5.35.235.35
As of: Sep 16, 2024 2:23am UTC |
Latest
{
"ip": "5.35.235.35",
"services": [
{
"_decoded": "ftp",
"_encoding": {
"banner": "DISPLAY_UTF8",
"certificate": "DISPLAY_HEX",
"banner_hex": "DISPLAY_HEX"
},
"banner": "220 ::ffff:5.35.235.35 FTP server ready\r\n",
"banner_hashes": [
"sha256:a26fbe4b5583b50f8a35e262b7685fdda292cf10ca96d9e4feae87becf9f5981"
],
"banner_hex": "323230203a3a666666663a352e33352e3233352e333520465450207365727665722072656164790d0a",
"certificate": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"extended_service_name": "FTPes",
"ftp": {
"_encoding": {
"banner": "DISPLAY_UTF8",
"auth_tls_response": "DISPLAY_UTF8"
},
"banner": "220 ::ffff:5.35.235.35 FTP server ready\r\n",
"auth_tls_response": "234 AUTH TLS successful\r\n",
"status_code": 220,
"status_meaning": "Service ready for new user.",
"implicit_tls": false
},
"labels": [
"file-sharing"
],
"observed_at": "2024-09-14T17:30:02.972556870Z",
"perspective_id": "PERSPECTIVE_NTT",
"port": 21,
"service_name": "FTP",
"source_ip": "206.168.34.39",
"tls": {
"version_selected": "TLSv1_3",
"cipher_selected": "TLS_CHACHA20_POLY1305_SHA256",
"certificates": {
"_encoding": {
"leaf_fp_sha_256": "DISPLAY_HEX",
"chain_fps_sha_256": "DISPLAY_HEX"
},
"leaf_fp_sha_256": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"chain_fps_sha_256": [
"973a41276ffd01e027a2aad49e34c37846d3e976ff6a620b6712e33832041aa6"
],
"leaf_data": {
"names": [
"*.ftp.server-he.ch",
"*.ftp.server-he.de",
"*.mail.server-he.ch",
"*.mail.server-he.de",
"*.mailout.server-he.ch",
"*.mailout.server-he.de",
"*.mywebdav.de",
"*.server-he.ch",
"*.server-he.de",
"*.storage.hosteurope.de",
"*.webpack.hosteurope.de",
"ftp.server-he.ch",
"ftp.server-he.de",
"mail.server-he.ch",
"mail.server-he.de",
"mailout.server-he.ch",
"mailout.server-he.de",
"mywebdav.de",
"server-he.ch",
"server-he.de",
"storage.hosteurope.de",
"webpack.hosteurope.de"
],
"subject_dn": "CN=*.webpack.hosteurope.de",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2",
"pubkey_bit_size": 2048,
"pubkey_algorithm": "RSA",
"tbs_fingerprint": "ed00f936e81acddb849611d08947d8dee072fdd207648bd0f39716e5b8022173",
"fingerprint": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"issuer": {
"common_name": [
"Go Daddy Secure Certificate Authority - G2"
],
"locality": [
"Scottsdale"
],
"organization": [
"GoDaddy.com, Inc."
],
"organizational_unit": [
"http://certs.godaddy.com/repository/"
],
"province": [
"Arizona"
],
"country": [
"US"
]
},
"subject": {
"common_name": [
"*.webpack.hosteurope.de"
]
},
"public_key": {
"key_algorithm": "RSA",
"rsa": {
"_encoding": {
"modulus": "DISPLAY_BASE64",
"exponent": "DISPLAY_BASE64"
},
"modulus": "wvC2VcxxtQrgbie9GHIErsPvnWnuluS0kGaPvR1tMTC3pV+1opgT9uGKQv7MCKsoB4Gr25J/CL8fDHu4myH5tOYvVFfHNZsHXAB+utxZX9Jfz5ILwaNWaJrbMHXiOnBtwMAdW1YonClBHOGy2hB7eYm0trgSz98tIgphZIqhr0XbewlYkFccHA+mRLFr4ZCABI33Oo3s5FYjRP+S6OZiYe3AXnQym/HCv0jO7+tz3Z5HmfSkhXkF0bPddHAgyRvTNu7hEKsPlpGo+wXKQdyVHBfgbrdADxS3BsRFpyRC84E1xcBEgQmWXRqjt+zwFCovrbWmBl5kUhldYp5YjJcaSw==",
"exponent": "AAEAAQ==",
"length": 256
},
"fingerprint": "943f1445820198e0eab45cbef93e18ab356a0a3776f88aad3e38de4da2f383fc"
},
"signature": {
"signature_algorithm": "SHA256-RSA",
"self_signed": false
}
},
"chain": [
{
"fingerprint": "973a41276ffd01e027a2aad49e34c37846d3e976ff6a620b6712e33832041aa6",
"subject_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., CN=Go Daddy Root Certificate Authority - G2"
}
]
},
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "475c9302dc42b2751db9edcac3b74891",
"ja4s": "t130200_1303_a56c5b993250"
},
"transport_fingerprint": {
"raw": "43440,64,true,MSTNW,1460,false,false"
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "ssh",
"_encoding": {
"banner": "DISPLAY_UTF8",
"banner_hex": "DISPLAY_HEX"
},
"banner": "SSH-2.0-OpenSSH_7.9p1 Debian-10+deb10u4",
"banner_hashes": [
"sha256:e169f45801a20f7e68ce6566ba0226a3aeeb38565494180fad93f4f45553651a"
],
"banner_hex": "5353482d322e302d4f70656e5353485f372e3970312044656269616e2d31302b64656231307534",
"extended_service_name": "SSH",
"labels": [
"remote-access"
],
"observed_at": "2024-09-15T18:08:09.671215085Z",
"perspective_id": "PERSPECTIVE_HE",
"port": 22,
"service_name": "SSH",
"software": [
{
"product": "openssh",
"other": {
"comment": "Debian-10+deb10u4"
},
"source": "OSI_APPLICATION_LAYER"
},
{
"uniform_resource_identifier": "cpe:2.3:o:*:linux:*:*:*:*:*:*:*:*",
"part": "o",
"product": "linux",
"source": "OSI_TRANSPORT_LAYER"
},
{
"uniform_resource_identifier": "cpe:2.3:a:openbsd:openssh:7.9:p1:*:*:*:*:*:*",
"part": "a",
"vendor": "OpenBSD",
"product": "OpenSSH",
"version": "7.9",
"update": "p1",
"other": {
"family": "OpenSSH"
},
"source": "OSI_APPLICATION_LAYER"
},
{
"uniform_resource_identifier": "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
"part": "o",
"vendor": "Debian",
"product": "Linux",
"version": "10.0",
"other": {
"family": "Linux"
},
"source": "OSI_APPLICATION_LAYER"
}
],
"source_ip": "162.142.125.198",
"ssh": {
"endpoint_id": {
"_encoding": {
"raw": "DISPLAY_UTF8"
},
"raw": "SSH-2.0-OpenSSH_7.9p1 Debian-10+deb10u4",
"protocol_version": "2.0",
"software_version": "OpenSSH_7.9p1",
"comment": "Debian-10+deb10u4"
},
"kex_init_message": {
"kex_algorithms": [
"curve25519-sha256",
"[email protected]",
"ecdh-sha2-nistp256",
"ecdh-sha2-nistp384",
"ecdh-sha2-nistp521",
"diffie-hellman-group-exchange-sha256",
"diffie-hellman-group16-sha512",
"diffie-hellman-group18-sha512",
"diffie-hellman-group14-sha256",
"diffie-hellman-group14-sha1",
"[email protected]"
],
"host_key_algorithms": [
"rsa-sha2-512",
"rsa-sha2-256",
"ssh-rsa"
],
"client_to_server_ciphers": [
"aes128-ctr",
"aes256-ctr",
"aes128-cbc",
"aes256-cbc"
],
"server_to_client_ciphers": [
"aes128-ctr",
"aes256-ctr",
"aes128-cbc",
"aes256-cbc"
],
"client_to_server_macs": [
"[email protected]",
"[email protected]",
"[email protected]",
"[email protected]",
"[email protected]",
"[email protected]",
"[email protected]",
"hmac-sha2-256",
"hmac-sha2-512",
"hmac-sha1"
],
"server_to_client_macs": [
"[email protected]",
"[email protected]",
"[email protected]",
"[email protected]",
"[email protected]",
"[email protected]",
"[email protected]",
"hmac-sha2-256",
"hmac-sha2-512",
"hmac-sha1"
],
"client_to_server_compression": [
"none",
"[email protected]"
],
"server_to_client_compression": [
"none",
"[email protected]"
],
"first_kex_follows": false
},
"algorithm_selection": {
"kex_algorithm": "[email protected]",
"host_key_algorithm": "ssh-rsa",
"client_to_server_alg_group": {
