Returning 10 result(s) out of 12,414 in 0.382 second(s)

  • 137.220.148.156:11112 (tcp/http) - last seen on 2024-11-21 at 08:11:13 UTC

    • IP
      137.220.148.156
      Network
      137.220.144.0/20
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      HTTP Title
      400 Bad Request
      ASN
      AS152194
      Organization
      CTG Server Limited
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
      Product
      F5 Nginx
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      28715c6ec3fd38b6ed232e3e37959e9c
      HTTP Header MD5
      a629a0fe278971ad61801ba6975ba467
      HTTP Body MD5
      16444d0bf46608253d591db62f41e7c3
    • HTTP/1.1 400 Bad Request
      Server: nginx
      Date: Thu, 21 Nov 2024 08:11:12 GMT
      Content-Type: text/html
      Content-Length: 150
      Connection: close
      
      <html>
      <head><title>400 Bad Request</title></head>
      <body>
      <center><h1>400 Bad Request</h1></center>
      <hr><center>nginx</center>
      </body>
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-21T08:11:13.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "16444d0bf46608253d591db62f41e7c3",
               "bodymmh3" : -534304446,
               "headermd5" : "a629a0fe278971ad61801ba6975ba467",
               "headermmh3" : 813093177,
               "title" : "400 Bad Request"
            },
            "length" : 295
         },
         "asn" : "AS152194",
         "city" : "Tokyo",
         "country" : "JP",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 400 Bad Request\r\nServer: nginx\r\nDate: Thu, 21 Nov 2024 08:11:12 GMT\r\nContent-Type: text/html\r\nContent-Length: 150\r\nConnection: close\r\n\r\n<html>\r\n<head><title>400 Bad Request</title></head>\r\n<body>\r\n<center><h1>400 Bad Request</h1></center>\r\n<hr><center>nginx</center>\r\n</body>\r\n</html>\r\n",
         "datamd5" : "28715c6ec3fd38b6ed232e3e37959e9c",
         "datammh3" : -1512152686,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS152194",
            "continent" : "AS",
            "continentname" : "Asia",
            "country" : "JP",
            "countryname" : "Japan",
            "domain" : [
               "ctgserver.com",
               "rackip.com"
            ],
            "isineu" : "false",
            "latitude" : "36.204824",
            "location" : "36.204824,138.252924",
            "longitude" : "138.252924",
            "netname" : "CTG220-128-JP",
            "organization" : "RACKIP CONSULTANCY PTE. LTD.",
            "subnet" : "137.220.144.0/20"
         },
         "ip" : "137.220.148.156",
         "ipv6" : "false",
         "latitude" : "35.6893",
         "location" : "35.6893,139.6899",
         "longitude" : "139.6899",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "CTG Server Limited",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 11112,
         "product" : "Nginx",
         "productvendor" : "F5",
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Bad Request",
         "seen_date" : "2024-11-21",
         "source" : "datascan",
         "status" : 400,
         "subnet" : "137.220.144.0/20",
         "tag" : "<enterprise field>: tag",
         "tls" : "false",
         "transport" : "tcp"
      }
      
  • 103.118.214.110:11112 (tcp/http) - last seen on 2024-11-21 at 08:09:42 UTC

    • IP
      103.118.214.110
      Network
      103.118.208.0/21
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      HTTP Title
      400 Bad Request
      ASN
      AS138968
      Organization
      rainbow network limited
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
      Product
      F5 Nginx
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      28715c6ec3fd38b6ed232e3e37959e9c
      HTTP Header MD5
      a629a0fe278971ad61801ba6975ba467
      HTTP Body MD5
      16444d0bf46608253d591db62f41e7c3
    • HTTP/1.1 400 Bad Request
      Server: nginx
      Date: Thu, 21 Nov 2024 08:09:41 GMT
      Content-Type: text/html
      Content-Length: 150
      Connection: close
      
