89.161.136.214
As of: Oct 04, 2024 8:21am UTC |
Latest
{
"ip": "89.161.136.214",
"services": [
{
"_decoded": "ftp",
"_encoding": {
"banner": "DISPLAY_UTF8",
"certificate": "DISPLAY_HEX",
"banner_hex": "DISPLAY_HEX"
},
"banner": "220-Idea FTP Server 6.2.0 (ekonomik2.home.pl) [89.161.136.214]\r\n220 Ready\r\n",
"banner_hashes": [
"sha256:747e3744d861021970e3176b64805a27d42c98205ec8208415d0939d1e351820"
],
"banner_hex": "3232302d49646561204654502053657276657220362e322e302028656b6f6e6f6d696b322e686f6d652e706c29205b38392e3136312e3133362e3231345d0d0a3232302052656164790d0a",
"certificate": "1c12ea601b0bf59cc7ba2a74fffdd93691d97bcd2af411df7f1b4e7dc36214d8",
"discovery_method": "PREDICTIVE_METHOD_12",
"extended_service_name": "FTPes",
"ftp": {
"_encoding": {
"banner": "DISPLAY_UTF8",
"auth_tls_response": "DISPLAY_UTF8"
},
"banner": "220-Idea FTP Server 6.2.0 (ekonomik2.home.pl) [89.161.136.214]\r\n220 Ready\r\n",
"auth_tls_response": "234 AUTH command successful.\r\n",
"status_code": 220,
"status_meaning": "Service ready for new user.",
"implicit_tls": false
},
"labels": [
"file-sharing"
],
"observed_at": "2024-10-03T04:03:35.898472455Z",
"perspective_id": "PERSPECTIVE_HE",
"port": 21,
"service_name": "FTP",
"source_ip": "162.142.125.42",
"tls": {
"version_selected": "TLSv1_3",
"cipher_selected": "TLS_AES_256_GCM_SHA384",
"certificates": {
"_encoding": {
"leaf_fp_sha_256": "DISPLAY_HEX",
"chain_fps_sha_256": "DISPLAY_HEX"
},
"leaf_fp_sha_256": "1c12ea601b0bf59cc7ba2a74fffdd93691d97bcd2af411df7f1b4e7dc36214d8",
"chain_fps_sha_256": [
"a95f23b52af10895886fb65323d29a9876ea7d396f805e4ca280d561c26e3dad",
"9e852c59dfc6fd6abd4e17ea80b5f4e56fc04192d107258d54da8a92528670d6",
"5c58468d55f58e497e743982d2b50010b6d165374acf83a7d4a32db768c4408e"
],
"leaf_data": {
"names": [
"*.home.pl",
"home.pl"
],
"subject_dn": "CN=*.home.pl",
"issuer_dn": "C=PL, O=home.pl S.A., CN=Certyfikat SSL",
"pubkey_bit_size": 2048,
"pubkey_algorithm": "RSA",
"tbs_fingerprint": "b807971c7c77a9b1d29605c36800a6de0b187340a2aa0086a88d70656f313845",
"fingerprint": "1c12ea601b0bf59cc7ba2a74fffdd93691d97bcd2af411df7f1b4e7dc36214d8",
"issuer": {
"common_name": [
"Certyfikat SSL"
],
"organization": [
"home.pl S.A."
],
"country": [
"PL"
]
},
"subject": {
"common_name": [
"*.home.pl"
]
},
"public_key": {
"key_algorithm": "RSA",
"rsa": {
"_encoding": {
"modulus": "DISPLAY_BASE64",
"exponent": "DISPLAY_BASE64"
},
"modulus": "5vsb3m8t53OmPOeuFMuLbTjRCOvJq87kcgnhz1EuMJPGFenPS+TqlgjPmDaTqyFIas1ouLzMA/WOXOA3oRsAKGJ9b/Bo9hb1JikVqjwIEMYrQQa8M9d4e0LrPr0Dv539XsfkOU+tOETU7isAaDtqmEaPaaHyMr2UgQHAIwN5WgYKrvGJKnk8199QNSV8Xq5bO5qxg6LMysAM6yicQIp1QrRgd6HqsgPb+kM51UFAkySCbU0JGdgSkUVmGatxALl/jpLcBGDTxFPFcPgrXOl2qe1Ub4OrXM/GCTgmDrEXOJPzhdnEHqI0fjfpT9JCDBs6e/ZKnlq1dAU/3IxiGavz5w==",
"exponent": "AAEAAQ==",
"length": 256
},
"fingerprint": "1a7e3e768f8709c2b3a45327e0af99ea1429f0ee8f081c085c3a271340b09ce7"
},
"signature": {
"signature_algorithm": "SHA256-RSA",
"self_signed": false
}
},
"chain": [
{
"fingerprint": "a95f23b52af10895886fb65323d29a9876ea7d396f805e4ca280d561c26e3dad",
"subject_dn": "C=PL, O=home.pl S.A., CN=Certyfikat SSL",
"issuer_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Global Services CA SHA2"
},
{
"fingerprint": "9e852c59dfc6fd6abd4e17ea80b5f4e56fc04192d107258d54da8a92528670d6",
"subject_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Global Services CA SHA2",
"issuer_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA"
},
{
"fingerprint": "5c58468d55f58e497e743982d2b50010b6d165374acf83a7d4a32db768c4408e",
"subject_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA",
"issuer_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA"
}
]
},
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "15af977ce25de452b96affa2addb1036",
"ja4s": "t130200_1302_a56c5b993250"
},
"transport_fingerprint": {
"raw": "31856,64,true,MSTNW,1460,false,false"
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "smtp",
"_encoding": {
"banner": "DISPLAY_UTF8",
"certificate": "DISPLAY_HEX",
"banner_hex": "DISPLAY_HEX"
},
"banner": "220 cloudserver022566.home.pl ESMTP Mailsystemx\r\n",
"banner_hashes": [
"sha256:3a8ad35ce21704c92cda3498c048e91c91848f37d4f8e3975d676c9ce00f156b"
],
"banner_hex": "32323020636c6f75647365727665723032323536362e686f6d652e706c2045534d5450204d61696c73797374656d780d0a",
"certificate": "1c12ea601b0bf59cc7ba2a74fffdd93691d97bcd2af411df7f1b4e7dc36214d8",
"discovery_method": "PREDICTIVE_METHOD_7",
"extended_service_name": "SMTP-STARTTLS",
"labels": [
"email"
],
"observed_at": "2024-10-03T05:13:30.882596334Z",
"perspective_id": "PERSPECTIVE_PCCW",
"port": 25,
"service_name": "SMTP",
"smtp": {
"_encoding": {
"banner": "DISPLAY_UTF8",
"ehlo": "DISPLAY_UTF8",
"start_tls": "DISPLAY_UTF8"
},
"banner": "220 cloudserver022566.home.pl ESMTP Mailsystemx\r\n",
"ehlo": "250-cloudserver022566.home.pl\r\n250-PIPELINING\r\n250-SIZE 157286400\r\n250-ETRN\r\n250-STARTTLS\r\n250-AUTH PLAIN LOGIN\r\n250-ENHANCEDSTATUSCODES\r\n250-8BITMIME\r\n250-DSN\r\n250 CHUNKING\r\n",
"start_tls": "220 2.0.0 Ready to start TLS\r\n"
},
"source_ip": "199.45.154.137",
"tls": {
"version_selected": "TLSv1_3",
"cipher_selected": "TLS_CHACHA20_POLY1305_SHA256",
"certificates": {
"_encoding": {
"leaf_fp_sha_256": "DISPLAY_HEX",
"chain_fps_sha_256": "DISPLAY_HEX"
},
"leaf_fp_sha_256": "1c12ea601b0bf59cc7ba2a74fffdd93691d97bcd2af411df7f1b4e7dc36214d8",
"chain_fps_sha_256": [
"a95f23b52af10895886fb65323d29a9876ea7d396f805e4ca280d561c26e3dad",
"9e852c59dfc6fd6abd4e17ea80b5f4e56fc04192d107258d54da8a92528670d6",
"5c58468d55f58e497e743982d2b50010b6d165374acf83a7d4a32db768c4408e"
],
"leaf_data": {
"names": [
"*.home.pl",
"home.pl"
],
"subject_dn": "CN=*.home.pl",
"issuer_dn": "C=PL, O=home.pl S.A., CN=Certyfikat SSL",
"pubkey_bit_size": 2048,
"pubkey_algorithm": "RSA",
"tbs_fingerprint": "b807971c7c77a9b1d29605c36800a6de0b187340a2aa0086a88d70656f313845",
"fingerprint": "1c12ea601b0bf59cc7ba2a74fffdd93691d97bcd2af411df7f1b4e7dc36214d8",
"issuer": {
"common_name": [
"Certyfikat SSL"
],
"organization": [
"home.pl S.A."
