5.35.235.35
As of: Jan 26, 2025 3:08pm UTC |
Latest
{
"ip": "5.35.235.35",
"services": [
{
"_decoded": "ftp",
"_encoding": {
"banner": "DISPLAY_UTF8",
"certificate": "DISPLAY_HEX",
"banner_hex": "DISPLAY_HEX"
},
"banner": "220 ::ffff:5.35.235.35 FTP server ready\r\n",
"banner_hashes": [
"sha256:a26fbe4b5583b50f8a35e262b7685fdda292cf10ca96d9e4feae87becf9f5981"
],
"banner_hex": "323230203a3a666666663a352e33352e3233352e333520465450207365727665722072656164790d0a",
"certificate": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"extended_service_name": "FTPes",
"ftp": {
"_encoding": {
"banner": "DISPLAY_UTF8",
"auth_tls_response": "DISPLAY_UTF8"
},
"banner": "220 ::ffff:5.35.235.35 FTP server ready\r\n",
"auth_tls_response": "234 AUTH TLS successful\r\n",
"status_code": 220,
"status_meaning": "Service ready for new user.",
"implicit_tls": false
},
"labels": [
"file-sharing"
],
"observed_at": "2025-01-26T12:45:07.951567315Z",
"perspective_id": "PERSPECTIVE_UNKNOWN",
"port": 21,
"service_name": "FTP",
"source_ip": "206.168.34.70",
"tls": {
"version_selected": "TLSv1_3",
"cipher_selected": "TLS_AES_256_GCM_SHA384",
"certificates": {
"_encoding": {
"leaf_fp_sha_256": "DISPLAY_HEX",
"chain_fps_sha_256": "DISPLAY_HEX"
},
"leaf_fp_sha_256": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"chain_fps_sha_256": [
"973a41276ffd01e027a2aad49e34c37846d3e976ff6a620b6712e33832041aa6"
],
"leaf_data": {
"names": [
"*.ftp.server-he.ch",
"*.ftp.server-he.de",
"*.mail.server-he.ch",
"*.mail.server-he.de",
"*.mailout.server-he.ch",
"*.mailout.server-he.de",
"*.mywebdav.de",
"*.server-he.ch",
"*.server-he.de",
"*.storage.hosteurope.de",
"*.webpack.hosteurope.de",
"ftp.server-he.ch",
"ftp.server-he.de",
"mail.server-he.ch",
"mail.server-he.de",
"mailout.server-he.ch",
"mailout.server-he.de",
"mywebdav.de",
"server-he.ch",
"server-he.de",
"storage.hosteurope.de",
"webpack.hosteurope.de"
],
"subject_dn": "CN=*.webpack.hosteurope.de",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2",
"pubkey_bit_size": 2048,
"pubkey_algorithm": "RSA",
"tbs_fingerprint": "ed00f936e81acddb849611d08947d8dee072fdd207648bd0f39716e5b8022173",
"fingerprint": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"issuer": {
"common_name": [
"Go Daddy Secure Certificate Authority - G2"
],
"locality": [
"Scottsdale"
],
"organization": [
"GoDaddy.com, Inc."
],
"organizational_unit": [
"http://certs.godaddy.com/repository/"
],
"province": [
"Arizona"
],
"country": [
"US"
]
},
"subject": {
"common_name": [
"*.webpack.hosteurope.de"
]
},
"public_key": {
"key_algorithm": "RSA",
"rsa": {
"_encoding": {
"modulus": "DISPLAY_BASE64",
"exponent": "DISPLAY_BASE64"
},
"modulus": "wvC2VcxxtQrgbie9GHIErsPvnWnuluS0kGaPvR1tMTC3pV+1opgT9uGKQv7MCKsoB4Gr25J/CL8fDHu4myH5tOYvVFfHNZsHXAB+utxZX9Jfz5ILwaNWaJrbMHXiOnBtwMAdW1YonClBHOGy2hB7eYm0trgSz98tIgphZIqhr0XbewlYkFccHA+mRLFr4ZCABI33Oo3s5FYjRP+S6OZiYe3AXnQym/HCv0jO7+tz3Z5HmfSkhXkF0bPddHAgyRvTNu7hEKsPlpGo+wXKQdyVHBfgbrdADxS3BsRFpyRC84E1xcBEgQmWXRqjt+zwFCovrbWmBl5kUhldYp5YjJcaSw==",
"exponent": "AAEAAQ==",
"length": 256
},
"fingerprint": "943f1445820198e0eab45cbef93e18ab356a0a3776f88aad3e38de4da2f383fc"
},
"signature": {
"signature_algorithm": "SHA256-RSA",
"self_signed": false
}
},
"chain": [
{
"fingerprint": "973a41276ffd01e027a2aad49e34c37846d3e976ff6a620b6712e33832041aa6",
"subject_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., CN=Go Daddy Root Certificate Authority - G2"
}
]
},
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "15af977ce25de452b96affa2addb1036",
"ja4s": "t130200_1302_a56c5b993250"
},
"transport_fingerprint": {
"raw": "43440,64,true,MSTNW,1460,false,false"
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "ssh",
"_encoding": {
"banner": "DISPLAY_UTF8",
"banner_hex": "DISPLAY_HEX"
},
"banner": "SSH-2.0-OpenSSH_9.2p1 Debian-2+deb12u3",
"banner_hashes": [
"sha256:aecc50748fc4fcf22950dbe2bd03093166a09499ff9961c4b7e47dfd041376f4"
],
"banner_hex": "5353482d322e302d4f70656e5353485f392e3270312044656269616e2d322b64656231327533",
"extended_service_name": "SSH",
"labels": [
"remote-access"
],
"observed_at": "2025-01-26T00:57:29.515203132Z",
"perspective_id": "PERSPECTIVE_UNKNOWN",
"port": 22,
"service_name": "SSH",
"software": [
{
"uniform_resource_identifier": "cpe:2.3:o:*:linux:*:*:*:*:*:*:*:*",
"part": "o",
"product": "linux",
"source": "OSI_TRANSPORT_LAYER"
}
],
"source_ip": "167.94.138.191",
"ssh": {
"endpoint_id": {
"_encoding": {
"raw": "DISPLAY_UTF8"
},
"raw": "SSH-2.0-OpenSSH_9.2p1 Debian-2+deb12u3",
"protocol_version": "2.0",
"software_version": "OpenSSH_9.2p1",
"comment": "Debian-2+deb12u3"
},
"kex_init_message": {
"kex_algorithms": [
"[email protected]",
"curve25519-sha256",
"[email protected]",
"ecdh-sha2-nistp256",
"ecdh-sha2-nistp384",
"ecdh-sha2-nistp521",
"diffie-hellman-group-exchange-sha256",
"diffie-hellman-group16-sha512",
"diffie-hellman-group18-sha512",
"diffie-hellman-group14-sha256",
"[email protected]"
],
"host_key_algorithms": [
"rsa-sha2-512",
"rsa-sha2-256",
"ecdsa-sha2-nistp256",
"ssh-ed25519"
],
"client_to_server_ciphers": [
"[email protected]",
"aes128-ctr",
"aes192-ctr",
"aes256-ctr",
"[email protected]",
"[email protected]"
],
"server_to_client_ciphers": [
"[email protected]",
"aes128-ctr",
"aes192-ctr",
"aes256-ctr",
"[email protected]",
"[email protected]"
],
"client_to_server_macs": [
"[email protected]",
"[email protected]",
"[email protected]",
"[email protected]",
"[email protected]",
"[email protected]",
"[email protected]",
"hmac-sha2-256",
"hmac-sha2-512",
"hmac-sha1"
],
"server_to_client_macs": [
"[email protected]",
"[email protected]",
"[email protected]",
"[email protected]",
"[email protected]",
"[email protected]",
"[email protected]",
"hmac-sha2-256",
"hmac-sha2-512",
"hmac-sha1"
],
"client_to_server_compression": [
"none",
"[email protected]"
],
"server_to_client_compression": [
"none",
"[email protected]"
],
"first_kex_follows": false
},
"algorithm_selection": {
"kex_algorithm": "[email protected]",
"host_key_algorithm": "ecdsa-sha2-nistp256",
"client_to_server_alg_group": {
"cipher": "aes128-ctr",
"mac": "hmac-sha2-256",
"compression": "none"
},
"server_to_client_alg_group": {
"cipher": "aes128-ctr",
"mac": "hmac-sha2-256",
"compression": "none"
}
},
"server_host_key": {
