21 /
tcp
-1899293607 | 2025-03-18T21:23:18.596875
220 HIHO
530 Login or password incorrect!
214-The following commands are recognized:
USER PASS QUIT CWD PWD PORT PASV TYPE
LIST REST CDUP RETR STOR SIZE DELE RMD
MKD RNFR RNTO ABOR SYST NOOP APPE NLST
MDTM XPWD XCUP XMKD XRMD NOP EPSV EPRT
AUTH ADAT PBSZ PROT FEAT MODE OPTS HELP
ALLO MLST MLSD SITE P@SW STRU CLNT MFMT
HASH
214 Have a nice day.
211-Features:
MDTM
REST STREAM
SIZE
MLST type*;size*;modify*;
MLSD
UTF8
CLNT
MFMT
211 End
53 /
udp
2071339610 | 2025-03-23T00:16:24.326579
not currently available
Resolver name: 1A-7178
1244866810 | 2025-03-21T20:12:29.212754
HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Sat, 30 Apr 2005 00:49:47 GMT
Accept-Ranges: bytes
ETag: "80c7ae811e4dc51:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
Date: Fri, 21 Mar 2025 20:12:28 GMT
Content-Length: 6338
Vulnerabilities
110 /
tcp
-1283034168 | 2025-03-11T09:14:20.715830
+OK POP3
+OK CAPA list follows
USER
UIDL
TOP
.
135 /
tcp
176560298 | 2025-03-19T12:40:41.996213
Microsoft RPC Endpoint Mapper
d95afe70-a6d5-4259-822e-2c84da1ddb0d
version: v1.0
protocol: [MS-RSP]: Remote Shutdown Protocol
provider: wininit.exe
ncacn_ip_tcp: 89.200.169.116:49152
ncalrpc: WindowsShutdown
ncacn_np: \\1A-7178\PIPE\InitShutdown
ncalrpc: WMsgKRpc098600
76f226c3-ec14-4325-8a99-6a46348418af
version: v1.0
provider: winlogon.exe
ncalrpc: WindowsShutdown
ncacn_np: \\1A-7178\PIPE\InitShutdown
ncalrpc: WMsgKRpc098600
ncalrpc: WMsgKRpc0985F1
ncalrpc: WMsgKRpc03C6B42
12345778-1234-abcd-ef00-0123456789ac
version: v1.0
protocol: [MS-SAMR]: Security Account Manager (SAM) Remote Protocol
provider: samsrv.dll
ncacn_ip_tcp: 89.200.169.116:49155
ncalrpc: samss lpc
ncalrpc: dsrole
ncacn_np: \\1A-7178\PIPE\protected_storage
ncalrpc: protected_storage
ncalrpc: securityevent
ncalrpc: audit
ncalrpc: LRPC-43fa5f3097fe9b4692
ncacn_np: \\1A-7178\pipe\lsass
c9ac6db5-82b7-4e55-ae8a-e464ed7b4277
version: v1.0
annotation: Impl friendly name
provider: sysntfy.dll
ncalrpc: samss lpc
ncalrpc: dsrole
ncacn_np: \\1A-7178\PIPE\protected_storage
ncalrpc: protected_storage
ncalrpc: securityevent
ncalrpc: audit
ncalrpc: LRPC-43fa5f3097fe9b4692
ncacn_np: \\1A-7178\pipe\lsass
ncalrpc: LRPC-583567427b509d1559
ncacn_np: \\1A-7178\PIPE\srvsvc
ncalrpc: SECLOGON
ncacn_ip_tcp: 89.200.169.116:49154
ncacn_np: \\1A-7178\PIPE\atsvc
ncalrpc: OLEF00F863D41184EF4B339C089ACE9
ncalrpc: senssvc
ncalrpc: IUserProfile2
ncalrpc: senssvc
ncalrpc: IUserProfile2
ncalrpc: IUserProfile2
ncalrpc: LRPC-962d4dc0bf92f395a3
3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6
version: v1.0
annotation: DHCPv6 Client LRPC Endpoint
provider: dhcpcsvc6.dll
ncalrpc: dhcpcsvc6
ncalrpc: dhcpcsvc
