],
            "isineu" : "false",
            "latitude" : "35.86166",
            "location" : "35.86166,104.195397",
            "longitude" : "104.195397",
            "netname" : "TencentCloud",
            "organization" : "TencentCloud",
            "subnet" : "140.143.0.0/16"
         },
         "ip" : "140.143.226.128",
         "ipv6" : "false",
         "latitude" : "34.7732",
         "location" : "34.7732,113.7220",
         "longitude" : "113.7220",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "Shenzhen Tencent Computer Systems Company Limited",
         "os" : "Windows",
         "osvendor" : "Microsoft",
         "port" : 5985,
         "product" : "HTTPAPI",
         "productvendor" : "Microsoft",
         "productversion" : "2.0",
         "protocol" : "winrm",
         "protocolversion" : "1.1",
         "seen_date" : "2024-11-21",
         "source" : "datascan",
         "status" : 401,
         "subnet" : "140.143.0.0/16",
         "tag" : "<enterprise field>: tag",
         "tls" : "false",
         "transport" : "tcp"
      }
      
  • 38.11.47.39:5985 (tcp/winrm) - last seen on 2024-11-21 at 09:10:32 UTC

    • IP
      38.11.47.39
      Network
      38.11.0.0/18
      Device

      <enterprise field>: device.class

      Operating System
      Microsoft Windows
      ASN
      AS54600
      Organization
      PEG-SV
      Protocol
      winrm
      Source
      datascan
    • Operating System
      Microsoft Windows
      Product
      Microsoft HTTPAPI 2.0
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      e899186f574741b96aebc4929f015b0b
      HTTP Header MD5
      eb8dfa5136702f42e29b01a5ef58d026
      HTTP Body MD5
      d41d8cd98f00b204e9800998ecf8427e
    • HTTP/1.1 401 
      Server: Microsoft-HTTPAPI/2.0
      WWW-Authenticate: Negotiate
      Date: Thu, 21 Nov 2024 09:10:29 GMT
      Connection: close
      Content-Length: 0
      
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-21T09:10:32.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "d41d8cd98f00b204e9800998ecf8427e",
               "bodymmh3" : -1,
               "headermd5" : "eb8dfa5136702f42e29b01a5ef58d026",
               "headermmh3" : 395279295
            },
            "length" : 152
         },
         "asn" : "AS54600",
         "city" : "San Jose",
         "country" : "US",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 401 \r\nServer: Microsoft-HTTPAPI/2.0\r\nWWW-Authenticate: Negotiate\r\nDate: Thu, 21 Nov 2024 09:10:29 GMT\r\nConnection: close\r\nContent-Length: 0\r\n\r\n",
         "datamd5" : "e899186f574741b96aebc4929f015b0b",
         "datammh3" : 1821300650,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS54600",
            "continent" : "NA",
            "continentname" : "North America",
            "country" : "US",
            "countryname" : "United States",
            "domain" : [
               "cogentco.com",
               "petaexpress.com"
            ],
            "isineu" : "false",
            "latitude" : "37.09024",
            "location" : "37.09024,-95.712891",
            "longitude" : "-95.712891",
            "netname" : "PEG-TECH-CGNT-NET-14",
            "organization" : "PEG TECH INC",
            "subnet" : "38.11.0.0/18"
         },
         "ip" : "38.11.47.39",
         "ipv6" : "false",
         "latitude" : "37.1835",
         "location" : "37.1835,-121.7714",
         "longitude" : "-121.7714",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "PEG-SV",
         "os" : "Windows",
         "osvendor" : "Microsoft",
         "port" : 5985,
         "product" : "HTTPAPI",
         "productvendor" : "Microsoft",
         "productversion" : "2.0",
         "protocol" : "winrm",
         "protocolversion" : "1.1",
         "seen_date" : "2024-11-21",
         "source" : "datascan",
         "status" : 401,
         "subnet" : "38.11.0.0/18",
         "tag" : "<enterprise field>: tag",
         "tls" : "false",
         "transport" : "tcp"
      }
      
  • 46.245.90.52:5985 (tcp/winrm) - last seen on 2024-11-21 at 09:10:31 UTC

    • IP
      46.245.90.52
      Alternative IP(s)
      104.21.70.204 116.202.177.143 172.67.139.73 2606:4700:3035:0:0:0:6815:46cc 2606:4700:3037:0:0:0:ac43:8b49
      Network
      46.245.64.0/18
      Domain(s)
      abin.ir
      Device

