-1521289231 | 2024-10-30T20:39:56.290676
21 /
tcp
220 FileZilla Server version 0.9.46 beta written by Tim Kosse (Tim.Kosse@gmx.de) Please visit http://sourceforge.
530 Login or password incorrect!
214-The following commands are recognized:
ABOR ADAT ALLO APPE AUTH CDUP CLNT CWD
DELE EPRT EPSV FEAT HASH HELP LIST MDTM
MFMT MKD MLSD MLST MODE NLST NOOP NOP
OPTS P@SW PASS PASV PBSZ PORT PROT PWD
QUIT REST RETR RMD RNFR RNTO SITE SIZE
STOR STRU SYST TYPE USER XCUP XCWD XMKD
XPWD XRMD
214 Have a nice day.
211-Features:
MDTM
REST STREAM
SIZE
MLST type*;size*;modify*;
MLSD
UTF8
CLNT
MFMT
211 End
-170300965 | 2024-10-30T07:58:02.534195
80 /
tcp
HTTP/1.1 200 OK
Server: nginx
Date: Wed, 30 Oct 2024 07:58:48 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
X-Powered-By: PHP/7.0.33
-1545134620 | 2024-10-28T20:04:11.008037
135 /
tcp
Microsoft RPC Endpoint Mapper
d95afe70-a6d5-4259-822e-2c84da1ddb0d
version: v1.0
protocol: [MS-RSP]: Remote Shutdown Protocol
provider: wininit.exe
ncacn_ip_tcp: 23.158.72.18:49664
ncalrpc: WindowsShutdown
ncacn_np: \\WIN-GHAM948BGPH\PIPE\InitShutdown
ncalrpc: WMsgKRpc059F80
76f226c3-ec14-4325-8a99-6a46348418af
version: v1.0
provider: winlogon.exe
ncalrpc: WindowsShutdown
ncacn_np: \\WIN-GHAM948BGPH\PIPE\InitShutdown
ncalrpc: WMsgKRpc059F80
ncalrpc: WMsgKRpc0B9DD1
ncalrpc: WMsgKRpc01C82702
fc48cd89-98d6-4628-9839-86f7a3e4161a
version: v1.0
ncalrpc: LRPC-0d4dbdc11ef21f56d0
ncalrpc: dabrpc
ncalrpc: csebpub
ncalrpc: LRPC-dfc1fd295959b98326
ncalrpc: LRPC-19af0139c61bf7aac7
ncalrpc: OLE3D8950749318D67C2FFE3AA7B15E
ncacn_np: \\WIN-GHAM948BGPH\pipe\LSM_API_service
ncalrpc: LSMApi
ncalrpc: LRPC-f2c133857a1dd4a28b
ncalrpc: LRPC-aa4e3a4f453dbae8e8
ncalrpc: LRPC-bdd11ba063f73a78f3
ncalrpc: actkernel
ncalrpc: umpo
9b008953-f195-4bf9-bde0-4471971e58ed
version: v1.0
ncalrpc: LRPC-0d4dbdc11ef21f56d0
ncalrpc: dabrpc
ncalrpc: csebpub
ncalrpc: LRPC-dfc1fd295959b98326
ncalrpc: LRPC-19af0139c61bf7aac7
ncalrpc: OLE3D8950749318D67C2FFE3AA7B15E
ncacn_np: \\WIN-GHAM948BGPH\pipe\LSM_API_service
ncalrpc: LSMApi
ncalrpc: LRPC-f2c133857a1dd4a28b
ncalrpc: LRPC-aa4e3a4f453dbae8e8
ncalrpc: LRPC-bdd11ba063f73a78f3
ncalrpc: actkernel
ncalrpc: umpo
d09bdeb5-6171-4a34-bfe2-06fa82652568
version: v1.0
ncalrpc: csebpub
ncalrpc: LRPC-dfc1fd295959b98326
ncalrpc: LRPC-19af0139c61bf7aac7
ncalrpc: OLE3D8950749318D67C2FFE3AA7B15E
ncacn_np: \\WIN-GHAM948BGPH\pipe\LSM_API_service
ncalrpc: LSMApi
ncalrpc: LRPC-f2c133857a1dd4a28b
ncalrpc: LRPC-aa4e3a4f453dbae8e8
ncalrpc: LRPC-bdd11ba063f73a78f3
ncalrpc: actkernel
ncalrpc: umpo
ncalrpc: LRPC-19af0139c61bf7aac7
ncalrpc: OLE3D8950749318D67C2FFE3AA7B15E
ncacn_np: \\WIN-GHAM948BGPH\pipe\LSM_API_service
ncalrpc: LSMApi
ncalrpc: LRPC-f2c133857a1dd4a28b
ncalrpc: LRPC-aa4e3a4f453dbae8e8
ncalrpc: LRPC-bdd11ba063f73a78f3
ncalrpc: actkernel
ncalrpc: umpo
ncalrpc: LRPC-935504ba4fc017b471
ncalrpc: LRPC-5395b5af1fedd45257
ncalrpc: dhcpcsvc
ncalrpc: dhcpcsvc6
ncacn_ip_tcp: 23.158.72.18:49665
ncacn_np: \\WIN-GHAM948BGPH\pipe\eventlog
ncalrpc: eventlog
ncalrpc: LRPC-741c9e68941087f9a7
ncalrpc: senssvc
ncalrpc: LRPC-7fae78aaa1df98f6f0
ncalrpc: IUserProfile2
ncalrpc: LRPC-73d412df2255b79524
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\WIN-GHAM948BGPH\PIPE\atsvc
ncacn_ip_tcp: 23.158.72.18:49666
ncacn_np: \\WIN-GHAM948BGPH\pipe\SessEnvPublicRpc
ncalrpc: SessEnvPrivateRpc
ncalrpc: DeviceSetupManager
ncalrpc: LRPC-0a54d87edf16f835aa
ncalrpc: LRPC-3096683bcfe09b80ef
ncalrpc: OLED9C4BDB74FF28DE3112A3473017E
697dcda9-3ba9-4eb2-9247-e11f1901b0d2
version: v1.0
ncalrpc: LRPC-dfc1fd295959b98326
