25 /
tcp
-1395464144 | 2025-02-16T14:19:30.633805
220 WIN-QHD98838P8B.rakroid.ir ESMTP MailEnable Service, Version: 10.11-- ready at 02/16/25 17:49:28
250-rakroid.ir [224.252.128.184], this server offers 4 extensions
250-AUTH LOGIN
250-SIZE 40960000
250-HELP
250 AUTH=LOGIN
918251753 | 2025-02-13T07:31:23.345286
HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Wed, 03 Jul 2019 04:40:30 GMT
Accept-Ranges: bytes
ETag: "f50dd715931d51:0"
Server: Microsoft-IIS/8.0
X-Powered-By: ASP.NET
Date: Thu, 13 Feb 2025 07:31:22 GMT
Content-Length: 1398
0 | 2025-02-23T15:19:45.938925
<empty title>
HTTP/1.1 302 Found
Date: Sun, 23 Feb 2025 15:19:40 GMT
Server: Apache/2.4.41 (Win64) OpenSSL/1.1.1c PHP/7.3.9
X-Powered-By: PHP/7.3.9
Location: http://89.32.249.215/dashboard/
Content-Length: 0
Content-Type: text/html; charset=UTF-8
110 /
tcp
-471102630 | 2025-01-28T06:13:01.962983
+OK Welcome to MailEnable POP3 Server
+OK Capability list follows
TOP
USER
UIDL
.
135 /
tcp
-361489132 | 2025-02-21T13:33:29.107263
Microsoft RPC Endpoint Mapper
d95afe70-a6d5-4259-822e-2c84da1ddb0d
version: v1.0
protocol: [MS-RSP]: Remote Shutdown Protocol
provider: wininit.exe
ncacn_ip_tcp: 89.32.249.215:49152
ncalrpc: WindowsShutdown
ncacn_np: \\WIN-QHD98838P8B\PIPE\InitShutdown
ncalrpc: WMsgKRpc053AF0
76f226c3-ec14-4325-8a99-6a46348418af
version: v1.0
provider: winlogon.exe
ncalrpc: WindowsShutdown
ncacn_np: \\WIN-QHD98838P8B\PIPE\InitShutdown
ncalrpc: WMsgKRpc053AF0
ncalrpc: WMsgKRpc054421
ncalrpc: WMsgKRpc01C730AC2
c9ac6db5-82b7-4e55-ae8a-e464ed7b4277
version: v1.0
annotation: Impl friendly name
provider: sysntfy.dll
ncalrpc: LRPC-32c13fc4139ae1ff5e
ncalrpc: actkernel
ncalrpc: umpo
ncalrpc: LRPC-25322f5257c29f9844
ncacn_np: \\WIN-QHD98838P8B\PIPE\srvsvc
ncacn_ip_tcp: 89.32.249.215:49155
ncacn_np: \\WIN-QHD98838P8B\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEDADE149E9CA86D8D9E770166387F
ncalrpc: IUserProfile2
ncalrpc: senssvc
ncalrpc: OLEDADE149E9CA86D8D9E770166387F
ncalrpc: IUserProfile2
ncalrpc: OLEDADE149E9CA86D8D9E770166387F
ncalrpc: IUserProfile2
ncalrpc: IUserProfile2
0d3e2735-cea0-4ecc-a9e2-41a2d81aed4e
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
c605f9fb-f0a3-4e2a-a073-73560f8d9e3e
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
1b37ca91-76b1-4f5e-a3c7-2abfc61f2bb0
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
8bfc3be1-6def-4e2d-af74-7c47cd0ade4a
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
2d98a740-581d-41b9-aa0d-a88b9d5ce938
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
3b338d89-6cfa-44b8-847e-531531bc9992
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
8782d3b9-ebbd-4644-a3d8-e8725381919b
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
085b0334-e454-4d91-9b8c-4134f9e793f3
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
4bec6bb8-b5c2-4b6f-b2c1-5da5cf92d0d9
version: v1.0
ncalrpc: actkernel
ncalrpc: umpo
3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5
version: v1.0
annotation: DHCP Client LRPC Endpoint
provider: dhcpcsvc.dll
ncalrpc: dhcpcsvc
ncalrpc: dhcpcsvc6
ncalrpc: LRPC-967f0b5c9f7a01723e
ncacn_ip_tcp: 89.32.249.215:49153
ncacn_np: \\WIN-QHD98838P8B\pipe\eventlog
ncalrpc: eventlog
3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6
version: v1.0
annotation: DHCPv6 Client LRPC Endpoint
provider: dhcpcsvc6.dll
ncalrpc: dhcpcsvc6
ncalrpc: LRPC-967f0b5c9f7a01723e
ncacn_ip_tcp: 89.32.249.215:49153
ncacn_np: \\WIN-QHD98838P8B\pipe\eventlog
ncalrpc: eventlog
30adc50c-5cbc-46ce-9a0e-91914789e23c
version: v1.0