"fingerprint_sha256": "01cc276efc9e0b30ec5ea7cbf8cd5a31df2df60626a8e85ea61b3ac2486e9748",
"ecdsa_public_key": {
"_encoding": {
"b": "DISPLAY_BASE64",
"gx": "DISPLAY_BASE64",
"gy": "DISPLAY_BASE64",
"n": "DISPLAY_BASE64",
"p": "DISPLAY_BASE64",
"x": "DISPLAY_BASE64",
"y": "DISPLAY_BASE64"
},
"b": "WsY12Ko6k+ez671VdpiGvGUdBrDMU7D2O848PifSYEs=",
"curve": "P-256",
"gx": "axfR8uEsQkf4vOblY6RA8ncDfYEt6zOg9KE5RdiYwpY=",
"gy": "T+NC4v4af5uO5+tKfA+eFivOM1drMV7Oy7ZAaDe/UfU=",
"length": 256,
"n": "/////wAAAAD//////////7zm+q2nF56E87nKwvxjJVE=",
"p": "/////wAAAAEAAAAAAAAAAAAAAAD///////////////8=",
"x": "psQAjNpCccdJwp48k2kytJq7jwWRTWoL2qvvkXTkc1s=",
"y": "zAV5MlmLy71lqUujtkktDH62MzwepHK6AwXZ8jckqJM="
}
},
"hassh_fingerprint": "a65c3b91f743d3f246e72172e77288f1"
},
"transport_fingerprint": {
"id": 72,
"os": "Ubuntu / Debian / CentOS",
"raw": "28960,64,true,MSTNW,1460,false,false"
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "smtp",
"_encoding": {
"banner": "DISPLAY_UTF8",
"certificate": "DISPLAY_HEX",
"banner_hex": "DISPLAY_HEX"
},
"banner": "220 vwp12946.webpack.hosteurope.de ESMTP Host Europe Mail Service Sun, 26 Jan 2025 01:54:03 +0100\r\n",
"banner_hashes": [
"sha256:f2fbb8c948b3d0e3da2d663a9dd7b66ea99156ce12ce4e4dbdad74ca87114e91"
],
"banner_hex": "3232302076777031323934362e7765627061636b2e686f73746575726f70652e64652045534d545020486f7374204575726f7065204d61696c20536572766963652053756e2c203236204a616e20323032352030313a35343a3033202b303130300d0a",
"certificate": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"extended_service_name": "SMTP-STARTTLS",
"labels": [
"email"
],
"observed_at": "2025-01-26T00:54:03.071369357Z",
"perspective_id": "PERSPECTIVE_UNKNOWN",
"port": 25,
"service_name": "SMTP",
"smtp": {
"_encoding": {
"banner": "DISPLAY_UTF8",
"ehlo": "DISPLAY_UTF8",
"start_tls": "DISPLAY_UTF8"
},
"banner": "220 vwp12946.webpack.hosteurope.de ESMTP Host Europe Mail Service Sun, 26 Jan 2025 01:54:03 +0100\r\n",
"ehlo": "250-vwp12946.webpack.hosteurope.de Hello www.censys.io [167.94.138.59]\r\n250-SIZE 52428800\r\n250-8BITMIME\r\n250-PIPELINING\r\n250-PIPECONNECT\r\n250-AUTH PLAIN LOGIN\r\n250-STARTTLS\r\n250 HELP\r\n",
"start_tls": "220 TLS go ahead\r\n"
},
"source_ip": "167.94.138.59",
"tls": {
"version_selected": "TLSv1_3",
"cipher_selected": "TLS_CHACHA20_POLY1305_SHA256",
"certificates": {
"_encoding": {
"leaf_fp_sha_256": "DISPLAY_HEX",
"chain_fps_sha_256": "DISPLAY_HEX"
},
"leaf_fp_sha_256": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"chain_fps_sha_256": [
"973a41276ffd01e027a2aad49e34c37846d3e976ff6a620b6712e33832041aa6"
],
"leaf_data": {
"names": [
"*.ftp.server-he.ch",
"*.ftp.server-he.de",
"*.mail.server-he.ch",
"*.mail.server-he.de",
"*.mailout.server-he.ch",
"*.mailout.server-he.de",
"*.mywebdav.de",
"*.server-he.ch",
"*.server-he.de",
"*.storage.hosteurope.de",
"*.webpack.hosteurope.de",
"ftp.server-he.ch",
"ftp.server-he.de",
"mail.server-he.ch",
"mail.server-he.de",
"mailout.server-he.ch",
"mailout.server-he.de",
"mywebdav.de",
"server-he.ch",
"server-he.de",
"storage.hosteurope.de",
"webpack.hosteurope.de"
],
"subject_dn": "CN=*.webpack.hosteurope.de",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2",
"pubkey_bit_size": 2048,
"pubkey_algorithm": "RSA",
"tbs_fingerprint": "ed00f936e81acddb849611d08947d8dee072fdd207648bd0f39716e5b8022173",
"fingerprint": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"issuer": {
"common_name": [
"Go Daddy Secure Certificate Authority - G2"
],
"locality": [
"Scottsdale"
],
"organization": [
"GoDaddy.com, Inc."
],
"organizational_unit": [
"http://certs.godaddy.com/repository/"
],
"province": [
"Arizona"
],
"country": [
"US"
]
},
"subject": {
"common_name": [
"*.webpack.hosteurope.de"
]
},
"public_key": {
"key_algorithm": "RSA",
"rsa": {
"_encoding": {
"modulus": "DISPLAY_BASE64",
"exponent": "DISPLAY_BASE64"
},
"modulus": "wvC2VcxxtQrgbie9GHIErsPvnWnuluS0kGaPvR1tMTC3pV+1opgT9uGKQv7MCKsoB4Gr25J/CL8fDHu4myH5tOYvVFfHNZsHXAB+utxZX9Jfz5ILwaNWaJrbMHXiOnBtwMAdW1YonClBHOGy2hB7eYm0trgSz98tIgphZIqhr0XbewlYkFccHA+mRLFr4ZCABI33Oo3s5FYjRP+S6OZiYe3AXnQym/HCv0jO7+tz3Z5HmfSkhXkF0bPddHAgyRvTNu7hEKsPlpGo+wXKQdyVHBfgbrdADxS3BsRFpyRC84E1xcBEgQmWXRqjt+zwFCovrbWmBl5kUhldYp5YjJcaSw==",
"exponent": "AAEAAQ==",
"length": 256
},
"fingerprint": "943f1445820198e0eab45cbef93e18ab356a0a3776f88aad3e38de4da2f383fc"
},
"signature": {
"signature_algorithm": "SHA256-RSA",
"self_signed": false
}
},
"chain": [
{
"fingerprint": "973a41276ffd01e027a2aad49e34c37846d3e976ff6a620b6712e33832041aa6",
"subject_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., CN=Go Daddy Root Certificate Authority - G2"
}
]
},
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "d75f9129bb5d05492a65ff78e081bcb2",
"ja4s": "t130200_1303_234ea6891581"
},
"transport_fingerprint": {
"raw": "43440,64,true,MSTNW,1460,false,false"
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "http",
"_encoding": {
"banner": "DISPLAY_UTF8",
"banner_hex": "DISPLAY_HEX"
},
"banner": "HTTP/1.1 403 Forbidden\r\nServer: nginx\r\nDate: <REDACTED>\r\nContent-Type: text/html\r\nContent-Length: 2867\r\nConnection: keep-alive\r\nETag: \"6391baca-b33\"\r\n",
"banner_hashes": [
"sha256:4030f4a9bbb6a32b34dfbb0567f3e92df5c3903af2eb57e1ca4efc7a80fe4d88"
],
"banner_hex": "485454502f312e312034303320466f7262696464656e0d0a5365727665723a206e67696e780d0a446174653a20203c52454441435445443e0d0a436f6e74656e742d547970653a20746578742f68746d6c0d0a436f6e74656e742d4c656e6774683a20323836370d0a436f6e6e656374696f6e3a206b6565702d616c6976650d0a455461673a202236333931626163612d623333220d0a",
"extended_service_name": "HTTP",
"http": {
"request": {
"method": "GET",
"uri": "http://5.35.235.35/",
"headers": {
"User_Agent": [
"Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)"
],
"_encoding": {
"User_Agent": "DISPLAY_UTF8",
"Accept": "DISPLAY_UTF8"
},
"Accept": [
"*/*"
]
}
},
"response": {
"protocol": "HTTP/1.1",
"status_code": 403,
"status_reason": "Forbidden",
"headers": {
"Date": [
"<REDACTED>"
],
"_encoding": {
"Date": "DISPLAY_UTF8",
"Server": "DISPLAY_UTF8",
"Content_Length": "DISPLAY_UTF8",
"Content_Type": "DISPLAY_UTF8",
"ETag": "DISPLAY_UTF8",
"Connection": "DISPLAY_UTF8"
},
"Server": [
"nginx"
],
"Content_Length": [
"2867"
],
"Content_Type": [
"text/html"
],
"ETag": [
"\"6391baca-b33\""
],
"Connection": [
"keep-alive"
]
