Hostnames |
zettamobi.xyz www.zettamobi.xyz |
Domains | zettamobi.xyz |
Country | India |
City | Delhi |
Organization | Primenet Web Technologies Pvt Ltd |
ISP | Primesoftex Ltd |
ASN | AS17426 |
Note: the device may not be impacted by all of these issues. The vulnerabilities are implied based on the software and version.
CVE-2014-4078 | 5.1The IP Security feature in Microsoft Internet Information Services (IIS) 8.0 and 8.5 does not properly process wildcard allow and deny rules for domains within the "IP Address and Domain Restrictions" list, which makes it easier for remote attackers to bypass an intended rule set via an HTTP request, aka "IIS Security Feature Bypass Vulnerability." |
-985096807 | 2024-05-19T09:09:59.89521580 / tcp
HTTP/1.1 403 Forbidden Content-Type: text/html Server: Microsoft-IIS/8.5 X-Powered-By: ASP.NET Date: Sun, 19 May 2024 09:09:58 GMT Content-Length: 1233
-1898739010 | 2024-05-22T19:36:37.814040135 / tcp
Microsoft RPC Endpoint Mapper d95afe70-a6d5-4259-822e-2c84da1ddb0d version: v1.0 protocol: [MS-RSP]: Remote Shutdown Protocol provider: wininit.exe ncacn_ip_tcp: 103.91.90.251:10000 ncalrpc: WindowsShutdown ncacn_np: \\WIN-5TDSVV5L6Q3\PIPE\InitShutdown ncalrpc: WMsgKRpc099EE0 76f226c3-ec14-4325-8a99-6a46348418af version: v1.0 provider: winlogon.exe ncalrpc: WindowsShutdown ncacn_np: \\WIN-5TDSVV5L6Q3\PIPE\InitShutdown ncalrpc: WMsgKRpc099EE0 ncalrpc: WMsgKRpc0A0E51 ncalrpc: WMsgKRpc03180D2 9b008953-f195-4bf9-bde0-4471971e58ed version: v1.0 ncalrpc: dabrpc ncalrpc: LRPC-e641514c4e830607d6 ncacn_np: \\WIN-5TDSVV5L6Q3\pipe\LSM_API_service ncalrpc: LSMApi ncalrpc: LRPC-0e4b2aba8e1bd1584e ncalrpc: actkernel ncalrpc: umpo 697dcda9-3ba9-4eb2-9247-e11f1901b0d2 version: v1.0 ncalrpc: LRPC-e641514c4e830607d6 ncacn_np: \\WIN-5TDSVV5L6Q3\pipe\LSM_API_service ncalrpc: LSMApi ncalrpc: LRPC-0e4b2aba8e1bd1584e ncalrpc: actkernel ncalrpc: umpo c9ac6db5-82b7-4e55-ae8a-e464ed7b4277 version: v1.0 annotation: Impl friendly name provider: sysntfy.dll ncalrpc: LRPC-0e4b2aba8e1bd1584e ncalrpc: actkernel ncalrpc: umpo ncacn_np: \\WIN-5TDSVV5L6Q3\PIPE\srvsvc ncacn_ip_tcp: 103.91.90.251:10002 ncalrpc: ubpmtaskhostchannel ncacn_np: \\WIN-5TDSVV5L6Q3\PIPE\atsvc ncalrpc: senssvc ncalrpc: OLE607126F7F3E45DE7BC97C9627DD5 ncalrpc: IUserProfile2 ncalrpc: senssvc ncalrpc: OLE607126F7F3E45DE7BC97C9627DD5 ncalrpc: IUserProfile2 ncalrpc: IUserProfile2 ncalrpc: IUserProfile2 0d3e2735-cea0-4ecc-a9e2-41a2d81aed4e version: v1.0 ncalrpc: actkernel ncalrpc: umpo c605f9fb-f0a3-4e2a-a073-73560f8d9e3e version: v1.0 ncalrpc: actkernel ncalrpc: umpo 1b37ca91-76b1-4f5e-a3c7-2abfc61f2bb0 version: v1.0 ncalrpc: actkernel ncalrpc: umpo 8bfc3be1-6def-4e2d-af74-7c47cd0ade4a version: v1.0 ncalrpc: actkernel ncalrpc: umpo 2d98a740-581d-41b9-aa0d-a88b9d5ce938 version: v1.0 ncalrpc: actkernel ncalrpc: umpo bdaa0970-413b-4a3e-9e5d-f6dc9d7e0760 version: v1.0 ncalrpc: actkernel ncalrpc: umpo 3b338d89-6cfa-44b8-847e-531531bc9992 version: v1.0 ncalrpc: actkernel ncalrpc: umpo 8782d3b9-ebbd-4644-a3d8-e8725381919b version: v1.0 ncalrpc: actkernel ncalrpc: umpo 085b0334-e454-4d91-9b8c-4134f9e793f3 version: v1.0 ncalrpc: actkernel ncalrpc: umpo 4bec6bb8-b5c2-4b6f-b2c1-5da5cf92d0d9 version: v1.0 ncalrpc: actkernel ncalrpc: umpo 30adc50c-5cbc-46ce-9a0e-91914789e23c version: v1.0 annotation: NRP server endpoint provider: nrpsrv.dll ncalrpc: dhcpcsvc ncalrpc: dhcpcsvc6 ncalrpc: LRPC-61c3136d9079455767 ncacn_ip_tcp: 103.91.90.251:10001 ncacn_np: \\WIN-5TDSVV5L6Q3\pipe\eventlog ncalrpc: eventlog abfb6ca3-0c5e-4734-9285-0aee72fe8d1c version: v1.0 annotation: Wcm Service ncalrpc: dhcpcsvc6 ncalrpc: LRPC-61c3136d9079455767 ncacn_ip_tcp: 103.91.90.251:10001 ncacn_np: \\WIN-5TDSVV5L6Q3\pipe\eventlog ncalrpc: eventlog 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5 version: v1.0 annotation: DHCP Client LRPC Endpoint provider: dhcpcsvc.dll ncalrpc: dhcpcsvc ncalrpc: dhcpcsvc6 ncalrpc: LRPC-61c3136d9079455767 ncacn_ip_tcp: 103.91.90.251:10001 ncacn_np: \\WIN-5TDSVV5L6Q3\pipe\eventlog ncalrpc: eventlog 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6 version: v1.0 annotation: DHCPv6 Client LRPC Endpoint provider: dhcpcsvc6.dll ncalrpc: dhcpcsvc6 ncalrpc: LRPC-61c3136d9079455767 ncacn_ip_tcp: 103.91.90.251:10001 ncacn_np: \\WIN-5TDSVV5L6Q3\pipe\eventlog ncalrpc: eventlog f6beaff7-1e19-4fbb-9f8f-b89e2018337c version: v1.0 annotation: Event log TCPIP protocol: [MS-EVEN6]: EventLog Remoting Protocol provider: wevtsvc.dll ncacn_ip_tcp: 103.91.90.251:10001 ncacn_np: \\WIN-5TDSVV5L6Q3\pipe\eventlog ncalrpc: eventlog 30b044a5-a225-43f0-b3a4-e060df91f9c1 version: v1.0 provider: certprop.dll ncalrpc: LRPC-30f87593e97428e8ae ncacn_np: \\WIN-5TDSVV5L6Q3\PIPE\srvsvc ncacn_ip_tcp: 103.91.90.251:10002 ncalrpc: ubpmtaskhostchannel ncacn_np: \\WIN-5TDSVV5L6Q3\PIPE\atsvc ncalrpc: senssvc ncalrpc: OLE607126F7F3E45DE7BC97C9627DD5 ncalrpc: IUserProfile2 1a0d010f-1c33-432c-b0f5-8cf4e8053099 version: v1.0 annotation: IdSegSrv service ncacn_ip_tcp: 103.91.90.251:10002 ncalrpc: ubpmtaskhostchannel ncacn_np: \\WIN-5TDSVV5L6Q3\PIPE\atsvc ncalrpc: senssvc ncalrpc: OLE607126F7F3E45DE7BC97C9627DD5 ncalrpc: IUserProfile2 98716d03-89ac-44c7-bb8c-285824e51c4a version: v1.0 annotation: XactSrv service provider: srvsvc.dll ncacn_ip_tcp: 103.91.90.251:10002 ncalrpc: ubpmtaskhostchannel ncacn_np: \\WIN-5TDSVV5L6Q3\PIPE\atsvc ncalrpc: senssvc ncalrpc: OLE607126F7F3E45DE7BC97C9627DD5 ncalrpc: IUserProfile2 