      <html>
      <head><title>400 Bad Request</title></head>
      <body>
      <center><h1>400 Bad Request</h1></center>
      <hr><center>nginx</center>
      </body>
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-21T08:09:42.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "16444d0bf46608253d591db62f41e7c3",
               "bodymmh3" : -534304446,
               "headermd5" : "a629a0fe278971ad61801ba6975ba467",
               "headermmh3" : 1202057865,
               "title" : "400 Bad Request"
            },
            "length" : 295
         },
         "asn" : "AS138968",
         "country" : "CN",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 400 Bad Request\r\nServer: nginx\r\nDate: Thu, 21 Nov 2024 08:09:41 GMT\r\nContent-Type: text/html\r\nContent-Length: 150\r\nConnection: close\r\n\r\n<html>\r\n<head><title>400 Bad Request</title></head>\r\n<body>\r\n<center><h1>400 Bad Request</h1></center>\r\n<hr><center>nginx</center>\r\n</body>\r\n</html>\r\n",
         "datamd5" : "28715c6ec3fd38b6ed232e3e37959e9c",
         "datammh3" : -1512152686,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS138968",
            "continent" : "AS",
            "continentname" : "Asia",
            "country" : "TW",
            "countryname" : "Taiwan",
            "domain" : [
               "cloudie.hk"
            ],
            "isineu" : "false",
            "latitude" : "23.69781",
            "location" : "23.69781,120.960515",
            "longitude" : "120.960515",
            "netname" : "Ybnetwork",
            "organization" : "Rainbow Network  Limited",
            "subnet" : "103.118.208.0/21"
         },
         "ip" : "103.118.214.110",
         "ipv6" : "false",
         "latitude" : "34.7732",
         "location" : "34.7732,113.7220",
         "longitude" : "113.7220",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "rainbow network limited",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 11112,
         "product" : "Nginx",
         "productvendor" : "F5",
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Bad Request",
         "seen_date" : "2024-11-21",
         "source" : "datascan",
         "status" : 400,
         "subnet" : "103.118.208.0/21",
         "tag" : "<enterprise field>: tag",
         "tls" : "false",
         "transport" : "tcp"
      }
      
  • 118.163.235.229:11112 (tcp/unknown) - last seen on 2024-11-21 at 08:08:08 UTC

    • IP
      118.163.235.229
      Network
      118.160.0.0/13
      Domain(s)
      hinet.net
      Device

      <enterprise field>: device.class

      Operating System
      Microsoft Windows
      Reverse DNS
      118-163-235-229.hinet-ip.hinet.net
      ASN
      AS3462
      Organization
      Data Communication Business Group
      Protocol
      unknown
      Source
      datascan
    • Operating System
      Microsoft Windows
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      777f52e2eefbf3b7f6214ab058ba770c
    • \x00\x02HK\xd3\x19$x\xbe\xc3\x0d\xb5\xac;\x00\x03
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-21T08:08:08.000Z",
         "app" : {
            "length" : 16
         },
         "asn" : "AS3462",
         "city" : "Kaohsiung",
         "country" : "TW",
         "data" : "\\x00\\x02HK\\xd3\\x19$x\\xbe\\xc3\\x0d\\xb5\\xac;\\x00\\x03",
         "datamd5" : "777f52e2eefbf3b7f6214ab058ba770c",
         "datammh3" : 286935579,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "hinet.net"
         ],
         "geolocus" : {
            "asn" : "AS3462",
            "continent" : "AS",
            "continentname" : "Asia",
            "country" : "TW",
            "countryname" : "Taiwan",
            "domain" : [
               "hinet.net",
               "twnic.net",
               "twnic.net.tw"
            ],
            "isineu" : "false",
            "latitude" : "23.69781",
            "location" : "23.69781,120.960515",
            "longitude" : "120.960515",
            "netname" : "HINET-NET",
            "organization" : "Data Communication Business Group",
            "subnet" : "118.163.224.0/20"
         },
         "host" : [
            "118-163-235-229"
         ],
         "hostname" : [
            "118-163-235-229.hinet-ip.hinet.net"
         ],
         "ip" : "118.163.235.229",
         "ipv6" : "false",
         "latitude" : "22.6148",
         "location" : "22.6148,120.3139",
         "longitude" : "120.3139",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "Data Communication Business Group",
         "os" : "Windows",
         "osvendor" : "Microsoft",
         "port" : 11112,
         "protocol" : "unknown",
         "reverse" : [
            "118-163-235-229.hinet-ip.hinet.net"
         ],
         "seen_date" : "2024-11-21",
         "source" : "datascan",
         "subdomains" : [
            "hinet-ip.hinet.net"
         ],
         "subnet" : "118.160.0.0/13",
         "tag" : "<enterprise field>: tag",
         "tld" : [
            "net"
         ],
         "tls" : "false",
         "transport" : "tcp"
      }
      
