Returning 10 result(s) out of 130 in 0.084 second(s)

  • 185.234.66.63:789 (tcp/http) - last seen on 2024-11-07 at 05:10:27 UTC

    • IP
      185.234.66.63
      Network
      185.234.64.0/22
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Ubuntu
      URL

      http://185.234.66.63:789/ 400

      HTTP Title
      400 The plain HTTP request was sent to HTTPS port
      ASN
      AS44477
      Organization
      Stark Industries Solutions Ltd
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Ubuntu
      Product
      F5 Nginx 1.18.0
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      0f607a794922d0e529ea46b57721417d
      HTTP Header MD5
      73b5b39070f21c93f1b94a75281c1ce0
      HTTP Body MD5
      e2c7b0e1a897b6683f3a2814cb2f67cd
    • HTTP/1.1 400 Bad Request
      Server: nginx/1.18.0 (Ubuntu)
      Date: Thu, 07 Nov 2024 05:10:27 GMT
      Content-Type: text/html
      Content-Length: 264
      Connection: close
      
      <html>
      <head><title>400 The plain HTTP request was sent to HTTPS port</title></head>
      <body>
      <center><h1>400 Bad Request</h1></center>
      <center>The plain HTTP request was sent to HTTPS port</center>
      <hr><center>nginx/1.18.0 (Ubuntu)</center>
      </body>
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:10:27.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "e2c7b0e1a897b6683f3a2814cb2f67cd",
               "bodymmh3" : -1741231556,
               "headermd5" : "73b5b39070f21c93f1b94a75281c1ce0",
               "headermmh3" : -436203353,
               "title" : "400 The plain HTTP request was sent to HTTPS port"
            },
            "length" : 425
         },
         "asn" : "AS44477",
         "country" : "MD",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 400 Bad Request\r\nServer: nginx/1.18.0 (Ubuntu)\r\nDate: Thu, 07 Nov 2024 05:10:27 GMT\r\nContent-Type: text/html\r\nContent-Length: 264\r\nConnection: close\r\n\r\n<html>\r\n<head><title>400 The plain HTTP request was sent to HTTPS port</title></head>\r\n<body>\r\n<center><h1>400 Bad Request</h1></center>\r\n<center>The plain HTTP request was sent to HTTPS port</center>\r\n<hr><center>nginx/1.18.0 (Ubuntu)</center>\r\n</body>\r\n</html>\r\n",
         "datamd5" : "0f607a794922d0e529ea46b57721417d",
         "datammh3" : 907783723,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS44477",
            "continent" : "AS",
            "continentname" : "Asia",
            "country" : "TR",
            "countryname" : "Turkey",
            "domain" : [
               "stark-industries.solutions"
            ],
            "isineu" : "false",
            "latitude" : "38.963745",
            "location" : "38.963745,35.243322",
            "longitude" : "35.243322",
            "netname" : "STARK",
            "organization" : "STARK INDUSTRIES SOLUTIONS LTD.",
            "subnet" : "185.234.66.0/24"
         },
         "ip" : "185.234.66.63",
         "ipv6" : "false",
         "latitude" : "47.0188",
         "location" : "47.0188,28.8128",
         "longitude" : "28.8128",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "Stark Industries Solutions Ltd",
         "os" : "Linux",
         "osdistribution" : "Ubuntu",
         "osvendor" : "Linux",
         "port" : 789,
         "product" : "Nginx",
         "productvendor" : "F5",
         "productversion" : "1.18.0",
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Bad Request",
         "seen_date" : "2024-11-07",
         "source" : "datascan",
         "status" : 400,
         "subnet" : "185.234.64.0/22",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 200.68.111.24:789 (tcp/http) - last seen on 2024-11-07 at 05:10:04 UTC

    • IP
      200.68.111.24
      Network
      200.68.96.0/20
      Domain(s)
      iplannetworks.net
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Ubuntu
      URL

      http://200.68.111.24:789/ 400

      HTTP Title
      400 The plain HTTP request was sent to HTTPS port
      Reverse DNS
      customer-static-68-111-24.iplannetworks.net
      ASN
      AS16814
      Organization
      NSS S.A.
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Ubuntu
      Product
      F5 Nginx 1.18.0
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      0f607a794922d0e529ea46b57721417d
      HTTP Header MD5
      73b5b39070f21c93f1b94a75281c1ce0
      HTTP Body MD5
      e2c7b0e1a897b6683f3a2814cb2f67cd
    • HTTP/1.1 400 Bad Request
      Server: nginx/1.18.0 (Ubuntu)
      Date: Thu, 07 Nov 2024 05:10:04 GMT
      Content-Type: text/html
      Content-Length: 264
      Connection: close
      