],
"country": [
"PL"
]
},
"subject": {
"common_name": [
"*.home.pl"
]
},
"public_key": {
"key_algorithm": "RSA",
"rsa": {
"_encoding": {
"modulus": "DISPLAY_BASE64",
"exponent": "DISPLAY_BASE64"
},
"modulus": "5vsb3m8t53OmPOeuFMuLbTjRCOvJq87kcgnhz1EuMJPGFenPS+TqlgjPmDaTqyFIas1ouLzMA/WOXOA3oRsAKGJ9b/Bo9hb1JikVqjwIEMYrQQa8M9d4e0LrPr0Dv539XsfkOU+tOETU7isAaDtqmEaPaaHyMr2UgQHAIwN5WgYKrvGJKnk8199QNSV8Xq5bO5qxg6LMysAM6yicQIp1QrRgd6HqsgPb+kM51UFAkySCbU0JGdgSkUVmGatxALl/jpLcBGDTxFPFcPgrXOl2qe1Ub4OrXM/GCTgmDrEXOJPzhdnEHqI0fjfpT9JCDBs6e/ZKnlq1dAU/3IxiGavz5w==",
"exponent": "AAEAAQ==",
"length": 256
},
"fingerprint": "1a7e3e768f8709c2b3a45327e0af99ea1429f0ee8f081c085c3a271340b09ce7"
},
"signature": {
"signature_algorithm": "SHA256-RSA",
"self_signed": false
}
},
"chain": [
{
"fingerprint": "a95f23b52af10895886fb65323d29a9876ea7d396f805e4ca280d561c26e3dad",
"subject_dn": "C=PL, O=home.pl S.A., CN=Certyfikat SSL",
"issuer_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Global Services CA SHA2"
},
{
"fingerprint": "9e852c59dfc6fd6abd4e17ea80b5f4e56fc04192d107258d54da8a92528670d6",
"subject_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Global Services CA SHA2",
"issuer_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA"
},
{
"fingerprint": "5c58468d55f58e497e743982d2b50010b6d165374acf83a7d4a32db768c4408e",
"subject_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA",
"issuer_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA"
}
]
},
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "475c9302dc42b2751db9edcac3b74891",
"ja4s": "t130200_1303_a56c5b993250"
},
"transport_fingerprint": {
"raw": "31856,64,true,MSTNW,1460,false,false"
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "http",
"_encoding": {
"banner": "DISPLAY_UTF8",
"banner_hex": "DISPLAY_HEX"
},
"banner": "HTTP/1.1 302\r\nDate: <REDACTED>\r\nContent-Type: text/html\r\nContent-Length: 565\r\nConnection: keep-alive\r\nLocation: http://zse.com.pl\r\nServer: IdeaWebServer/6.2.0\r\nStatus: 302\r\n",
"banner_hashes": [
"sha256:dc4c5ba78d6bae350f1a5f94e3b6998a9ce9e8153b32c62d322763a5266a04e7"
],
"banner_hex": "485454502f312e31203330320d0a446174653a20203c52454441435445443e0d0a436f6e74656e742d547970653a20746578742f68746d6c0d0a436f6e74656e742d4c656e6774683a203536350d0a436f6e6e656374696f6e3a206b6565702d616c6976650d0a4c6f636174696f6e3a20687474703a2f2f7a73652e636f6d2e706c0d0a5365727665723a20496465615765625365727665722f362e322e300d0a5374617475733a203330320d0a",
"discovery_method": "PREDICTIVE_METHOD_7",
"extended_service_name": "HTTP",
"http": {
"request": {
"method": "GET",
"uri": "http://89.161.136.214/",
"headers": {
"User_Agent": [
"Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)"
],
"_encoding": {
"User_Agent": "DISPLAY_UTF8",
"Accept": "DISPLAY_UTF8"
},
"Accept": [
"*/*"
]
}
},
"response": {
"protocol": "HTTP/1.1",
"status_code": 302,
"headers": {
"Server": [
"IdeaWebServer/6.2.0"
],
"_encoding": {
"Server": "DISPLAY_UTF8",
"Content_Length": "DISPLAY_UTF8",
"Content_Type": "DISPLAY_UTF8",
"Location": "DISPLAY_UTF8",
"Status": "DISPLAY_UTF8",
"Connection": "DISPLAY_UTF8",
"Date": "DISPLAY_UTF8"
},
"Content_Length": [
"565"
],
"Content_Type": [
"text/html"
],
"Location": [
"http://zse.com.pl"
],
"Status": [
"302"
],
"Connection": [
"keep-alive"
],
"Date": [
"<REDACTED>"
]
},
"_encoding": {
"html_tags": "DISPLAY_UTF8",
"body": "DISPLAY_UTF8",
"body_hash": "DISPLAY_UTF8",
"html_title": "DISPLAY_UTF8"
},
"html_tags": [
"<title>Error 302</title>",
"<meta charset=\"utf-8\">",
"<meta http-equiv=\"X-UA-Compatible\" content=\"IE=edge\">",
"<meta name=\"viewport\" content=\"width=device-width, initial-scale=1\">"
],
"body_size": 565,
"body": "<!DOCTYPE html><html lang=\"en\"><head><meta charset=\"utf-8\"><meta http-equiv=\"X-UA-Compatible\" content=\"IE=edge\"><meta name=\"viewport\" content=\"width=device-width, initial-scale=1\"><title>Error 302</title><link href=\"/idea/static/style.css\" rel=\"stylesheet\"></head><body><div class=\"error-container\"><div class=\"error-text\"><h1>Error</h1></div><div class=\"error-text-strong\"><h1>302</h1></div><div class=\"error-text\"><h1>Moved</h1></div></div><div class=\"error-descr-container\"><p>The document has moved <A HREF=\"http://zse.com.pl\">here</A>.</p></div> </body></html>",
"body_hashes": [
"sha256:09f7f857595cf463fb23e518872c8e6c6448064ba27914a1e404dba6b2cd23d6",
"sha1:0748e4ee8048d19492cb9181041a91874ba85c5b"
],
"body_hash": "sha1:0748e4ee8048d19492cb9181041a91874ba85c5b",
"html_title": "Error 302"
},
"supports_http2": false
},
"observed_at": "2024-10-01T19:26:00.030876208Z",
"pending_removal_since": "2024-10-03T13:34:36.408249963Z",
"perspective_id": "PERSPECTIVE_HE",
"port": 80,
"service_name": "HTTP",
"software": [
{
"uniform_resource_identifier": "cpe:2.3:a:home.pl:idea_web_server:6.2.0:*:*:*:*:*:*:*",
"part": "a",
"vendor": "home.pl",
"product": "Idea Web Server",
"version": "6.2.0",
"source": "OSI_APPLICATION_LAYER"
}
],
"source_ip": "162.142.125.206",
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "pop3",
"_encoding": {
"banner": "DISPLAY_UTF8",
"certificate": "DISPLAY_HEX",
"banner_hex": "DISPLAY_HEX"
},
"banner": "+OK Dovecot ready.\r\n",
"banner_hashes": [
"sha256:095c6dbf7d6290d9c885271a78f82e11a7df7c9a8733d4e13236b47608e527c4"
],
"banner_hex": "2b4f4b20446f7665636f742072656164792e0d0a",
"certificate": "1c12ea601b0bf59cc7ba2a74fffdd93691d97bcd2af411df7f1b4e7dc36214d8",
"discovery_method": "IPV4_WALK_FULL_PRIORITY_1",
"extended_service_name": "POP3S",
"labels": [
"email"
],
"observed_at": "2024-10-04T04:06:07.761589439Z",
"pending_removal_since": "2024-10-04T08:20:57.684869713Z",
"perspective_id": "PERSPECTIVE_TATA",
"pop3": {
"_encoding": {
"banner": "DISPLAY_UTF8",
"start_tls": "DISPLAY_UTF8"
},
"banner": "+OK Dovecot ready.\r\n",
"start_tls": "+OK Begin TLS negotiation now.\r\n"
},
"port": 110,
"service_name": "POP3",
"software": [
{
"uniform_resource_identifier": "cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*",
"part": "a",
"vendor": "Dovecot",
"product": "Dovecot",
"other": {
"family": "Dovecot"
},
"source": "OSI_APPLICATION_LAYER"
}
],
"source_ip": "167.94.138.54",
"tls": {
"version_selected": "TLSv1_3",
"cipher_selected": "TLS_CHACHA20_POLY1305_SHA256",
"certificates": {
"_encoding": {
"leaf_fp_sha_256": "DISPLAY_HEX",
"chain_fps_sha_256": "DISPLAY_HEX"
},
"leaf_fp_sha_256": "1c12ea601b0bf59cc7ba2a74fffdd93691d97bcd2af411df7f1b4e7dc36214d8",
"chain_fps_sha_256": [
"a95f23b52af10895886fb65323d29a9876ea7d396f805e4ca280d561c26e3dad",
"9e852c59dfc6fd6abd4e17ea80b5f4e56fc04192d107258d54da8a92528670d6",
"5c58468d55f58e497e743982d2b50010b6d165374acf83a7d4a32db768c4408e"
],
"leaf_data": {
"names": [
"*.home.pl",
"home.pl"
],
"subject_dn": "CN=*.home.pl",
"issuer_dn": "C=PL, O=home.pl S.A., CN=Certyfikat SSL",
"pubkey_bit_size": 2048,
"pubkey_algorithm": "RSA",
"tbs_fingerprint": "b807971c7c77a9b1d29605c36800a6de0b187340a2aa0086a88d70656f313845",
"fingerprint": "1c12ea601b0bf59cc7ba2a74fffdd93691d97bcd2af411df7f1b4e7dc36214d8",
"issuer": {
"common_name": [
"Certyfikat SSL"
],
"organization": [
"home.pl S.A."