  • 1.179.151.13:11112 (tcp/dicom) - last seen on 2024-11-21 at 08:07:23 UTC

    • IP
      1.179.151.13
      Network
      1.179.128.0/19
      Device

      <enterprise field>: device.class

      Operating System
      Microsoft Windows
      ASN
      AS131293
      Organization
      TOT Public Company Limited
      Protocol
      dicom
      Source
      datascan
    • Operating System
      Microsoft Windows
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      f87a87545287c011e3b026e07080a80a
    • \x02\x00\x00\x00\x00\xb8\x00\x01\x00\x00ANY-SCP         ECHOSCU         \x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x10\x00\x00\x151.2.840.10008.3.1.1.1!\x00\x00\x19\x01\x00\x00\x00@\x00\x00\x111.2.840.10008.1.2P\x00\x00:Q\x00\x00\x04\x00\x00@\x00R\x00\x00\x1b1.2.276.0.7230010.3.0.3.6.7U\x00\x00\x0fOFFIS_DCMTK_367\x04\x00\x00\x00\x00T\x00\x00\x00P\x01\x03\x00\x00\x00\x00\x04\x00\x00\x00B\x00\x00\x00\x00\x00\x02\x00\x12\x00\x00\x001.2.840.10008.1.1\x00\x00\x00\x00\x01\x02\x00\x00\x000\x80\x00\x00 \x01\x02\x00\x00\x00\x01\x00\x00\x00\x00\x08\x02\x00\x00\x00\x01\x01\x00\x00\x00	\x02\x00\x00\x00\x00\x00\x06\x00\x00\x00\x00\x04\x00\x00\x00\x00
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-21T08:07:23.000Z",
         "app" : {
            "extract" : {
               "ip" : [
                  "3.0.3.6"
               ]
            },
            "length" : 290
         },
         "asn" : "AS131293",
         "city" : "Nakhon Pathom",
         "country" : "TH",
         "data" : "\\x02\\x00\\x00\\x00\\x00\\xb8\\x00\\x01\\x00\\x00ANY-SCP         ECHOSCU         \\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x151.2.840.10008.3.1.1.1!\\x00\\x00\\x19\\x01\\x00\\x00\\x00@\\x00\\x00\\x111.2.840.10008.1.2P\\x00\\x00:Q\\x00\\x00\\x04\\x00\\x00@\\x00R\\x00\\x00\\x1b1.2.276.0.7230010.3.0.3.6.7U\\x00\\x00\\x0fOFFIS_DCMTK_367\\x04\\x00\\x00\\x00\\x00T\\x00\\x00\\x00P\\x01\\x03\\x00\\x00\\x00\\x00\\x04\\x00\\x00\\x00B\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x12\\x00\\x00\\x001.2.840.10008.1.1\\x00\\x00\\x00\\x00\\x01\\x02\\x00\\x00\\x000\\x80\\x00\\x00 \\x01\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x08\\x02\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\t\\x02\\x00\\x00\\x00\\x00\\x00\\x06\\x00\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00",
         "datamd5" : "f87a87545287c011e3b026e07080a80a",
         "datammh3" : -64688376,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS131293",
            "continent" : "AS",
            "continentname" : "Asia",
            "country" : "TH",
            "countryname" : "Thailand",
            "domain" : [
               "ntplc.co.th",
               "totbb.net",
               "totidc.net",
               "totisp.net"
            ],
            "isineu" : "false",
            "latitude" : "15.870032",
            "location" : "15.870032,100.992541",
            "longitude" : "100.992541",
            "netname" : "TOTnet",
            "organization" : "TOT Public Company Limited",
            "subnet" : "1.179.128.0/19"
         },
         "ip" : "1.179.151.13",
         "ipv6" : "false",
         "latitude" : "13.8667",
         "location" : "13.8667,100.1917",
         "longitude" : "100.1917",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "TOT Public Company Limited",
         "os" : "Windows",
         "osvendor" : "Microsoft",
         "port" : 11112,
         "protocol" : "dicom",
         "seen_date" : "2024-11-21",
         "source" : "datascan",
         "subnet" : "1.179.128.0/19",
         "tls" : "false",
         "transport" : "tcp"
      }
      