      <html>
      <head><title>400 The plain HTTP request was sent to HTTPS port</title></head>
      <body>
      <center><h1>400 Bad Request</h1></center>
      <center>The plain HTTP request was sent to HTTPS port</center>
      <hr><center>nginx/1.18.0 (Ubuntu)</center>
      </body>
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:10:04.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "e2c7b0e1a897b6683f3a2814cb2f67cd",
               "bodymmh3" : -1741231556,
               "headermd5" : "73b5b39070f21c93f1b94a75281c1ce0",
               "headermmh3" : 1177357258,
               "title" : "400 The plain HTTP request was sent to HTTPS port"
            },
            "length" : 425
         },
         "asn" : "AS16814",
         "city" : "Buenos Aires",
         "country" : "AR",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 400 Bad Request\r\nServer: nginx/1.18.0 (Ubuntu)\r\nDate: Thu, 07 Nov 2024 05:10:04 GMT\r\nContent-Type: text/html\r\nContent-Length: 264\r\nConnection: close\r\n\r\n<html>\r\n<head><title>400 The plain HTTP request was sent to HTTPS port</title></head>\r\n<body>\r\n<center><h1>400 Bad Request</h1></center>\r\n<center>The plain HTTP request was sent to HTTPS port</center>\r\n<hr><center>nginx/1.18.0 (Ubuntu)</center>\r\n</body>\r\n</html>\r\n",
         "datamd5" : "0f607a794922d0e529ea46b57721417d",
         "datammh3" : 907783723,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "iplannetworks.net"
         ],
         "geolocus" : {
            "asn" : "AS16814",
            "continent" : "SA",
            "continentname" : "South America",
            "country" : "AR",
            "countryname" : "Argentina",
            "domain" : [
               "iplan.com.ar"
            ],
            "isineu" : "false",
            "latitude" : "-38.416097",
            "location" : "-38.416097,-63.616672",
            "longitude" : "-63.616672",
            "netname" : "AR-SASA106-LACNIC",
            "organization" : "SIF AMERICA S.A.",
            "subnet" : "200.68.96.0/20"
         },
         "host" : [
            "customer-static-68-111-24"
         ],
         "hostname" : [
            "customer-static-68-111-24.iplannetworks.net"
         ],
         "ip" : "200.68.111.24",
         "ipv6" : "false",
         "latitude" : "-34.6049",
         "location" : "-34.6049,-58.4455",
         "longitude" : "-58.4455",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "NSS S.A.",
         "os" : "Linux",
         "osdistribution" : "Ubuntu",
         "osvendor" : "Linux",
         "port" : 789,
         "product" : "Nginx",
         "productvendor" : "F5",
         "productversion" : "1.18.0",
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Bad Request",
         "reverse" : [
            "customer-static-68-111-24.iplannetworks.net"
         ],
         "seen_date" : "2024-11-07",
         "source" : "datascan",
         "status" : 400,
         "subnet" : "200.68.96.0/20",
         "tld" : [
            "net"
         ],
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 67.230.161.3:789 (tcp/http) - last seen on 2024-11-07 at 04:07:04 UTC

    • IP
      67.230.161.3
      Network
      67.230.160.0/19
      Domain(s)
      16clouds.com
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      URL

      http://67.230.161.3:789/ 400

      HTTP Title
      400 The plain HTTP request was sent to HTTPS port
      Reverse DNS
      67.230.161.3.16clouds.com
      ASN
      AS25820
      Organization
      IT7NET
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
      Product
      F5 Nginx 1.18.0
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      1a534cf98628c83d237d23ef4a2aabdd
      HTTP Header MD5
      0f39dc4f140a76145099bbf0048ae6f4
      HTTP Body MD5
      8e688195eec136e2ab8be1bc1a0a1afa
    • HTTP/1.1 400 Bad Request
      Server: nginx/1.18.0
      Date: Thu, 07 Nov 2024 04:07:03 GMT
      Content-Type: text/html
      Content-Length: 255
      Connection: close
      
