879918521 | 2024-12-09T08:39:04.418490
135 /
tcp
Microsoft RPC Endpoint Mapper
d95afe70-a6d5-4259-822e-2c84da1ddb0d
version: v1.0
protocol: [MS-RSP]: Remote Shutdown Protocol
provider: wininit.exe
ncacn_ip_tcp: 154.221.31.250:49152
ncalrpc: WindowsShutdown
ncacn_np: \\YISU-670E558AC8\PIPE\InitShutdown
ncalrpc: WMsgKRpc04ACC0
76f226c3-ec14-4325-8a99-6a46348418af
version: v1.0
provider: winlogon.exe
ncalrpc: WindowsShutdown
ncacn_np: \\YISU-670E558AC8\PIPE\InitShutdown
ncalrpc: WMsgKRpc04ACC0
ncalrpc: WMsgKRpc04CC01
ncalrpc: WMsgKRpc01111482
9b008953-f195-4bf9-bde0-4471971e58ed
version: v1.0
ncalrpc: LRPC-d3a899499879be74fa
ncacn_np: \\YISU-670E558AC8\pipe\LSM_API_service
ncalrpc: LSMApi
ncalrpc: LRPC-fed7fe97fde2e38b7a
ncalrpc: actkernel
ncalrpc: umpo
697dcda9-3ba9-4eb2-9247-e11f1901b0d2
version: v1.0
ncalrpc: LRPC-d3a899499879be74fa
ncacn_np: \\YISU-670E558AC8\pipe\LSM_API_service
ncalrpc: LSMApi
ncalrpc: LRPC-fed7fe97fde2e38b7a
ncalrpc: actkernel
ncalrpc: umpo
c9ac6db5-82b7-4e55-ae8a-e464ed7b4277
version: v1.0
annotation: Impl friendly name
provider: sysntfy.dll
ncalrpc: LRPC-fed7fe97fde2e38b7a
ncalrpc: actkernel
ncalrpc: umpo
ncalrpc: DeviceSetupManager
ncacn_ip_tcp: 154.221.31.250:49154
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\YISU-670E558AC8\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLE7A2F8FAC58883774FF8DCC723920
ncalrpc: IUserProfile2
ncalrpc: senssvc
ncalrpc: OLE7A2F8FAC58883774FF8DCC723920
ncalrpc: IUserProfile2
ncalrpc: IUserProfile2
ncalrpc: IUserProfile2
0d3e2735-cea0-4ecc-a9e2-41a2d81aed4e
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
c605f9fb-f0a3-4e2a-a073-73560f8d9e3e
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
1b37ca91-76b1-4f5e-a3c7-2abfc61f2bb0
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
8bfc3be1-6def-4e2d-af74-7c47cd0ade4a
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
2d98a740-581d-41b9-aa0d-a88b9d5ce938
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
bdaa0970-413b-4a3e-9e5d-f6dc9d7e0760
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
3b338d89-6cfa-44b8-847e-531531bc9992
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
8782d3b9-ebbd-4644-a3d8-e8725381919b
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
085b0334-e454-4d91-9b8c-4134f9e793f3
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
4bec6bb8-b5c2-4b6f-b2c1-5da5cf92d0d9
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5
version: v1.0
annotation: DHCP Client LRPC Endpoint
provider: dhcpcsvc.dll
ncalrpc: dhcpcsvc
ncalrpc: dhcpcsvc6
ncalrpc: LRPC-7cde929a1057cf7341
ncacn_ip_tcp: 154.221.31.250:49153
ncacn_np: \\YISU-670E558AC8\pipe\eventlog
ncalrpc: eventlog
3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6
version: v1.0
annotation: DHCPv6 Client LRPC Endpoint
provider: dhcpcsvc6.dll
ncalrpc: dhcpcsvc6
ncalrpc: LRPC-7cde929a1057cf7341
ncacn_ip_tcp: 154.221.31.250:49153