],
"country": [
"PL"
]
},
"subject": {
"common_name": [
"*.home.pl"
]
},
"public_key": {
"key_algorithm": "RSA",
"rsa": {
"_encoding": {
"modulus": "DISPLAY_BASE64",
"exponent": "DISPLAY_BASE64"
},
"modulus": "5vsb3m8t53OmPOeuFMuLbTjRCOvJq87kcgnhz1EuMJPGFenPS+TqlgjPmDaTqyFIas1ouLzMA/WOXOA3oRsAKGJ9b/Bo9hb1JikVqjwIEMYrQQa8M9d4e0LrPr0Dv539XsfkOU+tOETU7isAaDtqmEaPaaHyMr2UgQHAIwN5WgYKrvGJKnk8199QNSV8Xq5bO5qxg6LMysAM6yicQIp1QrRgd6HqsgPb+kM51UFAkySCbU0JGdgSkUVmGatxALl/jpLcBGDTxFPFcPgrXOl2qe1Ub4OrXM/GCTgmDrEXOJPzhdnEHqI0fjfpT9JCDBs6e/ZKnlq1dAU/3IxiGavz5w==",
"exponent": "AAEAAQ==",
"length": 256
},
"fingerprint": "1a7e3e768f8709c2b3a45327e0af99ea1429f0ee8f081c085c3a271340b09ce7"
},
"signature": {
"signature_algorithm": "SHA256-RSA",
"self_signed": false
}
},
"chain": [
{
"fingerprint": "a95f23b52af10895886fb65323d29a9876ea7d396f805e4ca280d561c26e3dad",
"subject_dn": "C=PL, O=home.pl S.A., CN=Certyfikat SSL",
"issuer_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Global Services CA SHA2"
},
{
"fingerprint": "9e852c59dfc6fd6abd4e17ea80b5f4e56fc04192d107258d54da8a92528670d6",
"subject_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Global Services CA SHA2",
"issuer_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA"
},
{
"fingerprint": "5c58468d55f58e497e743982d2b50010b6d165374acf83a7d4a32db768c4408e",
"subject_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA",
"issuer_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA"
}
]
},
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "475c9302dc42b2751db9edcac3b74891",
"ja4s": "t130200_1303_a56c5b993250"
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "imap",
"_encoding": {
"banner": "DISPLAY_UTF8",
"certificate": "DISPLAY_HEX",
"banner_hex": "DISPLAY_HEX"
},
"banner": "* OK [CAPABILITY IMAP4rev1 SASL-IR LOGIN-REFERRALS ID ENABLE IDLE LITERAL+ STARTTLS AUTH=PLAIN AUTH=LOGIN] Dovecot ready.\r\n",
"banner_hashes": [
"sha256:6bbb57521067d37a1d9f59c01b41df949b35ccc44edbf97bbbe2d0cdcb0e81a4"
],
"banner_hex": "2a204f4b205b4341504142494c49545920494d41503472657631205341534c2d4952204c4f47494e2d524546455252414c5320494420454e41424c452049444c45204c49544552414c2b205354415254544c5320415554483d504c41494e20415554483d4c4f47494e5d20446f7665636f742072656164792e0d0a",
"certificate": "1c12ea601b0bf59cc7ba2a74fffdd93691d97bcd2af411df7f1b4e7dc36214d8",
"discovery_method": "PREDICTIVE_METHOD_18",
"extended_service_name": "IMAPS",
"imap": {
"_encoding": {
"banner": "DISPLAY_UTF8"
},
"banner": "* OK [CAPABILITY IMAP4rev1 SASL-IR LOGIN-REFERRALS ID ENABLE IDLE LITERAL+ STARTTLS AUTH=PLAIN AUTH=LOGIN] Dovecot ready.\r\n",
"start_tls": "a001 OK Begin TLS negotiation now.\r\n"
},
"labels": [
"email"
],
"observed_at": "2024-10-04T00:58:52.452286429Z",
"perspective_id": "PERSPECTIVE_PCCW",
"port": 143,
"service_name": "IMAP",
"software": [
{
"uniform_resource_identifier": "cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*",
"part": "a",
"vendor": "Dovecot",
"product": "Dovecot",
"other": {
"family": "Dovecot"
},
"source": "OSI_APPLICATION_LAYER"
}
],
"source_ip": "199.45.154.128",
"tls": {
"version_selected": "TLSv1_3",
"cipher_selected": "TLS_CHACHA20_POLY1305_SHA256",
"certificates": {
"_encoding": {
"leaf_fp_sha_256": "DISPLAY_HEX",
"chain_fps_sha_256": "DISPLAY_HEX"
},
"leaf_fp_sha_256": "1c12ea601b0bf59cc7ba2a74fffdd93691d97bcd2af411df7f1b4e7dc36214d8",
"chain_fps_sha_256": [
"a95f23b52af10895886fb65323d29a9876ea7d396f805e4ca280d561c26e3dad",
"9e852c59dfc6fd6abd4e17ea80b5f4e56fc04192d107258d54da8a92528670d6",
"5c58468d55f58e497e743982d2b50010b6d165374acf83a7d4a32db768c4408e"
],
"leaf_data": {
"names": [
"*.home.pl",
"home.pl"
],
"subject_dn": "CN=*.home.pl",
"issuer_dn": "C=PL, O=home.pl S.A., CN=Certyfikat SSL",
"pubkey_bit_size": 2048,
"pubkey_algorithm": "RSA",
"tbs_fingerprint": "b807971c7c77a9b1d29605c36800a6de0b187340a2aa0086a88d70656f313845",
"fingerprint": "1c12ea601b0bf59cc7ba2a74fffdd93691d97bcd2af411df7f1b4e7dc36214d8",
"issuer": {
"common_name": [
"Certyfikat SSL"
],
"organization": [
"home.pl S.A."
],
"country": [
"PL"
]
},
"subject": {
"common_name": [
"*.home.pl"
]
},
"public_key": {
"key_algorithm": "RSA",
"rsa": {
"_encoding": {
"modulus": "DISPLAY_BASE64",
"exponent": "DISPLAY_BASE64"
},
"modulus": "5vsb3m8t53OmPOeuFMuLbTjRCOvJq87kcgnhz1EuMJPGFenPS+TqlgjPmDaTqyFIas1ouLzMA/WOXOA3oRsAKGJ9b/Bo9hb1JikVqjwIEMYrQQa8M9d4e0LrPr0Dv539XsfkOU+tOETU7isAaDtqmEaPaaHyMr2UgQHAIwN5WgYKrvGJKnk8199QNSV8Xq5bO5qxg6LMysAM6yicQIp1QrRgd6HqsgPb+kM51UFAkySCbU0JGdgSkUVmGatxALl/jpLcBGDTxFPFcPgrXOl2qe1Ub4OrXM/GCTgmDrEXOJPzhdnEHqI0fjfpT9JCDBs6e/ZKnlq1dAU/3IxiGavz5w==",
"exponent": "AAEAAQ==",
"length": 256
},
"fingerprint": "1a7e3e768f8709c2b3a45327e0af99ea1429f0ee8f081c085c3a271340b09ce7"
},
"signature": {
"signature_algorithm": "SHA256-RSA",
"self_signed": false
}
},
"chain": [
{
"fingerprint": "a95f23b52af10895886fb65323d29a9876ea7d396f805e4ca280d561c26e3dad",
"subject_dn": "C=PL, O=home.pl S.A., CN=Certyfikat SSL",
"issuer_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Global Services CA SHA2"
},
{
"fingerprint": "9e852c59dfc6fd6abd4e17ea80b5f4e56fc04192d107258d54da8a92528670d6",
"subject_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Global Services CA SHA2",
"issuer_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA"
},
{
"fingerprint": "5c58468d55f58e497e743982d2b50010b6d165374acf83a7d4a32db768c4408e",
"subject_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA",
"issuer_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA"
}
]
},
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "475c9302dc42b2751db9edcac3b74891",
"ja4s": "t130200_1303_a56c5b993250",
"versions": [
{
"tls_version": "TLSv1_3",
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "475c9302dc42b2751db9edcac3b74891",
"ja4s": "t130200_1303_a56c5b993250"
}
]
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "http",
"_encoding": {
"banner": "DISPLAY_UTF8",
"certificate": "DISPLAY_HEX",
"banner_hex": "DISPLAY_HEX"
},
"banner": "HTTP/1.1 302\r\nDate: <REDACTED>\r\nContent-Type: text/html\r\nContent-Length: 565\r\nConnection: keep-alive\r\nLocation: http://zse.com.pl\r\nServer: IdeaWebServer/6.2.0\r\nStatus: 302\r\n",
"banner_hashes": [
"sha256:dc4c5ba78d6bae350f1a5f94e3b6998a9ce9e8153b32c62d322763a5266a04e7"
],
"banner_hex": "485454502f312e31203330320d0a446174653a20203c52454441435445443e0d0a436f6e74656e742d547970653a20746578742f68746d6c0d0a436f6e74656e742d4c656e6774683a203536350d0a436f6e6e656374696f6e3a206b6565702d616c6976650d0a4c6f636174696f6e3a20687474703a2f2f7a73652e636f6d2e706c0d0a5365727665723a20496465615765625365727665722f362e322e300d0a5374617475733a203330320d0a",
"certificate": "1c12ea601b0bf59cc7ba2a74fffdd93691d97bcd2af411df7f1b4e7dc36214d8",
"discovery_method": "PREDICTIVE_METHOD_18",
"extended_service_name": "HTTPS",
"http": {
"request": {
"method": "GET",
"uri": "https://89.161.136.214/",
"headers": {
"User_Agent": [
"Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)"
],
"_encoding": {
"User_Agent": "DISPLAY_UTF8",
"Accept": "DISPLAY_UTF8"
},
"Accept": [
"*/*"
]
}
},
"response": {
"protocol": "HTTP/1.1",
"status_code": 302,
"headers": {
"Server": [
"IdeaWebServer/6.2.0"
],
"_encoding": {
"Server": "DISPLAY_UTF8",
"Content_Length": "DISPLAY_UTF8",
"Content_Type": "DISPLAY_UTF8",
"Location": "DISPLAY_UTF8",
"Status": "DISPLAY_UTF8",
"Connection": "DISPLAY_UTF8",
"Date": "DISPLAY_UTF8"
},
"Content_Length": [
"565"
],
"Content_Type": [
"text/html"
],
"Location": [
"http://zse.com.pl"
],
"Status": [
"302"
],
"Connection": [
"keep-alive"
],
"Date": [
"<REDACTED>"
]
},
"_encoding": {
"html_tags": "DISPLAY_UTF8",
"body": "DISPLAY_UTF8",
"body_hash": "DISPLAY_UTF8",
"html_title": "DISPLAY_UTF8"
},
"html_tags": [
"<title>Error 302</title>",
"<meta charset=\"utf-8\">",
"<meta http-equiv=\"X-UA-Compatible\" content=\"IE=edge\">",
"<meta name=\"viewport\" content=\"width=device-width, initial-scale=1\">"
],
"body_size": 565,
"body": "<!DOCTYPE html><html lang=\"en\"><head><meta charset=\"utf-8\"><meta http-equiv=\"X-UA-Compatible\" content=\"IE=edge\"><meta name=\"viewport\" content=\"width=device-width, initial-scale=1\"><title>Error 302</title><link href=\"/idea/static/style.css\" rel=\"stylesheet\"></head><body><div class=\"error-container\"><div class=\"error-text\"><h1>Error</h1></div><div class=\"error-text-strong\"><h1>302</h1></div><div class=\"error-text\"><h1>Moved</h1></div></div><div class=\"error-descr-container\"><p>The document has moved <A HREF=\"http://zse.com.pl\">here</A>.</p></div> </body></html>",
"body_hashes": [
"sha256:09f7f857595cf463fb23e518872c8e6c6448064ba27914a1e404dba6b2cd23d6",
"sha1:0748e4ee8048d19492cb9181041a91874ba85c5b"
],
"body_hash": "sha1:0748e4ee8048d19492cb9181041a91874ba85c5b",
"html_title": "Error 302"
},
"supports_http2": true
},
"observed_at": "2024-10-03T14:21:28.136587416Z",
"perspective_id": "PERSPECTIVE_NTT",
"port": 443,
"service_name": "HTTP",
"software": [
{
"uniform_resource_identifier": "cpe:2.3:a:home.pl:idea_web_server:6.2.0:*:*:*:*:*:*:*",
"part": "a",
"vendor": "home.pl",
"product": "Idea Web Server",
"version": "6.2.0",
"source": "OSI_APPLICATION_LAYER"
}
],
"source_ip": "206.168.34.47",
"tls": {
"version_selected": "TLSv1_3",
"cipher_selected": "TLS_AES_256_GCM_SHA384",
"certificates": {
"_encoding": {
"leaf_fp_sha_256": "DISPLAY_HEX",
"chain_fps_sha_256": "DISPLAY_HEX"
},
"leaf_fp_sha_256": "1c12ea601b0bf59cc7ba2a74fffdd93691d97bcd2af411df7f1b4e7dc36214d8",
"chain_fps_sha_256": [
"a95f23b52af10895886fb65323d29a9876ea7d396f805e4ca280d561c26e3dad",
"9e852c59dfc6fd6abd4e17ea80b5f4e56fc04192d107258d54da8a92528670d6",
"5c58468d55f58e497e743982d2b50010b6d165374acf83a7d4a32db768c4408e"
],
"leaf_data": {
"names": [
"*.home.pl",
"home.pl"
],
"subject_dn": "CN=*.home.pl",
"issuer_dn": "C=PL, O=home.pl S.A., CN=Certyfikat SSL",
"pubkey_bit_size": 2048,
"pubkey_algorithm": "RSA",
"tbs_fingerprint": "b807971c7c77a9b1d29605c36800a6de0b187340a2aa0086a88d70656f313845",
"fingerprint": "1c12ea601b0bf59cc7ba2a74fffdd93691d97bcd2af411df7f1b4e7dc36214d8",
"issuer": {
"common_name": [
"Certyfikat SSL"
],
"organization": [
"home.pl S.A."