  • 179.104.6.144:11112 (tcp/dicom) - last seen on 2024-11-21 at 08:07:08 UTC

    • IP
      179.104.6.144
      Network
      179.104.0.0/16
      Domain(s)
      algarnetsuper.com.br
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      Reverse DNS
      179-104-006-144.xd-dynamic.algarnetsuper.com.br
      ASN
      AS53006
      Organization
      ALGAR TELECOM SA
      Protocol
      dicom
      Source
      datascan
    • Operating System
      Linux Linux Kernel
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      f75a55e371548d8af9db9364871fb172
    • \x03\x00\x00\x00\x00\x04\x00\x01\x01\x07
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-21T08:07:08.000Z",
         "app" : {
            "length" : 10
         },
         "asn" : "AS53006",
         "city" : "Ituiutaba",
         "country" : "BR",
         "data" : "\\x03\\x00\\x00\\x00\\x00\\x04\\x00\\x01\\x01\\x07",
         "datamd5" : "f75a55e371548d8af9db9364871fb172",
         "datammh3" : 89833742,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "algarnetsuper.com.br"
         ],
         "geolocus" : {
            "asn" : "AS25799",
            "continent" : "SA",
            "continentname" : "South America",
            "country" : "BR",
            "countryname" : "Brazil",
            "domain" : [
               "algarnetsuper.com.br",
               "algartelecom.com.br",
               "cert.br"
            ],
            "isineu" : "false",
            "latitude" : "-14.235004",
            "location" : "-14.235004,-51.92528",
            "longitude" : "-51.92528",
            "netname" : "71.208.516/0001-74",
            "organization" : "ALGAR TELECOM S/A",
            "subnet" : "179.104.0.0/16"
         },
         "host" : [
            "179-104-006-144"
         ],
         "hostname" : [
            "179-104-006-144.xd-dynamic.algarnetsuper.com.br"
         ],
         "ip" : "179.104.6.144",
         "ipv6" : "false",
         "latitude" : "-19.0137",
         "location" : "-19.0137,-49.5496",
         "longitude" : "-49.5496",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "ALGAR TELECOM SA",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 11112,
         "protocol" : "dicom",
         "reverse" : [
            "179-104-006-144.xd-dynamic.algarnetsuper.com.br"
         ],
         "seen_date" : "2024-11-21",
         "source" : "datascan",
         "subdomains" : [
            "xd-dynamic.algarnetsuper.com.br"
         ],
         "subnet" : "179.104.0.0/16",
         "tld" : [
            "com.br"
         ],
         "tls" : "false",
         "transport" : "tcp"
      }
      
