Hostnames |
autodiscover.aexp.com mail.aexp.com mymail.aexp.com autodiscover.aexp.onmicrosoft.com autodiscover.aexp.mail.onmicrosoft.com namp161-provisioning.internal.outlook.com pod51234.outlook.com pod51234-pri.outlook.com pod51234ip.outlook.com pod51234psh.outlook.com |
Domains | aexp.com onmicrosoft.com outlook.com |
Country | United States |
City | Chicago |
Organization | Microsoft Corporation |
ISP | Microsoft Corporation |
ASN | AS8075 |
Operating System | Windows |
1368866468 | 2024-12-23T06:28:38.66628225 / tcp
220 CH2P161CA0001.outlook.office365.com Microsoft ESMTP MAIL Service ready at Mon, 23 Dec 2024 06:28:28 +0000 [08DD2302CF43DA2C] 250-CH2P161CA0001.outlook.office365.com Hello [224.7.125.189] 250-SIZE 157286400 250-PIPELINING 250-DSN 250-ENHANCEDSTATUSCODES 250-STARTTLS 250-8BITMIME 250-BINARYMIME 250-CHUNKING 250 SMTPUTF8
Certificate: Data: Version: 3 (0x2) Serial Number: 36:26:77:eb:b3:28:f4:df:6f:76:ab:ba:68:44:03:de Signature Algorithm: sha256WithRSAEncryption Issuer: C=US, O=Entrust, Inc., OU=See www.entrust.net\/legal-terms, OU=(c) 2012 Entrust, Inc. - for authorized use only, CN=Entrust Certification Authority - L1K Validity Not Before: Sep 4 17:53:34 2024 GMT Not After : Sep 4 17:53:33 2025 GMT Subject: C=US, ST=New York, L=New York, O=American Express Company, CN=mymail.aexp.com Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (2048 bit) Modulus: 00:ba:46:79:9e:04:d6:ed:51:dc:7c:f3:eb:a4:08: 33:5e:74:bc:20:c0:20:be:c6:7c:a0:a9:5b:37:b2: 9a:b3:4a:a7:dc:49:53:a7:d2:a6:db:de:2b:fe:06: 53:ec:8d:78:13:1d:8d:1c:43:ba:a2:c3:d6:a5:c0: 8e:40:ee:38:f8:1c:3c:d5:57:c4:5f:0f:32:52:14: f8:55:76:f1:e7:e5:c8:ee:5c:8c:45:5b:eb:0b:01: 09:22:72:b8:82:a2:ca:63:27:a8:5e:32:dc:57:b6: 81:68:27:a7:11:ca:c0:df:73:cb:43:45:0d:ff:3d: d0:22:0c:49:02:4a:14:e2:f0:98:8d:52:2c:20:da: e8:c8:6f:1d:c0:0d:bd:96:b9:f2:12:6c:63:3c:92: e9:d6:d5:b0:a2:cd:7b:ec:3d:a9:8a:e0:dc:37:b3: 51:b9:04:10:8f:5f:11:b7:83:a2:d5:84:7f:15:d9: 63:d7:52:62:cc:a3:7f:cd:37:0d:c1:a8:2b:21:7c: 6f:81:37:1c:22:c6:ed:80:56:03:a2:e6:48:cf:48: cb:36:ce:6f:eb:2c:d1:83:8c:7d:aa:9f:bf:01:9a: ca:23:8f:ca:0b:41:d3:5c:03:38:e6:a1:43:d2:65: 11:48:ff:24:67:33:cd:4e:ba:16:84:0f:56:a0:a8: 1f:95 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Basic Constraints: critical CA:FALSE X509v3 Subject Key Identifier: 05:50:22:6C:C3:22:F6:8A:80:68:C2:E1:B0:00:66:A5:06:60:0C:BD X509v3 Authority Key Identifier: 82:A2:70:74:DD:BC:53:3F:CF:7B:D4:F7:CD:7F:A7:60:C6:0A:4C:BF Authority Information Access: OCSP - URI:http://ocsp.entrust.net CA Issuers - URI:http://aia.entrust.net/l1k-chain256.cer X509v3 CRL Distribution Points: Full Name: URI:http://crl.entrust.net/level1k.crl X509v3 Subject Alternative Name: DNS:mymail.aexp.com, DNS:*.pod51234.outlook.com, DNS:autodiscover.aexp.com, DNS:autodiscover.aexp.mail.onmicrosoft.com, DNS:autodiscover.aexp.onmicrosoft.com, DNS:mail.aexp.com, DNS:namp161-provisioning.internal.outlook.com, DNS:pod51234.outlook.com, DNS:pod51234ip.outlook.com, DNS:pod51234-pri.outlook.com, DNS:pod51234psh.outlook.com X509v3 Key Usage: critical Digital Signature, Key Encipherment X509v3 Extended Key Usage: TLS Web Server Authentication, TLS Web Client Authentication X509v3 Certificate Policies: Policy: 2.23.140.1.2.2 CT Precertificate SCTs: Signed Certificate Timestamp: Version : v1 (0x0) Log ID : E6:D2:31:63:40:77:8C:C1:10:41:06:D7:71:B9:CE:C1: D2:40:F6:96:84:86:FB:BA:87:32:1D:FD:1E:37:8E:50 Timestamp : Sep 4 17:53:34.905 2024 GMT Extensions: none Signature : ecdsa-with-SHA256 30:45:02:20:58:4D:A3:D6:02:B3:2D:14:E8:6E:22:A5: C2:4C:C6:4A:77:80:02:9A:B8:FB:70:79:87:72:3C:F6: 04:0C:BD:4A:02:21:00:8C:71:90:BE:BE:20:DE:17:AD: F1:A3:BD:F5:B7:3B:92:4B:43:43:14:F1:42:E2:0E:AE: 23:A7:96:2A:C9:1B:E5 Signed Certificate Timestamp: Version : v1 (0x0) Log ID : 0D:E1:F2:30:2B:D3:0D:C1:40:62:12:09:EA:55:2E:FC: 47:74:7C:B1:D7:E9:30:EF:0E:42:1E:B4:7E:4E:AA:34 Timestamp : Sep 4 17:53:34.913 2024 GMT Extensions: none Signature : ecdsa-with-SHA256 30:45:02:21:00:95:79:F6:63:BF:BA:8A:08:ED:98:C7: 8D:31:43:B2:8C:B1:B6:29:07:29:C7:97:DB:7F:36:34: 2A:8C:DD:ED:10:02:20:44:9A:37:8C:9E:9B:9E:A4:2C: 42:BA:D7:65:69:16:39:5C:20:BC:9A:D7:65:EA:BB:8B: 5E:C1:00:72:13:9A:39 Signed Certificate Timestamp: Version : v1 (0x0) Log ID : DD:DC:CA:34:95:D7:E1:16:05:E7:95:32:FA:C7:9F:F8: 3D:1C:50:DF:DB:00:3A:14:12:76:0A:2C:AC:BB:C8:2A Timestamp : Sep 4 17:53:34.934 2024 GMT Extensions: none Signature : ecdsa-with-SHA256 30:46:02:21:00:F6:1E:48:A4:C6:ED:73:69:FA:BC:66: A0:37:7C:B6:CE:D8:5C:95:14:22:13:15:C2:C7:69:3D: FD:DF:41:24:EE:02:21:00:DD:75:14:D2:21:FE:5C:B2: A8:68:FC:FE:F4:8D:45:8D:E2:12:65:18:36:E0:85:8C: F9:B3:41:84:A3:D3:38:7C Signature Algorithm: sha256WithRSAEncryption Signature Value: 54:4a:da:2e:61:23:7a:f3:e1:06:77:9c:0f:42:48:8c:c7:f5: c8:6d:a1:2a:3b:fc:e4:d4:9e:65:b9:a4:dc:82:95:d5:a0:12: 58:de:e2:41:73:f2:66:19:cd:6b:6c:b8:9a:b3:7e:f9:7f:18: 9c:91:f8:8a:0b:7b:13:5c:0d:75:e2:1c:21:17:ec:07:0d:94: e2:86:95:4d:b9:f9:c0:97:35:e6:ee:0c:53:68:a7:31:aa:7c: ce:ba:c8:94:76:bd:c3:4a:89:fd:5f:a9:09:a8:c8:b9:8d:49: e7:ac:20:6e:30:52:31:0c:05:76:f3:58:8f:da:1d:1d:72:73: 0f:a6:69:c1:53:13:0a:70:4d:52:94:90:ef:6a:79:40:fa:32: a3:7a:ea:b2:68:74:6c:4f:66:11:21:49:50:7d:94:54:47:f2: ef:b9:90:46:91:cf:88:51:98:95:9e:d6:c9:20:4c:6b:bc:63: 5b:96:39:e4:86:83:59:8a:1d:f1:31:9c:00:1f:45:42:ab:28: 85:80:c8:b7:52:4e:66:55:48:32:0c:d6:33:37:c5:d0:81:4d: 8f:e5:b0:5a:1b:c4:f7:d9:66:99:cc:99:08:06:30:38:3d:0f: 87:2f:18:01:b7:c7:59:73:55:50:7c:f1:62:a4:8a:9e:c8:c2: 3b:e8:14:b4
-730641974 | 2024-12-28T13:27:17.24075380 / tcp
HTTP/1.1 301 Moved Permanently Cache-Control: no-cache Pragma: no-cache Location: https://52.96.71.145/owa/ Server: Microsoft-IIS/10.0 request-id: 8ca13699-77da-7586-4190-bf51a534afa0 X-FEServer: CH2P161CA0003 X-RequestId: a72adec8-5880-4aaf-a430-3f055a3c250a X-FEProxyInfo: CH2P161CA0003.NAMP161.PROD.OUTLOOK.COM X-FEEFZInfo: MDW MS-CV: mTahjNp3hnVBkL9RpTSvoA.0 X-Powered-By: ASP.NET X-FEServer: CH2P161CA0003 Date: Sat, 28 Dec 2024 13:27:16 GMT Connection: close Content-Length: 0
1504902275 | 2024-12-22T23:54:33.448404110 / tcp
+OK The Microsoft Exchange POP3 service is ready. [QwBIADIAUAAxADYAMQBDAEEAMAAwADAAMQAuAE4AQQBNAFAAMQA2ADEALgBQAFIATwBEAC4ATwBVAFQATABPAE8ASwAuAEMATwBNAA==] +OK TOP UIDL STLS .