ncalrpc: LRPC-19af0139c61bf7aac7
ncalrpc: OLE3D8950749318D67C2FFE3AA7B15E
ncacn_np: \\WIN-GHAM948BGPH\pipe\LSM_API_service
ncalrpc: LSMApi
ncalrpc: LRPC-f2c133857a1dd4a28b
ncalrpc: LRPC-aa4e3a4f453dbae8e8
ncalrpc: LRPC-bdd11ba063f73a78f3
ncalrpc: actkernel
ncalrpc: umpo
c9ac6db5-82b7-4e55-ae8a-e464ed7b4277
version: v1.0
annotation: Impl friendly name
provider: sysntfy.dll
ncalrpc: LRPC-f2c133857a1dd4a28b
ncalrpc: LRPC-aa4e3a4f453dbae8e8
ncalrpc: LRPC-bdd11ba063f73a78f3
ncalrpc: actkernel
ncalrpc: umpo
ncalrpc: senssvc
ncalrpc: LRPC-7fae78aaa1df98f6f0
ncalrpc: IUserProfile2
ncalrpc: LRPC-73d412df2255b79524
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\WIN-GHAM948BGPH\PIPE\atsvc
ncacn_ip_tcp: 23.158.72.18:49666
ncacn_np: \\WIN-GHAM948BGPH\pipe\SessEnvPublicRpc
ncalrpc: SessEnvPrivateRpc
ncalrpc: DeviceSetupManager
ncalrpc: LRPC-0a54d87edf16f835aa
ncalrpc: LRPC-3096683bcfe09b80ef
ncalrpc: OLED9C4BDB74FF28DE3112A3473017E
ncalrpc: IUserProfile2
ncalrpc: LRPC-73d412df2255b79524
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\WIN-GHAM948BGPH\PIPE\atsvc
ncacn_ip_tcp: 23.158.72.18:49666
ncacn_np: \\WIN-GHAM948BGPH\pipe\SessEnvPublicRpc
ncalrpc: SessEnvPrivateRpc
ncalrpc: DeviceSetupManager
ncalrpc: LRPC-0a54d87edf16f835aa
ncalrpc: LRPC-3096683bcfe09b80ef
ncalrpc: OLED9C4BDB74FF28DE3112A3473017E
ncacn_ip_tcp: 23.158.72.18:49666
ncacn_np: \\WIN-GHAM948BGPH\pipe\SessEnvPublicRpc
ncalrpc: SessEnvPrivateRpc
ncalrpc: DeviceSetupManager
ncalrpc: LRPC-0a54d87edf16f835aa
ncalrpc: LRPC-3096683bcfe09b80ef
ncalrpc: OLED9C4BDB74FF28DE3112A3473017E
ncalrpc: LRPC-0a54d87edf16f835aa
ncalrpc: LRPC-3096683bcfe09b80ef
ncalrpc: OLED9C4BDB74FF28DE3112A3473017E
857fb1be-084f-4fb5-b59c-4b2c4be5f0cf
version: v1.0
ncalrpc: LRPC-aa4e3a4f453dbae8e8
ncalrpc: LRPC-bdd11ba063f73a78f3
ncalrpc: actkernel
ncalrpc: umpo
b8cadbaf-e84b-46b9-84f2-6f71c03f9e55
version: v1.0
ncalrpc: LRPC-aa4e3a4f453dbae8e8
ncalrpc: LRPC-bdd11ba063f73a78f3
ncalrpc: actkernel
ncalrpc: umpo
20c40295-8dba-48e6-aebf-3e78ef3bb144
version: v1.0
ncalrpc: LRPC-aa4e3a4f453dbae8e8
ncalrpc: LRPC-bdd11ba063f73a78f3
ncalrpc: actkernel
ncalrpc: umpo
2513bcbe-6cd4-4348-855e-7efb3c336dd3
version: v1.0
ncalrpc: LRPC-aa4e3a4f453dbae8e8
ncalrpc: LRPC-bdd11ba063f73a78f3
ncalrpc: actkernel
ncalrpc: umpo
88abcbc3-34ea-76ae-8215-767520655a23
version: v0.0
ncalrpc: LRPC-bdd11ba063f73a78f3
ncalrpc: actkernel
ncalrpc: umpo
76c217bc-c8b4-4201-a745-373ad9032b1a
version: v1.0
ncalrpc: LRPC-bdd11ba063f73a78f3
ncalrpc: actkernel
ncalrpc: umpo
55e6b932-1979-45d6-90c5-7f6270724112
version: v1.0
ncalrpc: LRPC-bdd11ba063f73a78f3
ncalrpc: actkernel
ncalrpc: umpo
4dace966-a243-4450-ae3f-9b7bcb5315b8
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
1832bcf6-cab8-41d4-85d2-c9410764f75a
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
c521facf-09a9-42c5-b155-72388595cbf0
version: v0.0
ncalrpc: actkernel
ncalrpc: umpo
2c7fd9ce-e706-4b40-b412-953107ef9bb0
version: v0.0
ncalrpc: actkernel
ncalrpc: umpo
0d3e2735-cea0-4ecc-a9e2-41a2d81aed4e
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
c605f9fb-f0a3-4e2a-a073-73560f8d9e3e
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
1b37ca91-76b1-4f5e-a3c7-2abfc61f2bb0
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
8bfc3be1-6def-4e2d-af74-7c47cd0ade4a
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
2d98a740-581d-41b9-aa0d-a88b9d5ce938
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
5824833b-3c1a-4ad2-bdfd-c31d19e23ed2
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
bdaa0970-413b-4a3e-9e5d-f6dc9d7e0760
