1138219898 | 2024-12-29T03:41:20.950939
80 /
tcp
HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Wed, 20 Sep 2023 14:42:10 GMT
Accept-Ranges: bytes
ETag: "69cb5a3d0ebd91:0"
Server: Microsoft-IIS/8.5
X-Powered-By: ASP.NET
Date: Sun, 29 Dec 2024 03:41:20 GMT
Content-Length: 701
-1137714825 | 2024-12-08T00:07:04.784413
135 /
tcp
Microsoft RPC Endpoint Mapper
d95afe70-a6d5-4259-822e-2c84da1ddb0d
version: v1.0
protocol: [MS-RSP]: Remote Shutdown Protocol
provider: wininit.exe
ncacn_ip_tcp: 210.211.101.84:49152
ncalrpc: WindowsShutdown
ncacn_np: \\WIN-8M679OO1T5G\PIPE\InitShutdown
ncalrpc: WMsgKRpc069BE0
76f226c3-ec14-4325-8a99-6a46348418af
version: v1.0
provider: winlogon.exe
ncalrpc: WindowsShutdown
ncacn_np: \\WIN-8M679OO1T5G\PIPE\InitShutdown
ncalrpc: WMsgKRpc069BE0
ncalrpc: WMsgKRpc06C541
ncalrpc: WMsgKRpc09D7F62
9b008953-f195-4bf9-bde0-4471971e58ed
version: v1.0
ncalrpc: LRPC-0a6c75a2910e7b5067
ncacn_np: \\WIN-8M679OO1T5G\pipe\LSM_API_service
ncalrpc: LSMApi
ncalrpc: LRPC-f81711c8fb849cd8ac
ncalrpc: actkernel
ncalrpc: umpo
697dcda9-3ba9-4eb2-9247-e11f1901b0d2
version: v1.0
ncalrpc: LRPC-0a6c75a2910e7b5067
ncacn_np: \\WIN-8M679OO1T5G\pipe\LSM_API_service
ncalrpc: LSMApi
ncalrpc: LRPC-f81711c8fb849cd8ac
ncalrpc: actkernel
ncalrpc: umpo
c9ac6db5-82b7-4e55-ae8a-e464ed7b4277
version: v1.0
annotation: Impl friendly name
provider: sysntfy.dll
ncalrpc: LRPC-f81711c8fb849cd8ac
ncalrpc: actkernel
ncalrpc: umpo
ncacn_np: \\WIN-8M679OO1T5G\PIPE\srvsvc
ncacn_ip_tcp: 210.211.101.84:49154
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\WIN-8M679OO1T5G\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLE3D32E7A9ED0EE605292CF0AC26F6
ncalrpc: IUserProfile2
ncalrpc: senssvc
ncalrpc: OLE3D32E7A9ED0EE605292CF0AC26F6
ncalrpc: IUserProfile2
ncalrpc: OLE3D32E7A9ED0EE605292CF0AC26F6
ncalrpc: IUserProfile2
ncalrpc: IUserProfile2
0d3e2735-cea0-4ecc-a9e2-41a2d81aed4e
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
c605f9fb-f0a3-4e2a-a073-73560f8d9e3e
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
1b37ca91-76b1-4f5e-a3c7-2abfc61f2bb0
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
8bfc3be1-6def-4e2d-af74-7c47cd0ade4a
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
2d98a740-581d-41b9-aa0d-a88b9d5ce938
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
bdaa0970-413b-4a3e-9e5d-f6dc9d7e0760
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
3b338d89-6cfa-44b8-847e-531531bc9992
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
8782d3b9-ebbd-4644-a3d8-e8725381919b
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
085b0334-e454-4d91-9b8c-4134f9e793f3
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
4bec6bb8-b5c2-4b6f-b2c1-5da5cf92d0d9
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6
