-1154938775 | 2024-12-14T18:23:45.923601
135 /
tcp
Microsoft RPC Endpoint Mapper
d95afe70-a6d5-4259-822e-2c84da1ddb0d
version: v1.0
protocol: [MS-RSP]: Remote Shutdown Protocol
provider: wininit.exe
ncacn_ip_tcp: 213.252.247.93:49152
ncalrpc: WindowsShutdown
ncacn_np: \\WIN-GV0KSI2A5NA\PIPE\InitShutdown
ncalrpc: WMsgKRpc05E1D0
76f226c3-ec14-4325-8a99-6a46348418af
version: v1.0
provider: winlogon.exe
ncalrpc: WindowsShutdown
ncacn_np: \\WIN-GV0KSI2A5NA\PIPE\InitShutdown
ncalrpc: WMsgKRpc05E1D0
ncalrpc: WMsgKRpc05E4D1
c9ac6db5-82b7-4e55-ae8a-e464ed7b4277
version: v1.0
annotation: Impl friendly name
provider: sysntfy.dll
ncalrpc: LRPC-490a8838e0c52265a4
ncacn_np: \\WIN-GV0KSI2A5NA\PIPE\srvsvc
ncacn_ip_tcp: 213.252.247.93:49154
ncacn_np: \\WIN-GV0KSI2A5NA\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEB01F633C79234291B8709A1CC749
ncalrpc: IUserProfile2
ncalrpc: senssvc
ncalrpc: OLEB01F633C79234291B8709A1CC749
ncalrpc: IUserProfile2
ncalrpc: OLEB01F633C79234291B8709A1CC749
ncalrpc: IUserProfile2
ncalrpc: IUserProfile2
3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6
version: v1.0
annotation: DHCPv6 Client LRPC Endpoint
provider: dhcpcsvc6.dll
ncalrpc: dhcpcsvc6
ncalrpc: dhcpcsvc
ncacn_ip_tcp: 213.252.247.93:49153
ncacn_np: \\WIN-GV0KSI2A5NA\pipe\eventlog
ncalrpc: eventlog
3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5
version: v1.0
annotation: DHCP Client LRPC Endpoint
provider: dhcpcsvc.dll
ncalrpc: dhcpcsvc
ncacn_ip_tcp: 213.252.247.93:49153
ncacn_np: \\WIN-GV0KSI2A5NA\pipe\eventlog
ncalrpc: eventlog
30adc50c-5cbc-46ce-9a0e-91914789e23c
version: v1.0
annotation: NRP server endpoint
provider: nrpsrv.dll
ncacn_ip_tcp: 213.252.247.93:49153
ncacn_np: \\WIN-GV0KSI2A5NA\pipe\eventlog
ncalrpc: eventlog
f6beaff7-1e19-4fbb-9f8f-b89e2018337c
version: v1.0
annotation: Event log TCPIP
protocol: [MS-EVEN6]: EventLog Remoting Protocol
provider: wevtsvc.dll
ncacn_ip_tcp: 213.252.247.93:49153
ncacn_np: \\WIN-GV0KSI2A5NA\pipe\eventlog
ncalrpc: eventlog
24019106-a203-4642-b88d-82dae9158929
version: v1.0
provider: authui.dll
ncalrpc: LRPC-d3072c0bcc2e245eea
30b044a5-a225-43f0-b3a4-e060df91f9c1
version: v1.0
provider: certprop.dll
ncacn_np: \\WIN-GV0KSI2A5NA\PIPE\srvsvc
ncacn_ip_tcp: 213.252.247.93:49154
ncacn_np: \\WIN-GV0KSI2A5NA\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEB01F633C79234291B8709A1CC749
ncalrpc: IUserProfile2
98716d03-89ac-44c7-bb8c-285824e51c4a
version: v1.0
annotation: XactSrv service
provider: srvsvc.dll
ncacn_ip_tcp: 213.252.247.93:49154
ncacn_np: \\WIN-GV0KSI2A5NA\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEB01F633C79234291B8709A1CC749
ncalrpc: IUserProfile2
552d076a-cb29-4e44-8b6a-d15e59e2c0af
version: v1.0
annotation: IP Transition Configuration endpoint
provider: iphlpsvc.dll
ncacn_ip_tcp: 213.252.247.93:49154
ncacn_np: \\WIN-GV0KSI2A5NA\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEB01F633C79234291B8709A1CC749
ncalrpc: IUserProfile2
86d35949-83c9-4044-b424-db363231fd0c
version: v1.0
protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol
provider: schedsvc.dll