ncacn_ip_tcp: 89.200.169.116:49153
ncacn_np: \\1A-7178\pipe\eventlog
ncalrpc: eventlog
3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5
version: v1.0
annotation: DHCP Client LRPC Endpoint
provider: dhcpcsvc.dll
ncalrpc: dhcpcsvc
ncacn_ip_tcp: 89.200.169.116:49153
ncacn_np: \\1A-7178\pipe\eventlog
ncalrpc: eventlog
f6beaff7-1e19-4fbb-9f8f-b89e2018337c
version: v1.0
annotation: Event log TCPIP
protocol: [MS-EVEN6]: EventLog Remoting Protocol
provider: wevtsvc.dll
ncacn_ip_tcp: 89.200.169.116:49153
ncacn_np: \\1A-7178\pipe\eventlog
ncalrpc: eventlog
30b044a5-a225-43f0-b3a4-e060df91f9c1
version: v1.0
provider: certprop.dll
ncacn_np: \\1A-7178\PIPE\srvsvc
ncalrpc: SECLOGON
ncacn_ip_tcp: 89.200.169.116:49154
ncacn_np: \\1A-7178\PIPE\atsvc
ncalrpc: OLEF00F863D41184EF4B339C089ACE9
ncalrpc: senssvc
ncalrpc: IUserProfile2
a398e520-d59a-4bdd-aa7a-3c1e0303a511
version: v1.0
annotation: IKE/Authip API
provider: IKEEXT.DLL
ncacn_ip_tcp: 89.200.169.116:49154
ncacn_np: \\1A-7178\PIPE\atsvc
ncalrpc: OLEF00F863D41184EF4B339C089ACE9
ncalrpc: senssvc
ncalrpc: IUserProfile2
86d35949-83c9-4044-b424-db363231fd0c
version: v1.0
protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol
provider: schedsvc.dll
ncacn_ip_tcp: 89.200.169.116:49154
ncacn_np: \\1A-7178\PIPE\atsvc
ncalrpc: OLEF00F863D41184EF4B339C089ACE9
ncalrpc: senssvc
ncalrpc: IUserProfile2
378e52b0-c0a9-11cf-822d-00aa0051e40f
version: v1.0
protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol
provider: taskcomp.dll
ncacn_np: \\1A-7178\PIPE\atsvc
ncalrpc: OLEF00F863D41184EF4B339C089ACE9
ncalrpc: senssvc
ncalrpc: IUserProfile2
1ff70682-0a51-30e8-076d-740be8cee98b
version: v1.0
protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol
provider: taskcomp.dll
ncacn_np: \\1A-7178\PIPE\atsvc
ncalrpc: OLEF00F863D41184EF4B339C089ACE9
ncalrpc: senssvc
ncalrpc: IUserProfile2
0a74ef1c-41a4-4e06-83ae-dc74fb1cdd53
version: v1.0
provider: schedsvc.dll
ncalrpc: OLEF00F863D41184EF4B339C089ACE9
ncalrpc: senssvc
ncalrpc: IUserProfile2
2eb08e3e-639f-4fba-97b1-14f878961076
version: v1.0
provider: gpsvc.dll
ncalrpc: LRPC-962d4dc0bf92f395a3
24019106-a203-4642-b88d-82dae9158929
version: v1.0
provider: authui.dll
ncalrpc: LRPC-576aa6609f11007054
ncalrpc: LRPC-12da7f221d7db8b962
3473dd4d-2e88-4006-9cba-22570909dd10
version: v5.256
annotation: WinHttp Auto-Proxy Service
ncacn_np: \\1A-7178\PIPE\W32TIME_ALT
ncalrpc: W32TIME_ALT
ncacn_np: \\1A-7178\PIPE\wkssvc
ncalrpc: LRPC-ef2704b773625ffc4b
ncalrpc: OLEF3A3FC70E3FE4D89A0E7585C48C2
7ea70bcf-48af-4f6a-8968-6a440754d5fa
version: v1.0
annotation: NSI server endpoint
provider: nsisvc.dll
ncalrpc: LRPC-ef2704b773625ffc4b
ncalrpc: OLEF3A3FC70E3FE4D89A0E7585C48C2