},
"_encoding": {
"html_tags": "DISPLAY_UTF8",
"body": "DISPLAY_UTF8",
"body_hash": "DISPLAY_UTF8",
"html_title": "DISPLAY_UTF8"
},
"html_tags": [
"<title>\n Host Europe GmbH\n </title>",
"<meta name=\"robots\" content=\"noarchive\">",
"<meta name=\"robots\" content=\"noindex, follow\">",
"<meta name=\"revisit-after\" content=\"1 day\">"
],
"body_size": 2867,
"body": "<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//EN\"\n \"http://www.w3.org/TR/html4/loose.dtd\">\n<html>\n<head>\n <meta name=\"robots\" content=\"noarchive\">\n <meta name=\"robots\" content=\"noindex, follow\">\n <meta name=\"revisit-after\" content=\"1 day\">\n <title>\n Host Europe GmbH\n </title> \n <style type=\"text/css\">\n body{\n margin:0;\n background-color: #999;\n background-image:url('/globalhererrordocuments/bgcolor.jpg');\n background-position:absolute;\n top:0px;\n background-repeat: repeat-x;\n font-size:11px;\n font-family:\"verdana\", sans-serif;\n }\n h1{\n font-size:18pt;\n font-weight:bold;\n font-family:'Verdana', sans-serif;\n color:#333;\n }\n h2{\n font-size:12pt;\n font-family:'Verdana', sans-serif;\n font-weight:bold;\n margin:5px;\n margin-left:0;\n color:#333;\n }\n h3{\n font-size:11pt;\n font-family:'Verdana', sans-serif;\n font-weight:bold;\n margin:5px;\n margin-left:0;\n color:#333;\n }\n p{\n font-size:10pt;\n font-family:'Verdana', sans-serif;\n font-weight:bold;\n margin:5px;\n margin-left:0;\n color:#333;\n }\n td{ \n color:#333;\n }\n </style>\n</head>\n<body>\n<table id=\"tab_allcontent\" width=\"762\" cellpadding=\"0\" cellspacing=\"0\" border=\"0\" summary=\"page-container\">\n <tr style=\"vertical-align:top; height:10px;\">\n <td>\n <img src=\"/globalhererrordocuments/tabspace5x5.gif\" width=\"10\" height=\"10\" alt=\"\">\n </td>\n </tr>\n <tr style=\"vertical-align:top;\">\n <td style=\"width:10px;\"></td>\n <td class=\"all\" style=\"width:752px;\">\n <table id=\"tab_contentonly\" width=\"752\" cellpadding=\"0\" cellspacing=\"0\" border=\"0\" summary=\"error-container\">\n <tr style=\"height:110px; vertical-align:top;\">\n <td>\n <table id=\"tab_contentheader\" width=\"721\" cellpadding=\"0\" cellspacing=\"0\" border=\"0\" summary=\"error-sign-and-message\">\n <tr valign=\"top\">\n <td style=\"width:150px;\">\n <img src=\"/globalhererrordocuments/header_caution_sign_verlauf.gif\" alt=\"header_caution_sign_verlauf.gif, 9 kB\" title=\"Domain ist temporär nicht erreichbar\" border=\"0\" height=\"150\" width=\"150\">\n </td>\n <td valign=\"middle\">\n <h2 style=\"font-weight:bold;font-size:medium;\">Die von Ihnen gewünschte Seite ist temporär nicht erreichbar.</h2>\n <h3 style=\"font-weight:normal;font-size:142%;\">Bitte versuchen Sie es zu einem späteren Zeitpunkt noch einmal.</h3>\n\t\t <h2 style=\"font-weight:bold;font-size:medium;\">This site is temporarily unavailable.</h2>\n <h3 style=\"font-weight:normal;font-size:142%;\">Please try again later.</h3>\n </td> \n </tr>\n </table>\n </td>\n </tr> \n </table> \n </td> \n </tr>\n</table>\n</body>\n</html>\n",
"body_hashes": [
"sha256:ce83de3976867bd4b4f9a3da99ca65a552e0ece986b93b01d72f8cffc21567f3",
"sha1:f4dce2cb8ecb19650ad3ebe31b87badbce816998"
],
"body_hash": "sha1:f4dce2cb8ecb19650ad3ebe31b87badbce816998",
"html_title": "\n Host Europe GmbH\n "
},
"supports_http2": false
},
"observed_at": "2025-01-26T12:43:02.051052836Z",
"perspective_id": "PERSPECTIVE_UNKNOWN",
"port": 80,
"service_name": "HTTP",
"software": [
{
"uniform_resource_identifier": "cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*",
"part": "a",
"vendor": "nginx",
"product": "nginx",
"other": {
"family": "nginx"
},
"source": "OSI_APPLICATION_LAYER"
}
],
"source_ip": "206.168.34.77",
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "pop3",
"_encoding": {
"banner": "DISPLAY_UTF8",
"certificate": "DISPLAY_HEX",
"banner_hex": "DISPLAY_HEX"
},
"banner": "+OK Dovecot (Debian) ready.\r\n",
"banner_hashes": [
"sha256:d23f942eab9de1c939a3dcab0aefadf6c86ebc2b99ba56b2b364c14c7c2b8dad"
],
"banner_hex": "2b4f4b20446f7665636f74202844656269616e292072656164792e0d0a",
"certificate": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"extended_service_name": "POP3S",
"labels": [
"email"
],
"observed_at": "2025-01-25T22:28:59.122908882Z",
"perspective_id": "PERSPECTIVE_UNKNOWN",
"pop3": {
"_encoding": {
"banner": "DISPLAY_UTF8",
"start_tls": "DISPLAY_UTF8"
},
"banner": "+OK Dovecot (Debian) ready.\r\n",
"start_tls": "+OK Begin TLS negotiation now.\r\n"
},
"port": 110,
"service_name": "POP3",
"software": [
{
"uniform_resource_identifier": "cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*",
"part": "a",
"vendor": "Dovecot",
"product": "Dovecot",
"other": {
"family": "Dovecot"
},
"source": "OSI_APPLICATION_LAYER"
},
{
"uniform_resource_identifier": "cpe:2.3:o:debian:debian_linux:*:*:*:*:*:*:*:*",
"part": "o",
"vendor": "Debian",
"product": "Linux",
"other": {
"family": "Linux"
},
"source": "OSI_APPLICATION_LAYER"
}
],
"source_ip": "206.168.34.201",
"tls": {
"version_selected": "TLSv1_3",
"cipher_selected": "TLS_AES_256_GCM_SHA384",
"certificates": {
"_encoding": {
"leaf_fp_sha_256": "DISPLAY_HEX",
"chain_fps_sha_256": "DISPLAY_HEX"
},
"leaf_fp_sha_256": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"chain_fps_sha_256": [
"973a41276ffd01e027a2aad49e34c37846d3e976ff6a620b6712e33832041aa6"
],
"leaf_data": {
"names": [
"*.ftp.server-he.ch",
"*.ftp.server-he.de",
"*.mail.server-he.ch",
"*.mail.server-he.de",
"*.mailout.server-he.ch",
"*.mailout.server-he.de",
"*.mywebdav.de",
"*.server-he.ch",
"*.server-he.de",
"*.storage.hosteurope.de",
"*.webpack.hosteurope.de",
"ftp.server-he.ch",
"ftp.server-he.de",
"mail.server-he.ch",
"mail.server-he.de",
"mailout.server-he.ch",
"mailout.server-he.de",
"mywebdav.de",
"server-he.ch",
"server-he.de",
"storage.hosteurope.de",
"webpack.hosteurope.de"
],
"subject_dn": "CN=*.webpack.hosteurope.de",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2",
"pubkey_bit_size": 2048,
"pubkey_algorithm": "RSA",
"tbs_fingerprint": "ed00f936e81acddb849611d08947d8dee072fdd207648bd0f39716e5b8022173",
"fingerprint": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"issuer": {
"common_name": [
"Go Daddy Secure Certificate Authority - G2"
],
"locality": [
"Scottsdale"
],
"organization": [
"GoDaddy.com, Inc."