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
3b338d89-6cfa-44b8-847e-531531bc9992
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
8782d3b9-ebbd-4644-a3d8-e8725381919b
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
085b0334-e454-4d91-9b8c-4134f9e793f3
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
4bec6bb8-b5c2-4b6f-b2c1-5da5cf92d0d9
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
bf4dc912-e52f-4904-8ebe-9317c1bdd497
version: v1.0
ncalrpc: LRPC-ab403233467220de51
ncalrpc: trkwks
ncacn_np: \\WIN-GHAM948BGPH\pipe\trkwks
ncalrpc: LRPC-ffdca89e29d06012ea
ncalrpc: TSUMRPD_PRINT_DRV_LPC_API
ncalrpc: OLEA1FB51D866AE796E3EB558048452
ncalrpc: LRPC-cceba58de619172be7
ncalrpc: LRPC-935504ba4fc017b471
54b4c689-969a-476f-8dc2-990885e9f562
version: v0.0
ncalrpc: trkwks
ncacn_np: \\WIN-GHAM948BGPH\pipe\trkwks
ncalrpc: LRPC-ffdca89e29d06012ea
ncalrpc: TSUMRPD_PRINT_DRV_LPC_API
ncalrpc: OLEA1FB51D866AE796E3EB558048452
ncalrpc: LRPC-cceba58de619172be7
ncalrpc: LRPC-935504ba4fc017b471
be7f785e-0e3a-4ab7-91de-7e46e443be29
version: v0.0
ncalrpc: trkwks
ncacn_np: \\WIN-GHAM948BGPH\pipe\trkwks
ncalrpc: LRPC-ffdca89e29d06012ea
ncalrpc: TSUMRPD_PRINT_DRV_LPC_API
ncalrpc: OLEA1FB51D866AE796E3EB558048452
ncalrpc: LRPC-cceba58de619172be7
ncalrpc: LRPC-935504ba4fc017b471
0767a036-0d22-48aa-ba69-b619480f38cb
version: v1.0
annotation: PcaSvc
provider: pcasvc.dll
ncalrpc: trkwks
ncacn_np: \\WIN-GHAM948BGPH\pipe\trkwks
ncalrpc: LRPC-ffdca89e29d06012ea
ncalrpc: TSUMRPD_PRINT_DRV_LPC_API
ncalrpc: OLEA1FB51D866AE796E3EB558048452
ncalrpc: LRPC-cceba58de619172be7
ncalrpc: LRPC-935504ba4fc017b471
e40f7b57-7a25-4cd3-a135-7f7d3df9d16b
version: v1.0
annotation: Network Connection Broker server endpoint
ncalrpc: LRPC-ffdca89e29d06012ea
ncalrpc: TSUMRPD_PRINT_DRV_LPC_API
ncalrpc: OLEA1FB51D866AE796E3EB558048452
ncalrpc: LRPC-cceba58de619172be7
ncalrpc: LRPC-935504ba4fc017b471
880fd55e-43b9-11e0-b1a8-cf4edfd72085
version: v1.0
annotation: KAPI Service endpoint
ncalrpc: LRPC-ffdca89e29d06012ea
ncalrpc: TSUMRPD_PRINT_DRV_LPC_API
ncalrpc: OLEA1FB51D866AE796E3EB558048452
ncalrpc: LRPC-cceba58de619172be7
ncalrpc: LRPC-935504ba4fc017b471
5222821f-d5e2-4885-84f1-5f6185a0ec41
version: v1.0
annotation: Network Connection Broker server endpoint for NCB Reset module
ncalrpc: LRPC-cceba58de619172be7
ncalrpc: LRPC-935504ba4fc017b471
30adc50c-5cbc-46ce-9a0e-91914789e23c
version: v1.0
annotation: NRP server endpoint
provider: nrpsrv.dll
ncalrpc: LRPC-d41e89fbe9bc4c8ed9
ncalrpc: LRPC-48703ecc4c9eff44ad
ncalrpc: LRPC-5395b5af1fedd45257
ncalrpc: dhcpcsvc
ncalrpc: dhcpcsvc6
ncacn_ip_tcp: 23.158.72.18:49665
ncacn_np: \\WIN-GHAM948BGPH\pipe\eventlog
ncalrpc: eventlog
a500d4c6-0dd1-4543-bc0c-d5f93486eaf8
version: v1.0
ncalrpc: LRPC-48703ecc4c9eff44ad
ncalrpc: LRPC-5395b5af1fedd45257
ncalrpc: dhcpcsvc
ncalrpc: dhcpcsvc6
ncacn_ip_tcp: 23.158.72.18:49665
ncacn_np: \\WIN-GHAM948BGPH\pipe\eventlog
ncalrpc: eventlog
3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5
version: v1.0
annotation: DHCP Client LRPC Endpoint
provider: dhcpcsvc.dll
ncalrpc: dhcpcsvc
ncalrpc: dhcpcsvc6
ncacn_ip_tcp: 23.158.72.18:49665
ncacn_np: \\WIN-GHAM948BGPH\pipe\eventlog
ncalrpc: eventlog
3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6
version: v1.0
annotation: DHCPv6 Client LRPC Endpoint
provider: dhcpcsvc6.dll
ncalrpc: dhcpcsvc6
ncacn_ip_tcp: 23.158.72.18:49665
ncacn_np: \\WIN-GHAM948BGPH\pipe\eventlog
ncalrpc: eventlog
f6beaff7-1e19-4fbb-9f8f-b89e2018337c
version: v1.0
annotation: Event log TCPIP
protocol: [MS-EVEN6]: EventLog Remoting Protocol
provider: wevtsvc.dll