2fb92682-6599-42dc-ae13-bd2ca89bd11c
version: v1.0
annotation: Fw APIs
provider: MPSSVC.dll
ncalrpc: LRPC-35da7b97b2a83a9110
7f9d11bf-7fb9-436b-a812-b2d50c5d4c03
version: v1.0
annotation: Fw APIs
provider: MPSSVC.dll
ncalrpc: LRPC-35da7b97b2a83a9110
dd490425-5325-4565-b774-7e27d6c09c24
version: v1.0
annotation: Base Firewall Engine API
provider: BFE.DLL
ncalrpc: LRPC-35da7b97b2a83a9110
4a452661-8290-4b36-8fbe-7f4093a94978
version: v1.0
annotation: Spooler function endpoint
provider: spoolsv.exe
ncalrpc: spoolss
ae33069b-a2a8-46ee-a235-ddfd339be281
version: v1.0
annotation: Spooler base remote object endpoint
protocol: [MS-PAN]: Print System Asynchronous Notification Protocol
provider: spoolsv.exe
ncalrpc: spoolss
0b6edbfa-4a24-4fc6-8a23-942b1eca65d1
version: v1.0
annotation: Spooler function endpoint
protocol: [MS-PAN]: Print System Asynchronous Notification Protocol
provider: spoolsv.exe
ncalrpc: spoolss
12345678-1234-abcd-ef00-0123456789ab
version: v1.0
annotation: IPSec Policy agent endpoint
protocol: [MS-RPRN]: Print System Remote Protocol
provider: spoolsv.exe
ncalrpc: LRPC-b49e53365bbd81792d
ncacn_ip_tcp: 89.200.169.116:49156
6b5bdd1e-528c-422c-af8c-a4079be4fe48
version: v1.0
annotation: Remote Fw APIs
protocol: [MS-FASP]: Firewall and Advanced Security Protocol
provider: FwRemoteSvr.dll
ncacn_ip_tcp: 89.200.169.116:49156
367abb81-9844-35f1-ad32-98f038001003
version: v2.0
protocol: [MS-SCMR]: Service Control Manager Remote Protocol
provider: services.exe
ncacn_ip_tcp: 89.200.169.116:49160
906b0ce0-c70b-1067-b317-00dd010662da
version: v1.0
protocol: [MS-CMPO]: MSDTC Connection Manager:
provider: msdtcprx.dll
ncalrpc: LRPC-7d75b94d994cb10b14
ncalrpc: LRPC-7d75b94d994cb10b14
ncalrpc: LRPC-7d75b94d994cb10b14
ncalrpc: LRPC-7d75b94d994cb10b14
12e65dd8-887f-41ef-91bf-8d816c42c2e7
version: v1.0
annotation: Secure Desktop LRPC interface
provider: winlogon.exe
ncalrpc: WMsgKRpc03C6B42
143 /
tcp
27672397 | 2025-03-22T18:12:13.431242
* OK IMAPrev1
* CAPABILITY IMAP4 IMAP4rev1 CHILDREN IDLE QUOTA SORT ACL NAMESPACE RIGHTS=texk
A001 OK CAPABILITY completed
A002 BAD Unknown or NULL command
A003 BAD Unknown or NULL command
* BYE Have a nice day
A004 OK Logout completed
445 /
tcp
1052066098 | 2025-03-23T13:06:37.371304
SMB Status:
Authentication: enabled
SMB Version: 1
OS: Windows (R) Web Server 2008 6003 Service Pack 2
Software: Windows (R) Web Server 2008 6.0
Capabilities: extended-security, infolevel-passthru, large-files, large-readx, large-writex, level2-oplocks, lock-and-read, lwio, nt-find, nt-smb, nt-status, raw-mode, rpc-remote-api, unicode
995 /
tcp
-1283034168 | 2025-03-12T12:42:57.352142
+OK POP3
+OK CAPA list follows
USER
UIDL
TOP
.