      <enterprise field>: device.class

      Operating System
      Microsoft Windows
      Reverse DNS
      abin.ir mail.abin.ir
      ASN
      AS43754
      Organization
      Asiatech Data Transmission company
      Protocol
      winrm
      Source
      datascan
    • Operating System
      Microsoft Windows
      Product
      Microsoft HTTPAPI 2.0
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      e899186f574741b96aebc4929f015b0b
      HTTP Header MD5
      eb8dfa5136702f42e29b01a5ef58d026
      HTTP Body MD5
      d41d8cd98f00b204e9800998ecf8427e
    • HTTP/1.1 401 
      Server: Microsoft-HTTPAPI/2.0
      WWW-Authenticate: Negotiate
      Date: Thu, 21 Nov 2024 09:10:29 GMT
      Connection: close
      Content-Length: 0
      
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-21T09:10:31.000Z",
         "alternativeip" : [
            "104.21.70.204",
            "116.202.177.143",
            "172.67.139.73",
            "2606:4700:3035:0:0:0:6815:46cc",
            "2606:4700:3037:0:0:0:ac43:8b49"
         ],
         "app" : {
            "http" : {
               "bodymd5" : "d41d8cd98f00b204e9800998ecf8427e",
               "bodymmh3" : -1,
               "headermd5" : "eb8dfa5136702f42e29b01a5ef58d026",
               "headermmh3" : 395279295
            },
            "length" : 152
         },
         "asn" : "AS43754",
         "country" : "IR",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 401 \r\nServer: Microsoft-HTTPAPI/2.0\r\nWWW-Authenticate: Negotiate\r\nDate: Thu, 21 Nov 2024 09:10:29 GMT\r\nConnection: close\r\nContent-Length: 0\r\n\r\n",
         "datamd5" : "e899186f574741b96aebc4929f015b0b",
         "datammh3" : 1821300650,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "abin.ir"
         ],
         "host" : [
            "mail"
         ],
         "hostname" : [
            "abin.ir",
            "mail.abin.ir"
         ],
         "ip" : "46.245.90.52",
         "ipv6" : "false",
         "latitude" : "35.6980",
         "location" : "35.6980,51.4115",
         "longitude" : "51.4115",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "Asiatech Data Transmission company",
         "os" : "Windows",
         "osvendor" : "Microsoft",
         "port" : 5985,
         "product" : "HTTPAPI",
         "productvendor" : "Microsoft",
         "productversion" : "2.0",
         "protocol" : "winrm",
         "protocolversion" : "1.1",
         "reverse" : [
            "abin.ir",
            "mail.abin.ir"
         ],
         "seen_date" : "2024-11-21",
         "source" : "datascan",
         "status" : 401,
         "subnet" : "46.245.64.0/18",
         "tag" : "<enterprise field>: tag",
         "tld" : [
            "ir"
         ],
         "tls" : "false",
         "transport" : "tcp"
      }
      
  • 158.140.197.187:5985 (tcp/winrm) - last seen on 2024-11-21 at 09:10:30 UTC

    • IP
      158.140.197.187
      Network
      158.140.192.0/19
      Device

      <enterprise field>: device.class

      Operating System
      Microsoft Windows
      ASN
      AS18779
      Organization
      EGIHOSTING
      Protocol
      winrm
      Source
      datascan
    • Operating System
      Microsoft Windows
      Product
      Microsoft HTTPAPI 2.0
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      e899186f574741b96aebc4929f015b0b
      HTTP Header MD5
      eb8dfa5136702f42e29b01a5ef58d026
      HTTP Body MD5
      d41d8cd98f00b204e9800998ecf8427e
    • HTTP/1.1 401 
      Server: Microsoft-HTTPAPI/2.0
      WWW-Authenticate: Negotiate
      Date: Thu, 21 Nov 2024 09:09:38 GMT
      Connection: close
      Content-Length: 0
      