  • 42.112.148.128:11112 (tcp/socks4a) - last seen on 2024-11-21 at 08:07:01 UTC

    • IP
      42.112.148.128
      Network
      42.112.0.0/13
      Operating System
      Linux Linux Kernel
      ASN
      AS18403
      Organization
      FPT Telecom Company
      Protocol
      socks4a
      Source
      datascan
    • Operating System
      Linux Linux Kernel
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      8bdffca8bfeb9b269cb21441e9d23a21
    • \x00[\x048
      XXq
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-21T08:07:01.000Z",
         "app" : {
            "length" : 8
         },
         "asn" : "AS18403",
         "city" : "Hanoi",
         "country" : "VN",
         "data" : "\\x00[\\x048\nXXq",
         "datamd5" : "8bdffca8bfeb9b269cb21441e9d23a21",
         "datammh3" : 1898839447,
         "geolocus" : {
            "asn" : "AS18403",
            "continent" : "AS",
            "continentname" : "Asia",
            "country" : "VN",
            "countryname" : "Vietnam",
            "domain" : [
               "fpt.com",
               "fpt.net",
               "fpt.vn",
               "vnnic.vn"
            ],
            "isineu" : "false",
            "latitude" : "14.058324",
            "location" : "14.058324,108.277199",
            "longitude" : "108.277199",
            "netname" : "FPT-STATICIP-NET",
            "organization" : "Vietnam Internet Network Information Center (VNNIC)",
            "subnet" : "42.112.148.0/24"
         },
         "ip" : "42.112.148.128",
         "ipv6" : "false",
         "latitude" : "21.0292",
         "location" : "21.0292,105.8526",
         "longitude" : "105.8526",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "FPT Telecom Company",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 11112,
         "protocol" : "socks4a",
         "seen_date" : "2024-11-21",
         "source" : "datascan",
         "subnet" : "42.112.0.0/13",
         "tag" : "<enterprise field>: tag",
         "tls" : "false",
         "transport" : "tcp"
      }
      
  • 36.236.10.55:11112 (tcp/http) - last seen on 2024-11-21 at 08:07:01 UTC

    • IP
      36.236.10.55
      Network
      36.224.0.0/12
      Domain(s)
      hinet.net
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      HTTP Title
      400 Bad Request
      Reverse DNS
      36-236-10-55.dynamic-ip.hinet.net
      ASN
      AS3462
      Organization
      Data Communication Business Group
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      a4ba467ca88e6762c7ccca5acab568bc
      HTTP Header MD5
      99e0e889d493a570fcc47b0120bea32f
      HTTP Body MD5
      16444d0bf46608253d591db62f41e7c3
    • HTTP/1.1 400 Bad Request
      Server: keycdn
      Date: Thu, 21 Nov 2024 08:06:59 GMT
      Content-Type: text/html
      Content-Length: 150
      Connection: close
      X-Edge-Location: frpa
      