annotation: NRP server endpoint
provider: nrpsrv.dll
ncalrpc: LRPC-967f0b5c9f7a01723e
ncacn_ip_tcp: 89.32.249.215:49153
ncacn_np: \\WIN-QHD98838P8B\pipe\eventlog
ncalrpc: eventlog
f6beaff7-1e19-4fbb-9f8f-b89e2018337c
version: v1.0
annotation: Event log TCPIP
protocol: [MS-EVEN6]: EventLog Remoting Protocol
provider: wevtsvc.dll
ncacn_ip_tcp: 89.32.249.215:49153
ncacn_np: \\WIN-QHD98838P8B\pipe\eventlog
ncalrpc: eventlog
58e604e8-9adb-4d2e-a464-3b0683fb1480
version: v1.0
annotation: AppInfo
provider: appinfo.dll
ncalrpc: DeviceSetupManager
ncalrpc: LRPC-6e4acd13e0a277c7ec
ncalrpc: SessEnvPrivateRpc
ncalrpc: LRPC-b9bf000b3c12eb5140
ncalrpc: LRPC-25322f5257c29f9844
ncacn_np: \\WIN-QHD98838P8B\PIPE\srvsvc
ncacn_ip_tcp: 89.32.249.215:49155
ncacn_np: \\WIN-QHD98838P8B\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEDADE149E9CA86D8D9E770166387F
ncalrpc: IUserProfile2
fd7a0523-dc70-43dd-9b2e-9c5ed48225b1
version: v1.0
annotation: AppInfo
provider: appinfo.dll
ncalrpc: DeviceSetupManager
ncalrpc: LRPC-6e4acd13e0a277c7ec
ncalrpc: SessEnvPrivateRpc
ncalrpc: LRPC-b9bf000b3c12eb5140
ncalrpc: LRPC-25322f5257c29f9844
ncacn_np: \\WIN-QHD98838P8B\PIPE\srvsvc
ncacn_ip_tcp: 89.32.249.215:49155
ncacn_np: \\WIN-QHD98838P8B\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEDADE149E9CA86D8D9E770166387F
ncalrpc: IUserProfile2
5f54ce7d-5b79-4175-8584-cb65313a0e98
version: v1.0
annotation: AppInfo
provider: appinfo.dll
ncalrpc: DeviceSetupManager
ncalrpc: LRPC-6e4acd13e0a277c7ec
ncalrpc: SessEnvPrivateRpc
ncalrpc: LRPC-b9bf000b3c12eb5140
ncalrpc: LRPC-25322f5257c29f9844
ncacn_np: \\WIN-QHD98838P8B\PIPE\srvsvc
ncacn_ip_tcp: 89.32.249.215:49155
ncacn_np: \\WIN-QHD98838P8B\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEDADE149E9CA86D8D9E770166387F
ncalrpc: IUserProfile2
201ef99a-7fa0-444c-9399-19ba84f12a1a
version: v1.0
annotation: AppInfo
provider: appinfo.dll
ncalrpc: DeviceSetupManager
ncalrpc: LRPC-6e4acd13e0a277c7ec
ncalrpc: SessEnvPrivateRpc
ncalrpc: LRPC-b9bf000b3c12eb5140
ncalrpc: LRPC-25322f5257c29f9844
ncacn_np: \\WIN-QHD98838P8B\PIPE\srvsvc
ncacn_ip_tcp: 89.32.249.215:49155
ncacn_np: \\WIN-QHD98838P8B\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEDADE149E9CA86D8D9E770166387F
ncalrpc: IUserProfile2
9b008953-f195-4bf9-bde0-4471971e58ed
version: v1.0
ncalrpc: LRPC-6e4acd13e0a277c7ec
ncalrpc: SessEnvPrivateRpc
ncalrpc: LRPC-b9bf000b3c12eb5140
ncalrpc: LRPC-25322f5257c29f9844
ncacn_np: \\WIN-QHD98838P8B\PIPE\srvsvc
ncacn_ip_tcp: 89.32.249.215:49155
ncacn_np: \\WIN-QHD98838P8B\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEDADE149E9CA86D8D9E770166387F
ncalrpc: IUserProfile2
30b044a5-a225-43f0-b3a4-e060df91f9c1
version: v1.0
provider: certprop.dll
ncalrpc: LRPC-b9bf000b3c12eb5140
ncalrpc: LRPC-25322f5257c29f9844
ncacn_np: \\WIN-QHD98838P8B\PIPE\srvsvc
ncacn_ip_tcp: 89.32.249.215:49155
ncacn_np: \\WIN-QHD98838P8B\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEDADE149E9CA86D8D9E770166387F
ncalrpc: IUserProfile2
880fd55e-43b9-11e0-b1a8-cf4edfd72085
version: v1.0
annotation: KAPI Service endpoint
ncalrpc: LRPC-25322f5257c29f9844
ncacn_np: \\WIN-QHD98838P8B\PIPE\srvsvc
ncacn_ip_tcp: 89.32.249.215:49155
ncacn_np: \\WIN-QHD98838P8B\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEDADE149E9CA86D8D9E770166387F
ncalrpc: IUserProfile2
e40f7b57-7a25-4cd3-a135-7f7d3df9d16b
version: v1.0
annotation: Network Connection Broker server endpoint
ncalrpc: LRPC-25322f5257c29f9844
ncacn_np: \\WIN-QHD98838P8B\PIPE\srvsvc
ncacn_ip_tcp: 89.32.249.215:49155