ncacn_np: \\YISU-670E558AC8\pipe\eventlog
ncalrpc: eventlog
abfb6ca3-0c5e-4734-9285-0aee72fe8d1c
version: v1.0
annotation: Wcm Service
ncalrpc: LRPC-7cde929a1057cf7341
ncacn_ip_tcp: 154.221.31.250:49153
ncacn_np: \\YISU-670E558AC8\pipe\eventlog
ncalrpc: eventlog
f6beaff7-1e19-4fbb-9f8f-b89e2018337c
version: v1.0
annotation: Event log TCPIP
protocol: [MS-EVEN6]: EventLog Remoting Protocol
provider: wevtsvc.dll
ncacn_ip_tcp: 154.221.31.250:49153
ncacn_np: \\YISU-670E558AC8\pipe\eventlog
ncalrpc: eventlog
58e604e8-9adb-4d2e-a464-3b0683fb1480
version: v1.0
annotation: AppInfo
provider: appinfo.dll
ncacn_np: \\YISU-670E558AC8\pipe\SessEnvPublicRpc
ncalrpc: SessEnvPrivateRpc
ncalrpc: LRPC-343fb81c43e98943fc
ncalrpc: DeviceSetupManager
ncacn_ip_tcp: 154.221.31.250:49154
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\YISU-670E558AC8\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLE7A2F8FAC58883774FF8DCC723920
ncalrpc: IUserProfile2
fd7a0523-dc70-43dd-9b2e-9c5ed48225b1
version: v1.0
annotation: AppInfo
provider: appinfo.dll
ncacn_np: \\YISU-670E558AC8\pipe\SessEnvPublicRpc
ncalrpc: SessEnvPrivateRpc
ncalrpc: LRPC-343fb81c43e98943fc
ncalrpc: DeviceSetupManager
ncacn_ip_tcp: 154.221.31.250:49154
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\YISU-670E558AC8\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLE7A2F8FAC58883774FF8DCC723920
ncalrpc: IUserProfile2
5f54ce7d-5b79-4175-8584-cb65313a0e98
version: v1.0
annotation: AppInfo
provider: appinfo.dll
ncacn_np: \\YISU-670E558AC8\pipe\SessEnvPublicRpc
ncalrpc: SessEnvPrivateRpc
ncalrpc: LRPC-343fb81c43e98943fc
ncalrpc: DeviceSetupManager
ncacn_ip_tcp: 154.221.31.250:49154
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\YISU-670E558AC8\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLE7A2F8FAC58883774FF8DCC723920
ncalrpc: IUserProfile2
201ef99a-7fa0-444c-9399-19ba84f12a1a
version: v1.0
annotation: AppInfo
provider: appinfo.dll
ncacn_np: \\YISU-670E558AC8\pipe\SessEnvPublicRpc
ncalrpc: SessEnvPrivateRpc
ncalrpc: LRPC-343fb81c43e98943fc
ncalrpc: DeviceSetupManager
ncacn_ip_tcp: 154.221.31.250:49154
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\YISU-670E558AC8\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLE7A2F8FAC58883774FF8DCC723920
ncalrpc: IUserProfile2
30b044a5-a225-43f0-b3a4-e060df91f9c1
version: v1.0
provider: certprop.dll
ncalrpc: LRPC-343fb81c43e98943fc
ncalrpc: DeviceSetupManager
ncacn_ip_tcp: 154.221.31.250:49154
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\YISU-670E558AC8\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLE7A2F8FAC58883774FF8DCC723920
ncalrpc: IUserProfile2
c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1
version: v1.0
annotation: Adh APIs
ncacn_ip_tcp: 154.221.31.250:49154
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\YISU-670E558AC8\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLE7A2F8FAC58883774FF8DCC723920
ncalrpc: IUserProfile2