],
"organizational_unit": [
"http://certs.godaddy.com/repository/"
],
"province": [
"Arizona"
],
"country": [
"US"
]
},
"subject": {
"common_name": [
"*.webpack.hosteurope.de"
]
},
"public_key": {
"key_algorithm": "RSA",
"rsa": {
"_encoding": {
"modulus": "DISPLAY_BASE64",
"exponent": "DISPLAY_BASE64"
},
"modulus": "wvC2VcxxtQrgbie9GHIErsPvnWnuluS0kGaPvR1tMTC3pV+1opgT9uGKQv7MCKsoB4Gr25J/CL8fDHu4myH5tOYvVFfHNZsHXAB+utxZX9Jfz5ILwaNWaJrbMHXiOnBtwMAdW1YonClBHOGy2hB7eYm0trgSz98tIgphZIqhr0XbewlYkFccHA+mRLFr4ZCABI33Oo3s5FYjRP+S6OZiYe3AXnQym/HCv0jO7+tz3Z5HmfSkhXkF0bPddHAgyRvTNu7hEKsPlpGo+wXKQdyVHBfgbrdADxS3BsRFpyRC84E1xcBEgQmWXRqjt+zwFCovrbWmBl5kUhldYp5YjJcaSw==",
"exponent": "AAEAAQ==",
"length": 256
},
"fingerprint": "943f1445820198e0eab45cbef93e18ab356a0a3776f88aad3e38de4da2f383fc"
},
"signature": {
"signature_algorithm": "SHA256-RSA",
"self_signed": false
}
},
"chain": [
{
"fingerprint": "973a41276ffd01e027a2aad49e34c37846d3e976ff6a620b6712e33832041aa6",
"subject_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., CN=Go Daddy Root Certificate Authority - G2"
}
]
},
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "15af977ce25de452b96affa2addb1036",
"ja4s": "t130200_1302_a56c5b993250"
},
"transport_fingerprint": {
"raw": "43440,64,true,MSTNW,1460,false,false"
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "ntp",
"extended_service_name": "NTP",
"ntp": {
"get_time_header": {
"version": 3,
"mode": 4,
"stratum": 5,
"precision": -22,
"_encoding": {
"reference_id": "DISPLAY_UTF8"
},
"reference_id": "P\ud011",
"leap_indicator": 0,
"poll": 0
}
},
"observed_at": "2025-01-26T09:42:04.133469837Z",
"perspective_id": "PERSPECTIVE_UNKNOWN",
"port": 123,
"service_name": "NTP",
"source_ip": "167.94.138.117",
"transport_protocol": "UDP",
"truncated": false
},
{
"_decoded": "imap",
"_encoding": {
"banner": "DISPLAY_UTF8",
"certificate": "DISPLAY_HEX",
"banner_hex": "DISPLAY_HEX"
},
"banner": "* OK [CAPABILITY IMAP4rev1 SASL-IR LOGIN-REFERRALS ID ENABLE IDLE LITERAL+ STARTTLS AUTH=PLAIN] Dovecot (Debian) ready.\r\n",
"banner_hashes": [
"sha256:30da5d31a6902099f19ddc50a2f3de9fceaa1081ac7b6fed7c48384108795c93"
],
"banner_hex": "2a204f4b205b4341504142494c49545920494d41503472657631205341534c2d4952204c4f47494e2d524546455252414c5320494420454e41424c452049444c45204c49544552414c2b205354415254544c5320415554483d504c41494e5d20446f7665636f74202844656269616e292072656164792e0d0a",
"certificate": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"extended_service_name": "IMAPS",
"imap": {
"_encoding": {
"banner": "DISPLAY_UTF8"
},
"banner": "* OK [CAPABILITY IMAP4rev1 SASL-IR LOGIN-REFERRALS ID ENABLE IDLE LITERAL+ STARTTLS AUTH=PLAIN] Dovecot (Debian) ready.\r\n",
"start_tls": "a001 OK Begin TLS negotiation now.\r\n"
},
"labels": [
"email"
],
"observed_at": "2025-01-26T03:15:06.547222771Z",
"perspective_id": "PERSPECTIVE_UNKNOWN",
"port": 143,
"service_name": "IMAP",
"software": [
{
"uniform_resource_identifier": "cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*",
"part": "a",
"vendor": "Dovecot",
"product": "Dovecot",
"other": {
"family": "Dovecot"
},
"source": "OSI_APPLICATION_LAYER"
},
{
"uniform_resource_identifier": "cpe:2.3:o:debian:debian_linux:*:*:*:*:*:*:*:*",
"part": "o",
"vendor": "Debian",
"product": "Linux",
"other": {
"family": "Linux"
},
"source": "OSI_APPLICATION_LAYER"
}
],
"source_ip": "206.168.34.74",
"tls": {
"version_selected": "TLSv1_3",
"cipher_selected": "TLS_AES_256_GCM_SHA384",
"certificates": {
"_encoding": {
"leaf_fp_sha_256": "DISPLAY_HEX",
"chain_fps_sha_256": "DISPLAY_HEX"
},
"leaf_fp_sha_256": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"chain_fps_sha_256": [
"973a41276ffd01e027a2aad49e34c37846d3e976ff6a620b6712e33832041aa6"
],
"leaf_data": {
"names": [
"*.ftp.server-he.ch",
"*.ftp.server-he.de",
"*.mail.server-he.ch",
"*.mail.server-he.de",
"*.mailout.server-he.ch",
"*.mailout.server-he.de",
"*.mywebdav.de",
"*.server-he.ch",
"*.server-he.de",
"*.storage.hosteurope.de",
"*.webpack.hosteurope.de",
"ftp.server-he.ch",
"ftp.server-he.de",
"mail.server-he.ch",
"mail.server-he.de",
"mailout.server-he.ch",
"mailout.server-he.de",
"mywebdav.de",
"server-he.ch",
"server-he.de",
"storage.hosteurope.de",
"webpack.hosteurope.de"
],
"subject_dn": "CN=*.webpack.hosteurope.de",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2",
"pubkey_bit_size": 2048,
"pubkey_algorithm": "RSA",
"tbs_fingerprint": "ed00f936e81acddb849611d08947d8dee072fdd207648bd0f39716e5b8022173",
"fingerprint": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"issuer": {
"common_name": [
"Go Daddy Secure Certificate Authority - G2"
],
"locality": [
"Scottsdale"
],
"organization": [
"GoDaddy.com, Inc."
],
"organizational_unit": [
"http://certs.godaddy.com/repository/"
],
"province": [
"Arizona"
],
"country": [
"US"
]
},
"subject": {
"common_name": [
"*.webpack.hosteurope.de"
]
},
"public_key": {
"key_algorithm": "RSA",
"rsa": {
"_encoding": {
"modulus": "DISPLAY_BASE64",
"exponent": "DISPLAY_BASE64"
},
"modulus": "wvC2VcxxtQrgbie9GHIErsPvnWnuluS0kGaPvR1tMTC3pV+1opgT9uGKQv7MCKsoB4Gr25J/CL8fDHu4myH5tOYvVFfHNZsHXAB+utxZX9Jfz5ILwaNWaJrbMHXiOnBtwMAdW1YonClBHOGy2hB7eYm0trgSz98tIgphZIqhr0XbewlYkFccHA+mRLFr4ZCABI33Oo3s5FYjRP+S6OZiYe3AXnQym/HCv0jO7+tz3Z5HmfSkhXkF0bPddHAgyRvTNu7hEKsPlpGo+wXKQdyVHBfgbrdADxS3BsRFpyRC84E1xcBEgQmWXRqjt+zwFCovrbWmBl5kUhldYp5YjJcaSw==",
"exponent": "AAEAAQ==",
"length": 256
},
"fingerprint": "943f1445820198e0eab45cbef93e18ab356a0a3776f88aad3e38de4da2f383fc"
},
"signature": {
"signature_algorithm": "SHA256-RSA",
"self_signed": false
}
},
"chain": [
{
"fingerprint": "973a41276ffd01e027a2aad49e34c37846d3e976ff6a620b6712e33832041aa6",
"subject_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., CN=Go Daddy Root Certificate Authority - G2"
}
]
},
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "15af977ce25de452b96affa2addb1036",
"ja4s": "t130200_1302_a56c5b993250",
"versions": [
{
"tls_version": "TLSv1_3",
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "15af977ce25de452b96affa2addb1036",
"ja4s": "t130200_1302_a56c5b993250"
}
]
},
"transport_fingerprint": {
"raw": "43440,64,true,MSTNW,1460,false,false"
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "http",
"_encoding": {
"banner": "DISPLAY_UTF8",
"certificate": "DISPLAY_HEX",
"banner_hex": "DISPLAY_HEX"
},
"banner": "HTTP/1.1 301 Moved Permanently\r\nServer: nginx\r\nDate: <REDACTED>\r\nContent-Type: text/html\r\nContent-Length: 162\r\nConnection: keep-alive\r\nLocation: https://www.healing-wisdom.de\r\n",
"banner_hashes": [
"sha256:d5e1bb3d5724383d3d28f9036e04e8d5d26cc65de1299917df0d79200525ccb2"
],
"banner_hex": "485454502f312e3120333031204d6f766564205065726d616e656e746c790d0a5365727665723a206e67696e780d0a446174653a20203c52454441435445443e0d0a436f6e74656e742d547970653a20746578742f68746d6c0d0a436f6e74656e742d4c656e6774683a203136320d0a436f6e6e656374696f6e3a206b6565702d616c6976650d0a4c6f636174696f6e3a2068747470733a2f2f7777772e6865616c696e672d776973646f6d2e64650d0a",
"certificate": "04bec9a82406accbd4ce78e485c69dcb661080aeca4aaf25f09b4315545bde85",
"extended_service_name": "HTTPS",
"http": {
"request": {
"method": "GET",
"uri": "https://5.35.235.35/",
"headers": {
"User_Agent": [
"Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)"
],
"_encoding": {
"User_Agent": "DISPLAY_UTF8",
"Accept": "DISPLAY_UTF8"
},
"Accept": [
"*/*"
]
}