Certificate: Data: Version: 3 (0x2) Serial Number: 36:26:77:eb:b3:28:f4:df:6f:76:ab:ba:68:44:03:de Signature Algorithm: sha256WithRSAEncryption Issuer: C=US, O=Entrust, Inc., OU=See www.entrust.net\/legal-terms, OU=(c) 2012 Entrust, Inc. - for authorized use only, CN=Entrust Certification Authority - L1K Validity Not Before: Sep 4 17:53:34 2024 GMT Not After : Sep 4 17:53:33 2025 GMT Subject: C=US, ST=New York, L=New York, O=American Express Company, CN=mymail.aexp.com Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (2048 bit) Modulus: 00:ba:46:79:9e:04:d6:ed:51:dc:7c:f3:eb:a4:08: 33:5e:74:bc:20:c0:20:be:c6:7c:a0:a9:5b:37:b2: 9a:b3:4a:a7:dc:49:53:a7:d2:a6:db:de:2b:fe:06: 53:ec:8d:78:13:1d:8d:1c:43:ba:a2:c3:d6:a5:c0: 8e:40:ee:38:f8:1c:3c:d5:57:c4:5f:0f:32:52:14: f8:55:76:f1:e7:e5:c8:ee:5c:8c:45:5b:eb:0b:01: 09:22:72:b8:82:a2:ca:63:27:a8:5e:32:dc:57:b6: 81:68:27:a7:11:ca:c0:df:73:cb:43:45:0d:ff:3d: d0:22:0c:49:02:4a:14:e2:f0:98:8d:52:2c:20:da: e8:c8:6f:1d:c0:0d:bd:96:b9:f2:12:6c:63:3c:92: e9:d6:d5:b0:a2:cd:7b:ec:3d:a9:8a:e0:dc:37:b3: 51:b9:04:10:8f:5f:11:b7:83:a2:d5:84:7f:15:d9: 63:d7:52:62:cc:a3:7f:cd:37:0d:c1:a8:2b:21:7c: 6f:81:37:1c:22:c6:ed:80:56:03:a2:e6:48:cf:48: cb:36:ce:6f:eb:2c:d1:83:8c:7d:aa:9f:bf:01:9a: ca:23:8f:ca:0b:41:d3:5c:03:38:e6:a1:43:d2:65: 11:48:ff:24:67:33:cd:4e:ba:16:84:0f:56:a0:a8: 1f:95 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Basic Constraints: critical CA:FALSE X509v3 Subject Key Identifier: 05:50:22:6C:C3:22:F6:8A:80:68:C2:E1:B0:00:66:A5:06:60:0C:BD X509v3 Authority Key Identifier: 82:A2:70:74:DD:BC:53:3F:CF:7B:D4:F7:CD:7F:A7:60:C6:0A:4C:BF Authority Information Access: OCSP - URI:http://ocsp.entrust.net CA Issuers - URI:http://aia.entrust.net/l1k-chain256.cer X509v3 CRL Distribution Points: Full Name: URI:http://crl.entrust.net/level1k.crl X509v3 Subject Alternative Name: DNS:mymail.aexp.com, DNS:*.pod51234.outlook.com, DNS:autodiscover.aexp.com, DNS:autodiscover.aexp.mail.onmicrosoft.com, DNS:autodiscover.aexp.onmicrosoft.com, DNS:mail.aexp.com, DNS:namp161-provisioning.internal.outlook.com, DNS:pod51234.outlook.com, DNS:pod51234ip.outlook.com, DNS:pod51234-pri.outlook.com, DNS:pod51234psh.outlook.com X509v3 Key Usage: critical Digital Signature, Key Encipherment X509v3 Extended Key Usage: TLS Web Server Authentication, TLS Web Client Authentication X509v3 Certificate Policies: Policy: 2.23.140.1.2.2 CT Precertificate SCTs: Signed Certificate Timestamp: Version : v1 (0x0) Log ID : E6:D2:31:63:40:77:8C:C1:10:41:06:D7:71:B9:CE:C1: D2:40:F6:96:84:86:FB:BA:87:32:1D:FD:1E:37:8E:50 Timestamp : Sep 4 17:53:34.905 2024 GMT Extensions: none Signature : ecdsa-with-SHA256 30:45:02:20:58:4D:A3:D6:02:B3:2D:14:E8:6E:22:A5: C2:4C:C6:4A:77:80:02:9A:B8:FB:70:79:87:72:3C:F6: 04:0C:BD:4A:02:21:00:8C:71:90:BE:BE:20:DE:17:AD: F1:A3:BD:F5:B7:3B:92:4B:43:43:14:F1:42:E2:0E:AE: 23:A7:96:2A:C9:1B:E5 Signed Certificate Timestamp: Version : v1 (0x0) Log ID : 0D:E1:F2:30:2B:D3:0D:C1:40:62:12:09:EA:55:2E:FC: 47:74:7C:B1:D7:E9:30:EF:0E:42:1E:B4:7E:4E:AA:34 Timestamp : Sep 4 17:53:34.913 2024 GMT Extensions: none Signature : ecdsa-with-SHA256 30:45:02:21:00:95:79:F6:63:BF:BA:8A:08:ED:98:C7: 8D:31:43:B2:8C:B1:B6:29:07:29:C7:97:DB:7F:36:34: 2A:8C:DD:ED:10:02:20:44:9A:37:8C:9E:9B:9E:A4:2C: 42:BA:D7:65:69:16:39:5C:20:BC:9A:D7:65:EA:BB:8B: 5E:C1:00:72:13:9A:39 Signed Certificate Timestamp: Version : v1 (0x0) Log ID : DD:DC:CA:34:95:D7:E1:16:05:E7:95:32:FA:C7:9F:F8: 3D:1C:50:DF:DB:00:3A:14:12:76:0A:2C:AC:BB:C8:2A Timestamp : Sep 4 17:53:34.934 2024 GMT Extensions: none Signature : ecdsa-with-SHA256 30:46:02:21:00:F6:1E:48:A4:C6:ED:73:69:FA:BC:66: A0:37:7C:B6:CE:D8:5C:95:14:22:13:15:C2:C7:69:3D: FD:DF:41:24:EE:02:21:00:DD:75:14:D2:21:FE:5C:B2: A8:68:FC:FE:F4:8D:45:8D:E2:12:65:18:36:E0:85:8C: F9:B3:41:84:A3:D3:38:7C Signature Algorithm: sha256WithRSAEncryption Signature Value: 54:4a:da:2e:61:23:7a:f3:e1:06:77:9c:0f:42:48:8c:c7:f5: c8:6d:a1:2a:3b:fc:e4:d4:9e:65:b9:a4:dc:82:95:d5:a0:12: 58:de:e2:41:73:f2:66:19:cd:6b:6c:b8:9a:b3:7e:f9:7f:18: 9c:91:f8:8a:0b:7b:13:5c:0d:75:e2:1c:21:17:ec:07:0d:94: e2:86:95:4d:b9:f9:c0:97:35:e6:ee:0c:53:68:a7:31:aa:7c: ce:ba:c8:94:76:bd:c3:4a:89:fd:5f:a9:09:a8:c8:b9:8d:49: e7:ac:20:6e:30:52:31:0c:05:76:f3:58:8f:da:1d:1d:72:73: 0f:a6:69:c1:53:13:0a:70:4d:52:94:90:ef:6a:79:40:fa:32: a3:7a:ea:b2:68:74:6c:4f:66:11:21:49:50:7d:94:54:47:f2: ef:b9:90:46:91:cf:88:51:98:95:9e:d6:c9:20:4c:6b:bc:63: 5b:96:39:e4:86:83:59:8a:1d:f1:31:9c:00:1f:45:42:ab:28: 85:80:c8:b7:52:4e:66:55:48:32:0c:d6:33:37:c5:d0:81:4d: 8f:e5:b0:5a:1b:c4:f7:d9:66:99:cc:99:08:06:30:38:3d:0f: 87:2f:18:01:b7:c7:59:73:55:50:7c:f1:62:a4:8a:9e:c8:c2: 3b:e8:14:b4
-1686668170 | 2024-12-28T07:12:34.659685143 / tcp
* OK The Microsoft Exchange IMAP4 service is ready. [QwBIADIAUAAxADYAMQBDAEEAMAAwADAANAAuAE4AQQBNAFAAMQA2ADEALgBQAFIATwBEAC4ATwBVAFQATABPAE8ASwAuAEMATwBNAA==] * CAPABILITY IMAP4 IMAP4rev1 LOGINDISABLED STARTTLS SASL-IR UIDPLUS ID UNSELECT CHILDREN IDLE NAMESPACE LITERAL+ A001 OK CAPABILITY completed. * ID ("name" "Microsoft.Exchange.Imap4.Imap4Server" "version" "15.20") A002 OK ID completed A003 BAD Command Error. 12 * BYE Microsoft Exchange Server IMAP4 server signing off. A004 OK LOGOUT completed.