],
"country": [
"PL"
]
},
"subject": {
"common_name": [
"*.home.pl"
]
},
"public_key": {
"key_algorithm": "RSA",
"rsa": {
"_encoding": {
"modulus": "DISPLAY_BASE64",
"exponent": "DISPLAY_BASE64"
},
"modulus": "5vsb3m8t53OmPOeuFMuLbTjRCOvJq87kcgnhz1EuMJPGFenPS+TqlgjPmDaTqyFIas1ouLzMA/WOXOA3oRsAKGJ9b/Bo9hb1JikVqjwIEMYrQQa8M9d4e0LrPr0Dv539XsfkOU+tOETU7isAaDtqmEaPaaHyMr2UgQHAIwN5WgYKrvGJKnk8199QNSV8Xq5bO5qxg6LMysAM6yicQIp1QrRgd6HqsgPb+kM51UFAkySCbU0JGdgSkUVmGatxALl/jpLcBGDTxFPFcPgrXOl2qe1Ub4OrXM/GCTgmDrEXOJPzhdnEHqI0fjfpT9JCDBs6e/ZKnlq1dAU/3IxiGavz5w==",
"exponent": "AAEAAQ==",
"length": 256
},
"fingerprint": "1a7e3e768f8709c2b3a45327e0af99ea1429f0ee8f081c085c3a271340b09ce7"
},
"signature": {
"signature_algorithm": "SHA256-RSA",
"self_signed": false
}
},
"chain": [
{
"fingerprint": "a95f23b52af10895886fb65323d29a9876ea7d396f805e4ca280d561c26e3dad",
"subject_dn": "C=PL, O=home.pl S.A., CN=Certyfikat SSL",
"issuer_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Global Services CA SHA2"
},
{
"fingerprint": "9e852c59dfc6fd6abd4e17ea80b5f4e56fc04192d107258d54da8a92528670d6",
"subject_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Global Services CA SHA2",
"issuer_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA"
},
{
"fingerprint": "5c58468d55f58e497e743982d2b50010b6d165374acf83a7d4a32db768c4408e",
"subject_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA",
"issuer_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA"
}
]
},
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "907bf3ecef1c987c889946b737b43de8",
"ja4s": "t130200_1302_234ea6891581",
"versions": [
{
"tls_version": "TLSv1_3",
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "907bf3ecef1c987c889946b737b43de8",
"ja4s": "t130200_1302_234ea6891581"
},
{
"tls_version": "TLSv1_2",
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "0debd3853f330c574b05e0b6d882dc27",
"ja4s": "t120200_c030_344b4dce5a52"
}
]
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "smtp",
"_encoding": {
"banner": "DISPLAY_UTF8",
"certificate": "DISPLAY_HEX",
"banner_hex": "DISPLAY_HEX"
},
"banner": "220 cloudserver022566.home.pl ESMTP Mailsystemx\r\n",
"banner_hashes": [
"sha256:3a8ad35ce21704c92cda3498c048e91c91848f37d4f8e3975d676c9ce00f156b"
],
"banner_hex": "32323020636c6f75647365727665723032323536362e686f6d652e706c2045534d5450204d61696c73797374656d780d0a",
"certificate": "1c12ea601b0bf59cc7ba2a74fffdd93691d97bcd2af411df7f1b4e7dc36214d8",
"discovery_method": "IPV4_WALK_FULL_PRIORITY_1",
"extended_service_name": "SMTP-STARTTLS",
"labels": [
"email"
],
"observed_at": "2024-10-03T20:47:03.101395424Z",
"perspective_id": "PERSPECTIVE_TATA",
"port": 587,
"service_name": "SMTP",
"smtp": {
"_encoding": {
"banner": "DISPLAY_UTF8",
"ehlo": "DISPLAY_UTF8",
"start_tls": "DISPLAY_UTF8"
},
"banner": "220 cloudserver022566.home.pl ESMTP Mailsystemx\r\n",
"ehlo": "250-cloudserver022566.home.pl\r\n250-PIPELINING\r\n250-SIZE 157286400\r\n250-ETRN\r\n250-STARTTLS\r\n250-AUTH PLAIN LOGIN\r\n250-ENHANCEDSTATUSCODES\r\n250-8BITMIME\r\n250-DSN\r\n250 CHUNKING\r\n",
"start_tls": "220 2.0.0 Ready to start TLS\r\n"
},
"source_ip": "167.94.138.58",
"tls": {
"version_selected": "TLSv1_3",
"cipher_selected": "TLS_CHACHA20_POLY1305_SHA256",
"certificates": {
"_encoding": {
"leaf_fp_sha_256": "DISPLAY_HEX",
"chain_fps_sha_256": "DISPLAY_HEX"
},
"leaf_fp_sha_256": "1c12ea601b0bf59cc7ba2a74fffdd93691d97bcd2af411df7f1b4e7dc36214d8",
"chain_fps_sha_256": [
"a95f23b52af10895886fb65323d29a9876ea7d396f805e4ca280d561c26e3dad",
"9e852c59dfc6fd6abd4e17ea80b5f4e56fc04192d107258d54da8a92528670d6",
"5c58468d55f58e497e743982d2b50010b6d165374acf83a7d4a32db768c4408e"
],
"leaf_data": {
"names": [
"*.home.pl",
"home.pl"
],
"subject_dn": "CN=*.home.pl",
"issuer_dn": "C=PL, O=home.pl S.A., CN=Certyfikat SSL",
"pubkey_bit_size": 2048,
"pubkey_algorithm": "RSA",
"tbs_fingerprint": "b807971c7c77a9b1d29605c36800a6de0b187340a2aa0086a88d70656f313845",
"fingerprint": "1c12ea601b0bf59cc7ba2a74fffdd93691d97bcd2af411df7f1b4e7dc36214d8",
"issuer": {
"common_name": [
"Certyfikat SSL"
],
"organization": [
"home.pl S.A."
