-1420197678 | 2024-12-10T23:40:58.094506
25 /
tcp
220 WIN-1RKDBNAVB11.chinahrs.net Winmail Mail Server ESMTP ready; Wed, 11 Dec 2024 07:40:55 +0800
250-Hello [224.214.10.225]
250-AUTH LOGIN PLAIN
250-AUTH=LOGIN PLAIN
250 8BITMIME
-919815153 | 2024-12-13T22:33:04.999786
80 /
tcp
HTTP/1.1 200 OK
Date: Fri, 13 Dec 2024 22:33:04 GMT
Server: Apache
Set-Cookie: magicwinmail_default_theme=default; expires=Sun, 12-Jan-2025 22:33:04 GMT; Max-Age=2592000; path=/; domain=106.120.107.147; HttpOnly
Set-Cookie: magicwinmail_agent_type=pc; expires=Sun, 12-Jan-2025 22:33:04 GMT; Max-Age=2592000; path=/; domain=106.120.107.147; HttpOnly
Set-Cookie: magicwinmail_default_language=ch_gb; expires=Sun, 12-Jan-2025 22:33:04 GMT; Max-Age=2592000; path=/; domain=106.120.107.147; HttpOnly
Set-Cookie: magicwinmail_login_domain=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; Max-Age=0; path=/; domain=106.120.107.147; HttpOnly
Set-Cookie: magicwinmail_client_id=e7f9a8a8355e29e169369236da3c8748; expires=Fri, 13-Dec-2024 23:03:04 GMT; Max-Age=1800; path=/; domain=106.120.107.147; HttpOnly
X-Frame-Options: SAMEORIGIN
Transfer-Encoding: chunked
Content-Type: text/html; charset=utf-8
1427864148 | 2024-12-10T10:08:33.018940
135 /
tcp
Microsoft RPC Endpoint Mapper
d95afe70-a6d5-4259-822e-2c84da1ddb0d
version: v1.0
protocol: [MS-RSP]: Remote Shutdown Protocol
provider: wininit.exe
ncacn_ip_tcp: 192.168.1.248:49152
ncalrpc: WindowsShutdown
ncacn_np: \\WIN-1RKDBNAVB11\PIPE\InitShutdown
ncalrpc: WMsgKRpc02FE120
76f226c3-ec14-4325-8a99-6a46348418af
version: v1.0
provider: winlogon.exe
ncalrpc: WindowsShutdown
ncacn_np: \\WIN-1RKDBNAVB11\PIPE\InitShutdown
ncalrpc: WMsgKRpc02FE120
ncalrpc: WMsgKRpc02FF651
c9ac6db5-82b7-4e55-ae8a-e464ed7b4277
version: v1.0
annotation: Impl friendly name
provider: sysntfy.dll
ncalrpc: LRPC-4957b5c815066ed447
ncacn_np: \\WIN-1RKDBNAVB11\PIPE\srvsvc
ncacn_ip_tcp: 192.168.1.248:49154
ncacn_np: \\WIN-1RKDBNAVB11\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEC08C10395E7C4891AEB2C9D70923
ncalrpc: IUserProfile2
ncalrpc: senssvc
ncalrpc: OLEC08C10395E7C4891AEB2C9D70923
ncalrpc: IUserProfile2
ncalrpc: IUserProfile2
ncalrpc: IUserProfile2
3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5
version: v1.0
annotation: DHCP Client LRPC Endpoint
provider: dhcpcsvc.dll
ncalrpc: dhcpcsvc
ncalrpc: dhcpcsvc6
ncacn_ip_tcp: 192.168.1.248:49153
ncacn_np: \\WIN-1RKDBNAVB11\pipe\eventlog
ncalrpc: eventlog
3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6
version: v1.0