"cipher": "aes128-ctr",
"mac": "hmac-sha2-256",
"compression": "none"
},
"server_to_client_alg_group": {
"cipher": "aes128-ctr",
"mac": "hmac-sha2-256",
"compression": "none"
}
},
"server_host_key": {
"fingerprint_sha256": "81070065f944274901768e8c3ded9563ec1bc4c011f85c9430fb90abba36ccf0",
"rsa_public_key": {
"_encoding": {
"modulus": "DISPLAY_BASE64",
"exponent": "DISPLAY_BASE64"
},
"modulus": "7arFp0YoXcPQR+N15081TtOqhbwj/7tL7XLJmwTxrzkYhdIik5F+NXrG+VlUWR4ZxXSwoEvuSqd0pgoVNJStxuT6A4N+TjqPH+fWaN338yODSfscYbehy+xpsc2scLhJzoLsZ33HlY0yX21agpOBCCaDHnJ2jHkfMb2siWELhjso77YSVvoGEHpNIkUxrY6fxz8eeIGfr21mZ5SJn7KV1SR3yw2xELMUoS1DpoeQNulHj4IyPu4raBkPcZDeXtZTmRTc+vDeMgLEurnTlfd/XJm/dDEqyjcp4MpkhBudH/Ae1HlpYfl+yXJCOwzIJhBTqRV/6RG63/HFVy7wCQpEaPOG7hAARrAOOK4UZBqmi3NFBsrf2NJ7IqhI0fssyDocKGRWyNZ809qyc3iGdONEjW+Fp++MjeggYf4UHgiUxCmXUMU1zeAAa/W/ueEPPMyoCNKOCHFA92FHFunI8nK0XbALMvu/QSW+91PjfhmFu/9N1lVoKWhRTwG1GWYcs3a9WhxhyXKa5k9FshconU/p2Nyq27Mv/7PmXM0TzQX2H/4reHy6FzUM/5LJVObjrRnUrE/ftfI11LNWqZJ1WNx34cy3O0CefJVYHDknFlIDu9wHtX1pO0y9yXVVIYieRQguh5JamIpw5MEhUK0hx4NCATmnLxy8ra9FMvg2yqYURlM=",
"exponent": "AAAAIw==",
"length": 4096
}
},
"hassh_fingerprint": "8108b68579b6fd4151299d5cca075c63"
},
"transport_fingerprint": {
"id": 72,
"os": "Ubuntu / Debian / CentOS",
"raw": "28960,64,true,MSTNW,1460,false,false"
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "smtp",
"_encoding": {
"banner": "DISPLAY_UTF8",
"certificate": "DISPLAY_HEX",
"banner_hex": "DISPLAY_HEX"
},
"banner": "220 vwp12946.webpack.hosteurope.de ESMTP Host Europe Mail Service Mon, 16 Sep 2024 04:23:25 +0200\r\n",
"banner_hashes": [
"sha256:ab904584bd12d3f5a90f66f0698d53350e2987ba78d8c78b2dddba6738e5ae4b"
],
"banner_hex": "3232302076777031323934362e7765627061636b2e686f73746575726f70652e64652045534d545020486f7374204575726f7065204d61696c2053657276696365204d6f6e2c2031362053657020323032342030343a32333a3235202b303230300d0a",
"certificate": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"extended_service_name": "SMTP-STARTTLS",
"labels": [
"email"
],
"observed_at": "2024-09-16T02:23:25.336372709Z",
"perspective_id": "PERSPECTIVE_ORANGE",
"port": 25,
"service_name": "SMTP",
"smtp": {
"_encoding": {
"banner": "DISPLAY_UTF8",
"ehlo": "DISPLAY_UTF8",
"start_tls": "DISPLAY_UTF8"
},
"banner": "220 vwp12946.webpack.hosteurope.de ESMTP Host Europe Mail Service Mon, 16 Sep 2024 04:23:25 +0200\r\n",
"ehlo": "250-vwp12946.webpack.hosteurope.de Hello www.censys.io [167.94.145.98]\r\n250-SIZE 52428800\r\n250-8BITMIME\r\n250-PIPELINING\r\n250-AUTH PLAIN LOGIN\r\n250-STARTTLS\r\n250 HELP\r\n",
"start_tls": "220 TLS go ahead\r\n"
},
"source_ip": "167.94.145.98",
"tls": {
"version_selected": "TLSv1_3",
"cipher_selected": "TLS_CHACHA20_POLY1305_SHA256",
"certificates": {
"_encoding": {
"leaf_fp_sha_256": "DISPLAY_HEX",
"chain_fps_sha_256": "DISPLAY_HEX"
},
"leaf_fp_sha_256": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"chain_fps_sha_256": [
"973a41276ffd01e027a2aad49e34c37846d3e976ff6a620b6712e33832041aa6"
],
"leaf_data": {
"names": [
"*.ftp.server-he.ch",
"*.ftp.server-he.de",
"*.mail.server-he.ch",
"*.mail.server-he.de",
"*.mailout.server-he.ch",
"*.mailout.server-he.de",
"*.mywebdav.de",
"*.server-he.ch",
"*.server-he.de",
"*.storage.hosteurope.de",
"*.webpack.hosteurope.de",
"ftp.server-he.ch",
"ftp.server-he.de",
"mail.server-he.ch",
"mail.server-he.de",
"mailout.server-he.ch",
"mailout.server-he.de",
"mywebdav.de",
"server-he.ch",
"server-he.de",
"storage.hosteurope.de",
"webpack.hosteurope.de"
],
"subject_dn": "CN=*.webpack.hosteurope.de",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2",
"pubkey_bit_size": 2048,
"pubkey_algorithm": "RSA",
"tbs_fingerprint": "ed00f936e81acddb849611d08947d8dee072fdd207648bd0f39716e5b8022173",
"fingerprint": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"issuer": {
"common_name": [
"Go Daddy Secure Certificate Authority - G2"
],
"locality": [
"Scottsdale"
],
"organization": [
"GoDaddy.com, Inc."
],
"organizational_unit": [
"http://certs.godaddy.com/repository/"
],
"province": [
"Arizona"
],
"country": [
"US"
]
},
"subject": {
"common_name": [
"*.webpack.hosteurope.de"
]
},
"public_key": {
"key_algorithm": "RSA",
"rsa": {
"_encoding": {
"modulus": "DISPLAY_BASE64",
"exponent": "DISPLAY_BASE64"
},
"modulus": "wvC2VcxxtQrgbie9GHIErsPvnWnuluS0kGaPvR1tMTC3pV+1opgT9uGKQv7MCKsoB4Gr25J/CL8fDHu4myH5tOYvVFfHNZsHXAB+utxZX9Jfz5ILwaNWaJrbMHXiOnBtwMAdW1YonClBHOGy2hB7eYm0trgSz98tIgphZIqhr0XbewlYkFccHA+mRLFr4ZCABI33Oo3s5FYjRP+S6OZiYe3AXnQym/HCv0jO7+tz3Z5HmfSkhXkF0bPddHAgyRvTNu7hEKsPlpGo+wXKQdyVHBfgbrdADxS3BsRFpyRC84E1xcBEgQmWXRqjt+zwFCovrbWmBl5kUhldYp5YjJcaSw==",
"exponent": "AAEAAQ==",
"length": 256
},
"fingerprint": "943f1445820198e0eab45cbef93e18ab356a0a3776f88aad3e38de4da2f383fc"
},
"signature": {
"signature_algorithm": "SHA256-RSA",
"self_signed": false
}
},
"chain": [
{
"fingerprint": "973a41276ffd01e027a2aad49e34c37846d3e976ff6a620b6712e33832041aa6",
"subject_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., CN=Go Daddy Root Certificate Authority - G2"
}
]
},
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "d75f9129bb5d05492a65ff78e081bcb2",
"ja4s": "t130200_1303_234ea6891581"
},
"transport_fingerprint": {
"raw": "43440,64,true,MSTNW,1460,false,false"
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "http",
"_encoding": {
"banner": "DISPLAY_UTF8",
"banner_hex": "DISPLAY_HEX"
},
"banner": "HTTP/1.1 403 Forbidden\r\nServer: nginx\r\nDate: <REDACTED>\r\nContent-Type: text/html\r\nContent-Length: 2867\r\nConnection: keep-alive\r\nETag: \"6391baca-b33\"\r\n",
"banner_hashes": [
"sha256:4030f4a9bbb6a32b34dfbb0567f3e92df5c3903af2eb57e1ca4efc7a80fe4d88"
],
"banner_hex": "485454502f312e312034303320466f7262696464656e0d0a5365727665723a206e67696e780d0a446174653a20203c52454441435445443e0d0a436f6e74656e742d547970653a20746578742f68746d6c0d0a436f6e74656e742d4c656e6774683a20323836370d0a436f6e6e656374696f6e3a206b6565702d616c6976650d0a455461673a202236333931626163612d623333220d0a",
"extended_service_name": "HTTP",
"http": {
"request": {
"method": "GET",
"uri": "http://5.35.235.35/",
"headers": {
"User_Agent": [
"Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)"
],
"_encoding": {
"User_Agent": "DISPLAY_UTF8",
"Accept": "DISPLAY_UTF8"
},
"Accept": [
"*/*"
]
}
},
"response": {
"protocol": "HTTP/1.1",
"status_code": 403,
"status_reason": "Forbidden",
"headers": {
"Date": [
"<REDACTED>"
],
"_encoding": {
"Date": "DISPLAY_UTF8",
"Server": "DISPLAY_UTF8",
"Content_Length": "DISPLAY_UTF8",
"Content_Type": "DISPLAY_UTF8",