},
"response": {
"protocol": "HTTP/1.1",
"status_code": 301,
"status_reason": "Moved Permanently",
"headers": {
"Date": [
"<REDACTED>"
],
"_encoding": {
"Date": "DISPLAY_UTF8",
"Server": "DISPLAY_UTF8",
"Content_Length": "DISPLAY_UTF8",
"Content_Type": "DISPLAY_UTF8",
"Location": "DISPLAY_UTF8",
"Connection": "DISPLAY_UTF8"
},
"Server": [
"nginx"
],
"Content_Length": [
"162"
],
"Content_Type": [
"text/html"
],
"Location": [
"https://www.healing-wisdom.de"
],
"Connection": [
"keep-alive"
]
},
"_encoding": {
"html_tags": "DISPLAY_UTF8",
"body": "DISPLAY_UTF8",
"body_hash": "DISPLAY_UTF8",
"html_title": "DISPLAY_UTF8"
},
"html_tags": [
"<title>301 Moved Permanently</title>"
],
"body_size": 162,
"body": "<html>\r\n<head><title>301 Moved Permanently</title></head>\r\n<body>\r\n<center><h1>301 Moved Permanently</h1></center>\r\n<hr><center>nginx</center>\r\n</body>\r\n</html>\r\n",
"body_hashes": [
"sha256:9e17cb15dd75bbbd5dbb984eda674863c3b10ab72613cf8a39a00c3e11a8492a",
"sha1:3adb1f02d5b6054de0046e367c1d687b6cdf7aff"
],
"body_hash": "sha1:3adb1f02d5b6054de0046e367c1d687b6cdf7aff",
"html_title": "301 Moved Permanently"
},
"supports_http2": false
},
"observed_at": "2025-01-26T11:02:47.124991476Z",
"perspective_id": "PERSPECTIVE_UNKNOWN",
"port": 443,
"service_name": "HTTP",
"software": [
{
"uniform_resource_identifier": "cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*",
"part": "a",
"vendor": "nginx",
"product": "nginx",
"other": {
"family": "nginx"
},
"source": "OSI_APPLICATION_LAYER"
}
],
"source_ip": "199.45.155.98",
"tls": {
"version_selected": "TLSv1_3",
"cipher_selected": "TLS_CHACHA20_POLY1305_SHA256",
"certificates": {
"_encoding": {
"leaf_fp_sha_256": "DISPLAY_HEX",
"chain_fps_sha_256": "DISPLAY_HEX"
},
"leaf_fp_sha_256": "04bec9a82406accbd4ce78e485c69dcb661080aeca4aaf25f09b4315545bde85",
"chain_fps_sha_256": [
"93a07898d89b2cca166ba6f1f8a14138ce43828e491b831926bc8247d391cc72"
],
"leaf_data": {
"names": [
"ilanabegovic.com",
"www.ilanabegovic.com"
],
"subject_dn": "OU=Domain Control Validated, CN=www.ilanabegovic.com",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies\\, Inc., OU=http://certs.starfieldtech.com/repository/, CN=Starfield Secure Certificate Authority - G2",
"pubkey_bit_size": 4096,
"pubkey_algorithm": "RSA",
"tbs_fingerprint": "a8b6bbb842d74ce1b8afdd0dea8bc5cbf39d0f39f7b085c2c7b187c0a7132204",
"fingerprint": "04bec9a82406accbd4ce78e485c69dcb661080aeca4aaf25f09b4315545bde85",
"issuer": {
"common_name": [
"Starfield Secure Certificate Authority - G2"
],
"locality": [
"Scottsdale"
],
"organization": [
"Starfield Technologies, Inc."
],
"organizational_unit": [
"http://certs.starfieldtech.com/repository/"
],
"province": [
"Arizona"
],
"country": [
"US"
]
},
"subject": {
"common_name": [
"www.ilanabegovic.com"
],
"organizational_unit": [
"Domain Control Validated"
]
},
"public_key": {
"key_algorithm": "RSA",
"rsa": {
"_encoding": {
"modulus": "DISPLAY_BASE64",
"exponent": "DISPLAY_BASE64"
},
"modulus": "loFP2ueCZ68fWTbKBzqbXVxFGkQ+1qao7VWJQgEfA7ADd2Xy+TalzGLN3qcrnCnk3B7sfSDFMnA+/P4qAXEC893IPyLH2mydlXrBDHPT//X66v//lFJ6UOmRekd6Iv8qiqEH49pk34DdBjrsGLY4GEKoXeDCwcva44o0ANZbJNBXxYBgf2dzO3c5oEin/jyEh/gU7boo1xYf/dLmopm09kMlFcwQPgnzd7nyhOuGh19fHe/eMmgdQhp6osgXEoF/A+bWCqA3z6+ThZ4z4ci03g3X0uKi7fPRTbHarWydmKTE8s4Q8KaGK1Ff+38/K8wu2EP3e+bY4lwzbDqfg05+lFZKlSt3dDa7OgUR6lt0KwQWB1H3xbQ9C4d+EBxF/Pm/UhuOteA1w/0dHFXr7fsDLLSymsKzNCgqkfliAku496tXypDU+nkITkfoF1nfY5eAqMZpN6vOqMWWb0R3VIemRyFer4rII8phXjz+1h1oHLnHcKudHPNwqE7vQU/tua5EwU5fptJqhCYBDvpfu4TaflSK6KTGUODdz9W/PjeSMqhyvRATAbx1c1MxtLh3CcHevaPh3eJFQJWgOSqc29WwRLTdaW+E+C28eEqmpvwXciiR+YfebxVZsb0fN2XE/CJozT4TFw7UwSdrtXX/6AYCLq9KUrNDfmGPdUpTRpR6fKk=",
"exponent": "AAEAAQ==",
"length": 512
},
"fingerprint": "ac77780d0090c898b0c2f77b47fe6a05b1f2e608cc371b3ea3315ff902f3bddc"
},
"signature": {
"signature_algorithm": "SHA256-RSA",
"self_signed": false
}
},
"chain": [
{
"fingerprint": "93a07898d89b2cca166ba6f1f8a14138ce43828e491b831926bc8247d391cc72",
"subject_dn": "C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies\\, Inc., OU=http://certs.starfieldtech.com/repository/, CN=Starfield Secure Certificate Authority - G2",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies\\, Inc., CN=Starfield Root Certificate Authority - G2"
}
]
},
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "475c9302dc42b2751db9edcac3b74891",
"ja4s": "t130200_1303_a56c5b993250",
"versions": [
{
"tls_version": "TLSv1_3",
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "475c9302dc42b2751db9edcac3b74891",
"ja4s": "t130200_1303_a56c5b993250"
},
{
"tls_version": "TLSv1_2",
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "d25619cb77d3219fc9fc14cb6b35eacc",
"ja4s": "t120200_cca8_344b4dce5a52"
}
]
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "smtp",
"_encoding": {
"banner": "DISPLAY_UTF8",
"certificate": "DISPLAY_HEX",
"banner_hex": "DISPLAY_HEX"
},
"banner": "220 vwp12946.webpack.hosteurope.de ESMTP Host Europe Mail Service Sun, 26 Jan 2025 16:08:25 +0100\r\n",
"banner_hashes": [
"sha256:40e497466cf5b3e9e99e3623d9bc554770603baaa27fc1ca508082e76fdd9519"
],
"banner_hex": "3232302076777031323934362e7765627061636b2e686f73746575726f70652e64652045534d545020486f7374204575726f7065204d61696c20536572766963652053756e2c203236204a616e20323032352031363a30383a3235202b303130300d0a",
"certificate": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"discovery_method": "PREDICTIVE_METHOD_19",
"extended_service_name": "SMTPS",
"labels": [
"email"
],
"observed_at": "2025-01-26T15:08:25.572343748Z",
"perspective_id": "PERSPECTIVE_UNKNOWN",
"port": 465,
"service_name": "SMTP",
"smtp": {
"_encoding": {
"banner": "DISPLAY_UTF8",
"ehlo": "DISPLAY_UTF8"
},
"banner": "220 vwp12946.webpack.hosteurope.de ESMTP Host Europe Mail Service Sun, 26 Jan 2025 16:08:25 +0100\r\n",
"ehlo": "250-vwp12946.webpack.hosteurope.de Hello www.censys.io [167.94.138.183]\r\n250-SIZE 52428800\r\n250-8BITMIME\r\n250-PIPELINING\r\n250-PIPECONNECT\r\n250-AUTH PLAIN LOGIN\r\n250 HELP\r\n"
},
"source_ip": "167.94.138.183",
"tls": {
"version_selected": "TLSv1_3",
"cipher_selected": "TLS_CHACHA20_POLY1305_SHA256",
"certificates": {
"_encoding": {
"leaf_fp_sha_256": "DISPLAY_HEX",
"chain_fps_sha_256": "DISPLAY_HEX"
},
"leaf_fp_sha_256": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"chain_fps_sha_256": [
"973a41276ffd01e027a2aad49e34c37846d3e976ff6a620b6712e33832041aa6"
],
"leaf_data": {
"names": [
"*.ftp.server-he.ch",
"*.ftp.server-he.de",
"*.mail.server-he.ch",
"*.mail.server-he.de",
"*.mailout.server-he.ch",
"*.mailout.server-he.de",
"*.mywebdav.de",
"*.server-he.ch",
"*.server-he.de",
"*.storage.hosteurope.de",
"*.webpack.hosteurope.de",
"ftp.server-he.ch",
"ftp.server-he.de",
"mail.server-he.ch",
"mail.server-he.de",
"mailout.server-he.ch",
"mailout.server-he.de",
"mywebdav.de",
"server-he.ch",
"server-he.de",
"storage.hosteurope.de",
"webpack.hosteurope.de"
],
"subject_dn": "CN=*.webpack.hosteurope.de",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2",
"pubkey_bit_size": 2048,
"pubkey_algorithm": "RSA",
"tbs_fingerprint": "ed00f936e81acddb849611d08947d8dee072fdd207648bd0f39716e5b8022173",
"fingerprint": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"issuer": {
"common_name": [
"Go Daddy Secure Certificate Authority - G2"
],
"locality": [
"Scottsdale"
],
"organization": [
"GoDaddy.com, Inc."