version: v1.0
annotation: DHCPv6 Client LRPC Endpoint
provider: dhcpcsvc6.dll
ncalrpc: dhcpcsvc6
ncalrpc: dhcpcsvc
ncalrpc: LRPC-53ce5538bb6915d266
ncacn_ip_tcp: 210.211.101.84:49153
ncacn_np: \\WIN-8M679OO1T5G\pipe\eventlog
ncalrpc: eventlog
abfb6ca3-0c5e-4734-9285-0aee72fe8d1c
version: v1.0
annotation: Wcm Service
ncalrpc: LRPC-53ce5538bb6915d266
ncacn_ip_tcp: 210.211.101.84:49153
ncacn_np: \\WIN-8M679OO1T5G\pipe\eventlog
ncalrpc: eventlog
3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5
version: v1.0
annotation: DHCP Client LRPC Endpoint
provider: dhcpcsvc.dll
ncalrpc: dhcpcsvc
ncalrpc: LRPC-53ce5538bb6915d266
ncacn_ip_tcp: 210.211.101.84:49153
ncacn_np: \\WIN-8M679OO1T5G\pipe\eventlog
ncalrpc: eventlog
30adc50c-5cbc-46ce-9a0e-91914789e23c
version: v1.0
annotation: NRP server endpoint
provider: nrpsrv.dll
ncalrpc: LRPC-53ce5538bb6915d266
ncacn_ip_tcp: 210.211.101.84:49153
ncacn_np: \\WIN-8M679OO1T5G\pipe\eventlog
ncalrpc: eventlog
f6beaff7-1e19-4fbb-9f8f-b89e2018337c
version: v1.0
annotation: Event log TCPIP
protocol: [MS-EVEN6]: EventLog Remoting Protocol
provider: wevtsvc.dll
ncacn_ip_tcp: 210.211.101.84:49153
ncacn_np: \\WIN-8M679OO1T5G\pipe\eventlog
ncalrpc: eventlog
30b044a5-a225-43f0-b3a4-e060df91f9c1
version: v1.0
provider: certprop.dll
ncalrpc: LRPC-00c54ec94430b3cc38
ncacn_np: \\WIN-8M679OO1T5G\PIPE\srvsvc
ncacn_ip_tcp: 210.211.101.84:49154
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\WIN-8M679OO1T5G\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLE3D32E7A9ED0EE605292CF0AC26F6
ncalrpc: IUserProfile2
1a0d010f-1c33-432c-b0f5-8cf4e8053099
version: v1.0
annotation: IdSegSrv service
ncacn_ip_tcp: 210.211.101.84:49154
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\WIN-8M679OO1T5G\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLE3D32E7A9ED0EE605292CF0AC26F6
ncalrpc: IUserProfile2
98716d03-89ac-44c7-bb8c-285824e51c4a
version: v1.0
annotation: XactSrv service
provider: srvsvc.dll
ncacn_ip_tcp: 210.211.101.84:49154
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\WIN-8M679OO1T5G\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLE3D32E7A9ED0EE605292CF0AC26F6
ncalrpc: IUserProfile2
c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1
version: v1.0
annotation: Adh APIs
ncacn_ip_tcp: 210.211.101.84:49154
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\WIN-8M679OO1T5G\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLE3D32E7A9ED0EE605292CF0AC26F6
ncalrpc: IUserProfile2
c36be077-e14b-4fe9-8abc-e856ef4f048b
version: v1.0
annotation: Proxy Manager client server endpoint
ncacn_ip_tcp: 210.211.101.84:49154
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\WIN-8M679OO1T5G\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLE3D32E7A9ED0EE605292CF0AC26F6