"ETag": "DISPLAY_UTF8",
"Connection": "DISPLAY_UTF8"
},
"Server": [
"nginx"
],
"Content_Length": [
"2867"
],
"Content_Type": [
"text/html"
],
"ETag": [
"\"6391baca-b33\""
],
"Connection": [
"keep-alive"
]
},
"_encoding": {
"html_tags": "DISPLAY_UTF8",
"body": "DISPLAY_UTF8",
"body_hash": "DISPLAY_UTF8",
"html_title": "DISPLAY_UTF8"
},
"html_tags": [
"<title>\n Host Europe GmbH\n </title>",
"<meta name=\"robots\" content=\"noarchive\">",
"<meta name=\"robots\" content=\"noindex, follow\">",
"<meta name=\"revisit-after\" content=\"1 day\">"
],
"body_size": 2867,
"body": "<!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 4.01 Transitional//EN\"\n \"http://www.w3.org/TR/html4/loose.dtd\">\n<html>\n<head>\n <meta name=\"robots\" content=\"noarchive\">\n <meta name=\"robots\" content=\"noindex, follow\">\n <meta name=\"revisit-after\" content=\"1 day\">\n <title>\n Host Europe GmbH\n </title> \n <style type=\"text/css\">\n body{\n margin:0;\n background-color: #999;\n background-image:url('/globalhererrordocuments/bgcolor.jpg');\n background-position:absolute;\n top:0px;\n background-repeat: repeat-x;\n font-size:11px;\n font-family:\"verdana\", sans-serif;\n }\n h1{\n font-size:18pt;\n font-weight:bold;\n font-family:'Verdana', sans-serif;\n color:#333;\n }\n h2{\n font-size:12pt;\n font-family:'Verdana', sans-serif;\n font-weight:bold;\n margin:5px;\n margin-left:0;\n color:#333;\n }\n h3{\n font-size:11pt;\n font-family:'Verdana', sans-serif;\n font-weight:bold;\n margin:5px;\n margin-left:0;\n color:#333;\n }\n p{\n font-size:10pt;\n font-family:'Verdana', sans-serif;\n font-weight:bold;\n margin:5px;\n margin-left:0;\n color:#333;\n }\n td{ \n color:#333;\n }\n </style>\n</head>\n<body>\n<table id=\"tab_allcontent\" width=\"762\" cellpadding=\"0\" cellspacing=\"0\" border=\"0\" summary=\"page-container\">\n <tr style=\"vertical-align:top; height:10px;\">\n <td>\n <img src=\"/globalhererrordocuments/tabspace5x5.gif\" width=\"10\" height=\"10\" alt=\"\">\n </td>\n </tr>\n <tr style=\"vertical-align:top;\">\n <td style=\"width:10px;\"></td>\n <td class=\"all\" style=\"width:752px;\">\n <table id=\"tab_contentonly\" width=\"752\" cellpadding=\"0\" cellspacing=\"0\" border=\"0\" summary=\"error-container\">\n <tr style=\"height:110px; vertical-align:top;\">\n <td>\n <table id=\"tab_contentheader\" width=\"721\" cellpadding=\"0\" cellspacing=\"0\" border=\"0\" summary=\"error-sign-and-message\">\n <tr valign=\"top\">\n <td style=\"width:150px;\">\n <img src=\"/globalhererrordocuments/header_caution_sign_verlauf.gif\" alt=\"header_caution_sign_verlauf.gif, 9 kB\" title=\"Domain ist temporär nicht erreichbar\" border=\"0\" height=\"150\" width=\"150\">\n </td>\n <td valign=\"middle\">\n <h2 style=\"font-weight:bold;font-size:medium;\">Die von Ihnen gewünschte Seite ist temporär nicht erreichbar.</h2>\n <h3 style=\"font-weight:normal;font-size:142%;\">Bitte versuchen Sie es zu einem späteren Zeitpunkt noch einmal.</h3>\n\t\t <h2 style=\"font-weight:bold;font-size:medium;\">This site is temporarily unavailable.</h2>\n <h3 style=\"font-weight:normal;font-size:142%;\">Please try again later.</h3>\n </td> \n </tr>\n </table>\n </td>\n </tr> \n </table> \n </td> \n </tr>\n</table>\n</body>\n</html>\n",
"body_hashes": [
"sha256:ce83de3976867bd4b4f9a3da99ca65a552e0ece986b93b01d72f8cffc21567f3",
"sha1:f4dce2cb8ecb19650ad3ebe31b87badbce816998"
],
"body_hash": "sha1:f4dce2cb8ecb19650ad3ebe31b87badbce816998",
"html_title": "\n Host Europe GmbH\n "
},
"supports_http2": false
},
"observed_at": "2024-09-15T16:32:24.792023580Z",
"perspective_id": "PERSPECTIVE_HE",
"port": 80,
"service_name": "HTTP",
"software": [
{
"uniform_resource_identifier": "cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*",
"part": "a",
"vendor": "nginx",
"product": "nginx",
"other": {
"family": "nginx"
},
"source": "OSI_APPLICATION_LAYER"
}
],
"source_ip": "162.142.125.222",
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "pop3",
"_encoding": {
"banner": "DISPLAY_UTF8",
"certificate": "DISPLAY_HEX",
"banner_hex": "DISPLAY_HEX"
},
"banner": "+OK Dovecot (Debian) ready.\r\n",
"banner_hashes": [
"sha256:d23f942eab9de1c939a3dcab0aefadf6c86ebc2b99ba56b2b364c14c7c2b8dad"
],
"banner_hex": "2b4f4b20446f7665636f74202844656269616e292072656164792e0d0a",
"certificate": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"extended_service_name": "POP3S",
"labels": [
"email"
],
"observed_at": "2024-09-15T13:33:42.975759654Z",
"perspective_id": "PERSPECTIVE_HE",
"pop3": {
"_encoding": {
"banner": "DISPLAY_UTF8",
"start_tls": "DISPLAY_UTF8"
},
"banner": "+OK Dovecot (Debian) ready.\r\n",
"start_tls": "+OK Begin TLS negotiation now.\r\n"
},
"port": 110,
"service_name": "POP3",
"software": [
{
"uniform_resource_identifier": "cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*",
"part": "a",
"vendor": "Dovecot",
"product": "Dovecot",
"other": {
"family": "Dovecot"
},
"source": "OSI_APPLICATION_LAYER"
},
{
"uniform_resource_identifier": "cpe:2.3:o:debian:debian_linux:*:*:*:*:*:*:*:*",
"part": "o",
"vendor": "Debian",
"product": "Linux",
"other": {
"family": "Linux"
},
"source": "OSI_APPLICATION_LAYER"
}
],
"source_ip": "162.142.125.221",
"tls": {
"version_selected": "TLSv1_3",
"cipher_selected": "TLS_AES_256_GCM_SHA384",
"certificates": {
"_encoding": {
"leaf_fp_sha_256": "DISPLAY_HEX",
"chain_fps_sha_256": "DISPLAY_HEX"
},
"leaf_fp_sha_256": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"chain_fps_sha_256": [
"973a41276ffd01e027a2aad49e34c37846d3e976ff6a620b6712e33832041aa6"
],
"leaf_data": {
"names": [
"*.ftp.server-he.ch",
"*.ftp.server-he.de",
"*.mail.server-he.ch",
"*.mail.server-he.de",
"*.mailout.server-he.ch",
"*.mailout.server-he.de",
"*.mywebdav.de",
"*.server-he.ch",
"*.server-he.de",
"*.storage.hosteurope.de",
"*.webpack.hosteurope.de",
"ftp.server-he.ch",
"ftp.server-he.de",
"mail.server-he.ch",
"mail.server-he.de",
"mailout.server-he.ch",
"mailout.server-he.de",
"mywebdav.de",
"server-he.ch",
"server-he.de",
"storage.hosteurope.de",
"webpack.hosteurope.de"
],
"subject_dn": "CN=*.webpack.hosteurope.de",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2",
"pubkey_bit_size": 2048,
"pubkey_algorithm": "RSA",
"tbs_fingerprint": "ed00f936e81acddb849611d08947d8dee072fdd207648bd0f39716e5b8022173",
"fingerprint": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"issuer": {
"common_name": [
"Go Daddy Secure Certificate Authority - G2"
],
"locality": [
"Scottsdale"
],
"organization": [
"GoDaddy.com, Inc."
