31.31.198.204

Basic Information

Network
AS-REG (RU)
Routing
31.31.198.0/24 via AS11164 , AS3491 , AS20485 , AS20485 , AS57724 , AS39561 , AS197695
Protocols
80/HTTP, 3306/MYSQL, 8080/HTTP, 993/IMAPS, 465/SMTP, 995/POP3S, 25/SMTP, 110/POP3, 21/FTP, 143/IMAP, 53/DNS, 587/SMTP, 443/HTTPS, 22/SSH, 4190/BANNER, 7081/BANNER, 7082/BANNER, 8081/BANNER, 8443/BANNER, 8880/BANNER
Tags
ftp http dns embedded database pop3s smtp imaps pop3 ssh https mysql imap

80/HTTP


Details Go

GET /

Server
nginx
Status Line
200 OK
Page Title
Домен не добавлен в панели
GET /
[view page]

8080/HTTP


Details Go

GET /

Server
Apache httpd
Status Line
200 OK
Page Title
Домен не добавлен в панели
GET /
[view page]

443/HTTPS


Details Go

GET /

Server
nginx
Status Line
200 OK
Page Title
Домен не добавлен в панели
GET /
[view page]

Chrome TLS Handshake

Version
TLSv1.2
Cipher Suite
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xC02F)
Browser Trusted
True

Heartbleed

Heartbleed
Heartbeat Disabled (OK)

Cryptographic Configuration

Export DHE
False
Export RSA
False
DHE Support
False

Certificate Chain

923deca03aa9e5e13d7dca428c1ed5122eca9a29b948d765706c1ce2dd83cc44
CN=*.hosting.reg.ru
C=BE, O=GlobalSign nv-sa, CN=AlphaSSL CA - SHA256 - G2
ee793643199474ed60efdc8ccde4d37445921683593aa751bbf8ee491a391e97
C=BE, O=GlobalSign nv-sa, CN=AlphaSSL CA - SHA256 - G2
C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA

21/FTP


Details

Banner Grab

Banner:
220 ProFTPD Server (ProFTPD) [31.31.198.204]

22/SSH


Details

SSHv2 Handshake

Server
Dropbear SSH 2019.78
Banner
SSH-2.0-dropbear_2019.78

Host Key

Algorithm
ecdsa-sha2-nistp256
Fingerprint
6681c5c43ed81a267bf70d59cedbbfa4a27ad719c4f4fb582ab7594fc2455206

Negotiated Algorithm

Key Exchange
[email protected]
Symmetric Cipher
aes128-ctr [] | aes128-ctr []
MAC
hmac-sha2-256 [] | hmac-sha2-256 []

25/SMTP


Details

Banner Grab and StartTLS Initiation

Server
Postfix
Banner
220 spl90.hosting.reg.ru ESMTP Postfix
EHLO
250-spl90.hosting.reg.ru
250-PIPELINING
250-SIZE 52428800
250-ETRN
250-STARTTLS
250-AUTH CRAM-MD5 PLAIN LOGIN
250-ENHANCEDSTATUSCODES
250-8BITMIME
250-DSN
250 CHUNKING
STARTTLS
220 2.0.0 Ready to start TLS

TLS Handshake

Version
TLSv1.2
Cipher Suite
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xC02F)
Browser Trusted
True

Certificate Chain

923deca03aa9e5e13d7dca428c1ed5122eca9a29b948d765706c1ce2dd83cc44
CN=*.hosting.reg.ru
C=BE, O=GlobalSign nv-sa, CN=AlphaSSL CA - SHA256 - G2
ee793643199474ed60efdc8ccde4d37445921683593aa751bbf8ee491a391e97
C=BE, O=GlobalSign nv-sa, CN=AlphaSSL CA - SHA256 - G2
C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA

465/SMTP


Details

Banner Grab

Banner
220 spl90.hosting.reg.ru ESMTP Postfix

TLS Handshake

Version
TLSv1.2
Cipher Suite
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xC02F)
Browser Trusted
True

Certificate Chain

923deca03aa9e5e13d7dca428c1ed5122eca9a29b948d765706c1ce2dd83cc44
CN=*.hosting.reg.ru
C=BE, O=GlobalSign nv-sa, CN=AlphaSSL CA - SHA256 - G2

587/SMTP


Details

Banner Grab and StartTLS Initiation

Server
Postfix
Banner
220 spl90.hosting.reg.ru ESMTP Postfix
EHLO
250-spl90.hosting.reg.ru
250-PIPELINING
250-SIZE 52428800
250-ETRN
250-STARTTLS
250-ENHANCEDSTATUSCODES
250-8BITMIME
250-DSN
250 CHUNKING
STARTTLS
220 2.0.0 Ready to start TLS

TLS Handshake

Version
TLSv1.2
Cipher Suite
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xC02F)
Browser Trusted
True

Certificate Chain

923deca03aa9e5e13d7dca428c1ed5122eca9a29b948d765706c1ce2dd83cc44
CN=*.hosting.reg.ru
C=BE, O=GlobalSign nv-sa, CN=AlphaSSL CA - SHA256 - G2
ee793643199474ed60efdc8ccde4d37445921683593aa751bbf8ee491a391e97
C=BE, O=GlobalSign nv-sa, CN=AlphaSSL CA - SHA256 - G2
C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA

53/DNS


Details

Open Resolver Query

Open Resolver
False

110/POP3


Details

Banner Grab and StartTLS Initiation

Server
Dovecot
Banner
+OK Dovecot ready. <[email protected]>
STARTTLS
+OK Begin TLS negotiation now.