      <html>
      <head><title>400 Bad Request</title></head>
      <body>
      <center><h1>400 Bad Request</h1></center>
      <hr><center>nginx</center>
      </body>
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-21T08:07:01.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "16444d0bf46608253d591db62f41e7c3",
               "bodymmh3" : -534304446,
               "headermd5" : "99e0e889d493a570fcc47b0120bea32f",
               "headermmh3" : 1086725235,
               "title" : "400 Bad Request"
            },
            "length" : 319
         },
         "asn" : "AS3462",
         "city" : "Chiayi City",
         "country" : "TW",
         "data" : "HTTP/1.1 400 Bad Request\r\nServer: keycdn\r\nDate: Thu, 21 Nov 2024 08:06:59 GMT\r\nContent-Type: text/html\r\nContent-Length: 150\r\nConnection: close\r\nX-Edge-Location: frpa\r\n\r\n<html>\r\n<head><title>400 Bad Request</title></head>\r\n<body>\r\n<center><h1>400 Bad Request</h1></center>\r\n<hr><center>nginx</center>\r\n</body>\r\n</html>\r\n",
         "datamd5" : "a4ba467ca88e6762c7ccca5acab568bc",
         "datammh3" : -1738804379,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "hinet.net"
         ],
         "geolocus" : {
            "asn" : "AS3462",
            "continent" : "AS",
            "continentname" : "Asia",
            "country" : "TW",
            "countryname" : "Taiwan",
            "domain" : [
               "hinet.net",
               "twnic.net",
               "twnic.net.tw"
            ],
            "isineu" : "false",
            "latitude" : "23.69781",
            "location" : "23.69781,120.960515",
            "longitude" : "120.960515",
            "netname" : "HINET-NET",
            "organization" : "Data Communication Business Group",
            "subnet" : "36.224.0.0/12"
         },
         "host" : [
            "36-236-10-55"
         ],
         "hostname" : [
            "36-236-10-55.dynamic-ip.hinet.net"
         ],
         "ip" : "36.236.10.55",
         "ipv6" : "false",
         "latitude" : "23.4815",
         "location" : "23.4815,120.4498",
         "longitude" : "120.4498",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "Data Communication Business Group",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 11112,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Bad Request",
         "reverse" : [
            "36-236-10-55.dynamic-ip.hinet.net"
         ],
         "seen_date" : "2024-11-21",
         "source" : "datascan",
         "status" : 400,
         "subdomains" : [
            "dynamic-ip.hinet.net"
         ],
         "subnet" : "36.224.0.0/12",
         "tag" : "<enterprise field>: tag",
         "tld" : [
            "net"
         ],
         "tls" : "false",
         "transport" : "tcp"
      }
      
  • 13.38.25.89:11112 (tcp/http) - last seen on 2024-11-21 at 08:07:00 UTC

    • IP
      13.38.25.89
      Network
      13.36.0.0/14
      Domain(s)
      amazonaws.com
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      Reverse DNS
      ec2-13-38-25-89.eu-west-3.compute.amazonaws.com
      ASN
      AS16509
      Organization
      AMAZON-02
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      1dafc1f061d065ae901038473ae33902
      HTTP Header MD5
      571b5ea6a2d05102b1dfe0a212263b89
      HTTP Body MD5
      d41d8cd98f00b204e9800998ecf8427e
    • HTTP/1.1 400 Bad Request
      Connection: close
      
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-21T08:07:00.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "d41d8cd98f00b204e9800998ecf8427e",
               "bodymmh3" : -1,
               "headermd5" : "571b5ea6a2d05102b1dfe0a212263b89",
               "headermmh3" : -521918475
            },
            "length" : 47
         },
         "asn" : "AS16509",
         "city" : "Paris",
         "country" : "FR",
         "data" : "HTTP/1.1 400 Bad Request\r\nConnection: close\r\n\r\n",
         "datamd5" : "1dafc1f061d065ae901038473ae33902",
         "datammh3" : -1150732002,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "amazonaws.com"
         ],
         "geolocus" : {
            "asn" : "AS16509",
            "continent" : "EU",
            "continentname" : "Europe",
            "country" : "FR",
            "countryname" : "France",
            "domain" : [
               "amazon.com",
               "amazonaws.com"
            ],
            "isineu" : "true",
            "latitude" : "46.227638",
            "location" : "46.227638,2.213749",
            "longitude" : "2.213749",
            "netname" : "AMAZON-CDG",
            "organization" : "Amazon Data Services France",
            "subnet" : "13.36.0.0/14"
         },
         "host" : [
            "ec2-13-38-25-89"
         ],
         "hostname" : [
            "ec2-13-38-25-89.eu-west-3.compute.amazonaws.com"
         ],
         "ip" : "13.38.25.89",
         "ipv6" : "false",
         "latitude" : "48.8323",
         "location" : "48.8323,2.4075",
         "longitude" : "2.4075",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "AMAZON-02",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 11112,
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Bad Request",
         "reverse" : [
            "ec2-13-38-25-89.eu-west-3.compute.amazonaws.com"
         ],
         "seen_date" : "2024-11-21",
         "source" : "datascan",
         "status" : 400,
         "subdomains" : [
            "compute.amazonaws.com",
            "eu-west-3.compute.amazonaws.com"
         ],
         "subnet" : "13.36.0.0/14",
         "tag" : "<enterprise field>: tag",
         "tld" : [
            "com"
         ],
         "tls" : "false",
         "transport" : "tcp"
      }
      
