22 /
tcp
-715691503 | 2025-03-04T18:47:52.297810
SSH-2.0-OpenSSH_for_Windows_8.1
Key type: ssh-rsa
Key: AAAAB3NzaC1yc2EAAAADAQABAAABgQDRAR/vAetM3dfgtQJPqSj0c9yPTx8IheNGbs3jrBmHQczV
FJYDXcuDZqmndhAK+0faF8548uoj2vTfsf4HXXIjjaVnvl+W48ggklN1UlUcV8o8cVjDJtq0CZsX
lyVqDmjt9mObj4vF976mB4SiBlxFHiagpzywYNK8iez/4ELfsy5tmtiBTGfNjXrm3QerVwqN+v7v
B7Z4xsYbsUSywpX8Yq9ZaMaRhEvSRMYXf0sUg2Nj+LT01ki9eS8uWcjj5M/dn/iFbQryrBjz3WAA
NOmIZ71uoUiiWDxYTSlpZjll5raktpoSQMl2IqAxv9nMBgIgVRgtEee+s69KnRc+ZPjLmhhMI9rd
gkOnYLTIHQrCsdd6FV5EScxUxPCeb7fNyC00fuEi9lwsPcn9eMCCNePBQIkSmjFQ41Rz4BnzTmeo
s4lbtCZTASyr+OpbOCdhuP0ydVkmzD+8+ABCZ1ohiCOROQubgRliJzK+dHtmml6XhAaoMljwsAkO
YN4BrL+2//U=
Fingerprint: 4d:c6:a5:92:0e:c5:32:06:88:3d:af:b0:92:0c:ce:da
Kex Algorithms:
curve25519-sha256
curve25519-sha256@libssh.org
ecdh-sha2-nistp256
ecdh-sha2-nistp384
ecdh-sha2-nistp521
diffie-hellman-group-exchange-sha256
diffie-hellman-group16-sha512
diffie-hellman-group18-sha512
diffie-hellman-group14-sha256
diffie-hellman-group14-sha1
Server Host Key Algorithms:
rsa-sha2-512
rsa-sha2-256
ssh-rsa
ecdsa-sha2-nistp256
ssh-ed25519
Encryption Algorithms:
chacha20-poly1305@openssh.com
aes128-ctr
aes192-ctr
aes256-ctr
aes128-gcm@openssh.com
aes256-gcm@openssh.com
MAC Algorithms:
umac-64-etm@openssh.com
umac-128-etm@openssh.com
hmac-sha2-256-etm@openssh.com
hmac-sha2-512-etm@openssh.com
hmac-sha1-etm@openssh.com
umac-64@openssh.com
umac-128@openssh.com
hmac-sha2-256
hmac-sha2-512
hmac-sha1
Compression Algorithms:
none
zlib@openssh.com
702266688 | 2025-03-18T02:55:02.567086
HTTP/1.1 301 Moved Permanently
Content-Type: text/html; charset=UTF-8
Location: https://20.163.115.234/
Server: Microsoft-IIS/10.0
Date: Tue, 18 Mar 2025 02:55:00 GMT
Content-Length: 146
137140212 | 2025-03-21T10:26:32.093880
HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
Vary: Cookie, origin
Server: Microsoft-IIS/10.0
Set-Cookie: csrftoken=PYY3YvR3XonswVE3Wymr6MLWMDqg5E7Q; expires=Fri, 20 Mar 2026 10:26:31 GMT; Max-Age=31449600; Path=/; SameSite=Lax
X-Frame-Options: DENY
X-Content-Type-Options: nosniff
Referrer-Policy: same-origin
Cross-Origin-Opener-Policy: same-origin
X-Powered-By: ARR/3.0
Strict-Transport-Security: max-age=0
Date: Fri, 21 Mar 2025 10:26:31 GMT
Content-Length: 1848
SSL Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
03:f7:ca:26:03:1b:a7:db:a2:9e:17:68:08:ae:47:91:6c:93
Signature Algorithm: sha256WithRSAEncryption
Issuer: C=US, O=Let's Encrypt, CN=R11
Validity
Not Before: Feb 4 18:12:24 2025 GMT
Not After : May 5 18:12:23 2025 GMT
Subject: CN=azure.outpostservices.com
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:8a:1b:78:5c:1d:fe:9d:e6:eb:4d:0e:1d:03:51:
c3:50:3d:d9:39:48:86:41:fb:89:1d:6f:f6:65:df:
ec:f4:6e:d1:99:9a:7c:40:c7:df:1d:fd:35:7d:7c:
a5:bb:b2:e8:2c:b2:f4:62:e9:71:48:f7:b7:62:b1:
7d:33:d0:01:ba:ef:4d:8b:f5:3d:4e:73:24:d6:55:
90:13:53:68:ea:fd:4d:22:c0:1b:aa:8c:5c:57:c1:
68:50:96:a5:5e:c5:8e:cd:00:f8:50:97:0d:13:43:
cd:c7:e5:80:b2:cf:8b:a1:ef:06:58:fb:d8:0b:3b:
ce:b2:da:39:8f:b5:4d:00:6f:e3:55:27:10:80:c9:
49:77:d4:00:73:eb:40:53:05:8d:cf:67:b0:13:ae:
1f:43:fe:e4:73:ae:e2:04:e6:c8:b9:cc:54:23:91:
05:2d:2f:2c:1f:9b:6d:b7:25:d6:06:56:ed:c0:3b:
e4:c5:4c:50:b6:c3:73:78:18:b6:97:1b:6b:d6:25:
90:67:bd:b9:30:5e:c5:0a:cb:3b:57:b1:cc:17:a1:
78:fa:46:f6:b4:0a:7b:3d:dc:fe:c5:bf:21:be:9f:
7a:dd:8f:73:eb:6d:06:fb:92:02:d1:b5:18:9a:d4:
74:2e:00:b4:98:7e:7d:98:98:8f:d9:6f:1e:48:c4:
b7:81
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
X509v3 Extended Key Usage:
TLS Web Server Authentication, TLS Web Client Authentication
X509v3 Basic Constraints: critical
CA:FALSE
X509v3 Subject Key Identifier:
AC:F5:0E:C8:85:A2:4E:77:A1:BC:AF:60:1E:EE:1F:1F:EC:88:48:64
X509v3 Authority Key Identifier:
C5:CF:46:A4:EA:F4:C3:C0:7A:6C:95:C4:2D:B0:5E:92:2F:26:E3:B9
Authority Information Access:
OCSP - URI:http://r11.o.lencr.org
CA Issuers - URI:http://r11.i.lencr.org/
X509v3 Subject Alternative Name:
DNS:azure.outpostservices.com
X509v3 Certificate Policies:
Policy: 2.23.140.1.2.1
CT Precertificate SCTs:
Signed Certificate Timestamp:
Version : v1 (0x0)
Log ID : A2:E3:0A:E4:45:EF:BD:AD:9B:7E:38:ED:47:67:77:53:
D7:82:5B:84:94:D7:2B:5E:1B:2C:C4:B9:50:A4:47:E7
Timestamp : Feb 4 19:10:54.998 2025 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:44:02:20:29:95:FD:B8:9D:0D:D3:D2:C5:D6:D3:B4:
4D:57:E3:F8:07:D7:C8:A5:E2:BF:08:9A:BB:D6:61:04:
5F:4F:58:2D:02:20:79:CC:28:F8:E7:24:6C:F2:1D:51:
5B:0E:B2:B0:6A:ED:91:7C:79:18:43:40:CC:7A:CD:B8:
02:49:A1:3B:6E:24
Signed Certificate Timestamp:
Version : v1 (0x0)
Log ID : 7D:59:1E:12:E1:78:2A:7B:1C:61:67:7C:5E:FD:F8:D0:
87:5C:14:A0:4E:95:9E:B9:03:2F:D9:0E:8C:2E:79:B8
Timestamp : Feb 4 19:10:54.998 2025 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:45:02:20:03:5F:80:02:DE:73:54:F0:EA:D2:3C:9E:
D3:E0:85:BC:0E:50:1C:2E:14:C8:88:78:3A:CC:C8:C5:
C4:B0:27:33:02:21:00:C3:71:14:5E:97:A3:A9:97:6A:
C1:77:A1:50:DA:20:49:0C:D6:96:95:77:F2:B7:E7:FE:
01:62:E7:A4:8B:59:3B
Signature Algorithm: sha256WithRSAEncryption
Signature Value:
76:5a:5d:f4:3f:36:48:87:e1:cd:9e:1a:01:33:ba:34:35:43:
9e:6c:b7:35:d8:41:00:da:20:d9:ff:82:3b:2d:da:19:bd:aa:
11:96:e5:12:9d:db:7e:77:49:2d:6f:b2:ce:8f:6e:2c:c6:97:
70:62:14:0a:2e:5b:03:9b:f7:c9:ed:68:0f:7c:d8:17:e9:79:
6b:0c:84:da:69:b2:04:e7:7c:ae:fb:19:4b:8c:30:a6:8d:03:
1a:a1:79:64:47:03:64:d7:d1:db:dc:a7:bb:83:63:14:55:91:
89:20:1d:6c:01:41:ae:88:be:94:0a:d7:53:fb:ba:34:5e:36:
8c:dc:ae:eb:f8:a6:34:25:68:84:08:d6:4c:9f:2b:c8:6d:dc:
72:17:74:69:f0:fe:f3:6d:bb:12:d7:6f:4c:1a:3e:fb:97:6b:
c0:0f:8b:62:ab:a1:31:78:53:67:9f:5a:57:52:7b:fd:e8:d4:
da:98:f9:31:74:11:92:72:38:7d:97:be:76:7c:01:78:1b:63:
6a:77:12:db:02:6c:e9:d6:b9:64:5e:ed:21:ad:3a:e8:f4:25:
0b:98:92:b7:ed:b1:44:19:ee:50:dc:74:4e:24:60:67:a5:84:
67:92:06:e4:35:31:3c:69:af:4f:e9:87:4c:f9:ab:e1:67:b7:
26:77:91:92
3389 /
tcp
839150221 | 2025-03-21T18:59:27.670461
Remote Desktop Protocol
\x03\x00\x00\x13\x0e\xd0\x00\x00\x124\x00\x02\x0f\x08\x00\x02\x00\x00\x00
Remote Desktop Protocol NTLM Info:
OS: Windows 11 (version 21H2)
OS Build: 10.0.22000
Target Name: WinTest
NetBIOS Domain Name: WinTest
NetBIOS Computer Name: WinTest
DNS Domain Name: WinTest
FQDN: WinTest
SSL Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
2e:b4:00:86:73:ca:32:9d:4c:20:c7:b2:69:8d:f1:b3
Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=WinTest
Validity
Not Before: Feb 7 03:22:33 2025 GMT
Not After : Aug 9 03:22:33 2025 GMT
Subject: CN=WinTest
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:df:51:e6:83:c9:72:3e:b0:48:3c:a7:b9:e8:65:
74:9b:7f:6c:cc:72:fe:b7:f8:ec:67:45:fe:fd:de:
67:f3:49:93:5c:b0:fb:d4:d4:68:28:37:67:6d:81:
70:84:0c:42:7d:f8:3c:8c:43:43:07:81:8e:c1:44:
5a:90:39:e4:d9:e8:81:a2:bc:1b:b0:7c:ce:2f:1c:
44:ea:c2:56:14:5c:2e:c3:fe:e3:7e:0d:74:17:c2:
86:12:8e:d7:72:55:2b:23:2d:c6:50:79:32:70:dc:
dd:29:08:e7:67:b8:3f:8c:59:4b:38:52:b4:51:7d:
57:7c:97:da:32:4b:89:7a:dd:4e:10:aa:9d:a4:08:
a4:8d:d0:0c:17:b9:ae:68:62:a6:58:d5:66:db:70:
4f:a5:c3:60:ba:a7:c4:71:96:16:2e:73:66:e6:d7:
e5:15:c3:18:7f:3a:7a:88:ed:aa:14:63:43:58:0f:
45:e1:64:ec:8c:03:ec:ae:9d:db:cf:2d:63:96:07:
02:f3:f1:38:fe:8b:21:57:fd:90:dd:43:0d:46:cb:
24:47:b2:4f:7d:ad:70:f0:53:ad:6f:80:b7:1c:35:
06:a5:80:61:a8:78:c9:97:a4:ab:32:d2:b4:9d:b0:
a0:ef:b9:96:a5:27:9b:c7:6b:6a:01:ce:4e:57:82:
5c:7d
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Extended Key Usage:
TLS Web Server Authentication
X509v3 Key Usage:
Key Encipherment, Data Encipherment
Signature Algorithm: sha256WithRSAEncryption
Signature Value:
ca:88:d3:70:3a:17:f7:f4:fc:44:f6:cd:9b:32:02:a5:cd:37:
35:14:f7:fb:34:96:fe:12:71:13:7c:9d:59:7c:7a:82:08:14:
3b:7a:68:4a:2a:56:75:de:14:15:77:a2:df:6a:f7:68:fc:33:
58:f0:9c:47:4c:2e:21:12:87:5a:8e:0d:43:6c:3e:6a:c1:26:
09:2b:dd:7a:e3:69:c7:33:01:f8:6f:9b:54:63:d0:97:52:f4:
2c:be:6a:7d:3e:5d:e4:8b:c4:31:7e:eb:ca:dc:61:3e:13:8d:
8f:fc:0c:f9:e6:5c:03:d4:52:b5:e1:10:2c:d9:64:ac:9c:e5:
22:15:5a:dc:c8:01:50:e7:59:33:80:6d:3c:86:a0:bf:04:1f:
a1:70:26:f2:22:38:9f:93:dc:9f:3f:f2:a6:e1:0a:2b:77:c5:
b6:46:ad:3a:28:6c:b4:4f:13:82:7d:2c:dc:ce:99:a5:93:a4:
7d:3b:16:37:42:98:ed:11:92:d0:71:0f:58:3f:47:c6:67:71:
9e:65:96:b9:94:30:40:2c:c9:2e:8a:a7:43:98:bf:5d:15:54:
1e:60:88:cd:b4:b1:3d:d9:c8:c0:e6:1c:01:ef:a0:4c:35:5e:
38:7a:12:6f:da:da:bd:54:8d:bd:d7:2b:13:5c:8c:78:b7:5c:
ea:a8:28:3d
-1641237991 | 2025-03-16T04:04:18.782348
HTTP/1.1 302 Found
Date: Sun, 16 Mar 2025 04:04:18 GMT
Server: WSGIServer/0.2 CPython/3.12.5
Content-Type: text/html; charset=utf-8
Location: /updatefe/
X-Frame-Options: DENY
Content-Length: 0
X-Content-Type-Options: nosniff
Referrer-Policy: same-origin
Cross-Origin-Opener-Policy: same-origin
Vary: origin