c36be077-e14b-4fe9-8abc-e856ef4f048b
version: v1.0
annotation: Proxy Manager client server endpoint
ncacn_ip_tcp: 154.221.31.250:49154
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\YISU-670E558AC8\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLE7A2F8FAC58883774FF8DCC723920
ncalrpc: IUserProfile2
2e6035b2-e8f1-41a7-a044-656b439c4c34
version: v1.0
annotation: Proxy Manager provider server endpoint
ncacn_ip_tcp: 154.221.31.250:49154
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\YISU-670E558AC8\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLE7A2F8FAC58883774FF8DCC723920
ncalrpc: IUserProfile2
552d076a-cb29-4e44-8b6a-d15e59e2c0af
version: v1.0
annotation: IP Transition Configuration endpoint
provider: iphlpsvc.dll
ncacn_ip_tcp: 154.221.31.250:49154
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\YISU-670E558AC8\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLE7A2F8FAC58883774FF8DCC723920
ncalrpc: IUserProfile2
a398e520-d59a-4bdd-aa7a-3c1e0303a511
version: v1.0
annotation: IKE/Authip API
provider: IKEEXT.DLL
ncacn_ip_tcp: 154.221.31.250:49154
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\YISU-670E558AC8\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLE7A2F8FAC58883774FF8DCC723920
ncalrpc: IUserProfile2
3a9ef155-691d-4449-8d05-09ad57031823
version: v1.0
ncacn_ip_tcp: 154.221.31.250:49154
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\YISU-670E558AC8\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLE7A2F8FAC58883774FF8DCC723920
ncalrpc: IUserProfile2
86d35949-83c9-4044-b424-db363231fd0c
version: v1.0
protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol
provider: schedsvc.dll
ncacn_ip_tcp: 154.221.31.250:49154
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\YISU-670E558AC8\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLE7A2F8FAC58883774FF8DCC723920
ncalrpc: IUserProfile2
378e52b0-c0a9-11cf-822d-00aa0051e40f
version: v1.0
protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol
provider: taskcomp.dll
ncacn_np: \\YISU-670E558AC8\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLE7A2F8FAC58883774FF8DCC723920
ncalrpc: IUserProfile2
1ff70682-0a51-30e8-076d-740be8cee98b
version: v1.0
protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol
provider: taskcomp.dll
ncacn_np: \\YISU-670E558AC8\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLE7A2F8FAC58883774FF8DCC723920
ncalrpc: IUserProfile2
0a74ef1c-41a4-4e06-83ae-dc74fb1cdd53
version: v1.0
provider: schedsvc.dll
ncalrpc: senssvc
ncalrpc: OLE7A2F8FAC58883774FF8DCC723920
ncalrpc: IUserProfile2
2eb08e3e-639f-4fba-97b1-14f878961076
version: v1.0
annotation: Group Policy RPC Interface
provider: gpsvc.dll
ncalrpc: LRPC-ff8034f3d44fa7a2de
3473dd4d-2e88-4006-9cba-22570909dd10
version: v5.256
annotation: WinHttp Auto-Proxy Service
ncacn_np: \\YISU-670E558AC8\PIPE\W32TIME_ALT
ncalrpc: W32TIME_ALT