ncacn_ip_tcp: 213.252.247.93:49154
ncacn_np: \\WIN-GV0KSI2A5NA\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEB01F633C79234291B8709A1CC749
ncalrpc: IUserProfile2
378e52b0-c0a9-11cf-822d-00aa0051e40f
version: v1.0
protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol
provider: taskcomp.dll
ncacn_np: \\WIN-GV0KSI2A5NA\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEB01F633C79234291B8709A1CC749
ncalrpc: IUserProfile2
1ff70682-0a51-30e8-076d-740be8cee98b
version: v1.0
protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol
provider: taskcomp.dll
ncacn_np: \\WIN-GV0KSI2A5NA\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEB01F633C79234291B8709A1CC749
ncalrpc: IUserProfile2
0a74ef1c-41a4-4e06-83ae-dc74fb1cdd53
version: v1.0
provider: schedsvc.dll
ncalrpc: senssvc
ncalrpc: OLEB01F633C79234291B8709A1CC749
ncalrpc: IUserProfile2
2eb08e3e-639f-4fba-97b1-14f878961076
version: v1.0
provider: gpsvc.dll
ncalrpc: OLEB01F633C79234291B8709A1CC749
ncalrpc: IUserProfile2
3473dd4d-2e88-4006-9cba-22570909dd10
version: v5.256
annotation: WinHttp Auto-Proxy Service
ncalrpc: LRPC-57cda558105dcd13f6
ncalrpc: OLE6FB03975F9DD47F7AF2C3C8098BE
7ea70bcf-48af-4f6a-8968-6a440754d5fa
version: v1.0
annotation: NSI server endpoint
provider: nsisvc.dll
ncalrpc: LRPC-57cda558105dcd13f6
ncalrpc: OLE6FB03975F9DD47F7AF2C3C8098BE
2fb92682-6599-42dc-ae13-bd2ca89bd11c
version: v1.0
annotation: Fw APIs
provider: MPSSVC.dll
ncalrpc: LRPC-c69eae9d6035d2e794
7f9d11bf-7fb9-436b-a812-b2d50c5d4c03
version: v1.0
annotation: Fw APIs
provider: MPSSVC.dll
ncalrpc: LRPC-c69eae9d6035d2e794
dd490425-5325-4565-b774-7e27d6c09c24
version: v1.0
annotation: Base Firewall Engine API
provider: BFE.DLL
ncalrpc: LRPC-c69eae9d6035d2e794
4a452661-8290-4b36-8fbe-7f4093a94978
version: v1.0
annotation: Spooler function endpoint
provider: spoolsv.exe
ncalrpc: spoolss
ae33069b-a2a8-46ee-a235-ddfd339be281
version: v1.0
annotation: Spooler base remote object endpoint
protocol: [MS-PAN]: Print System Asynchronous Notification Protocol
provider: spoolsv.exe
ncalrpc: spoolss
0b6edbfa-4a24-4fc6-8a23-942b1eca65d1
version: v1.0
annotation: Spooler function endpoint
protocol: [MS-PAN]: Print System Asynchronous Notification Protocol
provider: spoolsv.exe
ncalrpc: spoolss
367abb81-9844-35f1-ad32-98f038001003
version: v2.0
protocol: [MS-SCMR]: Service Control Manager Remote Protocol
provider: services.exe
ncacn_ip_tcp: 213.252.247.93:49155
12345778-1234-abcd-ef00-0123456789ac
version: v1.0
protocol: [MS-SAMR]: Security Account Manager (SAM) Remote Protocol
provider: samsrv.dll
ncacn_ip_tcp: 213.252.247.93:49156
ncalrpc: samss lpc
ncalrpc: dsrole
ncacn_np: \\WIN-GV0KSI2A5NA\PIPE\protected_storage
ncalrpc: protected_storage
ncalrpc: lsasspirpc
ncalrpc: lsapolicylookup
ncalrpc: LSARPC_ENDPOINT
ncalrpc: securityevent
ncalrpc: audit
ncalrpc: LRPC-cf487f7d06dd7b736a
ncacn_np: \\WIN-GV0KSI2A5NA\pipe\lsass
906b0ce0-c70b-1067-b317-00dd010662da
version: v1.0
protocol: [MS-CMPO]: MSDTC Connection Manager:
provider: msdtcprx.dll
ncalrpc: LRPC-8146f0647324d0763b
