Hostnames |
0.155.148.132.host.secureserver.net yms.mx www.yms.mx |
Domains | secureserver.net yms.mx |
Country | United States |
City | Phoenix |
Organization | GoDaddy.com, LLC |
ISP | GoDaddy.com, LLC |
ASN | AS26496 |
Operating System | Windows (build 6.3.9600) |
-1026813282 | 2024-11-12T05:44:36.51962721 / tcp
220 Microsoft FTP Service 230 User logged in. 214-The following commands are recognized (* ==>'s unimplemented). ABOR ACCT ADAT * ALLO APPE AUTH CCC CDUP CWD DELE ENC * EPRT EPSV FEAT HELP HOST LANG LIST MDTM MIC * MKD MODE NLST NOOP OPTS PASS PASV PBSZ PORT PROT PWD QUIT REIN REST RETR RMD RNFR RNTO SITE SIZE SMNT STAT STOR STOU STRU SYST TYPE USER XCUP XCWD XMKD XPWD XRMD 214 HELP command successful. 211-Extended features supported: LANG EN* UTF8 AUTH TLS;TLS-C;SSL;TLS-P; PBSZ PROT C;P; CCC HOST SIZE MDTM REST STREAM 211 END
Certificate: Data: Version: 3 (0x2) Serial Number: 7d:5a:66:c8:b8:90:31:91:4f:88:c5:df:5d:91:e7:f2 Signature Algorithm: sha1WithRSAEncryption Issuer: CN=WMSvc-S132-148-155-0 Validity Not Before: Aug 26 16:48:11 2018 GMT Not After : Aug 23 16:48:11 2028 GMT Subject: CN=WMSvc-S132-148-155-0 Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (2048 bit) Modulus: 00:d4:eb:e1:74:dd:8a:ee:90:3e:79:d9:cd:f6:2e: 8e:91:77:dc:76:51:88:44:66:c5:42:bb:f5:38:9b: c3:39:0b:fd:be:b8:a4:6c:fd:fc:cd:be:30:35:49: 44:64:ba:66:1a:79:0f:94:5a:28:c5:74:d6:43:99: 55:1d:bd:81:3c:48:fd:14:b4:54:b6:81:ac:63:eb: 4a:e0:73:04:55:03:e6:aa:46:72:d8:35:9a:04:7f: 7b:53:38:b8:65:28:a2:b2:c2:40:94:1b:73:3c:b8: 4c:5c:a7:b5:f0:29:c0:a5:b9:a9:50:96:5f:23:c4: 57:6b:e1:ae:c3:11:18:a6:5c:77:7b:39:96:fd:91: b1:b4:8b:a0:92:4e:92:f2:31:f6:1f:25:09:b9:29: 6a:4c:a8:2c:c3:4f:0a:2f:34:67:c6:4e:60:17:14: 61:41:32:aa:6e:27:4a:82:64:87:04:a1:83:3a:c2: b1:a9:cd:54:2f:83:e7:70:d5:54:f5:3f:5a:5e:32: 55:62:eb:d7:d5:f6:d1:36:73:56:dc:13:5c:28:fa: 2b:07:af:67:4b:39:88:f3:52:cc:3a:09:9b:cc:1d: 6b:15:7f:ee:2a:ec:a4:7b:12:a1:55:23:61:11:25: 8d:12:e9:e1:24:a8:ed:d4:98:c3:49:ea:5f:f0:f3: ec:51 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Extended Key Usage: TLS Web Server Authentication X509v3 Key Usage: Digital Signature, Key Encipherment, Data Encipherment Signature Algorithm: sha1WithRSAEncryption Signature Value: 7f:35:69:80:8b:84:a4:b3:6e:e3:73:04:d4:9f:17:bb:ee:2d: 87:28:e7:2f:aa:bd:f6:a5:c0:78:1c:f0:26:db:c8:d8:09:ce: 5d:1f:09:98:d6:11:fa:ee:16:9f:e3:49:89:1b:b9:5b:51:ee: 3d:f6:00:4c:33:d3:db:a8:1d:c0:fa:ba:f5:7c:27:83:ff:2e: f2:38:97:30:23:dd:f4:65:2d:a3:18:0b:98:cc:8e:9a:2d:8c: 04:b8:95:6b:87:5e:da:8f:d3:77:79:95:a3:4c:5b:44:71:5f: b6:e4:37:21:2c:e7:6f:7c:5e:0d:e7:a9:2e:00:6e:98:55:1d: 59:3f:d3:cb:69:3c:02:0a:c8:5f:86:54:fe:96:e8:4c:f9:a9: fb:98:47:b0:a4:5e:15:3f:c4:1e:2a:26:b8:9c:75:33:28:85: 5b:69:0f:ea:4e:54:90:e7:df:12:b5:62:12:67:d9:75:af:f5: 1a:3b:3b:e3:4c:98:9d:7c:d9:51:79:14:dd:e3:9d:f9:f5:f3: ee:a0:8b:79:20:03:f0:33:41:40:61:49:27:22:dd:ae:f4:39: a2:5b:a4:41:57:4c:de:f0:22:83:b5:75:03:07:de:dd:c4:d4: 15:68:82:fa:a3:71:0a:e9:68:16:b9:d1:b0:77:89:86:04:72: 25:82:4c:a2
-553166942 | 2024-11-10T04:45:25.57214753 / tcp
Recursion: enabled
-436832084 | 2024-11-17T12:43:07.21413880 / tcp
HTTP/1.1 401 Unauthorized Server: Microsoft-IIS/8.5 WWW-Authenticate: Digest qop="auth",algorithm=MD5-sess,nonce="+Upgraded+v1262e66b2ebf5245096342dea0800655312d79322ee38db019577534b8d2cfceca35c250c1f7780a857304ca4c5818fc989fd43d02a04fc48",charset=utf-8,realm="Digest" WWW-Authenticate: Negotiate WWW-Authenticate: NTLM Date: Sun, 17 Nov 2024 12:42:17 GMT Content-Length: 0 HTTP NTLM Info: OS: Windows 8.1/Windows Server 2012 R2 OS Build: 6.3.9600 Target Name: S132-148-155-0 NetBIOS Domain Name: S132-148-155-0 NetBIOS Computer Name: S132-148-155-0 DNS Domain Name: s132-148-155-0.secureserver.net FQDN: s132-148-155-0.secureserver.net