SSL Certificate
Certificate:
Data:
Version: 1 (0x0)
Serial Number:
e7:cf:aa:da:14:b4:27:37
Signature Algorithm: sha256WithRSAEncryption
Issuer: C=de, CN=mail.cetechnologie.de/emailAddress=ce@cetechnologie.de
Validity
Not Before: Feb 23 12:18:45 2018 GMT
Not After : Feb 23 12:18:45 2021 GMT
Subject: C=de, CN=mail.cetechnologie.de/emailAddress=ce@cetechnologie.de
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:ab:fc:18:86:81:87:de:e4:8c:04:56:6a:33:01:
a7:c1:ad:da:b3:d2:27:45:2e:90:1c:a3:5a:eb:b7:
12:37:3a:78:a1:24:88:34:d4:3a:7a:b9:fd:12:41:
8d:c9:40:0e:38:5a:19:54:4f:96:78:bb:68:67:d8:
16:75:9f:f4:ba:f2:00:ca:63:c1:c0:41:1c:0e:e6:
82:c2:99:ea:f8:b7:57:74:09:85:a1:b2:73:c1:5d:
db:bd:c5:e0:6d:17:98:99:dd:d6:1d:64:3c:5b:0d:
f0:e1:1a:d8:3b:f6:31:35:99:14:22:8b:04:40:94:
d5:c7:d9:f1:4e:a8:38:11:3c:f9:11:4a:d2:f8:15:
b7:37:0b:5d:9b:5c:ab:2e:40:64:e0:b1:db:1d:8b:
bf:a8:2b:76:c3:31:7c:c5:f3:aa:ac:a5:c8:f8:1e:
35:88:e0:75:fe:b6:fc:12:8f:71:52:f7:95:2d:74:
ad:fb:c1:0d:3d:ff:c5:44:83:57:13:c1:86:34:7c:
b9:17:02:d4:a7:e8:88:12:3f:68:76:06:5b:9c:02:
f1:28:8e:98:df:c7:fc:8f:33:55:92:ca:01:aa:a6:
ff:db:6e:ac:f5:aa:79:25:3c:cb:59:e1:d6:ae:fb:
ea:85:2c:5f:20:4c:b0:7d:97:59:63:1d:79:2a:17:
78:73
Exponent: 65537 (0x10001)
Signature Algorithm: sha256WithRSAEncryption
Signature Value:
90:9f:91:5d:a1:50:3e:04:de:31:d5:c0:0a:b5:63:cf:61:8a:
f5:ff:aa:3c:cf:da:8b:41:06:87:d4:80:bd:17:04:bb:c9:ad:
36:f9:4d:48:be:67:f3:d4:dd:ab:c4:49:61:32:e5:7f:aa:e5:
4b:6c:76:5e:f9:b0:73:67:c4:51:7a:a4:94:71:84:4a:16:77:
46:c5:4f:2e:03:85:85:e9:59:95:50:da:81:80:d4:b6:9d:1a:
71:78:a1:c4:5c:36:9f:26:5d:ec:f0:43:0f:2b:d7:58:40:17:
be:b2:1c:35:94:c6:13:d6:49:e7:9e:30:21:56:34:55:4f:d0:
bb:31:25:93:6e:3d:87:5f:5e:d5:82:53:5f:25:c3:c9:2b:73:
22:2e:10:0c:dc:2d:04:5d:1d:7f:af:26:60:84:48:21:19:94:
97:12:1c:14:46:fd:d2:37:07:81:67:3f:96:b0:81:5d:05:8f:
46:29:4f:48:c8:61:9b:88:e8:f5:cd:6d:b5:71:8b:44:5c:9b:
40:02:e8:30:3a:34:44:c7:a3:36:2a:5c:fa:14:46:d7:39:30:
2a:6a:1d:11:0c:3f:7c:44:e5:13:cd:ce:b9:14:d0:e9:4c:24:
dc:d5:77:f3:43:97:4a:8b:80:ec:94:ab:8c:54:c2:be:9f:86:
74:8b:19:6f
3389 /
tcp
-317144618 | 2025-03-23T16:43:01.209676
Remote Desktop Protocol
\x03\x00\x00\x13\x0e\xd0\x00\x00\x124\x00\x02\x00\x08\x00\x02\x00\x00\x00
Remote Desktop Protocol NTLM Info:
OS: Windows Vista/Windows Server 2008
OS Build: 6.0.6003
Target Name: 1A-7178
NetBIOS Domain Name: 1A-7178
NetBIOS Computer Name: 1A-7178
DNS Domain Name: 1A-7178
FQDN: 1A-7178
O Warten auf Lokaler Sitzungs-Manager...