c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1 version: v1.0 annotation: Adh APIs ncacn_ip_tcp: 103.91.90.251:10002 ncalrpc: ubpmtaskhostchannel ncacn_np: \\WIN-5TDSVV5L6Q3\PIPE\atsvc ncalrpc: senssvc ncalrpc: OLE607126F7F3E45DE7BC97C9627DD5 ncalrpc: IUserProfile2 c36be077-e14b-4fe9-8abc-e856ef4f048b version: v1.0 annotation: Proxy Manager client server endpoint ncacn_ip_tcp: 103.91.90.251:10002 ncalrpc: ubpmtaskhostchannel ncacn_np: \\WIN-5TDSVV5L6Q3\PIPE\atsvc ncalrpc: senssvc ncalrpc: OLE607126F7F3E45DE7BC97C9627DD5 ncalrpc: IUserProfile2 2e6035b2-e8f1-41a7-a044-656b439c4c34 version: v1.0 annotation: Proxy Manager provider server endpoint ncacn_ip_tcp: 103.91.90.251:10002 ncalrpc: ubpmtaskhostchannel ncacn_np: \\WIN-5TDSVV5L6Q3\PIPE\atsvc ncalrpc: senssvc ncalrpc: OLE607126F7F3E45DE7BC97C9627DD5 ncalrpc: IUserProfile2 552d076a-cb29-4e44-8b6a-d15e59e2c0af version: v1.0 annotation: IP Transition Configuration endpoint provider: iphlpsvc.dll ncacn_ip_tcp: 103.91.90.251:10002 ncalrpc: ubpmtaskhostchannel ncacn_np: \\WIN-5TDSVV5L6Q3\PIPE\atsvc ncalrpc: senssvc ncalrpc: OLE607126F7F3E45DE7BC97C9627DD5 ncalrpc: IUserProfile2 a398e520-d59a-4bdd-aa7a-3c1e0303a511 version: v1.0 annotation: IKE/Authip API provider: IKEEXT.DLL ncacn_ip_tcp: 103.91.90.251:10002 ncalrpc: ubpmtaskhostchannel ncacn_np: \\WIN-5TDSVV5L6Q3\PIPE\atsvc ncalrpc: senssvc ncalrpc: OLE607126F7F3E45DE7BC97C9627DD5 ncalrpc: IUserProfile2 3a9ef155-691d-4449-8d05-09ad57031823 version: v1.0 ncacn_ip_tcp: 103.91.90.251:10002 ncalrpc: ubpmtaskhostchannel ncacn_np: \\WIN-5TDSVV5L6Q3\PIPE\atsvc ncalrpc: senssvc ncalrpc: OLE607126F7F3E45DE7BC97C9627DD5 ncalrpc: IUserProfile2 86d35949-83c9-4044-b424-db363231fd0c version: v1.0 protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol provider: schedsvc.dll ncacn_ip_tcp: 103.91.90.251:10002 ncalrpc: ubpmtaskhostchannel ncacn_np: \\WIN-5TDSVV5L6Q3\PIPE\atsvc ncalrpc: senssvc ncalrpc: OLE607126F7F3E45DE7BC97C9627DD5 ncalrpc: IUserProfile2 378e52b0-c0a9-11cf-822d-00aa0051e40f version: v1.0 protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol provider: taskcomp.dll ncacn_np: \\WIN-5TDSVV5L6Q3\PIPE\atsvc ncalrpc: senssvc ncalrpc: OLE607126F7F3E45DE7BC97C9627DD5 ncalrpc: IUserProfile2 1ff70682-0a51-30e8-076d-740be8cee98b version: v1.0 protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol provider: taskcomp.dll ncacn_np: \\WIN-5TDSVV5L6Q3\PIPE\atsvc ncalrpc: senssvc ncalrpc: OLE607126F7F3E45DE7BC97C9627DD5 ncalrpc: IUserProfile2 0a74ef1c-41a4-4e06-83ae-dc74fb1cdd53 version: v1.0 provider: schedsvc.dll ncalrpc: senssvc ncalrpc: OLE607126F7F3E45DE7BC97C9627DD5 ncalrpc: IUserProfile2 2eb08e3e-639f-4fba-97b1-14f878961076 version: v1.0 annotation: Group Policy RPC