],
"country": [
"PL"
]
},
"subject": {
"common_name": [
"*.home.pl"
]
},
"public_key": {
"key_algorithm": "RSA",
"rsa": {
"_encoding": {
"modulus": "DISPLAY_BASE64",
"exponent": "DISPLAY_BASE64"
},
"modulus": "5vsb3m8t53OmPOeuFMuLbTjRCOvJq87kcgnhz1EuMJPGFenPS+TqlgjPmDaTqyFIas1ouLzMA/WOXOA3oRsAKGJ9b/Bo9hb1JikVqjwIEMYrQQa8M9d4e0LrPr0Dv539XsfkOU+tOETU7isAaDtqmEaPaaHyMr2UgQHAIwN5WgYKrvGJKnk8199QNSV8Xq5bO5qxg6LMysAM6yicQIp1QrRgd6HqsgPb+kM51UFAkySCbU0JGdgSkUVmGatxALl/jpLcBGDTxFPFcPgrXOl2qe1Ub4OrXM/GCTgmDrEXOJPzhdnEHqI0fjfpT9JCDBs6e/ZKnlq1dAU/3IxiGavz5w==",
"exponent": "AAEAAQ==",
"length": 256
},
"fingerprint": "1a7e3e768f8709c2b3a45327e0af99ea1429f0ee8f081c085c3a271340b09ce7"
},
"signature": {
"signature_algorithm": "SHA256-RSA",
"self_signed": false
}
},
"chain": [
{
"fingerprint": "a95f23b52af10895886fb65323d29a9876ea7d396f805e4ca280d561c26e3dad",
"subject_dn": "C=PL, O=home.pl S.A., CN=Certyfikat SSL",
"issuer_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Global Services CA SHA2"
},
{
"fingerprint": "9e852c59dfc6fd6abd4e17ea80b5f4e56fc04192d107258d54da8a92528670d6",
"subject_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Global Services CA SHA2",
"issuer_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA"
},
{
"fingerprint": "5c58468d55f58e497e743982d2b50010b6d165374acf83a7d4a32db768c4408e",
"subject_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA",
"issuer_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA"
}
]
},
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "475c9302dc42b2751db9edcac3b74891",
"ja4s": "t130200_1303_a56c5b993250"
},
"transport_fingerprint": {
"raw": "31856,64,true,MSTNW,1460,false,false"
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "ftp",
"_encoding": {
"banner": "DISPLAY_UTF8",
"certificate": "DISPLAY_HEX",
"banner_hex": "DISPLAY_HEX"
},
"banner": "220-Idea FTP Server 6.2.0 (ekonomik2.home.pl) [89.161.136.214]\r\n220 Ready\r\n",
"banner_hashes": [
"sha256:747e3744d861021970e3176b64805a27d42c98205ec8208415d0939d1e351820"
],
"banner_hex": "3232302d49646561204654502053657276657220362e322e302028656b6f6e6f6d696b322e686f6d652e706c29205b38392e3136312e3133362e3231345d0d0a3232302052656164790d0a",
"certificate": "1c12ea601b0bf59cc7ba2a74fffdd93691d97bcd2af411df7f1b4e7dc36214d8",
"discovery_method": "IPV4_WALK_FULL_PRIORITY_1",
"extended_service_name": "FTPS",
"ftp": {
"_encoding": {
"banner": "DISPLAY_UTF8"
},
"banner": "220-Idea FTP Server 6.2.0 (ekonomik2.home.pl) [89.161.136.214]\r\n220 Ready\r\n",
"implicit_tls": true,
"status_code": 220,
"status_meaning": "Service ready for new user."
},
"labels": [
"file-sharing"
],
"observed_at": "2024-10-02T10:48:33.718611253Z",
"pending_removal_since": "2024-10-03T15:12:14.251985538Z",
"perspective_id": "PERSPECTIVE_TELIA",
"port": 990,
"service_name": "FTP",
"source_ip": "167.94.146.48",
"tls": {
"version_selected": "TLSv1_3",
"cipher_selected": "TLS_AES_256_GCM_SHA384",
"certificates": {
"_encoding": {
"leaf_fp_sha_256": "DISPLAY_HEX",
"chain_fps_sha_256": "DISPLAY_HEX"
},
"leaf_fp_sha_256": "1c12ea601b0bf59cc7ba2a74fffdd93691d97bcd2af411df7f1b4e7dc36214d8",
"chain_fps_sha_256": [
"a95f23b52af10895886fb65323d29a9876ea7d396f805e4ca280d561c26e3dad",
"9e852c59dfc6fd6abd4e17ea80b5f4e56fc04192d107258d54da8a92528670d6",
"5c58468d55f58e497e743982d2b50010b6d165374acf83a7d4a32db768c4408e"
],
"leaf_data": {
"names": [
"*.home.pl",
"home.pl"
],
"subject_dn": "CN=*.home.pl",
"issuer_dn": "C=PL, O=home.pl S.A., CN=Certyfikat SSL",
"pubkey_bit_size": 2048,
"pubkey_algorithm": "RSA",
"tbs_fingerprint": "b807971c7c77a9b1d29605c36800a6de0b187340a2aa0086a88d70656f313845",
"fingerprint": "1c12ea601b0bf59cc7ba2a74fffdd93691d97bcd2af411df7f1b4e7dc36214d8",
"issuer": {
"common_name": [
"Certyfikat SSL"
],
"organization": [
"home.pl S.A."
],
"country": [
"PL"
]
},
"subject": {
"common_name": [
"*.home.pl"
]
},
"public_key": {
"key_algorithm": "RSA",
"rsa": {
"_encoding": {
"modulus": "DISPLAY_BASE64",
"exponent": "DISPLAY_BASE64"
},
"modulus": "5vsb3m8t53OmPOeuFMuLbTjRCOvJq87kcgnhz1EuMJPGFenPS+TqlgjPmDaTqyFIas1ouLzMA/WOXOA3oRsAKGJ9b/Bo9hb1JikVqjwIEMYrQQa8M9d4e0LrPr0Dv539XsfkOU+tOETU7isAaDtqmEaPaaHyMr2UgQHAIwN5WgYKrvGJKnk8199QNSV8Xq5bO5qxg6LMysAM6yicQIp1QrRgd6HqsgPb+kM51UFAkySCbU0JGdgSkUVmGatxALl/jpLcBGDTxFPFcPgrXOl2qe1Ub4OrXM/GCTgmDrEXOJPzhdnEHqI0fjfpT9JCDBs6e/ZKnlq1dAU/3IxiGavz5w==",
"exponent": "AAEAAQ==",
"length": 256
},
"fingerprint": "1a7e3e768f8709c2b3a45327e0af99ea1429f0ee8f081c085c3a271340b09ce7"
},
"signature": {
"signature_algorithm": "SHA256-RSA",
"self_signed": false
}
},
"chain": [
{
"fingerprint": "a95f23b52af10895886fb65323d29a9876ea7d396f805e4ca280d561c26e3dad",
"subject_dn": "C=PL, O=home.pl S.A., CN=Certyfikat SSL",
"issuer_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Global Services CA SHA2"
},
{
"fingerprint": "9e852c59dfc6fd6abd4e17ea80b5f4e56fc04192d107258d54da8a92528670d6",
"subject_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Global Services CA SHA2",
"issuer_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA"
},
{
"fingerprint": "5c58468d55f58e497e743982d2b50010b6d165374acf83a7d4a32db768c4408e",
"subject_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA",
"issuer_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA"
}
]
},
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "15af977ce25de452b96affa2addb1036",
"ja4s": "t130200_1302_a56c5b993250",
"versions": [
{
"tls_version": "TLSv1_3",
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "15af977ce25de452b96affa2addb1036",
"ja4s": "t130200_1302_a56c5b993250"
},
{
"tls_version": "TLSv1_2",
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "0debd3853f330c574b05e0b6d882dc27",
"ja4s": "t120200_c030_344b4dce5a52"
},
{
"tls_version": "TLSv1_1",
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "ce815ab6e37127ab1cb9fe33d3ba250d",
"ja4s": "t110200_c014_344b4dce5a52"
}
]
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "imap",
"_encoding": {
"banner": "DISPLAY_UTF8",
"certificate": "DISPLAY_HEX",
"banner_hex": "DISPLAY_HEX"
},
"banner": "* OK [CAPABILITY IMAP4rev1 SASL-IR LOGIN-REFERRALS ID ENABLE IDLE LITERAL+ AUTH=PLAIN AUTH=LOGIN] Dovecot ready.\r\n",
"banner_hashes": [
"sha256:9fa634d81d68ef4e1e3b5f551a9e29411262794be17b6dff29abacd32d69acd2"
],
"banner_hex": "2a204f4b205b4341504142494c49545920494d41503472657631205341534c2d4952204c4f47494e2d524546455252414c5320494420454e41424c452049444c45204c49544552414c2b20415554483d504c41494e20415554483d4c4f47494e5d20446f7665636f742072656164792e0d0a",
"certificate": "1c12ea601b0bf59cc7ba2a74fffdd93691d97bcd2af411df7f1b4e7dc36214d8",
"discovery_method": "IPV4_WALK_FULL_PRIORITY_1",
"extended_service_name": "IMAPS",
"imap": {
"_encoding": {
"banner": "DISPLAY_UTF8"
},
"banner": "* OK [CAPABILITY IMAP4rev1 SASL-IR LOGIN-REFERRALS ID ENABLE IDLE LITERAL+ AUTH=PLAIN AUTH=LOGIN] Dovecot ready.\r\n"
},
"labels": [
"email"
],
"observed_at": "2024-10-04T02:30:22.113076833Z",
"pending_removal_since": "2024-10-04T06:09:22.493075696Z",
"perspective_id": "PERSPECTIVE_PCCW",
"port": 993,
"service_name": "IMAP",
"software": [
{
"uniform_resource_identifier": "cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*",
"part": "a",
"vendor": "Dovecot",
"product": "Dovecot",
"other": {
"family": "Dovecot"
},
"source": "OSI_APPLICATION_LAYER"
}
],
"source_ip": "199.45.154.155",
"tls": {
"version_selected": "TLSv1_3",
"cipher_selected": "TLS_CHACHA20_POLY1305_SHA256",
"certificates": {
"_encoding": {
"leaf_fp_sha_256": "DISPLAY_HEX",
"chain_fps_sha_256": "DISPLAY_HEX"
},
"leaf_fp_sha_256": "1c12ea601b0bf59cc7ba2a74fffdd93691d97bcd2af411df7f1b4e7dc36214d8",
"chain_fps_sha_256": [
"a95f23b52af10895886fb65323d29a9876ea7d396f805e4ca280d561c26e3dad",
"9e852c59dfc6fd6abd4e17ea80b5f4e56fc04192d107258d54da8a92528670d6",
"5c58468d55f58e497e743982d2b50010b6d165374acf83a7d4a32db768c4408e"
],
"leaf_data": {
"names": [
"*.home.pl",
"home.pl"
],
"subject_dn": "CN=*.home.pl",
"issuer_dn": "C=PL, O=home.pl S.A., CN=Certyfikat SSL",
"pubkey_bit_size": 2048,
"pubkey_algorithm": "RSA",
"tbs_fingerprint": "b807971c7c77a9b1d29605c36800a6de0b187340a2aa0086a88d70656f313845",
"fingerprint": "1c12ea601b0bf59cc7ba2a74fffdd93691d97bcd2af411df7f1b4e7dc36214d8",
"issuer": {
"common_name": [
"Certyfikat SSL"
],
"organization": [
"home.pl S.A."