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-21T09:10:30.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "d41d8cd98f00b204e9800998ecf8427e",
               "bodymmh3" : -1,
               "headermd5" : "eb8dfa5136702f42e29b01a5ef58d026",
               "headermmh3" : 1874338399
            },
            "length" : 152
         },
         "asn" : "AS18779",
         "country" : "US",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 401 \r\nServer: Microsoft-HTTPAPI/2.0\r\nWWW-Authenticate: Negotiate\r\nDate: Thu, 21 Nov 2024 09:09:38 GMT\r\nConnection: close\r\nContent-Length: 0\r\n\r\n",
         "datamd5" : "e899186f574741b96aebc4929f015b0b",
         "datammh3" : 1821300650,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS18779",
            "continent" : "OC",
            "continentname" : "Oceania",
            "country" : "AU",
            "countryname" : "Australia",
            "domain" : [
               "myrepublic.net",
               "myrepublicinternet.com.au"
            ],
            "isineu" : "false",
            "latitude" : "-25.274398",
            "location" : "-25.274398,133.775136",
            "longitude" : "133.775136",
            "netname" : "MYRAU-Subscribers",
            "organization" : "MYREPUBLIC PTY LTD",
            "subnet" : "158.140.192.0/19"
         },
         "ip" : "158.140.197.187",
         "ipv6" : "false",
         "latitude" : "37.7510",
         "location" : "37.7510,-97.8220",
         "longitude" : "-97.8220",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "EGIHOSTING",
         "os" : "Windows",
         "osvendor" : "Microsoft",
         "port" : 5985,
         "product" : "HTTPAPI",
         "productvendor" : "Microsoft",
         "productversion" : "2.0",
         "protocol" : "winrm",
         "protocolversion" : "1.1",
         "seen_date" : "2024-11-21",
         "source" : "datascan",
         "status" : 401,
         "subnet" : "158.140.192.0/19",
         "tag" : "<enterprise field>: tag",
         "tls" : "false",
         "transport" : "tcp"
      }
      
  • 145.239.71.43:5985 (tcp/winrm) - last seen on 2024-11-21 at 09:10:29 UTC

    • IP
      145.239.71.43
      Network
      145.239.0.0/16
      Domain(s)
      ip-145-239-71.eu
      Device

      <enterprise field>: device.class

      Operating System
      Microsoft Windows
      Reverse DNS
      ns3092359.ip-145-239-71.eu
      ASN
      AS16276
      Organization
      OVH SAS
      Protocol
      winrm
      Source
      datascan
    • Operating System
      Microsoft Windows
      Product
      Microsoft HTTPAPI 2.0
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      0ee2c1e941cdcabf9e7057ec828cac59
      HTTP Header MD5
      061cf7476b475da8ec195e8d72a93778
      HTTP Body MD5
      d41d8cd98f00b204e9800998ecf8427e
    • HTTP/1.1 401 
      Server: Microsoft-HTTPAPI/2.0
      WWW-Authenticate: Negotiate
      WWW-Authenticate: Kerberos
      Date: Thu, 21 Nov 2024 09:08:03 GMT
      Connection: close
      Content-Length: 0
      
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-21T09:10:29.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "d41d8cd98f00b204e9800998ecf8427e",
               "bodymmh3" : -1,
               "headermd5" : "061cf7476b475da8ec195e8d72a93778",
               "headermmh3" : -1116703765
            },
            "length" : 180
         },
         "asn" : "AS16276",
         "country" : "PL",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 401 \r\nServer: Microsoft-HTTPAPI/2.0\r\nWWW-Authenticate: Negotiate\r\nWWW-Authenticate: Kerberos\r\nDate: Thu, 21 Nov 2024 09:08:03 GMT\r\nConnection: close\r\nContent-Length: 0\r\n\r\n",
         "datamd5" : "0ee2c1e941cdcabf9e7057ec828cac59",
         "datammh3" : -911423918,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "ip-145-239-71.eu"
         ],
         "geolocus" : {
            "asn" : "AS16276",
            "continent" : "EU",
            "continentname" : "Europe",
            "country" : "FR",
            "countryname" : "France",
            "domain" : [
               "ovh.net"
            ],
            "isineu" : "true",
            "latitude" : "46.227638",
            "location" : "46.227638,2.213749",
            "longitude" : "2.213749",
            "netname" : "FR-OVH-19930901",
            "organization" : "OVH SAS",
            "subnet" : "145.239.0.0/16"
         },
         "host" : [
            "ns3092359"
         ],
         "hostname" : [
            "ns3092359.ip-145-239-71.eu"
         ],
         "ip" : "145.239.71.43",
         "ipv6" : "false",
         "latitude" : "52.2394",
         "location" : "52.2394,21.0362",
         "longitude" : "21.0362",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "OVH SAS",
         "os" : "Windows",
         "osvendor" : "Microsoft",
         "port" : 5985,
         "product" : "HTTPAPI",
         "productvendor" : "Microsoft",
         "productversion" : "2.0",
         "protocol" : "winrm",
         "protocolversion" : "1.1",
         "reverse" : [
            "ns3092359.ip-145-239-71.eu"
         ],
         "seen_date" : "2024-11-21",
         "source" : "datascan",
         "status" : 401,
         "subnet" : "145.239.0.0/16",
         "tag" : "<enterprise field>: tag",
         "tld" : [
            "eu"
         ],
         "tls" : "false",
         "transport" : "tcp"
      }
      