],
"organizational_unit": [
"http://certs.godaddy.com/repository/"
],
"province": [
"Arizona"
],
"country": [
"US"
]
},
"subject": {
"common_name": [
"*.webpack.hosteurope.de"
]
},
"public_key": {
"key_algorithm": "RSA",
"rsa": {
"_encoding": {
"modulus": "DISPLAY_BASE64",
"exponent": "DISPLAY_BASE64"
},
"modulus": "wvC2VcxxtQrgbie9GHIErsPvnWnuluS0kGaPvR1tMTC3pV+1opgT9uGKQv7MCKsoB4Gr25J/CL8fDHu4myH5tOYvVFfHNZsHXAB+utxZX9Jfz5ILwaNWaJrbMHXiOnBtwMAdW1YonClBHOGy2hB7eYm0trgSz98tIgphZIqhr0XbewlYkFccHA+mRLFr4ZCABI33Oo3s5FYjRP+S6OZiYe3AXnQym/HCv0jO7+tz3Z5HmfSkhXkF0bPddHAgyRvTNu7hEKsPlpGo+wXKQdyVHBfgbrdADxS3BsRFpyRC84E1xcBEgQmWXRqjt+zwFCovrbWmBl5kUhldYp5YjJcaSw==",
"exponent": "AAEAAQ==",
"length": 256
},
"fingerprint": "943f1445820198e0eab45cbef93e18ab356a0a3776f88aad3e38de4da2f383fc"
},
"signature": {
"signature_algorithm": "SHA256-RSA",
"self_signed": false
}
},
"chain": [
{
"fingerprint": "973a41276ffd01e027a2aad49e34c37846d3e976ff6a620b6712e33832041aa6",
"subject_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., CN=Go Daddy Root Certificate Authority - G2"
}
]
},
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "15af977ce25de452b96affa2addb1036",
"ja4s": "t130200_1302_a56c5b993250"
},
"transport_fingerprint": {
"raw": "43440,64,true,MSTNW,1460,false,false"
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "ntp",
"extended_service_name": "NTP",
"ntp": {
"get_time_header": {
"version": 3,
"mode": 4,
"stratum": 5,
"poll": 3,
"precision": -21,
"_encoding": {
"reference_id": "DISPLAY_UTF8"
},
"reference_id": "P\ud011",
"leap_indicator": 0
}
},
"observed_at": "2024-09-14T18:00:42.283512557Z",
"perspective_id": "PERSPECTIVE_NTT",
"port": 123,
"service_name": "NTP",
"source_ip": "206.168.34.35",
"transport_protocol": "UDP",
"truncated": false
},
{
"_decoded": "imap",
"_encoding": {
"banner": "DISPLAY_UTF8",
"certificate": "DISPLAY_HEX",
"banner_hex": "DISPLAY_HEX"
},
"banner": "* OK [CAPABILITY IMAP4rev1 SASL-IR LOGIN-REFERRALS ID ENABLE IDLE LITERAL+ STARTTLS AUTH=PLAIN] Dovecot (Debian) ready.\r\n",
"banner_hashes": [
"sha256:30da5d31a6902099f19ddc50a2f3de9fceaa1081ac7b6fed7c48384108795c93"
],
"banner_hex": "2a204f4b205b4341504142494c49545920494d41503472657631205341534c2d4952204c4f47494e2d524546455252414c5320494420454e41424c452049444c45204c49544552414c2b205354415254544c5320415554483d504c41494e5d20446f7665636f74202844656269616e292072656164792e0d0a",
"certificate": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"extended_service_name": "IMAPS",
"imap": {
"_encoding": {
"banner": "DISPLAY_UTF8"
},
"banner": "* OK [CAPABILITY IMAP4rev1 SASL-IR LOGIN-REFERRALS ID ENABLE IDLE LITERAL+ STARTTLS AUTH=PLAIN] Dovecot (Debian) ready.\r\n",
"start_tls": "a001 OK Begin TLS negotiation now.\r\n"
},
"labels": [
"email"
],
"observed_at": "2024-09-15T15:54:11.628003198Z",
"perspective_id": "PERSPECTIVE_TATA",
"port": 143,
"service_name": "IMAP",
"software": [
{
"uniform_resource_identifier": "cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*",
"part": "a",
"vendor": "Dovecot",
"product": "Dovecot",
"other": {
"family": "Dovecot"
},
"source": "OSI_APPLICATION_LAYER"
},
{
"uniform_resource_identifier": "cpe:2.3:o:debian:debian_linux:*:*:*:*:*:*:*:*",
"part": "o",
"vendor": "Debian",
"product": "Linux",
"other": {
"family": "Linux"
},
"source": "OSI_APPLICATION_LAYER"
}
],
"source_ip": "167.94.138.117",
"tls": {
"version_selected": "TLSv1_3",
"cipher_selected": "TLS_AES_256_GCM_SHA384",
"certificates": {
"_encoding": {
"leaf_fp_sha_256": "DISPLAY_HEX",
"chain_fps_sha_256": "DISPLAY_HEX"
},
"leaf_fp_sha_256": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"chain_fps_sha_256": [
"973a41276ffd01e027a2aad49e34c37846d3e976ff6a620b6712e33832041aa6"
],
"leaf_data": {
"names": [
"*.ftp.server-he.ch",
"*.ftp.server-he.de",
"*.mail.server-he.ch",
"*.mail.server-he.de",
"*.mailout.server-he.ch",
"*.mailout.server-he.de",
"*.mywebdav.de",
"*.server-he.ch",
"*.server-he.de",
"*.storage.hosteurope.de",
"*.webpack.hosteurope.de",
"ftp.server-he.ch",
"ftp.server-he.de",
"mail.server-he.ch",
"mail.server-he.de",
"mailout.server-he.ch",
"mailout.server-he.de",
"mywebdav.de",
"server-he.ch",
"server-he.de",
"storage.hosteurope.de",
"webpack.hosteurope.de"
],
"subject_dn": "CN=*.webpack.hosteurope.de",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2",
"pubkey_bit_size": 2048,
"pubkey_algorithm": "RSA",
"tbs_fingerprint": "ed00f936e81acddb849611d08947d8dee072fdd207648bd0f39716e5b8022173",
"fingerprint": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"issuer": {
"common_name": [
"Go Daddy Secure Certificate Authority - G2"
],
"locality": [
"Scottsdale"
],
"organization": [
"GoDaddy.com, Inc."
],
"organizational_unit": [
"http://certs.godaddy.com/repository/"
],
"province": [
"Arizona"
],
"country": [
"US"
]
},
"subject": {
"common_name": [
"*.webpack.hosteurope.de"
]
},
"public_key": {
"key_algorithm": "RSA",
"rsa": {
"_encoding": {
"modulus": "DISPLAY_BASE64",
"exponent": "DISPLAY_BASE64"
},
"modulus": "wvC2VcxxtQrgbie9GHIErsPvnWnuluS0kGaPvR1tMTC3pV+1opgT9uGKQv7MCKsoB4Gr25J/CL8fDHu4myH5tOYvVFfHNZsHXAB+utxZX9Jfz5ILwaNWaJrbMHXiOnBtwMAdW1YonClBHOGy2hB7eYm0trgSz98tIgphZIqhr0XbewlYkFccHA+mRLFr4ZCABI33Oo3s5FYjRP+S6OZiYe3AXnQym/HCv0jO7+tz3Z5HmfSkhXkF0bPddHAgyRvTNu7hEKsPlpGo+wXKQdyVHBfgbrdADxS3BsRFpyRC84E1xcBEgQmWXRqjt+zwFCovrbWmBl5kUhldYp5YjJcaSw==",
"exponent": "AAEAAQ==",
"length": 256
},
"fingerprint": "943f1445820198e0eab45cbef93e18ab356a0a3776f88aad3e38de4da2f383fc"
},
"signature": {
"signature_algorithm": "SHA256-RSA",
"self_signed": false
}
},
"chain": [
{
"fingerprint": "973a41276ffd01e027a2aad49e34c37846d3e976ff6a620b6712e33832041aa6",
"subject_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., CN=Go Daddy Root Certificate Authority - G2"
}
]
},
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "15af977ce25de452b96affa2addb1036",
"ja4s": "t130200_1302_a56c5b993250",
"versions": [
{
"tls_version": "TLSv1_3",
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "15af977ce25de452b96affa2addb1036",
"ja4s": "t130200_1302_a56c5b993250"
}
]
},
"transport_fingerprint": {
"raw": "43440,64,true,MSTNW,1460,false,false"
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "http",
"_encoding": {
"banner": "DISPLAY_UTF8",
"certificate": "DISPLAY_HEX",
"banner_hex": "DISPLAY_HEX"
},
"banner": "HTTP/1.1 301 Moved Permanently\r\nServer: nginx\r\nDate: <REDACTED>\r\nContent-Type: text/html\r\nContent-Length: 162\r\nConnection: keep-alive\r\nLocation: https://www.healing-wisdom.de\r\n",
"banner_hashes": [
"sha256:d5e1bb3d5724383d3d28f9036e04e8d5d26cc65de1299917df0d79200525ccb2"
],
"banner_hex": "485454502f312e3120333031204d6f766564205065726d616e656e746c790d0a5365727665723a206e67696e780d0a446174653a20203c52454441435445443e0d0a436f6e74656e742d547970653a20746578742f68746d6c0d0a436f6e74656e742d4c656e6774683a203136320d0a436f6e6e656374696f6e3a206b6565702d616c6976650d0a4c6f636174696f6e3a2068747470733a2f2f7777772e6865616c696e672d776973646f6d2e64650d0a",
"certificate": "04bec9a82406accbd4ce78e485c69dcb661080aeca4aaf25f09b4315545bde85",
"extended_service_name": "HTTPS",
"http": {
"request": {
"method": "GET",
"uri": "https://5.35.235.35/",
"headers": {
"User_Agent": [
"Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)"
],
"_encoding": {
"User_Agent": "DISPLAY_UTF8",
"Accept": "DISPLAY_UTF8"
},
"Accept": [
"*/*"
]
}
},
"response": {
"protocol": "HTTP/1.1",
"status_code": 301,
"status_reason": "Moved Permanently",
"headers": {
"Date": [
"<REDACTED>"
],
"_encoding": {
"Date": "DISPLAY_UTF8",
"Server": "DISPLAY_UTF8",
"Content_Length": "DISPLAY_UTF8",
"Content_Type": "DISPLAY_UTF8",
"Location": "DISPLAY_UTF8",
"Connection": "DISPLAY_UTF8"
},
"Server": [
"nginx"
],
"Content_Length": [
"162"
],
"Content_Type": [