],
"country": [
"PL"
]
},
"subject": {
"common_name": [
"*.home.pl"
]
},
"public_key": {
"key_algorithm": "RSA",
"rsa": {
"_encoding": {
"modulus": "DISPLAY_BASE64",
"exponent": "DISPLAY_BASE64"
},
"modulus": "5vsb3m8t53OmPOeuFMuLbTjRCOvJq87kcgnhz1EuMJPGFenPS+TqlgjPmDaTqyFIas1ouLzMA/WOXOA3oRsAKGJ9b/Bo9hb1JikVqjwIEMYrQQa8M9d4e0LrPr0Dv539XsfkOU+tOETU7isAaDtqmEaPaaHyMr2UgQHAIwN5WgYKrvGJKnk8199QNSV8Xq5bO5qxg6LMysAM6yicQIp1QrRgd6HqsgPb+kM51UFAkySCbU0JGdgSkUVmGatxALl/jpLcBGDTxFPFcPgrXOl2qe1Ub4OrXM/GCTgmDrEXOJPzhdnEHqI0fjfpT9JCDBs6e/ZKnlq1dAU/3IxiGavz5w==",
"exponent": "AAEAAQ==",
"length": 256
},
"fingerprint": "1a7e3e768f8709c2b3a45327e0af99ea1429f0ee8f081c085c3a271340b09ce7"
},
"signature": {
"signature_algorithm": "SHA256-RSA",
"self_signed": false
}
},
"chain": [
{
"fingerprint": "a95f23b52af10895886fb65323d29a9876ea7d396f805e4ca280d561c26e3dad",
"subject_dn": "C=PL, O=home.pl S.A., CN=Certyfikat SSL",
"issuer_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Global Services CA SHA2"
},
{
"fingerprint": "9e852c59dfc6fd6abd4e17ea80b5f4e56fc04192d107258d54da8a92528670d6",
"subject_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Global Services CA SHA2",
"issuer_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA"
},
{
"fingerprint": "5c58468d55f58e497e743982d2b50010b6d165374acf83a7d4a32db768c4408e",
"subject_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA",
"issuer_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA"
}
]
},
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "475c9302dc42b2751db9edcac3b74891",
"ja4s": "t130200_1303_a56c5b993250",
"versions": [
{
"tls_version": "TLSv1_3",
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "475c9302dc42b2751db9edcac3b74891",
"ja4s": "t130200_1303_a56c5b993250"
},
{
"tls_version": "TLSv1_2",
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "d25619cb77d3219fc9fc14cb6b35eacc",
"ja4s": "t120200_cca8_344b4dce5a52"
}
]
},
"transport_fingerprint": {
"raw": "31856,64,true,MSTNW,1460,false,false"
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "pop3",
"_encoding": {
"banner": "DISPLAY_UTF8",
"certificate": "DISPLAY_HEX",
"banner_hex": "DISPLAY_HEX"
},
"banner": "+OK Dovecot ready.\r\n",
"banner_hashes": [
"sha256:095c6dbf7d6290d9c885271a78f82e11a7df7c9a8733d4e13236b47608e527c4"
],
"banner_hex": "2b4f4b20446f7665636f742072656164792e0d0a",
"certificate": "1c12ea601b0bf59cc7ba2a74fffdd93691d97bcd2af411df7f1b4e7dc36214d8",
"discovery_method": "PREDICTIVE_METHOD_19",
"extended_service_name": "POP3S",
"labels": [
"email"
],
"observed_at": "2024-10-03T07:48:31.989999480Z",
"perspective_id": "PERSPECTIVE_NTT_2",
"pop3": {
"_encoding": {
"banner": "DISPLAY_UTF8"
},
"banner": "+OK Dovecot ready.\r\n"
},
"port": 995,
"service_name": "POP3",
"software": [
{
"uniform_resource_identifier": "cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*",
"part": "a",
"vendor": "Dovecot",
"product": "Dovecot",
"other": {
"family": "Dovecot"
},
"source": "OSI_APPLICATION_LAYER"
}
],
"source_ip": "199.45.155.98",
"tls": {
"version_selected": "TLSv1_3",
"cipher_selected": "TLS_CHACHA20_POLY1305_SHA256",
"certificates": {
"_encoding": {
"leaf_fp_sha_256": "DISPLAY_HEX",
"chain_fps_sha_256": "DISPLAY_HEX"
},
"leaf_fp_sha_256": "1c12ea601b0bf59cc7ba2a74fffdd93691d97bcd2af411df7f1b4e7dc36214d8",
"chain_fps_sha_256": [
"a95f23b52af10895886fb65323d29a9876ea7d396f805e4ca280d561c26e3dad",
"9e852c59dfc6fd6abd4e17ea80b5f4e56fc04192d107258d54da8a92528670d6",
"5c58468d55f58e497e743982d2b50010b6d165374acf83a7d4a32db768c4408e"
],
"leaf_data": {
"names": [
"*.home.pl",
"home.pl"
],
"subject_dn": "CN=*.home.pl",
"issuer_dn": "C=PL, O=home.pl S.A., CN=Certyfikat SSL",
"pubkey_bit_size": 2048,
"pubkey_algorithm": "RSA",
"tbs_fingerprint": "b807971c7c77a9b1d29605c36800a6de0b187340a2aa0086a88d70656f313845",
"fingerprint": "1c12ea601b0bf59cc7ba2a74fffdd93691d97bcd2af411df7f1b4e7dc36214d8",
"issuer": {
"common_name": [
"Certyfikat SSL"
],
"organization": [
"home.pl S.A."
],
"country": [
"PL"
]
},
"subject": {
"common_name": [
"*.home.pl"
]
},
"public_key": {
"key_algorithm": "RSA",
"rsa": {
"_encoding": {
"modulus": "DISPLAY_BASE64",
"exponent": "DISPLAY_BASE64"
},
"modulus": "5vsb3m8t53OmPOeuFMuLbTjRCOvJq87kcgnhz1EuMJPGFenPS+TqlgjPmDaTqyFIas1ouLzMA/WOXOA3oRsAKGJ9b/Bo9hb1JikVqjwIEMYrQQa8M9d4e0LrPr0Dv539XsfkOU+tOETU7isAaDtqmEaPaaHyMr2UgQHAIwN5WgYKrvGJKnk8199QNSV8Xq5bO5qxg6LMysAM6yicQIp1QrRgd6HqsgPb+kM51UFAkySCbU0JGdgSkUVmGatxALl/jpLcBGDTxFPFcPgrXOl2qe1Ub4OrXM/GCTgmDrEXOJPzhdnEHqI0fjfpT9JCDBs6e/ZKnlq1dAU/3IxiGavz5w==",
"exponent": "AAEAAQ==",
"length": 256
},
"fingerprint": "1a7e3e768f8709c2b3a45327e0af99ea1429f0ee8f081c085c3a271340b09ce7"
},
"signature": {
"signature_algorithm": "SHA256-RSA",
"self_signed": false
}
},
"chain": [
{
"fingerprint": "a95f23b52af10895886fb65323d29a9876ea7d396f805e4ca280d561c26e3dad",
"subject_dn": "C=PL, O=home.pl S.A., CN=Certyfikat SSL",
"issuer_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Global Services CA SHA2"
},
{
"fingerprint": "9e852c59dfc6fd6abd4e17ea80b5f4e56fc04192d107258d54da8a92528670d6",
"subject_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Global Services CA SHA2",
"issuer_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA"
},
{
"fingerprint": "5c58468d55f58e497e743982d2b50010b6d165374acf83a7d4a32db768c4408e",
"subject_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA",
"issuer_dn": "C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA"
}
]
},
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "475c9302dc42b2751db9edcac3b74891",
"ja4s": "t130200_1303_a56c5b993250"
},
"transport_fingerprint": {
"raw": "31856,64,true,MSTNW,1460,false,false"
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "mysql",
"_encoding": {
"banner": "DISPLAY_UTF8",
"certificate": "DISPLAY_HEX",
"banner_hex": "DISPLAY_HEX"
},
"banner": "5.7.42-46",
"banner_hashes": [
"sha256:69d023c1beb369087daeed7ef966cd4eced4e529ece2910262e3d99cdd1ee2aa"
],
"banner_hex": "352e372e34322d3436",
"certificate": "809b44cccf5b0d1966c410f915345c867d50e447ed3b5075bb92e098d43ee75e",
"discovery_method": "PREDICTIVE_METHOD_16",
"extended_service_name": "MYSQL",
"labels": [
"database"
],
"mysql": {
"protocol_version": 10,
"server_version": "5.7.42-46",
"connection_id": 21723802,
"_encoding": {
"auth_plugin_data": "DISPLAY_HEX"
},
"auth_plugin_data": "3772562c680f7325091c1613367c73634879206800",
"character_set": 9,
"status_flags": {
"SERVER_STATUS_AUTOCOMMIT": true
},
"capability_flags": {
"CLIENT_RESERVED": true,
"CLIENT_MULTI_STATEMENTS": true,
"CLIENT_PROTOCOL_41": true,
"CLIENT_CAN_HANDLE_EXPIRED_PASSWORDS": true,
"CLIENT_CONNECT_WITH_DB": true,
"CLIENT_SECURE_CONNECTION": true,
"CLIENT_ODBC": true,
"CLIENT_LONG_PASSWORD": true,
"CLIENT_IGNORE_SPACE": true,
"CLIENT_LOCAL_FILES": true,
"CLIENT_PLUGIN_AUTH_LEN_ENC_CLIENT_DATA": true,
"CLIENT_SSL": true,
"CLIENT_DEPRECATED_EOF": true,
"CLIENT_FOUND_ROWS": true,
"CLIENT_SESSION_TRACK": true,
"CLIENT_INTERACTIVE": true,
"CLIENT_IGNORE_SIGPIPE": true,