ncacn_ip_tcp: 23.158.72.18:49665
ncacn_np: \\WIN-GHAM948BGPH\pipe\eventlog
ncalrpc: eventlog
a4b8d482-80ce-40d6-934d-b22a01a44fe7
version: v1.0
annotation: LicenseManager
ncalrpc: LicenseServiceEndpoint
3473dd4d-2e88-4006-9cba-22570909dd10
version: v5.256
annotation: WinHttp Auto-Proxy Service
ncalrpc: OLE7FA166D743EC05F4DAF893CFAA9F
ncalrpc: LRPC-ce033236750dde1943
7ea70bcf-48af-4f6a-8968-6a440754d5fa
version: v1.0
annotation: NSI server endpoint
provider: nsisvc.dll
ncalrpc: LRPC-ce033236750dde1943
f3f09ffd-fbcf-4291-944d-70ad6e0e73bb
version: v1.0
ncalrpc: LRPC-4935702a5c09effbc6
c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1
version: v1.0
annotation: Adh APIs
ncalrpc: senssvc
ncalrpc: LRPC-7fae78aaa1df98f6f0
ncalrpc: IUserProfile2
ncalrpc: LRPC-73d412df2255b79524
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\WIN-GHAM948BGPH\PIPE\atsvc
ncacn_ip_tcp: 23.158.72.18:49666
ncacn_np: \\WIN-GHAM948BGPH\pipe\SessEnvPublicRpc
ncalrpc: SessEnvPrivateRpc
ncalrpc: DeviceSetupManager
ncalrpc: LRPC-0a54d87edf16f835aa
ncalrpc: LRPC-3096683bcfe09b80ef
ncalrpc: OLED9C4BDB74FF28DE3112A3473017E
c36be077-e14b-4fe9-8abc-e856ef4f048b
version: v1.0
annotation: Proxy Manager client server endpoint
ncalrpc: senssvc
ncalrpc: LRPC-7fae78aaa1df98f6f0
ncalrpc: IUserProfile2
ncalrpc: LRPC-73d412df2255b79524
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\WIN-GHAM948BGPH\PIPE\atsvc
ncacn_ip_tcp: 23.158.72.18:49666
ncacn_np: \\WIN-GHAM948BGPH\pipe\SessEnvPublicRpc
ncalrpc: SessEnvPrivateRpc
ncalrpc: DeviceSetupManager
ncalrpc: LRPC-0a54d87edf16f835aa
ncalrpc: LRPC-3096683bcfe09b80ef
ncalrpc: OLED9C4BDB74FF28DE3112A3473017E
2e6035b2-e8f1-41a7-a044-656b439c4c34
version: v1.0
annotation: Proxy Manager provider server endpoint
ncalrpc: senssvc
ncalrpc: LRPC-7fae78aaa1df98f6f0
ncalrpc: IUserProfile2
ncalrpc: LRPC-73d412df2255b79524
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\WIN-GHAM948BGPH\PIPE\atsvc
ncacn_ip_tcp: 23.158.72.18:49666
ncacn_np: \\WIN-GHAM948BGPH\pipe\SessEnvPublicRpc
ncalrpc: SessEnvPrivateRpc
ncalrpc: DeviceSetupManager
ncalrpc: LRPC-0a54d87edf16f835aa
ncalrpc: LRPC-3096683bcfe09b80ef
ncalrpc: OLED9C4BDB74FF28DE3112A3473017E
552d076a-cb29-4e44-8b6a-d15e59e2c0af
version: v1.0
annotation: IP Transition Configuration endpoint
provider: iphlpsvc.dll
ncalrpc: senssvc
ncalrpc: LRPC-7fae78aaa1df98f6f0
ncalrpc: IUserProfile2
ncalrpc: LRPC-73d412df2255b79524
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\WIN-GHAM948BGPH\PIPE\atsvc
ncacn_ip_tcp: 23.158.72.18:49666
ncacn_np: \\WIN-GHAM948BGPH\pipe\SessEnvPublicRpc
ncalrpc: SessEnvPrivateRpc
ncalrpc: DeviceSetupManager
ncalrpc: LRPC-0a54d87edf16f835aa
ncalrpc: LRPC-3096683bcfe09b80ef
ncalrpc: OLED9C4BDB74FF28DE3112A3473017E
0d3c7f20-1c8d-4654-a1b3-51563b298bda
version: v1.0
annotation: UserMgrCli
ncalrpc: LRPC-7fae78aaa1df98f6f0
ncalrpc: IUserProfile2
ncalrpc: LRPC-73d412df2255b79524
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\WIN-GHAM948BGPH\PIPE\atsvc
ncacn_ip_tcp: 23.158.72.18:49666
ncacn_np: \\WIN-GHAM948BGPH\pipe\SessEnvPublicRpc
ncalrpc: SessEnvPrivateRpc
ncalrpc: DeviceSetupManager
ncalrpc: LRPC-0a54d87edf16f835aa
ncalrpc: LRPC-3096683bcfe09b80ef
ncalrpc: OLED9C4BDB74FF28DE3112A3473017E
b18fbab6-56f8-4702-84e0-41053293a869
version: v1.0
annotation: UserMgrCli
ncalrpc: LRPC-7fae78aaa1df98f6f0
ncalrpc: IUserProfile2
ncalrpc: LRPC-73d412df2255b79524
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\WIN-GHAM948BGPH\PIPE\atsvc
ncacn_ip_tcp: 23.158.72.18:49666
ncacn_np: \\WIN-GHAM948BGPH\pipe\SessEnvPublicRpc
ncalrpc: SessEnvPrivateRpc