Certificate: Data: Version: 3 (0x2) Serial Number: 36:26:77:eb:b3:28:f4:df:6f:76:ab:ba:68:44:03:de Signature Algorithm: sha256WithRSAEncryption Issuer: C=US, O=Entrust, Inc., OU=See www.entrust.net\/legal-terms, OU=(c) 2012 Entrust, Inc. - for authorized use only, CN=Entrust Certification Authority - L1K Validity Not Before: Sep 4 17:53:34 2024 GMT Not After : Sep 4 17:53:33 2025 GMT Subject: C=US, ST=New York, L=New York, O=American Express Company, CN=mymail.aexp.com Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (2048 bit) Modulus: 00:ba:46:79:9e:04:d6:ed:51:dc:7c:f3:eb:a4:08: 33:5e:74:bc:20:c0:20:be:c6:7c:a0:a9:5b:37:b2: 9a:b3:4a:a7:dc:49:53:a7:d2:a6:db:de:2b:fe:06: 53:ec:8d:78:13:1d:8d:1c:43:ba:a2:c3:d6:a5:c0: 8e:40:ee:38:f8:1c:3c:d5:57:c4:5f:0f:32:52:14: f8:55:76:f1:e7:e5:c8:ee:5c:8c:45:5b:eb:0b:01: 09:22:72:b8:82:a2:ca:63:27:a8:5e:32:dc:57:b6: 81:68:27:a7:11:ca:c0:df:73:cb:43:45:0d:ff:3d: d0:22:0c:49:02:4a:14:e2:f0:98:8d:52:2c:20:da: e8:c8:6f:1d:c0:0d:bd:96:b9:f2:12:6c:63:3c:92: e9:d6:d5:b0:a2:cd:7b:ec:3d:a9:8a:e0:dc:37:b3: 51:b9:04:10:8f:5f:11:b7:83:a2:d5:84:7f:15:d9: 63:d7:52:62:cc:a3:7f:cd:37:0d:c1:a8:2b:21:7c: 6f:81:37:1c:22:c6:ed:80:56:03:a2:e6:48:cf:48: cb:36:ce:6f:eb:2c:d1:83:8c:7d:aa:9f:bf:01:9a: ca:23:8f:ca:0b:41:d3:5c:03:38:e6:a1:43:d2:65: 11:48:ff:24:67:33:cd:4e:ba:16:84:0f:56:a0:a8: 1f:95 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Basic Constraints: critical CA:FALSE X509v3 Subject Key Identifier: 05:50:22:6C:C3:22:F6:8A:80:68:C2:E1:B0:00:66:A5:06:60:0C:BD X509v3 Authority Key Identifier: 82:A2:70:74:DD:BC:53:3F:CF:7B:D4:F7:CD:7F:A7:60:C6:0A:4C:BF Authority Information Access: OCSP - URI:http://ocsp.entrust.net CA Issuers - URI:http://aia.entrust.net/l1k-chain256.cer X509v3 CRL Distribution Points: Full Name: URI:http://crl.entrust.net/level1k.crl X509v3 Subject Alternative Name: DNS:mymail.aexp.com, DNS:*.pod51234.outlook.com, DNS:autodiscover.aexp.com, DNS:autodiscover.aexp.mail.onmicrosoft.com, DNS:autodiscover.aexp.onmicrosoft.com, DNS:mail.aexp.com, DNS:namp161-provisioning.internal.outlook.com, DNS:pod51234.outlook.com, DNS:pod51234ip.outlook.com, DNS:pod51234-pri.outlook.com, DNS:pod51234psh.outlook.com X509v3 Key Usage: critical Digital Signature, Key Encipherment X509v3 Extended Key Usage: TLS Web Server Authentication, TLS Web Client Authentication X509v3 Certificate Policies: Policy: 2.23.140.1.2.2 CT Precertificate SCTs: Signed Certificate Timestamp: Version : v1 (0x0) Log ID : E6:D2:31:63:40:77:8C:C1:10:41:06:D7:71:B9:CE:C1: D2:40:F6:96:84:86:FB:BA:87:32:1D:FD:1E:37:8E:50 Timestamp : Sep 4 17:53:34.905 2024 GMT Extensions: none Signature : ecdsa-with-SHA256 30:45:02:20:58:4D:A3:D6:02:B3:2D:14:E8:6E:22:A5: C2:4C:C6:4A:77:80:02:9A:B8:FB:70:79:87:72:3C:F6: 04:0C:BD:4A:02:21:00:8C:71:90:BE:BE:20:DE:17:AD: F1:A3:BD:F5:B7:3B:92:4B:43:43:14:F1:42:E2:0E:AE: 23:A7:96:2A:C9:1B:E5 Signed Certificate Timestamp: Version : v1 (0x0) Log ID : 0D:E1:F2:30:2B:D3:0D:C1:40:62:12:09:EA:55:2E:FC: 47:74:7C:B1:D7:E9:30:EF:0E:42:1E:B4:7E:4E:AA:34 Timestamp : Sep 4 17:53:34.913 2024 GMT Extensions: none Signature : ecdsa-with-SHA256 30:45:02:21:00:95:79:F6:63:BF:BA:8A:08:ED:98:C7: 8D:31:43:B2:8C:B1:B6:29:07:29:C7:97:DB:7F:36:34: 2A:8C:DD:ED:10:02:20:44:9A:37:8C:9E:9B:9E:A4:2C: 42:BA:D7:65:69:16:39:5C:20:BC:9A:D7:65:EA:BB:8B: 5E:C1:00:72:13:9A:39 Signed Certificate Timestamp: Version : v1 (0x0) Log ID : DD:DC:CA:34:95:D7:E1:16:05:E7:95:32:FA:C7:9F:F8: 3D:1C:50:DF:DB:00:3A:14:12:76:0A:2C:AC:BB:C8:2A Timestamp : Sep 4 17:53:34.934 2024 GMT Extensions: none Signature : ecdsa-with-SHA256 30:46:02:21:00:F6:1E:48:A4:C6:ED:73:69:FA:BC:66: A0:37:7C:B6:CE:D8:5C:95:14:22:13:15:C2:C7:69:3D: FD:DF:41:24:EE:02:21:00:DD:75:14:D2:21:FE:5C:B2: A8:68:FC:FE:F4:8D:45:8D:E2:12:65:18:36:E0:85:8C: F9:B3:41:84:A3:D3:38:7C Signature Algorithm: sha256WithRSAEncryption Signature Value: 54:4a:da:2e:61:23:7a:f3:e1:06:77:9c:0f:42:48:8c:c7:f5: c8:6d:a1:2a:3b:fc:e4:d4:9e:65:b9:a4:dc:82:95:d5:a0:12: 58:de:e2:41:73:f2:66:19:cd:6b:6c:b8:9a:b3:7e:f9:7f:18: 9c:91:f8:8a:0b:7b:13:5c:0d:75:e2:1c:21:17:ec:07:0d:94: e2:86:95:4d:b9:f9:c0:97:35:e6:ee:0c:53:68:a7:31:aa:7c: ce:ba:c8:94:76:bd:c3:4a:89:fd:5f:a9:09:a8:c8:b9:8d:49: e7:ac:20:6e:30:52:31:0c:05:76:f3:58:8f:da:1d:1d:72:73: 0f:a6:69:c1:53:13:0a:70:4d:52:94:90:ef:6a:79:40:fa:32: a3:7a:ea:b2:68:74:6c:4f:66:11:21:49:50:7d:94:54:47:f2: ef:b9:90:46:91:cf:88:51:98:95:9e:d6:c9:20:4c:6b:bc:63: 5b:96:39:e4:86:83:59:8a:1d:f1:31:9c:00:1f:45:42:ab:28: 85:80:c8:b7:52:4e:66:55:48:32:0c:d6:33:37:c5:d0:81:4d: 8f:e5:b0:5a:1b:c4:f7:d9:66:99:cc:99:08:06:30:38:3d:0f: 87:2f:18:01:b7:c7:59:73:55:50:7c:f1:62:a4:8a:9e:c8:c2: 3b:e8:14:b4
-291205204 | 2024-12-28T13:27:21.317837443 / tcp