Windows Web Server 2008
SSL Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
6d:4b:e3:e0:04:3e:af:94:49:86:42:e3:f3:1c:83:3f
Signature Algorithm: sha1WithRSAEncryption
Issuer: CN=1A-7178
Validity
Not Before: Nov 21 21:58:12 2024 GMT
Not After : May 23 21:58:12 2025 GMT
Subject: CN=1A-7178
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:b1:c0:1e:98:33:a3:89:d6:5e:77:cc:c4:7c:4b:
8a:08:64:10:ba:60:1a:cb:ba:71:19:f6:9e:59:35:
05:67:00:87:ba:cb:f3:f9:4a:d7:86:30:4f:fe:b4:
d9:21:bc:3e:f3:d3:10:82:c7:61:38:51:17:e6:0e:
69:d1:48:20:20:23:4d:05:37:e7:cf:a3:28:f6:2e:
90:17:2f:30:1d:18:51:ec:5c:70:4f:53:49:ad:02:
f3:5f:56:c0:a2:2f:ae:cc:39:6f:25:e4:78:6a:7b:
a3:1d:3a:5d:91:a5:10:76:79:49:b9:67:ed:dd:e3:
ba:47:29:76:8d:eb:02:26:51:c8:9a:02:ff:71:10:
52:b7:05:ac:12:b0:9c:8e:0a:fc:e6:eb:e9:10:7d:
1a:a1:d8:fa:a2:d4:d6:e3:33:41:9e:6c:e1:9c:6c:
2c:e3:40:6e:20:1a:02:26:9c:85:2a:a7:c3:17:c6:
39:44:d0:12:b7:8a:c1:e3:ef:ee:2f:76:e8:29:e1:
2c:39:3f:e4:c1:62:ba:6a:bd:8f:85:ca:10:02:a7:
7c:d9:68:5c:1e:06:a0:60:f2:97:4c:7d:40:c1:da:
61:f6:8b:9f:aa:a5:c8:31:99:96:f4:f1:c8:4d:76:
a5:79:56:88:fb:c5:b3:b5:cd:4b:a0:53:f3:19:ce:
3d:5f
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Extended Key Usage:
TLS Web Server Authentication
X509v3 Key Usage:
Key Encipherment, Data Encipherment
Signature Algorithm: sha1WithRSAEncryption
Signature Value:
80:39:9f:1e:cc:32:81:6c:51:d7:88:aa:7c:98:78:52:f3:05:
6a:ad:4a:05:21:e6:6e:02:b2:c4:56:c4:59:e3:cf:68:05:c8:
fc:77:02:cc:47:3f:bf:5a:b3:82:a7:c4:ac:3e:10:aa:05:7d:
94:5c:2f:96:59:a5:ed:f5:53:60:0d:7e:a5:41:00:45:08:ad:
29:08:c9:77:79:d2:62:ed:22:0e:dc:1a:8e:2b:ca:77:c3:7d:
cf:8a:73:8d:1a:4f:97:53:0d:ed:87:5b:b3:b7:fa:af:8f:31:
53:71:e2:5b:a0:4a:d1:07:29:4e:d9:06:c7:cd:2c:c0:4f:42:
bf:e6:af:ce:d5:a7:5e:28:d0:ec:fd:5b:08:fa:b9:6b:40:14:
db:57:01:8f:e8:64:b8:83:de:98:0d:13:ab:de:45:6a:34:bc:
67:30:1e:81:a8:7d:c9:63:39:af:6f:9b:a4:0f:22:59:48:84:
af:73:2f:60:e0:6f:f4:c0:9d:b8:3f:67:ae:e5:59:11:3d:02:
18:18:fd:6b:1f:b2:85:42:55:b4:5f:01:3a:ca:07:30:d0:11:
30:58:b3:2e:9e:43:02:ac:76:c7:e6:8e:19:81:eb:65:a4:ba:
11:3d:44:0e:04:0e:26:b7:39:4d:c9:dc:cd:52:c9:8f:0a:27:
d3:c8:ca:11
-1684583448 | 2025-03-23T16:13:14.150395
HTTP/1.1 503 Service Unavailable
Content-Type: text/html; charset=us-ascii
Server: Microsoft-HTTPAPI/2.0
Date: Sun, 23 Mar 2025 16:13:09 GMT
Connection: close
Content-Length: 326