ncalrpc: IUserProfile2
2e6035b2-e8f1-41a7-a044-656b439c4c34
version: v1.0
annotation: Proxy Manager provider server endpoint
ncacn_ip_tcp: 210.211.101.84:49154
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\WIN-8M679OO1T5G\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLE3D32E7A9ED0EE605292CF0AC26F6
ncalrpc: IUserProfile2
552d076a-cb29-4e44-8b6a-d15e59e2c0af
version: v1.0
annotation: IP Transition Configuration endpoint
provider: iphlpsvc.dll
ncacn_ip_tcp: 210.211.101.84:49154
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\WIN-8M679OO1T5G\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLE3D32E7A9ED0EE605292CF0AC26F6
ncalrpc: IUserProfile2
a398e520-d59a-4bdd-aa7a-3c1e0303a511
version: v1.0
annotation: IKE/Authip API
provider: IKEEXT.DLL
ncacn_ip_tcp: 210.211.101.84:49154
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\WIN-8M679OO1T5G\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLE3D32E7A9ED0EE605292CF0AC26F6
ncalrpc: IUserProfile2
3a9ef155-691d-4449-8d05-09ad57031823
version: v1.0
ncacn_ip_tcp: 210.211.101.84:49154
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\WIN-8M679OO1T5G\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLE3D32E7A9ED0EE605292CF0AC26F6
ncalrpc: IUserProfile2
86d35949-83c9-4044-b424-db363231fd0c
version: v1.0
protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol
provider: schedsvc.dll
ncacn_ip_tcp: 210.211.101.84:49154
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\WIN-8M679OO1T5G\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLE3D32E7A9ED0EE605292CF0AC26F6
ncalrpc: IUserProfile2
378e52b0-c0a9-11cf-822d-00aa0051e40f
version: v1.0
protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol
provider: taskcomp.dll
ncacn_np: \\WIN-8M679OO1T5G\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLE3D32E7A9ED0EE605292CF0AC26F6
ncalrpc: IUserProfile2
1ff70682-0a51-30e8-076d-740be8cee98b
version: v1.0
protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol
provider: taskcomp.dll
ncacn_np: \\WIN-8M679OO1T5G\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLE3D32E7A9ED0EE605292CF0AC26F6
ncalrpc: IUserProfile2
0a74ef1c-41a4-4e06-83ae-dc74fb1cdd53
version: v1.0
provider: schedsvc.dll
ncalrpc: senssvc
ncalrpc: OLE3D32E7A9ED0EE605292CF0AC26F6
ncalrpc: IUserProfile2
2eb08e3e-639f-4fba-97b1-14f878961076
version: v1.0
annotation: Group Policy RPC Interface
provider: gpsvc.dll
ncalrpc: LRPC-6d575c21007f8d3660
3473dd4d-2e88-4006-9cba-22570909dd10
version: v5.256
annotation: WinHttp Auto-Proxy Service
ncacn_np: \\WIN-8M679OO1T5G\PIPE\W32TIME_ALT
ncalrpc: W32TIME_ALT
ncalrpc: LRPC-b09530398636c42cd6
ncalrpc: OLE5D9E334BB1A61B5F51BD064D30D2
7ea70bcf-48af-4f6a-8968-6a440754d5fa
version: v1.0
annotation: NSI server endpoint
provider: nsisvc.dll