HTTP/1.1 302 Content-Length: 777 Content-Type: text/html; charset=utf-8 Location: https://login.microsoftonline.com/common/oauth2/authorize?client_id=00000002-0000-0ff1-ce00-000000000000&redirect_uri=https%3a%2f%2f52.96.71.145%2fowa%2f&resource=00000002-0000-0ff1-ce00-000000000000&response_mode=form_post&response_type=code+id_token&scope=openid&msafed=0&msaredir=0&client-request-id=e1d9233e-4480-1f9d-e520-0d493bf84bdd&protectedtoken=true&claims=%7b%22id_token%22%3a%7b%22xms_cc%22%3a%7b%22values%22%3a%5b%22CP1%22%5d%7d%7d%7d&nonce=638709892412365326.9be066ec-3c23-4ecb-8aee-39d9a107d618&state=Dcs7FoAwCABBos_jYAhEAsfJh9rS65tittsEAOd2bIl2oKlYIzfnWlj0EdbbR5BqTJTJgjXmQOsRKL68F2pLi6X9Xvn9ev4B Server: Microsoft-IIS/10.0 request-id: e1d9233e-4480-1f9d-e520-0d493bf84bdd Strict-Transport-Security: max-age=31536000; includeSubDomains; preload X-CalculatedBETarget: DS0P161MB0339.NAMP161.PROD.OUTLOOK.COM X-BackEndHttpStatus: 302 P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI" Set-Cookie: ClientId=542EEA06549148329B67B2FE24850102; expires=Sun, 28-Dec-2025 13:27:21 GMT; path=/;SameSite=None; secure Set-Cookie: ClientId=542EEA06549148329B67B2FE24850102; expires=Sun, 28-Dec-2025 13:27:21 GMT; path=/;SameSite=None; secure Set-Cookie: OIDC=1; expires=Sat, 28-Jun-2025 13:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: RoutingKeyCookie=; expires=Wed, 28-Dec-1994 13:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: OpenIdConnect.token.v1=; expires=Wed, 28-Dec-1994 13:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: OpenIdConnect.token.v1=; domain=52.96.71.145; expires=Wed, 28-Dec-1994 13:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: OpenIdConnect.id_token.v1=; expires=Wed, 28-Dec-1994 13:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: OpenIdConnect.code.v1=; expires=Wed, 28-Dec-1994 13:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: OpenIdConnect.idp_nonce.v1=; expires=Wed, 28-Dec-1994 13:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: OpenIdConnect.idp_correlation_id=; expires=Wed, 28-Dec-1994 13:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: OpenIdConnect.tokenPostPath=; expires=Wed, 28-Dec-1994 13:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: OpenIdConnect.id_token.v1=; domain=52.96.71.145; expires=Wed, 28-Dec-1994 13:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: OpenIdConnect.code.v1=; domain=52.96.71.145; expires=Wed, 28-Dec-1994 13:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: OpenIdConnect.idp_nonce.v1=; domain=52.96.71.145; expires=Wed, 28-Dec-1994 13:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: OpenIdConnect.idp_correlation_id=; domain=52.96.71.145; expires=Wed, 28-Dec-1994 13:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: OpenIdConnect.tokenPostPath=; domain=52.96.71.145; expires=Wed, 28-Dec-1994 13:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: OpenIdConnect.nonce.v3.lsAOhAysOY587ivV5Kjwb_i5BGQNu7ZHxZY3-xmKCFQ=638709892412365326.9be066ec-3c23-4ecb-8aee-39d9a107d618; expires=Sat, 28-Dec-2024 14:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: HostSwitchPrg=; expires=Wed, 28-Dec-1994 13:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: OptInPrg=; expires=Wed, 28-Dec-1994 13:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: SuiteServiceProxyKey=; expires=Wed, 28-Dec-1994 13:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: ClientId=542EEA06549148329B67B2FE24850102; expires=Sun, 28-Dec-2025 13:27:21 GMT; path=/;SameSite=None; secure Set-Cookie: OIDC=1; expires=Sat, 28-Jun-2025 13:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: RoutingKeyCookie=; expires=Wed, 28-Dec-1994 13:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: OpenIdConnect.token.v1=; expires=Wed, 28-Dec-1994 13:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: OpenIdConnect.token.v1=; domain=52.96.71.145; expires=Wed, 28-Dec-1994 13:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: OpenIdConnect.id_token.v1=; expires=Wed, 28-Dec-1994 13:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: OpenIdConnect.code.v1=; expires=Wed, 28-Dec-1994 13:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: OpenIdConnect.idp_nonce.v1=; expires=Wed, 28-Dec-1994 13:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: OpenIdConnect.idp_correlation_id=; expires=Wed, 28-Dec-1994 13:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: OpenIdConnect.tokenPostPath=; expires=Wed, 28-Dec-1994 13:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: OpenIdConnect.id_token.v1=; domain=52.96.71.145; expires=Wed, 28-Dec-1994 13:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: OpenIdConnect.code.v1=; domain=52.96.71.145; expires=Wed, 28-Dec-1994 13:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: OpenIdConnect.idp_nonce.v1=; domain=52.96.71.145; expires=Wed, 28-Dec-1994 13:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: OpenIdConnect.idp_correlation_id=; domain=52.96.71.145; expires=Wed, 28-Dec-1994 13:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: OpenIdConnect.tokenPostPath=; domain=52.96.71.145; expires=Wed, 28-Dec-1994 13:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: OpenIdConnect.nonce.v3.lsAOhAysOY587ivV5Kjwb_i5BGQNu7ZHxZY3-xmKCFQ=638709892412365326.9be066ec-3c23-4ecb-8aee-39d9a107d618; expires=Sat, 28-Dec-2024 14:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: HostSwitchPrg=; expires=Wed, 28-Dec-1994 13:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: OptInPrg=; expires=Wed, 28-Dec-1994 13:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: SuiteServiceProxyKey=; expires=Wed, 28-Dec-1994 13:27:21 GMT; path=/;SameSite=None; secure; HttpOnly Set-Cookie: X-OWA-RedirectHistory=ArLym14BDlrEW0Mn3Qg; expires=Sat, 28-Dec-2024 19:29:21 GMT; path=/;SameSite=None; secure; HttpOnly X-RUM-Validated: 1 X-RUM-NotUpdateQueriedPath: 1 X-RUM-NotUpdateQueriedDbCopy: 1 X-Content-Type-Options: nosniff X-BeSku: WCS7 X-OWA-DiagnosticsInfo: 5;0;0; X-BackEnd-Begin: 2024-12-28T13:27:21.236 X-BackEnd-End: 2024-12-28T13:27:21.236 X-DiagInfo: DS0P161MB0339 X-BEServer: DS0P161MB0339 X-UA-Compatible: IE=EmulateIE7 X-ResponseOrigin: OwaAppPool X-Proxy-RoutingCorrectness: 1 Report-To: {"group":"NelOfficeUpload1","max_age":7200,"endpoints":[{"url":"https://exo.nel.measure.office.net/api/report?TenantId=&FrontEnd=Cafe&DestinationEndpoint=MDW&RemoteIP=66.240.219.0&Environment=MT"}],"include_subdomains":true} NEL: {"report_to":"NelOfficeUpload1","max_age":7200,"include_subdomains":true,"failure_fraction":1.0,"success_fraction":0.01} Alt-Svc: h3=":443";ma=2592000,h3-29=":443";ma=2592000 X-Proxy-BackendServerStatus: 302 X-FirstHopCafeEFZ: MDW X-FEProxyInfo: CH2P161CA0001.NAMP161.PROD.OUTLOOK.COM X-FEEFZInfo: MDW X-FEServer: CH2P161CA0001 Date: Sat, 28 Dec 2024 13:27:20 GMT