  • 121.37.47.96:5985 (tcp/winrm) - last seen on 2024-11-21 at 09:10:26 UTC

    • IP
      121.37.47.96
      Network
      121.36.0.0/15
      Domain(s)
      minujwrw.cfd
      Device

      <enterprise field>: device.class

      Operating System
      Microsoft Windows
      Reverse DNS
      mail.minujwrw.cfd
      ASN
      AS55990
      Organization
      Huawei Cloud Service data center
      Protocol
      winrm
      Source
      datascan
    • Operating System
      Microsoft Windows
      Product
      Microsoft HTTPAPI 2.0
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      e899186f574741b96aebc4929f015b0b
      HTTP Header MD5
      eb8dfa5136702f42e29b01a5ef58d026
      HTTP Body MD5
      d41d8cd98f00b204e9800998ecf8427e
    • HTTP/1.1 401 
      Server: Microsoft-HTTPAPI/2.0
      WWW-Authenticate: Negotiate
      Date: Thu, 21 Nov 2024 09:10:25 GMT
      Connection: close
      Content-Length: 0
      
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-21T09:10:26.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "d41d8cd98f00b204e9800998ecf8427e",
               "bodymmh3" : -1,
               "headermd5" : "eb8dfa5136702f42e29b01a5ef58d026",
               "headermmh3" : -1196385802
            },
            "length" : 152
         },
         "asn" : "AS55990",
         "country" : "CN",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 401 \r\nServer: Microsoft-HTTPAPI/2.0\r\nWWW-Authenticate: Negotiate\r\nDate: Thu, 21 Nov 2024 09:10:25 GMT\r\nConnection: close\r\nContent-Length: 0\r\n\r\n",
         "datamd5" : "e899186f574741b96aebc4929f015b0b",
         "datammh3" : 1821300650,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "minujwrw.cfd"
         ],
         "geolocus" : {
            "asn" : "AS55990",
            "continent" : "AS",
            "continentname" : "Asia",
            "country" : "CN",
            "countryname" : "China",
            "domain" : [
               "cnnic.cn",
               "huawei.com",
               "hwclouds-dns.com"
            ],
            "isineu" : "false",
            "latitude" : "35.86166",
            "location" : "35.86166,104.195397",
            "longitude" : "104.195397",
            "netname" : "HWCSNET",
            "organization" : "Huawei Public Cloud Service (Huawei Software Technologies Ltd.Co)",
            "subnet" : "121.37.0.0/16"
         },
         "host" : [
            "mail"
         ],
         "hostname" : [
            "mail.minujwrw.cfd"
         ],
         "ip" : "121.37.47.96",
         "ipv6" : "false",
         "latitude" : "34.7732",
         "location" : "34.7732,113.7220",
         "longitude" : "113.7220",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "Huawei Cloud Service data center",
         "os" : "Windows",
         "osvendor" : "Microsoft",
         "port" : 5985,
         "product" : "HTTPAPI",
         "productvendor" : "Microsoft",
         "productversion" : "2.0",
         "protocol" : "winrm",
         "protocolversion" : "1.1",
         "reverse" : [
            "mail.minujwrw.cfd"
         ],
         "seen_date" : "2024-11-21",
         "source" : "datascan",
         "status" : 401,
         "subnet" : "121.36.0.0/15",
         "tag" : "<enterprise field>: tag",
         "tld" : [
            "cfd"
         ],
         "tls" : "false",
         "transport" : "tcp"
      }
      
