362392020 | 2024-10-31T10:05:30.607691
80 /
tcp
HTTP/1.1 400 Bad Request
Server: WAF
Date: Thu, 31 Oct 2024 10:05:29 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
Set-Cookie: waf_404=0ebd4dde-3977-4ff1-81cb-78ca5b2f0d52; Max-Age=300; Path=/; HttpOnly
Cache-Control: no-cache, no-store
x-frame-options: sameorigin
521252104 | 2024-11-04T19:13:51.884953
443 /
tcp
HTTP/1.1 200 OK
Date: Mon, 04 Nov 2024 19:13:50 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
Set-Cookie: https_waf_cookie=0dd77739-553d-4bfaf3ba73f8b96e9cbb040c923219d9690e; Expires=1730754830; Path=/; Secure; HttpOnly
Server: WAF
Last-Modified: Mon, 22 Jan 2024 06:04:09 GMT
ETag: "f70e-60f8299208796"
Strict-Transport-Security: max-age=0; preload
X-Request-Id: a88cab46bb037ff078a224af32f65c17
X-Cache: BYPASS
SSL Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
85:e7:6f:c0:b2:79:50:0b:5f:54:6c:32:8c:e9:96:e0
Signature Algorithm: sha256WithRSAEncryption
Issuer: C=CN, O=WoTrus CA Limited, CN=WoTrus DV Server CA [Run by the Issuer]
Validity
Not Before: Jan 10 00:00:00 2024 GMT
Not After : Feb 9 23:59:59 2025 GMT
Subject: CN=*.hcr.com.cn
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:9f:83:5e:61:f5:85:e9:57:2a:1e:cb:56:f6:e0:
7a:1e:36:f3:d0:3d:0f:5b:28:b1:4c:18:12:7c:93:
cf:b9:28:7b:ae:71:15:12:b7:ea:c1:84:28:70:cb:
e7:99:46:41:ed:59:7f:48:99:e8:d9:dc:88:62:26:
90:d5:f1:45:7a:a0:8f:2a:3f:33:6b:9a:07:4d:01:
e8:8b:d2:8b:1c:29:b9:4f:21:e1:9a:d3:b5:8b:ed:
fb:27:63:17:1b:1c:f6:5e:5f:f9:e2:39:59:91:a0:
0d:c8:21:3e:53:75:71:4d:4a:b5:c8:4f:84:5f:7a:
3f:60:11:1c:ca:1f:fb:a1:c3:59:39:db:d7:48:15:
e5:1c:15:ce:6a:f4:a3:10:e2:5d:0a:e2:e0:a5:a9:
e4:d6:97:18:e7:64:f0:73:37:e5:33:5a:a5:4f:fe:
6f:64:30:67:f2:d0:67:f8:2d:7b:28:1b:44:be:b8:
80:bf:32:59:47:2f:18:b2:67:55:37:7b:0f:7b:88:
ce:5b:83:e5:c4:bf:d2:b9:42:05:fe:d2:77:98:54:
ab:d5:ef:e8:c6:85:e4:8c:90:5c:19:ed:ce:61:b8:
e7:82:a2:df:18:e4:7d:ee:8e:f0:2c:84:5a:69:2b:
17:0a:4c:bb:5b:9c:95:73:a8:32:b3:f2:d9:48:8d:
6c:63
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Authority Key Identifier:
99:9B:2D:F6:8B:F0:A3:DB:89:D4:9E:FB:E5:74:2F:68:D2:90:4F:E4
X509v3 Subject Key Identifier:
2D:6A:E7:1B:40:04:2D:A8:90:54:E8:2C:57:C3:B2:6E:25:34:FA:7D
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
X509v3 Basic Constraints: critical
CA:FALSE
X509v3 Extended Key Usage:
TLS Web Server Authentication, TLS Web Client Authentication
X509v3 Certificate Policies:
Policy: 1.3.6.1.4.1.6449.1.2.2.22
CPS: https://sectigo.com/CPS
Policy: 2.23.140.1.2.1
X509v3 CRL Distribution Points:
Full Name:
URI:http://crl.crlocsp.cn/WoTrusDVServerCA_2.crl
Authority Information Access:
CA Issuers - URI:http://aia.crlocsp.cn/WoTrusDVServerCA_2.crt
OCSP - URI:http://ocsp.crlocsp.cn
CT Precertificate SCTs:
Signed Certificate Timestamp:
Version : v1 (0x0)
Log ID : CF:11:56:EE:D5:2E:7C:AF:F3:87:5B:D9:69:2E:9B:E9:
1A:71:67:4A:B0:17:EC:AC:01:D2:5B:77:CE:CC:3B:08
Timestamp : Jan 10 00:53:30.556 2024 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:44:02:20:2F:13:48:CB:1A:57:A7:DD:C2:5E:EA:C9:
E2:94:3D:0F:C0:D6:F1:61:85:A8:07:7E:E8:2E:C5:E1:
A3:C3:A2:C4:02:20:1E:7E:BD:F3:80:5A:27:76:E6:02:
AA:D9:26:8F:B9:47:1D:AE:9E:11:42:4C:47:BB:00:1B:
A8:93:D0:E2:95:3B
Signed Certificate Timestamp:
Version : v1 (0x0)
Log ID : A2:E3:0A:E4:45:EF:BD:AD:9B:7E:38:ED:47:67:77:53:
D7:82:5B:84:94:D7:2B:5E:1B:2C:C4:B9:50:A4:47:E7
Timestamp : Jan 10 00:53:30.532 2024 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:46:02:21:00:B6:CF:6A:31:EF:E5:40:13:D6:75:77:
20:FB:4E:3B:2C:B7:FB:9C:EF:51:72:50:61:F7:02:35:
F1:EF:BE:3F:51:02:21:00:BE:3F:C2:A2:7E:35:F0:4C:
47:2A:EE:C1:54:23:F7:8F:FE:9D:2F:1D:84:53:B4:8C:
48:7F:BD:FA:5A:BB:EE:93
Signed Certificate Timestamp:
Version : v1 (0x0)
Log ID : 4E:75:A3:27:5C:9A:10:C3:38:5B:6C:D4:DF:3F:52:EB:
1D:F0:E0:8E:1B:8D:69:C0:B1:FA:64:B1:62:9A:39:DF
Timestamp : Jan 10 00:53:30.520 2024 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:44:02:20:18:A8:75:5D:D7:3A:DA:CE:5F:4E:C3:98:
CA:8E:BD:0D:61:10:AB:19:F2:A9:4B:2F:B5:1E:0E:0C:
89:C2:8B:79:02:20:0E:D5:91:1C:57:94:91:A8:DF:B5:
7F:44:13:4D:FA:C2:93:02:F2:18:58:6F:CD:64:AD:0A:
66:1B:A7:9F:59:9C
X509v3 Subject Alternative Name:
DNS:*.hcr.com.cn, DNS:hcr.com.cn
Signature Algorithm: sha256WithRSAEncryption
Signature Value:
b8:21:3c:44:b0:d7:a2:9d:99:c4:42:d9:ce:de:54:ca:67:b7:
da:62:5b:d8:2e:b8:98:e1:0f:05:89:bc:1b:6b:1f:fb:2a:f4:
c4:0b:dc:87:8f:96:aa:ef:42:d0:c6:dc:65:14:2d:b6:e8:b6:
28:38:75:5e:a2:df:b9:a3:42:f0:c2:33:99:11:ed:74:b2:9f:
0b:fd:77:82:8d:51:64:32:36:8b:7d:6c:59:74:6e:5a:75:00:
ab:58:77:3c:f3:53:25:9b:23:63:9f:8e:28:2c:5d:72:83:98:
bd:22:65:bb:f5:4b:a3:1c:7e:d3:7d:42:7b:a9:6b:20:a6:fe:
cc:d1:79:cd:24:e8:e2:39:a8:d6:37:df:6e:87:ef:d8:e8:7f:
70:53:67:27:ab:82:8e:74:48:49:2e:7e:08:c0:48:1f:03:f7:
47:fd:88:8f:f9:05:41:c7:d4:1d:f1:6b:ff:8a:b7:e4:f2:23:
4e:bc:2b:bf:95:29:70:34:bb:7e:81:1f:da:5b:36:61:33:9d:
74:18:83:b7:2c:95:fc:e6:e6:0b:30:5e:09:f7:83:58:c5:f1:
27:13:1d:ee:69:64:a2:e6:f8:a3:26:c0:ba:5e:92:7c:31:0b:
95:e0:f1:23:26:be:a9:8c:97:d3:2b:a4:79:af:1e:26:41:b9:
0c:d7:57:07
362392020 | 2024-10-10T18:40:13.447079
8080 /
tcp
HTTP/1.1 400 Bad Request
Server: WAF
Date: Thu, 10 Oct 2024 18:40:13 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