"CLIENT_PLUGIN_AUTH": true,
"CLIENT_MULTI_RESULTS": true,
"CLIENT_CONNECT_ATTRS": true,
"CLIENT_LONG_FLAG": true,
"CLIENT_TRANSACTIONS": true,
"CLIENT_COMPRESS": true,
"CLIENT_PS_MULTI_RESULTS": true,
"CLIENT_NO_SCHEMA": true
},
"auth_plugin_name": "mysql_native_password",
"error_code": 0
},
"observed_at": "2024-10-03T13:34:54.801080087Z",
"perspective_id": "PERSPECTIVE_TATA",
"port": 3306,
"service_name": "MYSQL",
"software": [
{
"uniform_resource_identifier": "cpe:2.3:a:oracle:mysql:5.7.42\\-46:*:*:*:*:*:*:*",
"part": "a",
"vendor": "Oracle",
"product": "MySQL",
"version": "5.7.42-46",
"other": {
"family": "MySQL"
},
"source": "OSI_APPLICATION_LAYER"
}
],
"source_ip": "167.94.138.127",
"tls": {
"version_selected": "TLSv1_2",
"cipher_selected": "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256",
"certificates": {
"_encoding": {
"leaf_fp_sha_256": "DISPLAY_HEX",
"chain_fps_sha_256": "DISPLAY_HEX"
},
"leaf_fp_sha_256": "809b44cccf5b0d1966c410f915345c867d50e447ed3b5075bb92e098d43ee75e",
"chain_fps_sha_256": [
"c25dee66dacb78f4d9a819a864d351ff01aa5f9a4cec1ed5cb80542c507ecc2c"
],
"leaf_data": {
"subject_dn": "CN=MySQL_Server_5.7.18-14_Auto_Generated_Server_Certificate",
"issuer_dn": "CN=MySQL_Server_5.7.18-14_Auto_Generated_CA_Certificate",
"pubkey_bit_size": 2048,
"pubkey_algorithm": "RSA",
"tbs_fingerprint": "388088a043efdaea522f724655c103cd8a5e2c699bd702a950ca465326646dff",
"fingerprint": "809b44cccf5b0d1966c410f915345c867d50e447ed3b5075bb92e098d43ee75e",
"issuer": {
"common_name": [
"MySQL_Server_5.7.18-14_Auto_Generated_CA_Certificate"
]
},
"subject": {
"common_name": [
"MySQL_Server_5.7.18-14_Auto_Generated_Server_Certificate"
]
},
"public_key": {
"key_algorithm": "RSA",
"rsa": {
"_encoding": {
"modulus": "DISPLAY_BASE64",
"exponent": "DISPLAY_BASE64"
},
"modulus": "8+falKjwrVL7SnhsOwsYG5GfPHC8BJ+C98D4QDo5hWMDdRwNseuuve+Sb7KfgJO3jx0cj9XZKf0cGt04yCpbe3yANxR4R7bDlUYhfWpwWGgI/qATkxyNLDTYfhZw/XV/DgjSbkW997EFQ8xOp13F5A33yRqVlwSqYYy2QOxkE7me5pjxYp469U9Ec+3IYhAeH764JoSnDFr1ModvzuW26FSAov6Nj8cQBUJ29GsCnf+IEdowZH3w/ZY5R+gOU0MMUdk90jmA2Qoksp9eUP7vy4FafHKDPTcNn2HenM77Ejz/vGf152h2rRpjljDrOgFAdm9vU77uwPi5k9rFM58M0Q==",
"exponent": "AAEAAQ==",
"length": 256
},
"fingerprint": "1e90cf233fb6d8071709d7f41f707ab2a18c263ca8813d8fdcbfaf063c90ada7"
},
"signature": {
"signature_algorithm": "SHA256-RSA",
"self_signed": false
}
},
"chain": [
{
"fingerprint": "c25dee66dacb78f4d9a819a864d351ff01aa5f9a4cec1ed5cb80542c507ecc2c",
"subject_dn": "CN=MySQL_Server_5.7.18-14_Auto_Generated_CA_Certificate",
"issuer_dn": "CN=MySQL_Server_5.7.18-14_Auto_Generated_CA_Certificate"
}
]
},
"server_key_exchange": {
"ec_params": {
"named_curve": 29
}
},
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "303951d4c50efb2e991652225a6f02b1",
"ja4s": "t120200_c02f_344b4dce5a52",
"versions": [
{
"tls_version": "TLSv1_2",
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "303951d4c50efb2e991652225a6f02b1",
"ja4s": "t120200_c02f_344b4dce5a52"
}
]
},
"transport_fingerprint": {
"raw": "31856,64,true,MSTNW,1460,false,false"
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "mysql",
"_encoding": {
"banner": "DISPLAY_UTF8",
"certificate": "DISPLAY_HEX",
"banner_hex": "DISPLAY_HEX"
},
"banner": "8.0.33-25",
"banner_hashes": [
"sha256:d5674732b9fa0f4c3ae138b0502269b6b1ee010cca46aededc4727b0a892f3a9"
],
"banner_hex": "382e302e33332d3235",
"certificate": "ebf5c582389cdf13a7ff9da697659e9f68e1a06a8622ff575c544c0cdbf6bb21",
"discovery_method": "PREDICTIVE_METHOD_30",
"extended_service_name": "MYSQL",
"labels": [
"database"
],
"mysql": {
"protocol_version": 10,
"server_version": "8.0.33-25",
"connection_id": 3367184,
"_encoding": {
"auth_plugin_data": "DISPLAY_HEX"
},
"auth_plugin_data": "40696c645d43732a7f3a3004165871425a350e5200",
"character_set": 45,
"status_flags": {
"SERVER_STATUS_AUTOCOMMIT": true
},
"capability_flags": {
"CLIENT_RESERVED": true,
"CLIENT_MULTI_STATEMENTS": true,
"CLIENT_PROTOCOL_41": true,
"CLIENT_CAN_HANDLE_EXPIRED_PASSWORDS": true,
"CLIENT_CONNECT_WITH_DB": true,
"CLIENT_SECURE_CONNECTION": true,
"CLIENT_ODBC": true,
"CLIENT_LONG_PASSWORD": true,
"CLIENT_IGNORE_SPACE": true,
"CLIENT_LOCAL_FILES": true,
"CLIENT_PLUGIN_AUTH_LEN_ENC_CLIENT_DATA": true,
"CLIENT_SSL": true,
"CLIENT_DEPRECATED_EOF": true,
"CLIENT_FOUND_ROWS": true,
"CLIENT_SESSION_TRACK": true,
"CLIENT_INTERACTIVE": true,
"CLIENT_IGNORE_SIGPIPE": true,
"CLIENT_PLUGIN_AUTH": true,
"CLIENT_MULTI_RESULTS": true,
"CLIENT_CONNECT_ATTRS": true,
"CLIENT_LONG_FLAG": true,
"CLIENT_TRANSACTIONS": true,
"CLIENT_COMPRESS": true,
"CLIENT_PS_MULTI_RESULTS": true,
"CLIENT_NO_SCHEMA": true
},
"auth_plugin_name": "mysql_native_password",
"error_code": 0
},
"observed_at": "2024-10-03T08:34:20.025776973Z",
"perspective_id": "PERSPECTIVE_NTT",
"port": 3380,
"service_name": "MYSQL",
"software": [
{
"uniform_resource_identifier": "cpe:2.3:a:oracle:mysql:8.0.33\\-25:*:*:*:*:*:*:*",
"part": "a",
"vendor": "Oracle",
"product": "MySQL",
"version": "8.0.33-25",
"other": {
"family": "MySQL"
},
"source": "OSI_APPLICATION_LAYER"
}
],
"source_ip": "206.168.34.47",
"tls": {
"version_selected": "TLSv1_3",
"cipher_selected": "TLS_CHACHA20_POLY1305_SHA256",
"certificates": {
"_encoding": {
"leaf_fp_sha_256": "DISPLAY_HEX",
"chain_fps_sha_256": "DISPLAY_HEX"
},
"leaf_fp_sha_256": "ebf5c582389cdf13a7ff9da697659e9f68e1a06a8622ff575c544c0cdbf6bb21",
"chain_fps_sha_256": [
"a2810bf48eb7fe4b85548da09b4029efd86527b1aeb234eff5b9c6596a1ae43d"
],
"leaf_data": {
"subject_dn": "CN=MySQL_Server_8.0.31-23_Auto_Generated_Server_Certificate",
"issuer_dn": "CN=MySQL_Server_8.0.31-23_Auto_Generated_CA_Certificate",
"pubkey_bit_size": 2048,
"pubkey_algorithm": "RSA",
"tbs_fingerprint": "a0ca3932fcc1e8154912f318ea362e93260d79a57c6cce9fc338743b613db8e4",
"fingerprint": "ebf5c582389cdf13a7ff9da697659e9f68e1a06a8622ff575c544c0cdbf6bb21",
"issuer": {
"common_name": [
"MySQL_Server_8.0.31-23_Auto_Generated_CA_Certificate"
]
},
"subject": {
"common_name": [
"MySQL_Server_8.0.31-23_Auto_Generated_Server_Certificate"
]
},
"public_key": {
"key_algorithm": "RSA",
"rsa": {
"_encoding": {
"modulus": "DISPLAY_BASE64",
"exponent": "DISPLAY_BASE64"
},
"modulus": "v0tofZkS5KV+pnl/As/IMIauae8OsmLkp25CtmUYuAkF2ZUN8guGTny1pK3uiiHEFbApzgZFJltRSlK+vjhS8q0LuQuvAf+HsjQbPb+XzNxZFtuuM8yMwIMpEaRJSClgerdUmOk+zAPyU2NjicZ8o+9JxbvrJvITxaH1nHBg2MyH06JEBTEbPjxvxy4Fd5S7VYrKpG9SuKzsM9/aX9JbnoY0Y4RCwdFhS/hlFLG14IdiFW6tAi2lMQ0WXkIhVjj5e0rh5TjsXDlGgStP89xIxWwz34qdLRcZSOxgDF4v+vW7JrAApoxGfv4w5m+a0OQsDeO1pbG06HAVtw5399Doyw==",
"exponent": "AAEAAQ==",
"length": 256
},
"fingerprint": "b1fe5dfa5f408da7c5a17a62acc9cc7a97f5c23a92954a3d598879dbd746d192"
},
"signature": {
"signature_algorithm": "SHA256-RSA",
"self_signed": false
}
},
"chain": [
{
"fingerprint": "a2810bf48eb7fe4b85548da09b4029efd86527b1aeb234eff5b9c6596a1ae43d",
"subject_dn": "CN=MySQL_Server_8.0.31-23_Auto_Generated_CA_Certificate",
"issuer_dn": "CN=MySQL_Server_8.0.31-23_Auto_Generated_CA_Certificate"
}
]
},