ncalrpc: DeviceSetupManager
ncalrpc: LRPC-0a54d87edf16f835aa
ncalrpc: LRPC-3096683bcfe09b80ef
ncalrpc: OLED9C4BDB74FF28DE3112A3473017E
3a9ef155-691d-4449-8d05-09ad57031823
version: v1.0
ncalrpc: LRPC-73d412df2255b79524
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\WIN-GHAM948BGPH\PIPE\atsvc
ncacn_ip_tcp: 23.158.72.18:49666
ncacn_np: \\WIN-GHAM948BGPH\pipe\SessEnvPublicRpc
ncalrpc: SessEnvPrivateRpc
ncalrpc: DeviceSetupManager
ncalrpc: LRPC-0a54d87edf16f835aa
ncalrpc: LRPC-3096683bcfe09b80ef
ncalrpc: OLED9C4BDB74FF28DE3112A3473017E
86d35949-83c9-4044-b424-db363231fd0c
version: v1.0
protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol
provider: schedsvc.dll
ncalrpc: LRPC-73d412df2255b79524
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\WIN-GHAM948BGPH\PIPE\atsvc
ncacn_ip_tcp: 23.158.72.18:49666
ncacn_np: \\WIN-GHAM948BGPH\pipe\SessEnvPublicRpc
ncalrpc: SessEnvPrivateRpc
ncalrpc: DeviceSetupManager
ncalrpc: LRPC-0a54d87edf16f835aa
ncalrpc: LRPC-3096683bcfe09b80ef
ncalrpc: OLED9C4BDB74FF28DE3112A3473017E
33d84484-3626-47ee-8c6f-e7e98b113be1
version: v2.0
ncalrpc: LRPC-73d412df2255b79524
ncalrpc: ubpmtaskhostchannel
ncacn_np: \\WIN-GHAM948BGPH\PIPE\atsvc
ncacn_ip_tcp: 23.158.72.18:49666
ncacn_np: \\WIN-GHAM948BGPH\pipe\SessEnvPublicRpc
ncalrpc: SessEnvPrivateRpc
ncalrpc: DeviceSetupManager
ncalrpc: LRPC-0a54d87edf16f835aa
ncalrpc: LRPC-3096683bcfe09b80ef
ncalrpc: OLED9C4BDB74FF28DE3112A3473017E
378e52b0-c0a9-11cf-822d-00aa0051e40f
version: v1.0
protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol
provider: taskcomp.dll
ncacn_np: \\WIN-GHAM948BGPH\PIPE\atsvc
ncacn_ip_tcp: 23.158.72.18:49666
ncacn_np: \\WIN-GHAM948BGPH\pipe\SessEnvPublicRpc
ncalrpc: SessEnvPrivateRpc
ncalrpc: DeviceSetupManager
ncalrpc: LRPC-0a54d87edf16f835aa
ncalrpc: LRPC-3096683bcfe09b80ef
ncalrpc: OLED9C4BDB74FF28DE3112A3473017E
1ff70682-0a51-30e8-076d-740be8cee98b
version: v1.0
protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol
provider: taskcomp.dll
ncacn_np: \\WIN-GHAM948BGPH\PIPE\atsvc
ncacn_ip_tcp: 23.158.72.18:49666
ncacn_np: \\WIN-GHAM948BGPH\pipe\SessEnvPublicRpc
ncalrpc: SessEnvPrivateRpc
ncalrpc: DeviceSetupManager
ncalrpc: LRPC-0a54d87edf16f835aa
ncalrpc: LRPC-3096683bcfe09b80ef
ncalrpc: OLED9C4BDB74FF28DE3112A3473017E
0a74ef1c-41a4-4e06-83ae-dc74fb1cdd53
version: v1.0
provider: schedsvc.dll
ncacn_ip_tcp: 23.158.72.18:49666
ncacn_np: \\WIN-GHAM948BGPH\pipe\SessEnvPublicRpc
ncalrpc: SessEnvPrivateRpc
ncalrpc: DeviceSetupManager
ncalrpc: LRPC-0a54d87edf16f835aa
ncalrpc: LRPC-3096683bcfe09b80ef
ncalrpc: OLED9C4BDB74FF28DE3112A3473017E
2eb08e3e-639f-4fba-97b1-14f878961076
version: v1.0
annotation: Group Policy RPC Interface
provider: gpsvc.dll
ncalrpc: LRPC-4f12f547e1ae7aef50
29770a8f-829b-4158-90a2-78cd488501f7
version: v1.0
ncacn_ip_tcp: 23.158.72.18:49666
ncacn_np: \\WIN-GHAM948BGPH\pipe\SessEnvPublicRpc
ncalrpc: SessEnvPrivateRpc
ncalrpc: DeviceSetupManager
ncalrpc: LRPC-0a54d87edf16f835aa
ncalrpc: LRPC-3096683bcfe09b80ef
ncalrpc: OLED9C4BDB74FF28DE3112A3473017E
30b044a5-a225-43f0-b3a4-e060df91f9c1
version: v1.0
provider: certprop.dll
ncalrpc: LRPC-3096683bcfe09b80ef
ncalrpc: OLED9C4BDB74FF28DE3112A3473017E
2fb92682-6599-42dc-ae13-bd2ca89bd11c
version: v1.0
annotation: Fw APIs
provider: MPSSVC.dll
ncalrpc: LRPC-d6f48087ae5d0f54c7
ncalrpc: LRPC-7f7d8b132e9ecf1925
ncalrpc: LRPC-66ed9f78e510384f50
f47433c3-3e9d-4157-aad4-83aa1f5c2d4c
version: v1.0
annotation: Fw APIs
ncalrpc: LRPC-d6f48087ae5d0f54c7
ncalrpc: LRPC-7f7d8b132e9ecf1925
ncalrpc: LRPC-66ed9f78e510384f50
7f9d11bf-7fb9-436b-a812-b2d50c5d4c03