Set-Cookie: waf_404=29fcf9ae-647e-4bd6-aaf5-0d1e48f21700; Max-Age=300; Path=/; HttpOnly
Cache-Control: no-cache, no-store
x-frame-options: sameorigin
362392020 | 2024-10-22T08:22:22.827518
8443 /
tcp
HTTP/1.1 400 Bad Request
Server: WAF
Date: Tue, 22 Oct 2024 08:22:22 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
Set-Cookie: waf_404=2dfbb8b1-ccd9-413f-a40b-a1baa7f28fd7; Max-Age=300; Path=/; Secure; HttpOnly
x-frame-options: sameorigin
Cache-Control: no-cache, no-store
SSL Certificate
Certificate:
Data:
Version: 1 (0x0)
Serial Number:
d4:7c:19:ad:8a:0c:45:e7
Signature Algorithm: sha256WithRSAEncryption
Issuer: C=CN, ST=Shanghai, L=Shanghai, O=Waf, OU=WAF, CN=Waf defaut certificate(Attack Behavior reported to the police)
Validity
Not Before: Aug 26 09:48:09 2020 GMT
Not After : Aug 24 09:48:09 2030 GMT
Subject: C=CN, ST=Shanghai, L=Shanghai, O=Waf, OU=WAF, CN=Waf defaut certificate(Attack Behavior reported to the police)
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:9f:5f:fd:c1:78:5e:44:d0:a9:bb:6b:cf:d9:75:
f2:70:74:68:0d:2a:83:20:11:d1:53:87:60:c9:19:
04:94:71:82:7a:9e:b0:25:81:5d:3f:91:21:e8:c3:
f7:8e:c2:70:85:9e:f7:13:35:1b:12:b4:fc:fa:a5:
cb:4b:1b:ce:cf:6b:94:70:7f:fc:84:da:67:b1:b9:
a6:4f:8a:2a:42:87:f2:75:ba:7e:2f:3f:1b:8c:cc:
41:eb:f2:96:05:6e:f4:4d:4d:01:f4:19:47:90:ae:
ef:ce:28:cf:9e:85:37:8e:3c:b0:f2:cd:b1:52:f5:
71:5a:4c:44:6d:54:f7:00:5e:52:0b:b2:1c:f2:cb:
a2:9c:f5:af:b7:b7:54:f3:47:24:2f:4d:78:f8:16:
86:b0:a7:bf:c8:a2:3d:bb:69:d1:e2:4d:29:68:06:
9c:65:31:a9:61:bf:98:5c:5e:4c:64:68:95:ff:a9:
69:f8:86:7a:0d:38:c6:39:e4:c5:cc:10:c9:a5:fe:
92:0e:db:70:23:45:15:78:38:9d:95:d9:2e:31:1e:
ef:8d:ff:3b:4a:a1:96:8a:b0:b9:5b:cd:64:a5:52:
b8:34:7e:f6:15:45:3b:6c:64:34:72:50:c7:bc:e4:
cc:ba:85:21:b3:3e:ec:45:58:81:0d:93:dc:a3:bb:
f7:ff
Exponent: 65537 (0x10001)
Signature Algorithm: sha256WithRSAEncryption
Signature Value:
31:1e:02:67:bd:0c:a6:cb:bb:32:1a:02:6e:1e:ec:16:d9:5e:
89:c7:09:dc:3e:65:ed:be:19:89:dc:25:8a:84:1a:1f:dc:0c:
48:11:61:85:0a:9a:00:e1:3d:b5:56:33:8a:ee:0d:9c:e8:5f:
b5:f5:0b:3f:9b:9d:ad:e0:ac:23:1f:b2:fa:a9:f7:d4:13:1b:
67:54:eb:12:16:e2:48:67:5f:a8:cf:30:42:f5:60:68:68:63:
9e:58:72:7b:7a:68:8a:bb:60:5e:b5:0b:cf:77:9f:ba:c9:ab:
47:24:45:b6:63:0f:a7:d8:74:e1:87:5a:1c:5e:53:4e:2d:b2:
84:e5:83:3b:bc:b3:d0:a9:53:a8:50:da:b4:4b:4d:ef:b3:d6:
03:7b:9c:c7:f0:fd:36:38:ad:e7:b9:50:ba:d7:5a:97:5b:8b:
c6:a3:9d:42:b1:90:12:04:2b:52:8c:b2:43:e1:8f:8e:05:57:
81:74:71:7e:72:cf:a7:d4:7d:fa:c0:31:84:e7:46:fa:ae:65:
94:ce:18:66:f9:e4:a3:0e:b1:81:f5:53:b7:9d:48:b1:b9:39:
cc:3a:61:72:ef:dd:8f:76:0d:41:a0:10:a6:82:2e:72:0c:f4:
5b:db:20:7a:5f:52:81:a5:3c:57:a2:0b:18:d5:fe:ed:f9:e3:
cd:95:c0:e4