],
"organizational_unit": [
"http://certs.godaddy.com/repository/"
],
"province": [
"Arizona"
],
"country": [
"US"
]
},
"subject": {
"common_name": [
"*.webpack.hosteurope.de"
]
},
"public_key": {
"key_algorithm": "RSA",
"rsa": {
"_encoding": {
"modulus": "DISPLAY_BASE64",
"exponent": "DISPLAY_BASE64"
},
"modulus": "wvC2VcxxtQrgbie9GHIErsPvnWnuluS0kGaPvR1tMTC3pV+1opgT9uGKQv7MCKsoB4Gr25J/CL8fDHu4myH5tOYvVFfHNZsHXAB+utxZX9Jfz5ILwaNWaJrbMHXiOnBtwMAdW1YonClBHOGy2hB7eYm0trgSz98tIgphZIqhr0XbewlYkFccHA+mRLFr4ZCABI33Oo3s5FYjRP+S6OZiYe3AXnQym/HCv0jO7+tz3Z5HmfSkhXkF0bPddHAgyRvTNu7hEKsPlpGo+wXKQdyVHBfgbrdADxS3BsRFpyRC84E1xcBEgQmWXRqjt+zwFCovrbWmBl5kUhldYp5YjJcaSw==",
"exponent": "AAEAAQ==",
"length": 256
},
"fingerprint": "943f1445820198e0eab45cbef93e18ab356a0a3776f88aad3e38de4da2f383fc"
},
"signature": {
"signature_algorithm": "SHA256-RSA",
"self_signed": false
}
},
"chain": [
{
"fingerprint": "973a41276ffd01e027a2aad49e34c37846d3e976ff6a620b6712e33832041aa6",
"subject_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., CN=Go Daddy Root Certificate Authority - G2"
}
]
},
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "d75f9129bb5d05492a65ff78e081bcb2",
"ja4s": "t130200_1303_234ea6891581",
"versions": [
{
"tls_version": "TLSv1_3",
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "d75f9129bb5d05492a65ff78e081bcb2",
"ja4s": "t130200_1303_234ea6891581"
},
{
"tls_version": "TLSv1_2",
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "3b1990d8d0d9e89b35d3f6c3abddba54",
"ja4s": "t120200_cca8_8fe157b277d7"
},
{
"tls_version": "TLSv1_1",
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "4887e172ec56727ac02b1b40d0cb3ae2",
"ja4s": "t110200_c013_8fe157b277d7"
},
{
"tls_version": "TLSv1_0",
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "171cb911c3fe3165cd0a1ab4da573fb4",
"ja4s": "t100200_c013_8fe157b277d7"
}
]
},
"transport_fingerprint": {
"raw": "43440,64,true,MSTNW,1460,false,false"
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "smtp",
"_encoding": {
"banner": "DISPLAY_UTF8",
"certificate": "DISPLAY_HEX",
"banner_hex": "DISPLAY_HEX"
},
"banner": "220 vwp12946.webpack.hosteurope.de ESMTP Host Europe Mail Service Sat, 25 Jan 2025 15:57:23 +0100\r\n",
"banner_hashes": [
"sha256:4b6ac2c9fd674e1188723cea73bf54feb1ce09427299f9ab29d19b530e18b6b1"
],
"banner_hex": "3232302076777031323934362e7765627061636b2e686f73746575726f70652e64652045534d545020486f7374204575726f7065204d61696c2053657276696365205361742c203235204a616e20323032352031353a35373a3233202b303130300d0a",
"certificate": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"extended_service_name": "SMTP-STARTTLS",
"labels": [
"email"
],
"observed_at": "2025-01-25T14:57:22.985741620Z",
"perspective_id": "PERSPECTIVE_UNKNOWN",
"port": 587,
"service_name": "SMTP",
"smtp": {
"_encoding": {
"banner": "DISPLAY_UTF8",
"ehlo": "DISPLAY_UTF8",
"start_tls": "DISPLAY_UTF8"
},
"banner": "220 vwp12946.webpack.hosteurope.de ESMTP Host Europe Mail Service Sat, 25 Jan 2025 15:57:23 +0100\r\n",
"ehlo": "250-vwp12946.webpack.hosteurope.de Hello www.censys.io [162.142.125.118]\r\n250-SIZE 52428800\r\n250-8BITMIME\r\n250-PIPELINING\r\n250-PIPECONNECT\r\n250-AUTH PLAIN LOGIN\r\n250-STARTTLS\r\n250 HELP\r\n",
"start_tls": "220 TLS go ahead\r\n"
},
"source_ip": "162.142.125.118",
"tls": {
"version_selected": "TLSv1_3",
"cipher_selected": "TLS_CHACHA20_POLY1305_SHA256",
"certificates": {
"_encoding": {
"leaf_fp_sha_256": "DISPLAY_HEX",
"chain_fps_sha_256": "DISPLAY_HEX"
},
"leaf_fp_sha_256": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"chain_fps_sha_256": [
"973a41276ffd01e027a2aad49e34c37846d3e976ff6a620b6712e33832041aa6"
],
"leaf_data": {
"names": [
"*.ftp.server-he.ch",
"*.ftp.server-he.de",
"*.mail.server-he.ch",
"*.mail.server-he.de",
"*.mailout.server-he.ch",
"*.mailout.server-he.de",
"*.mywebdav.de",
"*.server-he.ch",
"*.server-he.de",
"*.storage.hosteurope.de",
"*.webpack.hosteurope.de",
"ftp.server-he.ch",
"ftp.server-he.de",
"mail.server-he.ch",
"mail.server-he.de",
"mailout.server-he.ch",
"mailout.server-he.de",
"mywebdav.de",
"server-he.ch",
"server-he.de",
"storage.hosteurope.de",
"webpack.hosteurope.de"
],
"subject_dn": "CN=*.webpack.hosteurope.de",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2",
"pubkey_bit_size": 2048,
"pubkey_algorithm": "RSA",
"tbs_fingerprint": "ed00f936e81acddb849611d08947d8dee072fdd207648bd0f39716e5b8022173",
"fingerprint": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"issuer": {
"common_name": [
"Go Daddy Secure Certificate Authority - G2"
],
"locality": [
"Scottsdale"
],
"organization": [
"GoDaddy.com, Inc."