annotation: DHCPv6 Client LRPC Endpoint
provider: dhcpcsvc6.dll
ncalrpc: dhcpcsvc6
ncacn_ip_tcp: 192.168.1.248:49153
ncacn_np: \\WIN-1RKDBNAVB11\pipe\eventlog
ncalrpc: eventlog
30adc50c-5cbc-46ce-9a0e-91914789e23c
version: v1.0
annotation: NRP server endpoint
provider: nrpsrv.dll
ncacn_ip_tcp: 192.168.1.248:49153
ncacn_np: \\WIN-1RKDBNAVB11\pipe\eventlog
ncalrpc: eventlog
f6beaff7-1e19-4fbb-9f8f-b89e2018337c
version: v1.0
annotation: Event log TCPIP
protocol: [MS-EVEN6]: EventLog Remoting Protocol
provider: wevtsvc.dll
ncacn_ip_tcp: 192.168.1.248:49153
ncacn_np: \\WIN-1RKDBNAVB11\pipe\eventlog
ncalrpc: eventlog
30b044a5-a225-43f0-b3a4-e060df91f9c1
version: v1.0
provider: certprop.dll
ncacn_np: \\WIN-1RKDBNAVB11\PIPE\srvsvc
ncacn_ip_tcp: 192.168.1.248:49154
ncacn_np: \\WIN-1RKDBNAVB11\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEC08C10395E7C4891AEB2C9D70923
ncalrpc: IUserProfile2
98716d03-89ac-44c7-bb8c-285824e51c4a
version: v1.0
annotation: XactSrv service
provider: srvsvc.dll
ncacn_ip_tcp: 192.168.1.248:49154
ncacn_np: \\WIN-1RKDBNAVB11\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEC08C10395E7C4891AEB2C9D70923
ncalrpc: IUserProfile2
552d076a-cb29-4e44-8b6a-d15e59e2c0af
version: v1.0
annotation: IP Transition Configuration endpoint
provider: iphlpsvc.dll
ncacn_ip_tcp: 192.168.1.248:49154
ncacn_np: \\WIN-1RKDBNAVB11\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEC08C10395E7C4891AEB2C9D70923
ncalrpc: IUserProfile2
a398e520-d59a-4bdd-aa7a-3c1e0303a511
version: v1.0
annotation: IKE/Authip API
provider: IKEEXT.DLL
ncacn_ip_tcp: 192.168.1.248:49154
ncacn_np: \\WIN-1RKDBNAVB11\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEC08C10395E7C4891AEB2C9D70923
ncalrpc: IUserProfile2
86d35949-83c9-4044-b424-db363231fd0c
version: v1.0
protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol
provider: schedsvc.dll
ncacn_ip_tcp: 192.168.1.248:49154
ncacn_np: \\WIN-1RKDBNAVB11\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEC08C10395E7C4891AEB2C9D70923
ncalrpc: IUserProfile2
378e52b0-c0a9-11cf-822d-00aa0051e40f
version: v1.0
protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol
provider: taskcomp.dll
ncacn_np: \\WIN-1RKDBNAVB11\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEC08C10395E7C4891AEB2C9D70923
ncalrpc: IUserProfile2
1ff70682-0a51-30e8-076d-740be8cee98b
version: v1.0
protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol
provider: taskcomp.dll
ncacn_np: \\WIN-1RKDBNAVB11\PIPE\atsvc
ncalrpc: senssvc
ncalrpc: OLEC08C10395E7C4891AEB2C9D70923
ncalrpc: IUserProfile2