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "475c9302dc42b2751db9edcac3b74891",
"ja4s": "t130200_1303_a56c5b993250",
"versions": [
{
"tls_version": "TLSv1_3",
"_encoding": {
"ja3s": "DISPLAY_HEX"
},
"ja3s": "475c9302dc42b2751db9edcac3b74891",
"ja4s": "t130200_1303_a56c5b993250"
}
]
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "banner_grab",
"_encoding": {
"banner": "DISPLAY_UTF8",
"banner_hex": "DISPLAY_HEX"
},
"banner": "( success ( 2 2 ( ) ( edit-pipeline svndiff1 accepts-svndiff2 absent-entries commit-revprops depth log-revprops atomic-revprops partial-replay inherited-props ephemeral-txnprops file-revs-reverse list ) ) ) ",
"banner_hashes": [
"sha256:d7738f14893444b1ff239f17eee1c46ee55e16897b0d40ab92766b32f4d5723e"
],
"banner_hex": "28207375636365737320282032203220282029202820656469742d706970656c696e652073766e646966663120616363657074732d73766e646966663220616273656e742d656e747269657320636f6d6d69742d72657670726f7073206465707468206c6f672d72657670726f70732061746f6d69632d72657670726f7073207061727469616c2d7265706c617920696e686572697465642d70726f707320657068656d6572616c2d74786e70726f70732066696c652d726576732d72657665727365206c69737420292029202920",
"discovery_method": "PREDICTIVE_METHOD_23",
"extended_service_name": "UNKNOWN",
"observed_at": "2024-10-03T14:18:13.170354437Z",
"pending_removal_since": "2024-10-03T14:18:41.276010416Z",
"perspective_id": "PERSPECTIVE_HE",
"port": 3690,
"service_name": "UNKNOWN",
"source_ip": "162.142.125.39",
"transport_fingerprint": {
"raw": "31856,64,true,MSTNW,1460,false,false"
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "postgres",
"discovery_method": "IPV4_WALK_FULL_PRIORITY_1",
"extended_service_name": "POSTGRES",
"labels": [
"database"
],
"observed_at": "2024-10-03T23:44:59.564506836Z",
"perspective_id": "PERSPECTIVE_PCCW",
"port": 5432,
"postgres": {
"supported_versions": "FATAL: unsupported frontend protocol 0.0: server supports 2.0 to 3.0",
"protocol_error": {
"line": "2137",
"message": "unsupported frontend protocol 255.255: server supports 2.0 to 3.0",
"file": "postmaster.c",
"severity_v": "FATAL",
"code": "0A000",
"routine": "ProcessStartupPacket",
"severity": "FATAL"
},
"startup_error": {
"line": "2287",
"message": "no PostgreSQL user name specified in startup packet",
"file": "postmaster.c",
"severity_v": "FATAL",
"code": "28000",
"routine": "ProcessStartupPacket",
"severity": "FATAL"
}
},
"service_name": "POSTGRES",
"software": [
{
"uniform_resource_identifier": "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*",
"part": "a",
"vendor": "Postgresql",
"product": "Postgresql",
"source": "OSI_APPLICATION_LAYER"
}
],
"source_ip": "199.45.154.114",
"transport_fingerprint": {
"raw": "31856,64,true,MSTNW,1460,false,false"
},
"transport_protocol": "TCP",
"truncated": false
},
{
"_decoded": "ssh",
"_encoding": {
"banner": "DISPLAY_UTF8",
"banner_hex": "DISPLAY_HEX"
},
"banner": "SSH-2.0-HomeSSH-v1.2",
"banner_hashes": [
"sha256:aa9021c894a782228f0df246f2c6b0b1632a2dcbdee94ec6eb073f28609e56ae"
],
"banner_hex": "5353482d322e302d486f6d655353482d76312e32",
"discovery_method": "IPV4_WALK_FULL_PRIORITY_1",
"extended_service_name": "SSH",
"labels": [
"remote-access"
],
"observed_at": "2024-10-04T01:36:34.800422792Z",
"pending_removal_since": "2024-10-04T07:04:42.406347482Z",
"perspective_id": "PERSPECTIVE_TATA",
"port": 22222,
"service_name": "SSH",
"source_ip": "167.94.138.58",
"ssh": {
"endpoint_id": {
"_encoding": {
"raw": "DISPLAY_UTF8"
},
"raw": "SSH-2.0-HomeSSH-v1.2",
"protocol_version": "2.0",
"software_version": "HomeSSH-v1.2"
},
"kex_init_message": {
"kex_algorithms": [
"ecdh-sha2-nistp256",
"diffie-hellman-group14-sha1"
],
"host_key_algorithms": [
"ecdsa-sha2-nistp256",
"rsa-sha2-512",
"rsa-sha2-256",
"ssh-rsa",
"ssh-dss"
],
"client_to_server_ciphers": [
"[email protected]",
"[email protected]",
"aes256-ctr",
"aes192-ctr",
"aes128-ctr",
"aes256-cbc",
"aes192-cbc",
"aes128-cbc",
"3des-cbc"
],
"server_to_client_ciphers": [
"aes256-ctr",
"aes192-ctr",
"aes128-ctr"
],
"client_to_server_macs": [
"[email protected]",
"[email protected]",
"[email protected]",
"hmac-sha2-256",
"hmac-sha2-512",
"hmac-sha1"
],
"server_to_client_macs": [
"[email protected]",
"[email protected]",
"[email protected]",
"hmac-sha2-256",
"hmac-sha2-512",
"hmac-sha1"
],
"client_to_server_compression": [
"none"
],
"server_to_client_compression": [
"none"
],
"first_kex_follows": false
},
"algorithm_selection": {
"kex_algorithm": "ecdh-sha2-nistp256",
"host_key_algorithm": "ecdsa-sha2-nistp256",
"client_to_server_alg_group": {
"cipher": "aes128-ctr",
"mac": "hmac-sha2-256",
"compression": "none"
},
"server_to_client_alg_group": {
"cipher": "aes128-ctr",
"mac": "hmac-sha2-256",
"compression": "none"
}
},
"server_host_key": {
"fingerprint_sha256": "f9b28551cacfd129cca9106bed5d7e2ada1eb61330af29349c51e17fb664819f",
"ecdsa_public_key": {
"_encoding": {
"b": "DISPLAY_BASE64",
"gx": "DISPLAY_BASE64",
"gy": "DISPLAY_BASE64",
"n": "DISPLAY_BASE64",
"p": "DISPLAY_BASE64",
"x": "DISPLAY_BASE64",
"y": "DISPLAY_BASE64"
},
"b": "WsY12Ko6k+ez671VdpiGvGUdBrDMU7D2O848PifSYEs=",
"curve": "P-256",
"gx": "axfR8uEsQkf4vOblY6RA8ncDfYEt6zOg9KE5RdiYwpY=",
"gy": "T+NC4v4af5uO5+tKfA+eFivOM1drMV7Oy7ZAaDe/UfU=",
"length": 256,
"n": "/////wAAAAD//////////7zm+q2nF56E87nKwvxjJVE=",
"p": "/////wAAAAEAAAAAAAAAAAAAAAD///////////////8=",
"x": "KIT5AWL4NZwBtclOy0V0e0xdqVSiKJ4RFuzgY8ZDirk=",
"y": "qAlN3/ib96TILQKdazmuyGpDkPs1B3ngGCkuWpK2Qs8="
}
},
"hassh_fingerprint": "f0c354503999219c5dc8e5c1a3ca032f"
},
"transport_protocol": "TCP",
"truncated": false
}
],
"location": {
"continent": "Europe",
"country": "Poland",
"country_code": "PL",
"city": "Warsaw",
"postal_code": "00-002",
"timezone": "Europe/Warsaw",
"province": "Mazovia",
"coordinates": {
"latitude": 52.22977,
"longitude": 21.01178
}
},
"location_updated_at": "2024-09-26T12:36:15.559627899Z",
"autonomous_system": {
"asn": 12824,
"description": "HOMEPL-AS",
"bgp_prefix": "89.161.128.0/17",
"name": "HOMEPL-AS",
"country_code": "PL"
},
"autonomous_system_updated_at": "2024-09-26T12:36:15.560101696Z",
"whois": {
"network": {
"handle": "HOMEPL",
"name": "home.pl webhosting farm - static allocation",
"cidrs": [
"89.161.128.0/18"
],
"created": "2006-02-15T00:00:00Z",
"updated": "2009-07-08T00:00:00Z"
},
"organization": {
"handle": "ORG-HA12-RIPE",
"name": "home.pl S.A.",
"address": "ul. Zbozowa 4\\n70-653\\nSzczecin\\nPOLAND",
"abuse_contacts": [
{
"handle": "HA2866-RIPE",
"name": "home.pl abuse",
"email": "[email protected]"
}
],
"admin_contacts": [
{
"handle": "HNA8-RIPE",
"name": "home.pl Network Administrators",
"email": "[email protected]"
}
]
}
},
"dns": {
"names": [
"cloudserver022566.home.pl"
],
"records": {
"cloudserver022566.home.pl": {
"record_type": "A",
"resolved_at": "2024-09-18T01:03:35.024934585Z"
}
},
"reverse_dns": {
"names": [
"cloudserver022566.home.pl"
],
"resolved_at": "2024-09-22T17:01:26.265220075Z"
}
},
"last_updated_at": "2024-10-04T08:21:13.396Z",
"labels": [
"database",
"email",
"file-sharing",
"remote-access"
]
}