],
"organizational_unit": [
"http://certs.godaddy.com/repository/"
],
"province": [
"Arizona"
],
"country": [
"US"
]
},
"subject": {
"common_name": [
"*.webpack.hosteurope.de"
]
},
"public_key": {
"key_algorithm": "RSA",
"rsa": {
"_encoding": {
"modulus": "DISPLAY_BASE64",
"exponent": "DISPLAY_BASE64"
},
"modulus": "wvC2VcxxtQrgbie9GHIErsPvnWnuluS0kGaPvR1tMTC3pV+1opgT9uGKQv7MCKsoB4Gr25J/CL8fDHu4myH5tOYvVFfHNZsHXAB+utxZX9Jfz5ILwaNWaJrbMHXiOnBtwMAdW1YonClBHOGy2hB7eYm0trgSz98tIgphZIqhr0XbewlYkFccHA+mRLFr4ZCABI33Oo3s5FYjRP+S6OZiYe3AXnQym/HCv0jO7+tz3Z5HmfSkhXkF0bPddHAgyRvTNu7hEKsPlpGo+wXKQdyVHBfgbrdADxS3BsRFpyRC84E1xcBEgQmWXRqjt+zwFCovrbWmBl5kUhldYp5YjJcaSw==",
"exponent": "AAEAAQ==",
"length": 256
},
"fingerprint": "943f1445820198e0eab45cbef93e18ab356a0a3776f88aad3e38de4da2f383fc"
},
"signature": {
"signature_algorithm": "SHA256-RSA",
"self_signed": false
}
},
"chain": [
{
"fingerprint": "973a41276ffd01e027a2aad49e34c37846d3e976ff6a620b6712e33832041aa6",
"subject_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., CN=Go Daddy Root Certificate Authority - G2"
}
]
},
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "d75f9129bb5d05492a65ff78e081bcb2",
"ja4s": "t130200_1303_234ea6891581"
},
"transport_fingerprint": {
"raw": "43440,64,true,MSTNW,1460,false,false"
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "imap",
"_encoding": {
"banner": "DISPLAY_UTF8",
"certificate": "DISPLAY_HEX",
"banner_hex": "DISPLAY_HEX"
},
"banner": "* OK [CAPABILITY IMAP4rev1 SASL-IR LOGIN-REFERRALS ID ENABLE IDLE LITERAL+ AUTH=PLAIN] Dovecot (Debian) ready.\r\n",
"banner_hashes": [
"sha256:c6da3659113355d5304fa51a7cf8a22204b433dac37072359c696b6c8b3b9f30"
],
"banner_hex": "2a204f4b205b4341504142494c49545920494d41503472657631205341534c2d4952204c4f47494e2d524546455252414c5320494420454e41424c452049444c45204c49544552414c2b20415554483d504c41494e5d20446f7665636f74202844656269616e292072656164792e0d0a",
"certificate": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"extended_service_name": "IMAPS",
"imap": {
"_encoding": {
"banner": "DISPLAY_UTF8"
},
"banner": "* OK [CAPABILITY IMAP4rev1 SASL-IR LOGIN-REFERRALS ID ENABLE IDLE LITERAL+ AUTH=PLAIN] Dovecot (Debian) ready.\r\n"
},
"jarm": {
"_encoding": {
"fingerprint": "DISPLAY_HEX",
"cipher_and_version_fingerprint": "DISPLAY_HEX",
"tls_extensions_sha256": "DISPLAY_HEX"
},
"fingerprint": "29d29d15d29d29d21c42d42d000000dc2b105e4dda975fa70719c0cae5d0ce",
"cipher_and_version_fingerprint": "29d29d15d29d29d21c42d42d000000",
"tls_extensions_sha256": "dc2b105e4dda975fa70719c0cae5d0ce",
"observed_at": "2025-01-15T06:57:25.970547061Z"
},
"labels": [
"email"
],
"observed_at": "2025-01-26T06:10:01.474158897Z",
"perspective_id": "PERSPECTIVE_UNKNOWN",
"port": 993,
"service_name": "IMAP",
"software": [
{
"uniform_resource_identifier": "cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*",
"part": "a",
"vendor": "Dovecot",
"product": "Dovecot",
"other": {
"family": "Dovecot"
},
"source": "OSI_APPLICATION_LAYER"
},
{
"uniform_resource_identifier": "cpe:2.3:o:debian:debian_linux:*:*:*:*:*:*:*:*",
"part": "o",
"vendor": "Debian",
"product": "Linux",
"other": {
"family": "Linux"
},
"source": "OSI_APPLICATION_LAYER"
}
],
"source_ip": "167.94.146.63",
"tls": {
"version_selected": "TLSv1_3",
"cipher_selected": "TLS_AES_256_GCM_SHA384",
"certificates": {
"_encoding": {
"leaf_fp_sha_256": "DISPLAY_HEX",
"chain_fps_sha_256": "DISPLAY_HEX"
},
"leaf_fp_sha_256": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"chain_fps_sha_256": [
"973a41276ffd01e027a2aad49e34c37846d3e976ff6a620b6712e33832041aa6"
],
"leaf_data": {
"names": [
"*.ftp.server-he.ch",
"*.ftp.server-he.de",
"*.mail.server-he.ch",
"*.mail.server-he.de",
"*.mailout.server-he.ch",
"*.mailout.server-he.de",
"*.mywebdav.de",
"*.server-he.ch",
"*.server-he.de",
"*.storage.hosteurope.de",
"*.webpack.hosteurope.de",
"ftp.server-he.ch",
"ftp.server-he.de",
"mail.server-he.ch",
"mail.server-he.de",
"mailout.server-he.ch",
"mailout.server-he.de",
"mywebdav.de",
"server-he.ch",
"server-he.de",
"storage.hosteurope.de",
"webpack.hosteurope.de"
],
"subject_dn": "CN=*.webpack.hosteurope.de",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2",
"pubkey_bit_size": 2048,
"pubkey_algorithm": "RSA",
"tbs_fingerprint": "ed00f936e81acddb849611d08947d8dee072fdd207648bd0f39716e5b8022173",
"fingerprint": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"issuer": {
"common_name": [
"Go Daddy Secure Certificate Authority - G2"
],
"locality": [
"Scottsdale"
],
"organization": [
"GoDaddy.com, Inc."
],
"organizational_unit": [
"http://certs.godaddy.com/repository/"
],
"province": [
"Arizona"
],
"country": [
"US"
]
},
"subject": {
"common_name": [
"*.webpack.hosteurope.de"
]
},
"public_key": {
"key_algorithm": "RSA",
"rsa": {
"_encoding": {
"modulus": "DISPLAY_BASE64",
"exponent": "DISPLAY_BASE64"
},
"modulus": "wvC2VcxxtQrgbie9GHIErsPvnWnuluS0kGaPvR1tMTC3pV+1opgT9uGKQv7MCKsoB4Gr25J/CL8fDHu4myH5tOYvVFfHNZsHXAB+utxZX9Jfz5ILwaNWaJrbMHXiOnBtwMAdW1YonClBHOGy2hB7eYm0trgSz98tIgphZIqhr0XbewlYkFccHA+mRLFr4ZCABI33Oo3s5FYjRP+S6OZiYe3AXnQym/HCv0jO7+tz3Z5HmfSkhXkF0bPddHAgyRvTNu7hEKsPlpGo+wXKQdyVHBfgbrdADxS3BsRFpyRC84E1xcBEgQmWXRqjt+zwFCovrbWmBl5kUhldYp5YjJcaSw==",
"exponent": "AAEAAQ==",
"length": 256
},
"fingerprint": "943f1445820198e0eab45cbef93e18ab356a0a3776f88aad3e38de4da2f383fc"
},
"signature": {
"signature_algorithm": "SHA256-RSA",
"self_signed": false
}
},
"chain": [
{
"fingerprint": "973a41276ffd01e027a2aad49e34c37846d3e976ff6a620b6712e33832041aa6",
"subject_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., CN=Go Daddy Root Certificate Authority - G2"
}
]
},
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "15af977ce25de452b96affa2addb1036",
"ja4s": "t130200_1302_a56c5b993250",
"versions": [
{
"tls_version": "TLSv1_3",
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "15af977ce25de452b96affa2addb1036",
"ja4s": "t130200_1302_a56c5b993250"
},
{
"tls_version": "TLSv1_2",
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "303951d4c50efb2e991652225a6f02b1",
"ja4s": "t120200_c02f_344b4dce5a52"
},
{
"tls_version": "TLSv1_1",
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "b8d8f22562475aebf44ad54175c1d9c7",
"ja4s": "t110200_c013_344b4dce5a52"
},
{
"tls_version": "TLSv1_0",
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "184d532a16876b78846ae6a03f654890",
"ja4s": "t100200_c013_344b4dce5a52"
}
]
},
"transport_fingerprint": {
"raw": "43440,64,true,MSTNW,1460,false,false"
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "pop3",
"_encoding": {
"banner": "DISPLAY_UTF8",
"certificate": "DISPLAY_HEX",
"banner_hex": "DISPLAY_HEX"
},
"banner": "+OK Dovecot (Debian) ready.\r\n",
"banner_hashes": [
"sha256:d23f942eab9de1c939a3dcab0aefadf6c86ebc2b99ba56b2b364c14c7c2b8dad"
],
"banner_hex": "2b4f4b20446f7665636f74202844656269616e292072656164792e0d0a",
"certificate": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"discovery_method": "PREDICTIVE_METHOD_7",
"extended_service_name": "POP3S",
"jarm": {
"_encoding": {
"fingerprint": "DISPLAY_HEX",
"cipher_and_version_fingerprint": "DISPLAY_HEX",
"tls_extensions_sha256": "DISPLAY_HEX"
},
"fingerprint": "29d29d15d29d29d21c42d42d000000dc2b105e4dda975fa70719c0cae5d0ce",
"cipher_and_version_fingerprint": "29d29d15d29d29d21c42d42d000000",
"tls_extensions_sha256": "dc2b105e4dda975fa70719c0cae5d0ce",
"observed_at": "2025-01-25T00:02:55.883892139Z"
},
"labels": [
"email"
],
"observed_at": "2025-01-26T00:19:30.376254554Z",
"perspective_id": "PERSPECTIVE_UNKNOWN",
"pop3": {
"_encoding": {
"banner": "DISPLAY_UTF8"
},
"banner": "+OK Dovecot (Debian) ready.\r\n"
},
"port": 995,
"service_name": "POP3",
"software": [
{
"uniform_resource_identifier": "cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*",
"part": "a",
"vendor": "Dovecot",
"product": "Dovecot",
"other": {
"family": "Dovecot"
},
"source": "OSI_APPLICATION_LAYER"
},
{
"uniform_resource_identifier": "cpe:2.3:o:debian:debian_linux:*:*:*:*:*:*:*:*",
"part": "o",
"vendor": "Debian",
"product": "Linux",
"other": {
"family": "Linux"
},
"source": "OSI_APPLICATION_LAYER"
}
],
"source_ip": "206.168.34.41",
"tls": {
"version_selected": "TLSv1_3",
"cipher_selected": "TLS_AES_256_GCM_SHA384",
"certificates": {
"_encoding": {
"leaf_fp_sha_256": "DISPLAY_HEX",
"chain_fps_sha_256": "DISPLAY_HEX"
},
"leaf_fp_sha_256": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"chain_fps_sha_256": [
"973a41276ffd01e027a2aad49e34c37846d3e976ff6a620b6712e33832041aa6"
],
"leaf_data": {
"names": [
"*.ftp.server-he.ch",
"*.ftp.server-he.de",
"*.mail.server-he.ch",
"*.mail.server-he.de",
"*.mailout.server-he.ch",
"*.mailout.server-he.de",
"*.mywebdav.de",
"*.server-he.ch",
"*.server-he.de",
"*.storage.hosteurope.de",
"*.webpack.hosteurope.de",
"ftp.server-he.ch",
"ftp.server-he.de",
"mail.server-he.ch",
"mail.server-he.de",
"mailout.server-he.ch",
"mailout.server-he.de",
"mywebdav.de",
"server-he.ch",
"server-he.de",
"storage.hosteurope.de",
"webpack.hosteurope.de"
],
"subject_dn": "CN=*.webpack.hosteurope.de",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2",
"pubkey_bit_size": 2048,
"pubkey_algorithm": "RSA",
"tbs_fingerprint": "ed00f936e81acddb849611d08947d8dee072fdd207648bd0f39716e5b8022173",
"fingerprint": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"issuer": {
"common_name": [
"Go Daddy Secure Certificate Authority - G2"
],
"locality": [
"Scottsdale"
],
"organization": [
"GoDaddy.com, Inc."
