37.1.201.91

Basic Information

Network
SCALAXY-AS (NL)
Routing
37.1.200.0/21 via AS11164 , AS6461 , AS50673 , AS58061
Protocols
80/HTTP, 3306/MYSQL, 993/IMAPS, 465/SMTP, 995/POP3S, 25/SMTP, 110/POP3, 21/FTP, 143/IMAP, 53/DNS, 443/HTTPS, 587/SMTP, 2222/BANNER, 4190/BANNER
Tags
ftp http https database pop3s smtp imaps pop3 dns mysql imap

80/HTTP


Details Go

GET /

Server
nginx
Status Line
200 OK
Page Title
����� IP
GET /
[view page]

443/HTTPS


Details Go

GET /

Server
nginx
Status Line
200 OK
Page Title
����� IP
GET /
[view page]

Chrome TLS Handshake

Version
TLSv1.2
Cipher Suite
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xC02F)

Heartbleed

Heartbleed
Heartbeat Enabled. Immune to Heartbleed.

Cryptographic Configuration

Export DHE
False
Export RSA
False
DHE Support
True

Certificate Chain

24bb3662fc81487be16d87719839fc30d128132ade6fbedf9e9f1ebba274ebef
C=US, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]
C=US, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]
7363593d116aafcf804b974465546e1f02ed74b52db529ba7520345e5fed1ed4
C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO High-Assurance Secure Server CA
C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
687fa451382278fff0c8b11f8d43d576671c6eb2bceab413fb83d965d06d2ff2
C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
ebd41040e4bb3ec742c9e381d31ef2a41a48b6685c96e7cef3c1df6cd4331c99
C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
8d722f81a9c113c0791df136a2966db26c950a971db46b4199f4ea54b78bfb9f
C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA
C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA
64903546a58058d1e6f1bead1134ede66a6831d231f0df8d4e28535d7a300496
C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)10, CN=VeriSign Class 3 Secure Server CA - G3
C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
8420dfbe376f414bf4c0a81e6936d24ccc03f304835b86c7a39142fca723a689
C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority

21/FTP


Details

Banner Grab

Banner:
220 ProFTPD Server ready.

25/SMTP


Details

Banner Grab and StartTLS Initiation

Server
Exim
Banner
220 nlhosting.offshorehosting.name ESMTP Exim 4.92.3 Sat, 08 Aug 2020 16:40:15 +0300
EHLO
250-nlhosting.offshorehosting.name Hello worker-09.sfj.censys-scanner.com [192.35.168.144]
250-SIZE 52428800
250-8BITMIME
250-PIPELINING
250-AUTH PLAIN LOGIN
250-STARTTLS
250 HELP
STARTTLS
220 TLS go ahead

TLS Handshake

Version
TLSv1.2
Cipher Suite
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xC02F)

Certificate Chain

3a6a9bb40f89c5f8dd85ce44846c101bc6971010b401806b88879bc8a32372a5
C=GB, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]
C=GB, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]

465/SMTP


Details

Banner Grab

Banner
220 nlhosting.offshorehosting.name ESMTP Exim 4.92.3 Tue, 11 Aug 2020 05:53:01 +0300

TLS Handshake

Version
TLSv1.2
Cipher Suite
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xC02F)

Certificate Chain

3a6a9bb40f89c5f8dd85ce44846c101bc6971010b401806b88879bc8a32372a5
C=GB, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]
C=GB, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]

587/SMTP


Details

Banner Grab and StartTLS Initiation

Server
Exim
Banner
220 nlhosting.offshorehosting.name ESMTP Exim 4.92.3 Sat, 08 Aug 2020 08:22:49 +0300
EHLO
250-nlhosting.offshorehosting.name Hello worker-05.sfj.censys-scanner.com [192.35.168.80]
250-SIZE 52428800
250-8BITMIME
250-PIPELINING
250-AUTH PLAIN LOGIN
250-STARTTLS
250 HELP
STARTTLS
220 TLS go ahead

TLS Handshake

Version
TLSv1.2
Cipher Suite
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xC02F)

Certificate Chain

3a6a9bb40f89c5f8dd85ce44846c101bc6971010b401806b88879bc8a32372a5
C=GB, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]
C=GB, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]

53/DNS


Details

Open Resolver Query

Open Resolver
False

110/POP3


Details

Banner Grab and StartTLS Initiation

Server
Dovecot
Banner
+OK Dovecot DA ready.
STARTTLS
+OK Begin TLS negotiation now.

TLS Handshake

Version
TLSv1.2
Cipher Suite
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xC02F)

Certificate Chain

3a6a9bb40f89c5f8dd85ce44846c101bc6971010b401806b88879bc8a32372a5
C=GB, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]
C=GB, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]

143/IMAP


Details

Banner Grab and StartTLS Initiation

Server
Dovecot
Banner
* OK [CAPABILITY IMAP4rev1 SASL-IR LOGIN-REFERRALS ID ENABLE IDLE LITERAL+ STARTTLS AUTH=PLAIN] Dovecot DA ready.
STARTTLS
a001 OK Begin TLS negotiation now.

TLS Handshake

Version
TLSv1.2
Cipher Suite
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xC02F)

Certificate Chain

3a6a9bb40f89c5f8dd85ce44846c101bc6971010b401806b88879bc8a32372a5
C=GB, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]
C=GB, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]

993/IMAPS


Details

Banner Grab

Banner
* OK [CAPABILITY IMAP4rev1 SASL-IR LOGIN-REFERRALS ID ENABLE IDLE LITERAL+ AUTH=PLAIN] Dovecot DA ready.

TLS Handshake

Version
TLSv1.2
Cipher Suite
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xC02F)

Certificate Chain

3a6a9bb40f89c5f8dd85ce44846c101bc6971010b401806b88879bc8a32372a5
C=GB, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]
C=GB, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]

995/POP3S


Details

Banner Grab

Banner
+OK Dovecot DA ready.

TLS Handshake

Version
TLSv1.2
Cipher Suite
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xC02F)

Certificate Chain

3a6a9bb40f89c5f8dd85ce44846c101bc6971010b401806b88879bc8a32372a5
C=GB, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]
C=GB, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]

3306/MySQL


Details

Banner Grab

Version
(Unknown)
Protocol Version
0
Error Code
1130
Error
ER_HOST_NOT_PRIVILEGED
Error Message
Host 'worker-11.sfj.censys-scanner.com' is not allowed to connect to this MySQL server

2222/BANNER View Only


Details

Banner Info

Port
2222
Protocol
TCP
Decoded Banner
HTTP/1.1 

4190/BANNER View Only


Details

Banner Info

Port
4190
Protocol
TCP
Decoded Banner
"IMPLEMENTATION" "Dovecot Pigeonhole"
"SIEVE" "fileinto reject envelope encoded-character vacation subaddress comparator-i;ascii-numeric relational regex imap4flags copy include variables body enotify environment mailbox date index ihave duplicate mime foreverypart extracttext"
"NOTIFY" "mailto"
"SASL" "PLAIN"
"STARTTLS"
"VERSION" "1.0"
OK "Dovecot DA ready."
NO "Error in MANAGESIEVE command received by server."

Geographic Location

Country
Netherlands (NL)
Lat/Long
52.3824, 4.8995
Timezone
Europe/Amsterdam