0a74ef1c-41a4-4e06-83ae-dc74fb1cdd53
version: v1.0
provider: schedsvc.dll
ncalrpc: senssvc
ncalrpc: OLEC08C10395E7C4891AEB2C9D70923
ncalrpc: IUserProfile2
2eb08e3e-639f-4fba-97b1-14f878961076
version: v1.0
provider: gpsvc.dll
ncalrpc: IUserProfile2
3473dd4d-2e88-4006-9cba-22570909dd10
version: v5.256
annotation: WinHttp Auto-Proxy Service
ncalrpc: LRPC-05ebc64b86602caabc
ncalrpc: OLE4222028B74BF4F2988DAD3B2E396
7ea70bcf-48af-4f6a-8968-6a440754d5fa
version: v1.0
annotation: NSI server endpoint
provider: nsisvc.dll
ncalrpc: LRPC-05ebc64b86602caabc
ncalrpc: OLE4222028B74BF4F2988DAD3B2E396
2fb92682-6599-42dc-ae13-bd2ca89bd11c
version: v1.0
annotation: Fw APIs
provider: MPSSVC.dll
ncalrpc: LRPC-d5966219791b67d9c3
7f9d11bf-7fb9-436b-a812-b2d50c5d4c03
version: v1.0
annotation: Fw APIs
provider: MPSSVC.dll
ncalrpc: LRPC-d5966219791b67d9c3
dd490425-5325-4565-b774-7e27d6c09c24
version: v1.0
annotation: Base Firewall Engine API
provider: BFE.DLL
ncalrpc: LRPC-d5966219791b67d9c3
24019106-a203-4642-b88d-82dae9158929
version: v1.0
provider: authui.dll
ncalrpc: LRPC-ed000e601e94f84699
4a452661-8290-4b36-8fbe-7f4093a94978
version: v1.0
annotation: Spooler function endpoint
provider: spoolsv.exe
ncalrpc: spoolss
ae33069b-a2a8-46ee-a235-ddfd339be281
version: v1.0
annotation: Spooler base remote object endpoint
protocol: [MS-PAN]: Print System Asynchronous Notification Protocol
provider: spoolsv.exe
ncalrpc: spoolss
0b6edbfa-4a24-4fc6-8a23-942b1eca65d1
version: v1.0
annotation: Spooler function endpoint
protocol: [MS-PAN]: Print System Asynchronous Notification Protocol
provider: spoolsv.exe
ncalrpc: spoolss
12345778-1234-abcd-ef00-0123456789ac
version: v1.0
protocol: [MS-SAMR]: Security Account Manager (SAM) Remote Protocol
provider: samsrv.dll
ncacn_ip_tcp: 192.168.1.248:49155
ncalrpc: samss lpc
ncalrpc: dsrole
ncacn_np: \\WIN-1RKDBNAVB11\PIPE\protected_storage
ncalrpc: protected_storage
ncalrpc: lsasspirpc
ncalrpc: lsapolicylookup
ncalrpc: LSARPC_ENDPOINT
ncalrpc: securityevent
ncalrpc: audit
ncalrpc: LRPC-c4583df9f6940f15bc
ncacn_np: \\WIN-1RKDBNAVB11\pipe\lsass
12d4b7c8-77d5-11d1-8c24-00c04fa3080d
version: v1.0
provider: lserver.dll
ncacn_ip_tcp: 192.168.1.248:49156
ncacn_np: \\WIN-1RKDBNAVB11\pipe\HydraLsPipe
ncalrpc: LRPC-6dc1b6cb8be514b826
3d267954-eeb7-11d1-b94e-00c04fa3080d
version: v1.0
provider: lserver.dll
ncacn_ip_tcp: 192.168.1.248:49156
ncacn_np: \\WIN-1RKDBNAVB11\pipe\HydraLsPipe
ncalrpc: LRPC-6dc1b6cb8be514b826
367abb81-9844-35f1-ad32-98f038001003
version: v2.0