ncacn_np: \\WIN-QHD98838P8B\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEDADE149E9CA86D8D9E770166387F
ncalrpc: IUserProfile2
c36be077-e14b-4fe9-8abc-e856ef4f048b
version: v1.0
annotation: Proxy Manager client server endpoint
ncacn_np: \\WIN-QHD98838P8B\PIPE\srvsvc
ncacn_ip_tcp: 89.32.249.215:49155
ncacn_np: \\WIN-QHD98838P8B\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEDADE149E9CA86D8D9E770166387F
ncalrpc: IUserProfile2
c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1
version: v1.0
annotation: Adh APIs
ncacn_np: \\WIN-QHD98838P8B\PIPE\srvsvc
ncacn_ip_tcp: 89.32.249.215:49155
ncacn_np: \\WIN-QHD98838P8B\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEDADE149E9CA86D8D9E770166387F
ncalrpc: IUserProfile2
2e6035b2-e8f1-41a7-a044-656b439c4c34
version: v1.0
annotation: Proxy Manager provider server endpoint
ncacn_np: \\WIN-QHD98838P8B\PIPE\srvsvc
ncacn_ip_tcp: 89.32.249.215:49155
ncacn_np: \\WIN-QHD98838P8B\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEDADE149E9CA86D8D9E770166387F
ncalrpc: IUserProfile2
552d076a-cb29-4e44-8b6a-d15e59e2c0af
version: v1.0
annotation: IP Transition Configuration endpoint
provider: iphlpsvc.dll
ncacn_np: \\WIN-QHD98838P8B\PIPE\srvsvc
ncacn_ip_tcp: 89.32.249.215:49155
ncacn_np: \\WIN-QHD98838P8B\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEDADE149E9CA86D8D9E770166387F
ncalrpc: IUserProfile2
1a0d010f-1c33-432c-b0f5-8cf4e8053099
version: v1.0
annotation: IdSegSrv service
ncacn_ip_tcp: 89.32.249.215:49155
ncacn_np: \\WIN-QHD98838P8B\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEDADE149E9CA86D8D9E770166387F
ncalrpc: IUserProfile2
98716d03-89ac-44c7-bb8c-285824e51c4a
version: v1.0
annotation: XactSrv service
provider: srvsvc.dll
ncacn_ip_tcp: 89.32.249.215:49155
ncacn_np: \\WIN-QHD98838P8B\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEDADE149E9CA86D8D9E770166387F
ncalrpc: IUserProfile2
3a9ef155-691d-4449-8d05-09ad57031823
version: v1.0
ncacn_ip_tcp: 89.32.249.215:49155
ncacn_np: \\WIN-QHD98838P8B\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEDADE149E9CA86D8D9E770166387F
ncalrpc: IUserProfile2
86d35949-83c9-4044-b424-db363231fd0c
version: v1.0
protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol
provider: schedsvc.dll
ncacn_ip_tcp: 89.32.249.215:49155
ncacn_np: \\WIN-QHD98838P8B\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEDADE149E9CA86D8D9E770166387F
ncalrpc: IUserProfile2
378e52b0-c0a9-11cf-822d-00aa0051e40f
version: v1.0
protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol
provider: taskcomp.dll
ncacn_np: \\WIN-QHD98838P8B\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEDADE149E9CA86D8D9E770166387F
ncalrpc: IUserProfile2
1ff70682-0a51-30e8-076d-740be8cee98b
version: v1.0
protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol
provider: taskcomp.dll
ncacn_np: \\WIN-QHD98838P8B\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEDADE149E9CA86D8D9E770166387F
ncalrpc: IUserProfile2
0a74ef1c-41a4-4e06-83ae-dc74fb1cdd53
version: v1.0
provider: schedsvc.dll
ncalrpc: senssvc
ncalrpc: OLEDADE149E9CA86D8D9E770166387F
ncalrpc: IUserProfile2
2eb08e3e-639f-4fba-97b1-14f878961076
version: v1.0
annotation: Group Policy RPC Interface
provider: gpsvc.dll
ncalrpc: LRPC-617943f0f64d5abe45
7ea70bcf-48af-4f6a-8968-6a440754d5fa
version: v1.0
annotation: NSI server endpoint
provider: nsisvc.dll
ncalrpc: LRPC-9f9198b34cf0d88c4b
ncalrpc: OLEF33E08D5333132FEBC301485F425
12345778-1234-abcd-ef00-0123456789ac
version: v1.0
protocol: [MS-SAMR]: Security Account Manager (SAM) Remote Protocol