ncalrpc: LRPC-b09530398636c42cd6
ncalrpc: OLE5D9E334BB1A61B5F51BD064D30D2
b2507c30-b126-494a-92ac-ee32b6eeb039
version: v1.0
ncalrpc: LRPC-f54e83c648de395021
b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86
version: v2.0
annotation: KeyIso
ncacn_ip_tcp: 210.211.101.84:49155
ncalrpc: samss lpc
ncalrpc: SidKey Local End Point
ncalrpc: protected_storage
ncalrpc: lsasspirpc
ncalrpc: lsapolicylookup
ncalrpc: LSA_EAS_ENDPOINT
ncalrpc: lsacap
ncalrpc: LSARPC_ENDPOINT
ncalrpc: securityevent
ncalrpc: audit
ncacn_np: \\WIN-8M679OO1T5G\pipe\lsass
12345778-1234-abcd-ef00-0123456789ac
version: v1.0
protocol: [MS-SAMR]: Security Account Manager (SAM) Remote Protocol
provider: samsrv.dll
ncacn_ip_tcp: 210.211.101.84:49155
ncalrpc: samss lpc
ncalrpc: SidKey Local End Point
ncalrpc: protected_storage
ncalrpc: lsasspirpc
ncalrpc: lsapolicylookup
ncalrpc: LSA_EAS_ENDPOINT
ncalrpc: lsacap
ncalrpc: LSARPC_ENDPOINT
ncalrpc: securityevent
ncalrpc: audit
ncacn_np: \\WIN-8M679OO1T5G\pipe\lsass
2fb92682-6599-42dc-ae13-bd2ca89bd11c
version: v1.0
annotation: Fw APIs
provider: MPSSVC.dll
ncalrpc: LRPC-50a2cbdf7d3303456c
ncalrpc: LRPC-1c2e77c4c46ffbf4c3
f47433c3-3e9d-4157-aad4-83aa1f5c2d4c
version: v1.0
annotation: Fw APIs
ncalrpc: LRPC-50a2cbdf7d3303456c
ncalrpc: LRPC-1c2e77c4c46ffbf4c3
7f9d11bf-7fb9-436b-a812-b2d50c5d4c03
version: v1.0
annotation: Fw APIs
provider: MPSSVC.dll
ncalrpc: LRPC-50a2cbdf7d3303456c
ncalrpc: LRPC-1c2e77c4c46ffbf4c3
dd490425-5325-4565-b774-7e27d6c09c24
version: v1.0
annotation: Base Firewall Engine API
provider: BFE.DLL
ncalrpc: LRPC-1c2e77c4c46ffbf4c3
7f1343fe-50a9-4927-a778-0c5859517bac
version: v1.0
annotation: DfsDs service
ncacn_np: \\WIN-8M679OO1T5G\PIPE\wkssvc
ncalrpc: LRPC-4dc9fc6cb4a305bfc3
ncalrpc: DNSResolver
eb081a0d-10ee-478a-a1dd-50995283e7a8
version: v3.0
annotation: Witness Client Test Interface
ncalrpc: LRPC-4dc9fc6cb4a305bfc3
ncalrpc: DNSResolver
f2c9b409-c1c9-4100-8639-d8ab1486694a
version: v1.0
annotation: Witness Client Upcall Server
ncalrpc: LRPC-4dc9fc6cb4a305bfc3
ncalrpc: DNSResolver
76f03f96-cdfd-44fc-a22c-64950a001209
version: v1.0
protocol: [MS-PAR]: Print System Asynchronous Remote Protocol
provider: spoolsv.exe
ncacn_ip_tcp: 210.211.101.84:49156
ncalrpc: LRPC-231fd46c3612324226
4a452661-8290-4b36-8fbe-7f4093a94978
version: v1.0
provider: spoolsv.exe
ncacn_ip_tcp: 210.211.101.84:49156
ncalrpc: LRPC-231fd46c3612324226
ae33069b-a2a8-46ee-a235-ddfd339be281
version: v1.0
protocol: [MS-PAN]: Print System Asynchronous Notification Protocol
provider: spoolsv.exe
ncacn_ip_tcp: 210.211.101.84:49156
ncalrpc: LRPC-231fd46c3612324226
0b6edbfa-4a24-4fc6-8a23-942b1eca65d1
version: v1.0
protocol: [MS-PAN]: Print System Asynchronous Notification Protocol
provider: spoolsv.exe