protocol: [MS-SCMR]: Service Control Manager Remote Protocol
provider: services.exe
ncacn_ip_tcp: 192.168.1.248:49157
12345678-1234-abcd-ef00-0123456789ab
version: v1.0
annotation: IPSec Policy agent endpoint
protocol: [MS-RPRN]: Print System Remote Protocol
provider: spoolsv.exe
ncalrpc: LRPC-fb541a427876054fac
-1271692889 | 2024-12-08T13:12:54.396620
143 /
tcp
* OK WIN-1RKDBNAVB11.chinahrs.net Winmail Mail Server IMAP4 ready
* CAPABILITY IMAP4rev1 ID UIDPLUS STARTTLS APPENDLIMIT=52428800
A001 OK CAPABILITY completed
* ID ("name" "Winmail Mail Server" "version" "7.0.0630")
A002 OK ID completed
A003 BAD Error in IMAP command
* BYE IMAP4 server shutting down
A004 OK LOGOUT completed
1789744715 | 2024-12-23T12:41:34.220983
465 /
tcp
220 WIN-1RKDBNAVB11.chinahrs.net Winmail Mail Server Secure ESMTP ready; Mon, 23 Dec 2024 20:41:07 +0800
250-Hello [224.155.107.18]
250-AUTH LOGIN PLAIN
250-AUTH=LOGIN PLAIN
250 8BITMIME
SSL Certificate
Certificate:
Data:
Version: 1 (0x0)
Serial Number: 0 (0x0)
Signature Algorithm: md5WithRSAEncryption
Issuer: C=US, CN=WIN-1RKDBNAVB11
Validity
Not Before: Jul 30 04:22:46 2015 GMT
Not After : Jul 27 04:22:46 2025 GMT
Subject: C=US, CN=WIN-1RKDBNAVB11
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (1024 bit)
Modulus:
00:db:18:ec:e5:fb:74:af:4f:6b:6e:10:00:81:c7:
6b:87:45:c7:ab:3c:2b:5c:9c:8a:8d:44:46:f0:ec:
39:3d:6d:cd:ee:f1:6a:c8:51:8a:ba:ed:f8:69:08:
b5:38:26:29:9a:65:df:82:a4:08:5f:94:85:4e:7e:
e8:b2:7c:b1:47:a3:f2:a8:39:d6:0e:7a:02:a8:61:
84:b0:22:aa:15:9c:4f:3c:a9:ea:17:bd:dd:10:a8:
17:f5:ad:32:33:e3:2d:be:e9:af:c3:59:a2:18:90:
8e:9b:fa:3f:08:70:19:49:8c:78:83:92:80:4f:59:
5f:b9:39:9c:1b:e8:c7:16:2b
Exponent: 65537 (0x10001)
Signature Algorithm: md5WithRSAEncryption
Signature Value:
69:84:e8:d5:da:79:90:b7:bb:c4:cf:80:ea:aa:44:fa:b1:19:
63:44:a5:35:86:cf:f7:7d:82:ad:7e:01:aa:47:86:aa:6e:f4:
c4:78:25:54:01:ff:05:0e:e7:63:6f:8f:6b:07:6a:6a:f9:1b:
70:f0:75:43:fd:4b:6f:3b:af:e8:4b:6d:b3:26:40:44:5a:25:
32:b7:26:da:84:4f:d1:e6:b7:bf:02:9f:b1:9f:b1:57:f5:73:
a6:f4:3f:e2:af:31:68:90:bd:c8:1e:88:85:a6:bf:08:f1:cf:
a6:57:af:23:8d:fd:07:45:9d:f9:da:ff:c4:78:16:ef:39:70:
a4:37
-2052164652 | 2024-12-21T04:35:22.373037
587 /
tcp
220 WIN-1RKDBNAVB11.chinahrs.net Winmail Mail Server ESMTP(MSA) ready; Sat, 21 Dec 2024 12:35:19 +0800
250-Hello [224.157.250.39]
250-AUTH LOGIN PLAIN
250-AUTH=LOGIN PLAIN
250 8BITMIME
1705733471 | 2024-12-21T05:15:32.320309
993 /
tcp
* OK WIN-1RKDBNAVB11.chinahrs.net Winmail Mail Server Secure IMAP4 ready
* CAPABILITY IMAP4rev1 ID UIDPLUS APPENDLIMIT=52428800