"text/html"
],
"Location": [
"https://www.healing-wisdom.de"
],
"Connection": [
"keep-alive"
]
},
"_encoding": {
"html_tags": "DISPLAY_UTF8",
"body": "DISPLAY_UTF8",
"body_hash": "DISPLAY_UTF8",
"html_title": "DISPLAY_UTF8"
},
"html_tags": [
"<title>301 Moved Permanently</title>"
],
"body_size": 162,
"body": "<html>\r\n<head><title>301 Moved Permanently</title></head>\r\n<body>\r\n<center><h1>301 Moved Permanently</h1></center>\r\n<hr><center>nginx</center>\r\n</body>\r\n</html>\r\n",
"body_hashes": [
"sha256:9e17cb15dd75bbbd5dbb984eda674863c3b10ab72613cf8a39a00c3e11a8492a",
"sha1:3adb1f02d5b6054de0046e367c1d687b6cdf7aff"
],
"body_hash": "sha1:3adb1f02d5b6054de0046e367c1d687b6cdf7aff",
"html_title": "301 Moved Permanently"
},
"supports_http2": false
},
"jarm": {
"_encoding": {
"fingerprint": "DISPLAY_HEX",
"cipher_and_version_fingerprint": "DISPLAY_HEX",
"tls_extensions_sha256": "DISPLAY_HEX"
},
"fingerprint": "15d3fd16d29d29d00042d43d000000f6a76359d2423084924eaeb5187f1701",
"cipher_and_version_fingerprint": "15d3fd16d29d29d00042d43d000000",
"tls_extensions_sha256": "f6a76359d2423084924eaeb5187f1701",
"observed_at": "2024-09-08T14:37:00.181784243Z"
},
"observed_at": "2024-09-15T16:49:20.550308269Z",
"perspective_id": "PERSPECTIVE_TELIA",
"port": 443,
"service_name": "HTTP",
"software": [
{
"uniform_resource_identifier": "cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*",
"part": "a",
"vendor": "nginx",
"product": "nginx",
"other": {
"family": "nginx"
},
"source": "OSI_APPLICATION_LAYER"
}
],
"source_ip": "167.94.146.58",
"tls": {
"version_selected": "TLSv1_3",
"cipher_selected": "TLS_CHACHA20_POLY1305_SHA256",
"certificates": {
"_encoding": {
"leaf_fp_sha_256": "DISPLAY_HEX",
"chain_fps_sha_256": "DISPLAY_HEX"
},
"leaf_fp_sha_256": "04bec9a82406accbd4ce78e485c69dcb661080aeca4aaf25f09b4315545bde85",
"chain_fps_sha_256": [
"93a07898d89b2cca166ba6f1f8a14138ce43828e491b831926bc8247d391cc72"
],
"leaf_data": {
"names": [
"ilanabegovic.com",
"www.ilanabegovic.com"
],
"subject_dn": "OU=Domain Control Validated, CN=www.ilanabegovic.com",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies\\, Inc., OU=http://certs.starfieldtech.com/repository/, CN=Starfield Secure Certificate Authority - G2",
"pubkey_bit_size": 4096,
"pubkey_algorithm": "RSA",
"tbs_fingerprint": "a8b6bbb842d74ce1b8afdd0dea8bc5cbf39d0f39f7b085c2c7b187c0a7132204",
"fingerprint": "04bec9a82406accbd4ce78e485c69dcb661080aeca4aaf25f09b4315545bde85",
"issuer": {
"common_name": [
"Starfield Secure Certificate Authority - G2"
],
"locality": [
"Scottsdale"
],
"organization": [
"Starfield Technologies, Inc."
],
"organizational_unit": [
"http://certs.starfieldtech.com/repository/"
],
"province": [
"Arizona"
],
"country": [
"US"
]
},
"subject": {
"common_name": [
"www.ilanabegovic.com"
],
"organizational_unit": [
"Domain Control Validated"
]
},
"public_key": {
"key_algorithm": "RSA",
"rsa": {
"_encoding": {
"modulus": "DISPLAY_BASE64",
"exponent": "DISPLAY_BASE64"
},
"modulus": "loFP2ueCZ68fWTbKBzqbXVxFGkQ+1qao7VWJQgEfA7ADd2Xy+TalzGLN3qcrnCnk3B7sfSDFMnA+/P4qAXEC893IPyLH2mydlXrBDHPT//X66v//lFJ6UOmRekd6Iv8qiqEH49pk34DdBjrsGLY4GEKoXeDCwcva44o0ANZbJNBXxYBgf2dzO3c5oEin/jyEh/gU7boo1xYf/dLmopm09kMlFcwQPgnzd7nyhOuGh19fHe/eMmgdQhp6osgXEoF/A+bWCqA3z6+ThZ4z4ci03g3X0uKi7fPRTbHarWydmKTE8s4Q8KaGK1Ff+38/K8wu2EP3e+bY4lwzbDqfg05+lFZKlSt3dDa7OgUR6lt0KwQWB1H3xbQ9C4d+EBxF/Pm/UhuOteA1w/0dHFXr7fsDLLSymsKzNCgqkfliAku496tXypDU+nkITkfoF1nfY5eAqMZpN6vOqMWWb0R3VIemRyFer4rII8phXjz+1h1oHLnHcKudHPNwqE7vQU/tua5EwU5fptJqhCYBDvpfu4TaflSK6KTGUODdz9W/PjeSMqhyvRATAbx1c1MxtLh3CcHevaPh3eJFQJWgOSqc29WwRLTdaW+E+C28eEqmpvwXciiR+YfebxVZsb0fN2XE/CJozT4TFw7UwSdrtXX/6AYCLq9KUrNDfmGPdUpTRpR6fKk=",
"exponent": "AAEAAQ==",
"length": 512
},
"fingerprint": "ac77780d0090c898b0c2f77b47fe6a05b1f2e608cc371b3ea3315ff902f3bddc"
},
"signature": {
"signature_algorithm": "SHA256-RSA",
"self_signed": false
}
},
"chain": [
{
"fingerprint": "93a07898d89b2cca166ba6f1f8a14138ce43828e491b831926bc8247d391cc72",
"subject_dn": "C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies\\, Inc., OU=http://certs.starfieldtech.com/repository/, CN=Starfield Secure Certificate Authority - G2",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies\\, Inc., CN=Starfield Root Certificate Authority - G2"
}
]
},
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "475c9302dc42b2751db9edcac3b74891",
"ja4s": "t130200_1303_a56c5b993250",
"versions": [
{
"tls_version": "TLSv1_3",
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "475c9302dc42b2751db9edcac3b74891",
"ja4s": "t130200_1303_a56c5b993250"
},
{
"tls_version": "TLSv1_2",
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "d25619cb77d3219fc9fc14cb6b35eacc",
"ja4s": "t120200_cca8_344b4dce5a52"
}
]
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "smtp",
"_encoding": {
"banner": "DISPLAY_UTF8",
"certificate": "DISPLAY_HEX",
"banner_hex": "DISPLAY_HEX"
},
"banner": "220 vwp12946.webpack.hosteurope.de ESMTP Host Europe Mail Service Sun, 15 Sep 2024 23:31:13 +0200\r\n",
"banner_hashes": [
"sha256:e17ab31510ac4105092595de97f4fc031da7c7e4b6ecd8074da9f13370eec716"
],
"banner_hex": "3232302076777031323934362e7765627061636b2e686f73746575726f70652e64652045534d545020486f7374204575726f7065204d61696c20536572766963652053756e2c2031352053657020323032342032333a33313a3133202b303230300d0a",
"certificate": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"discovery_method": "IPV4_WALK_FULL_PRIORITY_1",
"extended_service_name": "SMTPS",
"jarm": {
"_encoding": {
"fingerprint": "DISPLAY_HEX",
"cipher_and_version_fingerprint": "DISPLAY_HEX",
"tls_extensions_sha256": "DISPLAY_HEX"
},
"fingerprint": "00014d16d21d21d07c42d14d07d41dcdc93fe30d6fb1fcbf8119a460abd4cf",
"cipher_and_version_fingerprint": "00014d16d21d21d07c42d14d07d41d",
"tls_extensions_sha256": "cdc93fe30d6fb1fcbf8119a460abd4cf",
"observed_at": "2024-09-02T14:34:48.146280743Z"
},
"labels": [
"email"
],
"observed_at": "2024-09-15T21:31:12.346686216Z",
"perspective_id": "PERSPECTIVE_TATA",
"port": 465,
"service_name": "SMTP",
"smtp": {
"_encoding": {
"banner": "DISPLAY_UTF8",
"ehlo": "DISPLAY_UTF8"
},
"banner": "220 vwp12946.webpack.hosteurope.de ESMTP Host Europe Mail Service Sun, 15 Sep 2024 23:31:13 +0200\r\n",
"ehlo": "250-vwp12946.webpack.hosteurope.de Hello www.censys.io [167.94.138.123]\r\n250-SIZE 52428800\r\n250-8BITMIME\r\n250-PIPELINING\r\n250-AUTH PLAIN LOGIN\r\n250 HELP\r\n"
},
"source_ip": "167.94.138.123",
"tls": {
"version_selected": "TLSv1_3",
"cipher_selected": "TLS_CHACHA20_POLY1305_SHA256",
"certificates": {
"_encoding": {
"leaf_fp_sha_256": "DISPLAY_HEX",
"chain_fps_sha_256": "DISPLAY_HEX"
},
"leaf_fp_sha_256": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"chain_fps_sha_256": [
"973a41276ffd01e027a2aad49e34c37846d3e976ff6a620b6712e33832041aa6"
],
"leaf_data": {
"names": [
"*.ftp.server-he.ch",
"*.ftp.server-he.de",
"*.mail.server-he.ch",
"*.mail.server-he.de",
"*.mailout.server-he.ch",
"*.mailout.server-he.de",
"*.mywebdav.de",
"*.server-he.ch",
"*.server-he.de",
"*.storage.hosteurope.de",
"*.webpack.hosteurope.de",
"ftp.server-he.ch",
"ftp.server-he.de",
"mail.server-he.ch",
"mail.server-he.de",
"mailout.server-he.ch",
"mailout.server-he.de",
"mywebdav.de",
"server-he.ch",
"server-he.de",
"storage.hosteurope.de",
"webpack.hosteurope.de"
],
"subject_dn": "CN=*.webpack.hosteurope.de",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2",
"pubkey_bit_size": 2048,
"pubkey_algorithm": "RSA",
"tbs_fingerprint": "ed00f936e81acddb849611d08947d8dee072fdd207648bd0f39716e5b8022173",
"fingerprint": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"issuer": {
"common_name": [
"Go Daddy Secure Certificate Authority - G2"
],
"locality": [
"Scottsdale"
],
"organization": [
"GoDaddy.com, Inc."