provider: samsrv.dll
ncacn_ip_tcp: 89.32.249.215:49154
ncalrpc: samss lpc
ncalrpc: SidKey Local End Point
ncalrpc: protected_storage
ncalrpc: lsasspirpc
ncalrpc: lsapolicylookup
ncalrpc: LSA_EAS_ENDPOINT
ncalrpc: lsacap
ncalrpc: LSARPC_ENDPOINT
ncalrpc: securityevent
ncalrpc: audit
ncacn_np: \\WIN-QHD98838P8B\pipe\lsass
b2507c30-b126-494a-92ac-ee32b6eeb039
version: v1.0
ncalrpc: LRPC-13b3497e2217240d37
ncalrpc: OLE51A1F176F0FD53DB033A0F3F8EDA
2fb92682-6599-42dc-ae13-bd2ca89bd11c
version: v1.0
annotation: Fw APIs
provider: MPSSVC.dll
ncalrpc: LRPC-119f95b1942f08b1a9
ncalrpc: LRPC-a1c31b00f90fd8f3ea
f47433c3-3e9d-4157-aad4-83aa1f5c2d4c
version: v1.0
annotation: Fw APIs
ncalrpc: LRPC-119f95b1942f08b1a9
ncalrpc: LRPC-a1c31b00f90fd8f3ea
7f9d11bf-7fb9-436b-a812-b2d50c5d4c03
version: v1.0
annotation: Fw APIs
provider: MPSSVC.dll
ncalrpc: LRPC-119f95b1942f08b1a9
ncalrpc: LRPC-a1c31b00f90fd8f3ea
dd490425-5325-4565-b774-7e27d6c09c24
version: v1.0
annotation: Base Firewall Engine API
provider: BFE.DLL
ncalrpc: LRPC-a1c31b00f90fd8f3ea
7f1343fe-50a9-4927-a778-0c5859517bac
version: v1.0
annotation: DfsDs service
ncacn_np: \\WIN-QHD98838P8B\PIPE\wkssvc
ncalrpc: LRPC-b31a11a2ece95938cd
ncalrpc: DNSResolver
eb081a0d-10ee-478a-a1dd-50995283e7a8
version: v3.0
annotation: Witness Client Test Interface
ncalrpc: LRPC-b31a11a2ece95938cd
ncalrpc: DNSResolver
f2c9b409-c1c9-4100-8639-d8ab1486694a
version: v1.0
annotation: Witness Client Upcall Server
ncalrpc: LRPC-b31a11a2ece95938cd
ncalrpc: DNSResolver
4a452661-8290-4b36-8fbe-7f4093a94978
version: v1.0
annotation: Spooler function endpoint
provider: spoolsv.exe
ncalrpc: spoolss
ae33069b-a2a8-46ee-a235-ddfd339be281
version: v1.0
annotation: Spooler base remote object endpoint
protocol: [MS-PAN]: Print System Asynchronous Notification Protocol
provider: spoolsv.exe
ncalrpc: spoolss
0b6edbfa-4a24-4fc6-8a23-942b1eca65d1
version: v1.0
annotation: Spooler function endpoint
protocol: [MS-PAN]: Print System Asynchronous Notification Protocol
provider: spoolsv.exe
ncalrpc: spoolss
50abc2a4-574d-40b3-9d66-ee4fd5fba076
version: v5.0
protocol: [MS-DNSP]: Domain Name Service (DNS) Server Management
provider: dns.exe
ncacn_ip_tcp: 89.32.249.215:49156
367abb81-9844-35f1-ad32-98f038001003
version: v2.0
protocol: [MS-SCMR]: Service Control Manager Remote Protocol
provider: services.exe
ncacn_ip_tcp: 89.32.249.215:49174
12345678-1234-abcd-ef00-0123456789ab
version: v1.0
annotation: IPSec Policy agent endpoint
protocol: [MS-RPRN]: Print System Remote Protocol
provider: spoolsv.exe
ncalrpc: LRPC-244973968f170b644d
ncacn_ip_tcp: 89.32.249.215:49175
6b5bdd1e-528c-422c-af8c-a4079be4fe48
version: v1.0
annotation: Remote Fw APIs
protocol: [MS-FASP]: Firewall and Advanced Security Protocol
provider: FwRemoteSvr.dll
ncacn_ip_tcp: 89.32.249.215:49175
906b0ce0-c70b-1067-b317-00dd010662da
version: v1.0
protocol: [MS-CMPO]: MSDTC Connection Manager:
provider: msdtcprx.dll
ncalrpc: LRPC-88729ba901330449e5
ncalrpc: LRPC-88729ba901330449e5
ncalrpc: LRPC-88729ba901330449e5
12e65dd8-887f-41ef-91bf-8d816c42c2e7
version: v1.0
annotation: Secure Desktop LRPC interface
provider: winlogon.exe
ncalrpc: WMsgKRpc01C730AC2
a500d4c6-0dd1-4543-bc0c-d5f93486eaf8
version: v1.0
ncalrpc: LRPC-d7491eee648c820a9d
137 /
udp
944786839 | 2025-02-21T20:49:23.391974
NetBIOS Response:
Server Name: WIN-QHD98838P8B
MAC Address: 00:16:3E:57:B5:E7
Names:
WIN-QHD98838P8B <0x0>
WORKGROUP <0x0>
WIN-QHD98838P8B <0x20>
MAC Addresses
00:16:3E:57:B5:E7
OUI: 00:16:3E
Organization: Xensource, Inc.