      <html>
      <head><title>400 The plain HTTP request was sent to HTTPS port</title></head>
      <body>
      <center><h1>400 Bad Request</h1></center>
      <center>The plain HTTP request was sent to HTTPS port</center>
      <hr><center>nginx/1.18.0</center>
      </body>
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T04:07:04.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "8e688195eec136e2ab8be1bc1a0a1afa",
               "bodymmh3" : -1468404449,
               "headermd5" : "0f39dc4f140a76145099bbf0048ae6f4",
               "headermmh3" : 213677886,
               "title" : "400 The plain HTTP request was sent to HTTPS port"
            },
            "length" : 407
         },
         "asn" : "AS25820",
         "city" : "Los Angeles",
         "country" : "US",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 400 Bad Request\r\nServer: nginx/1.18.0\r\nDate: Thu, 07 Nov 2024 04:07:03 GMT\r\nContent-Type: text/html\r\nContent-Length: 255\r\nConnection: close\r\n\r\n<html>\r\n<head><title>400 The plain HTTP request was sent to HTTPS port</title></head>\r\n<body>\r\n<center><h1>400 Bad Request</h1></center>\r\n<center>The plain HTTP request was sent to HTTPS port</center>\r\n<hr><center>nginx/1.18.0</center>\r\n</body>\r\n</html>\r\n",
         "datamd5" : "1a534cf98628c83d237d23ef4a2aabdd",
         "datammh3" : -682723585,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "16clouds.com"
         ],
         "geolocus" : {
            "asn" : "AS25820",
            "continent" : "NA",
            "continentname" : "North America",
            "country" : "CA",
            "countryname" : "Canada",
            "domain" : [
               "16clouds.com",
               "sioru.com"
            ],
            "isineu" : "false",
            "latitude" : "56.130366",
            "location" : "56.130366,-106.346771",
            "longitude" : "-106.346771",
            "netname" : "CL-67-230-160-0-19",
            "organization" : "Cluster Logic Inc",
            "subnet" : "67.230.160.0/19"
         },
         "host" : [
            67
         ],
         "hostname" : [
            "67.230.161.3.16clouds.com"
         ],
         "ip" : "67.230.161.3",
         "ipv6" : "false",
         "latitude" : "34.0514",
         "location" : "34.0514,-118.2707",
         "longitude" : "-118.2707",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "IT7NET",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 789,
         "product" : "Nginx",
         "productvendor" : "F5",
         "productversion" : "1.18.0",
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Bad Request",
         "reverse" : [
            "67.230.161.3.16clouds.com"
         ],
         "seen_date" : "2024-11-07",
         "source" : "datascan",
         "status" : 400,
         "subdomains" : [
            "161.3.16clouds.com",
            "230.161.3.16clouds.com",
            "3.16clouds.com"
         ],
         "subnet" : "67.230.160.0/19",
         "tld" : [
            "com"
         ],
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 91.92.215.81:789 (tcp/http) - last seen on 2024-11-07 at 03:30:04 UTC

    • IP
      91.92.215.81
      Network
      91.92.208.0/21
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Ubuntu
      URL

      http://91.92.215.81:789/ 400

      HTTP Title
      400 The plain HTTP request was sent to HTTPS port
      ASN
      AS58224
      Organization
      Iran Telecommunication Company PJS
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Ubuntu
      Product
      F5 Nginx 1.18.0
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      0f607a794922d0e529ea46b57721417d
      HTTP Header MD5
      73b5b39070f21c93f1b94a75281c1ce0
      HTTP Body MD5
      e2c7b0e1a897b6683f3a2814cb2f67cd
    • HTTP/1.1 400 Bad Request
      Server: nginx/1.18.0 (Ubuntu)
      Date: Thu, 07 Nov 2024 03:30:04 GMT
      Content-Type: text/html
      Content-Length: 264
      Connection: close
      
      <html>
      <head><title>400 The plain HTTP request was sent to HTTPS port</title></head>
      <body>
      <center><h1>400 Bad Request</h1></center>
      <center>The plain HTTP request was sent to HTTPS port</center>
      <hr><center>nginx/1.18.0 (Ubuntu)</center>
      </body>
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T03:30:04.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "e2c7b0e1a897b6683f3a2814cb2f67cd",
               "bodymmh3" : -1741231556,
               "headermd5" : "73b5b39070f21c93f1b94a75281c1ce0",
               "headermmh3" : -89993896,
               "title" : "400 The plain HTTP request was sent to HTTPS port"
            },
            "length" : 425
         },
         "asn" : "AS58224",
         "country" : "IR",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 400 Bad Request\r\nServer: nginx/1.18.0 (Ubuntu)\r\nDate: Thu, 07 Nov 2024 03:30:04 GMT\r\nContent-Type: text/html\r\nContent-Length: 264\r\nConnection: close\r\n\r\n<html>\r\n<head><title>400 The plain HTTP request was sent to HTTPS port</title></head>\r\n<body>\r\n<center><h1>400 Bad Request</h1></center>\r\n<center>The plain HTTP request was sent to HTTPS port</center>\r\n<hr><center>nginx/1.18.0 (Ubuntu)</center>\r\n</body>\r\n</html>\r\n",
         "datamd5" : "0f607a794922d0e529ea46b57721417d",
         "datammh3" : 907783723,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS12880",
            "continent" : "AS",
            "continentname" : "Asia",
            "country" : "IR",
            "countryname" : "Iran",
            "domain" : [
               "tci.ir"
            ],
            "isineu" : "false",
            "latitude" : "32.427908",
            "location" : "32.427908,53.688046",
            "longitude" : "53.688046",
            "netname" : "TCITHR",
            "organization" : "Telecommunication Company of Tehran",
            "subnet" : "91.92.212.0/22"
         },
         "ip" : "91.92.215.81",
         "ipv6" : "false",
         "latitude" : "35.6980",
         "location" : "35.6980,51.4115",
         "longitude" : "51.4115",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "Iran Telecommunication Company PJS",
         "os" : "Linux",
         "osdistribution" : "Ubuntu",
         "osvendor" : "Linux",
         "port" : 789,
         "product" : "Nginx",
         "productvendor" : "F5",
         "productversion" : "1.18.0",
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Bad Request",
         "seen_date" : "2024-11-07",
         "source" : "datascan",
         "status" : 400,
         "subnet" : "91.92.208.0/21",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 185.234.66.62:789 (tcp/http) - last seen on 2024-11-07 at 00:05:27 UTC