1359724819 | 2024-10-29T06:49:26.756634111 / tcp
Portmap Program Version Protocol Port portmapper 2 udp 111 portmapper 3 udp 111 portmapper 4 udp 111 portmapper 2 tcp 111 portmapper 3 tcp 111 portmapper 4 tcp 111 nfs 2 tcp 2049 nfs 3 tcp 2049 nfs 2 udp 2049 nfs 3 udp 2049 nfs 4 tcp 2049 mountd 1 tcp 2049 mountd 2 tcp 2049 mountd 3 tcp 2049 mountd 1 udp 2049 mountd 2 udp 2049 mountd 3 udp 2049 nlockmgr 1 tcp 2049 nlockmgr 2 tcp 2049 nlockmgr 3 tcp 2049 nlockmgr 4 tcp 2049 nlockmgr 1 udp 2049 nlockmgr 2 udp 2049 nlockmgr 3 udp 2049 nlockmgr 4 udp 2049 status 1 tcp 2049 status 1 udp 2049
1359724819 | 2024-11-01T06:12:13.850689111 / udp
Portmap Program Version Protocol Port portmapper 2 udp 111 portmapper 3 udp 111 portmapper 4 udp 111 portmapper 2 tcp 111 portmapper 3 tcp 111 portmapper 4 tcp 111 nfs 2 tcp 2049 nfs 3 tcp 2049 nfs 2 udp 2049 nfs 3 udp 2049 nfs 4 tcp 2049 mountd 1 tcp 2049 mountd 2 tcp 2049 mountd 3 tcp 2049 mountd 1 udp 2049 mountd 2 udp 2049 mountd 3 udp 2049 nlockmgr 1 tcp 2049 nlockmgr 2 tcp 2049 nlockmgr 3 tcp 2049 nlockmgr 4 tcp 2049 nlockmgr 1 udp 2049 nlockmgr 2 udp 2049 nlockmgr 3 udp 2049 nlockmgr 4 udp 2049 status 1 tcp 2049 status 1 udp 2049
1415871881 | 2024-10-28T12:37:45.491347135 / tcp
Microsoft RPC Endpoint Mapper d95afe70-a6d5-4259-822e-2c84da1ddb0d version: v1.0 protocol: [MS-RSP]: Remote Shutdown Protocol provider: wininit.exe ncacn_ip_tcp: 132.148.155.0:49152 ncalrpc: WindowsShutdown ncacn_np: \\S132-148-155-0\PIPE\InitShutdown ncalrpc: WMsgKRpc05E250 76f226c3-ec14-4325-8a99-6a46348418af version: v1.0 provider: winlogon.exe ncalrpc: WindowsShutdown ncacn_np: \\S132-148-155-0\PIPE\InitShutdown ncalrpc: WMsgKRpc05E250 ncalrpc: WMsgKRpc05F3F1 ncalrpc: WMsgKRpc0E5F782 9b008953-f195-4bf9-bde0-4471971e58ed version: v1.0 ncalrpc: LRPC-0f195919c3ae5b6c8c ncacn_np: \\S132-148-155-0\pipe\LSM_API_service ncalrpc: LSMApi ncalrpc: LRPC-867d2c6389fdc3937d ncalrpc: actkernel ncalrpc: umpo 697dcda9-3ba9-4eb2-9247-e11f1901b0d2 version: v1.0 ncalrpc: LRPC-0f195919c3ae5b6c8c ncacn_np: \\S132-148-155-0\pipe\LSM_API_service ncalrpc: LSMApi ncalrpc: LRPC-867d2c6389fdc3937d ncalrpc: actkernel ncalrpc: umpo c9ac6db5-82b7-4e55-ae8a-e464ed7b4277 version: v1.0 annotation: Impl friendly name provider: sysntfy.dll ncalrpc: LRPC-867d2c6389fdc3937d ncalrpc: actkernel ncalrpc: umpo ncacn_np: \\S132-148-155-0\PIPE\srvsvc ncacn_ip_tcp: 132.148.155.0:49154 ncalrpc: ubpmtaskhostchannel ncacn_np: \\S132-148-155-0\PIPE\atsvc ncalrpc: senssvc ncalrpc: OLEA60B3687422E13B8D9A97EA66B29 ncalrpc: IUserProfile2 ncalrpc: senssvc ncalrpc: OLEA60B3687422E13B8D9A97EA66B29 ncalrpc: IUserProfile2 ncalrpc: OLEA60B3687422E13B8D9A97EA66B29 ncalrpc: IUserProfile2 ncalrpc: IUserProfile2 0d3e2735-cea0-4ecc-a9e2-41a2d81aed4e version: v1.0 ncalrpc: actkernel ncalrpc: umpo c605f9fb-f0a3-4e2a-a073-73560f8d9e3e version: v1.0 ncalrpc: actkernel ncalrpc: umpo 1b37ca91-76b1-4f5e-a3c7-2abfc61f2bb0 version: v1.0 ncalrpc: actkernel ncalrpc: umpo 8bfc3be1-6def-4e2d-af74-7c47cd0ade4a version: v1.0 ncalrpc: actkernel ncalrpc: umpo 2d98a740-581d-41b9-aa0d-a88b9d5ce938 version: v1.0 ncalrpc: actkernel ncalrpc: umpo bdaa0970-413b-4a3e-9e5d-f6dc9d7e0760 version: v1.0 ncalrpc: actkernel ncalrpc: umpo 3b338d89-6cfa-44b8-847e-531531bc9992 version: v1.0 ncalrpc: actkernel ncalrpc: umpo 8782d3b9-ebbd-4644-a3d8-e8725381919b version: v1.0 ncalrpc: actkernel ncalrpc: umpo 085b0334-e454-4d91-9b8c-4134f9e793f3 version: v1.0 ncalrpc: actkernel ncalrpc: umpo 4bec6bb8-b5c2-4b6f-b2c1-5da5cf92d0d9 version: v1.0 ncalrpc: actkernel ncalrpc: umpo 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5 version: v1.0 annotation: DHCP Client LRPC Endpoint provider: dhcpcsvc.dll