version: v1.0
annotation: Fw APIs
provider: MPSSVC.dll
ncalrpc: LRPC-d6f48087ae5d0f54c7
ncalrpc: LRPC-7f7d8b132e9ecf1925
ncalrpc: LRPC-66ed9f78e510384f50
dd490425-5325-4565-b774-7e27d6c09c24
version: v1.0
annotation: Base Firewall Engine API
provider: BFE.DLL
ncalrpc: LRPC-7f7d8b132e9ecf1925
ncalrpc: LRPC-66ed9f78e510384f50
df4df73a-c52d-4e3a-8003-8437fdf8302a
version: v0.0
annotation: WM_WindowManagerRPC\Server
ncalrpc: LRPC-66ed9f78e510384f50
7f1343fe-50a9-4927-a778-0c5859517bac
version: v1.0
annotation: DfsDs service
ncacn_np: \\WIN-GHAM948BGPH\PIPE\wkssvc
ncalrpc: nlaapi
ncalrpc: nlaplg
eb081a0d-10ee-478a-a1dd-50995283e7a8
version: v3.0
annotation: Witness Client Test Interface
ncalrpc: nlaapi
ncalrpc: nlaplg
f2c9b409-c1c9-4100-8639-d8ab1486694a
version: v1.0
annotation: Witness Client Upcall Server
ncalrpc: nlaapi
ncalrpc: nlaplg
7aeb6705-3ae6-471a-882d-f39c109edc12
version: v1.0
ncalrpc: LRPC-4ec44339ca7c9b0af6
e7f76134-9ef5-4949-a2d6-3368cc0988f3
version: v1.0
ncalrpc: LRPC-4ec44339ca7c9b0af6
b3781086-6a54-489b-91c8-51d067172ab7
version: v1.0
ncalrpc: LRPC-4ec44339ca7c9b0af6
b37f900a-eae4-4304-a2ab-12bb668c0188
version: v1.0
ncalrpc: LRPC-4ec44339ca7c9b0af6
abfb6ca3-0c5e-4734-9285-0aee72fe8d1c
version: v1.0
ncalrpc: LRPC-4ec44339ca7c9b0af6
76f03f96-cdfd-44fc-a22c-64950a001209
version: v1.0
protocol: [MS-PAR]: Print System Asynchronous Remote Protocol
provider: spoolsv.exe
ncacn_ip_tcp: 23.158.72.18:49667
ncalrpc: LRPC-55408476ece6b870d7
4a452661-8290-4b36-8fbe-7f4093a94978
version: v1.0
provider: spoolsv.exe
ncacn_ip_tcp: 23.158.72.18:49667
ncalrpc: LRPC-55408476ece6b870d7
ae33069b-a2a8-46ee-a235-ddfd339be281
version: v1.0
protocol: [MS-PAN]: Print System Asynchronous Notification Protocol
provider: spoolsv.exe
ncacn_ip_tcp: 23.158.72.18:49667
ncalrpc: LRPC-55408476ece6b870d7
0b6edbfa-4a24-4fc6-8a23-942b1eca65d1
version: v1.0
protocol: [MS-PAN]: Print System Asynchronous Notification Protocol
provider: spoolsv.exe
ncacn_ip_tcp: 23.158.72.18:49667
ncalrpc: LRPC-55408476ece6b870d7
12345678-1234-abcd-ef00-0123456789ab
version: v1.0
protocol: [MS-RPRN]: Print System Remote Protocol
provider: spoolsv.exe
ncacn_ip_tcp: 23.158.72.18:49667
ncalrpc: LRPC-55408476ece6b870d7
1a0d010f-1c33-432c-b0f5-8cf4e8053099
version: v1.0
annotation: IdSegSrv service
ncalrpc: LRPC-11297c2a117cd98ec8
98716d03-89ac-44c7-bb8c-285824e51c4a
version: v1.0
annotation: XactSrv service
provider: srvsvc.dll
ncalrpc: LRPC-11297c2a117cd98ec8
367abb81-9844-35f1-ad32-98f038001003
version: v2.0
protocol: [MS-SCMR]: Service Control Manager Remote Protocol
provider: services.exe
ncacn_ip_tcp: 23.158.72.18:49669
e38f5360-8572-473e-b696-1b46873beeab
version: v1.0
ncalrpc: LRPC-40bf7bf47c5f519719
4c9dbf19-d39e-4bb9-90ee-8f7179b20283
version: v1.0
ncalrpc: LRPC-40bf7bf47c5f519719
c503f532-443a-4c69-8300-ccd1fbdb3839
version: v2.0
ncalrpc: LRPC-5fdfb3dc935e006f39
ncalrpc: OLE9F91486C55138E1E06C261CAFB00
51a227ae-825b-41f2-b4a9-1ac9557a1018
version: v1.0
annotation: Ngc Pop Key Service
ncacn_ip_tcp: 23.158.72.18:49691
ncalrpc: samss lpc
ncalrpc: SidKey Local End Point
ncalrpc: protected_storage
ncalrpc: lsasspirpc
ncalrpc: lsapolicylookup
ncalrpc: LSA_EAS_ENDPOINT
ncalrpc: LSA_IDPEXT_ENDPOINT
ncalrpc: lsacap
ncalrpc: LSARPC_ENDPOINT
ncalrpc: securityevent
ncalrpc: audit
ncacn_np: \\WIN-GHAM948BGPH\pipe\lsass
8fb74744-b2ff-4c00-be0d-9ef9a191fe1b
version: v1.0
annotation: Ngc Pop Key Service
ncacn_ip_tcp: 23.158.72.18:49691
ncalrpc: samss lpc
ncalrpc: SidKey Local End Point
ncalrpc: protected_storage
ncalrpc: lsasspirpc
ncalrpc: lsapolicylookup