],
"organizational_unit": [
"http://certs.godaddy.com/repository/"
],
"province": [
"Arizona"
],
"country": [
"US"
]
},
"subject": {
"common_name": [
"*.webpack.hosteurope.de"
]
},
"public_key": {
"key_algorithm": "RSA",
"rsa": {
"_encoding": {
"modulus": "DISPLAY_BASE64",
"exponent": "DISPLAY_BASE64"
},
"modulus": "wvC2VcxxtQrgbie9GHIErsPvnWnuluS0kGaPvR1tMTC3pV+1opgT9uGKQv7MCKsoB4Gr25J/CL8fDHu4myH5tOYvVFfHNZsHXAB+utxZX9Jfz5ILwaNWaJrbMHXiOnBtwMAdW1YonClBHOGy2hB7eYm0trgSz98tIgphZIqhr0XbewlYkFccHA+mRLFr4ZCABI33Oo3s5FYjRP+S6OZiYe3AXnQym/HCv0jO7+tz3Z5HmfSkhXkF0bPddHAgyRvTNu7hEKsPlpGo+wXKQdyVHBfgbrdADxS3BsRFpyRC84E1xcBEgQmWXRqjt+zwFCovrbWmBl5kUhldYp5YjJcaSw==",
"exponent": "AAEAAQ==",
"length": 256
},
"fingerprint": "943f1445820198e0eab45cbef93e18ab356a0a3776f88aad3e38de4da2f383fc"
},
"signature": {
"signature_algorithm": "SHA256-RSA",
"self_signed": false
}
},
"chain": [
{
"fingerprint": "973a41276ffd01e027a2aad49e34c37846d3e976ff6a620b6712e33832041aa6",
"subject_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., CN=Go Daddy Root Certificate Authority - G2"
}
]
},
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "d75f9129bb5d05492a65ff78e081bcb2",
"ja4s": "t130200_1303_234ea6891581",
"versions": [
{
"tls_version": "TLSv1_3",
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "d75f9129bb5d05492a65ff78e081bcb2",
"ja4s": "t130200_1303_234ea6891581"
},
{
"tls_version": "TLSv1_2",
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "3b1990d8d0d9e89b35d3f6c3abddba54",
"ja4s": "t120200_cca8_8fe157b277d7"
},
{
"tls_version": "TLSv1_1",
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "4887e172ec56727ac02b1b40d0cb3ae2",
"ja4s": "t110200_c013_8fe157b277d7"
},
{
"tls_version": "TLSv1_0",
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "171cb911c3fe3165cd0a1ab4da573fb4",
"ja4s": "t100200_c013_8fe157b277d7"
}
]
},
"transport_fingerprint": {
"raw": "43440,64,true,MSTNW,1460,false,false"
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "smtp",
"_encoding": {
"banner": "DISPLAY_UTF8",
"certificate": "DISPLAY_HEX",
"banner_hex": "DISPLAY_HEX"
},
"banner": "220 vwp12946.webpack.hosteurope.de ESMTP Host Europe Mail Service Sun, 15 Sep 2024 07:07:31 +0200\r\n",
"banner_hashes": [
"sha256:3a14d67f8363e9a689a92df7e2bec5370f221943b74f73af3bb461865f9e0935"
],
"banner_hex": "3232302076777031323934362e7765627061636b2e686f73746575726f70652e64652045534d545020486f7374204575726f7065204d61696c20536572766963652053756e2c2031352053657020323032342030373a30373a3331202b303230300d0a",
"certificate": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"extended_service_name": "SMTP-STARTTLS",
"labels": [
"email"
],
"observed_at": "2024-09-15T05:07:20.974725495Z",
"perspective_id": "PERSPECTIVE_NTT",
"port": 587,
"service_name": "SMTP",
"smtp": {
"_encoding": {
"banner": "DISPLAY_UTF8",
"ehlo": "DISPLAY_UTF8",
"start_tls": "DISPLAY_UTF8"
},
"banner": "220 vwp12946.webpack.hosteurope.de ESMTP Host Europe Mail Service Sun, 15 Sep 2024 07:07:31 +0200\r\n",
"ehlo": "250-vwp12946.webpack.hosteurope.de Hello www.censys.io [206.168.34.56]\r\n250-SIZE 52428800\r\n250-8BITMIME\r\n250-PIPELINING\r\n250-AUTH PLAIN LOGIN\r\n250-STARTTLS\r\n250 HELP\r\n",
"start_tls": "220 TLS go ahead\r\n"
},
"source_ip": "206.168.34.56",
"tls": {
"version_selected": "TLSv1_3",
"cipher_selected": "TLS_CHACHA20_POLY1305_SHA256",
"certificates": {
"_encoding": {
"leaf_fp_sha_256": "DISPLAY_HEX",
"chain_fps_sha_256": "DISPLAY_HEX"
},
"leaf_fp_sha_256": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"chain_fps_sha_256": [
"973a41276ffd01e027a2aad49e34c37846d3e976ff6a620b6712e33832041aa6"
],
"leaf_data": {
"names": [
"*.ftp.server-he.ch",
"*.ftp.server-he.de",
"*.mail.server-he.ch",
"*.mail.server-he.de",
"*.mailout.server-he.ch",
"*.mailout.server-he.de",
"*.mywebdav.de",
"*.server-he.ch",
"*.server-he.de",
"*.storage.hosteurope.de",
"*.webpack.hosteurope.de",
"ftp.server-he.ch",
"ftp.server-he.de",
"mail.server-he.ch",
"mail.server-he.de",
"mailout.server-he.ch",
"mailout.server-he.de",
"mywebdav.de",
"server-he.ch",
"server-he.de",
"storage.hosteurope.de",
"webpack.hosteurope.de"
],
"subject_dn": "CN=*.webpack.hosteurope.de",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2",
"pubkey_bit_size": 2048,
"pubkey_algorithm": "RSA",
"tbs_fingerprint": "ed00f936e81acddb849611d08947d8dee072fdd207648bd0f39716e5b8022173",
"fingerprint": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"issuer": {
"common_name": [
"Go Daddy Secure Certificate Authority - G2"
],
"locality": [
"Scottsdale"
],
"organization": [
"GoDaddy.com, Inc."