  • 104.233.253.200:11112 (tcp/http) - last seen on 2024-11-21 at 08:07:00 UTC

    • IP
      104.233.253.200
      Network
      104.233.252.0/22
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      HTTP Title
      400 Bad Request
      ASN
      AS398478
      Organization
      PEG-HK
      Protocol
      http
      Source
      datascan
    • Operating System
      Linux Linux Kernel
      Product
      F5 Nginx
      CPE(s)

      <enterprise field>: cpe

    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      28715c6ec3fd38b6ed232e3e37959e9c
      HTTP Header MD5
      a629a0fe278971ad61801ba6975ba467
      HTTP Body MD5
      16444d0bf46608253d591db62f41e7c3
    • HTTP/1.1 400 Bad Request
      Server: nginx
      Date: Thu, 21 Nov 2024 08:06:59 GMT
      Content-Type: text/html
      Content-Length: 150
      Connection: close
      
      <html>
      <head><title>400 Bad Request</title></head>
      <body>
      <center><h1>400 Bad Request</h1></center>
      <hr><center>nginx</center>
      </body>
      </html>
      
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-21T08:07:00.000Z",
         "app" : {
            "http" : {
               "bodymd5" : "16444d0bf46608253d591db62f41e7c3",
               "bodymmh3" : -534304446,
               "headermd5" : "a629a0fe278971ad61801ba6975ba467",
               "headermmh3" : 338143101,
               "title" : "400 Bad Request"
            },
            "length" : 295
         },
         "asn" : "AS398478",
         "city" : "Hong Kong",
         "country" : "HK",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "HTTP/1.1 400 Bad Request\r\nServer: nginx\r\nDate: Thu, 21 Nov 2024 08:06:59 GMT\r\nContent-Type: text/html\r\nContent-Length: 150\r\nConnection: close\r\n\r\n<html>\r\n<head><title>400 Bad Request</title></head>\r\n<body>\r\n<center><h1>400 Bad Request</h1></center>\r\n<hr><center>nginx</center>\r\n</body>\r\n</html>\r\n",
         "datamd5" : "28715c6ec3fd38b6ed232e3e37959e9c",
         "datammh3" : -1512152686,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS398478",
            "continent" : "NA",
            "continentname" : "North America",
            "country" : "US",
            "countryname" : "United States",
            "domain" : [
               "petaexpress.com"
            ],
            "isineu" : "false",
            "latitude" : "37.09024",
            "location" : "37.09024,-95.712891",
            "longitude" : "-95.712891",
            "netname" : "PEG-HK",
            "organization" : "PEG TECH INC",
            "subnet" : "104.233.252.0/22"
         },
         "ip" : "104.233.253.200",
         "ipv6" : "false",
         "latitude" : "22.2842",
         "location" : "22.2842,114.1759",
         "longitude" : "114.1759",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "PEG-HK",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 11112,
         "product" : "Nginx",
         "productvendor" : "F5",
         "protocol" : "http",
         "protocolversion" : "1.1",
         "reason" : "Bad Request",
         "seen_date" : "2024-11-21",
         "source" : "datascan",
         "status" : 400,
         "subnet" : "104.233.252.0/22",
         "tag" : "<enterprise field>: tag",
         "tls" : "false",
         "transport" : "tcp"
      }
      