TLS Handshake

Version
TLSv1.2
Cipher Suite
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xC02F)
Browser Trusted
True

Certificate Chain

923deca03aa9e5e13d7dca428c1ed5122eca9a29b948d765706c1ce2dd83cc44
CN=*.hosting.reg.ru
C=BE, O=GlobalSign nv-sa, CN=AlphaSSL CA - SHA256 - G2
ee793643199474ed60efdc8ccde4d37445921683593aa751bbf8ee491a391e97
C=BE, O=GlobalSign nv-sa, CN=AlphaSSL CA - SHA256 - G2
C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA

143/IMAP


Details

Banner Grab and StartTLS Initiation

Server
Dovecot
Banner
* OK [CAPABILITY IMAP4rev1 SASL-IR LOGIN-REFERRALS ID ENABLE IDLE LITERAL+ STARTTLS AUTH=PLAIN AUTH=LOGIN AUTH=DIGEST-MD5 AUTH=CRAM-MD5] Dovecot ready.
STARTTLS
a001 OK Begin TLS negotiation now.

TLS Handshake

Version
TLSv1.2
Cipher Suite
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xC02F)
Browser Trusted
True

Certificate Chain

923deca03aa9e5e13d7dca428c1ed5122eca9a29b948d765706c1ce2dd83cc44
CN=*.hosting.reg.ru
C=BE, O=GlobalSign nv-sa, CN=AlphaSSL CA - SHA256 - G2
ee793643199474ed60efdc8ccde4d37445921683593aa751bbf8ee491a391e97
C=BE, O=GlobalSign nv-sa, CN=AlphaSSL CA - SHA256 - G2
C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA

993/IMAPS


Details

Banner Grab

Banner
* OK [CAPABILITY IMAP4rev1 SASL-IR LOGIN-REFERRALS ID ENABLE IDLE LITERAL+ AUTH=PLAIN AUTH=LOGIN AUTH=DIGEST-MD5 AUTH=CRAM-MD5] Dovecot ready.

TLS Handshake

Version
TLSv1.2
Cipher Suite
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xC02F)
Browser Trusted
True

Certificate Chain

923deca03aa9e5e13d7dca428c1ed5122eca9a29b948d765706c1ce2dd83cc44
CN=*.hosting.reg.ru
C=BE, O=GlobalSign nv-sa, CN=AlphaSSL CA - SHA256 - G2
ee793643199474ed60efdc8ccde4d37445921683593aa751bbf8ee491a391e97
C=BE, O=GlobalSign nv-sa, CN=AlphaSSL CA - SHA256 - G2
C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA

995/POP3S


Details

Banner Grab

Banner
+OK Dovecot ready. <[email protected]u>

TLS Handshake

Version
TLSv1.2
Cipher Suite
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xC02F)
Browser Trusted
True

Certificate Chain

923deca03aa9e5e13d7dca428c1ed5122eca9a29b948d765706c1ce2dd83cc44
CN=*.hosting.reg.ru
C=BE, O=GlobalSign nv-sa, CN=AlphaSSL CA - SHA256 - G2
ee793643199474ed60efdc8ccde4d37445921683593aa751bbf8ee491a391e97
C=BE, O=GlobalSign nv-sa, CN=AlphaSSL CA - SHA256 - G2
C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA

3306/MySQL


Details

Banner Grab

Version
5.7.27-30
Protocol Version
10

TLS Handshake

Version
TLSv1.2
Cipher Suite
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xC02F)

Certificate Chain

b499fabc9be4614baa032ee1e558ec7a805df2e6f7ffb874e5e1e4703a8f3354
CN=MySQL_Server_5.7.27-30_Auto_Generated_Server_Certificate
CN=MySQL_Server_5.7.27-30_Auto_Generated_CA_Certificate
fbe60f394c064d5fec76bcb6280cafa9edf1f0be392b2ff4cecffc31d4470253
CN=MySQL_Server_5.7.27-30_Auto_Generated_CA_Certificate
CN=MySQL_Server_5.7.27-30_Auto_Generated_CA_Certificate

4190/BANNER View Only


Details

Banner Info

Port
4190
Protocol
TCP
Decoded Banner
"IMPLEMENTATION" "Dovecot Pigeonhole"
"SIEVE" "fileinto reject envelope encoded-character vacation subaddress comparator-i;ascii-numeric relational regex imap4flags copy include variables body enotify environment mailbox date index ihave duplicate mime foreverypart extracttext imapflags notify"
"NOTIFY" "mailto"
"SASL" "PLAIN LOGIN DIGEST-MD5 CRAM-MD5"
"STARTTLS"
"VERSION" "1.0"
OK "Dovecot ready."