Interface provider: gpsvc.dll ncalrpc: LRPC-0ca28271e5191821bb 3473dd4d-2e88-4006-9cba-22570909dd10 version: v5.256 annotation: WinHttp Auto-Proxy Service ncacn_np: \\WIN-5TDSVV5L6Q3\PIPE\W32TIME_ALT ncalrpc: W32TIME_ALT ncalrpc: LRPC-2efe0edac2e9cbc675 ncalrpc: OLE61EA2966E24DA694736CFE9D1961 7ea70bcf-48af-4f6a-8968-6a440754d5fa version: v1.0 annotation: NSI server endpoint provider: nsisvc.dll ncalrpc: LRPC-2efe0edac2e9cbc675 ncalrpc: OLE61EA2966E24DA694736CFE9D1961 2fb92682-6599-42dc-ae13-bd2ca89bd11c version: v1.0 annotation: Fw APIs provider: MPSSVC.dll ncalrpc: LRPC-5f968962af98dbde8e ncalrpc: LRPC-fc8410ac1ffeeabd00 f47433c3-3e9d-4157-aad4-83aa1f5c2d4c version: v1.0 annotation: Fw APIs ncalrpc: LRPC-5f968962af98dbde8e ncalrpc: LRPC-fc8410ac1ffeeabd00 7f9d11bf-7fb9-436b-a812-b2d50c5d4c03 version: v1.0 annotation: Fw APIs provider: MPSSVC.dll ncalrpc: LRPC-5f968962af98dbde8e ncalrpc: LRPC-fc8410ac1ffeeabd00 dd490425-5325-4565-b774-7e27d6c09c24 version: v1.0 annotation: Base Firewall Engine API provider: BFE.DLL ncalrpc: LRPC-fc8410ac1ffeeabd00 b2507c30-b126-494a-92ac-ee32b6eeb039 version: v1.0 ncalrpc: LRPC-0f5f94c4ddc99b8049 7f1343fe-50a9-4927-a778-0c5859517bac version: v1.0 annotation: DfsDs service ncacn_np: \\WIN-5TDSVV5L6Q3\PIPE\wkssvc ncalrpc: LRPC-6f60543290a64dc614 ncalrpc: DNSResolver eb081a0d-10ee-478a-a1dd-50995283e7a8 version: v3.0 annotation: Witness Client Test Interface ncalrpc: LRPC-6f60543290a64dc614 ncalrpc: DNSResolver f2c9b409-c1c9-4100-8639-d8ab1486694a version: v1.0 annotation: Witness Client Upcall Server ncalrpc: LRPC-6f60543290a64dc614 ncalrpc: DNSResolver 76f03f96-cdfd-44fc-a22c-64950a001209 version: v1.0 protocol: [MS-PAR]: Print System Asynchronous Remote Protocol provider: spoolsv.exe ncacn_ip_tcp: 103.91.90.251:10003 ncalrpc: LRPC-18191670857676399a 4a452661-8290-4b36-8fbe-7f4093a94978 version: v1.0 provider: spoolsv.exe ncacn_ip_tcp: 103.91.90.251:10003 ncalrpc: LRPC-18191670857676399a ae33069b-a2a8-46ee-a235-ddfd339be281 version: v1.0 protocol: [MS-PAN]: Print System Asynchronous Notification Protocol provider: spoolsv.exe ncacn_ip_tcp: 103.91.90.251:10003 ncalrpc: LRPC-18191670857676399a 0b6edbfa-4a24-4fc6-8a23-942b1eca65d1 version: v1.0 protocol: [MS-PAN]: Print System Asynchronous Notification Protocol provider: spoolsv.exe ncacn_ip_tcp: 103.91.90.251:10003 ncalrpc: LRPC-18191670857676399a 12345678-1234-abcd-ef00-0123456789ab version: v1.0 protocol: [MS-RPRN]: Print System Remote Protocol provider: spoolsv.exe ncacn_ip_tcp: 103.91.90.251:10003 ncalrpc: LRPC-18191670857676399a b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86 version: v2.0 annotation: KeyIso ncacn_ip_tcp: 103.91.90.251:10004 ncalrpc: samss lpc ncalrpc: SidKey Local