  • 117.18.224.145:5985 (tcp/winrm) - last seen on 2024-11-21 at 09:10:26 UTC

    • IP
      117.18.224.145
      Network
      117.18.224.0/22
      Device

      <enterprise field>: device.class

      Operating System
      Microsoft Windows
      ASN
      AS134548
      Organization
      DXTL Tseung Kwan O Service
      Protocol
      winrm
      Source
      datascan
    • Operating System
      Microsoft Windows
      Product
      Microsoft HTTPAPI 2.0
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      e899186f574741b96aebc4929f015b0b
      HTTP Header MD5
      eb8dfa5136702f42e29b01a5ef58d026
      HTTP Body MD5
      d41d8cd98f00b204e9800998ecf8427e
    • HTTP/1.1 401 
      Server: Microsoft-HTTPAPI/2.0
      WWW-Authenticate: Negotiate
      Date: Thu, 21 Nov 2024 09:10:24 GMT
      Connection: close
      Content-Length: 0
      
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-21T09:10:26.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "d41d8cd98f00b204e9800998ecf8427e",
               "bodymmh3" : -1,
               "headermd5" : "eb8dfa5136702f42e29b01a5ef58d026",
               "headermmh3" : 155389186
            },
            "length" : 152
         },
         "asn" : "AS134548",
         "country" : "HK",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 401 \r\nServer: Microsoft-HTTPAPI/2.0\r\nWWW-Authenticate: Negotiate\r\nDate: Thu, 21 Nov 2024 09:10:24 GMT\r\nConnection: close\r\nContent-Length: 0\r\n\r\n",
         "datamd5" : "e899186f574741b96aebc4929f015b0b",
         "datammh3" : 1821300650,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS134548",
            "continent" : "AS",
            "continentname" : "Asia",
            "country" : "HK",
            "countryname" : "Hong Kong",
            "domain" : [
               "gmail.com"
            ],
            "isineu" : "false",
            "latitude" : "22.396428",
            "location" : "22.396428,114.109497",
            "longitude" : "114.109497",
            "netname" : "DXTL-HK",
            "organization" : "DingFeng XinHui(HongKong) Technology Limited",
            "subnet" : "117.18.224.0/22"
         },
         "ip" : "117.18.224.145",
         "ipv6" : "false",
         "latitude" : "22.2578",
         "location" : "22.2578,114.1657",
         "longitude" : "114.1657",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "DXTL Tseung Kwan O Service",
         "os" : "Windows",
         "osvendor" : "Microsoft",
         "port" : 5985,
         "product" : "HTTPAPI",
         "productvendor" : "Microsoft",
         "productversion" : "2.0",
         "protocol" : "winrm",
         "protocolversion" : "1.1",
         "seen_date" : "2024-11-21",
         "source" : "datascan",
         "status" : 401,
         "subnet" : "117.18.224.0/22",
         "tag" : "<enterprise field>: tag",
         "tls" : "false",
         "transport" : "tcp"
      }
      
  • 45.60.163.45:5985 (tcp/http) - last seen on 2024-11-21 at 09:10:26 UTC

    • IP
      45.60.163.45
      Network
      45.60.160.0/21
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      URL

      http://45.60.163.45:5985/wsman 503

      ASN
      AS19551
      Organization
      INCAPSULA
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      8970b17533db0db8cc9841c820a84b8a
      HTTP Header MD5
      9f0a5fc6afaeb8fba6913434b1d0f381
      HTTP Body MD5
      aca0b7ada1b0121ce6e8837f91080ff5
    • HTTP/1.1 503 Service Unavailable
      Content-Type: text/html
      Cache-Control: no-cache, no-store
      Connection: close
      Content-Length: 689
      X-Iinfo: 52-18774264-0 0NNN RT(1732180224315 209) q(0 -1 -1 -1) r(0 -1)
      