],
"organizational_unit": [
"http://certs.godaddy.com/repository/"
],
"province": [
"Arizona"
],
"country": [
"US"
]
},
"subject": {
"common_name": [
"*.webpack.hosteurope.de"
]
},
"public_key": {
"key_algorithm": "RSA",
"rsa": {
"_encoding": {
"modulus": "DISPLAY_BASE64",
"exponent": "DISPLAY_BASE64"
},
"modulus": "wvC2VcxxtQrgbie9GHIErsPvnWnuluS0kGaPvR1tMTC3pV+1opgT9uGKQv7MCKsoB4Gr25J/CL8fDHu4myH5tOYvVFfHNZsHXAB+utxZX9Jfz5ILwaNWaJrbMHXiOnBtwMAdW1YonClBHOGy2hB7eYm0trgSz98tIgphZIqhr0XbewlYkFccHA+mRLFr4ZCABI33Oo3s5FYjRP+S6OZiYe3AXnQym/HCv0jO7+tz3Z5HmfSkhXkF0bPddHAgyRvTNu7hEKsPlpGo+wXKQdyVHBfgbrdADxS3BsRFpyRC84E1xcBEgQmWXRqjt+zwFCovrbWmBl5kUhldYp5YjJcaSw==",
"exponent": "AAEAAQ==",
"length": 256
},
"fingerprint": "943f1445820198e0eab45cbef93e18ab356a0a3776f88aad3e38de4da2f383fc"
},
"signature": {
"signature_algorithm": "SHA256-RSA",
"self_signed": false
}
},
"chain": [
{
"fingerprint": "973a41276ffd01e027a2aad49e34c37846d3e976ff6a620b6712e33832041aa6",
"subject_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., CN=Go Daddy Root Certificate Authority - G2"
}
]
},
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "d75f9129bb5d05492a65ff78e081bcb2",
"ja4s": "t130200_1303_234ea6891581"
},
"transport_fingerprint": {
"raw": "43440,64,true,MSTNW,1460,false,false"
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "imap",
"_encoding": {
"banner": "DISPLAY_UTF8",
"certificate": "DISPLAY_HEX",
"banner_hex": "DISPLAY_HEX"
},
"banner": "* OK [CAPABILITY IMAP4rev1 SASL-IR LOGIN-REFERRALS ID ENABLE IDLE LITERAL+ AUTH=PLAIN] Dovecot (Debian) ready.\r\n",
"banner_hashes": [
"sha256:c6da3659113355d5304fa51a7cf8a22204b433dac37072359c696b6c8b3b9f30"
],
"banner_hex": "2a204f4b205b4341504142494c49545920494d41503472657631205341534c2d4952204c4f47494e2d524546455252414c5320494420454e41424c452049444c45204c49544552414c2b20415554483d504c41494e5d20446f7665636f74202844656269616e292072656164792e0d0a",
"certificate": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"extended_service_name": "IMAPS",
"imap": {
"_encoding": {
"banner": "DISPLAY_UTF8"
},
"banner": "* OK [CAPABILITY IMAP4rev1 SASL-IR LOGIN-REFERRALS ID ENABLE IDLE LITERAL+ AUTH=PLAIN] Dovecot (Debian) ready.\r\n"
},
"jarm": {
"_encoding": {
"fingerprint": "DISPLAY_HEX",
"cipher_and_version_fingerprint": "DISPLAY_HEX",
"tls_extensions_sha256": "DISPLAY_HEX"
},
"fingerprint": "29d29d15d29d29d21c42d42d000000dc2b105e4dda975fa70719c0cae5d0ce",
"cipher_and_version_fingerprint": "29d29d15d29d29d21c42d42d000000",
"tls_extensions_sha256": "dc2b105e4dda975fa70719c0cae5d0ce",
"observed_at": "2024-09-08T20:50:17.106425314Z"
},
"labels": [
"email"
],
"observed_at": "2024-09-15T21:07:13.000332578Z",
"perspective_id": "PERSPECTIVE_TELIA",
"port": 993,
"service_name": "IMAP",
"software": [
{
"uniform_resource_identifier": "cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*",
"part": "a",
"vendor": "Dovecot",
"product": "Dovecot",
"other": {
"family": "Dovecot"
},
"source": "OSI_APPLICATION_LAYER"
},
{
"uniform_resource_identifier": "cpe:2.3:o:debian:debian_linux:*:*:*:*:*:*:*:*",
"part": "o",
"vendor": "Debian",
"product": "Linux",
"other": {
"family": "Linux"
},
"source": "OSI_APPLICATION_LAYER"
}
],
"source_ip": "167.94.146.56",
"tls": {
"version_selected": "TLSv1_3",
"cipher_selected": "TLS_AES_256_GCM_SHA384",
"certificates": {
"_encoding": {
"leaf_fp_sha_256": "DISPLAY_HEX",
"chain_fps_sha_256": "DISPLAY_HEX"
},
"leaf_fp_sha_256": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"chain_fps_sha_256": [
"973a41276ffd01e027a2aad49e34c37846d3e976ff6a620b6712e33832041aa6"
],
"leaf_data": {
"names": [
"*.ftp.server-he.ch",
"*.ftp.server-he.de",
"*.mail.server-he.ch",
"*.mail.server-he.de",
"*.mailout.server-he.ch",
"*.mailout.server-he.de",
"*.mywebdav.de",
"*.server-he.ch",
"*.server-he.de",
"*.storage.hosteurope.de",
"*.webpack.hosteurope.de",
"ftp.server-he.ch",
"ftp.server-he.de",
"mail.server-he.ch",
"mail.server-he.de",
"mailout.server-he.ch",
"mailout.server-he.de",
"mywebdav.de",
"server-he.ch",
"server-he.de",
"storage.hosteurope.de",
"webpack.hosteurope.de"
],
"subject_dn": "CN=*.webpack.hosteurope.de",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2",
"pubkey_bit_size": 2048,
"pubkey_algorithm": "RSA",
"tbs_fingerprint": "ed00f936e81acddb849611d08947d8dee072fdd207648bd0f39716e5b8022173",
"fingerprint": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"issuer": {
"common_name": [
"Go Daddy Secure Certificate Authority - G2"
],
"locality": [
"Scottsdale"
],
"organization": [
"GoDaddy.com, Inc."
],
"organizational_unit": [
"http://certs.godaddy.com/repository/"
],
"province": [
"Arizona"
],
"country": [
"US"
]
},
"subject": {
"common_name": [
"*.webpack.hosteurope.de"
]
},
"public_key": {
"key_algorithm": "RSA",
"rsa": {
"_encoding": {
"modulus": "DISPLAY_BASE64",
"exponent": "DISPLAY_BASE64"
},
"modulus": "wvC2VcxxtQrgbie9GHIErsPvnWnuluS0kGaPvR1tMTC3pV+1opgT9uGKQv7MCKsoB4Gr25J/CL8fDHu4myH5tOYvVFfHNZsHXAB+utxZX9Jfz5ILwaNWaJrbMHXiOnBtwMAdW1YonClBHOGy2hB7eYm0trgSz98tIgphZIqhr0XbewlYkFccHA+mRLFr4ZCABI33Oo3s5FYjRP+S6OZiYe3AXnQym/HCv0jO7+tz3Z5HmfSkhXkF0bPddHAgyRvTNu7hEKsPlpGo+wXKQdyVHBfgbrdADxS3BsRFpyRC84E1xcBEgQmWXRqjt+zwFCovrbWmBl5kUhldYp5YjJcaSw==",
"exponent": "AAEAAQ==",
"length": 256
},
"fingerprint": "943f1445820198e0eab45cbef93e18ab356a0a3776f88aad3e38de4da2f383fc"
},
"signature": {
"signature_algorithm": "SHA256-RSA",
"self_signed": false
}
},
"chain": [
{
"fingerprint": "973a41276ffd01e027a2aad49e34c37846d3e976ff6a620b6712e33832041aa6",
"subject_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., CN=Go Daddy Root Certificate Authority - G2"
}
]
},
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "15af977ce25de452b96affa2addb1036",
"ja4s": "t130200_1302_a56c5b993250",
"versions": [
{
"tls_version": "TLSv1_3",
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "15af977ce25de452b96affa2addb1036",
"ja4s": "t130200_1302_a56c5b993250"
},
{
"tls_version": "TLSv1_2",
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "303951d4c50efb2e991652225a6f02b1",
"ja4s": "t120200_c02f_344b4dce5a52"
},
{
"tls_version": "TLSv1_1",
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "b8d8f22562475aebf44ad54175c1d9c7",
"ja4s": "t110200_c013_344b4dce5a52"
},
{
"tls_version": "TLSv1_0",
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "184d532a16876b78846ae6a03f654890",
"ja4s": "t100200_c013_344b4dce5a52"
}
]
},
"transport_fingerprint": {
"raw": "43440,64,true,MSTNW,1460,false,false"
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "pop3",
"_encoding": {
"banner": "DISPLAY_UTF8",
"certificate": "DISPLAY_HEX",
"banner_hex": "DISPLAY_HEX"
},
"banner": "+OK Dovecot (Debian) ready.\r\n",
"banner_hashes": [
"sha256:d23f942eab9de1c939a3dcab0aefadf6c86ebc2b99ba56b2b364c14c7c2b8dad"
],
"banner_hex": "2b4f4b20446f7665636f74202844656269616e292072656164792e0d0a",
"certificate": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"discovery_method": "PREDICTIVE_METHOD_7",
"extended_service_name": "POP3S",
"jarm": {
"_encoding": {
"fingerprint": "DISPLAY_HEX",
"cipher_and_version_fingerprint": "DISPLAY_HEX",
"tls_extensions_sha256": "DISPLAY_HEX"
},
"fingerprint": "29d29d15d29d29d21c42d42d000000dc2b105e4dda975fa70719c0cae5d0ce",
"cipher_and_version_fingerprint": "29d29d15d29d29d21c42d42d000000",
"tls_extensions_sha256": "dc2b105e4dda975fa70719c0cae5d0ce",
"observed_at": "2024-08-24T21:06:01.543502759Z"
},
"labels": [
"email"
],
"observed_at": "2024-09-15T02:20:57.995586795Z",
"perspective_id": "PERSPECTIVE_TATA",
"pop3": {
"_encoding": {
"banner": "DISPLAY_UTF8"
},
"banner": "+OK Dovecot (Debian) ready.\r\n"
},
"port": 995,
"service_name": "POP3",
"software": [
{
"uniform_resource_identifier": "cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*",
"part": "a",
"vendor": "Dovecot",
"product": "Dovecot",
"other": {
"family": "Dovecot"
},
"source": "OSI_APPLICATION_LAYER"
},
{
"uniform_resource_identifier": "cpe:2.3:o:debian:debian_linux:*:*:*:*:*:*:*:*",
"part": "o",
"vendor": "Debian",
"product": "Linux",
"other": {
"family": "Linux"
},
"source": "OSI_APPLICATION_LAYER"
}
],
"source_ip": "167.94.138.54",
"tls": {
"version_selected": "TLSv1_3",
"cipher_selected": "TLS_AES_256_GCM_SHA384",
"certificates": {
"_encoding": {
"leaf_fp_sha_256": "DISPLAY_HEX",
"chain_fps_sha_256": "DISPLAY_HEX"
},
"leaf_fp_sha_256": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"chain_fps_sha_256": [
"973a41276ffd01e027a2aad49e34c37846d3e976ff6a620b6712e33832041aa6"
],
"leaf_data": {
"names": [
"*.ftp.server-he.ch",
"*.ftp.server-he.de",
"*.mail.server-he.ch",
"*.mail.server-he.de",
"*.mailout.server-he.ch",
"*.mailout.server-he.de",
"*.mywebdav.de",
"*.server-he.ch",
"*.server-he.de",
"*.storage.hosteurope.de",
"*.webpack.hosteurope.de",
"ftp.server-he.ch",
"ftp.server-he.de",
"mail.server-he.ch",
"mail.server-he.de",
"mailout.server-he.ch",
"mailout.server-he.de",
"mywebdav.de",
"server-he.ch",
"server-he.de",
"storage.hosteurope.de",
"webpack.hosteurope.de"
],
"subject_dn": "CN=*.webpack.hosteurope.de",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2",
"pubkey_bit_size": 2048,
"pubkey_algorithm": "RSA",
"tbs_fingerprint": "ed00f936e81acddb849611d08947d8dee072fdd207648bd0f39716e5b8022173",
"fingerprint": "e178dafd6ae7bb75372de7edf74fa8c306f5266e329ec5ad671ed56d7e74fcf9",
"issuer": {
"common_name": [
"Go Daddy Secure Certificate Authority - G2"
],
"locality": [
"Scottsdale"
],
"organization": [
"GoDaddy.com, Inc."