  • 102.216.106.134:11112 (tcp/dicom) - last seen on 2024-11-21 at 08:06:51 UTC

    • IP
      102.216.106.134
      Network
      102.216.104.0/22
      Device

      <enterprise field>: device.class

      Operating System
      FreeBSD FreeBSD
      ASN
      AS328638
      Organization
      LETABANETWORKS
      Protocol
      dicom
      Source
      datascan
    • Operating System
      FreeBSD FreeBSD
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      2de90cb790a3d98159f9ec368fa9904a
    • \x02\x00\x00\x00\x00\xb3\x00\x01\x00\x00ANY-SCP         ECHOSCU         \x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x10\x00\x00\x151.2.840.10008.3.1.1.1!\x00\x00\x19\x01\x00\x00\x00@\x00\x00\x111.2.840.10008.1.2P\x00\x005Q\x00\x00\x04\x00\x00@\x00R\x00\x00\x1b1.2.276.0.7230010.3.0.3.6.1U\x00\x00
      OSIRIX_361\x04\x00\x00\x00\x00T\x00\x00\x00P\x01\x03\x00\x00\x00\x00\x04\x00\x00\x00B\x00\x00\x00\x00\x00\x02\x00\x12\x00\x00\x001.2.840.10008.1.1\x00\x00\x00\x00\x01\x02\x00\x00\x000\x80\x00\x00 \x01\x02\x00\x00\x00\x01\x00\x00\x00\x00\x08\x02\x00\x00\x00\x01\x01\x00\x00\x00	\x02\x00\x00\x00\x00\x00\x06\x00\x00\x00\x00\x04\x00\x00\x00\x00
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-21T08:06:51.000Z",
         "app" : {
            "extract" : {
               "ip" : [
                  "3.0.3.6"
               ]
            },
            "length" : 285
         },
         "asn" : "AS328638",
         "city" : "Phalaborwa",
         "country" : "ZA",
         "data" : "\\x02\\x00\\x00\\x00\\x00\\xb3\\x00\\x01\\x00\\x00ANY-SCP         ECHOSCU         \\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x151.2.840.10008.3.1.1.1!\\x00\\x00\\x19\\x01\\x00\\x00\\x00@\\x00\\x00\\x111.2.840.10008.1.2P\\x00\\x005Q\\x00\\x00\\x04\\x00\\x00@\\x00R\\x00\\x00\\x1b1.2.276.0.7230010.3.0.3.6.1U\\x00\\x00\nOSIRIX_361\\x04\\x00\\x00\\x00\\x00T\\x00\\x00\\x00P\\x01\\x03\\x00\\x00\\x00\\x00\\x04\\x00\\x00\\x00B\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x12\\x00\\x00\\x001.2.840.10008.1.1\\x00\\x00\\x00\\x00\\x01\\x02\\x00\\x00\\x000\\x80\\x00\\x00 \\x01\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x08\\x02\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\t\\x02\\x00\\x00\\x00\\x00\\x00\\x06\\x00\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00",
         "datamd5" : "2de90cb790a3d98159f9ec368fa9904a",
         "datammh3" : -538190534,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "geolocus" : {
            "asn" : "AS328638",
            "continent" : "AF",
            "continentname" : "Africa",
            "country" : "ZA",
            "countryname" : "South Africa",
            "isineu" : "false",
            "latitude" : "-30.559482",
            "location" : "-30.559482,22.937506",
            "longitude" : "22.937506",
            "netname" : "LetabaNetworks",
            "organization" : "Letaba Networks (Pty) Ltd",
            "subnet" : "102.216.106.0/23"
         },
         "ip" : "102.216.106.134",
         "ipv6" : "false",
         "latitude" : "-23.9500",
         "location" : "-23.9500,31.1167",
         "longitude" : "31.1167",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "LETABANETWORKS",
         "os" : "FreeBSD",
         "osvendor" : "FreeBSD",
         "port" : 11112,
         "protocol" : "dicom",
         "seen_date" : "2024-11-21",
         "source" : "datascan",
         "subnet" : "102.216.104.0/22",
         "tls" : "false",
         "transport" : "tcp"
      }