Assignment: MA-L
Registration Date: 2005-10-29
143 /
tcp
539834032 | 2025-02-03T12:09:46.621797
* OK IMAP4rev1 server ready at 02/03/25 15:39:45
* CAPABILITY IMAP4rev1 IMAP4 AUTH=LOGIN AUTH=CRAM-MD5 IDLE CHILDREN UIDPLUS
A001 OK CAPABILITY completed
A002 BAD UNKNOWN Command
A003 BAD UNKNOWN Command
* BYE IMAP4rev1 server terminating connection
A004 OK LOGOUT Initiated
-905500524 | 2025-02-22T23:15:12.594739
HTTP/1.1 200 OK
Date: Sat, 22 Feb 2025 23:15:11 GMT
Server: Apache/2.4.41 (Win64) OpenSSL/1.1.1c PHP/7.3.9
Last-Modified: Mon, 02 Sep 2019 15:46:28 GMT
ETag: "1d98-59193e001fd00"
Accept-Ranges: bytes
Content-Length: 7576
Content-Type: text/html
SSL Certificate
Certificate:
Data:
Version: 1 (0x0)
Serial Number:
b5:c7:52:c9:87:81:b5:03
Signature Algorithm: sha1WithRSAEncryption
Issuer: CN=localhost
Validity
Not Before: Nov 10 23:48:47 2009 GMT
Not After : Nov 8 23:48:47 2019 GMT
Subject: CN=localhost
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (1024 bit)
Modulus:
00:c1:25:d3:27:e3:ec:ad:0d:83:6a:6d:e7:5f:9a:
75:10:23:e2:90:9d:a0:63:95:8f:1d:41:9a:58:d5:
9c:63:8c:5b:73:86:90:79:cc:c3:d6:a3:89:b8:75:
bc:1e:94:7c:7c:6e:e3:ad:e8:27:5c:0b:c6:0c:6a:
f9:0f:32:fe:b3:c4:7a:10:23:04:2b:29:28:d4:aa:
f9:b3:2f:66:10:f8:a7:c1:cd:60:c4:6b:28:57:e3:
67:3b:f7:9e:cd:48:22:dc:38:ea:48:13:80:3a:40:
97:57:0c:47:35:46:3d:71:62:9a:ee:53:9d:63:0e:
67:7a:28:c9:a4:34:ff:19:ed
Exponent: 65537 (0x10001)
Signature Algorithm: sha1WithRSAEncryption
Signature Value:
6a:f1:f3:49:6c:f9:ba:68:5f:6f:f3:27:04:c6:b9:0c:bd:95:
37:34:be:f7:08:66:9a:9b:03:18:41:be:b9:1d:24:33:55:b6:
19:02:1d:54:71:c9:4f:21:5d:68:75:f3:81:52:41:41:c5:93:
c2:1a:7c:e2:7b:c7:4a:24:13:0c:14:9a:4f:a7:10:35:0a:6f:
6a:0f:d3:68:40:ff:48:44:29:9b:45:6a:0c:5c:29:7c:56:2e:
b9:f0:4b:bd:53:5b:2e:42:b1:6c:ad:97:c1:4b:ee:d1:1c:68:
2d:d0:4c:0b:ff:3d:1e:aa:d9:d2:9a:62:38:db:90:f9:7d:8c:
b7:11
445 /
tcp
973987490 | 2025-02-19T08:40:57.756467
SMB Status:
Authentication: enabled
SMB Version: 1
OS: Windows Server 2012 Standard 9200
Software: Windows Server 2012 Standard 6.2
Capabilities: extended-security, infolevel-passthru, large-files, large-readx, large-writex, level2-oplocks, lock-and-read, lwio, nt-find, nt-smb, nt-status, rpc-remote-api, unicode
587 /
tcp
891669271 | 2025-01-28T09:30:28.632188
220 WIN-QHD98838P8B.rakroid.ir ESMTP MailEnable Service, Version: 10.11-- ready at 01/28/25 13:00:26
250-rakroid.ir [224.147.113.194], this server offers 4 extensions
250-AUTH LOGIN
250-SIZE 40960000
250-HELP
250 AUTH=LOGIN
-319991952 | 2025-02-14T19:18:51.314895
HTTP/1.1 202 OK
Connection: Keep-Alive
Content-Length: 1999
Content-Type: text/html
Keep-Alive: timeout=15; max=19
SSL Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 0 (0x0)
Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=vpn124281827.softether.net, O=vpn124281827.softether.net, OU=vpn124281827.softether.net, C=US
Validity
Not Before: Oct 15 06:16:03 2022 GMT
Not After : Dec 31 06:16:03 2037 GMT
Subject: CN=vpn124281827.softether.net, O=vpn124281827.softether.net, OU=vpn124281827.softether.net, C=US
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:d9:41:d0:5b:54:ca:d1:7d:30:8f:02:d1:92:18:
a1:5c:fc:a1:c7:5d:2b:d0:9e:49:b3:a4:45:1b:4f:
5e:5c:77:1f:0e:09:44:c2:32:3f:2c:b0:a7:a9:bc:
86:28:fd:40:99:72:0a:df:34:9f:ff:df:6d:8d:3b:
c0:b1:07:03:4e:93:bb:4e:78:ee:dc:f6:38:5d:7e:
d1:38:94:18:fc:09:9f:81:a4:6d:d7:1f:bf:c3:dd:
b0:5c:76:85:ec:2e:1d:46:65:37:5a:14:2c:4a:32:
d2:42:48:d9:1e:d1:26:83:ac:68:86:58:3f:d6:e5:
64:f9:7a:5d:bd:9b:0f:b4:e0:ad:4c:c3:f8:f5:67:
32:13:25:c1:be:fc:59:02:90:9c:6f:8f:dd:11:e6:
37:ee:80:4a:1f:b2:fa:b2:64:85:11:36:62:66:c3:
96:7c:4f:69:c1:f0:25:76:81:fa:73:76:e8:40:07:
23:d4:92:09:6d:a2:e8:8e:da:b2:5e:c6:57:c5:e3:
13:bd:c0:8c:f5:82:36:3a:54:36:d4:35:d1:ae:39:
6c:9e:2a:d0:13:d2:df:9e:30:24:4a:bd:d4:d0:6c:
69:f4:9f:b7:90:ff:7b:4a:4b:7a:78:28:d1:8e:ac:
ca:e3:3b:eb:75:ba:bd:22:e4:fd:b1:56:58:0a:5c:
a0:55
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Basic Constraints: critical
CA:TRUE
X509v3 Key Usage:
Digital Signature, Non Repudiation, Key Encipherment, Data Encipherment, Certificate Sign, CRL Sign
X509v3 Extended Key Usage:
TLS Web Server Authentication, TLS Web Client Authentication, Code Signing, E-mail Protection, IPSec End System, IPSec Tunnel, IPSec User, Time Stamping, OCSP Signing
Signature Algorithm: sha256WithRSAEncryption
Signature Value:
b1:8d:18:bc:e1:5b:aa:12:cb:94:93:c0:5c:25:96:07:60:16:
cc:b8:7f:4d:72:cc:be:b1:4c:9f:38:00:e3:21:2e:75:a8:d2:
d8:f1:70:a6:d1:ca:3a:bb:a0:88:93:56:29:bd:e8:fd:b4:3e:
a7:57:5b:a6:58:77:9b:18:aa:59:f4:e8:0b:82:fe:f0:47:a7:
0f:9f:af:e7:76:ba:1d:c9:ef:90:5a:10:95:bc:cc:13:30:7a:
7f:3a:b0:b0:66:9a:bc:e3:ec:fa:ea:aa:d5:db:90:8c:b8:a3:
54:a0:db:99:94:4b:8a:07:8c:17:9c:6a:85:7b:48:11:e6:29:
80:45:87:a8:75:77:09:46:30:4c:18:2d:e0:05:41:80:37:cc:
ea:87:d4:0d:d5:33:a5:8c:f0:52:c7:c7:ca:1e:b1:8f:95:ab:
9d:2b:7b:26:86:06:32:7d:40:46:05:12:85:b9:d9:41:b5:76:
19:da:94:05:51:ed:b0:19:86:09:d9:42:99:3c:76:4f:ff:b8:
eb:70:9c:ae:ce:b1:b1:77:b0:5c:70:5a:55:46:87:01:3c:6f:
0c:3a:6e:bf:e8:50:aa:ec:69:8f:1b:5f:20:bd:a8:cc:c7:eb:
68:bf:4a:49:99:09:4f:7b:34:30:5e:5a:6f:6d:85:6c:a0:b0:
d7:49:bd:67
1194 /
udp
127193572 | 2025-02-19T01:17:16.661118
@F\xbc\x04\xab\xe2\x11z^\x01\x00\x00\x00\x00\xd9\xce:\xbe\xf6\x98\xa5m\x00\x00\x00\x00
1433 /
tcp
-1074397532 | 2025-02-21T21:48:05.960965
MS-SQL NTLM Info:
OS: Windows 8/Windows Server 2012
OS Build: 6.2.9200
Target Name: WIN-QHD98838P8B
NetBIOS Domain Name: WIN-QHD98838P8B
NetBIOS Computer Name: WIN-QHD98838P8B
DNS Domain Name: WIN-QHD98838P8B
FQDN: WIN-QHD98838P8B
1701 /
udp
17529794 | 2025-02-13T18:48:42.690884
\xc8\x02\x00_\x00\x00\x00\x00\x00\x00\x00\x01\x80\x08\x00\x00\x00\x00\x00\x02\x80\x08\x00\x00\x00\x02\x01\x00\x00\n\x00\x00\x00\x03\x00\x00\x00\x03\x00\n\x00\x00\x00\x04\x00\x00\x00\x03\x80\x15\x00\x00\x00\x07WIN-QHD98838P8B\x00\n\x00\x00\x00\x08L2TP\x80\x08\x00\x00\x00\t\x00\x01\x00\x08\x00\x00\x00\n\x00\x10
-1060095501 | 2025-02-04T19:19:03.861661
HTTP/1.1 404 Not Found
X-Powered-By: Express
Content-Security-Policy: default-src 'none'
X-Content-Type-Options: nosniff
Content-Type: text/html; charset=utf-8
Content-Length: 139
Date: Tue, 04 Feb 2025 19:18:34 GMT
Connection: keep-alive
Keep-Alive: timeout=5
3306 /
tcp
-1829392689 | 2025-02-13T18:37:47.642166
MariaDB:
Protocol Version: 10
Version: 10.4.6-MariaDB
Capabilities: 63486
Server Language: 8
Server Status: 2
Extended Server Capabilities: 33279
Authentication Plugin: mysql_native_password
4500 /
udp