ncalrpc: LRPC-8146f0647324d0763b
ncalrpc: LRPC-8146f0647324d0763b
ncalrpc: LRPC-8146f0647324d0763b
1641389631 | 2025-01-07T09:42:46.211027
445 /
tcp
SMB Status:
Authentication: enabled
SMB Version: 1
OS: Windows Server 2008 R2 Standard 7601 Service Pack 1
Software: Windows Server 2008 R2 Standard 6.1
Capabilities: extended-security, infolevel-passthru, large-files, large-readx, large-writex, level2-oplocks, lock-and-read, lwio, nt-find, nt-smb, nt-status, rpc-remote-api, unicode
-1024493026 | 2024-12-31T00:35:21.059968
3389 /
tcp
Remote Desktop Protocol
\x03\x00\x00\x13\x0e\xd0\x00\x00\x124\x00\x02\t\x08\x00\x02\x00\x00\x00
Remote Desktop Protocol NTLM Info:
OS: Windows 7/Windows Server 2008 R2
OS Build: 6.1.7601
Target Name: WIN-GV0KSI2A5NA
NetBIOS Domain Name: WIN-GV0KSI2A5NA
NetBIOS Computer Name: WIN-GV0KSI2A5NA
DNS Domain Name: WIN-GV0KSI2A5NA
FQDN: WIN-GV0KSI2A5NA
2
Administrator BaCloud.com User
(A
4 Windows Server-2008rz
Standard
SSL Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
65:23:a6:a4:e9:bc:34:ab:42:35:e3:1c:b2:2e:d2:90
Signature Algorithm: sha1WithRSAEncryption
Issuer: CN=WIN-GV0KSI2A5NA
Validity
Not Before: Aug 21 14:07:43 2024 GMT
Not After : Feb 20 14:07:43 2025 GMT
Subject: CN=WIN-GV0KSI2A5NA
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:bb:42:c5:95:d8:e5:63:5d:cd:f7:1b:8e:3c:4b:
23:36:e7:3c:bc:5b:92:c0:67:b0:8e:7a:dd:4d:f6:
99:29:c2:b2:ed:c8:2d:ad:79:e8:16:46:da:e3:b1:
3e:4d:25:eb:41:15:1b:ba:c0:d8:f0:0b:c3:71:5c:
80:01:78:0b:99:05:65:71:d8:c4:cf:bb:8c:3f:5e:
bf:7e:a3:17:44:0f:a2:8c:6b:8f:da:df:f9:7c:aa:
4d:88:43:79:b4:84:63:f4:91:07:b0:f5:89:db:89:
5d:22:ec:b7:73:2c:0d:bc:b1:e2:0a:0e:6d:d9:db:
85:d1:1e:77:ba:4e:af:d8:a3:a9:5f:4e:af:67:22:
16:62:62:77:e4:05:64:3d:1c:4f:64:b1:35:9f:19:
52:92:6b:83:54:55:ff:71:71:b5:d8:b7:34:38:a2:
fe:a4:db:f0:25:72:3f:90:65:bd:50:a5:5b:a1:90:
8f:7f:64:e6:e5:83:11:d9:d0:bf:58:f6:7b:7e:b7:
ee:c4:de:f3:ce:d1:e8:8a:3d:42:25:26:00:de:80:
a9:08:f0:00:c9:83:f7:94:31:b2:27:ea:51:b3:23:
44:e8:02:4e:4a:12:1d:18:ff:e6:f2:cf:05:d6:f8:
58:ba:6f:01:e2:1a:2e:7e:2d:19:38:07:02:07:c9:
60:11
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Extended Key Usage:
TLS Web Server Authentication
X509v3 Key Usage:
Key Encipherment, Data Encipherment
Signature Algorithm: sha1WithRSAEncryption
Signature Value:
3b:ba:e3:44:8c:3e:14:6e:d9:2f:3c:47:a9:81:22:06:fc:3f:
90:8b:44:ca:02:43:cd:ae:68:41:44:93:c5:8d:ca:f0:cc:9f:
33:6a:8d:38:d9:e3:b9:c2:45:36:a1:aa:e4:e8:87:5c:6e:55:
a2:89:b3:f3:74:0c:52:c3:e5:63:45:6c:b9:f7:e2:66:ea:2c:
df:26:18:fd:a1:59:f4:35:e8:19:3d:46:21:65:42:4c:63:cb:
94:45:d3:5c:9d:61:41:86:bd:8f:09:94:d0:47:65:97:39:7a:
89:b1:a9:bb:50:fc:95:7e:41:59:1f:df:32:54:93:aa:57:19:
f6:25:ba:b8:78:10:bd:49:20:91:7d:fb:16:c5:92:19:e3:c2:
ba:f4:d5:e1:13:aa:ac:7d:b4:96:bc:39:25:15:64:b4:73:d1:
18:a3:6c:fc:43:a6:10:d2:76:7f:ea:3b:f8:cb:88:9e:9b:bf:
bf:f0:75:9a:c3:88:7f:15:3c:a1:8a:cb:af:2c:df:80:38:9b:
25:e4:9e:98:28:f4:2e:ca:85:e7:65:6a:37:76:38:62:d0:d6:
05:ae:88:ef:24:a3:ea:18:f0:df:c9:f6:7b:a9:e6:4f:3b:d8:
ae:ad:bb:31:31:b8:62:41:26:62:c5:45:21:c9:f4:b4:fc:45:
c1:7b:36:32