      <html style="height:100%"><head><META NAME="ROBOTS" CONTENT="NOINDEX, NOFOLLOW"><meta name="format-detection" content="telephone=no"><meta name="viewport" content="initial-scale=1.0"><meta http-equiv="X-UA-Compatible" content="IE=edge,chrome=1"></head><body style="margin:0px;height:100%"><iframe id="main-iframe" src="/_Incapsula_Resource?CWUDNSAI=5&xinfo=52-18774264-0%200NNN%20RT%281732180224315%20209%29%20q%280%20-1%20-1%20-1%29%20r%280%20-1%29&incident_id=0-83259861002028276&edet=22&cinfo=ffffffff&rpinfo=0&mth=POST" frameborder=0 width="100%" height="100%" marginheight="0px" marginwidth="0px">Request unsuccessful. Incapsula incident ID: 0-83259861002028276</iframe></body></html>
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-21T09:10:26.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "aca0b7ada1b0121ce6e8837f91080ff5",
               "bodymmh3" : -162911895,
               "headermd5" : "9f0a5fc6afaeb8fba6913434b1d0f381",
               "headermmh3" : 2143589213
            },
            "length" : 898
         },
         "asn" : "AS19551",
         "country" : "US",
         "data" : "HTTP/1.1 503 Service Unavailable\r\nContent-Type: text/html\r\nCache-Control: no-cache, no-store\r\nConnection: close\r\nContent-Length: 689\r\nX-Iinfo: 52-18774264-0 0NNN RT(1732180224315 209) q(0 -1 -1 -1) r(0 -1)\r\n\r\n<html style=\"height:100%\"><head><META NAME=\"ROBOTS\" CONTENT=\"NOINDEX, NOFOLLOW\"><meta name=\"format-detection\" content=\"telephone=no\"><meta name=\"viewport\" content=\"initial-scale=1.0\"><meta http-equiv=\"X-UA-Compatible\" content=\"IE=edge,chrome=1\"></head><body style=\"margin:0px;height:100%\"><iframe id=\"main-iframe\" src=\"/_Incapsula_Resource?CWUDNSAI=5&xinfo=52-18774264-0%200NNN%20RT%281732180224315%20209%29%20q%280%20-1%20-1%20-1%29%20r%280%20-1%29&incident_id=0-83259861002028276&edet=22&cinfo=ffffffff&rpinfo=0&mth=POST\" frameborder=0 width=\"100%\" height=\"100%\" marginheight=\"0px\" marginwidth=\"0px\">Request unsuccessful. Incapsula incident ID: 0-83259861002028276</iframe></body></html>",
         "datamd5" : "8970b17533db0db8cc9841c820a84b8a",
         "datammh3" : -171782501,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS19551",
            "continent" : "NA",
            "continentname" : "North America",
            "country" : "US",
            "countryname" : "United States",
            "domain" : [
               "imperva.com",
               "incapsula.com",
               "thalesgroup.com"
            ],
            "isineu" : "false",
            "latitude" : "37.09024",
            "location" : "37.09024,-95.712891",
            "longitude" : "-95.712891",
            "netname" : "INCAPSULA-NET",
            "organization" : "Incapsula Inc",
            "subnet" : "45.60.163.44/30"
         },
         "ip" : "45.60.163.45",
         "ipv6" : "false",
         "latitude" : "37.7510",
         "location" : "37.7510,-97.8220",
         "longitude" : "-97.8220",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "INCAPSULA",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 5985,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Service Unavailable",
         "seen_date" : "2024-11-21",
         "source" : "datascan",
         "status" : 503,
         "subnet" : "45.60.160.0/21",
         "tag" : "<enterprise field>: tag",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/wsman"
      }
      
  • 143.107.240.128:5985 (tcp/http) - last seen on 2024-11-21 at 09:10:08 UTC

    • IP
      143.107.240.128
      Network
      143.107.0.0/16
      Device

      <enterprise field>: device.class

      Operating System
      Microsoft Windows
      URL

      http://143.107.240.128:5985/wsman 401

      ASN
      AS28571
      Organization
      UNIVERSIDADE DE SAO PAULO
      Protocol
      http
      Source
      datascan
    • Operating System
      Microsoft Windows
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      17f6e05b174e4a9e6b80384555516a57
      HTTP Header MD5
      c55a5b3552b72d4d2a257355ba46392a
      HTTP Body MD5
      d41d8cd98f00b204e9800998ecf8427e
    • HTTP/1.1 401 
      WWW-Authenticate: Negotiate
      Date: Thu, 21 Nov 2024 09:11:01 GMT
      Connection: close
      Content-Length: 0
      