    • IP
      185.234.66.62
      Network
      185.234.64.0/22
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Ubuntu
      URL

      http://185.234.66.62:789/ 400

      HTTP Title
      400 The plain HTTP request was sent to HTTPS port
      ASN
      AS44477
      Organization
      Stark Industries Solutions Ltd
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Ubuntu
      Product
      F5 Nginx 1.18.0
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      0f607a794922d0e529ea46b57721417d
      HTTP Header MD5
      73b5b39070f21c93f1b94a75281c1ce0
      HTTP Body MD5
      e2c7b0e1a897b6683f3a2814cb2f67cd
    • HTTP/1.1 400 Bad Request
      Server: nginx/1.18.0 (Ubuntu)
      Date: Thu, 07 Nov 2024 00:05:27 GMT
      Content-Type: text/html
      Content-Length: 264
      Connection: close
      
      <html>
      <head><title>400 The plain HTTP request was sent to HTTPS port</title></head>
      <body>
      <center><h1>400 Bad Request</h1></center>
      <center>The plain HTTP request was sent to HTTPS port</center>
      <hr><center>nginx/1.18.0 (Ubuntu)</center>
      </body>
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T00:05:27.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "e2c7b0e1a897b6683f3a2814cb2f67cd",
               "bodymmh3" : -1741231556,
               "headermd5" : "73b5b39070f21c93f1b94a75281c1ce0",
               "headermmh3" : -301980734,
               "title" : "400 The plain HTTP request was sent to HTTPS port"
            },
            "length" : 425
         },
         "asn" : "AS44477",
         "country" : "MD",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 400 Bad Request\r\nServer: nginx/1.18.0 (Ubuntu)\r\nDate: Thu, 07 Nov 2024 00:05:27 GMT\r\nContent-Type: text/html\r\nContent-Length: 264\r\nConnection: close\r\n\r\n<html>\r\n<head><title>400 The plain HTTP request was sent to HTTPS port</title></head>\r\n<body>\r\n<center><h1>400 Bad Request</h1></center>\r\n<center>The plain HTTP request was sent to HTTPS port</center>\r\n<hr><center>nginx/1.18.0 (Ubuntu)</center>\r\n</body>\r\n</html>\r\n",
         "datamd5" : "0f607a794922d0e529ea46b57721417d",
         "datammh3" : 907783723,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS44477",
            "continent" : "AS",
            "continentname" : "Asia",
            "country" : "TR",
            "countryname" : "Turkey",
            "domain" : [
               "stark-industries.solutions"
            ],
            "isineu" : "false",
            "latitude" : "38.963745",
            "location" : "38.963745,35.243322",
            "longitude" : "35.243322",
            "netname" : "STARK",
            "organization" : "STARK INDUSTRIES SOLUTIONS LTD.",
            "subnet" : "185.234.66.0/24"
         },
         "ip" : "185.234.66.62",
         "ipv6" : "false",
         "latitude" : "47.0188",
         "location" : "47.0188,28.8128",
         "longitude" : "28.8128",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "Stark Industries Solutions Ltd",
         "os" : "Linux",
         "osdistribution" : "Ubuntu",
         "osvendor" : "Linux",
         "port" : 789,
         "product" : "Nginx",
         "productvendor" : "F5",
         "productversion" : "1.18.0",
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Bad Request",
         "seen_date" : "2024-11-07",
         "source" : "datascan",
         "status" : 400,
         "subnet" : "185.234.64.0/22",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 157.20.25.229:789 (tcp/http) - last seen on 2024-11-06 at 23:03:43 UTC

