104.244.75.48
As of: Sep 18, 2024 6:59am UTC |
Latest
{
"ip": "104.244.75.48",
"services": [
{
"_decoded": "ssh",
"_encoding": {
"banner": "DISPLAY_UTF8",
"banner_hex": "DISPLAY_HEX"
},
"banner": "SSH-2.0-OpenSSH_8.2p1 Ubuntu-4ubuntu0.11",
"banner_hashes": [
"sha256:2bf2033dbf501c6d1f063e64b737f30c2ab11dd1fb2e65a7dd4b2a88c71f23e5"
],
"banner_hex": "5353482d322e302d4f70656e5353485f382e327031205562756e74752d347562756e7475302e3131",
"discovery_method": "PREDICTIVE_METHOD_7",
"extended_service_name": "SSH",
"labels": [
"remote-access"
],
"observed_at": "2024-09-17T20:40:17.863242952Z",
"perspective_id": "PERSPECTIVE_HE",
"port": 22,
"service_name": "SSH",
"software": [
{
"product": "openssh",
"other": {
"comment": "Ubuntu-4ubuntu0.11"
},
"source": "OSI_APPLICATION_LAYER"
},
{
"uniform_resource_identifier": "cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:*:*:*:*",
"part": "o",
"vendor": "Ubuntu",
"product": "Linux",
"version": "20.04",
"other": {
"family": "Linux"
},
"source": "OSI_APPLICATION_LAYER"
},
{
"uniform_resource_identifier": "cpe:2.3:a:openbsd:openssh:8.2:p1:*:*:*:*:*:*",
"part": "a",
"vendor": "OpenBSD",
"product": "OpenSSH",
"version": "8.2",
"update": "p1",
"other": {
"family": "OpenSSH"
},
"source": "OSI_APPLICATION_LAYER"
}
],
"source_ip": "162.142.125.192",
"ssh": {
"endpoint_id": {
"_encoding": {
"raw": "DISPLAY_UTF8"
},
"raw": "SSH-2.0-OpenSSH_8.2p1 Ubuntu-4ubuntu0.11",
"protocol_version": "2.0",
"software_version": "OpenSSH_8.2p1",
"comment": "Ubuntu-4ubuntu0.11"
},
"kex_init_message": {
"kex_algorithms": [
"curve25519-sha256",
"[email protected]",
"ecdh-sha2-nistp256",
"ecdh-sha2-nistp384",
"ecdh-sha2-nistp521",
"diffie-hellman-group-exchange-sha256",
"diffie-hellman-group16-sha512",
"diffie-hellman-group18-sha512",
"diffie-hellman-group14-sha256",
"[email protected]"
],
"host_key_algorithms": [
"rsa-sha2-512",
"rsa-sha2-256",
"ssh-rsa",
"ecdsa-sha2-nistp256",
"ssh-ed25519"
],
"client_to_server_ciphers": [
"[email protected]",
"aes128-ctr",
"aes192-ctr",
"aes256-ctr",
"[email protected]",
"[email protected]"
],
"server_to_client_ciphers": [
"[email protected]",
"aes128-ctr",
"aes192-ctr",
"aes256-ctr",
"[email protected]",
"[email protected]"
],
"client_to_server_macs": [
"[email protected]",
"[email protected]",
"[email protected]",
"[email protected]",
"[email protected]",
"[email protected]",
"[email protected]",
"hmac-sha2-256",
"hmac-sha2-512",
"hmac-sha1"
],
"server_to_client_macs": [
"[email protected]",
"[email protected]",
"[email protected]",
"[email protected]",
"[email protected]",
"[email protected]",
"[email protected]",
"hmac-sha2-256",
"hmac-sha2-512",
"hmac-sha1"
],
"client_to_server_compression": [
"none",
"[email protected]"
],
"server_to_client_compression": [
"none",
"[email protected]"
],
"first_kex_follows": false
},
"algorithm_selection": {
"kex_algorithm": "[email protected]",
"host_key_algorithm": "ecdsa-sha2-nistp256",
"client_to_server_alg_group": {
"cipher": "aes128-ctr",
"mac": "hmac-sha2-256",
"compression": "none"
},
"server_to_client_alg_group": {