ncalrpc: LRPC-1afbc4a8a567ee5211
ncalrpc: OLE4BB162377EDD1782FC86B30DB2E8
7ea70bcf-48af-4f6a-8968-6a440754d5fa
version: v1.0
annotation: NSI server endpoint
provider: nsisvc.dll
ncalrpc: LRPC-1afbc4a8a567ee5211
ncalrpc: OLE4BB162377EDD1782FC86B30DB2E8
b2507c30-b126-494a-92ac-ee32b6eeb039
version: v1.0
ncalrpc: LRPC-4f311aff293634b533
2fb92682-6599-42dc-ae13-bd2ca89bd11c
version: v1.0
annotation: Fw APIs
provider: MPSSVC.dll
ncalrpc: LRPC-126507ad8ce6536e02
ncalrpc: LRPC-ac6268d3b1507559e2
f47433c3-3e9d-4157-aad4-83aa1f5c2d4c
version: v1.0
annotation: Fw APIs
ncalrpc: LRPC-126507ad8ce6536e02
ncalrpc: LRPC-ac6268d3b1507559e2
7f9d11bf-7fb9-436b-a812-b2d50c5d4c03
version: v1.0
annotation: Fw APIs
provider: MPSSVC.dll
ncalrpc: LRPC-126507ad8ce6536e02
ncalrpc: LRPC-ac6268d3b1507559e2
dd490425-5325-4565-b774-7e27d6c09c24
version: v1.0
annotation: Base Firewall Engine API
provider: BFE.DLL
ncalrpc: LRPC-ac6268d3b1507559e2
7f1343fe-50a9-4927-a778-0c5859517bac
version: v1.0
annotation: DfsDs service
ncacn_np: \\YISU-670E558AC8\PIPE\wkssvc
ncalrpc: LRPC-89e97f7346bc5b069d
ncalrpc: DNSResolver
eb081a0d-10ee-478a-a1dd-50995283e7a8
version: v3.0
annotation: Witness Client Test Interface
ncalrpc: LRPC-89e97f7346bc5b069d
ncalrpc: DNSResolver
f2c9b409-c1c9-4100-8639-d8ab1486694a
version: v1.0
annotation: Witness Client Upcall Server
ncalrpc: LRPC-89e97f7346bc5b069d
ncalrpc: DNSResolver
906b0ce0-c70b-1067-b317-00dd010662da
version: v1.0
protocol: [MS-CMPO]: MSDTC Connection Manager:
provider: msdtcprx.dll
ncalrpc: LRPC-3c087e4c34fb6f6e42
ncalrpc: LRPC-3c087e4c34fb6f6e42
ncalrpc: LRPC-3c087e4c34fb6f6e42
367abb81-9844-35f1-ad32-98f038001003
version: v2.0
protocol: [MS-SCMR]: Service Control Manager Remote Protocol
provider: services.exe
ncacn_ip_tcp: 154.221.31.250:49156
6b5bdd1e-528c-422c-af8c-a4079be4fe48
version: v1.0
annotation: Remote Fw APIs
protocol: [MS-FASP]: Firewall and Advanced Security Protocol
provider: FwRemoteSvr.dll
ncacn_ip_tcp: 154.221.31.250:49157
12345778-1234-abcd-ef00-0123456789ac
version: v1.0
protocol: [MS-SAMR]: Security Account Manager (SAM) Remote Protocol
provider: samsrv.dll
ncacn_ip_tcp: 154.221.31.250:49159
ncalrpc: samss lpc
ncalrpc: SidKey Local End Point
ncalrpc: protected_storage
ncalrpc: lsasspirpc
ncalrpc: lsapolicylookup
ncalrpc: LSA_EAS_ENDPOINT
ncalrpc: lsacap
ncalrpc: LSARPC_ENDPOINT
ncalrpc: securityevent
ncalrpc: audit
ncacn_np: \\YISU-670E558AC8\pipe\lsass
12e65dd8-887f-41ef-91bf-8d816c42c2e7
version: v1.0
annotation: Secure Desktop LRPC interface
provider: winlogon.exe
ncalrpc: WMsgKRpc01111482
2101583777 | 2025-01-01T23:46:13.583432
137 /
udp
NetBIOS Response:
MAC Address: 52:54:00:13:8F:61
Names:
YISU69670E55 <0x0>
YISU-670E558AC8 <0x0>
MAC Addresses
52:54:00:13:8F:61
Unknown
-1003729242 | 2024-12-31T06:44:43.667458
3389 /
tcp
Remote Desktop Protocol
\x03\x00\x00\x13\x0e\xd0\x00\x00\x124\x00\x02\x0f\x08\x00\x02\x00\x00\x00