Certificate: Data: Version: 3 (0x2) Serial Number: 36:26:77:eb:b3:28:f4:df:6f:76:ab:ba:68:44:03:de Signature Algorithm: sha256WithRSAEncryption Issuer: C=US, O=Entrust, Inc., OU=See www.entrust.net\/legal-terms, OU=(c) 2012 Entrust, Inc. - for authorized use only, CN=Entrust Certification Authority - L1K Validity Not Before: Sep 4 17:53:34 2024 GMT Not After : Sep 4 17:53:33 2025 GMT Subject: C=US, ST=New York, L=New York, O=American Express Company, CN=mymail.aexp.com Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (2048 bit) Modulus: 00:ba:46:79:9e:04:d6:ed:51:dc:7c:f3:eb:a4:08: 33:5e:74:bc:20:c0:20:be:c6:7c:a0:a9:5b:37:b2: 9a:b3:4a:a7:dc:49:53:a7:d2:a6:db:de:2b:fe:06: 53:ec:8d:78:13:1d:8d:1c:43:ba:a2:c3:d6:a5:c0: 8e:40:ee:38:f8:1c:3c:d5:57:c4:5f:0f:32:52:14: f8:55:76:f1:e7:e5:c8:ee:5c:8c:45:5b:eb:0b:01: 09:22:72:b8:82:a2:ca:63:27:a8:5e:32:dc:57:b6: 81:68:27:a7:11:ca:c0:df:73:cb:43:45:0d:ff:3d: d0:22:0c:49:02:4a:14:e2:f0:98:8d:52:2c:20:da: e8:c8:6f:1d:c0:0d:bd:96:b9:f2:12:6c:63:3c:92: e9:d6:d5:b0:a2:cd:7b:ec:3d:a9:8a:e0:dc:37:b3: 51:b9:04:10:8f:5f:11:b7:83:a2:d5:84:7f:15:d9: 63:d7:52:62:cc:a3:7f:cd:37:0d:c1:a8:2b:21:7c: 6f:81:37:1c:22:c6:ed:80:56:03:a2:e6:48:cf:48: cb:36:ce:6f:eb:2c:d1:83:8c:7d:aa:9f:bf:01:9a: ca:23:8f:ca:0b:41:d3:5c:03:38:e6:a1:43:d2:65: 11:48:ff:24:67:33:cd:4e:ba:16:84:0f:56:a0:a8: 1f:95 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Basic Constraints: critical CA:FALSE X509v3 Subject Key Identifier: 05:50:22:6C:C3:22:F6:8A:80:68:C2:E1:B0:00:66:A5:06:60:0C:BD X509v3 Authority Key Identifier: 82:A2:70:74:DD:BC:53:3F:CF:7B:D4:F7:CD:7F:A7:60:C6:0A:4C:BF Authority Information Access: OCSP - URI:http://ocsp.entrust.net CA Issuers - URI:http://aia.entrust.net/l1k-chain256.cer X509v3 CRL Distribution Points: Full Name: URI:http://crl.entrust.net/level1k.crl X509v3 Subject Alternative Name: DNS:mymail.aexp.com, DNS:*.pod51234.outlook.com, DNS:autodiscover.aexp.com, DNS:autodiscover.aexp.mail.onmicrosoft.com, DNS:autodiscover.aexp.onmicrosoft.com, DNS:mail.aexp.com, DNS:namp161-provisioning.internal.outlook.com, DNS:pod51234.outlook.com, DNS:pod51234ip.outlook.com, DNS:pod51234-pri.outlook.com, DNS:pod51234psh.outlook.com X509v3 Key Usage: critical Digital Signature, Key Encipherment X509v3 Extended Key Usage: TLS Web Server Authentication, TLS Web Client Authentication X509v3 Certificate Policies: Policy: 2.23.140.1.2.2 CT Precertificate SCTs: Signed Certificate Timestamp: Version : v1 (0x0) Log ID : E6:D2:31:63:40:77:8C:C1:10:41:06:D7:71:B9:CE:C1: D2:40:F6:96:84:86:FB:BA:87:32:1D:FD:1E:37:8E:50 Timestamp : Sep 4 17:53:34.905 2024 GMT Extensions: none Signature : ecdsa-with-SHA256 30:45:02:20:58:4D:A3:D6:02:B3:2D:14:E8:6E:22:A5: C2:4C:C6:4A:77:80:02:9A:B8:FB:70:79:87:72:3C:F6: 04:0C:BD:4A:02:21:00:8C:71:90:BE:BE:20:DE:17:AD: F1:A3:BD:F5:B7:3B:92:4B:43:43:14:F1:42:E2:0E:AE: 23:A7:96:2A:C9:1B:E5 Signed Certificate Timestamp: Version : v1 (0x0) Log ID : 0D:E1:F2:30:2B:D3:0D:C1:40:62:12:09:EA:55:2E:FC: 47:74:7C:B1:D7:E9:30:EF:0E:42:1E:B4:7E:4E:AA:34 Timestamp : Sep 4 17:53:34.913 2024 GMT Extensions: none Signature : ecdsa-with-SHA256 30:45:02:21:00:95:79:F6:63:BF:BA:8A:08:ED:98:C7: 8D:31:43:B2:8C:B1:B6:29:07:29:C7:97:DB:7F:36:34: 2A:8C:DD:ED:10:02:20:44:9A:37:8C:9E:9B:9E:A4:2C: 42:BA:D7:65:69:16:39:5C:20:BC:9A:D7:65:EA:BB:8B: 5E:C1:00:72:13:9A:39 Signed Certificate Timestamp: Version : v1 (0x0) Log ID : DD:DC:CA:34:95:D7:E1:16:05:E7:95:32:FA:C7:9F:F8: 3D:1C:50:DF:DB:00:3A:14:12:76:0A:2C:AC:BB:C8:2A Timestamp : Sep 4 17:53:34.934 2024 GMT Extensions: none Signature : ecdsa-with-SHA256 30:46:02:21:00:F6:1E:48:A4:C6:ED:73:69:FA:BC:66: A0:37:7C:B6:CE:D8:5C:95:14:22:13:15:C2:C7:69:3D: FD:DF:41:24:EE:02:21:00:DD:75:14:D2:21:FE:5C:B2: A8:68:FC:FE:F4:8D:45:8D:E2:12:65:18:36:E0:85:8C: F9:B3:41:84:A3:D3:38:7C Signature Algorithm: sha256WithRSAEncryption Signature Value: 54:4a:da:2e:61:23:7a:f3:e1:06:77:9c:0f:42:48:8c:c7:f5: c8:6d:a1:2a:3b:fc:e4:d4:9e:65:b9:a4:dc:82:95:d5:a0:12: 58:de:e2:41:73:f2:66:19:cd:6b:6c:b8:9a:b3:7e:f9:7f:18: 9c:91:f8:8a:0b:7b:13:5c:0d:75:e2:1c:21:17:ec:07:0d:94: e2:86:95:4d:b9:f9:c0:97:35:e6:ee:0c:53:68:a7:31:aa:7c: ce:ba:c8:94:76:bd:c3:4a:89:fd:5f:a9:09:a8:c8:b9:8d:49: e7:ac:20:6e:30:52:31:0c:05:76:f3:58:8f:da:1d:1d:72:73: 0f:a6:69:c1:53:13:0a:70:4d:52:94:90:ef:6a:79:40:fa:32: a3:7a:ea:b2:68:74:6c:4f:66:11:21:49:50:7d:94:54:47:f2: ef:b9:90:46:91:cf:88:51:98:95:9e:d6:c9:20:4c:6b:bc:63: 5b:96:39:e4:86:83:59:8a:1d:f1:31:9c:00:1f:45:42:ab:28: 85:80:c8:b7:52:4e:66:55:48:32:0c:d6:33:37:c5:d0:81:4d: 8f:e5:b0:5a:1b:c4:f7:d9:66:99:cc:99:08:06:30:38:3d:0f: 87:2f:18:01:b7:c7:59:73:55:50:7c:f1:62:a4:8a:9e:c8:c2: 3b:e8:14:b4
-1350764109 | 2024-12-27T23:24:12.677283587 / tcp
