130.185.73.6

Basic Information

Network
PARVASYSTEM (IR)
Routing
130.185.73.0/24 via AS7018 , AS1299 , AS29049 , AS49666 , AS41689 , AS43754 , AS60631 AS60631 AS60631 AS60631 AS60631
Protocols
80/HTTP, 3306/MYSQL, 993/IMAPS, 465/SMTP, 995/POP3S, 25/SMTP, 110/POP3, 21/FTP, 143/IMAP, 53/DNS, 587/SMTP, 443/HTTPS, 22/SSH, 4190/BANNER
Tags
ftp http https database pop3s smtp imaps pop3 ssh dns mysql imap

80/HTTP


Details Go

GET /

Server
Apache httpd 2
Status Line
200 OK
GET /
[view page]

443/HTTPS


Details Go

GET /

Server
Apache httpd 2
Status Line
200 OK
GET /
[view page]

Chrome TLS Handshake

Version
TLSv1.2
Cipher Suite
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xC02F)

Heartbleed

Heartbleed
Heartbeat Enabled. Immune to Heartbleed.

Cryptographic Configuration

Export DHE
False
Export RSA
False
DHE Support
True

Certificate Chain

9856e97a177c34463d71d94f45915ec1bfb06f1db3710940cf614cb6ff5480fe
C=US, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]
C=US, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]

21/FTP


Details

Banner Grab

Server
Pure-FTPd
Banner:
220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------
220-You are user number 1 of 50 allowed.
220-Local time is now 12:24. Server port: 21.
220-This is a private system - No anonymous login
220-IPv6 connections are also welcome on this server.
220 You will be disconnected after 15 minutes of inactivity.

22/SSH


Details

SSHv2 Handshake

Server
OpenSSH 7.4
Banner
SSH-2.0-OpenSSH_7.4

Host Key

Algorithm
ecdsa-sha2-nistp256
Fingerprint
c1b7a880c17df474fccea765063e5df404b011c505014bf2b353e34fb9fe23b5

Negotiated Algorithm

Key Exchange
[email protected]
Symmetric Cipher
aes128-ctr [] | aes128-ctr []
MAC
hmac-sha2-256 [] | hmac-sha2-256 []

25/SMTP


Details

Banner Grab and StartTLS Initiation

Server
Exim
Banner
220 srv120985.sanatechco.com ESMTP Exim 4.94 Sun, 24 Oct 2021 00:05:07 +0330
EHLO
250-srv120985.sanatechco.com Hello worker-07.sfj.censys-scanner.com [192.35.168.112]
250-SIZE 52428800
250-8BITMIME
250-PIPELINING
250-X_PIPE_CONNECT
250-AUTH PLAIN LOGIN
250-STARTTLS
250 HELP
STARTTLS
220 TLS go ahead

TLS Handshake

Version
TLSv1.2
Cipher Suite
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xC02F)

Certificate Chain

106418516098a945dd779c720b526b1452f467c837545610fec518173a06a910
C=GB, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]
C=GB, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]

465/SMTP


Details

Banner Grab

Banner
220 srv120985.sanatechco.com ESMTP Exim 4.94 Tue, 19 Oct 2021 09:54:39 +0330

TLS Handshake

Version
TLSv1.2
Cipher Suite
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xC02F)

Certificate Chain

106418516098a945dd779c720b526b1452f467c837545610fec518173a06a910
C=GB, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]
C=GB, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]

587/SMTP


Details

Banner Grab and StartTLS Initiation

Server
Exim
Banner
220 srv120985.sanatechco.com ESMTP Exim 4.94 Sat, 23 Oct 2021 07:34:19 +0330
EHLO
250-srv120985.sanatechco.com Hello worker-08.sfj.censys-scanner.com [192.35.168.128]
250-SIZE 52428800
250-8BITMIME
250-PIPELINING
250-X_PIPE_CONNECT
250-AUTH PLAIN LOGIN
250-STARTTLS
250 HELP
STARTTLS
220 TLS go ahead

TLS Handshake

Version
TLSv1.2
Cipher Suite
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xC02F)

Certificate Chain

106418516098a945dd779c720b526b1452f467c837545610fec518173a06a910
C=GB, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]
C=GB, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]

53/DNS


Details

Open Resolver Query

Open Resolver
False

110/POP3


Details

Banner Grab and StartTLS Initiation

Server
Dovecot
Banner
+OK Dovecot DA ready.
STARTTLS
+OK Begin TLS negotiation now.

TLS Handshake

Version
TLSv1.2
Cipher Suite
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xC02F)

Certificate Chain

106418516098a945dd779c720b526b1452f467c837545610fec518173a06a910
C=GB, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]
C=GB, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]

143/IMAP


Details

Banner Grab and StartTLS Initiation

Server
Dovecot
Banner
* OK [CAPABILITY IMAP4rev1 SASL-IR LOGIN-REFERRALS ID ENABLE IDLE LITERAL+ STARTTLS AUTH=PLAIN] Dovecot DA ready.
STARTTLS
a001 OK Begin TLS negotiation now.

TLS Handshake

Version
TLSv1.2
Cipher Suite
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xC02F)

Certificate Chain

106418516098a945dd779c720b526b1452f467c837545610fec518173a06a910
C=GB, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]
C=GB, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]

993/IMAPS


Details

Banner Grab

Banner
* OK [CAPABILITY IMAP4rev1 SASL-IR LOGIN-REFERRALS ID ENABLE IDLE LITERAL+ AUTH=PLAIN] Dovecot DA ready.

TLS Handshake

Version
TLSv1.2
Cipher Suite
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xC02F)

Certificate Chain

106418516098a945dd779c720b526b1452f467c837545610fec518173a06a910
C=GB, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]
C=GB, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]

995/POP3S


Details

Banner Grab

Banner
+OK Dovecot DA ready.

TLS Handshake

Version
TLSv1.2
Cipher Suite
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xC02F)

Certificate Chain

106418516098a945dd779c720b526b1452f467c837545610fec518173a06a910
C=GB, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]
C=GB, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]

3306/MySQL


Details

Banner Grab

Version
(Unknown)
Protocol Version
0
Error Code
1130
Error
ER_HOST_NOT_PRIVILEGED
Error Message
Host 'worker-04.sfj.censys-scanner.com' is not allowed to connect to this MySQL server

4190/BANNER View Only


Details

Banner Info

Port
4190
Protocol
TCP
Decoded Banner
"IMPLEMENTATION" "Dovecot Pigeonhole"
"SIEVE" "fileinto reject envelope encoded-character vacation subaddress comparator-i;ascii-numeric relational regex imap4flags copy include variables body enotify environment mailbox date index ihave duplicate mime foreverypart extracttext"
"NOTIFY" "mailto"
"SASL" "PLAIN"
"STARTTLS"
"VERSION" "1.0"
OK "Dovecot DA ready."
NO "Error in MANAGESIEVE command received by server."

Geographic Location

Country
Iran (IR)
Lat/Long
35.698, 51.4115
Timezone
Asia/Tehran