A001 OK CAPABILITY completed
* ID ("name" "Winmail Mail Server" "version" "7.0.0630")
A002 OK ID completed
A003 BAD Error in IMAP command
* BYE IMAP4 server shutting down
A004 OK LOGOUT completed
SSL Certificate
Certificate:
Data:
Version: 1 (0x0)
Serial Number: 0 (0x0)
Signature Algorithm: md5WithRSAEncryption
Issuer: C=US, CN=WIN-1RKDBNAVB11
Validity
Not Before: Jul 30 04:22:46 2015 GMT
Not After : Jul 27 04:22:46 2025 GMT
Subject: C=US, CN=WIN-1RKDBNAVB11
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (1024 bit)
Modulus:
00:db:18:ec:e5:fb:74:af:4f:6b:6e:10:00:81:c7:
6b:87:45:c7:ab:3c:2b:5c:9c:8a:8d:44:46:f0:ec:
39:3d:6d:cd:ee:f1:6a:c8:51:8a:ba:ed:f8:69:08:
b5:38:26:29:9a:65:df:82:a4:08:5f:94:85:4e:7e:
e8:b2:7c:b1:47:a3:f2:a8:39:d6:0e:7a:02:a8:61:
84:b0:22:aa:15:9c:4f:3c:a9:ea:17:bd:dd:10:a8:
17:f5:ad:32:33:e3:2d:be:e9:af:c3:59:a2:18:90:
8e:9b:fa:3f:08:70:19:49:8c:78:83:92:80:4f:59:
5f:b9:39:9c:1b:e8:c7:16:2b
Exponent: 65537 (0x10001)
Signature Algorithm: md5WithRSAEncryption
Signature Value:
69:84:e8:d5:da:79:90:b7:bb:c4:cf:80:ea:aa:44:fa:b1:19:
63:44:a5:35:86:cf:f7:7d:82:ad:7e:01:aa:47:86:aa:6e:f4:
c4:78:25:54:01:ff:05:0e:e7:63:6f:8f:6b:07:6a:6a:f9:1b:
70:f0:75:43:fd:4b:6f:3b:af:e8:4b:6d:b3:26:40:44:5a:25:
32:b7:26:da:84:4f:d1:e6:b7:bf:02:9f:b1:9f:b1:57:f5:73:
a6:f4:3f:e2:af:31:68:90:bd:c8:1e:88:85:a6:bf:08:f1:cf:
a6:57:af:23:8d:fd:07:45:9d:f9:da:ff:c4:78:16:ef:39:70:
a4:37
-2060740054 | 2024-12-15T13:42:34.407375
995 /
tcp
+OK WIN-1RKDBNAVB11.chinahrs.net Winmail Mail Server Secure POP3 ready
+OK Capability list follows
TOP
USER
UIDL
PLAIN
.
SSL Certificate
Certificate:
Data:
Version: 1 (0x0)
Serial Number: 0 (0x0)
Signature Algorithm: md5WithRSAEncryption
Issuer: C=US, CN=WIN-1RKDBNAVB11
Validity
Not Before: Jul 30 04:22:46 2015 GMT
Not After : Jul 27 04:22:46 2025 GMT
Subject: C=US, CN=WIN-1RKDBNAVB11
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (1024 bit)
Modulus:
00:db:18:ec:e5:fb:74:af:4f:6b:6e:10:00:81:c7:
6b:87:45:c7:ab:3c:2b:5c:9c:8a:8d:44:46:f0:ec:
39:3d:6d:cd:ee:f1:6a:c8:51:8a:ba:ed:f8:69:08:
b5:38:26:29:9a:65:df:82:a4:08:5f:94:85:4e:7e:
e8:b2:7c:b1:47:a3:f2:a8:39:d6:0e:7a:02:a8:61:
84:b0:22:aa:15:9c:4f:3c:a9:ea:17:bd:dd:10:a8:
17:f5:ad:32:33:e3:2d:be:e9:af:c3:59:a2:18:90:
8e:9b:fa:3f:08:70:19:49:8c:78:83:92:80:4f:59:
5f:b9:39:9c:1b:e8:c7:16:2b
Exponent: 65537 (0x10001)
Signature Algorithm: md5WithRSAEncryption
Signature Value:
69:84:e8:d5:da:79:90:b7:bb:c4:cf:80:ea:aa:44:fa:b1:19:
63:44:a5:35:86:cf:f7:7d:82:ad:7e:01:aa:47:86:aa:6e:f4:
c4:78:25:54:01:ff:05:0e:e7:63:6f:8f:6b:07:6a:6a:f9:1b:
70:f0:75:43:fd:4b:6f:3b:af:e8:4b:6d:b3:26:40:44:5a:25:
32:b7:26:da:84:4f:d1:e6:b7:bf:02:9f:b1:9f:b1:57:f5:73:
a6:f4:3f:e2:af:31:68:90:bd:c8:1e:88:85:a6:bf:08:f1:cf:
a6:57:af:23:8d:fd:07:45:9d:f9:da:ff:c4:78:16:ef:39:70:
a4:37
-1947422558 | 2024-12-07T12:03:11.426188
6443 /
tcp
HTTP/1.1 200 OK
Date: Sat, 07 Dec 2024 12:03:10 GMT
Server: Apache
Set-Cookie: magicwinmail_default_theme=default; expires=Mon, 06-Jan-2025 12:03:10 GMT; Max-Age=2592000; path=/; domain=106.120.107.147; secure; HttpOnly
Set-Cookie: magicwinmail_agent_type=pc; expires=Mon, 06-Jan-2025 12:03:10 GMT; Max-Age=2592000; path=/; domain=106.120.107.147; secure; HttpOnly
Set-Cookie: magicwinmail_default_language=ch_gb; expires=Mon, 06-Jan-2025 12:03:10 GMT; Max-Age=2592000; path=/; domain=106.120.107.147; secure; HttpOnly
Set-Cookie: magicwinmail_login_domain=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; Max-Age=0; path=/; domain=106.120.107.147; secure; HttpOnly
Set-Cookie: magicwinmail_client_id=7beff0c6f5ae4fb84d8775c4e90cbcde; expires=Sat, 07-Dec-2024 12:33:10 GMT; Max-Age=1800; path=/; domain=106.120.107.147; secure; HttpOnly
X-Frame-Options: SAMEORIGIN
Upgrade: h2,h2c
Connection: Upgrade
Transfer-Encoding: chunked
Content-Type: text/html; charset=utf-8
SSL Certificate
Certificate:
Data:
Version: 1 (0x0)
Serial Number: 0 (0x0)
Signature Algorithm: md5WithRSAEncryption
Issuer: C=US, CN=WIN-1RKDBNAVB11
Validity
Not Before: Jul 30 04:22:46 2015 GMT
Not After : Jul 27 04:22:46 2025 GMT
Subject: C=US, CN=WIN-1RKDBNAVB11
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (1024 bit)
Modulus:
00:db:18:ec:e5:fb:74:af:4f:6b:6e:10:00:81:c7:
6b:87:45:c7:ab:3c:2b:5c:9c:8a:8d:44:46:f0:ec:
39:3d:6d:cd:ee:f1:6a:c8:51:8a:ba:ed:f8:69:08:
b5:38:26:29:9a:65:df:82:a4:08:5f:94:85:4e:7e:
e8:b2:7c:b1:47:a3:f2:a8:39:d6:0e:7a:02:a8:61:
84:b0:22:aa:15:9c:4f:3c:a9:ea:17:bd:dd:10:a8:
17:f5:ad:32:33:e3:2d:be:e9:af:c3:59:a2:18:90:
8e:9b:fa:3f:08:70:19:49:8c:78:83:92:80:4f:59:
5f:b9:39:9c:1b:e8:c7:16:2b
Exponent: 65537 (0x10001)
Signature Algorithm: md5WithRSAEncryption
Signature Value:
69:84:e8:d5:da:79:90:b7:bb:c4:cf:80:ea:aa:44:fa:b1:19:
63:44:a5:35:86:cf:f7:7d:82:ad:7e:01:aa:47:86:aa:6e:f4:
c4:78:25:54:01:ff:05:0e:e7:63:6f:8f:6b:07:6a:6a:f9:1b:
70:f0:75:43:fd:4b:6f:3b:af:e8:4b:6d:b3:26:40:44:5a:25:
32:b7:26:da:84:4f:d1:e6:b7:bf:02:9f:b1:9f:b1:57:f5:73:
a6:f4:3f:e2:af:31:68:90:bd:c8:1e:88:85:a6:bf:08:f1:cf:
a6:57:af:23:8d:fd:07:45:9d:f9:da:ff:c4:78:16:ef:39:70:
a4:37