220 CH2P161CA0006.outlook.office365.com Microsoft ESMTP MAIL Service ready at Fri, 27 Dec 2024 23:24:05 +0000 [08DD2677008678B8] 250-CH2P161CA0006.outlook.office365.com Hello [224.194.159.135] 250-SIZE 157286400 250-PIPELINING 250-DSN 250-ENHANCEDSTATUSCODES 250-STARTTLS 250-8BITMIME 250-BINARYMIME 250-CHUNKING 250 SMTPUTF8
Certificate: Data: Version: 3 (0x2) Serial Number: 36:26:77:eb:b3:28:f4:df:6f:76:ab:ba:68:44:03:de Signature Algorithm: sha256WithRSAEncryption Issuer: C=US, O=Entrust, Inc., OU=See www.entrust.net\/legal-terms, OU=(c) 2012 Entrust, Inc. - for authorized use only, CN=Entrust Certification Authority - L1K Validity Not Before: Sep 4 17:53:34 2024 GMT Not After : Sep 4 17:53:33 2025 GMT Subject: C=US, ST=New York, L=New York, O=American Express Company, CN=mymail.aexp.com Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (2048 bit) Modulus: 00:ba:46:79:9e:04:d6:ed:51:dc:7c:f3:eb:a4:08: 33:5e:74:bc:20:c0:20:be:c6:7c:a0:a9:5b:37:b2: 9a:b3:4a:a7:dc:49:53:a7:d2:a6:db:de:2b:fe:06: 53:ec:8d:78:13:1d:8d:1c:43:ba:a2:c3:d6:a5:c0: 8e:40:ee:38:f8:1c:3c:d5:57:c4:5f:0f:32:52:14: f8:55:76:f1:e7:e5:c8:ee:5c:8c:45:5b:eb:0b:01: 09:22:72:b8:82:a2:ca:63:27:a8:5e:32:dc:57:b6: 81:68:27:a7:11:ca:c0:df:73:cb:43:45:0d:ff:3d: d0:22:0c:49:02:4a:14:e2:f0:98:8d:52:2c:20:da: e8:c8:6f:1d:c0:0d:bd:96:b9:f2:12:6c:63:3c:92: e9:d6:d5:b0:a2:cd:7b:ec:3d:a9:8a:e0:dc:37:b3: 51:b9:04:10:8f:5f:11:b7:83:a2:d5:84:7f:15:d9: 63:d7:52:62:cc:a3:7f:cd:37:0d:c1:a8:2b:21:7c: 6f:81:37:1c:22:c6:ed:80:56:03:a2:e6:48:cf:48: cb:36:ce:6f:eb:2c:d1:83:8c:7d:aa:9f:bf:01:9a: ca:23:8f:ca:0b:41:d3:5c:03:38:e6:a1:43:d2:65: 11:48:ff:24:67:33:cd:4e:ba:16:84:0f:56:a0:a8: 1f:95 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Basic Constraints: critical CA:FALSE X509v3 Subject Key Identifier: 05:50:22:6C:C3:22:F6:8A:80:68:C2:E1:B0:00:66:A5:06:60:0C:BD X509v3 Authority Key Identifier: 82:A2:70:74:DD:BC:53:3F:CF:7B:D4:F7:CD:7F:A7:60:C6:0A:4C:BF Authority Information Access: OCSP - URI:http://ocsp.entrust.net CA Issuers - URI:http://aia.entrust.net/l1k-chain256.cer X509v3 CRL Distribution Points: Full Name: URI:http://crl.entrust.net/level1k.crl X509v3 Subject Alternative Name: DNS:mymail.aexp.com, DNS:*.pod51234.outlook.com, DNS:autodiscover.aexp.com, DNS:autodiscover.aexp.mail.onmicrosoft.com, DNS:autodiscover.aexp.onmicrosoft.com, DNS:mail.aexp.com, DNS:namp161-provisioning.internal.outlook.com, DNS:pod51234.outlook.com, DNS:pod51234ip.outlook.com, DNS:pod51234-pri.outlook.com, DNS:pod51234psh.outlook.com X509v3 Key Usage: critical Digital Signature, Key Encipherment X509v3 Extended Key Usage: TLS Web Server Authentication, TLS Web Client Authentication X509v3 Certificate Policies: Policy: 2.23.140.1.2.2 CT Precertificate SCTs: Signed Certificate Timestamp: Version : v1 (0x0) Log ID : E6:D2:31:63:40:77:8C:C1:10:41:06:D7:71:B9:CE:C1: D2:40:F6:96:84:86:FB:BA:87:32:1D:FD:1E:37:8E:50 Timestamp : Sep 4 17:53:34.905 2024 GMT Extensions: none Signature : ecdsa-with-SHA256 30:45:02:20:58:4D:A3:D6:02:B3:2D:14:E8:6E:22:A5: C2:4C:C6:4A:77:80:02:9A:B8:FB:70:79:87:72:3C:F6: 04:0C:BD:4A:02:21:00:8C:71:90:BE:BE:20:DE:17:AD: F1:A3:BD:F5:B7:3B:92:4B:43:43:14:F1:42:E2:0E:AE: 23:A7:96:2A:C9:1B:E5 Signed Certificate Timestamp: Version : v1 (0x0) Log ID : 0D:E1:F2:30:2B:D3:0D:C1:40:62:12:09:EA:55:2E:FC: 47:74:7C:B1:D7:E9:30:EF:0E:42:1E:B4:7E:4E:AA:34 Timestamp : Sep 4 17:53:34.913 2024 GMT Extensions: none Signature : ecdsa-with-SHA256 30:45:02:21:00:95:79:F6:63:BF:BA:8A:08:ED:98:C7: 8D:31:43:B2:8C:B1:B6:29:07:29:C7:97:DB:7F:36:34: 2A:8C:DD:ED:10:02:20:44:9A:37:8C:9E:9B:9E:A4:2C: 42:BA:D7:65:69:16:39:5C:20:BC:9A:D7:65:EA:BB:8B: 5E:C1:00:72:13:9A:39 Signed Certificate Timestamp: Version : v1 (0x0) Log ID : DD:DC:CA:34:95:D7:E1:16:05:E7:95:32:FA:C7:9F:F8: 3D:1C:50:DF:DB:00:3A:14:12:76:0A:2C:AC:BB:C8:2A Timestamp : Sep 4 17:53:34.934 2024 GMT Extensions: none Signature : ecdsa-with-SHA256 30:46:02:21:00:F6:1E:48:A4:C6:ED:73:69:FA:BC:66: A0:37:7C:B6:CE:D8:5C:95:14:22:13:15:C2:C7:69:3D: FD:DF:41:24:EE:02:21:00:DD:75:14:D2:21:FE:5C:B2: A8:68:FC:FE:F4:8D:45:8D:E2:12:65:18:36:E0:85:8C: F9:B3:41:84:A3:D3:38:7C Signature Algorithm: sha256WithRSAEncryption Signature Value: 54:4a:da:2e:61:23:7a:f3:e1:06:77:9c:0f:42:48:8c:c7:f5: c8:6d:a1:2a:3b:fc:e4:d4:9e:65:b9:a4:dc:82:95:d5:a0:12: 58:de:e2:41:73:f2:66:19:cd:6b:6c:b8:9a:b3:7e:f9:7f:18: 9c:91:f8:8a:0b:7b:13:5c:0d:75:e2:1c:21:17:ec:07:0d:94: e2:86:95:4d:b9:f9:c0:97:35:e6:ee:0c:53:68:a7:31:aa:7c: ce:ba:c8:94:76:bd:c3:4a:89:fd:5f:a9:09:a8:c8:b9:8d:49: e7:ac:20:6e:30:52:31:0c:05:76:f3:58:8f:da:1d:1d:72:73: 0f:a6:69:c1:53:13:0a:70:4d:52:94:90:ef:6a:79:40:fa:32: a3:7a:ea:b2:68:74:6c:4f:66:11:21:49:50:7d:94:54:47:f2: ef:b9:90:46:91:cf:88:51:98:95:9e:d6:c9:20:4c:6b:bc:63: 5b:96:39:e4:86:83:59:8a:1d:f1:31:9c:00:1f:45:42:ab:28: 85:80:c8:b7:52:4e:66:55:48:32:0c:d6:33:37:c5:d0:81:4d: 8f:e5:b0:5a:1b:c4:f7:d9:66:99:cc:99:08:06:30:38:3d:0f: 87:2f:18:01:b7:c7:59:73:55:50:7c:f1:62:a4:8a:9e:c8:c2: 3b:e8:14:b4
-1901500261 | 2024-12-02T19:25:16.899884993 / tcp
* OK The Microsoft Exchange IMAP4 service is ready. [QwBIADIAUAAxADYAMQBDAEEAMAAwADAAMgAuAE4AQQBNAFAAMQA2ADEALgBQAFIATwBEAC4ATwBVAFQATABPAE8ASwAuAEMATwBNAA==] * CAPABILITY IMAP4 IMAP4rev1 AUTH=PLAIN AUTH=XOAUTH2 SASL-IR UIDPLUS ID UNSELECT CHILDREN IDLE NAMESPACE LITERAL+ A001 OK CAPABILITY completed. * ID ("name" "Microsoft.Exchange.Imap4.Imap4Server" "version" "15.20") A002 OK ID completed A003 BAD Command Error. 12 * BYE Microsoft Exchange Server IMAP4 server signing off. A004 OK LOGOUT completed.