379953474 | 2025-02-17T16:15:34.286339
VPN (IKE NAT-T)
Initiator SPI: ac7c3775e2e6b0e9
Responder SPI: 0000000000000000
Next Payload: Notification (N)
Version: 1.0
Exchange Type: Informational
Flags:
Encryption: False
Commit: False
Authentication: False
Message ID: 0b311ea8
Length: 48
1489525118 | 2025-02-07T10:13:22.300392
HTTP/1.1 404 Not Found
Content-Type: text/html; charset=us-ascii
Server: Microsoft-HTTPAPI/2.0
Date: Fri, 07 Feb 2025 10:13:21 GMT
Connection: close
Content-Length: 315
WinRM NTLM Info:
OS: Windows Server 2012
OS Build: 6.2.9200
Target Name: WIN-QHD98838P8B
NetBIOS Domain Name: WIN-QHD98838P8B
NetBIOS Computer Name: WIN-QHD98838P8B
DNS Domain Name: WIN-QHD98838P8B
FQDN: WIN-QHD98838P8B
6379 /
tcp
-1468174468 | 2025-02-20T14:27:42.798373
# Server
redis_version:3.0.504
redis_git_sha1:00000000
redis_git_dirty:0
redis_build_id:a4f7a6e86f2d60b3
redis_mode:standalone
os:Windows
arch_bits:64
multiplexing_api:WinSock_IOCP
process_id:1520
run_id:7a1a1020ef04bfd15743f8c5c79d80af6d758a12
tcp_port:6379
uptime_in_seconds:2003913
uptime_in_days:23
hz:10
lru_clock:12008414
config_file:C:\Program Files\Redis\redis.windows-service.conf
# Clients
connected_clients:17
client_longest_output_list:0
client_biggest_input_buf:0
blocked_clients:0
# Memory
used_memory:1026024
used_memory_human:1001.98K
used_memory_rss:967376
used_memory_peak:1046888
used_memory_peak_human:1022.35K
used_memory_lua:36864
mem_fragmentation_ratio:0.94
mem_allocator:jemalloc-3.6.0
# Persistence
loading:0
rdb_changes_since_last_save:0
rdb_bgsave_in_progress:0
rdb_last_save_time:1739262229
rdb_last_bgsave_status:ok
rdb_last_bgsave_time_sec:0
rdb_current_bgsave_time_sec:-1
aof_enabled:0
aof_rewrite_in_progress:0
aof_rewrite_scheduled:0
aof_last_rewrite_time_sec:-1
aof_current_rewrite_time_sec:-1
aof_last_bgrewrite_status:ok
aof_last_write_status:ok
# Stats
total_connections_received:484
total_commands_processed:1064
instantaneous_ops_per_sec:0
total_net_input_bytes:477624
total_net_output_bytes:1821681
instantaneous_input_kbps:0.00
instantaneous_output_kbps:0.00
rejected_connections:0
sync_full:0
sync_partial_ok:0
sync_partial_err:0
expired_keys:42
evicted_keys:0
keyspace_hits:184
keyspace_misses:44
pubsub_channels:0
pubsub_patterns:0
latest_fork_usec:884
migrate_cached_sockets:0
# Replication
role:master
connected_slaves:0
master_repl_offset:0
repl_backlog_active:0
repl_backlog_size:1048576
repl_backlog_first_byte_offset:0
repl_backlog_histlen:0
# CPU
used_cpu_sys:5.66
used_cpu_user:2.13
used_cpu_sys_children:0.00
used_cpu_user_children:0.00
# Cluster
cluster_enabled:0
# Keyspace
# Keys
# Connected Clients
id=332 addr=194.165.16.10:65045 fd=22 name= age=795876 idle=795876 flags=N db=0 sub=0 psub=0 multi=-1 qbuf=0 qbuf-free=0 obl=0 oll=0 omem=0 events=r cmd=NULL
id=36 addr=134.122.120.229:17797 fd=11 name= age=1903453 idle=1903453 flags=N db=0 sub=0 psub=0 multi=-1 qbuf=0 qbuf-free=0 obl=0 oll=0 omem=0 events=r cmd=NULL
id=397 addr=178.128.155.207:58023 fd=21 name= age=551085 idle=551085 flags=N db=0 sub=0 psub=0 multi=-1 qbuf=0 qbuf-free=0 obl=0 oll=0 omem=0 events=r cmd=NULL
id=147 addr=45.227.254.8:65114 fd=13 name= age=1537050 idle=1537050 flags=N db=0 sub=0 psub=0 multi=-1 qbuf=0 qbuf-free=0 obl=0 oll=0 omem=0 events=r cmd=NULL