    • IP
      157.20.25.229
      Network
      157.20.25.0/24
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Ubuntu
      URL

      http://157.20.25.229:789/ 400

      HTTP Title
      400 The plain HTTP request was sent to HTTPS port
      ASN
      AS152387
      Organization
      Rumah Sakit Panti Rapih
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Ubuntu
      Product
      F5 Nginx 1.18.0
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      0f607a794922d0e529ea46b57721417d
      HTTP Header MD5
      73b5b39070f21c93f1b94a75281c1ce0
      HTTP Body MD5
      e2c7b0e1a897b6683f3a2814cb2f67cd
    • HTTP/1.1 400 Bad Request
      Server: nginx/1.18.0 (Ubuntu)
      Date: Wed, 06 Nov 2024 23:03:43 GMT
      Content-Type: text/html
      Content-Length: 264
      Connection: close
      
      <html>
      <head><title>400 The plain HTTP request was sent to HTTPS port</title></head>
      <body>
      <center><h1>400 Bad Request</h1></center>
      <center>The plain HTTP request was sent to HTTPS port</center>
      <hr><center>nginx/1.18.0 (Ubuntu)</center>
      </body>
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-06T23:03:43.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "e2c7b0e1a897b6683f3a2814cb2f67cd",
               "bodymmh3" : -1741231556,
               "headermd5" : "73b5b39070f21c93f1b94a75281c1ce0",
               "headermmh3" : -1549598350,
               "title" : "400 The plain HTTP request was sent to HTTPS port"
            },
            "length" : 425
         },
         "asn" : "AS152387",
         "country" : "ID",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 400 Bad Request\r\nServer: nginx/1.18.0 (Ubuntu)\r\nDate: Wed, 06 Nov 2024 23:03:43 GMT\r\nContent-Type: text/html\r\nContent-Length: 264\r\nConnection: close\r\n\r\n<html>\r\n<head><title>400 The plain HTTP request was sent to HTTPS port</title></head>\r\n<body>\r\n<center><h1>400 Bad Request</h1></center>\r\n<center>The plain HTTP request was sent to HTTPS port</center>\r\n<hr><center>nginx/1.18.0 (Ubuntu)</center>\r\n</body>\r\n</html>\r\n",
         "datamd5" : "0f607a794922d0e529ea46b57721417d",
         "datammh3" : 907783723,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS63506",
            "continent" : "AS",
            "continentname" : "Asia",
            "country" : "ID",
            "countryname" : "Indonesia",
            "domain" : [
               "basarnas.go.id"
            ],
            "isineu" : "false",
            "latitude" : "-0.789275",
            "location" : "-0.789275,113.921327",
            "longitude" : "113.921327",
            "netname" : "IDNIC-BASARNAS-ID",
            "organization" : "Badan SAR Nasional",
            "subnet" : "157.20.24.0/23"
         },
         "ip" : "157.20.25.229",
         "ipv6" : "false",
         "latitude" : "-6.1728",
         "location" : "-6.1728,106.8272",
         "longitude" : "106.8272",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "Rumah Sakit Panti Rapih",
         "os" : "Linux",
         "osdistribution" : "Ubuntu",
         "osvendor" : "Linux",
         "port" : 789,
         "product" : "Nginx",
         "productvendor" : "F5",
         "productversion" : "1.18.0",
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Bad Request",
         "seen_date" : "2024-11-06",
         "source" : "datascan",
         "status" : 400,
         "subnet" : "157.20.25.0/24",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 185.238.44.185:789 (tcp/http) - last seen on 2024-11-06 at 21:42:00 UTC

    • IP
      185.238.44.185
      Network
      185.238.44.0/22
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Ubuntu
      URL

      http://185.238.44.185:789/ 200

      HTTP Title
      سامانه شهروندیار - شهرداری کرمانشاه
      ASN
      AS48359
      Organization
      Hesabgar Pardaz Gharb PJSC
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Ubuntu
      Product
      F5 Nginx 1.18.0
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      c8d22b4bea53c5466f5fbf4d7706f4cd
      HTTP Header MD5
      7cc11d7c7254197fc3d4afdc95bd6b09
      HTTP Body MD5
      aac2ee28381be7abc796036261e96690
    • HTTP/1.1 200 OK
      Server: nginx/1.18.0 (Ubuntu)
      Date: Wed, 06 Nov 2024 21:41:59 GMT
      Content-Type: text/html
      Content-Length: 595
      Last-Modified: Wed, 06 Nov 2024 11:22:07 GMT
      Connection: close
      ETag: "672b515f-253"
      Accept-Ranges: bytes
      
      <!DOCTYPE html>
      <html lang="fa" class="!tw-overflow-hidden">
      
      <head>
          <meta charset="UTF-8" />
          <link rel="icon" href="/assets/logo-kermanshah-00e92124.png" />
          <meta name="viewport" content="width=device-width, initial-scale=1.0" />
          <meta id="theme_color" name="theme-color" content="#00000" />
          <title>سامانه شهروندیار - شهرداری کرمانشاه</title>
        <script type="module" crossorigin src="/assets/index-04416858.js"></script>
        <link rel="stylesheet" href="/assets/index-19a8ef20.css">
      </head>
      
