-312030558 | 2024-09-22T08:23:15.490255
135 /
tcp
Microsoft RPC Endpoint Mapper
3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5
version: v1.0
annotation: DHCP Client LRPC Endpoint
provider: dhcpcsvc.dll
ncalrpc: dhcpcsvc
ncalrpc: DNSResolver
0a74ef1c-41a4-4e06-83ae-dc74fb1cdd53
version: v1.0
provider: schedsvc.dll
ncacn_np: \\NS2\PIPE\atsvc
ncalrpc: OLE48F5D0A6CD4A44289B7E37301333
ncalrpc: wzcsvc
378e52b0-c0a9-11cf-822d-00aa0051e40f
version: v1.0
protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol
provider: taskcomp.dll
ncacn_np: \\NS2\PIPE\atsvc
ncalrpc: OLE48F5D0A6CD4A44289B7E37301333
ncalrpc: wzcsvc
1ff70682-0a51-30e8-076d-740be8cee98b
version: v1.0
protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol
provider: taskcomp.dll
ncacn_np: \\NS2\PIPE\atsvc
ncalrpc: OLE48F5D0A6CD4A44289B7E37301333
ncalrpc: wzcsvc
906b0ce0-c70b-1067-b317-00dd010662da
version: v1.0
protocol: [MS-CMPO]: MSDTC Connection Manager:
provider: msdtcprx.dll
ncalrpc: LRPC00000578.00000001
ncalrpc: LRPC00000578.00000001
ncalrpc: LRPC00000578.00000001
ncalrpc: LRPC00000578.00000001
12345678-1234-abcd-ef00-0123456789ab
version: v1.0
annotation: IPSec Policy agent endpoint
protocol: [MS-RPRN]: Print System Remote Protocol
provider: spoolsv.exe
ncacn_ip_tcp: 72.252.24.135:1025
ncalrpc: dsrole
ncacn_np: \\NS2\PIPE\protected_storage
ncalrpc: protected_storage
ncalrpc: securityevent
ncalrpc: audit
ncacn_np: \\NS2\PIPE\lsass
12345778-1234-abcd-ef00-0123456789ac
version: v1.0
protocol: [MS-SAMR]: Security Account Manager (SAM) Remote Protocol
provider: samsrv.dll
ncacn_ip_tcp: 72.252.24.135:1025
ncalrpc: dsrole
ncacn_np: \\NS2\PIPE\protected_storage
ncalrpc: protected_storage
ncalrpc: securityevent
ncalrpc: audit
ncacn_np: \\NS2\PIPE\lsass
1426900579 | 2024-09-17T16:10:08.562483
137 /
udp
NetBIOS Response:
MAC Address: 00:0C:29:E7:CB:D5
Names:
NS2 <0x0>
WORKGROUP <0x0>
MAC Addresses
00:0C:29:E7:CB:D5
OUI: 00:0C:29
Organization: VMware, Inc.
Assignment: MA-L
Registration Date: 2003-01-21
-303278144 | 2024-09-09T12:09:08.055526
3389 /
tcp
Remote Desktop Protocol
\x03\x00\x00\x13\x0e\xd0\x00\x00\x124\x00\x03\x00\x08\x00\x02\x00\x00\x00
Log On to Windows
User name:
Password:
Cancel Options