"cipher": "aes128-ctr",
"mac": "hmac-sha2-256",
"compression": "none"
}
},
"server_host_key": {
"fingerprint_sha256": "e44f10b0516494f9af042fc8208e496f136e0ecd27fac151bca8716c5993b085",
"ecdsa_public_key": {
"_encoding": {
"b": "DISPLAY_BASE64",
"gx": "DISPLAY_BASE64",
"gy": "DISPLAY_BASE64",
"n": "DISPLAY_BASE64",
"p": "DISPLAY_BASE64",
"x": "DISPLAY_BASE64",
"y": "DISPLAY_BASE64"
},
"b": "WsY12Ko6k+ez671VdpiGvGUdBrDMU7D2O848PifSYEs=",
"curve": "P-256",
"gx": "axfR8uEsQkf4vOblY6RA8ncDfYEt6zOg9KE5RdiYwpY=",
"gy": "T+NC4v4af5uO5+tKfA+eFivOM1drMV7Oy7ZAaDe/UfU=",
"length": 256,
"n": "/////wAAAAD//////////7zm+q2nF56E87nKwvxjJVE=",
"p": "/////wAAAAEAAAAAAAAAAAAAAAD///////////////8=",
"x": "LCPhaTN0Atp6SScVRXP6egcWcBt2eVydt1bjM1JEXak=",
"y": "+qTl5djcWaBmBWnevDfpkEpLfCd2DyMdtG8bp3bFeWo="
}
},
"hassh_fingerprint": "779664e66160bf75999f091fce5edb5a"
},
"transport_fingerprint": {
"raw": "65160,64,true,MSTNW,1400,false,false"
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "x11",
"discovery_method": "IPV4_WALK_FULL_PRIORITY_1",
"extended_service_name": "X11",
"labels": [
"remote-access"
],
"observed_at": "2024-09-18T06:59:55.702523437Z",
"perspective_id": "PERSPECTIVE_TATA",
"port": 6001,
"service_name": "X11",
"source_ip": "167.94.138.53",
"transport_fingerprint": {
"raw": "65160,64,true,MSTNW,1400,false,false"
},
"transport_protocol": "TCP",
"truncated": false,
"x11": {
"version": "11.0",
"refusal_reason": "Client is not authorized to connect to Server",
"requires_authentication": true
}
}
],
"location": {
"continent": "Europe",
"country": "Luxembourg",
"country_code": "LU",
"city": "Dudelange",
"postal_code": "L-3410",
"timezone": "Europe/Luxembourg",
"province": "Esch-sur-Alzette",
"coordinates": {
"latitude": 49.48056,
"longitude": 6.0875
}
},
"location_updated_at": "2024-09-17T18:18:38.182269203Z",
"autonomous_system": {
"asn": 53667,
"description": "PONYNET",
"bgp_prefix": "104.244.75.0/24",
"name": "PONYNET",
"country_code": "US"
},
"autonomous_system_updated_at": "2024-09-17T18:18:38.182364984Z",
"whois": {
"network": {
"handle": "BUYVM-LUXEMBOURG-01",
"name": "BuyVM",
"cidrs": [
"104.244.72.0/21"
],
"created": "2017-10-01T00:00:00Z",
"updated": "2017-10-01T00:00:00Z",
"allocation_type": "REALLOCATION"
},
"organization": {
"handle": "BUYVM",
"name": "BuyVM",
"street": "3, op der Poukewiss",
"city": "Roost",
"postal_code": "7795",
"country": "LU",
"abuse_contacts": [
{
"handle": "FDI19-ARIN",
"name": "Francisco Dias",
"email": "[email protected]"
}
],
"admin_contacts": [
{
"handle": "FDI19-ARIN",
"name": "Francisco Dias",
"email": "[email protected]"
}
],
"tech_contacts": [
{
"handle": "FDI19-ARIN",
"name": "Francisco Dias",
"email": "[email protected]"
}
]
}
},
"operating_system": {
"uniform_resource_identifier": "cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:*:*:*:*",
"part": "o",
"vendor": "Ubuntu",
"product": "Linux",
"version": "20.04",
"other": {
"family": "Linux"
}
},
"dns": {},
"last_updated_at": "2024-09-18T06:59:57.978Z",
"labels": [
"remote-access"
]
}