End Point ncalrpc: protected_storage ncalrpc: lsasspirpc ncalrpc: lsapolicylookup ncalrpc: LSA_EAS_ENDPOINT ncalrpc: lsacap ncalrpc: LSARPC_ENDPOINT ncalrpc: securityevent ncalrpc: audit ncacn_np: \\WIN-5TDSVV5L6Q3\pipe\lsass 12345778-1234-abcd-ef00-0123456789ac version: v1.0 protocol: [MS-SAMR]: Security Account Manager (SAM) Remote Protocol provider: samsrv.dll ncacn_ip_tcp: 103.91.90.251:10004 ncalrpc: samss lpc ncalrpc: SidKey Local End Point ncalrpc: protected_storage ncalrpc: lsasspirpc ncalrpc: lsapolicylookup ncalrpc: LSA_EAS_ENDPOINT ncalrpc: lsacap ncalrpc: LSARPC_ENDPOINT ncalrpc: securityevent ncalrpc: audit ncacn_np: \\WIN-5TDSVV5L6Q3\pipe\lsass 367abb81-9844-35f1-ad32-98f038001003 version: v2.0 protocol: [MS-SCMR]: Service Control Manager Remote Protocol provider: services.exe ncacn_ip_tcp: 103.91.90.251:10006 6b5bdd1e-528c-422c-af8c-a4079be4fe48 version: v1.0 annotation: Remote Fw APIs protocol: [MS-FASP]: Firewall and Advanced Security Protocol provider: FwRemoteSvr.dll ncacn_ip_tcp: 103.91.90.251:10007 76209fe5-9049-4336-ba84-632d907cb154 version: v1.0 annotation: Interprocess Logon Service ncalrpc: ReportingServices$MSRS11.MSSQLSERVER ncalrpc: OLE777964F06F1212EF71EF239E05C5 12e65dd8-887f-41ef-91bf-8d816c42c2e7 version: v1.0 annotation: Secure Desktop LRPC interface provider: winlogon.exe ncalrpc: WMsgKRpc03180D2 a500d4c6-0dd1-4543-bc0c-d5f93486eaf8 version: v1.0 ncalrpc: LRPC-ff7eef6c049f372f41 e40f7b57-7a25-4cd3-a135-7f7d3df9d16b version: v1.0 annotation: Network Connection Broker server endpoint ncalrpc: OLEB96D1F514442CD43D67B3B513BAE ncalrpc: TSUMRPD_PRINT_DRV_LPC_API ncalrpc: trkwks ncacn_np: \\WIN-5TDSVV5L6Q3\pipe\trkwks 880fd55e-43b9-11e0-b1a8-cf4edfd72085 version: v1.0 annotation: KAPI Service endpoint ncalrpc: OLEB96D1F514442CD43D67B3B513BAE ncalrpc: TSUMRPD_PRINT_DRV_LPC_API ncalrpc: trkwks ncacn_np: \\WIN-5TDSVV5L6Q3\pipe\trkwks 5222821f-d5e2-4885-84f1-5f6185a0ec41 version: v1.0 annotation: Network Connection Broker server endpoint for NCB Reset module ncalrpc: TSUMRPD_PRINT_DRV_LPC_API ncalrpc: trkwks ncacn_np: \\WIN-5TDSVV5L6Q3\pipe\trkwks 906b0ce0-c70b-1067-b317-00dd010662da version: v1.0 protocol: [MS-CMPO]: MSDTC Connection Manager: provider: msdtcprx.dll ncalrpc: LRPC-e74c51b8a4f1beafe4 ncalrpc: LRPC-e74c51b8a4f1beafe4 ncalrpc: LRPC-e74c51b8a4f1beafe4
1489525118 | 2024-05-14T00:56:32.998314443 / tcp
HTTP/1.1 404 Not Found Content-Type: text/html; charset=us-ascii Server: Microsoft-HTTPAPI/2.0 Date: Tue, 14 May 2024 00:56:30 GMT Connection: close Content-Length: 315