7081/BANNER View Only


Details

Banner Info

Port
7081
Protocol
TCP
Decoded Banner
HTTP/1.1 400 Bad Request
Date: Mon, 11 Oct 2021 06:13:00 GMT
Server: Apache
Content-Length: 362
Connection: close
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>400 Bad Request</title>
</head><body>
<h1>Bad Request</h1>
<p>Your browser sent a request that this server could not understand.<br />
Reason: You're speaking plain HTTP to an SSL-enabled server port.<br />
 Instead use the HTTPS scheme to access this URL, please.<br />
</p>
</body></html>

7082/BANNER View Only


Details

Banner Info

Port
7082
Protocol
TCP
Decoded Banner
HTTP/1.1 400 Bad Request
Date: Mon, 11 Oct 2021 06:13:00 GMT
Server: Apache
Last-Modified: Tue, 06 Jun 2017 16:26:35 GMT
ETag: "407-5514d154924c0"
Accept-Ranges: bytes
Content-Length: 1031
X-Powered-By: PleskLin
Connection: close
Content-Type: text/html

<HTML>
<HEAD>
<TITLE>400 Bad Request</TITLE>
</HEAD>
<BODY>
<H1>Bad Request</H1>
Your browser sent a request that this server could not understand.
<P>
Client sent malformed Host header
<P>
<HR>
<ADDRESS>
Web Server at u0360585.plsk.regruhosting.ru
</ADDRESS>
</BODY>
</HTML>

<!--
   - Unfortunately, Microsoft has added a clever new
   - "feature" to Internet Explorer. If the text of
   - an error's message is "too small", specifically
   - less than 512 bytes, Internet Explorer returns
   - its own error message. You can turn that off,
   - but it's pretty tricky to find switch called
   - "smart error messages". That means, of course,
   - that short error messages are censored by default.
   - IIS always returns error messages that are long
   -

8081/BANNER View Only


Details

Banner Info

Port
8081
Protocol
TCP
Decoded Banner
HTTP/1.1 200 OK
Date: Mon, 11 Oct 2021 06:13:00 GMT
Server: Apache
Last-Modified: Tue, 06 Jun 2017 16:26:34 GMT
ETag: "15bc-5514d1539e280"
Accept-Ranges: bytes
Content-Length: 5564
X-Powered-By: PleskLin
Content-Type: text/html

<!DOCTYPE html><html lang="en"><head><meta charset="UTF-8"><title>Сайт надёжно припаркован и ожидает открытия</title><link rel="stylesheet" media="all" href="style.css"><link rel="stylesheet" media="all" href="http://reg.ru/css/all-styles.~E4C521.css"><link rel="icon" href="favicon.ico" type="image/x-icon"><script src="modernizr.js"></script><!--[if lt IE 9]><script src="html5shiv.js"></script><![endif]--></head><body class="b-page b-page_type_parking"><header class="b-header-parking"><div class="b-parking__grid b-page__content-wrapper"><div class="b-parking__left-side"><div class="b-header-parking__content b-header-parking__content-logo"><div class="b-header-parking__name"><strong class="b-header-parking__title"><span class="j_dname"></

8443/BANNER View Only


Details

Banner Info

Port
8443
Protocol
TCP
Decoded Banner
HTTP/1.1 302 Moved Temporarily
Server: sw-cp-server
Date: Mon, 11 Oct 2021 06:13:00 GMT
Content-Type: text/html
Content-Length: 138
Connection: close
Location: https://31.31.198.204:8443/

<html>
<head><title>302 Found</title></head>
<body>
<center><h1>302 Found</h1></center>
<hr><center>nginx</center>
</body>
</html>

8880/BANNER View Only


Details

Banner Info

Port
8880
Protocol
TCP
Decoded Banner
HTTP/1.1 303 See Other
Server: sw-cp-server
Date: Mon, 11 Oct 2021 06:13:00 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
Expires: Fri, 28 May 1999 00:00:00 GMT
Last-Modified: Mon, 11 Oct 2021 06:13:00 GMT
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Pragma: no-cache
P3P: CP="NON COR CURa ADMa OUR NOR UNI COM NAV STA"
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
Location: http://31.31.198.204:8880/login.php?success_redirect_url=http%3A%2F%2F31.31.198.204%3A8880%2F

0

Geographic Location

Country
Russia (RU)
Lat/Long
55.7386, 37.6068
Timezone
Europe/Moscow