Certificate: Data: Version: 3 (0x2) Serial Number: 36:26:77:eb:b3:28:f4:df:6f:76:ab:ba:68:44:03:de Signature Algorithm: sha256WithRSAEncryption Issuer: C=US, O=Entrust, Inc., OU=See www.entrust.net\/legal-terms, OU=(c) 2012 Entrust, Inc. - for authorized use only, CN=Entrust Certification Authority - L1K Validity Not Before: Sep 4 17:53:34 2024 GMT Not After : Sep 4 17:53:33 2025 GMT Subject: C=US, ST=New York, L=New York, O=American Express Company, CN=mymail.aexp.com Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (2048 bit) Modulus: 00:ba:46:79:9e:04:d6:ed:51:dc:7c:f3:eb:a4:08: 33:5e:74:bc:20:c0:20:be:c6:7c:a0:a9:5b:37:b2: 9a:b3:4a:a7:dc:49:53:a7:d2:a6:db:de:2b:fe:06: 53:ec:8d:78:13:1d:8d:1c:43:ba:a2:c3:d6:a5:c0: 8e:40:ee:38:f8:1c:3c:d5:57:c4:5f:0f:32:52:14: f8:55:76:f1:e7:e5:c8:ee:5c:8c:45:5b:eb:0b:01: 09:22:72:b8:82:a2:ca:63:27:a8:5e:32:dc:57:b6: 81:68:27:a7:11:ca:c0:df:73:cb:43:45:0d:ff:3d: d0:22:0c:49:02:4a:14:e2:f0:98:8d:52:2c:20:da: e8:c8:6f:1d:c0:0d:bd:96:b9:f2:12:6c:63:3c:92: e9:d6:d5:b0:a2:cd:7b:ec:3d:a9:8a:e0:dc:37:b3: 51:b9:04:10:8f:5f:11:b7:83:a2:d5:84:7f:15:d9: 63:d7:52:62:cc:a3:7f:cd:37:0d:c1:a8:2b:21:7c: 6f:81:37:1c:22:c6:ed:80:56:03:a2:e6:48:cf:48: cb:36:ce:6f:eb:2c:d1:83:8c:7d:aa:9f:bf:01:9a: ca:23:8f:ca:0b:41:d3:5c:03:38:e6:a1:43:d2:65: 11:48:ff:24:67:33:cd:4e:ba:16:84:0f:56:a0:a8: 1f:95 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Basic Constraints: critical CA:FALSE X509v3 Subject Key Identifier: 05:50:22:6C:C3:22:F6:8A:80:68:C2:E1:B0:00:66:A5:06:60:0C:BD X509v3 Authority Key Identifier: 82:A2:70:74:DD:BC:53:3F:CF:7B:D4:F7:CD:7F:A7:60:C6:0A:4C:BF Authority Information Access: OCSP - URI:http://ocsp.entrust.net CA Issuers - URI:http://aia.entrust.net/l1k-chain256.cer X509v3 CRL Distribution Points: Full Name: URI:http://crl.entrust.net/level1k.crl X509v3 Subject Alternative Name: DNS:mymail.aexp.com, DNS:*.pod51234.outlook.com, DNS:autodiscover.aexp.com, DNS:autodiscover.aexp.mail.onmicrosoft.com, DNS:autodiscover.aexp.onmicrosoft.com, DNS:mail.aexp.com, DNS:namp161-provisioning.internal.outlook.com, DNS:pod51234.outlook.com, DNS:pod51234ip.outlook.com, DNS:pod51234-pri.outlook.com, DNS:pod51234psh.outlook.com X509v3 Key Usage: critical Digital Signature, Key Encipherment X509v3 Extended Key Usage: TLS Web Server Authentication, TLS Web Client Authentication X509v3 Certificate Policies: Policy: 2.23.140.1.2.2 CT Precertificate SCTs: Signed Certificate Timestamp: Version : v1 (0x0) Log ID : E6:D2:31:63:40:77:8C:C1:10:41:06:D7:71:B9:CE:C1: D2:40:F6:96:84:86:FB:BA:87:32:1D:FD:1E:37:8E:50 Timestamp : Sep 4 17:53:34.905 2024 GMT Extensions: none Signature : ecdsa-with-SHA256 30:45:02:20:58:4D:A3:D6:02:B3:2D:14:E8:6E:22:A5: C2:4C:C6:4A:77:80:02:9A:B8:FB:70:79:87:72:3C:F6: 04:0C:BD:4A:02:21:00:8C:71:90:BE:BE:20:DE:17:AD: F1:A3:BD:F5:B7:3B:92:4B:43:43:14:F1:42:E2:0E:AE: 23:A7:96:2A:C9:1B:E5 Signed Certificate Timestamp: Version : v1 (0x0) Log ID : 0D:E1:F2:30:2B:D3:0D:C1:40:62:12:09:EA:55:2E:FC: 47:74:7C:B1:D7:E9:30:EF:0E:42:1E:B4:7E:4E:AA:34 Timestamp : Sep 4 17:53:34.913 2024 GMT Extensions: none Signature : ecdsa-with-SHA256 30:45:02:21:00:95:79:F6:63:BF:BA:8A:08:ED:98:C7: 8D:31:43:B2:8C:B1:B6:29:07:29:C7:97:DB:7F:36:34: 2A:8C:DD:ED:10:02:20:44:9A:37:8C:9E:9B:9E:A4:2C: 42:BA:D7:65:69:16:39:5C:20:BC:9A:D7:65:EA:BB:8B: 5E:C1:00:72:13:9A:39 Signed Certificate Timestamp: Version : v1 (0x0) Log ID : DD:DC:CA:34:95:D7:E1:16:05:E7:95:32:FA:C7:9F:F8: 3D:1C:50:DF:DB:00:3A:14:12:76:0A:2C:AC:BB:C8:2A Timestamp : Sep 4 17:53:34.934 2024 GMT Extensions: none Signature : ecdsa-with-SHA256 30:46:02:21:00:F6:1E:48:A4:C6:ED:73:69:FA:BC:66: A0:37:7C:B6:CE:D8:5C:95:14:22:13:15:C2:C7:69:3D: FD:DF:41:24:EE:02:21:00:DD:75:14:D2:21:FE:5C:B2: A8:68:FC:FE:F4:8D:45:8D:E2:12:65:18:36:E0:85:8C: F9:B3:41:84:A3:D3:38:7C Signature Algorithm: sha256WithRSAEncryption Signature Value: 54:4a:da:2e:61:23:7a:f3:e1:06:77:9c:0f:42:48:8c:c7:f5: c8:6d:a1:2a:3b:fc:e4:d4:9e:65:b9:a4:dc:82:95:d5:a0:12: 58:de:e2:41:73:f2:66:19:cd:6b:6c:b8:9a:b3:7e:f9:7f:18: 9c:91:f8:8a:0b:7b:13:5c:0d:75:e2:1c:21:17:ec:07:0d:94: e2:86:95:4d:b9:f9:c0:97:35:e6:ee:0c:53:68:a7:31:aa:7c: ce:ba:c8:94:76:bd:c3:4a:89:fd:5f:a9:09:a8:c8:b9:8d:49: e7:ac:20:6e:30:52:31:0c:05:76:f3:58:8f:da:1d:1d:72:73: 0f:a6:69:c1:53:13:0a:70:4d:52:94:90:ef:6a:79:40:fa:32: a3:7a:ea:b2:68:74:6c:4f:66:11:21:49:50:7d:94:54:47:f2: ef:b9:90:46:91:cf:88:51:98:95:9e:d6:c9:20:4c:6b:bc:63: 5b:96:39:e4:86:83:59:8a:1d:f1:31:9c:00:1f:45:42:ab:28: 85:80:c8:b7:52:4e:66:55:48:32:0c:d6:33:37:c5:d0:81:4d: 8f:e5:b0:5a:1b:c4:f7:d9:66:99:cc:99:08:06:30:38:3d:0f: 87:2f:18:01:b7:c7:59:73:55:50:7c:f1:62:a4:8a:9e:c8:c2: 3b:e8:14:b4
1829668245 | 2024-12-22T19:43:56.730556995 / tcp
+OK The Microsoft Exchange POP3 service is ready. [QwBIADIAUAAxADYAMQBDAEEAMAAwADAAMgAuAE4AQQBNAFAAMQA2ADEALgBQAFIATwBEAC4ATwBVAFQATABPAE8ASwAuAEMATwBNAA==] +OK TOP UIDL SASL PLAIN XOAUTH2 USER .