ncacn_ip_tcp: 210.211.101.84:49156
ncalrpc: LRPC-231fd46c3612324226
12345678-1234-abcd-ef00-0123456789ab
version: v1.0
protocol: [MS-RPRN]: Print System Remote Protocol
provider: spoolsv.exe
ncacn_ip_tcp: 210.211.101.84:49156
ncalrpc: LRPC-231fd46c3612324226
76209fe5-9049-4336-ba84-632d907cb154
version: v1.0
annotation: Interprocess Logon Service
ncalrpc: ReportingServices$MSRS13.MSSQL201684
ncalrpc: OLE4446799A64CE42E36881133B4068
367abb81-9844-35f1-ad32-98f038001003
version: v2.0
protocol: [MS-SCMR]: Service Control Manager Remote Protocol
provider: services.exe
ncacn_ip_tcp: 210.211.101.84:49162
6b5bdd1e-528c-422c-af8c-a4079be4fe48
version: v1.0
annotation: Remote Fw APIs
protocol: [MS-FASP]: Firewall and Advanced Security Protocol
provider: FwRemoteSvr.dll
ncacn_ip_tcp: 210.211.101.84:49163
12e65dd8-887f-41ef-91bf-8d816c42c2e7
version: v1.0
annotation: Secure Desktop LRPC interface
provider: winlogon.exe
ncalrpc: WMsgKRpc09D7F62
906b0ce0-c70b-1067-b317-00dd010662da
version: v1.0
protocol: [MS-CMPO]: MSDTC Connection Manager:
provider: msdtcprx.dll
ncalrpc: LRPC-f88e808ea58e823fef
ncalrpc: LRPC-f88e808ea58e823fef
ncalrpc: LRPC-f88e808ea58e823fef
1327386965 | 2024-12-03T13:19:28.976268
137 /
udp
NetBIOS Response:
Server Name: WIN-8M679OO1T5G
MAC Address: E8:39:35:ED:83:B6
Names:
WIN-8M679OO1T5G <0x0>
WORKGROUP <0x0>
WIN-8M679OO1T5G <0x20>
MAC Addresses
E8:39:35:ED:83:B6
OUI: E8:39:35
Organization: Hewlett Packard
Assignment: MA-L
Registration Date: 2011-10-06
1489525118 | 2024-12-29T09:41:51.880732
443 /
tcp
HTTP/1.1 404 Not Found
Content-Type: text/html; charset=us-ascii
Server: Microsoft-HTTPAPI/2.0
Date: Sun, 29 Dec 2024 09:41:50 GMT
Connection: close
Content-Length: 315
SSL Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
b0:ea:7e:63:8e:40:d4:5a:63:ed:ed:15:8a:13:85:02
Signature Algorithm: sha256WithRSAEncryption
Issuer: C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Domain Validation Secure Server CA
Validity
Not Before: Jan 4 00:00:00 2024 GMT
Not After : Feb 3 23:59:59 2025 GMT
Subject: CN=*.bkholding.vn
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:a0:be:d5:b1:33:e8:0d:7a:63:c6:75:09:4e:33:
91:93:4b:49:46:4f:cb:be:69:08:0e:9b:5d:b6:c0:
fe:1e:d3:bd:86:1c:cf:a3:4c:01:64:53:bc:cc:86:
28:0b:08:41:1f:48:a0:24:cb:9c:3f:06:8e:eb:e7:
e0:8a:33:05:b0:d3:ee:87:15:83:6e:da:93:43:e6:
9a:29:03:44:31:55:cd:40:e8:28:0d:82:1d:61:20:
99:1a:48:e8:50:8e:80:3d:56:35:69:86:0f:97:54:
6f:70:1c:64:c3:5f:d6:33:9a:73:0c:3e:d0:4b:a4:
0b:66:1c:49:44:11:b9:df:69:bf:d4:56:0d:8c:a7:
cd:df:7e:24:e3:aa:cb:57:72:c7:8a:d9:5d:36:2f:
da:51:b9:30:f4:7a:8b:1d:3f:80:e2:73:33:25:cf:
6c:92:1f:2c:b7:56:77:7e:d1:c4:ab:56:42:14:a0:
52:99:94:78:7e:ce:99:09:91:7c:cd:85:94:87:76:
7a:c9:0d:5e:17:9d:41:85:93:5c:7d:c3:25:88:ca:
e7:0b:0f:be:6d:5a:91:75:c6:c2:07:d4:18:35:42:
67:c5:ea:03:97:a1:7b:e8:58:de:03:c2:cf:99:15:
68:2c:a6:44:5c:f5:5f:15:45:ef:58:9e:3b:f5:2f:
11:91
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Authority Key Identifier:
8D:8C:5E:C4:54:AD:8A:E1:77:E9:9B:F9:9B:05:E1:B8:01:8D:61:E1
X509v3 Subject Key Identifier:
23:AC:CC:F1:00:B1:9C:AC:16:37:89:8F:B8:2B:43:B4:0F:13:70:95
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
X509v3 Basic Constraints: critical
CA:FALSE
X509v3 Extended Key Usage:
TLS Web Server Authentication, TLS Web Client Authentication
X509v3 Certificate Policies:
Policy: 1.3.6.1.4.1.6449.1.2.2.7
CPS: https://sectigo.com/CPS
Policy: 2.23.140.1.2.1
Authority Information Access:
CA Issuers - URI:http://crt.sectigo.com/SectigoRSADomainValidationSecureServerCA.crt
OCSP - URI:http://ocsp.sectigo.com
X509v3 Subject Alternative Name:
DNS:*.bkholding.vn, DNS:bkholding.vn
CT Precertificate SCTs:
Signed Certificate Timestamp:
Version : v1 (0x0)
Log ID : CF:11:56:EE:D5:2E:7C:AF:F3:87:5B:D9:69:2E:9B:E9:
1A:71:67:4A:B0:17:EC:AC:01:D2:5B:77:CE:CC:3B:08
Timestamp : Jan 4 03:37:44.861 2024 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:45:02:20:76:24:D3:1D:3F:0B:87:01:12:E0:A4:23:
46:E6:6E:C8:F3:97:AF:93:C1:E3:60:1C:A0:95:5A:2B:
39:00:86:5A:02:21:00:95:77:22:22:2E:36:0B:8A:3B:
B1:D5:0B:A4:F5:2B:3D:E3:BE:5E:C5:72:FD:E1:A3:3C:
09:24:55:16:EB:D6:86
Signed Certificate Timestamp:
Version : v1 (0x0)
Log ID : A2:E3:0A:E4:45:EF:BD:AD:9B:7E:38:ED:47:67:77:53:
D7:82:5B:84:94:D7:2B:5E:1B:2C:C4:B9:50:A4:47:E7
Timestamp : Jan 4 03:37:44.818 2024 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:46:02:21:00:80:76:60:49:AC:66:40:4F:EE:CC:A0:
36:5A:ED:EC:8F:71:7A:B7:BB:5B:0F:E3:24:1A:CE:4D:
AA:18:4C:F3:06:02:21:00:EF:F0:F6:6C:0F:98:B8:D0:
3A:D8:4A:39:F1:FA:82:78:55:A4:67:76:77:D1:5F:9D:
59:6E:F8:0B:F1:D2:9E:77
Signed Certificate Timestamp:
Version : v1 (0x0)
Log ID : 4E:75:A3:27:5C:9A:10:C3:38:5B:6C:D4:DF:3F:52:EB:
1D:F0:E0:8E:1B:8D:69:C0:B1:FA:64:B1:62:9A:39:DF
Timestamp : Jan 4 03:37:44.826 2024 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:44:02:20:42:EE:28:5C:F2:8C:89:EF:BF:36:EC:57:
0C:E9:A5:B5:5C:48:9E:66:77:72:84:03:3B:92:64:A1:
E9:B4:49:B8:02:20:7F:19:E4:00:3F:FE:82:FD:80:5A:
A3:A7:A8:5D:D1:19:89:52:ED:00:DE:FE:2E:80:EC:67:
CE:C5:EF:05:FF:73
Signature Algorithm: sha256WithRSAEncryption
Signature Value:
62:f4:81:c2:9b:2e:7c:2e:80:58:41:fb:3b:26:3d:36:34:8d:
a0:5e:27:d6:c9:b4:c5:d8:af:be:8a:c7:bd:77:c2:84:44:06:
e5:7f:11:b0:bd:39:71:15:2c:b5:81:30:db:dc:d9:57:43:8e:
e1:d8:d1:e4:e5:7e:90:52:e3:9e:12:03:48:7a:bd:09:6b:0f:
1c:b2:e0:cf:1f:32:43:6f:49:05:df:fe:c6:e9:1e:ef:30:ab:
f9:f8:85:a9:39:fb:42:81:be:f1:30:ca:e1:a3:bb:38:64:6a:
5e:50:2a:9e:11:2a:2d:37:96:37:8a:75:a3:44:01:d6:39:1c:
1f:a9:f3:22:c5:ec:9a:84:2d:aa:f5:9d:45:bb:f2:50:f6:a4:
42:e8:36:88:c6:57:e8:09:04:73:8d:39:8a:b0:6e:c1:1c:5a:
87:6c:1b:e2:8e:94:34:83:53:69:07:09:8c:73:f7:58:13:b6:
a6:d6:bb:41:50:62:8e:e2:47:18:7a:0d:58:f6:00:74:98:08:
aa:b9:10:d6:cd:57:4e:93:5c:df:c0:e7:dc:f6:9e:a9:24:8c:
23:71:86:0a:f6:7e:ac:99:6c:95:b0:ba:67:c8:29:e5:cd:41:
df:ee:f0:86:f3:71:39:d2:c3:31:76:93:31:26:3f:f0:ec:af:
5b:3f:6a:4f
1688663994 | 2024-12-05T00:07:04.832862
445 /
tcp
SMB Status:
Authentication: enabled
SMB Version: 1
OS: Windows Server 2012 R2 Standard 9600
Software: Windows Server 2012 R2 Standard 6.3
Capabilities: extended-security, infolevel-passthru, large-files, large-readx, large-writex, level2-oplocks, lock-and-read, lwio, nt-find, nt-smb, nt-status, rpc-remote-api, unicode
-355189785 | 2024-12-03T02:24:37.110182
1434 /
udp
SQL Server Browser Service:
Instance #1:
Server Name: WIN-8M679OO1T5G
Instance Name: MSSQL201684
Is Clustered: False
Version: 13.0.1601.5
TCP Port: 49081
Version Name: MS-SQL Server 2016 RTM
-2078198558 | 2024-12-06T05:23:03.392027
2000 /
tcp
HTTP/1.1 400 Bad Request
Content-Type: text/html; charset=us-ascii
Server: Microsoft-HTTPAPI/2.0
Date: Fri, 06 Dec 2024 05:22:53 GMT
Connection: close
Content-Length: 326
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN""http://www.w3.org/TR/html4/strict.dtd">
<HTML><HEAD><TITLE>Bad Request</TITLE>
<META HTTP-EQUIV="Content-Type" Content="text/html; charset=us-ascii"></HEAD>
<BODY><h2>Bad Request - Invalid Verb</h2>
<hr><p>HTTP Error 400. The request verb is invalid.</p>
</BODY></HTML>
-1559332324 | 2024-12-05T07:06:25.753940
3000 /
tcp
HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Sat, 09 Dec 2023 04:59:39 GMT
Accept-Ranges: bytes
ETag: "802f5b835c2ada1:0"
Server: Microsoft-IIS/8.5
X-Powered-By: ASP.NET
Date: Thu, 05 Dec 2024 07:06:17 GMT
Content-Length: 8668
1489525118 | 2024-12-07T19:55:47.709857
5985 /
tcp
HTTP/1.1 404 Not Found
Content-Type: text/html; charset=us-ascii
Server: Microsoft-HTTPAPI/2.0
Date: Sat, 07 Dec 2024 19:55:47 GMT
Connection: close
Content-Length: 315
WinRM NTLM Info:
OS: Windows Server 2012 R2
OS Build: 6.3.9600
Target Name: WIN-8M679OO1T5G
NetBIOS Domain Name: WIN-8M679OO1T5G
NetBIOS Computer Name: WIN-8M679OO1T5G
DNS Domain Name: WIN-8M679OO1T5G
FQDN: WIN-8M679OO1T5G
-1128897935 | 2024-12-27T01:41:32.848535
8200 /
tcp
<empty title>
HTTP/1.1 404 Not Found
Content-Length: 0
X-Correlation-ID: 0HN962J4I1ALO:00000002
X-Powered-By: ASP.NET
Date: Fri, 27 Dec 2024 01:41:26 GMT
-1658900839 | 2024-12-03T04:02:47.174161
49081 /
tcp
MS-SQL NTLM Info:
OS: Windows 8.1/Windows Server 2012 R2
OS Build: 6.3.9600
Target Name: WIN-8M679OO1T5G
NetBIOS Domain Name: WIN-8M679OO1T5G
NetBIOS Computer Name: WIN-8M679OO1T5G
DNS Domain Name: WIN-8M679OO1T5G
FQDN: WIN-8M679OO1T5G