12367564 | 2024-12-21T23:14:22.124227
135 /
tcp
Microsoft RPC Endpoint Mapper
d95afe70-a6d5-4259-822e-2c84da1ddb0d
version: v1.0
protocol: [MS-RSP]: Remote Shutdown Protocol
provider: wininit.exe
ncacn_ip_tcp: 177.21.96.4:1025
ncalrpc: WindowsShutdown
ncacn_np: \\ACA-BCKSRV01\PIPE\InitShutdown
ncalrpc: WMsgKRpc062F70
76f226c3-ec14-4325-8a99-6a46348418af
version: v1.0
provider: winlogon.exe
ncalrpc: WindowsShutdown
ncacn_np: \\ACA-BCKSRV01\PIPE\InitShutdown
ncalrpc: WMsgKRpc062F70
ncalrpc: WMsgKRpc063191
c9ac6db5-82b7-4e55-ae8a-e464ed7b4277
version: v1.0
annotation: Impl friendly name
provider: sysntfy.dll
ncalrpc: LRPC-f4a825a35ba16157aa
ncacn_np: \\ACA-BCKSRV01\PIPE\srvsvc
ncacn_ip_tcp: 177.21.96.4:1027
ncacn_np: \\ACA-BCKSRV01\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEB169D4819EB648DF8AED1DEC2156
ncalrpc: IUserProfile2
ncalrpc: senssvc
ncalrpc: OLEB169D4819EB648DF8AED1DEC2156
ncalrpc: IUserProfile2
ncalrpc: IUserProfile2
ncalrpc: IUserProfile2
3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5
version: v1.0
annotation: DHCP Client LRPC Endpoint
provider: dhcpcsvc.dll
ncalrpc: dhcpcsvc
ncalrpc: dhcpcsvc6
ncacn_ip_tcp: 177.21.96.4:1026
ncacn_np: \\ACA-BCKSRV01\pipe\eventlog
ncalrpc: eventlog
3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6
version: v1.0
annotation: DHCPv6 Client LRPC Endpoint
provider: dhcpcsvc6.dll
ncalrpc: dhcpcsvc6
ncacn_ip_tcp: 177.21.96.4:1026
ncacn_np: \\ACA-BCKSRV01\pipe\eventlog
ncalrpc: eventlog
30adc50c-5cbc-46ce-9a0e-91914789e23c
version: v1.0
annotation: NRP server endpoint
provider: nrpsrv.dll
ncacn_ip_tcp: 177.21.96.4:1026
ncacn_np: \\ACA-BCKSRV01\pipe\eventlog
ncalrpc: eventlog
f6beaff7-1e19-4fbb-9f8f-b89e2018337c
version: v1.0
annotation: Event log TCPIP
protocol: [MS-EVEN6]: EventLog Remoting Protocol
provider: wevtsvc.dll
ncacn_ip_tcp: 177.21.96.4:1026
ncacn_np: \\ACA-BCKSRV01\pipe\eventlog
ncalrpc: eventlog
8c7daf44-b6dc-11d1-9a4c-0020af6e7c57
version: v1.0
provider: appmgmts.dll
ncalrpc: RemoteAccessLrpc
ncalrpc: VpnikeRpc
ncalrpc: RasmanLrpc
ncacn_np: \\ACA-BCKSRV01\PIPE\ROUTER
ncacn_np: \\ACA-BCKSRV01\PIPE\srvsvc
ncacn_ip_tcp: 177.21.96.4:1027
ncacn_np: \\ACA-BCKSRV01\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEB169D4819EB648DF8AED1DEC2156
ncalrpc: IUserProfile2
30b044a5-a225-43f0-b3a4-e060df91f9c1
version: v1.0
provider: certprop.dll
ncacn_np: \\ACA-BCKSRV01\PIPE\srvsvc
ncacn_ip_tcp: 177.21.96.4:1027
ncacn_np: \\ACA-BCKSRV01\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEB169D4819EB648DF8AED1DEC2156
ncalrpc: IUserProfile2
98716d03-89ac-44c7-bb8c-285824e51c4a
version: v1.0
annotation: XactSrv service
provider: srvsvc.dll
ncacn_ip_tcp: 177.21.96.4:1027
ncacn_np: \\ACA-BCKSRV01\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEB169D4819EB648DF8AED1DEC2156
ncalrpc: IUserProfile2
552d076a-cb29-4e44-8b6a-d15e59e2c0af
version: v1.0
annotation: IP Transition Configuration endpoint
provider: iphlpsvc.dll
ncacn_ip_tcp: 177.21.96.4:1027
ncacn_np: \\ACA-BCKSRV01\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEB169D4819EB648DF8AED1DEC2156
ncalrpc: IUserProfile2
a398e520-d59a-4bdd-aa7a-3c1e0303a511
version: v1.0
annotation: IKE/Authip API
provider: IKEEXT.DLL
ncacn_ip_tcp: 177.21.96.4:1027