Certificate: Data: Version: 3 (0x2) Serial Number: 36:26:77:eb:b3:28:f4:df:6f:76:ab:ba:68:44:03:de Signature Algorithm: sha256WithRSAEncryption Issuer: C=US, O=Entrust, Inc., OU=See www.entrust.net\/legal-terms, OU=(c) 2012 Entrust, Inc. - for authorized use only, CN=Entrust Certification Authority - L1K Validity Not Before: Sep 4 17:53:34 2024 GMT Not After : Sep 4 17:53:33 2025 GMT Subject: C=US, ST=New York, L=New York, O=American Express Company, CN=mymail.aexp.com Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (2048 bit) Modulus: 00:ba:46:79:9e:04:d6:ed:51:dc:7c:f3:eb:a4:08: 33:5e:74:bc:20:c0:20:be:c6:7c:a0:a9:5b:37:b2: 9a:b3:4a:a7:dc:49:53:a7:d2:a6:db:de:2b:fe:06: 53:ec:8d:78:13:1d:8d:1c:43:ba:a2:c3:d6:a5:c0: 8e:40:ee:38:f8:1c:3c:d5:57:c4:5f:0f:32:52:14: f8:55:76:f1:e7:e5:c8:ee:5c:8c:45:5b:eb:0b:01: 09:22:72:b8:82:a2:ca:63:27:a8:5e:32:dc:57:b6: 81:68:27:a7:11:ca:c0:df:73:cb:43:45:0d:ff:3d: d0:22:0c:49:02:4a:14:e2:f0:98:8d:52:2c:20:da: e8:c8:6f:1d:c0:0d:bd:96:b9:f2:12:6c:63:3c:92: e9:d6:d5:b0:a2:cd:7b:ec:3d:a9:8a:e0:dc:37:b3: 51:b9:04:10:8f:5f:11:b7:83:a2:d5:84:7f:15:d9: 63:d7:52:62:cc:a3:7f:cd:37:0d:c1:a8:2b:21:7c: 6f:81:37:1c:22:c6:ed:80:56:03:a2:e6:48:cf:48: cb:36:ce:6f:eb:2c:d1:83:8c:7d:aa:9f:bf:01:9a: ca:23:8f:ca:0b:41:d3:5c:03:38:e6:a1:43:d2:65: 11:48:ff:24:67:33:cd:4e:ba:16:84:0f:56:a0:a8: 1f:95 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Basic Constraints: critical CA:FALSE X509v3 Subject Key Identifier: 05:50:22:6C:C3:22:F6:8A:80:68:C2:E1:B0:00:66:A5:06:60:0C:BD X509v3 Authority Key Identifier: 82:A2:70:74:DD:BC:53:3F:CF:7B:D4:F7:CD:7F:A7:60:C6:0A:4C:BF Authority Information Access: OCSP - URI:http://ocsp.entrust.net CA Issuers - URI:http://aia.entrust.net/l1k-chain256.cer X509v3 CRL Distribution Points: Full Name: URI:http://crl.entrust.net/level1k.crl X509v3 Subject Alternative Name: DNS:mymail.aexp.com, DNS:*.pod51234.outlook.com, DNS:autodiscover.aexp.com, DNS:autodiscover.aexp.mail.onmicrosoft.com, DNS:autodiscover.aexp.onmicrosoft.com, DNS:mail.aexp.com, DNS:namp161-provisioning.internal.outlook.com, DNS:pod51234.outlook.com, DNS:pod51234ip.outlook.com, DNS:pod51234-pri.outlook.com, DNS:pod51234psh.outlook.com X509v3 Key Usage: critical Digital Signature, Key Encipherment X509v3 Extended Key Usage: TLS Web Server Authentication, TLS Web Client Authentication X509v3 Certificate Policies: Policy: 2.23.140.1.2.2 CT Precertificate SCTs: Signed Certificate Timestamp: Version : v1 (0x0) Log ID : E6:D2:31:63:40:77:8C:C1:10:41:06:D7:71:B9:CE:C1: D2:40:F6:96:84:86:FB:BA:87:32:1D:FD:1E:37:8E:50 Timestamp : Sep 4 17:53:34.905 2024 GMT Extensions: none Signature : ecdsa-with-SHA256 30:45:02:20:58:4D:A3:D6:02:B3:2D:14:E8:6E:22:A5: C2:4C:C6:4A:77:80:02:9A:B8:FB:70:79:87:72:3C:F6: 04:0C:BD:4A:02:21:00:8C:71:90:BE:BE:20:DE:17:AD: F1:A3:BD:F5:B7:3B:92:4B:43:43:14:F1:42:E2:0E:AE: 23:A7:96:2A:C9:1B:E5 Signed Certificate Timestamp: Version : v1 (0x0) Log ID : 0D:E1:F2:30:2B:D3:0D:C1:40:62:12:09:EA:55:2E:FC: 47:74:7C:B1:D7:E9:30:EF:0E:42:1E:B4:7E:4E:AA:34 Timestamp : Sep 4 17:53:34.913 2024 GMT Extensions: none Signature : ecdsa-with-SHA256 30:45:02:21:00:95:79:F6:63:BF:BA:8A:08:ED:98:C7: 8D:31:43:B2:8C:B1:B6:29:07:29:C7:97:DB:7F:36:34: 2A:8C:DD:ED:10:02:20:44:9A:37:8C:9E:9B:9E:A4:2C: 42:BA:D7:65:69:16:39:5C:20:BC:9A:D7:65:EA:BB:8B: 5E:C1:00:72:13:9A:39 Signed Certificate Timestamp: Version : v1 (0x0) Log ID : DD:DC:CA:34:95:D7:E1:16:05:E7:95:32:FA:C7:9F:F8: 3D:1C:50:DF:DB:00:3A:14:12:76:0A:2C:AC:BB:C8:2A Timestamp : Sep 4 17:53:34.934 2024 GMT Extensions: none Signature : ecdsa-with-SHA256 30:46:02:21:00:F6:1E:48:A4:C6:ED:73:69:FA:BC:66: A0:37:7C:B6:CE:D8:5C:95:14:22:13:15:C2:C7:69:3D: FD:DF:41:24:EE:02:21:00:DD:75:14:D2:21:FE:5C:B2: A8:68:FC:FE:F4:8D:45:8D:E2:12:65:18:36:E0:85:8C: F9:B3:41:84:A3:D3:38:7C Signature Algorithm: sha256WithRSAEncryption Signature Value: 54:4a:da:2e:61:23:7a:f3:e1:06:77:9c:0f:42:48:8c:c7:f5: c8:6d:a1:2a:3b:fc:e4:d4:9e:65:b9:a4:dc:82:95:d5:a0:12: 58:de:e2:41:73:f2:66:19:cd:6b:6c:b8:9a:b3:7e:f9:7f:18: 9c:91:f8:8a:0b:7b:13:5c:0d:75:e2:1c:21:17:ec:07:0d:94: e2:86:95:4d:b9:f9:c0:97:35:e6:ee:0c:53:68:a7:31:aa:7c: ce:ba:c8:94:76:bd:c3:4a:89:fd:5f:a9:09:a8:c8:b9:8d:49: e7:ac:20:6e:30:52:31:0c:05:76:f3:58:8f:da:1d:1d:72:73: 0f:a6:69:c1:53:13:0a:70:4d:52:94:90:ef:6a:79:40:fa:32: a3:7a:ea:b2:68:74:6c:4f:66:11:21:49:50:7d:94:54:47:f2: ef:b9:90:46:91:cf:88:51:98:95:9e:d6:c9:20:4c:6b:bc:63: 5b:96:39:e4:86:83:59:8a:1d:f1:31:9c:00:1f:45:42:ab:28: 85:80:c8:b7:52:4e:66:55:48:32:0c:d6:33:37:c5:d0:81:4d: 8f:e5:b0:5a:1b:c4:f7:d9:66:99:cc:99:08:06:30:38:3d:0f: 87:2f:18:01:b7:c7:59:73:55:50:7c:f1:62:a4:8a:9e:c8:c2: 3b:e8:14:b4