      <body>
          <div id="app"></div>
          
      </body>
      
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-06T21:42:00.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "aac2ee28381be7abc796036261e96690",
               "bodymmh3" : 1774159650,
               "header" : [
                  {
                     "name" : "Last-Modified",
                     "value" : "Wed, 06 Nov 2024 11:22:07 GMT"
                  },
                  {
                     "value" : "672b515f-253",
                     "name" : "ETag"
                  }
               ],
               "headermd5" : "7cc11d7c7254197fc3d4afdc95bd6b09",
               "headermmh3" : -566566586,
               "title" : "\u0633\u0627\u0645\u0627\u0646\u0647 \u0634\u0647\u0631\u0648\u0646\u062f\u06cc\u0627\u0631 - \u0634\u0647\u0631\u062f\u0627\u0631\u06cc \u06a9\u0631\u0645\u0627\u0646\u0634\u0627\u0647"
            },
            "length" : 837
         },
         "asn" : "AS48359",
         "city" : "Kermanshah",
         "country" : "IR",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 200 OK\r\nServer: nginx/1.18.0 (Ubuntu)\r\nDate: Wed, 06 Nov 2024 21:41:59 GMT\r\nContent-Type: text/html\r\nContent-Length: 595\r\nLast-Modified: Wed, 06 Nov 2024 11:22:07 GMT\r\nConnection: close\r\nETag: \"672b515f-253\"\r\nAccept-Ranges: bytes\r\n\r\n<!DOCTYPE html>\n<html lang=\"fa\" class=\"!tw-overflow-hidden\">\n\n<head>\n    <meta charset=\"UTF-8\" />\n    <link rel=\"icon\" href=\"/assets/logo-kermanshah-00e92124.png\" />\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\" />\n    <meta id=\"theme_color\" name=\"theme-color\" content=\"#00000\" />\n    <title>\u0633\u0627\u0645\u0627\u0646\u0647 \u0634\u0647\u0631\u0648\u0646\u062f\u06cc\u0627\u0631 - \u0634\u0647\u0631\u062f\u0627\u0631\u06cc \u06a9\u0631\u0645\u0627\u0646\u0634\u0627\u0647</title>\n  <script type=\"module\" crossorigin src=\"/assets/index-04416858.js\"></script>\n  <link rel=\"stylesheet\" href=\"/assets/index-19a8ef20.css\">\n</head>\n\n<body>\n    <div id=\"app\"></div>\n    \n</body>\n\n</html>\n",
         "datamd5" : "c8d22b4bea53c5466f5fbf4d7706f4cd",
         "datammh3" : 39286073,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "ip" : "185.238.44.185",
         "ipv6" : "false",
         "latitude" : "34.3117",
         "location" : "34.3117,47.0611",
         "longitude" : "47.0611",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "Hesabgar Pardaz Gharb PJSC",
         "os" : "Linux",
         "osdistribution" : "Ubuntu",
         "osvendor" : "Linux",
         "port" : 789,
         "product" : "Nginx",
         "productvendor" : "F5",
         "productversion" : "1.18.0",
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "OK",
         "seen_date" : "2024-11-06",
         "source" : "datascan",
         "status" : 200,
         "subnet" : "185.238.44.0/22",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 103.90.86.104:789 (tcp/http) - last seen on 2024-11-06 at 16:37:00 UTC

    • IP
      103.90.86.104
      Network
      103.90.86.0/23
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Ubuntu
      URL

      http://103.90.86.104:789/ 404

      ASN
      AS23647
      Organization
      Communications & Communicate Nepal Pvt Ltd
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Ubuntu
      Product
      F5 Nginx 1.18.0
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      5cbc09081ddf73035fd5f56f1a5cff0a
      HTTP Header MD5
      d19c22e362a78214139942684c5a731d
      HTTP Body MD5
      d41d8cd98f00b204e9800998ecf8427e
    • HTTP/1.1 404 Not Found
      Server: nginx/1.18.0 (Ubuntu)
      Date: Wed, 06 Nov 2024 16:37:00 GMT
      Content-Length: 0
      Connection: close
      