],
"organizational_unit": [
"http://certs.godaddy.com/repository/"
],
"province": [
"Arizona"
],
"country": [
"US"
]
},
"subject": {
"common_name": [
"*.webpack.hosteurope.de"
]
},
"public_key": {
"key_algorithm": "RSA",
"rsa": {
"_encoding": {
"modulus": "DISPLAY_BASE64",
"exponent": "DISPLAY_BASE64"
},
"modulus": "wvC2VcxxtQrgbie9GHIErsPvnWnuluS0kGaPvR1tMTC3pV+1opgT9uGKQv7MCKsoB4Gr25J/CL8fDHu4myH5tOYvVFfHNZsHXAB+utxZX9Jfz5ILwaNWaJrbMHXiOnBtwMAdW1YonClBHOGy2hB7eYm0trgSz98tIgphZIqhr0XbewlYkFccHA+mRLFr4ZCABI33Oo3s5FYjRP+S6OZiYe3AXnQym/HCv0jO7+tz3Z5HmfSkhXkF0bPddHAgyRvTNu7hEKsPlpGo+wXKQdyVHBfgbrdADxS3BsRFpyRC84E1xcBEgQmWXRqjt+zwFCovrbWmBl5kUhldYp5YjJcaSw==",
"exponent": "AAEAAQ==",
"length": 256
},
"fingerprint": "943f1445820198e0eab45cbef93e18ab356a0a3776f88aad3e38de4da2f383fc"
},
"signature": {
"signature_algorithm": "SHA256-RSA",
"self_signed": false
}
},
"chain": [
{
"fingerprint": "973a41276ffd01e027a2aad49e34c37846d3e976ff6a620b6712e33832041aa6",
"subject_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2",
"issuer_dn": "C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com\\, Inc., CN=Go Daddy Root Certificate Authority - G2"
}
]
},
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "15af977ce25de452b96affa2addb1036",
"ja4s": "t130200_1302_a56c5b993250"
},
"transport_fingerprint": {
"raw": "43440,64,true,MSTNW,1460,false,false"
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "mysql",
"extended_service_name": "MYSQL",
"labels": [
"database"
],
"mysql": {
"error_code": 1130,
"error_id": "ER_HOST_NOT_PRIVILEGED",
"error_message": "Host '206.168.34.58' is not allowed to connect to this MySQL server",
"protocol_version": 0,
"connection_id": 0,
"character_set": 0
},
"observed_at": "2024-09-15T02:15:15.347577338Z",
"perspective_id": "PERSPECTIVE_NTT",
"port": 3306,
"service_name": "MYSQL",
"software": [
{
"uniform_resource_identifier": "cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*",
"part": "a",
"vendor": "Oracle",
"product": "MySQL",
"other": {
"family": "MySQL"
},
"source": "OSI_APPLICATION_LAYER"
},
{
"uniform_resource_identifier": "cpe:2.3:o:*:linux:*:*:*:*:*:*:*:*",
"part": "o",
"product": "linux",
"source": "OSI_TRANSPORT_LAYER"
}
],
"source_ip": "206.168.34.58",
"transport_fingerprint": {
"id": 72,
"os": "Ubuntu / Debian / CentOS",
"raw": "28960,64,true,MSTNW,1460,false,false"
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "banner_grab",
"_encoding": {
"banner": "DISPLAY_UTF8",
"banner_hex": "DISPLAY_HEX"
},
"banner": "\u0005\u0000\u0000\u0000\u000b\b\u0005\u001a\u0000",
"banner_hashes": [
"sha256:5cf471b74061d818ff16b1d9301293c7d258d35f081298d4b88bad50b15aaf3f"
],
"banner_hex": "050000000b08051a00",
"discovery_method": "PREDICTIVE_METHOD_20",
"extended_service_name": "UNKNOWN",
"observed_at": "2024-09-15T02:18:04.401254152Z",
"perspective_id": "PERSPECTIVE_PCCW",
"port": 33060,
"service_name": "UNKNOWN",
"source_ip": "199.45.154.133",
"transport_fingerprint": {
"raw": "43440,64,true,MSTNW,1460,false,false"
},
"transport_protocol": "TCP",
"truncated": false
}
],
"location": {
"continent": "Europe",
"country": "Germany",
"country_code": "DE",
"city": "Kehl",
"postal_code": "77694",
"timezone": "Europe/Berlin",
"province": "Baden-Wurttemberg",
"coordinates": {
"latitude": 48.57297,
"longitude": 7.81523
}
},
"location_updated_at": "2024-09-01T12:42:46.239331438Z",
"autonomous_system": {
"asn": 20773,
"description": "GODADDY",
"bgp_prefix": "5.35.224.0/19",
"name": "GODADDY",
"country_code": "DE"
},
"autonomous_system_updated_at": "2024-09-01T12:42:46.239343817Z",
"whois": {
"network": {
"handle": "DE-HE-SH-DSM-FAL1-NET",
"name": "Host Europe GmbH",
"cidrs": [
"5.35.232.0/22"
],
"created": "2013-09-16T00:00:00Z",
"updated": "2015-11-17T00:00:00Z"
},
"organization": {
"handle": "ORG-OG1-RIPE",
"name": "Host Europe GmbH",
"address": "c/o WeWork Wallarkaden\\n50674\\nK\u00f6ln\\nGERMANY",
"abuse_contacts": [
{
"handle": "HEAH",
"name": "Host Europe Abuse Handling",
"email": "[email protected]"
}
],
"admin_contacts": [
{
"handle": "GDDY",
"name": "GoDaddy LIR",
"email": "[email protected]"
}
]
}
},
"operating_system": {
"uniform_resource_identifier": "cpe:2.3:o:debian:debian_linux:*:*:*:*:*:*:*:*",
"part": "o",
"vendor": "Debian",
"product": "Linux",
"other": {
"family": "Linux"
}
},
"dns": {
"names": [
"www.healing-wisdom.de",
"www.shop.healing-wisdom.de",
"ilanabegovic.com",
"www.ilanabegovic.com",
"vwp12946.webpack.hosteurope.de",
"healing-wisdom.de"
],
"records": {
"ilanabegovic.com": {
"record_type": "A",
"resolved_at": "2024-09-14T17:22:23.060659844Z"
},
"www.shop.healing-wisdom.de": {
"record_type": "A",
"resolved_at": "2024-08-21T18:57:55.053635814Z"
},
"www.ilanabegovic.com": {
"record_type": "A",
"resolved_at": "2024-09-07T16:07:22.101085456Z"
},
"healing-wisdom.de": {
"record_type": "A",
"resolved_at": "2024-09-05T18:36:27.956297121Z"
},
"www.healing-wisdom.de": {
"record_type": "A",
"resolved_at": "2024-09-10T16:28:30.214180850Z"
},
"vwp12946.webpack.hosteurope.de": {
"record_type": "A",
"resolved_at": "2024-09-11T19:26:21.711755555Z"
}
},
"reverse_dns": {
"names": [
"vwp12946.webpack.hosteurope.de"
],
"resolved_at": "2024-09-03T16:19:19.524289151Z"
}
},
"last_updated_at": "2024-09-16T02:23:26.229Z",
"labels": [
"database",
"email",
"file-sharing",
"remote-access"
]
}