Hostnames |
mhtwindows.com www.mhtwindows.com static.vnpt.vn |
Domains | mhtwindows.com vnpt.vn |
Country | Viet Nam |
City | Thái Nguyên |
Organization | Vietnam Posts and Telecommunications Group |
ISP | VNPT Corp |
ASN | AS45899 |
703707298 | 2024-03-08T07:50:07.64418980 / tcp
HTTP/1.1 200 OK Content-Type: text/html Last-Modified: Mon, 26 Jun 2023 08:16:34 GMT Accept-Ranges: bytes ETag: "e9bb1b856a8d91:0" Server: Microsoft-IIS/10.0 X-Powered-By: ASP.NET Date: Fri, 08 Mar 2024 07:50:07 GMT Content-Length: 703
533410148 | 2024-03-26T00:31:57.055399135 / tcp
Microsoft RPC Endpoint Mapper 51a227ae-825b-41f2-b4a9-1ac9557a1018 version: v1.0 annotation: Ngc Pop Key Service ncacn_ip_tcp: 113.160.161.75:49664 ncalrpc: samss lpc ncalrpc: SidKey Local End Point ncalrpc: protected_storage ncalrpc: lsasspirpc ncalrpc: lsapolicylookup ncalrpc: LSA_EAS_ENDPOINT ncalrpc: LSA_IDPEXT_ENDPOINT ncalrpc: lsacap ncalrpc: LSARPC_ENDPOINT ncalrpc: securityevent ncalrpc: audit ncacn_np: \\WIN-B9T7E7OUACK\pipe\lsass 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b version: v1.0 annotation: Ngc Pop Key Service ncacn_ip_tcp: 113.160.161.75:49664 ncalrpc: samss lpc ncalrpc: SidKey Local End Point ncalrpc: protected_storage ncalrpc: lsasspirpc ncalrpc: lsapolicylookup ncalrpc: LSA_EAS_ENDPOINT ncalrpc: LSA_IDPEXT_ENDPOINT ncalrpc: lsacap ncalrpc: LSARPC_ENDPOINT ncalrpc: securityevent ncalrpc: audit ncacn_np: \\WIN-B9T7E7OUACK\pipe\lsass b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86 version: v2.0 annotation: KeyIso ncacn_ip_tcp: 113.160.161.75:49664 ncalrpc: samss lpc ncalrpc: SidKey Local End Point ncalrpc: protected_storage ncalrpc: lsasspirpc ncalrpc: lsapolicylookup ncalrpc: LSA_EAS_ENDPOINT ncalrpc: LSA_IDPEXT_ENDPOINT ncalrpc: lsacap ncalrpc: LSARPC_ENDPOINT ncalrpc: securityevent ncalrpc: audit ncacn_np: \\WIN-B9T7E7OUACK\pipe\lsass 12345778-1234-abcd-ef00-0123456789ac version: v1.0 protocol: [MS-SAMR]: Security Account Manager (SAM) Remote Protocol provider: samsrv.dll ncacn_ip_tcp: 113.160.161.75:49664 ncalrpc: samss lpc ncalrpc: SidKey Local End Point ncalrpc: protected_storage ncalrpc: lsasspirpc ncalrpc: lsapolicylookup ncalrpc: LSA_EAS_ENDPOINT ncalrpc: LSA_IDPEXT_ENDPOINT ncalrpc: lsacap ncalrpc: LSARPC_ENDPOINT ncalrpc: securityevent ncalrpc: audit ncacn_np: \\WIN-B9T7E7OUACK\pipe\lsass d95afe70-a6d5-4259-822e-2c84da1ddb0d version: v1.0 protocol: [MS-RSP]: Remote Shutdown Protocol provider: wininit.exe ncacn_ip_tcp: 113.160.161.75:49665 ncalrpc: WindowsShutdown ncacn_np: \\WIN-B9T7E7OUACK\PIPE\InitShutdown ncalrpc: WMsgKRpc014F7F0 76f226c3-ec14-4325-8a99-6a46348418af version: v1.0 provider: winlogon.exe ncalrpc: WindowsShutdown ncacn_np: \\WIN-B9T7E7OUACK\PIPE\InitShutdown ncalrpc: WMsgKRpc014F7F0 ncalrpc: WMsgKRpc01513B1 d09bdeb5-6171-4a34-bfe2-06fa82652568 version: v1.0 ncalrpc: csebpub ncalrpc: LRPC-bf0c3600aa32cd347c ncalrpc: LRPC-4addb1b8317d9b78a1 ncalrpc: LRPC-639ab6d7b48f2bc100 ncalrpc: LRPC-a298716dea69e9c072 ncalrpc: LRPC-3a6cbaa81ecc3556e3 ncalrpc: OLE5D719D03D7C26E220994F94FF1B9 ncalrpc: actkernel ncalrpc: umpo ncalrpc: LRPC-4addb1b8317d9b78a1 ncalrpc: LRPC-639ab6d7b48f2bc100 ncalrpc: LRPC-a298716dea69e9c072 ncalrpc: LRPC-3a6cbaa81ecc3556e3 ncalrpc: OLE5D719D03D7C26E220994F94FF1B9 ncalrpc: actkernel ncalrpc: umpo ncalrpc: LRPC-639ab6d7b48f2bc100 ncalrpc: LRPC-a298716dea69e9c072 ncalrpc: LRPC-3a6cbaa81ecc3556e3 ncalrpc: OLE5D719D03D7C26E220994F94FF1B9 ncalrpc: actkernel ncalrpc: umpo ncalrpc: LRPC-f58ab8cc6198548047 ncalrpc: LRPC-53c0d7ddbe4f4b7362 697dcda9-3ba9-4eb2-9247-e11f1901b0d2 version: v1.0 ncalrpc: LRPC-bf0c3600aa32cd347c ncalrpc: LRPC-4addb1b8317d9b78a1 ncalrpc: LRPC-639ab6d7b48f2bc100 ncalrpc: LRPC-a298716dea69e9c072 ncalrpc: LRPC-3a6cbaa81ecc3556e3 ncalrpc: OLE5D719D03D7C26E220994F94FF1B9 ncalrpc: actkernel ncalrpc: umpo 9b008953-f195-4bf9-bde0-4471971e58ed version: v1.0 ncalrpc: LRPC-4addb1b8317d9b78a1 ncalrpc: LRPC-639ab6d7b48f2bc100 ncalrpc: LRPC-a298716dea69e9c072 ncalrpc: LRPC-3a6cbaa81ecc3556e3 ncalrpc: OLE5D719D03D7C26E220994F94FF1B9 ncalrpc: actkernel ncalrpc: umpo 0d47017b-b33b-46ad-9e18-fe96456c5078 version: v1.0 ncalrpc: umpo 95406f0b-b239-4318-91bb-cea3a46ff0dc version: v1.0 ncalrpc: umpo 4ed8abcc-f1e2-438b-981f-bb0e8abc010c version: v1.0 ncalrpc: umpo 0ff1f646-13bb-400a-ab50-9a78f2b7a85a version: v1.0 ncalrpc: umpo 6982a06e-5fe2-46b1-b39c-a2c545bfa069 version: v1.0 ncalrpc: umpo 082a3471-31b6-422a-b931-a54401960c62 version: v1.0 ncalrpc: umpo fae436b0-b864-4a87-9eda-298547cd82f2 version: v1.0 ncalrpc: umpo e53d94ca-7464-4839-b044-09a2fb8b3ae5 version: v1.0 ncalrpc: umpo 178d84be-9291-4994-82c6-3f909aca5a03 version: v1.0 ncalrpc: umpo 4dace966-a243-4450-ae3f-9b7bcb5315b8 version: v2.0 ncalrpc: umpo 1832bcf6-cab8-41d4-85d2-c9410764f75a version: v1.0 ncalrpc: umpo c521facf-09a9-42c5-b155-72388595cbf0 version: v0.0 ncalrpc: umpo 2c7fd9ce-e706-4b40-b412-953107ef9bb0 version: v0.0 ncalrpc: umpo 88abcbc3-34ea-76ae-8215-767520655a23 version: v0.0 ncalrpc: LRPC-a298716dea69e9c072 ncalrpc: LRPC-3a6cbaa81ecc3556e3 ncalrpc: OLE5D719D03D7C26E220994F94FF1B9 ncalrpc: actkernel ncalrpc: umpo 76c217bc-c8b4-4201-a745-373ad9032b1a version: v1.0 ncalrpc: LRPC-a298716dea69e9c072 ncalrpc: LRPC-3a6cbaa81ecc3556e3 ncalrpc: OLE5D719D03D7C26E220994F94FF1B9 ncalrpc: actkernel ncalrpc: umpo 55e6b932-1979-45d6-90c5-7f6270724112 version: v1.0 ncalrpc: LRPC-a298716dea69e9c072 ncalrpc: LRPC-3a6cbaa81ecc3556e3 ncalrpc: OLE5D719D03D7C26E220994F94FF1B9 ncalrpc: actkernel ncalrpc: umpo 857fb1be-084f-4fb5-b59c-4b2c4be5f0cf version: v1.0 ncalrpc: LRPC-3a6cbaa81ecc3556e3 ncalrpc: OLE5D719D03D7C26E220994F94FF1B9 ncalrpc: actkernel ncalrpc: umpo 20c40295-8dba-48e6-aebf-3e78ef3bb144 version: v2.0 ncalrpc: LRPC-3a6cbaa81ecc3556e3 ncalrpc: OLE5D719D03D7C26E220994F94FF1B9 ncalrpc: actkernel ncalrpc: umpo 2513bcbe-6cd4-4348-855e-7efb3c336dd3 version: v2.0 ncalrpc: LRPC-3a6cbaa81ecc3556e3 ncalrpc: OLE5D719D03D7C26E220994F94FF1B9 ncalrpc: actkernel ncalrpc: umpo 0d3e2735-cea0-4ecc-a9e2-41a2d81aed4e version: v1.0 ncalrpc: LRPC-3a6cbaa81ecc3556e3 ncalrpc: OLE5D719D03D7C26E220994F94FF1B9 ncalrpc: actkernel ncalrpc: umpo c605f9fb-f0a3-4e2a-a073-73560f8d9e3e version: v1.0 ncalrpc: LRPC-3a6cbaa81ecc3556e3 ncalrpc: OLE5D719D03D7C26E220994F94FF1B9 ncalrpc: actkernel ncalrpc: umpo 1b37ca91-76b1-4f5e-a3c7-2abfc61f2bb0 version: v1.0 ncalrpc: LRPC-3a6cbaa81ecc3556e3 ncalrpc: OLE5D719D03D7C26E220994F94FF1B9 ncalrpc: actkernel ncalrpc: umpo 8bfc3be1-6def-4e2d-af74-7c47cd0ade4a version: v1.0 ncalrpc: LRPC-3a6cbaa81ecc3556e3 ncalrpc: OLE5D719D03D7C26E220994F94FF1B9 ncalrpc: actkernel ncalrpc: umpo 2d98a740-581d-41b9-aa0d-a88b9d5ce938 version: v1.0 ncalrpc: LRPC-3a6cbaa81ecc3556e3 ncalrpc: OLE5D719D03D7C26E220994F94FF1B9 ncalrpc: actkernel ncalrpc: umpo dd59071b-3215-4c59-8481-972edadc0f6a version: v1.0 ncalrpc: OLE5D719D03D7C26E220994F94FF1B9 ncalrpc: actkernel ncalrpc: umpo 0361ae94-0316-4c6c-8ad8-c594375800e2 version: v1.0 ncalrpc: umpo 5824833b-3c1a-4ad2-bdfd-c31d19e23ed2 version: v1.0 ncalrpc: umpo bdaa0970-413b-4a3e-9e5d-f6dc9d7e0760 version: v1.0 ncalrpc: umpo 3b338d89-6cfa-44b8-847e-531531bc9992 version: v1.0 ncalrpc: umpo 8782d3b9-ebbd-4644-a3d8-e8725381919b version: v1.0 ncalrpc: umpo 085b0334-e454-4d91-9b8c-4134f9e793f3 version: v1.0 ncalrpc: umpo 4bec6bb8-b5c2-4b6f-b2c1-5da5cf92d0d9 version: v1.0 ncalrpc: umpo c9ac6db5-82b7-4e55-ae8a-e464ed7b4277 version: v1.0 annotation: Impl friendly name provider: sysntfy.dll ncalrpc: LRPC-2ff6e8b2388e8559b0 ncalrpc: LRPC-471b1562341d36d7c6 ncalrpc: IUserProfile2 ncalrpc: LRPC-47371fd8a31d3876a6 ncalrpc: senssvc f3f09ffd-fbcf-4291-944d-70ad6e0e73bb version: v1.0 ncalrpc: LRPC-12f95b4c599e2d05d6 e40f7b57-7a25-4cd3-a135-7f7d3df9d16b version: v1.0 ncalrpc: LRPC-41f668aeafa6f4d65c 880fd55e-43b9-11e0-b1a8-cf4edfd72085 version: v1.0 annotation: KAPI Service endpoint ncalrpc: LRPC-dff71b844ccd5c575d ncalrpc: OLEFE87536E6932FD100E2847F45C64 ncalrpc: LRPC-f58ab8cc6198548047 5222821f-d5e2-4885-84f1-5f6185a0ec41 version: v1.0 ncalrpc: LRPC-2e2547ccb0c33134ed a500d4c6-0dd1-4543-bc0c-d5f93486eaf8 version: v1.0 ncalrpc: LRPC-6b210fc4c8b94564c6 ncalrpc: LRPC-53c0d7ddbe4f4b7362 f6beaff7-1e19-4fbb-9f8f-b89e2018337c version: v1.0 annotation: Event log TCPIP protocol: [MS-EVEN6]: EventLog Remoting Protocol provider: wevtsvc.dll ncacn_ip_tcp: 113.160.161.75:49666 ncacn_np: \\WIN-B9T7E7OUACK\pipe\eventlog ncalrpc: eventlog 7ea70bcf-48af-4f6a-8968-6a440754d5fa version: v1.0 annotation: NSI server endpoint provider: nsisvc.dll ncalrpc: LRPC-7b221ed8bc889ad077 2eb08e3e-639f-4fba-97b1-14f878961076 version: v1.0 annotation: Group Policy RPC Interface provider: gpsvc.dll ncalrpc: LRPC-0909b6b93344881b28 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6 version: v1.0 annotation: DHCPv6 Client LRPC Endpoint provider: dhcpcsvc6.dll ncalrpc: dhcpcsvc6 ncalrpc: dhcpcsvc 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5 version: v1.0 annotation: DHCP Client LRPC Endpoint provider: dhcpcsvc.dll ncalrpc: dhcpcsvc 3a9ef155-691d-4449-8d05-09ad57031823 version: v1.0 ncacn_ip_tcp: 113.160.161.75:49667 ncalrpc: LRPC-a565da2614b78165e3 ncalrpc: ubpmtaskhostchannel ncacn_np: \\WIN-B9T7E7OUACK\PIPE\atsvc ncalrpc: LRPC-9b6c1158423e0625de 86d35949-83c9-4044-b424-db363231fd0c version: v1.0 protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol provider: schedsvc.dll ncacn_ip_tcp: 113.160.161.75:49667 ncalrpc: LRPC-a565da2614b78165e3 ncalrpc: ubpmtaskhostchannel ncacn_np: \\WIN-B9T7E7OUACK\PIPE\atsvc ncalrpc: LRPC-9b6c1158423e0625de 33d84484-3626-47ee-8c6f-e7e98b113be1 version: v2.0 ncalrpc: LRPC-a565da2614b78165e3 ncalrpc: ubpmtaskhostchannel ncacn_np: \\WIN-B9T7E7OUACK\PIPE\atsvc ncalrpc: LRPC-9b6c1158423e0625de 378e52b0-c0a9-11cf-822d-00aa0051e40f version: v1.0 protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol provider: taskcomp.dll ncacn_np: \\WIN-B9T7E7OUACK\PIPE\atsvc ncalrpc: LRPC-9b6c1158423e0625de 1ff70682-0a51-30e8-076d-740be8cee98b version: v1.0 protocol: [MS-TSCH]: Task Scheduler Service Remoting Protocol provider: taskcomp.dll ncacn_np: \\WIN-B9T7E7OUACK\PIPE\atsvc ncalrpc: LRPC-9b6c1158423e0625de 0a74ef1c-41a4-4e06-83ae-dc74fb1cdd53 version: v1.0 provider: schedsvc.dll ncalrpc: LRPC-9b6c1158423e0625de 30adc50c-5cbc-46ce-9a0e-91914789e23c version: v1.0 annotation: NRP server endpoint provider: nrpsrv.dll ncalrpc: LRPC-c521995de100e56679 ncalrpc: DNSResolver 7f1343fe-50a9-4927-a778-0c5859517bac version: v1.0 annotation: DfsDs service ncacn_np: \\WIN-B9T7E7OUACK\PIPE\wkssvc ncalrpc: LRPC-66a1332896a839b1ac eb081a0d-10ee-478a-a1dd-50995283e7a8 version: v3.0 annotation: Witness Client Test Interface ncalrpc: LRPC-66a1332896a839b1ac f2c9b409-c1c9-4100-8639-d8ab1486694a version: v1.0 annotation: Witness Client Upcall Server ncalrpc: LRPC-66a1332896a839b1ac 2fb92682-6599-42dc-ae13-bd2ca89bd11c version: v1.0 annotation: Fw APIs provider: MPSSVC.dll ncalrpc: LRPC-f52f6984bdaaafc99d ncalrpc: LRPC-e8a11049c738086b29 ncalrpc: LRPC-7762359d3b60f3ca27 ncalrpc: LRPC-d6d4e33794a808c643 f47433c3-3e9d-4157-aad4-83aa1f5c2d4c version: v1.0 annotation: Fw APIs ncalrpc: LRPC-e8a11049c738086b29 ncalrpc: LRPC-7762359d3b60f3ca27 ncalrpc: LRPC-d6d4e33794a808c643 7f9d11bf-7fb9-436b-a812-b2d50c5d4c03 version: v1.0 annotation: Fw APIs provider: MPSSVC.dll ncalrpc: LRPC-7762359d3b60f3ca27 ncalrpc: LRPC-d6d4e33794a808c643 dd490425-5325-4565-b774-7e27d6c09c24 version: v1.0 annotation: Base Firewall Engine API provider: BFE.DLL ncalrpc: LRPC-d6d4e33794a808c643 3473dd4d-2e88-4006-9cba-22570909dd10 version: v5.256 annotation: WinHttp Auto-Proxy Service ncalrpc: adc905cb-0c3b-4146-ba64-0ba2b84846d5 ncalrpc: LRPC-7faafe5c2e31e4d78a 13560fa9-8c09-4b56-a1fd-04d083b9b2a1 version: v1.0 ncalrpc: LRPC-86a8f84e9a2da71115 c2d1b5dd-fa81-4460-9dd6-e7658b85454b version: v1.0 ncalrpc: LRPC-86a8f84e9a2da71115 f44e62af-dab1-44c2-8013-049a9de417d6 version: v1.0 ncalrpc: LRPC-86a8f84e9a2da71115 b37f900a-eae4-4304-a2ab-12bb668c0188 version: v1.0 ncalrpc: LRPC-86a8f84e9a2da71115 abfb6ca3-0c5e-4734-9285-0aee72fe8d1c version: v1.0 ncalrpc: LRPC-86a8f84e9a2da71115 a398e520-d59a-4bdd-aa7a-3c1e0303a511 version: v1.0 annotation: IKE/Authip API provider: IKEEXT.DLL ncalrpc: LRPC-5118b363ac8e30f44b 3f787932-3452-4363-8651-6ea97bb373bb version: v1.0 annotation: NSP Rpc Interface ncalrpc: LRPC-8d87736ae6da0abcc8 ncalrpc: OLE412B343EB86881343B038DCB47EF c36be077-e14b-4fe9-8abc-e856ef4f048b version: v1.0 annotation: Proxy Manager client server endpoint ncalrpc: OLEB554333E8F65C07D090B7E5E9B27 ncalrpc: TeredoControl ncalrpc: TeredoDiagnostics ncalrpc: LRPC-447d25e540a41f6248 2e6035b2-e8f1-41a7-a044-656b439c4c34 version: v1.0 annotation: Proxy Manager provider server endpoint ncalrpc: OLEB554333E8F65C07D090B7E5E9B27 ncalrpc: TeredoControl ncalrpc: TeredoDiagnostics ncalrpc: LRPC-447d25e540a41f6248 c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1 version: v1.0 annotation: Adh APIs ncalrpc: TeredoControl ncalrpc: TeredoDiagnostics ncalrpc: LRPC-447d25e540a41f6248 552d076a-cb29-4e44-8b6a-d15e59e2c0af version: v1.0 annotation: IP Transition Configuration endpoint provider: iphlpsvc.dll ncalrpc: LRPC-447d25e540a41f6248 b58aa02e-2884-4e97-8176-4ee06d794184 version: v1.0 provider: sysmain.dll ncalrpc: LRPC-102a4248bd22d80c79 0d3c7f20-1c8d-4654-a1b3-51563b298bda version: v1.0 annotation: UserMgrCli ncalrpc: LRPC-3889dce4f5bbf4244c ncalrpc: OLE410614BAB4F650F1F972AF4CE7C3 b18fbab6-56f8-4702-84e0-41053293a869 version: v1.0 annotation: UserMgrCli ncalrpc: LRPC-3889dce4f5bbf4244c ncalrpc: OLE410614BAB4F650F1F972AF4CE7C3 76f03f96-cdfd-44fc-a22c-64950a001209 version: v1.0 protocol: [MS-PAR]: Print System Asynchronous Remote Protocol provider: spoolsv.exe ncacn_ip_tcp: 113.160.161.75:49668 ncalrpc: LRPC-242f26618047dceb99 4a452661-8290-4b36-8fbe-7f4093a94978 version: v1.0 provider: spoolsv.exe ncacn_ip_tcp: 113.160.161.75:49668 ncalrpc: LRPC-242f26618047dceb99 ae33069b-a2a8-46ee-a235-ddfd339be281 version: v1.0 protocol: [MS-PAN]: Print System Asynchronous Notification Protocol provider: spoolsv.exe ncacn_ip_tcp: 113.160.161.75:49668 ncalrpc: LRPC-242f26618047dceb99 0b6edbfa-4a24-4fc6-8a23-942b1eca65d1 version: v1.0 protocol: [MS-PAN]: Print System Asynchronous Notification Protocol provider: spoolsv.exe ncacn_ip_tcp: 113.160.161.75:49668 ncalrpc: LRPC-242f26618047dceb99 12345678-1234-abcd-ef00-0123456789ab version: v1.0 protocol: [MS-RPRN]: Print System Remote Protocol provider: spoolsv.exe ncacn_ip_tcp: 113.160.161.75:49668 ncalrpc: LRPC-242f26618047dceb99 1a0d010f-1c33-432c-b0f5-8cf4e8053099 version: v1.0 annotation: IdSegSrv service ncalrpc: LRPC-990fed928a2058b4d1 98716d03-89ac-44c7-bb8c-285824e51c4a version: v1.0 annotation: XactSrv service provider: srvsvc.dll ncalrpc: LRPC-990fed928a2058b4d1 650a7e26-eab8-5533-ce43-9c1dfce11511 version: v1.0 annotation: Vpn APIs ncalrpc: LRPC-cad37906c9dd8f4db0 ncalrpc: VpnikeRpc ncalrpc: RasmanLrpc ncacn_np: \\WIN-B9T7E7OUACK\PIPE\ROUTER 6b5bdd1e-528c-422c-af8c-a4079be4fe48 version: v1.0 annotation: Remote Fw APIs protocol: [MS-FASP]: Firewall and Advanced Security Protocol provider: FwRemoteSvr.dll ncacn_ip_tcp: 113.160.161.75:49669 ncalrpc: ipsec 509bc7ae-77be-4ee8-b07c-0d096bb44345 version: v1.0 ncalrpc: LRPC-028f7e0ef1227e112e ncalrpc: OLECC038869BB0DBBD1605ECADB2DCE 1d45e083-478f-437c-9618-3594ced8c235 version: v1.0 ncalrpc: LRPC-fddecb4c6a30895f30 ncalrpc: OLE7BE19C4646CFCCA95E6657D3D1DF 98cd761e-e77d-41c8-a3c0-0fb756d90ec2 version: v1.0 ncalrpc: LRPC-fddecb4c6a30895f30 ncalrpc: OLE7BE19C4646CFCCA95E6657D3D1DF d22895ef-aff4-42c5-a5b2-b14466d34ab4 version: v1.0 ncalrpc: LRPC-fddecb4c6a30895f30 ncalrpc: OLE7BE19C4646CFCCA95E6657D3D1DF e38f5360-8572-473e-b696-1b46873beeab version: v1.0 ncalrpc: LRPC-fddecb4c6a30895f30 ncalrpc: OLE7BE19C4646CFCCA95E6657D3D1DF 95095ec8-32ea-4eb0-a3e2-041f97b36168 version: v1.0 ncalrpc: LRPC-fddecb4c6a30895f30 ncalrpc: OLE7BE19C4646CFCCA95E6657D3D1DF fd8be72b-a9cd-4b2c-a9ca-4ded242fbe4d version: v1.0 ncalrpc: LRPC-fddecb4c6a30895f30 ncalrpc: OLE7BE19C4646CFCCA95E6657D3D1DF 4c9dbf19-d39e-4bb9-90ee-8f7179b20283 version: v1.0 ncalrpc: LRPC-fddecb4c6a30895f30 ncalrpc: OLE7BE19C4646CFCCA95E6657D3D1DF d4051bde-9cdd-4910-b393-4aa85ec3c482 version: v1.0 ncalrpc: LRPC-fddecb4c6a30895f30 ncalrpc: OLE7BE19C4646CFCCA95E6657D3D1DF 7df1ceae-de4e-4e6f-ab14-49636e7c2052 version: v1.0 ncalrpc: LRPC-64920ad8d282d4f966 9b3e3722-b9de-913a-4b50-525250524f50 version: v29384.48143 annotation: DEFER_THREAD_INIT ncalrpc: PRRUniversal#2B412EFCDE2B5504:4028 ncalrpc: PRRNameService:4028 9b3e3722-b8eb-3e0b-4b50-52524f424a53 version: v29384.48143 annotation: TaskManager ncalrpc: PRRUniversal#2B412EFCDE2B5504:4028 ncalrpc: PRRNameService:4028 9b3e3722-2175-40a9-4b50-525250524f50 version: v29384.48143 annotation: cpTEMPFILE_SYSCACHED ncalrpc: PRRUniversal#2B412EFCDE2B5504:4028 ncalrpc: PRRNameService:4028 9b3e3722-7d85-bb8f-4b50-525250524f50 version: v29384.48143 annotation: npTM_PROFILE ncalrpc: PRRUniversal#2B412EFCDE2B5504:4028 ncalrpc: PRRNameService:4028 9b3e3722-97cf-5c32-4b50-525250524f50 version: v29384.48143 annotation: native file io object streams ncalrpc: PRRUniversal#2B412EFCDE2B5504:4028 ncalrpc: PRRNameService:4028 9b3e3722-d7d6-630a-4b50-525250524f50 version: v29384.48143 annotation: native file io object is a stream really ncalrpc: PRRUniversal#2B412EFCDE2B5504:4028 ncalrpc: PRRNameService:4028 9b3e3722-49dd-4e78-4b50-525250524f50 version: v29384.48143 annotation: antimalware.oas.PenderPtr ncalrpc: PRRUniversal#2B412EFCDE2B5504:4028 ncalrpc: PRRNameService:4028 9b3e3722-3fdc-66a9-4b50-525250524f50 version: v29384.48143 annotation: npOBJECT_STARTUP ncalrpc: PRRUniversal#2B412EFCDE2B5504:4028 ncalrpc: PRRNameService:4028 9b3e3722-da96-8fb3-4b50-525250524f50 version: v29384.48143 annotation: npENGINE_INTEGRAL_PARENT_IO ncalrpc: PRRUniversal#2B412EFCDE2B5504:4028 ncalrpc: PRRNameService:4028 9b3e3722-dfbb-7d89-4b50-525250524f50 version: v29384.48143 annotation: npENGINE_OBJECT_SET_WRITE_ACCESS_tERROR ncalrpc: PRRUniversal#2B412EFCDE2B5504:4028 ncalrpc: PRRNameService:4028 9b3e3722-b130-2d78-4b50-525250524f50 version: v29384.48143 annotation: npENGINE_OBJECT_EXECUTABLE_PARENT_IO_hOBJECT ncalrpc: PRRUniversal#2B412EFCDE2B5504:4028 ncalrpc: PRRNameService:4028 9b3e3722-7dc3-c215-4b50-525250524f50 version: v29384.48143 annotation: npENGINE_OBJECT_READONLY_tERROR ncalrpc: PRRUniversal#2B412EFCDE2B5504:4028 ncalrpc: PRRNameService:4028 9b3e3722-56be-b1b4-4b50-525250524f50 version: v29384.48143 annotation: npSCAN_OBJECT_CONTEXT ncalrpc: PRRUniversal#2B412EFCDE2B5504:4028 ncalrpc: PRRNameService:4028 9b3e3722-7819-d199-4b50-525250524f50 version: v29384.48143 annotation: antimalware.am_core_dll.registered ncalrpc: PRRUniversal#2B412EFCDE2B5504:4028 ncalrpc: PRRNameService:4028 9b3e3722-1d09-1186-4b50-525250524f50 version: v29384.48143 annotation: npAVS_SCAN_AREA_ID ncalrpc: PRRUniversal#2B412EFCDE2B5504:4028 ncalrpc: PRRNameService:4028 9b3e3722-62c7-816c-4b50-525250524f50 version: v29384.48143 annotation: npUserContext ncalrpc: PRRUniversal#2B412EFCDE2B5504:4028 ncalrpc: PRRNameService:4028 9b3e3722-6122-0a2a-4b50-525250524f50 version: v29384.48143 annotation: npENGINE_VIRTUAL_OBJECT_NAME ncalrpc: PRRUniversal#2B412EFCDE2B5504:4028 ncalrpc: PRRNameService:4028 9b3e3722-c49b-fe45-4b50-525250524f50 version: v29384.48143 annotation: PROTOCOL_TYPE ncalrpc: PRRUniversal#2B412EFCDE2B5504:4028 ncalrpc: PRRNameService:4028 9b3e3722-0276-35b6-4b50-525250524f50 version: v29384.48143 annotation: MESSAGE_CHECK_ONLY ncalrpc: PRRUniversal#2B412EFCDE2B5504:4028 ncalrpc: PRRNameService:4028 9b3e3722-86c2-73eb-4b50-525250524f50 version: v29384.48143 annotation: MESSAGE_IS_INCOMING ncalrpc: PRRUniversal#2B412EFCDE2B5504:4028 ncalrpc: PRRNameService:4028 9b3e3722-f7aa-5ba3-4b50-525250524f50 version: v29384.48143 annotation: npAVS_HTTP_RSP ncalrpc: PRRUniversal#2B412EFCDE2B5504:4028 ncalrpc: PRRNameService:4028 9b3e3722-a39b-5baa-4b50-525250524f50 version: v29384.48143 annotation: npAVS_HTTP_REQ ncalrpc: PRRUniversal#2B412EFCDE2B5504:4028 ncalrpc: PRRNameService:4028 9b3e3722-050c-2b49-4b50-525250524f50 version: v29384.48143 annotation: cpTASK_MANAGER_TASK_ID ncalrpc: PRRUniversal#2B412EFCDE2B5504:4028 ncalrpc: PRRNameService:4028 9b3e3722-f9a8-d5cb-4b50-525250524f50 version: v29384.48143 annotation: cpTASK_MANAGER_PROFILE_NAME ncalrpc: PRRUniversal#2B412EFCDE2B5504:4028 ncalrpc: PRRNameService:4028 9b3e3722-1441-c93d-4b50-525250524f50 version: v29384.48143 annotation: cpTASK_MANAGER_TASK_TYPE_NAME ncalrpc: PRRUniversal#2B412EFCDE2B5504:4028 ncalrpc: PRRNameService:4028 9b3e3722-c75c-28ad-4b50-52524f424a53 version: v29384.48143 annotation: PRRoot ncalrpc: PRRUniversal#2B412EFCDE2B5504:4028 ncalrpc: PRRNameService:4028 9b3e3722-bab3-e001-4b50-52524f424a53 version: v29384.48143 annotation: ai_loader_remote_object ncalrpc: PRRUniversal#2B412EFCDE2B5504:4028 ncalrpc: PRRNameService:4028 ncalrpc: PRRUniversal#2B412EFCDE2B5504:4028 ncalrpc: PRRNameService:4028 9b3e3722-7551-7dee-4b50-525250524f50 version: v29384.48143 annotation: cpTEMPFILE_MEMMANAGER ncalrpc: PRRUniversal#2B412EFCDE2B5504:4028 ncalrpc: PRRNameService:4028 9b3e3722-e474-f035-4b50-525250524f50 version: v29384.48143 annotation: cpnPRAGUE_REMOTE_API ncalrpc: PRRUniversal#2B412EFCDE2B5504:4028 ncalrpc: PRRNameService:4028 9b3e3722-d801-7233-4b50-525250524f50 version: v29384.48143 annotation: PR_REMOTE_MANAGER_PROP ncalrpc: PRRUniversal#2B412EFCDE2B5504:4028 ncalrpc: PRRNameService:4028 9b3e3722-52c3-d00e-4b50-525250494453 version: v29384.48143 annotation: PRRUniversal#2B412EFCDE2B5504:4028 ncalrpc: PRRUniversal#2B412EFCDE2B5504:4028 d249bd56-4cc0-4fd3-8ce6-6fe050d590cb version: v0.0 ncalrpc: LRPC-f09f5864ec1dae3b31 d8140e00-5c46-4ae6-80ac-2f9a76df224c version: v0.0 ncalrpc: LRPC-f09f5864ec1dae3b31 367abb81-9844-35f1-ad32-98f038001003 version: v2.0 protocol: [MS-SCMR]: Service Control Manager Remote Protocol provider: services.exe ncacn_ip_tcp: 113.160.161.75:49670 906b0ce0-c70b-1067-b317-00dd010662da version: v1.0 protocol: [MS-CMPO]: MSDTC Connection Manager: provider: msdtcprx.dll ncalrpc: LRPC-c483fc0b20969ed772 ncalrpc: LRPC-c483fc0b20969ed772 ncalrpc: LRPC-c483fc0b20969ed772 0767a036-0d22-48aa-ba69-b619480f38cb version: v1.0 annotation: PcaSvc provider: pcasvc.dll ncalrpc: LRPC-bd193f7980e6389fca bf4dc912-e52f-4904-8ebe-9317c1bdd497 version: v1.0 ncalrpc: LRPC-3cbd6625c7b1919aac ncalrpc: OLEEC08D5FE034BC1059F4F034A37F6 9b3e3722-72dd-a52f-4b50-525250494453 version: v26307.58899 annotation: PRRUniversal#92CD811C1B4C21C3:65744 ncalrpc: PRRUniversal#92CD811C1B4C21C3:65744