Certificate: Data: Version: 3 (0x2) Serial Number: 9d:56:ed:14:32:39:6a:76:a2:20:17:86:b6:a1:65:36 Signature Algorithm: sha256WithRSAEncryption Issuer: C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Domain Validation Secure Server CA Validity Not Before: Jul 14 00:00:00 2023 GMT Not After : Jul 13 23:59:59 2024 GMT Subject: CN=zettamobi.xyz Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (2048 bit) Modulus: 00:91:20:07:8f:52:c7:6f:75:16:63:e1:a8:69:20: 27:2d:4f:5b:eb:a7:5f:2a:d0:35:1f:00:0e:f2:b6: b2:38:04:ec:41:d3:fd:f4:ff:d9:85:c4:6c:68:cd: 92:c7:6a:66:bc:26:2d:38:68:e0:5f:ad:49:04:3b: dc:f8:a3:52:e1:68:4c:69:d7:14:22:08:ad:06:7f: 8f:fa:f6:a4:fd:25:9f:ed:29:2e:9c:9d:f6:da:dc: cc:fb:fc:e2:0b:82:77:23:1c:dc:a3:59:50:2d:2c: ab:a5:49:02:53:84:17:66:fc:ef:36:8b:5b:ef:75: a9:63:08:5a:00:3f:ff:84:8c:1c:d9:c2:e6:77:22: 7b:78:08:75:cc:0d:4a:64:f0:7a:9c:12:66:52:93: 14:93:d9:0e:1d:e5:58:a5:ac:9e:f8:ca:66:e5:94: 80:65:7b:db:e0:18:6c:10:8d:1d:b2:6f:7c:76:eb: 4d:cf:bf:d1:5b:dd:e2:af:73:a9:cb:a4:38:e6:b9: 29:d8:39:bf:dd:de:3d:c7:46:2b:9a:4c:95:8f:f4: 09:c3:c2:1b:d4:61:9b:4b:43:4e:ce:2c:34:a7:56: 5f:4c:06:e3:0d:9a:a7:5b:42:f2:d3:3c:73:44:97: 33:a3:24:d4:c9:d4:91:da:45:5f:94:19:0a:f0:98: 4a:03 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Authority Key Identifier: 8D:8C:5E:C4:54:AD:8A:E1:77:E9:9B:F9:9B:05:E1:B8:01:8D:61:E1 X509v3 Subject Key Identifier: 67:51:6D:47:9D:3C:7D:9E:D4:B1:22:DB:F4:42:FA:BD:1A:38:24:87 X509v3 Key Usage: critical Digital Signature, Key Encipherment X509v3 Basic Constraints: critical CA:FALSE X509v3 Extended Key Usage: TLS Web Server Authentication, TLS Web Client Authentication X509v3 Certificate Policies: Policy: 1.3.6.1.4.1.6449.1.2.2.7 CPS: https://sectigo.com/CPS Policy: 2.23.140.1.2.1 Authority Information Access: CA Issuers - URI:http://crt.sectigo.com/SectigoRSADomainValidationSecureServerCA.crt OCSP - URI:http://ocsp.sectigo.com X509v3 Subject Alternative Name: DNS:zettamobi.xyz, DNS:www.zettamobi.xyz CT Precertificate SCTs: Signed Certificate Timestamp: Version : v1 (0x0) Log ID : 76:FF:88:3F:0A:B6:FB:95:51:C2:61:CC:F5:87:BA:34: B4:A4:CD:BB:29:DC:68:42:0A:9F:E6:67:4C:5A:3A:74 Timestamp : Jul 14 12:55:21.340 2023 GMT Extensions: none Signature : ecdsa-with-SHA256 30:45:02:21:00:A0:03:3F:28:BF:8B:E5:D9:1A:99:1B: B6:58:77:C9:72:12:D0:FE:6E:5A:DA:B1:5E:F7:EE:6D: 09:CE:C3:01:A3:02:20:13:21:06:B7:9C:B4:1E:64:FE: C3:2F:93:29:FC:9B:00:9D:03:68:4A:6B:84:00:88:08: 3E:87:22:34:5C:8C:D4 Signed Certificate Timestamp: Version : v1 (0x0) Log ID : DA:B6:BF:6B:3F:B5:B6:22:9F:9B:C2:BB:5C:6B:E8:70: 91:71:6C:BB:51:84:85:34:BD:A4:3D:30:48:D7:FB:AB Timestamp : Jul 14 12:55:21.413 2023 GMT Extensions: none Signature : ecdsa-with-SHA256 30:45:02:21:00:99:99:68:38:06:11:60:B1:C3:7F:6F: 43:FB:5F:F4:11:5B:C4:80:67:F1:B9:A2:B1:1C:D4:80: 62:46:7C:00:09:02:20:32:7C:7E:56:49:0E:FF:BF:FC: 22:0C:33:6E:EA:90:0E:C0:95:D4:9F:9D:77:F3:65:8A: FA:01:EB:8B:92:F0:DA Signed Certificate Timestamp: Version : v1 (0x0) Log ID : EE:CD:D0:64:D5:DB:1A:CE:C5:5C:B7:9D:B4:CD:13:A2: 32:87:46:7C:BC:EC:DE:C3:51:48:59:46:71:1F:B5:9B Timestamp : Jul 14 12:55:21.378 2023 GMT Extensions: none Signature : ecdsa-with-SHA256 30:45:02:21:00:A3:36:D3:6B:E1:9C:B6:84:01:CF:51: FB:10:65:BE:2E:CE:9A:E0:ED:EC:91:00:7D:32:F3:07: 42:26:94:C1:F8:02:20:25:E4:5B:46:90:53:29:8E:27: 58:4A:94:2D:2C:41:E0:D0:3A:54:F0:9C:78:C1:A9:48: B0:4C:60:8E:D3:2C:9F Signature Algorithm: sha256WithRSAEncryption Signature Value: 01:4e:9f:d0:53:96:a6:ab:93:e8:fd:b8:05:d3:60:eb:b1:37: 22:6e:40:5e:bc:33:74:e0:41:be:32:2f:dd:86:95:28:2a:4a: 81:94:4d:a3:a1:31:01:ad:49:52:7d:71:45:8e:d0:90:ad:fb: df:1b:17:50:c9:e2:1c:84:7b:4e:6a:6a:04:09:21:1e:c0:5b: d9:8c:93:18:0f:af:17:6a:62:f0:ff:e0:f1:ef:7a:9b:48:fa: 3d:bd:80:f6:a6:ad:fc:71:be:c7:d8:9a:39:f6:10:76:ce:16: a1:13:1d:04:0e:3d:41:aa:e2:6c:d3:bb:15:34:b2:93:2d:22: 7e:d8:08:4f:70:ca:61:2e:bd:0a:98:99:f7:36:8d:90:ce:db: d7:0c:a7:15:4c:97:39:e5:93:d7:21:89:8c:83:a4:a8:9f:03: 1f:62:49:7e:58:14:c4:60:e0:06:4b:f5:bf:3c:72:53:f4:2a: 3d:01:99:cd:0c:c8:79:6a:6e:36:60:e1:be:27:8b:5d:7e:f9: d4:34:dc:c1:af:67:35:e9:f8:6f:fc:84:f3:37:2a:b7:d9:a4: 1b:54:58:42:bc:b4:1b:1b:cc:60:0c:19:92:8a:e1:00:b7:81: 40:d5:73:be:0d:3a:32:18:22:e9:f7:c6:22:61:43:3d:6b:ff: 0f:6e:fc:be
1688663994 | 2024-05-15T08:20:39.072552445 / tcp
SMB Status: Authentication: enabled SMB Version: 1 OS: Windows Server 2012 R2 Standard 9600 Software: Windows Server 2012 R2 Standard 6.3 Capabilities: extended-security, infolevel-passthru, large-files, large-readx, large-writex, level2-oplocks, lock-and-read, lwio, nt-find, nt-smb, nt-status, rpc-remote-api, unicode
-280566269 | 2024-05-02T22:24:29.4139691433 / tcp
MS-SQL NTLM Info: OS: Windows 8.1/Windows Server 2012 R2 OS Build: 6.3.9600 Target Name: WIN-5TDSVV5L6Q3 NetBIOS Domain Name: WIN-5TDSVV5L6Q3 NetBIOS Computer Name: WIN-5TDSVV5L6Q3 DNS Domain Name: WIN-5TDSVV5L6Q3 FQDN: WIN-5TDSVV5L6Q3
2065843501 | 2024-04-28T23:18:10.7868841434 / udp
SQL Server Browser Service: Instance #1: Server Name: WIN-5TDSVV5L6Q3 Instance Name: MSSQLSERVER Is Clustered: False Version: 11.0.6020.0 TCP Port: 1433 Named Pipe: \\WIN-5TDSVV5L6Q3\pipe\sql\query Version Name: MS-SQL Server 2012 SP3RTW/PCU3
1489525118 | 2024-05-10T02:38:50.6890405985 / tcp
HTTP/1.1 404 Not Found Content-Type: text/html; charset=us-ascii Server: Microsoft-HTTPAPI/2.0 Date: Fri, 10 May 2024 02:38:44 GMT Connection: close Content-Length: 315 WinRM NTLM Info: OS: Windows Server 2012 R2 OS Build: 6.3.9600 Target Name: WIN-5TDSVV5L6Q3 NetBIOS Domain Name: WIN-5TDSVV5L6Q3 NetBIOS Computer Name: WIN-5TDSVV5L6Q3 DNS Domain Name: WIN-5TDSVV5L6Q3 FQDN: WIN-5TDSVV5L6Q3