ncalrpc: dhcpcsvc ncalrpc: dhcpcsvc6 ncalrpc: LRPC-b8c45dbcb8e1991c49 ncacn_ip_tcp: 132.148.155.0:49153 ncacn_np: \\S132-148-155-0\pipe\eventlog ncalrpc: eventlog 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6 version: v1.0 annotation: DHCPv6 Client LRPC Endpoint provider: dhcpcsvc6.dll ncalrpc: dhcpcsvc6 ncalrpc: LRPC-b8c45dbcb8e1991c49 ncacn_ip_tcp: 132.148.155.0:49153 ncacn_np: \\S132-148-155-0\pipe\eventlog ncalrpc: eventlog abfb6ca3-0c5e-4734-9285-0aee72fe8d1c version: v1.0 annotation: Wcm Service ncalrpc: LRPC-b8c45dbcb8e1991c49 ncacn_ip_tcp: 132.148.155.0:49153 ncacn_np: \\S132-148-155-0\pipe\eventlog ncalrpc: eventlog 30adc50c-5cbc-46ce-9a0e-91914789e23c version: v1.0 annotation: NRP server endpoint provider: nrpsrv.dll ncalrpc: LRPC-b8c45dbcb8e1991c49 ncacn_ip_tcp: 132.148.155.0:49153 ncacn_np: \\S132-148-155-0\pipe\eventlog ncalrpc: eventlog f6beaff7-1e19-4fbb-9f8f-b89e2018337c version: v1.0 annotation: Event log TCPIP protocol: [MS-EVEN6]: EventLog Remoting Protocol provider: wevtsvc.dll ncacn_ip_tcp: 132.148.155.0:49153 ncacn_np: \\S132-148-155-0\pipe\eventlog ncalrpc: eventlog 58e604e8-9adb-4d2e-a464-3b0683fb1480 version: v1.0 annotation: AppInfo provider: appinfo.dll ncacn_np: \\S132-148-155-0\pipe\SessEnvPublicRpc ncalrpc: SessEnvPrivateRpc ncalrpc: LRPC-78205f6087cbd1cc2c ncacn_np: \\S132-148-155-0\PIPE\srvsvc ncacn_ip_tcp: 132.148.155.0:49154 ncalrpc: ubpmtaskhostchannel ncacn_np: \\S132-148-155-0\PIPE\atsvc ncalrpc: senssvc ncalrpc: OLEA60B3687422E13B8D9A97EA66B29 ncalrpc: IUserProfile2 fd7a0523-dc70-43dd-9b2e-9c5ed48225b1 version: v1.0 annotation: AppInfo provider: appinfo.dll ncacn_np: \\S132-148-155-0\pipe\SessEnvPublicRpc ncalrpc: SessEnvPrivateRpc ncalrpc: LRPC-78205f6087cbd1cc2c ncacn_np: \\S132-148-155-0\PIPE\srvsvc ncacn_ip_tcp: 132.148.155.0:49154 ncalrpc: ubpmtaskhostchannel ncacn_np: \\S132-148-155-0\PIPE\atsvc ncalrpc: senssvc ncalrpc: OLEA60B3687422E13B8D9A97EA66B29 ncalrpc: IUserProfile2 5f54ce7d-5b79-4175-8584-cb65313a0e98 version: v1.0 annotation: AppInfo provider: appinfo.dll ncacn_np: \\S132-148-155-0\pipe\SessEnvPublicRpc ncalrpc: SessEnvPrivateRpc ncalrpc: LRPC-78205f6087cbd1cc2c ncacn_np: \\S132-148-155-0\PIPE\srvsvc ncacn_ip_tcp: 132.148.155.0:49154 ncalrpc: ubpmtaskhostchannel ncacn_np: \\S132-148-155-0\PIPE\atsvc ncalrpc: senssvc ncalrpc: OLEA60B3687422E13B8D9A97EA66B29 ncalrpc: IUserProfile2 201ef99a-7fa0-444c-9399-19ba84f12a1a version: v1.0 annotation: AppInfo provider: appinfo.dll ncacn_np: \\S132-148-155-0\pipe\SessEnvPublicRpc ncalrpc: SessEnvPrivateRpc ncalrpc: LRPC-78205f6087cbd1cc2c ncacn_np: \\S132-148-155-0\PIPE\srvsvc ncacn_ip_tcp: 132.148.155.0:49154 ncalrpc: ubpmtaskhostchannel ncacn_np: \\S132-148-155-0\PIPE\atsvc ncalrpc: senssvc ncalrpc: OLEA60B3687422E13B8D9A97EA66B29 ncalrpc: IUserProfile2 7d814569-35b3-4850-bb32-83035fcebf6e version: v1.0 annotation: IAS RPC server provider: ias.dll ncacn_np: \\S132-148-155-0\pipe\SessEnvPublicRpc ncalrpc: SessEnvPrivateRpc ncalrpc: LRPC-78205f6087cbd1cc2c ncacn_np: \\S132-148-155-0\PIPE\srvsvc ncacn_ip_tcp: 132.148.155.0:49154 ncalrpc: ubpmtaskhostchannel ncacn_np: \\S132-148-155-0\PIPE\atsvc ncalrpc: senssvc ncalrpc: OLEA60B3687422E13B8D9A97EA66B29 ncalrpc: IUserProfile2 30b044a5-a225-43f0-b3a4-e060df91f9c1 version: v1.0 provider: certprop.dll ncalrpc: LRPC-78205f6087cbd1cc2c ncacn_np: \\S132-148-155-0\PIPE\srvsvc ncacn_ip_tcp: 132.148.155.0:49154 ncalrpc: ubpmtaskhostchannel ncacn_np: \\S132-148-155-0\PIPE\atsvc ncalrpc: senssvc ncalrpc: OLEA60B3687422E13B8D9A97EA66B29 ncalrpc: IUserProfile2 1a0d010f-1c33-432c-b0f5-8cf4e8053099 version: v1.0 annotation: IdSegSrv service ncacn_ip_tcp: 132.148.155.0:49154 ncalrpc: ubpmtaskhostchannel ncacn_np: \\S132-148-155-0\PIPE\atsvc ncalrpc: senssvc ncalrpc: OLEA60B3687422E13B8D9A97EA66B29 ncalrpc: IUserProfile2 98716d03-89ac-44c7-bb8c-285824e51c4a version: v1.0 annotation: XactSrv service provider: srvsvc.dll ncacn_ip_tcp: 132.148.155.0:49154 ncalrpc: ubpmtaskhostchannel ncacn_np: \\S132-148-155-0\PIPE\atsvc ncalrpc: senssvc ncalrpc: OLEA60B3687422E13B8D9A97EA66B29 ncalrpc: IUserProfile2 c36be077-e14b-4fe9-8abc-e856ef4f048b version: v1.0 annotation: Proxy Manager client server endpoint ncacn_ip_tcp: 132.148.155.0:49154 ncalrpc: ubpmtaskhostchannel ncacn_np: \\S132-148-155-0\PIPE\atsvc ncalrpc: senssvc ncalrpc: OLEA60B3687422E13B8D9A97EA66B29 ncalrpc: IUserProfile2 c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1 version: v1.0 annotation: Adh APIs ncacn_ip_tcp: 132.148.155.0:49154 ncalrpc: ubpmtaskhostchannel ncacn_np: \\S132-148-155-0\PIPE\atsvc ncalrpc: senssvc ncalrpc: OLEA60B3687422E13B8D9A97EA66B29 ncalrpc: IUserProfile2 2e6035b2-e8f1-41a7-a044-656b439c4c34 version: v1.0 annotation: Proxy Manager provider server endpoint ncacn_ip_tcp: 132.148.155.0:49154 ncalrpc: ubpmtaskhostchannel ncacn_np: \\S132-148-155-0\PIPE\atsvc ncalrpc: senssvc ncalrpc: OLEA60B3687422E13B8D9A97EA66B29 ncalrpc: IUserProfile2 552d076a-cb29-4e44-8b6a-d15e59e2c0af version: v1.0 annotation: IP Transition Configuration endpoint provider: iphlpsvc.dll ncacn_ip_tcp: 132.148.155.0:49154 ncalrpc: ubpmtaskhostchannel ncacn_np: \\S132-148-155-0\PIPE\atsvc ncalrpc: senssvc ncalrpc: OLEA60B3687422E13B8D9A97EA66B29 ncalrpc: IUserProfile2 a398e520-d59a-4bdd-aa7a-3c1e0303a511 version: v1.0 annotation: IKE/Authip API provider: IKEEXT.DLL ncacn_ip_tcp: 132.148.155.0:49154 ncalrpc: ubpmtaskhostchannel ncacn_np: \\S132-148-155-0\PIPE\atsvc ncalrpc: senssvc ncalrpc: OLEA60B3687422E13B8D9A97EA66B29 ncalrpc: IUserProfile2 3a9ef155-691d-4449-8d05-09ad57031823 version: v1.0 ncacn_ip_tcp: 132.148.155.0:49154 ncalrpc: ubpmtaskhostchannel ncacn_np: \\S132-148-155-0\PIPE\atsvc ncalrpc: senssvc ncalrpc: OLEA60B3687422E13B8D9A97EA66B29 ncalrpc: IUserProfile2 86d35949-83c9-4044-b424-db363231fd0c version: v1.0 protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol provider: schedsvc.dll ncacn_ip_tcp: 132.148.155.0:49154 ncalrpc: ubpmtaskhostchannel ncacn_np: \\S132-148-155-0\PIPE\atsvc ncalrpc: senssvc ncalrpc: OLEA60B3687422E13B8D9A97EA66B29 ncalrpc: IUserProfile2 378e52b0-c0a9-11cf-822d-00aa0051e40f version: v1.0 protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol provider: taskcomp.dll ncacn_np: \\S132-148-155-0\PIPE\atsvc ncalrpc: senssvc ncalrpc: OLEA60B3687422E13B8D9A97EA66B29 ncalrpc: IUserProfile2 1ff70682-0a51-30e8-076d-740be8cee98b version: v1.0 protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol provider: taskcomp.dll ncacn_np: \\S132-148-155-0\PIPE\atsvc ncalrpc: senssvc ncalrpc: OLEA60B3687422E13B8D9A97EA66B29 ncalrpc: IUserProfile2 0a74ef1c-41a4-4e06-83ae-dc74fb1cdd53 version: v1.0 provider: schedsvc.dll ncalrpc: senssvc ncalrpc: OLEA60B3687422E13B8D9A97EA66B29 ncalrpc: IUserProfile2 2eb08e3e-639f-4fba-97b1-14f878961076 version: v1.0 annotation: Group Policy RPC Interface provider: gpsvc.dll ncalrpc: LRPC-b193c4e36f249516e8 b2507c30-b126-494a-92ac-ee32b6eeb039 version: v1.0 ncalrpc: LRPC-8011c2a2e1119496d2 ncalrpc: OLE7C5386D9781D6000A747C7B11F66 3473dd4d-2e88-4006-9cba-22570909dd10 version: v5.256 annotation: WinHttp Auto-Proxy Service ncalrpc: LRPC-d1ad11d340c888b711 ncalrpc: OLE1848F7DF4B10781CF4E4F448E0A5 7ea70bcf-48af-4f6a-8968-6a440754d5fa version: v1.0 annotation: NSI server endpoint provider: nsisvc.dll ncalrpc: LRPC-d1ad11d340c888b711 ncalrpc: OLE1848F7DF4B10781CF4E4F448E0A5 2fb92682-6599-42dc-ae13-bd2ca89bd11c version: v1.0 annotation: Fw APIs provider: MPSSVC.dll ncalrpc: LRPC-e8b8ca782b107bcb5e ncalrpc: LRPC-0ec61c40e676375aa5 f47433c3-3e9d-4157-aad4-83aa1f5c2d4c version: v1.0 annotation: Fw APIs ncalrpc: LRPC-e8b8ca782b107bcb5e ncalrpc: LRPC-0ec61c40e676375aa5 7f9d11bf-7fb9-436b-a812-b2d50c5d4c03 version: v1.0 annotation: Fw APIs provider: MPSSVC.dll ncalrpc: LRPC-e8b8ca782b107bcb5e ncalrpc: LRPC-0ec61c40e676375aa5 dd490425-5325-4565-b774-7e27d6c09c24 version: v1.0 annotation: Base Firewall Engine API provider: BFE.DLL ncalrpc: LRPC-0ec61c40e676375aa5 7f1343fe-50a9-4927-a778-0c5859517bac version: v1.0 annotation: DfsDs service ncacn_np: \\S132-148-155-0\PIPE\wkssvc ncalrpc: LRPC-6e6d1acb912383caec ncalrpc: DNSResolver eb081a0d-10ee-478a-a1dd-50995283e7a8 version: v3.0 annotation: Witness Client Test Interface ncalrpc: LRPC-6e6d1acb912383caec ncalrpc: DNSResolver f2c9b409-c1c9-4100-8639-d8ab1486694a version: v1.0 annotation: Witness Client Upcall Server ncalrpc: LRPC-6e6d1acb912383caec ncalrpc: DNSResolver 76f03f96-cdfd-44fc-a22c-64950a001209 version: v1.0 protocol: [MS-PAR]: Print System Asynchronous Remote Protocol provider: spoolsv.exe ncacn_ip_tcp: 132.148.155.0:49155 ncalrpc: LRPC-34d6330c85f5a1f28e 4a452661-8290-4b36-8fbe-7f4093a94978 version: v1.0 provider: spoolsv.exe ncacn_ip_tcp: 132.148.155.0:49155 ncalrpc: LRPC-34d6330c85f5a1f28e ae33069b-a2a8-46ee-a235-ddfd339be281 version: v1.0 protocol: [MS-PAN]: Print System Asynchronous Notification Protocol provider: spoolsv.exe ncacn_ip_tcp: 132.148.155.0:49155 ncalrpc: LRPC-34d6330c85f5a1f28e 0b6edbfa-4a24-4fc6-8a23-942b1eca65d1 version: v1.0 protocol: [MS-PAN]: Print System Asynchronous Notification Protocol provider: spoolsv.exe ncacn_ip_tcp: 132.148.155.0:49155 ncalrpc: LRPC-34d6330c85f5a1f28e 12345678-1234-abcd-ef00-0123456789ab version: v1.0 protocol: [MS-RPRN]: Print System Remote Protocol provider: spoolsv.exe ncacn_ip_tcp: 132.148.155.0:49155 ncalrpc: LRPC-34d6330c85f5a1f28e 1a9134dd-7b39-45ba-ad88-44d01ca47f28 version: v1.0 annotation: Message Queuing - RemoteRead V1 protocol: [MS-MQRR]: Message Queuing (MSMQ): provider: mqqm.dll ncacn_ip_tcp: 132.148.155.0:2105 ncacn_ip_tcp: 132.148.155.0:2103 ncacn_ip_tcp: 132.148.155.0:2107 ncacn_ip_tcp: 132.148.155.0:49156 ncalrpc: QMMgmtFacility$s132-148-155-0 ncalrpc: QMsvc$s132-148-155-0 1088a980-eae5-11d0-8d9b-00a02453c337 version: v1.0 annotation: Message Queuing - QM2QM V1 protocol: [MS-MQQP]: Message Queuing (MSMQ): provider: mqqm.dll ncacn_ip_tcp: 132.148.155.0:2105 ncacn_ip_tcp: 132.148.155.0:2103 ncacn_ip_tcp: 132.148.155.0:2107 ncacn_ip_tcp: 132.148.155.0:49156 ncalrpc: QMMgmtFacility$s132-148-155-0 ncalrpc: QMsvc$s132-148-155-0 76d12b80-3467-11d3-91ff-0090272f9ea3 version: v1.0 annotation: Message Queuing - QMRT V2 protocol: [MS-MQMP]: Message Queuing (MSMQ): provider: mqqm.dll ncacn_ip_tcp: 132.148.155.0:2105 ncacn_ip_tcp: 132.148.155.0:2103 ncacn_ip_tcp: 132.148.155.0:2107 ncacn_ip_tcp: 132.148.155.0:49156 ncalrpc: QMMgmtFacility$s132-148-155-0 ncalrpc: QMsvc$s132-148-155-0 fdb3a030-065f-11d1-bb9b-00a024ea5525 version: v1.0 annotation: Message Queuing - QMRT V1 protocol: [MS-MQMP]: Message Queuing (MSMQ): provider: mqqm.dll ncacn_ip_tcp: 132.148.155.0:2105 ncacn_ip_tcp: 132.148.155.0:2103 ncacn_ip_tcp: 132.148.155.0:2107 ncacn_ip_tcp: 132.148.155.0:49156 ncalrpc: QMMgmtFacility$s132-148-155-0 ncalrpc: QMsvc$s132-148-155-0 50abc2a4-574d-40b3-9d66-ee4fd5fba076 version: v5.0 protocol: [MS-DNSP]: Domain Name Service (DNS) Server Management provider: dns.exe ncacn_ip_tcp: 132.148.155.0:49157 367abb81-9844-35f1-ad32-98f038001003 version: v2.0 protocol: [MS-SCMR]: Service Control Manager Remote Protocol provider: services.exe ncacn_ip_tcp: 132.148.155.0:49173 6b5bdd1e-528c-422c-af8c-a4079be4fe48 version: v1.0 