1843068698 | 2024-03-26T22:39:50.355842137 / udp
NetBIOS Response: Server Name: WIN-B9T7E7OUACK MAC Address: EC:2A:72:33:2C:00 Names: WIN-B9T7E7OUACK <0x0> WORKGROUP <0x0> WIN-B9T7E7OUACK <0x20>
EC:2A:72:33:2C:00 OUI: EC:2A:72 Organization: Dell Inc. Assignment: MA-L Registration Date: 2021-09-13
1489525118 | 2024-03-26T02:33:28.155167443 / tcp
HTTP/1.1 404 Not Found Content-Type: text/html; charset=us-ascii Server: Microsoft-HTTPAPI/2.0 Date: Tue, 26 Mar 2024 02:33:27 GMT Connection: close Content-Length: 315
Certificate: Data: Version: 3 (0x2) Serial Number: 81:79:ac:e6:9a:1c:e1:7a:39:40:06:0a:69:6f:7b:18 Signature Algorithm: sha256WithRSAEncryption Issuer: C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Domain Validation Secure Server CA Validity Not Before: Nov 15 00:00:00 2022 GMT Not After : Nov 15 23:59:59 2023 GMT Subject: CN=www.mhtwindows.com Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (2048 bit) Modulus: 00:b9:d0:6b:f8:40:9e:d4:b0:17:02:3e:ef:8d:bb: 9d:6b:ad:97:e5:ae:c3:d0:e7:67:33:2a:c8:a4:8b: eb:86:c7:93:7c:71:18:1b:2d:a3:54:15:f0:b8:d3: d4:f5:39:4b:35:21:ff:66:d1:b2:19:53:3d:42:5e: ca:b3:ad:7c:cb:6f:36:e0:4d:c8:1a:03:84:6e:7d: 40:c1:08:f3:3e:56:97:be:ad:68:28:28:82:99:71: b8:4e:b8:b8:bd:f7:90:89:7a:6b:54:1d:43:b4:12: 95:54:47:40:bc:47:8d:dd:a9:c6:e7:74:bd:80:3c: 07:69:b2:c2:44:99:ea:c2:a9:57:f9:39:f3:fa:76: ec:b3:6e:25:bc:da:ff:cc:55:7d:e8:48:66:04:ba: 89:c2:e4:66:35:55:87:82:b8:e9:96:1c:bd:c9:7f: 56:b7:a6:1c:c8:2e:76:9c:4e:78:df:67:78:55:32: ab:49:6f:c3:f9:a4:94:e7:41:d9:f5:f3:5c:2f:1e: c9:10:aa:9c:23:b1:5b:54:93:d1:32:ba:b2:01:bd: 9a:c3:7a:ff:20:f6:21:70:16:1a:63:55:d0:d1:0f: ba:2b:0b:da:a4:e8:09:8d:86:4b:e3:45:0c:f9:06: 15:f4:8a:f5:58:c6:1e:d8:8c:0d:64:c3:89:e8:af: 81:4f Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Authority Key Identifier: 8D:8C:5E:C4:54:AD:8A:E1:77:E9:9B:F9:9B:05:E1:B8:01:8D:61:E1 X509v3 Subject Key Identifier: 88:15:EE:C6:96:E6:02:27:5E:17:43:33:A0:B0:9F:A6:82:62:62:F5 X509v3 Key Usage: critical Digital Signature, Key Encipherment X509v3 Basic Constraints: critical CA:FALSE X509v3 Extended Key Usage: TLS Web Server Authentication, TLS Web Client Authentication X509v3 Certificate Policies: Policy: 1.3.6.1.4.1.6449.1.2.2.7 CPS: https://sectigo.com/CPS Policy: 2.23.140.1.2.1 Authority Information Access: CA Issuers - URI:http://crt.sectigo.com/SectigoRSADomainValidationSecureServerCA.crt OCSP - URI:http://ocsp.sectigo.com X509v3 Subject Alternative Name: DNS:www.mhtwindows.com, DNS:mhtwindows.com CT Precertificate SCTs: Signed Certificate Timestamp: Version : v1 (0x0) Log ID : AD:F7:BE:FA:7C:FF:10:C8:8B:9D:3D:9C:1E:3E:18:6A: B4:67:29:5D:CF:B1:0C:24:CA:85:86:34:EB:DC:82:8A Timestamp : Nov 15 11:05:37.944 2022 GMT Extensions: none Signature : ecdsa-with-SHA256 30:44:02:20:16:20:A2:35:ED:0F:50:A8:FD:59:65:D9: 4F:79:68:BF:D0:90:5C:B7:C0:1F:B7:CF:3B:5B:2B:12: 53:0A:89:A5:02:20:48:31:7A:DE:8E:C0:47:F7:5E:C1: E9:3F:E8:6F:13:80:C1:D9:BD:CD:A5:6F:52:6E:2D:D5: C3:85:A5:1D:63:A8 Signed Certificate Timestamp: Version : v1 (0x0) Log ID : 7A:32:8C:54:D8:B7:2D:B6:20:EA:38:E0:52:1E:E9:84: 16:70:32:13:85:4D:3B:D2:2B:C1:3A:57:A3:52:EB:52 Timestamp : Nov 15 11:05:37.889 2022 GMT Extensions: none Signature : ecdsa-with-SHA256 30:45:02:20:4F:07:13:FE:CE:BB:25:F9:40:0B:24:91: CB:90:47:99:8B:E5:F6:65:62:FF:E6:28:8C:46:B7:46: 