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-06T16:37:00.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "d41d8cd98f00b204e9800998ecf8427e",
               "bodymmh3" : -1,
               "headermd5" : "d19c22e362a78214139942684c5a731d",
               "headermmh3" : 1909487857
            },
            "length" : 132
         },
         "asn" : "AS23647",
         "country" : "NP",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 404 Not Found\r\nServer: nginx/1.18.0 (Ubuntu)\r\nDate: Wed, 06 Nov 2024 16:37:00 GMT\r\nContent-Length: 0\r\nConnection: close\r\n\r\n",
         "datamd5" : "5cbc09081ddf73035fd5f56f1a5cff0a",
         "datammh3" : -1281775670,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS23647",
            "continent" : "AS",
            "continentname" : "Asia",
            "country" : "NP",
            "countryname" : "Nepal",
            "domain" : [
               "datahub.com.np"
            ],
            "isineu" : "false",
            "latitude" : "28.394857",
            "location" : "28.394857,84.124008",
            "longitude" : "84.124008",
            "netname" : "DATAHUB-NP",
            "organization" : "Data Hub Pvt. Ltd.",
            "subnet" : "103.90.86.0/23"
         },
         "ip" : "103.90.86.104",
         "ipv6" : "false",
         "latitude" : "28.0124",
         "location" : "28.0124,83.9979",
         "longitude" : "83.9979",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "Communications & Communicate Nepal Pvt Ltd",
         "os" : "Linux",
         "osdistribution" : "Ubuntu",
         "osvendor" : "Linux",
         "port" : 789,
         "product" : "Nginx",
         "productvendor" : "F5",
         "productversion" : "1.18.0",
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Not Found",
         "seen_date" : "2024-11-06",
         "source" : "datascan",
         "status" : 404,
         "subnet" : "103.90.86.0/23",
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 82.140.97.114:789 (tcp/http) - last seen on 2024-11-06 at 15:43:15 UTC

    • IP
      82.140.97.114
      Alternative IP(s)
      178.19.250.20
      Network
      82.140.96.0/19
      Domain(s)
      neosystems.ru
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Ubuntu
      URL

      http://82.140.97.114:789/ 400

      HTTP Title
      400 The plain HTTP request was sent to HTTPS port
      Reverse DNS
      ltd.neosystems.ru
      ASN
      AS20632
      Organization
      PJSC MegaFon
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Ubuntu
      Product
      F5 Nginx 1.18.0
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      0f607a794922d0e529ea46b57721417d
      HTTP Header MD5
      73b5b39070f21c93f1b94a75281c1ce0
      HTTP Body MD5
      e2c7b0e1a897b6683f3a2814cb2f67cd
    • HTTP/1.1 400 Bad Request
      Server: nginx/1.18.0 (Ubuntu)
      Date: Wed, 06 Nov 2024 15:43:15 GMT
      Content-Type: text/html
      Content-Length: 264
      Connection: close
      
      <html>
      <head><title>400 The plain HTTP request was sent to HTTPS port</title></head>
      <body>
      <center><h1>400 Bad Request</h1></center>
      <center>The plain HTTP request was sent to HTTPS port</center>
      <hr><center>nginx/1.18.0 (Ubuntu)</center>
      </body>
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-06T15:43:15.000Z",
         "alternativeip" : [
            "178.19.250.20"
         ],
         "app" : {
            "http" : {
               "bodymd5" : "e2c7b0e1a897b6683f3a2814cb2f67cd",
               "bodymmh3" : -1741231556,
               "headermd5" : "73b5b39070f21c93f1b94a75281c1ce0",
               "headermmh3" : -1360827439,
               "title" : "400 The plain HTTP request was sent to HTTPS port"
            },
            "length" : 425
         },
         "asn" : "AS20632",
         "country" : "RU",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 400 Bad Request\r\nServer: nginx/1.18.0 (Ubuntu)\r\nDate: Wed, 06 Nov 2024 15:43:15 GMT\r\nContent-Type: text/html\r\nContent-Length: 264\r\nConnection: close\r\n\r\n<html>\r\n<head><title>400 The plain HTTP request was sent to HTTPS port</title></head>\r\n<body>\r\n<center><h1>400 Bad Request</h1></center>\r\n<center>The plain HTTP request was sent to HTTPS port</center>\r\n<hr><center>nginx/1.18.0 (Ubuntu)</center>\r\n</body>\r\n</html>\r\n",
         "datamd5" : "0f607a794922d0e529ea46b57721417d",
         "datammh3" : 907783723,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "neosystems.ru"
         ],
         "geolocus" : {
            "asn" : "AS20632",
            "continent" : "EU",
            "continentname" : "Europe",
            "country" : "RU",
            "countryname" : "Russia",
            "domain" : [
               "megafon.ru"
            ],
            "isineu" : "false",
            "latitude" : "61.52401",
            "location" : "61.52401,105.318756",
            "longitude" : "105.318756",
            "netname" : "CORE-BUS-SYS",
            "organization" : "ZAO PeterStar",
            "subnet" : "82.140.96.0/19"
         },
         "host" : [
            "ltd"
         ],
         "hostname" : [
            "ltd.neosystems.ru"
         ],
         "ip" : "82.140.97.114",
         "ipv6" : "false",
         "latitude" : "55.7386",
         "location" : "55.7386,37.6068",
         "longitude" : "37.6068",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "PJSC MegaFon",
         "os" : "Linux",
         "osdistribution" : "Ubuntu",
         "osvendor" : "Linux",
         "port" : 789,
         "product" : "Nginx",
         "productvendor" : "F5",
         "productversion" : "1.18.0",
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Bad Request",
         "reverse" : [
            "ltd.neosystems.ru"
         ],
         "seen_date" : "2024-11-06",
         "source" : "datascan",
         "status" : 400,
         "subnet" : "82.140.96.0/19",
         "tld" : [
            "ru"
         ],
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }
      