],
"organizational_unit": [
"http://certs.godaddy.com/repository/"
],
"province": [
"Arizona"
],
"country": [
"US"
]
},
"subject": {
"common_name": [
"*.webpack.hosteurope.de"
]
},
"public_key": {
"key_algorithm": "RSA",
"rsa": {
"_encoding": {
"modulus": "DISPLAY_BASE64",
"exponent": "DISPLAY_BASE64"
},
"modulus": "wvC2VcxxtQrgbie9GHIErsPvnWnuluS0kGaPvR1tMTC3pV+1opgT9uGKQv7MCKsoB4Gr25J/CL8fDHu4myH5tOYvVFfHNZsHXAB+utxZX9Jfz5ILwaNWaJrbMHXiOnBtwMAdW1YonClBHOGy2hB7eYm0trgSz98tIgphZIqhr0XbewlYkFccHA+mRLFr4ZCABI33Oo3s5FYjRP+S6OZiYe3AXnQym/HCv0jO7+tz3Z5HmfSkhXkF0bPddHAgyRvTNu7hEKsPlpGo+wXKQdyVHBfgbrdADxS3BsRFpyRC84E1xcBEgQmWXRqjt+zwFCovrbWmBl5kUhldYp5YjJcaSw==",
"exponent": "AAEAAQ==",
"length": 256
},
"fingerprint": "943f1445820198e0eab45cbef93e18ab356a0a3776f88aad3e38de4da2f383fc"
},
"signature": {
"signature_algorithm": "SHA256-RSA",
"self_signed": false
}
},
"chain": [
{
"fingerprint": "973a41276ffd01e027a2aad49e34c37846d3e976ff6a620b6712e33832041aa6",
"subject_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., CN=Go Daddy Root Certificate Authority - G2"
}
]
},
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "15af977ce25de452b96affa2addb1036",
"ja4s": "t130200_1302_a56c5b993250"
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "mysql",
"extended_service_name": "MYSQL",
"labels": [
"database"
],
"mysql": {
"error_code": 1130,
"error_id": "ER_HOST_NOT_PRIVILEGED",
"error_message": "Host '206.168.34.43' is not allowed to connect to this MySQL server",
"protocol_version": 0,
"connection_id": 0,
"character_set": 0
},
"observed_at": "2025-01-26T06:46:18.575480949Z",
"perspective_id": "PERSPECTIVE_UNKNOWN",
"port": 3306,
"service_name": "MYSQL",
"software": [
{
"uniform_resource_identifier": "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
"part": "a",
"vendor": "Oracle",
"product": "MySQL",
"other": {
"family": "MySQL"
},
"source": "OSI_APPLICATION_LAYER"
},
{
"uniform_resource_identifier": "cpe:2.3:o:*:linux:*:*:*:*:*:*:*:*",
"part": "o",
"product": "linux",
"source": "OSI_TRANSPORT_LAYER"
}
],
"source_ip": "206.168.34.43",
"transport_fingerprint": {
"id": 72,
"os": "Ubuntu / Debian / CentOS",
"raw": "28960,64,true,MSTNW,1460,false,false"
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "banner_grab",
"_encoding": {
"banner": "DISPLAY_UTF8",
"banner_hex": "DISPLAY_HEX"
},
"banner": "\u0005\u0000\u0000\u0000\u000b\b\u0005\u001a\u0000",
"banner_hashes": [
"sha256:5cf471b74061d818ff16b1d9301293c7d258d35f081298d4b88bad50b15aaf3f"
],
"banner_hex": "050000000b08051a00",
"discovery_method": "PREDICTIVE_METHOD_20",
"extended_service_name": "UNKNOWN",
"observed_at": "2025-01-26T09:40:20.246999853Z",
"perspective_id": "PERSPECTIVE_UNKNOWN",
"port": 33060,
"service_name": "UNKNOWN",
"source_ip": "199.45.154.154",
"transport_fingerprint": {
"raw": "43440,64,true,MSTNW,1460,false,false"
},
"transport_protocol": "TCP",
"truncated": false
}
],
"location": {
"continent": "Europe",
"country": "Germany",
"country_code": "DE",
"city": "Kehl",
"postal_code": "77694",
"timezone": "Europe/Berlin",
"province": "Baden-Wurttemberg",
"coordinates": {
"latitude": 48.57297,
"longitude": 7.81523
}
},
"location_updated_at": "2025-01-15T02:09:47.158593833Z",
"autonomous_system": {
"asn": 20773,
"description": "GODADDY",
"bgp_prefix": "5.35.224.0/19",
"name": "GODADDY",
"country_code": "DE"
},
"autonomous_system_updated_at": "2025-01-15T02:09:47.158748152Z",
"whois": {
"network": {
"handle": "DE-HE-SH-DSM-FAL1-NET",
"name": "Host Europe GmbH",
"cidrs": [
"5.35.232.0/22"
],
"created": "2013-09-16T00:00:00Z",
"updated": "2015-11-17T00:00:00Z"
},
"organization": {
"handle": "ORG-OG1-RIPE",
"name": "Host Europe GmbH",
"address": "c/o WeWork Wallarkaden\\n50674\\nK\u00f6ln\\nGERMANY",
"abuse_contacts": [
{
"handle": "HEAH",
"name": "Host Europe Abuse Handling",
"email": "[email protected]"
}
],
"admin_contacts": [
{
"handle": "GDDY",
"name": "GoDaddy LIR",
"email": "[email protected]"
}
]
}
},
"operating_system": {
"uniform_resource_identifier": "cpe:2.3:o:debian:debian_linux:*:*:*:*:*:*:*:*",
"part": "o",
"vendor": "Debian",
"product": "Linux",
"other": {
"family": "Linux"
}
},
"dns": {
"names": [
"www.healing-wisdom.de",
"www.shop.healing-wisdom.de",
"ilanabegovic.com",
"www.ilanabegovic.com",
"vwp12946.webpack.hosteurope.de",
"healing-wisdom.de"
],
"records": {
"ilanabegovic.com": {
"record_type": "A",
"resolved_at": "2025-01-20T18:12:00.172679132Z"
},
"www.shop.healing-wisdom.de": {
"record_type": "A",
"resolved_at": "2025-01-22T20:48:57.888370009Z"
},
"www.ilanabegovic.com": {
"record_type": "A",
"resolved_at": "2025-01-18T17:04:37.136842875Z"
},
"healing-wisdom.de": {
"record_type": "A",
"resolved_at": "2025-01-13T20:20:13.821542672Z"
},
"www.healing-wisdom.de": {
"record_type": "A",
"resolved_at": "2025-01-04T21:39:44.555501312Z"
},
"vwp12946.webpack.hosteurope.de": {
"record_type": "A",
"resolved_at": "2025-01-10T19:37:44.713532583Z"
}
},
"reverse_dns": {
"names": [
"vwp12946.webpack.hosteurope.de"
],
"resolved_at": "2025-01-26T04:48:34.261573679Z"
}
},
"last_updated_at": "2025-01-26T15:08:32.536Z",
"labels": [
"database",
"email",
"file-sharing",
"remote-access"
]
}