annotation: Remote Fw APIs protocol: [MS-FASP]: Firewall and Advanced Security Protocol provider: FwRemoteSvr.dll ncacn_ip_tcp: 132.148.155.0:49174 906b0ce0-c70b-1067-b317-00dd010662da version: v1.0 protocol: [MS-CMPO]: MSDTC Connection Manager: provider: msdtcprx.dll ncalrpc: LRPC-1f082430bb48a831ea ncalrpc: LRPC-1f082430bb48a831ea ncalrpc: LRPC-1f082430bb48a831ea ncalrpc: LRPC-3ea0a873a96409a02a ncalrpc: OLE086D431D338FE8E50C3000E7891E b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86 version: v2.0 annotation: KeyIso ncacn_ip_tcp: 132.148.155.0:55905 ncalrpc: efslrpc ncacn_np: \\S132-148-155-0\pipe\efsrpc ncalrpc: samss lpc ncalrpc: SidKey Local End Point ncalrpc: protected_storage ncalrpc: lsasspirpc ncalrpc: lsapolicylookup ncalrpc: LSA_EAS_ENDPOINT ncalrpc: lsacap ncalrpc: LSARPC_ENDPOINT ncalrpc: securityevent ncalrpc: audit ncacn_np: \\S132-148-155-0\pipe\lsass 12345778-1234-abcd-ef00-0123456789ac version: v1.0 protocol: [MS-SAMR]: Security Account Manager (SAM) Remote Protocol provider: samsrv.dll ncacn_ip_tcp: 132.148.155.0:55905 ncalrpc: efslrpc ncacn_np: \\S132-148-155-0\pipe\efsrpc ncalrpc: samss lpc ncalrpc: SidKey Local End Point ncalrpc: protected_storage ncalrpc: lsasspirpc ncalrpc: lsapolicylookup ncalrpc: LSA_EAS_ENDPOINT ncalrpc: lsacap ncalrpc: LSARPC_ENDPOINT ncalrpc: securityevent ncalrpc: audit ncacn_np: \\S132-148-155-0\pipe\lsass 12e65dd8-887f-41ef-91bf-8d816c42c2e7 version: v1.0 annotation: Secure Desktop LRPC interface provider: winlogon.exe ncalrpc: WMsgKRpc0E5F782 9435cc56-1d9c-4924-ac7d-b60a2c3520e1 version: v1.0 annotation: SPPSVC Default RPC Interface provider: sppsvc.exe ncalrpc: SPPCTransportEndpoint-00001
1102275607 | 2024-11-11T07:25:59.541365443 / tcp
HTTP/1.1 401 Unauthorized Server: Microsoft-IIS/8.5 WWW-Authenticate: Digest qop="auth",algorithm=MD5-sess,nonce="+Upgraded+v1262e66b2ebf5245096342dea08006553973d6cde0a34db0104819c7fc45304c87822a84df377cc3388a03cad03010691a5d49a9c829cceb9",charset=utf-8,realm="Digest" WWW-Authenticate: Negotiate WWW-Authenticate: NTLM Date: Mon, 11 Nov 2024 07:25:22 GMT Content-Length: 0 HTTP NTLM Info: OS: Windows 8.1/Windows Server 2012 R2 OS Build: 6.3.9600 Target Name: S132-148-155-0 NetBIOS Domain Name: S132-148-155-0 NetBIOS Computer Name: S132-148-155-0 DNS Domain Name: s132-148-155-0.secureserver.net FQDN: s132-148-155-0.secureserver.net
Certificate: Data: Version: 3 (0x2) Serial Number: 3464132320970217480 (0x301311fdfe611808) Signature Algorithm: sha256WithRSAEncryption Issuer: C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., OU=http:\/\/certs.godaddy.com\/repository\/, CN=Go Daddy Secure Certificate Authority - G2 Validity Not Before: Aug 16 19:19:58 2024 GMT Not After : Nov 14 00:40:09 2024 GMT Subject: CN=yms.mx Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (2048 bit) Modulus: 00:ea:bc:2f:c5:38:17:99:b5:55:23:02:4c:98:28: db:8a:58:c2:04:fe:3e:59:e9:22:89:f1:0c:40:d8: f2:e4:85:07:7a:14:11:36:64:97:2a:94:4e:6c:99: ba:98:bf:93:5b:00:04:44:20:b3:dc:22:f9:f2:67: 55:d9:0a:e8:ba:a8:50:6b:7d:a0:55:23:68:fb:ec: c0:15:d7:17:76:ef:5b:d2:e6:b3:79:06:57:2e:96: 61:7f:8d:f0:8c:b6:59:35:a6:da:aa:8a:87:b4:30: 37:13:63:17:ae:2f:5c:50:bf:5c:d1:f7:aa:40:fe: 34:4e:e7:b6:b9:c1:df:80:68:1c:85:b1:c4:91:c9: 09:bf:cc:13:ac:77:b4:4e:53:91:0f:ec:35:38:05: 8d:4b:0f:17:d1:05:a9:c0:c6:6b:de:ed:15:c0:5e: 79:b0:2f:82:5a:93:da:2b:e9:9e:9a:d2:bd:65:e5: a5:1b:8e:63:29:2a:a0:11:a7:a2:52:8c:10:83:b6: 5e:b2:ea:c3:cf:7c:a8:2f:9f:ab:47:fc:e9:8e:a9: d1:32:3d:a3:6d:e1:96:66:e9:f4:40:78:da:f1:45: 78:a9:1f:f7:c2:e0:26:90:f3:3b:9b:b7:7a:77:6c: bd:95:35:f5:96:fe:49:1d:4c:9b:81:2b:5e:09:23: 13:2d Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Basic Constraints: critical CA:FALSE X509v3 Extended Key Usage: TLS Web Server Authentication, TLS Web Client Authentication X509v3 Key Usage: critical Digital Signature, Key Encipherment X509v3 CRL Distribution Points: Full Name: URI:http://crl.godaddy.com/gdig2s1-28615.crl X509v3 Certificate Policies: Policy: 2.16.840.1.114413.1.7.23.1 CPS: http://certificates.godaddy.com/repository/ Policy: 2.23.140.1.2.1 Authority Information Access: OCSP - URI:http://ocsp.godaddy.com/ CA Issuers - URI:http://certificates.godaddy.com/repository/gdig2.crt X509v3 Authority Key Identifier: 40:C2:BD:27:8E:CC:34:83:30:A2:33:D7:FB:6C:B3:F0:B4:2C:80:CE X509v3 Subject Alternative Name: DNS:yms.mx, DNS:www.yms.mx X509v3 Subject Key Identifier: F3:69:BA:37:C7:4E:CC:F2:39:DA:7B:08:EA:26:BA:07:AB:55:38:CD CT Precertificate SCTs: Signed Certificate Timestamp: Version : v1 (0x0) Log ID : EE:CD:D0:64:D5:DB:1A:CE:C5:5C:B7:9D:B4:CD:13:A2: 32:87:46:7C:BC:EC:DE:C3:51:48:59:46:71:1F:B5:9B Timestamp : Aug 16 19:19:59.005 2024 GMT Extensions: none Signature : ecdsa-with-SHA256 30:44:02:20:63:3D:ED:DD:01:4D:0F:9A:26:1E:F7:A7: 87:30:F5:0B:66:45:26:1A:DA:FE:D5:08:F9:19:53:B6: 87:1F:1F:06:02:20:23:94:06:3C:1C:1F:09:F4:53:AE: 10:D1:18:3B:DD:3B:01:E6:A9:B2:0E:91:B3:5D:9D:9A: AF:A2:A2:EB:6B:E2 Signed Certificate Timestamp: Version : v1 (0x0) Log ID : 48:B0:E3:6B:DA:A6:47:34:0F:E5:6A:02:FA:9D:30:EB: 1C:52:01:CB:56:DD:2C:81:D9:BB:BF:AB:39:D8:84:73 Timestamp : Aug 16 19:19:59.159 2024 GMT Extensions: none Signature : ecdsa-with-SHA256 30:44:02:20:3C:DF:D3:3B:E8:54:27:62:49:07:01:0B: FC:F0:E1:DF:CF:70:95:36:AC:2D:43:AD:D4:05:26:8D: 7C:7D:12:B5:02:20:70:45:8C:A7:5F:AA:34:F5:4A:7E: 39:F2:82:0D:C0:22:64:31:7D:F4:F6:AA:A2:E6:02:FC: 1E:EA:99:2F:15:33 Signed Certificate Timestamp: Version : v1 (0x0) Log ID : DA:B6:BF:6B:3F:B5:B6:22:9F:9B:C2:BB:5C:6B:E8:70: 91:71:6C:BB:51:84:85:34:BD:A4:3D:30:48:D7:FB:AB Timestamp : Aug 16 19:19:59.282 2024 GMT Extensions: none Signature : ecdsa-with-SHA256 30:45:02:20:4F:12:B9:93:F4:F3:2F:D0:07:C3:EC:23: 13:43:8B:3B:F7:CC:8A:52:97:9D:0C:D7:F5:BE:F2:DD: 37:79:A9:75:02:21:00:CB:C5:3B:54:1D:1F:28:27:48: 82:30:FC:89:C3:3B:32:4A:F0:D6:52:48:CA:54:B8:64: 84:DA:86:B1:2E:B9:F0 Signature Algorithm: sha256WithRSAEncryption Signature Value: 06:a5:4f:d0:6f:37:0f:45:a4:53:57:95:6e:fc:3e:db:50:a3: be:ec:8e:dc:11:37:db:12:0b:30:23:f8:77:b1:97:a5:31:2b: 30:5e:88:7c:bf:99:e5:a2:77:55:c9:dd:25:a6:32:6c:ff:7f: 47:a2:1f:ed:27:be:b8:95:6d:cd:03:6e:0b:4c:28:f2:0b:a1: 82:2d:f0:8c:b9:04:7d:81:d5:e7:10:3e:36:8b:d0:2f:63:52: 9a:b3:64:ed:66:27:10:4c:40:10:78:da:d4:72:4a:29:d5:27: 4a:fe:01:8b:d2:75:7a:44:98:b4:be:ab:50:f5:7a:ff:da:f8: 36:5a:8c:1f:bd:82:b8:d9:de:8c:3c:32:52:0b:bb:03:a0:7e: 10:01:d5:5b:09:c5:03:b7:c6:c7:94:14:b7:4e:e9:8b:ec:52: 45:70:ac:6a:f4:ed:04:47:2f:81:ed:5f:a9:54:f7:3d:13:49: a9:91:0e:b0:48:6e:92:2c:31:f9:c9:e5:51:53:d4:24:f9:81: fe:8b:b5:c1:fe:e3:a3:ae:5b:cf:8b:ea:88:da:6e:9c:18:e3: 18:1a:89:e4:13:79:27:00:ab:d1:0d:86:bd:62:48:c2:9f:0a: 12:7a:12:51:63:52:5a:0d:8e:8a:07:53:9a:0b:0d:c4:d0:23: 4a:f6:89:c4
-1413703094 | 2024-11-02T09:30:23.372624445 / tcp
SMB Status: Authentication: enabled SMB Version: 1 OS: Windows Server 2012 R2 Standard 9600 Software: Windows Server 2012 R2 Standard 6.3 Capabilities: dfs, extended-security, infolevel-passthru, large-files, large-readx, large-writex, level2-oplocks, lock-and-read, lwio, nt-find, nt-smb, nt-status, rpc-remote-api, unicode
2053869773 | 2024-11-17T09:13:03.6348801433 / tcp
MS-SQL NTLM Info: OS: Windows 8.1/Windows Server 2012 R2 OS Build: 6.3.9600 Target Name: S132-148-155-0 NetBIOS Domain Name: S132-148-155-0 NetBIOS Computer Name: S132-148-155-0 DNS Domain Name: s132-148-155-0.secureserver.net FQDN: s132-148-155-0.secureserver.net
1209100331 | 2024-11-16T04:27:28.9006891434 / udp