id=251 addr=157.230.63.85:8759 fd=18 name= age=1165859 idle=1165859 flags=N db=0 sub=0 psub=0 multi=-1 qbuf=0 qbuf-free=0 obl=0 oll=0 omem=0 events=r cmd=NULL
id=434 addr=137.184.133.154:24263 fd=25 name= age=366649 idle=366649 flags=N db=0 sub=0 psub=0 multi=-1 qbuf=0 qbuf-free=0 obl=0 oll=0 omem=0 events=r cmd=NULL
id=342 addr=91.238.181.32:65504 fd=20 name= age=734324 idle=734324 flags=N db=0 sub=0 psub=0 multi=-1 qbuf=0 qbuf-free=0 obl=0 oll=0 omem=0 events=r cmd=NULL
id=218 addr=194.165.16.73:65212 fd=7 name= age=1290180 idle=1290180 flags=N db=0 sub=0 psub=0 multi=-1 qbuf=0 qbuf-free=0 obl=0 oll=0 omem=0 events=r cmd=NULL
id=314 addr=147.45.112.151:65116 fd=16 name= age=921218 idle=921218 flags=N db=0 sub=0 psub=0 multi=-1 qbuf=0 qbuf-free=0 obl=0 oll=0 omem=0 events=r cmd=NULL
id=485 addr=224.110.133.116:50528 fd=26 name= age=0 idle=0 flags=N db=0 sub=0 psub=0 multi=-1 qbuf=0 qbuf-free=32768 obl=0 oll=0 omem=0 events=r cmd=client
id=178 addr=80.66.76.130:65062 fd=14 name= age=1414722 idle=1414722 flags=N db=0 sub=0 psub=0 multi=-1 qbuf=0 qbuf-free=0 obl=0 oll=0 omem=0 events=r cmd=NULL
id=202 addr=91.238.181.35:65459 fd=15 name= age=1353195 idle=1353195 flags=N db=0 sub=0 psub=0 multi=-1 qbuf=0 qbuf-free=0 obl=0 oll=0 omem=0 events=r cmd=NULL
id=216 addr=[::1c00:0:0:0]:65247 fd=12 name= age=1306717 idle=800333 flags=N db=0 sub=0 psub=0 multi=-1 qbuf=0 qbuf-free=0 obl=0 oll=0 omem=0 events=r cmd=set
id=287 addr=159.223.112.248:37691 fd=17 name= age=1045281 idle=1045281 flags=N db=0 sub=0 psub=0 multi=-1 qbuf=0 qbuf-free=0 obl=0 oll=0 omem=0 events=r cmd=NULL
id=190 addr=147.182.142.88:15219 fd=9 name= age=1379894 idle=1379894 flags=N db=0 sub=0 psub=0 multi=-1 qbuf=0 qbuf-free=0 obl=0 oll=0 omem=0 events=r cmd=NULL
id=457 addr=159.89.229.111:14187 fd=24 name= age=195784 idle=195784 flags=N db=0 sub=0 psub=0 multi=-1 qbuf=0 qbuf-free=0 obl=0 oll=0 omem=0 events=r cmd=NULL
id=324 addr=147.182.174.221:64185 fd=19 name= age=845952 idle=845952 flags=N db=0 sub=0 psub=0 multi=-1 qbuf=0 qbuf-free=0 obl=0 oll=0 omem=0 events=r cmd=NULL
1159887650 | 2025-02-13T03:30:57.028814
HTTP/1.1 302 Found
Cache-Control: private
Content-Type: text/html; charset=utf-8
Location: /Default.aspx?pid=Login&ReturnUrl=%2f
Server: Microsoft-IIS/8.0
X-Powered-By: ASP.NET
Date: Thu, 13 Feb 2025 03:30:56 GMT
Content-Length: 158
<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="/Default.aspx?pid=Login&ReturnUrl=%2f">here</a>.</h2>
</body></html>
-1487178651 | 2025-02-20T03:59:05.179797
HTTP/1.1 400 Bad Request
Content-Type: text/html; charset=us-ascii
Server: Microsoft-HTTPAPI/2.0
Date: Thu, 20 Feb 2025 03:59:04 GMT
Connection: close
Content-Length: 334
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN""http://www.w3.org/TR/html4/strict.dtd">
<HTML><HEAD><TITLE>Bad Request</TITLE>
<META HTTP-EQUIV="Content-Type" Content="text/html; charset=us-ascii"></HEAD>
<BODY><h2>Bad Request - Invalid Hostname</h2>
<hr><p>HTTP Error 400. The request hostname is invalid.</p>
</BODY></HTML>
1298793639 | 2025-02-09T20:05:01.392690
HTTP/1.1 400 Bad Request
Content-Type: text/html; charset=us-ascii
Server: Microsoft-HTTPAPI/2.0
Date: Sun, 09 Feb 2025 20:05:00 GMT
Connection: close
Content-Length: 334