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-21T09:10:08.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "d41d8cd98f00b204e9800998ecf8427e",
               "bodymmh3" : -1,
               "headermd5" : "c55a5b3552b72d4d2a257355ba46392a",
               "headermmh3" : 1560370998
            },
            "length" : 121
         },
         "asn" : "AS28571",
         "city" : "S\u00e3o Paulo",
         "country" : "BR",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 401 \r\nWWW-Authenticate: Negotiate\r\nDate: Thu, 21 Nov 2024 09:11:01 GMT\r\nConnection: close\r\nContent-Length: 0\r\n\r\n",
         "datamd5" : "17f6e05b174e4a9e6b80384555516a57",
         "datammh3" : 421566560,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS28571",
            "continent" : "SA",
            "continentname" : "South America",
            "country" : "BR",
            "countryname" : "Brazil",
            "domain" : [
               "cert.br",
               "usp.br"
            ],
            "isineu" : "false",
            "latitude" : "-14.235004",
            "location" : "-14.235004,-51.92528",
            "longitude" : "-51.92528",
            "netname" : "63.025.530/0001-04",
            "organization" : "UNIVERSIDADE DE SAO PAULO",
            "subnet" : "143.107.0.0/16"
         },
         "ip" : "143.107.240.128",
         "ipv6" : "false",
         "latitude" : "-23.6283",
         "location" : "-23.6283,-46.6409",
         "longitude" : "-46.6409",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "UNIVERSIDADE DE SAO PAULO",
         "os" : "Windows",
         "osvendor" : "Microsoft",
         "port" : 5985,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "seen_date" : "2024-11-21",
         "source" : "datascan",
         "status" : 401,
         "subnet" : "143.107.0.0/16",
         "tag" : "<enterprise field>: tag",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/wsman"
      }
      
  • 38.11.135.252:5985 (tcp/winrm) - last seen on 2024-11-21 at 09:10:01 UTC

    • IP
      38.11.135.252
      Network
      38.11.128.0/19
      Device

      <enterprise field>: device.class

      Operating System
      Microsoft Windows
      ASN
      AS398478
      Organization
      PEG-HK
      Protocol
      winrm
      Source
      datascan
    • Operating System
      Microsoft Windows
      Product
      Microsoft HTTPAPI 2.0
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      e899186f574741b96aebc4929f015b0b
      HTTP Header MD5
      eb8dfa5136702f42e29b01a5ef58d026
      HTTP Body MD5
      d41d8cd98f00b204e9800998ecf8427e
    • HTTP/1.1 401 
      Server: Microsoft-HTTPAPI/2.0
      WWW-Authenticate: Negotiate
      Date: Thu, 21 Nov 2024 09:09:58 GMT
      Connection: close
      Content-Length: 0
      
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-21T09:10:01.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "d41d8cd98f00b204e9800998ecf8427e",
               "bodymmh3" : -1,
               "headermd5" : "eb8dfa5136702f42e29b01a5ef58d026",
               "headermmh3" : -706292877
            },
            "length" : 152
         },
         "asn" : "AS398478",
         "city" : "Hong Kong",
         "country" : "HK",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 401 \r\nServer: Microsoft-HTTPAPI/2.0\r\nWWW-Authenticate: Negotiate\r\nDate: Thu, 21 Nov 2024 09:09:58 GMT\r\nConnection: close\r\nContent-Length: 0\r\n\r\n",
         "datamd5" : "e899186f574741b96aebc4929f015b0b",
         "datammh3" : 1821300650,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS398478",
            "continent" : "NA",
            "continentname" : "North America",
            "country" : "US",
            "countryname" : "United States",
            "domain" : [
               "cogentco.com"
            ],
            "isineu" : "false",
            "latitude" : "37.09024",
            "location" : "37.09024,-95.712891",
            "longitude" : "-95.712891",
            "netname" : "COGENT-A",
            "organization" : "PSINet, Inc.",
            "subnet" : "38.11.128.0/19"
         },
         "ip" : "38.11.135.252",
         "ipv6" : "false",
         "latitude" : "22.2842",
         "location" : "22.2842,114.1759",
         "longitude" : "114.1759",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "PEG-HK",
         "os" : "Windows",
         "osvendor" : "Microsoft",
         "port" : 5985,
         "product" : "HTTPAPI",
         "productvendor" : "Microsoft",
         "productversion" : "2.0",
         "protocol" : "winrm",
         "protocolversion" : "1.1",
         "seen_date" : "2024-11-21",
         "source" : "datascan",
         "status" : 401,
         "subnet" : "38.11.128.0/19",
         "tag" : "<enterprise field>: tag",
         "tls" : "false",
         "transport" : "tcp"
      }