ncacn_np: \\ACA-BCKSRV01\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEB169D4819EB648DF8AED1DEC2156
ncalrpc: IUserProfile2
86d35949-83c9-4044-b424-db363231fd0c
version: v1.0
protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol
provider: schedsvc.dll
ncacn_ip_tcp: 177.21.96.4:1027
ncacn_np: \\ACA-BCKSRV01\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEB169D4819EB648DF8AED1DEC2156
ncalrpc: IUserProfile2
378e52b0-c0a9-11cf-822d-00aa0051e40f
version: v1.0
protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol
provider: taskcomp.dll
ncacn_np: \\ACA-BCKSRV01\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEB169D4819EB648DF8AED1DEC2156
ncalrpc: IUserProfile2
1ff70682-0a51-30e8-076d-740be8cee98b
version: v1.0
protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol
provider: taskcomp.dll
ncacn_np: \\ACA-BCKSRV01\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEB169D4819EB648DF8AED1DEC2156
ncalrpc: IUserProfile2
0a74ef1c-41a4-4e06-83ae-dc74fb1cdd53
version: v1.0
provider: schedsvc.dll
ncalrpc: senssvc
ncalrpc: OLEB169D4819EB648DF8AED1DEC2156
ncalrpc: IUserProfile2
2eb08e3e-639f-4fba-97b1-14f878961076
version: v1.0
provider: gpsvc.dll
ncalrpc: IUserProfile2
3473dd4d-2e88-4006-9cba-22570909dd10
version: v5.256
annotation: WinHttp Auto-Proxy Service
ncacn_np: \\ACA-BCKSRV01\PIPE\W32TIME_ALT
ncalrpc: W32TIME_ALT
ncalrpc: LRPC-67b60cc7c6dc9dac7b
ncalrpc: OLE069D5E97CF67449B9409833C81F9
7ea70bcf-48af-4f6a-8968-6a440754d5fa
version: v1.0
annotation: NSI server endpoint
provider: nsisvc.dll
ncalrpc: LRPC-67b60cc7c6dc9dac7b
ncalrpc: OLE069D5E97CF67449B9409833C81F9
2fb92682-6599-42dc-ae13-bd2ca89bd11c
version: v1.0
annotation: Fw APIs
provider: MPSSVC.dll
ncalrpc: LRPC-bcbe784df15e198da7
7f9d11bf-7fb9-436b-a812-b2d50c5d4c03
version: v1.0
annotation: Fw APIs
provider: MPSSVC.dll
ncalrpc: LRPC-bcbe784df15e198da7
dd490425-5325-4565-b774-7e27d6c09c24
version: v1.0
annotation: Base Firewall Engine API
provider: BFE.DLL
ncalrpc: LRPC-bcbe784df15e198da7
7f1343fe-50a9-4927-a778-0c5859517bac
version: v1.0
annotation: DfsDs service
ncacn_np: \\ACA-BCKSRV01\PIPE\wkssvc
ncalrpc: DNSResolver
24019106-a203-4642-b88d-82dae9158929
version: v1.0
provider: authui.dll
ncalrpc: LRPC-64b6c6bf8abe6dc757
12345778-1234-abcd-ef00-0123456789ac
version: v1.0
protocol: [MS-SAMR]: Security Account Manager (SAM) Remote Protocol
provider: samsrv.dll
ncacn_ip_tcp: 177.21.96.4:1028
ncalrpc: efslrpc
ncacn_np: \\ACA-BCKSRV01\pipe\efsrpc
ncalrpc: samss lpc
ncalrpc: dsrole
ncacn_np: \\ACA-BCKSRV01\PIPE\protected_storage
ncalrpc: protected_storage
ncalrpc: lsasspirpc
ncalrpc: lsapolicylookup
ncalrpc: LSARPC_ENDPOINT
ncalrpc: securityevent
ncalrpc: audit
ncalrpc: LRPC-308c32788ea94141ac
ncacn_np: \\ACA-BCKSRV01\pipe\lsass
367abb81-9844-35f1-ad32-98f038001003
version: v2.0
protocol: [MS-SCMR]: Service Control Manager Remote Protocol
provider: services.exe
ncacn_ip_tcp: 177.21.96.4:1030
12345678-1234-abcd-ef00-0123456789ab
version: v1.0
annotation: IPSec Policy agent endpoint
protocol: [MS-RPRN]: Print System Remote Protocol
provider: spoolsv.exe
ncalrpc: LRPC-e44fd7873f0c7e5c18
906b0ce0-c70b-1067-b317-00dd010662da
version: v1.0
protocol: [MS-CMPO]: MSDTC Connection Manager:
provider: msdtcprx.dll
ncalrpc: LRPC-07fe8a838fb59531de
ncalrpc: LRPC-07fe8a838fb59531de
ncalrpc: LRPC-07fe8a838fb59531de
ncalrpc: LRPC-07fe8a838fb59531de
2f5f6521-cb55-1059-b446-00df0bce31db
version: v1.0
annotation: Unimodem LRPC Endpoint
ncalrpc: unimdmsvc
ncalrpc: tapsrvlpc
ncacn_np: \\ACA-BCKSRV01\pipe\tapsrv
1641389631 | 2024-12-30T22:01:06.037255
445 /
tcp
SMB Status:
Authentication: enabled
SMB Version: 1
OS: Windows Server 2008 R2 Standard 7601 Service Pack 1
Software: Windows Server 2008 R2 Standard 6.1
Capabilities: extended-security, infolevel-passthru, large-files, large-readx, large-writex, level2-oplocks, lock-and-read, lwio, nt-find, nt-smb, nt-status, rpc-remote-api, unicode
1178934707 | 2025-01-07T14:39:23.309299
3389 /
tcp
Remote Desktop Protocol
\x03\x00\x00\x13\x0e\xd0\x00\x00\x124\x00\x02\t\x08\x00\x02\x00\x00\x00
Remote Desktop Protocol NTLM Info:
OS: Windows 7/Windows Server 2008 R2
OS Build: 6.1.7601
Target Name: ACA-BCKSRV01
NetBIOS Domain Name: ACA-BCKSRV01
NetBIOS Computer Name: ACA-BCKSRV01
DNS Domain Name: ACA-BCKSRV01
FQDN: ACA-BCKSRV01
SSL Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
48:16:d9:cf:67:e3:be:80:42:e6:4f:2e:9b:89:da:16
Signature Algorithm: sha1WithRSAEncryption
Issuer: CN=ACA-BCKSRV01
Validity
Not Before: Oct 3 16:00:06 2024 GMT
Not After : Apr 4 16:00:06 2025 GMT
Subject: CN=ACA-BCKSRV01
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:f8:26:99:d8:c6:8c:67:e6:9f:d8:a5:92:a6:43:
c9:b0:cd:97:d2:30:81:d7:a9:18:ec:db:b8:b4:07:
68:1c:ad:2f:41:b8:c0:c8:73:4d:a1:01:28:61:3b:
20:74:a0:4d:18:12:19:7b:3a:10:70:16:ce:bd:2e:
24:9e:c3:4f:56:55:7a:73:45:d9:76:b4:2e:63:1a:
0f:15:07:93:96:aa:78:16:12:13:2b:38:9b:d2:cd:
6d:1d:f7:17:42:d5:6b:bc:20:b7:67:0d:6d:30:a9:
e6:12:e0:c8:11:58:ab:aa:fb:bd:f9:8c:e3:5e:c3:
73:e2:69:fd:9e:9e:18:9b:09:56:03:6d:a5:9d:02:
65:0c:89:5a:1f:67:d4:06:ad:c1:29:37:7f:ba:c9:
4a:0f:c1:13:ac:90:fc:73:0f:e4:e2:64:02:5d:c5:
41:fe:af:4f:3c:c3:46:18:8d:2e:c5:4c:7c:2c:39:
46:1a:8d:08:c7:c0:62:c0:85:f4:bf:98:2d:b1:6a:
90:0b:90:35:36:42:83:83:0e:7d:47:2c:c1:5c:59:
27:2b:c6:fa:42:9f:29:e7:a5:bf:9d:51:16:11:ed:
b0:2f:8e:44:f9:ee:71:a2:dc:90:11:0a:ac:76:47:
c9:8b:1d:47:2a:c3:94:60:9a:1b:99:35:bf:bb:06:
de:49
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Extended Key Usage:
TLS Web Server Authentication
X509v3 Key Usage:
Key Encipherment, Data Encipherment
Signature Algorithm: sha1WithRSAEncryption
Signature Value:
e0:ea:8f:59:4b:26:52:6d:f5:7f:e9:0a:85:be:ad:54:59:9e:
10:fb:8f:e3:9d:51:bb:08:d1:d3:f8:91:42:6f:b7:29:30:da:
d1:77:06:4d:6e:b1:b9:47:9c:3f:69:1f:b7:cc:af:0a:87:b5:
57:6f:f1:67:cc:b8:08:9c:e2:79:88:34:cc:09:73:11:72:aa:
fe:44:1f:af:15:5e:9e:ad:1d:b3:7b:cc:18:bf:dc:f4:6e:c0:
35:56:1b:23:cf:77:66:c5:a7:d6:e5:bf:0e:16:94:5b:8f:34:
3b:b2:62:b9:3a:d1:a6:a8:a7:ff:5f:e3:3c:d9:b4:10:25:34:
43:6c:6d:66:cb:44:76:46:ae:7d:0a:66:37:4c:87:6e:22:e5:
8b:53:d1:bc:b6:83:13:de:52:1c:ae:ad:1c:52:60:25:de:83:
24:76:f9:59:fb:98:82:0d:76:bc:39:c6:76:4b:54:0c:83:3a:
6a:ed:e5:0c:6b:f1:8f:3c:31:cd:de:94:52:14:5e:18:78:93:
12:61:29:97:23:a5:ea:df:d6:79:44:f5:28:76:89:d9:b5:82:
39:86:ef:fd:32:df:28:1a:17:a8:5e:55:5d:98:c0:db:50:69:
5e:70:76:c5:b0:9e:9a:b6:c9:89:b2:29:b6:f7:9a:54:17:c3:
2d:2a:05:69