  • 139.99.179.105:789 (tcp/http) - last seen on 2024-11-06 at 13:27:02 UTC

    • IP
      139.99.179.105
      Network
      139.99.0.0/16
      Domain(s)
      ip-139-99-179.net
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Ubuntu
      URL

      http://139.99.179.105:789/ 400

      HTTP Title
      400 The plain HTTP request was sent to HTTPS port
      Reverse DNS
      ip105.ip-139-99-179.net
      ASN
      AS16276
      Organization
      OVH SAS
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Ubuntu
      Product
      F5 Nginx 1.18.0
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      0f607a794922d0e529ea46b57721417d
      HTTP Header MD5
      73b5b39070f21c93f1b94a75281c1ce0
      HTTP Body MD5
      e2c7b0e1a897b6683f3a2814cb2f67cd
    • HTTP/1.1 400 Bad Request
      Server: nginx/1.18.0 (Ubuntu)
      Date: Wed, 06 Nov 2024 13:27:01 GMT
      Content-Type: text/html
      Content-Length: 264
      Connection: close
      
      <html>
      <head><title>400 The plain HTTP request was sent to HTTPS port</title></head>
      <body>
      <center><h1>400 Bad Request</h1></center>
      <center>The plain HTTP request was sent to HTTPS port</center>
      <hr><center>nginx/1.18.0 (Ubuntu)</center>
      </body>
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-06T13:27:02.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "e2c7b0e1a897b6683f3a2814cb2f67cd",
               "bodymmh3" : -1741231556,
               "headermd5" : "73b5b39070f21c93f1b94a75281c1ce0",
               "headermmh3" : 1656417587,
               "title" : "400 The plain HTTP request was sent to HTTPS port"
            },
            "length" : 425
         },
         "asn" : "AS16276",
         "city" : "Sydney",
         "country" : "AU",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 400 Bad Request\r\nServer: nginx/1.18.0 (Ubuntu)\r\nDate: Wed, 06 Nov 2024 13:27:01 GMT\r\nContent-Type: text/html\r\nContent-Length: 264\r\nConnection: close\r\n\r\n<html>\r\n<head><title>400 The plain HTTP request was sent to HTTPS port</title></head>\r\n<body>\r\n<center><h1>400 Bad Request</h1></center>\r\n<center>The plain HTTP request was sent to HTTPS port</center>\r\n<hr><center>nginx/1.18.0 (Ubuntu)</center>\r\n</body>\r\n</html>\r\n",
         "datamd5" : "0f607a794922d0e529ea46b57721417d",
         "datammh3" : 907783723,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "ip-139-99-179.net"
         ],
         "geolocus" : {
            "asn" : "AS16276",
            "continent" : "OC",
            "continentname" : "Oceania",
            "country" : "AU",
            "countryname" : "Australia",
            "domain" : [
               "ovh.ca",
               "ovh.net"
            ],
            "isineu" : "false",
            "latitude" : "-25.274398",
            "location" : "-25.274398,133.775136",
            "longitude" : "133.775136",
            "netname" : "OVH-INFRA",
            "organization" : "OVH Australia PTY LTD",
            "subnet" : "139.99.128.0/17"
         },
         "host" : [
            "ip105"
         ],
         "hostname" : [
            "ip105.ip-139-99-179.net"
         ],
         "ip" : "139.99.179.105",
         "ipv6" : "false",
         "latitude" : "-33.8715",
         "location" : "-33.8715,151.2006",
         "longitude" : "151.2006",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "OVH SAS",
         "os" : "Linux",
         "osdistribution" : "Ubuntu",
         "osvendor" : "Linux",
         "port" : 789,
         "product" : "Nginx",
         "productvendor" : "F5",
         "productversion" : "1.18.0",
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Bad Request",
         "reverse" : [
            "ip105.ip-139-99-179.net"
         ],
         "seen_date" : "2024-11-06",
         "source" : "datascan",
         "status" : 400,
         "subnet" : "139.99.0.0/16",
         "tag" : "<enterprise field>: tag",
         "tld" : [
            "net"
         ],
         "tls" : "false",
         "transport" : "tcp",
         "url" : "/"
      }