SQL Server Browser Service: Instance #1: Server Name: S132-148-155-0 Instance Name: SQLEXPRESS Is Clustered: False Version: 11.0.7001.0 TCP Port: 1433 Named Pipe: \\S132-148-155-0\pipe\MSSQL$SQLEXPRESS\sql\query Version Name: MS-SQL Server 2012 SP4RTW/PCU4
1965740638 | 2024-11-02T13:28:54.2500491801 / tcp
\x10Z\x0b\x00LIOR<\x02\x00\x00\xff\xff\xff\xff\x00\x00\x12\x00\x06U=Q6\xdf\xc7@\x96C\x17\\<\xe7l\xaaY\xcb\x96\xc8\xda\x02\x9dG\x8315k\x8d\x8aL\xc9\x00\x00\x00\x00\x10\x02\x00\x00ZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZ
-1752762301 | 2024-11-16T14:50:20.9015613260 / tcp
Not found any reachable targets
-2107675290 | 2024-11-14T12:03:18.9382073389 / tcp
Remote Desktop Protocol \x03\x00\x00\x13\x0e\xd0\x00\x00\x124\x00\x02\x0f\x08\x00\x02\x00\x00\x00 Remote Desktop Protocol NTLM Info: OS: Windows 8.1/Windows Server 2012 R2 OS Build: 6.3.9600 Target Name: S132-148-155-0 NetBIOS Domain Name: S132-148-155-0 NetBIOS Computer Name: S132-148-155-0 DNS Domain Name: s132-148-155-0.secureserver.net FQDN: s132-148-155-0.secureserver.net dotconmet appuser am Windows Server 2012R2
Certificate: Data: Version: 3 (0x2) Serial Number: 5e:0d:a2:e9:84:41:3d:b6:46:0f:b0:9f:7f:1a:f8:e6 Signature Algorithm: sha256WithRSAEncryption Issuer: CN=s132-148-155-0.secureserver.net Validity Not Before: Nov 9 00:00:01 2024 GMT Not After : May 11 00:00:01 2025 GMT Subject: CN=s132-148-155-0.secureserver.net Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (2048 bit) Modulus: 00:b2:93:6a:54:4b:f5:7c:49:c6:d7:37:1d:14:93: 24:a1:cc:88:98:49:2b:0b:b2:64:20:4c:e5:0b:9d: 73:4f:a5:b1:36:76:f7:9d:d9:fe:6c:51:96:8b:9d: 61:6f:69:21:24:82:98:b1:97:d7:c3:a0:0f:8f:98: 77:30:ba:0e:4e:43:f3:1a:d6:08:0f:f2:c1:53:32: f1:97:c5:ea:3d:19:cd:55:6e:7c:4d:81:54:cb:2c: 93:fe:75:3a:a1:16:dc:5f:fa:f8:72:aa:06:f9:a0: 2e:fc:71:1b:e7:8e:bc:44:ac:59:bc:18:74:1c:78: a5:43:0d:22:b3:de:a6:d3:21:ef:7d:36:14:7a:d4: a2:72:12:75:16:4e:15:2f:ec:ce:34:9b:9e:c2:bd: 6a:35:01:39:31:85:1d:2e:13:02:5a:a6:5a:81:6f: 65:e5:64:69:ad:10:9f:fa:b2:39:6a:ae:93:ca:f6: 21:ce:a4:88:6e:38:47:44:69:e6:a9:e6:31:6d:ef: f4:be:f9:36:83:df:55:e5:a3:db:62:9b:1e:60:79: 51:69:1e:80:c3:02:8f:a4:b8:db:ab:6a:d4:9d:d9: da:eb:f6:be:36:30:e6:7c:6a:b0:64:00:ab:b7:19: e7:4c:32:fc:37:38:75:49:be:88:6e:25:4f:e6:8d: 5c:1d Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Extended Key Usage: TLS Web Server Authentication X509v3 Key Usage: Key Encipherment, Data Encipherment Signature Algorithm: sha256WithRSAEncryption Signature Value: 4b:e4:f8:44:12:3f:74:ee:46:50:58:41:28:4d:13:f2:ed:0f: 29:80:eb:c6:ba:bd:42:01:11:b7:e8:45:6e:45:c3:b5:84:1d: 88:9f:9a:79:f2:b1:45:02:78:05:ac:67:e4:4c:3b:e3:5b:a2: bf:03:c2:d2:38:a8:36:38:7f:ce:a3:57:a2:5b:99:c3:e4:08: 26:84:69:b1:7d:f0:d8:51:eb:7c:eb:64:5d:05:53:d8:f8:34: 93:e2:9a:cf:b1:2e:07:1a:b7:52:32:b6:60:1b:c5:9a:2b:d8: b1:71:2b:ff:c9:26:77:83:fd:d8:8d:ed:1c:6f:46:c2:a3:c0: a9:f6:e4:45:ef:e1:56:a3:d1:97:51:c5:51:ad:be:1a:ea:e4: 60:2a:5d:e6:d8:c6:25:d6:2a:ab:0c:a5:f0:cf:4c:00:91:70: 07:53:b9:2c:ce:b2:70:40:29:32:95:2f:ac:5d:e4:8e:8f:90: 62:17:68:03:68:3d:b7:e0:11:c1:c0:95:2a:26:3b:9f:ed:03: d7:e2:6b:24:5a:3e:25:20:0c:14:85:90:a5:ab:ad:05:33:8d: 83:3b:45:32:c8:1a:e2:73:9b:11:42:fb:12:10:0b:35:dd:04: 1e:69:10:f9:13:b3:ef:91:b4:8a:a7:cb:31:e7:41:0b:87:8a: 83:e9:12:ca
1489525118 | 2024-11-10T08:21:22.2069455985 / tcp
HTTP/1.1 404 Not Found Content-Type: text/html; charset=us-ascii Server: Microsoft-HTTPAPI/2.0 Date: Sun, 10 Nov 2024 08:20:47 GMT Connection: close Content-Length: 315 WinRM NTLM Info: OS: Windows Server 2012 R2 OS Build: 6.3.9600 Target Name: S132-148-155-0 NetBIOS Domain Name: S132-148-155-0 NetBIOS Computer Name: S132-148-155-0 DNS Domain Name: s132-148-155-0.secureserver.net FQDN: s132-148-155-0.secureserver.net