ncalrpc: LSA_EAS_ENDPOINT
ncalrpc: LSA_IDPEXT_ENDPOINT
ncalrpc: lsacap
ncalrpc: LSARPC_ENDPOINT
ncalrpc: securityevent
ncalrpc: audit
ncacn_np: \\WIN-GHAM948BGPH\pipe\lsass
b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86
version: v2.0
annotation: KeyIso
ncacn_ip_tcp: 23.158.72.18:49691
ncalrpc: samss lpc
ncalrpc: SidKey Local End Point
ncalrpc: protected_storage
ncalrpc: lsasspirpc
ncalrpc: lsapolicylookup
ncalrpc: LSA_EAS_ENDPOINT
ncalrpc: LSA_IDPEXT_ENDPOINT
ncalrpc: lsacap
ncalrpc: LSARPC_ENDPOINT
ncalrpc: securityevent
ncalrpc: audit
ncacn_np: \\WIN-GHAM948BGPH\pipe\lsass
12345778-1234-abcd-ef00-0123456789ac
version: v1.0
protocol: [MS-SAMR]: Security Account Manager (SAM) Remote Protocol
provider: samsrv.dll
ncacn_ip_tcp: 23.158.72.18:49691
ncalrpc: samss lpc
ncalrpc: SidKey Local End Point
ncalrpc: protected_storage
ncalrpc: lsasspirpc
ncalrpc: lsapolicylookup
ncalrpc: LSA_EAS_ENDPOINT
ncalrpc: LSA_IDPEXT_ENDPOINT
ncalrpc: lsacap
ncalrpc: LSARPC_ENDPOINT
ncalrpc: securityevent
ncalrpc: audit
ncacn_np: \\WIN-GHAM948BGPH\pipe\lsass
4b112204-0e19-11d3-b42b-0000f81feb9f
version: v1.0
provider: ssdpsrv.dll
ncalrpc: LRPC-47f26af5f6b3c6c371
12e65dd8-887f-41ef-91bf-8d816c42c2e7
version: v1.0
annotation: Secure Desktop LRPC interface
provider: winlogon.exe
ncalrpc: WMsgKRpc01C82702
b1ef227e-dfa5-421e-82bb-67a6a129c496
version: v0.0
ncalrpc: LRPC-896096e85565c3a33f
ncalrpc: OLEDE19582C27A471D7885854DA567C
0fc77b1a-95d8-4a2e-a0c0-cff54237462b
version: v0.0
ncalrpc: LRPC-896096e85565c3a33f
ncalrpc: OLEDE19582C27A471D7885854DA567C
8ec21e98-b5ce-4916-a3d6-449fa428a007
version: v0.0
ncalrpc: LRPC-896096e85565c3a33f
ncalrpc: OLEDE19582C27A471D7885854DA567C
923c9623-db7f-4b34-9e6d-e86580f8ca2a
version: v1.0
ncalrpc: LRPC-4895e8fadf004a9dc6
ncalrpc: OLECDAD2B831BB1AEB0C4F19D1A35CA
0c53aa2e-fb1c-49c5-bfb6-c54f8e5857cd
version: v1.0
ncalrpc: LRPC-4895e8fadf004a9dc6
ncalrpc: OLECDAD2B831BB1AEB0C4F19D1A35CA
d2716e94-25cb-4820-bc15-537866578562
version: v1.0
ncalrpc: LRPC-4895e8fadf004a9dc6
ncalrpc: OLECDAD2B831BB1AEB0C4F19D1A35CA
369832658 | 2024-10-29T11:51:57.971415
137 /
udp
NetBIOS Response:
Server Name: WIN-GHAM948BGPH
MAC Address: 0C:C4:7A:85:CA:40
Names:
WIN-GHAM948BGPH <0x20>
WIN-GHAM948BGPH <0x0>
WORKGROUP <0x0>
MAC Addresses
0C:C4:7A:85:CA:40
OUI: 0C:C4:7A
Organization: Super Micro Computer, Inc.
Assignment: MA-L
Registration Date: 2013-10-24
-790859001 | 2024-11-02T10:44:16.973557
443 /
tcp
HTTP/1.1 200 OK
Server: nginx
Date: Sat, 02 Nov 2024 10:45:13 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
X-Powered-By: PHP/5.2.17
SSL Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
03:2a:25:14:39:c2:c9:98:6b:fe:4b:34:c9:a4:9e:66:c7:ff
Signature Algorithm: sha256WithRSAEncryption
Issuer: C=US, O=Let's Encrypt, CN=R10
Validity
Not Before: Oct 8 10:18:09 2024 GMT
Not After : Jan 6 10:18:08 2025 GMT
Subject: CN=game.jerald.cc
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:c3:70:a2:28:d4:b0:7c:b7:04:5d:d7:80:f2:bf:
23:ce:f2:23:21:bb:69:c2:8f:db:15:25:a9:e3:aa:
05:05:43:60:e4:f0:59:2c:90:9a:3f:c5:a0:b8:45:
d5:a0:44:59:ba:e4:d0:3f:62:36:b6:78:6c:3a:46:
bc:8c:04:c6:4c:ab:4a:35:5e:ce:fa:aa:2d:c9:e4:
48:42:95:28:52:6d:ec:38:e6:6b:38:5b:c0:e8:0e:
2e:4e:25:4a:46:3a:33:67:2f:5d:65:57:88:7d:62:
39:82:1c:9b:56:ab:8b:34:81:d5:91:2d:4c:67:4a:
a2:d2:f7:70:8e:b0:78:df:4c:65:69:19:a8:ad:e6:
95:85:c2:a4:05:90:0d:c9:48:bd:01:8e:81:32:da:
b2:5e:09:42:2b:a7:39:e9:05:50:73:db:66:83:a7:
c1:4c:99:5a:64:17:eb:36:2b:68:ce:9c:d9:72:5d:
81:c8:2c:30:d3:d4:78:1b:9c:3f:d7:8f:2e:0f:9b:
01:15:6a:f3:a1:c6:de:b3:45:43:f6:79:58:2a:fd:
aa:e1:fc:97:0f:8c:e4:64:c5:36:b6:12:ad:2a:8d:
d6:e9:5f:31:a3:1a:2a:8b:fb:42:18:f9:8a:23:31:
68:76:67:71:b2:5e:58:b4:7a:aa:2a:0e:fb:b8:da:
f2:af
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
X509v3 Extended Key Usage:
TLS Web Server Authentication, TLS Web Client Authentication
X509v3 Basic Constraints: critical
CA:FALSE
X509v3 Subject Key Identifier:
15:1E:89:AC:45:9F:52:01:AA:47:C8:C4:5D:C8:0D:88:33:3F:88:D4
X509v3 Authority Key Identifier:
BB:BC:C3:47:A5:E4:BC:A9:C6:C3:A4:72:0C:10:8D:A2:35:E1:C8:E8
Authority Information Access:
OCSP - URI:http://r10.o.lencr.org
CA Issuers - URI:http://r10.i.lencr.org/
X509v3 Subject Alternative Name:
DNS:game.jerald.cc
X509v3 Certificate Policies:
Policy: 2.23.140.1.2.1
CT Precertificate SCTs:
Signed Certificate Timestamp:
Version : v1 (0x0)
Log ID : E6:D2:31:63:40:77:8C:C1:10:41:06:D7:71:B9:CE:C1:
D2:40:F6:96:84:86:FB:BA:87:32:1D:FD:1E:37:8E:50
Timestamp : Oct 8 11:16:39.623 2024 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:46:02:21:00:C8:6E:18:9C:D7:68:FB:F9:3D:6A:76:
32:54:03:97:7F:B8:66:23:CB:43:89:FC:1F:8D:01:62:
89:4A:A7:CB:FD:02:21:00:8E:E3:55:2F:E1:F1:69:17:
32:87:64:A2:BB:30:59:53:34:03:3B:CA:34:CF:84:05:
D7:41:0D:9B:A2:7A:8A:7A
Signed Certificate Timestamp:
Version : v1 (0x0)
Log ID : CF:11:56:EE:D5:2E:7C:AF:F3:87:5B:D9:69:2E:9B:E9:
1A:71:67:4A:B0:17:EC:AC:01:D2:5B:77:CE:CC:3B:08
Timestamp : Oct 8 11:16:39.690 2024 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:45:02:20:58:86:3B:B2:2B:7C:91:25:C8:DE:A7:B9:
5C:B1:62:E3:1F:5E:EC:48:D2:25:79:97:99:20:E3:AE:
5B:CC:CD:93:02:21:00:93:B5:58:5D:6F:68:C5:35:CA:
60:8B:8A:3B:B5:1E:29:30:60:F7:30:F9:88:CD:8D:2F:
D7:FA:20:3C:A3:82:A9
Signature Algorithm: sha256WithRSAEncryption
Signature Value:
97:f8:96:fd:2a:79:6c:91:7d:04:ac:f2:26:31:cd:6e:84:f8:
d7:74:b4:e1:c0:31:4b:f2:2d:2b:25:11:25:91:a6:07:86:e5:
c2:29:63:1b:b7:f7:ba:34:21:0c:0e:77:cc:af:ec:b5:3f:7a:
5d:e9:46:ec:be:06:0f:27:98:ba:40:0f:ca:22:43:b9:e7:6e:
54:86:6f:b8:59:72:70:81:a8:19:5a:6e:84:64:d1:b1:68:ae:
a5:fa:c3:c3:c1:8e:fe:a2:1b:ea:20:83:9d:b1:5c:14:b8:83:
ec:47:e4:01:4e:fa:ba:51:5d:cf:0f:6d:a9:1f:6b:14:d9:75:
6d:c5:c2:0b:16:ea:f0:db:93:57:06:64:4c:e4:8b:e3:ac:17:
a0:09:e8:95:29:9e:0f:6c:4c:d6:4b:d9:f0:ce:72:e3:cb:e0:
d4:e4:e3:9c:32:18:0e:a5:be:24:df:b1:aa:76:55:eb:56:ef:
ac:a4:5e:6c:a8:f1:95:21:4f:f5:b8:ad:6a:32:bd:d3:68:8b:
2e:58:8c:0f:67:a4:47:6a:73:69:44:ce:37:7f:92:e6:3c:77:
10:43:b8:cc:2e:e1:5d:17:d5:82:5b:75:b0:f7:a2:a2:f7:75:
02:03:9b:2c:36:18:ba:17:10:d0:4c:22:c3:18:8a:bd:80:46:
20:c3:07:5f
1702712738 | 2024-11-02T15:46:43.814936
445 /
tcp
SMB Status:
Authentication: enabled
SMB Version: 1
OS: Windows Server 2016 Datacenter 14393
Software: Windows Server 2016 Datacenter 6.3
Capabilities: extended-security, infolevel-passthru, large-files, large-readx, large-writex, level2-oplocks, lock-and-read, lwio, nt-find, nt-smb, nt-status, rpc-remote-api, unicode
423993957 | 2024-10-12T12:29:44.221033
3306 /
tcp
MySQL:
Protocol Version: 10
Version: 5.6.51-log
Capabilities: 63487
Server Language: 33
Server Status: 2
Extended Server Capabilities: 32895
Authentication Plugin: mysql_native_password
-85749389 | 2024-10-17T06:09:00.182614
8888 /
tcp
HTTP/1.1 404 NOT FOUND
Content-Type: text/html
Content-Length: 138
Server: nginx
Connection: keep-alive
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
X-Content-Type-Options: nosniff
Set-Cookie: 47735be5e67df2546038ab53efaa7e68=eef8c9fc-158f-4620-9ce1-09c19d1123f6.9xCDDmfZUk3x95rWpYkK4-rPvpc; Expires=Fri, 18-Oct-2024 06:09:13 GMT; HttpOnly; Path=/
Date: Thu, 17 Oct 2024 06:09:13 GMT