Remote Desktop Protocol NTLM Info:
OS: Windows 8.1/Windows Server 2012 R2
OS Build: 6.3.9600
Target Name: YISU-670E558AC8
NetBIOS Domain Name: YISU-670E558AC8
NetBIOS Computer Name: YISU-670E558AC8
DNS Domain Name: yisu-670e558ac8123
FQDN: yisu-670e558ac8123
Administrator
am Windows Server 2012R2
SSL Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
6a:54:30:c9:87:52:6e:80:48:81:34:a5:2b:38:31:62
Signature Algorithm: sha1WithRSAEncryption
Issuer: CN=yisu-670e558ac8123
Validity
Not Before: Oct 14 11:45:05 2024 GMT
Not After : Apr 15 11:45:05 2025 GMT
Subject: CN=yisu-670e558ac8123
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:d0:52:36:83:cf:90:84:6b:27:bd:27:20:03:01:
70:7c:6a:f0:57:43:04:32:16:c7:97:1f:f1:5c:a4:
81:32:05:f3:e2:11:21:e0:d3:85:ab:ed:da:05:e1:
06:cf:19:4c:a3:c5:ac:9c:f9:76:50:f2:d6:16:71:
d0:70:6e:1e:c7:b3:2c:29:40:f2:38:ae:5f:f8:be:
41:a5:e9:33:9e:3d:ed:3c:75:08:83:9a:77:d2:59:
0e:5d:6a:24:eb:82:90:81:b8:b6:63:97:86:c0:f0:
02:31:dd:36:65:41:62:a6:94:c5:05:e6:06:e0:38:
6e:c4:02:2f:87:12:94:44:9c:05:0f:49:e9:37:1d:
5b:aa:b7:7a:a6:a6:38:08:82:20:1f:46:3a:d5:59:
c2:1f:6d:cb:d2:e2:3d:29:f1:fa:b3:6e:b4:46:b7:
c7:c8:ff:9a:fe:ce:7d:d1:75:00:72:6b:68:60:80:
93:e1:f9:4a:28:d2:a2:81:b7:32:5a:35:d1:a8:e7:
a7:de:10:28:e4:64:79:92:70:97:70:19:f4:c2:02:
15:13:36:6c:e9:fa:5c:41:10:22:4b:f6:77:c8:59:
da:5c:4d:52:32:43:42:d1:bf:bb:b0:be:46:aa:86:
45:b6:77:00:e4:83:24:b0:69:65:e7:46:d4:2a:7a:
78:a1
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Extended Key Usage:
TLS Web Server Authentication
X509v3 Key Usage:
Key Encipherment, Data Encipherment
Signature Algorithm: sha1WithRSAEncryption
Signature Value:
64:aa:e2:a4:9c:46:46:8d:30:ab:ba:8f:6a:03:4b:d3:08:25:
07:92:5d:52:35:bd:78:cf:6d:de:b0:76:1f:78:d6:dd:a8:d8:
6e:ed:6f:b4:57:14:d3:cd:9b:78:e0:28:bc:cd:20:69:b1:35:
1d:16:b8:3e:30:98:7b:80:d0:a7:52:ad:a0:27:67:7e:27:41:
8e:b5:ed:0d:fc:aa:aa:31:a3:c2:8e:8b:5d:38:91:a4:8c:d0:
fd:7a:00:6a:49:7a:62:f6:60:ea:c9:78:fe:5a:55:47:29:bf:
49:5f:70:cb:37:86:e1:d8:54:e2:d8:dd:1d:ac:80:62:bf:9a:
97:5f:bb:d2:03:10:86:e0:fd:f2:29:55:24:d2:4d:b5:fd:7b:
96:e8:64:46:82:a9:63:55:7e:62:c9:4c:8a:4b:bc:86:9f:61:
fb:f6:6d:e5:dd:39:0c:1f:8d:87:37:b4:6b:19:9e:db:96:fe:
60:0e:b9:9b:3c:79:a9:16:91:9d:57:09:a3:0c:79:cc:61:e7:
34:a7:5a:6d:bb:1d:c4:df:69:d2:2f:f3:25:30:4d:d0:2a:ae:
69:da:67:15:03:5d:8a:28:78:69:81:2d:2f:9e:3b:49:ab:e7:
87:8e:55:4c:d7:8c:ba:d3:19:4b:f9:0d:d2:d8:d4:b2:85:ed:
b8:3f:9d:0f
MAC Addresses
67:0E:55:8A:C8:12
Unknown
1489525118 | 2025-01-03T03:42:16.321353
5985 /
tcp
HTTP/1.1 404 Not Found
Content-Type: text/html; charset=us-ascii
Server: Microsoft-HTTPAPI/2.0
Date: Fri, 03 Jan 2025 03:42:14 GMT
Connection: close
Content-Length: 315
WinRM NTLM Info:
OS: Windows Server 2012 R2
OS Build: 6.3.9600
Target Name: YISU-670E558AC8
NetBIOS Domain Name: YISU-670E558AC8
NetBIOS Computer Name: YISU-670E558AC8
DNS Domain Name: yisu-670e558ac8123
FQDN: yisu-670e558ac8123