0E:D4:83:17:02:21:00:9D:55:08:E2:99:8B:56:CD:62: 2F:24:7E:58:D6:EF:4B:CE:00:CB:0B:89:3E:8A:79:A1: AE:FB:F4:2A:E7:CA:D6 Signed Certificate Timestamp: Version : v1 (0x0) Log ID : E8:3E:D0:DA:3E:F5:06:35:32:E7:57:28:BC:89:6B:C9: 03:D3:CB:D1:11:6B:EC:EB:69:E1:77:7D:6D:06:BD:6E Timestamp : Nov 15 11:05:37.852 2022 GMT Extensions: none Signature : ecdsa-with-SHA256 30:46:02:21:00:EE:93:B1:CC:1F:93:8B:01:A6:FD:14: 35:6A:23:31:00:C0:2A:9F:B9:C5:E3:2D:EF:8E:03:AE: CF:A0:3D:05:32:02:21:00:C4:24:A9:25:14:0E:99:79: F4:57:03:73:99:82:42:BA:CD:4F:12:F1:7B:92:36:96: 64:2F:D6:62:F1:CC:61:05 Signature Algorithm: sha256WithRSAEncryption Signature Value: 3a:9e:b9:01:8f:35:a5:16:9e:17:d3:44:9e:fd:40:ea:21:d7: 9f:84:69:6b:ac:98:30:24:05:3e:72:58:c0:a8:78:18:18:57: e1:23:fb:11:31:50:f4:87:34:e7:14:be:4b:1b:55:73:4b:49: 21:e9:67:94:25:1a:09:4b:5c:0b:9b:5b:e8:f4:27:dd:34:47: e0:a7:71:e6:9d:aa:b2:98:e0:bb:58:b5:10:4d:13:16:fb:d6: b9:b4:e4:20:f8:69:df:6c:ee:0e:c4:ef:e9:3a:3e:a1:26:b2: 52:98:0c:e9:db:a2:82:76:43:2f:b0:44:95:fd:1c:31:2a:eb: 92:fe:2e:30:70:50:e0:74:eb:b2:01:2c:f1:dd:f1:1d:42:0d: 63:bc:47:51:cb:41:8c:e5:1b:26:ce:8a:ca:f4:23:f3:a1:c4: 56:be:5c:86:ea:64:e1:98:8a:d9:58:ca:22:7d:c4:66:51:58: d9:0d:d7:91:b4:98:90:07:2e:db:71:ec:da:e9:8b:61:9b:dc: 44:e6:23:ed:2b:33:f9:da:75:60:2a:d8:fb:92:c5:2e:d6:2b: 6e:53:bf:98:27:79:0f:c5:25:99:2d:b9:c1:3e:9e:bc:c9:05: 02:20:a4:a3:e0:05:f6:db:d9:9f:18:88:97:2e:15:ba:82:6b: 5a:b3:ca:af
78945672 | 2024-03-28T16:21:09.0024443306 / tcp
MySQL: Error Message: Host '192.168.100.1' is blocked because of many connection errors; unblock with 'mysqladmin flush-hosts' Error Code: 1129
1489525118 | 2024-03-23T18:28:09.2384225985 / tcp
HTTP/1.1 404 Not Found Content-Type: text/html; charset=us-ascii Server: Microsoft-HTTPAPI/2.0 Date: Sat, 23 Mar 2024 18:28:09 GMT Connection: close Content-Length: 315 WinRM NTLM Info: OS: Windows Server 2022 OS Build: 10.0.20348 Target Name: WIN-B9T7E7OUACK NetBIOS Domain Name: WIN-B9T7E7OUACK NetBIOS Computer Name: WIN-B9T7E7OUACK DNS Domain Name: WIN-B9T7E7OUACK FQDN: WIN-B9T7E7OUACK
617312107 | 2024-03-17T00:06:45.1478248012 / tcp
HTTP/1.1 301 Moved Permanently Content-Type: text/html; charset=UTF-8 Location: https://anhkhoitea.com.vn/ Server: Microsoft-IIS/10.0 X-Powered-By: PHP/7.4.33 X-Redirect-By: WordPress X-Powered-By: ASP.NET Date: Sun, 17 Mar 2024 00:06:44 GMT Content-Length: 0
-1351636737 | 2024-03-27T07:04:19.9794538080 / tcp
HTTP/1.1 301 Moved Permanently Content-Type: text/html; charset=UTF-8 Location: http://vietdungaudio.com/ Server: Microsoft-IIS/10.0 X-Powered-By: PHP/7.4.33 X-Pingback: http://vietdungaudio.com/xmlrpc.php X-Redirect-By: WordPress X-Powered-By: ASP.NET Date: Wed, 27 Mar 2024 07:04:19 GMT Content-Length: 0
145660609 | 2024-03-20T14:18:58.8446698081 / tcp
HTTP/1.1 301 Moved Permanently Content-Type: text/html; charset=UTF-8 Location: http://retsi.edu.vn/ Server: Microsoft-IIS/10.0 X-Powered-By: PHP/7.4.33 X-Redirect-By: WordPress X-Powered-By: ASP.NET Date: Wed, 20 Mar 2024 14:18:58 GMT Content-Length: 0
-816155263 | 2024-03-18T13:07:24.9295618082 / tcp
HTTP/1.1 301 Moved Permanently Content-Type: text/html; charset=UTF-8 Location: https://mhtwindows.com/ Server: Microsoft-IIS/10.0 X-Powered-By: PHP/7.4.33 X-Pingback: http://mhtwindows.com/xmlrpc.php X-Redirect-By: WordPress X-Powered-By: ASP.NET Date: Mon, 18 Mar 2024 13:07:23 GMT Content-Length: 0
1682078393 | 2024-03-26T02:33:23.6371658099 / tcp
HTTP/1.1 301 Moved Permanently Content-Type: text/html; charset=UTF-8 Location: https://myphamkyo.com/ Server: Microsoft-IIS/10.0 X-Powered-By: PHP/7.4.33 X-Redirect-By: WordPress X-Powered-By: ASP.NET Date: Tue, 26 Mar 2024 02:33:16 GMT Content-Length: 0