Returning 10 result(s) out of 244,601 in 0.163 second(s)

  • 130.185.182.252:25 (tcp/smtp/tls) - last seen on 2024-11-07 at 05:55:22 UTC

    • IP
      130.185.182.252
      Network
      130.185.182.0/23
      Domain(s)
      onice.io
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      Reverse DNS
      travtech.onice.io
      ASN
      AS198167
      Organization
      Apptc.me s.r.o.
      Protocol
      smtp Cert not expired smtp
      Source
      datascan
    • Operating System
      Linux Linux Kernel
    • Issuer Common Name
      R10
      Issuer Organization
      Let's Encrypt
      Subject Common Name
      travtech.onice.io
      Subject Alt Name
      travtech.onice.io
      SHA256 Fingerprint
      51e1d0c00f095e4fe4da0131019b66c2256ad06180928a4528b2b36ed7ccd8f4
      Validity Not Before
      2024-09-20T01:21:48Z
      Validity Not After
      2024-12-19T01:21:47Z
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      f8b006ce593c866068430169c2207ec3
    • 220 mail.cruise.com ESMTP Private Mail Server; Thu, 07 Nov 2024 05:55:07 +0000
      250-mail.cruise.com Hello <ip> [<srcip>], pleased to meet you.
      250-ENHANCEDSTATUSCODES
      250-SIZE
      250-EXPN
      250-ETRN
      250-ATRN
      250-CHECKPOINT
      250-8BITMIME
      250-SMTPUTF8
      250-DSN
      250-STARTTLS
      250 HELP
      220 2.0.0 Ready to start TLS
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:55:22.000Z",
         "app" : {
            "length" : 314
         },
         "asn" : "AS198167",
         "basicconstraints" : "critical",
         "ca" : "false",
         "country" : "CZ",
         "data" : "220 mail.cruise.com ESMTP Private Mail Server; Thu, 07 Nov 2024 05:55:07 +0000\r\n250-mail.cruise.com Hello <ip> [<srcip>], pleased to meet you.\r\n250-ENHANCEDSTATUSCODES\r\n250-SIZE\r\n250-EXPN\r\n250-ETRN\r\n250-ATRN\r\n250-CHECKPOINT\r\n250-8BITMIME\r\n250-SMTPUTF8\r\n250-DSN\r\n250-STARTTLS\r\n250 HELP\r\n220 2.0.0 Ready to start TLS",
         "datamd5" : "f8b006ce593c866068430169c2207ec3",
         "datammh3" : 1376812109,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "onice.io"
         ],
         "extkeyusage" : [
            "serverAuth",
            "clientAuth"
         ],
         "fingerprint" : {
            "md5" : "47ec44126c78f40b1b2b9a448ec11ae9",
            "sha1" : "8a2946983e2e86824ff5a47d486270161c501a8e",
            "sha256" : "51e1d0c00f095e4fe4da0131019b66c2256ad06180928a4528b2b36ed7ccd8f4"
         },
         "host" : [
            "travtech"
         ],
         "hostname" : [
            "travtech.onice.io"
         ],
         "ip" : "130.185.182.252",
         "ipv6" : "false",
         "issuer" : {
            "commonname" : "R10",
            "country" : "US",
            "organization" : "Let's Encrypt"
         },
         "keyusage" : [
            "digitalSignature",
            "keyEncipherment"
         ],
         "latitude" : "50.0853",
         "location" : "50.0853,14.4110",
         "longitude" : "14.4110",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "Apptc.me s.r.o.",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 25,
         "protocol" : "smtp",
         "publickey" : {
            "algorithm" : "rsaEncryption",
            "length" : 3072
         },
         "reverse" : [
            "travtech.onice.io"
         ],
         "seen_date" : "2024-11-07",
         "serial" : "03:06:80:99:0e:61:60:82:19:51:47:6a:98:c5:1a:b9:b5:a9",
         "signature" : {
            "algorithm" : "sha256WithRSAEncryption"
         },
         "source" : "datascan",
         "subject" : {
            "altname" : [
               "travtech.onice.io"
            ],
            "commonname" : "travtech.onice.io"
         },
         "subnet" : "130.185.182.0/23",
         "tld" : [
            "io"
         ],
         "tls" : "true",
         "transport" : "tcp",
         "validity" : {
            "notafter" : "2024-12-19T01:21:47Z",
            "notbefore" : "2024-09-20T01:21:48Z"
         },
         "version" : "v3",
         "wildcard" : "false"
      }
      
  • 51.75.55.164:25 (tcp/smtp/tls) - last seen on 2024-11-07 at 05:55:21 UTC

    • IP
      51.75.55.164
      Network
      51.75.0.0/16
      Domain(s)
      radiogwen.ch
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      Reverse DNS
      plasmon.radiogwen.ch
      ASN
      AS16276
      Organization
      OVH SAS
      Protocol
      smtp Cert not expired smtp
      Source
      datascan
    • Operating System
      Linux Linux Kernel
      Product
      Postfix Postfix
      CPE(s)

      <enterprise field>: cpe

    • Issuer Common Name
      R10
      Issuer Organization
      Let's Encrypt
      Subject Common Name
      mail.radiogwen.ch
      Subject Alt Name
      mail.radiogwen.ch
      SHA256 Fingerprint
      1ebdbc8afb9ecf6cac97acd35b0438291185923bb65a055391bd7cf266715e24
      Validity Not Before
      2024-11-03T10:11:28Z
      Validity Not After
      2025-02-01T10:11:27Z
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      a0f18d4eaba3e134dfdee4fa8431b631
    • 220 mail.radiogwen.ch ESMTP Postfix
      250-mail.radiogwen.ch
      250-PIPELINING
      250-SIZE 52428800
      250-VRFY
      250-ETRN
      250-STARTTLS
      250-AUTH PLAIN LOGIN
      250-AUTH=PLAIN LOGIN
      250-ENHANCEDSTATUSCODES
      250-8BITMIME
      250-DSN
      250-SMTPUTF8
      250 CHUNKING
      220 2.0.0 Ready to start TLS
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:55:21.000Z",
         "app" : {
            "length" : 277
         },
         "asn" : "AS16276",
         "basicconstraints" : "critical",
         "ca" : "false",
         "country" : "FR",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "220 mail.radiogwen.ch ESMTP Postfix\r\n250-mail.radiogwen.ch\r\n250-PIPELINING\r\n250-SIZE 52428800\r\n250-VRFY\r\n250-ETRN\r\n250-STARTTLS\r\n250-AUTH PLAIN LOGIN\r\n250-AUTH=PLAIN LOGIN\r\n250-ENHANCEDSTATUSCODES\r\n250-8BITMIME\r\n250-DSN\r\n250-SMTPUTF8\r\n250 CHUNKING\r\n220 2.0.0 Ready to start TLS",
         "datamd5" : "a0f18d4eaba3e134dfdee4fa8431b631",
         "datammh3" : -1645559434,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "radiogwen.ch"
         ],
         "extkeyusage" : [
            "serverAuth",
            "clientAuth"
         ],
         "fingerprint" : {
            "md5" : "a060d387734f2db99b5a272e131d1435",
            "sha1" : "4b55bf8b4cfa0b74c0be9607959e5523b022c49b",
            "sha256" : "1ebdbc8afb9ecf6cac97acd35b0438291185923bb65a055391bd7cf266715e24"
         },
         "geolocus" : {
            "asn" : "AS16276",
            "continent" : "EU",
            "continentname" : "Europe",
            "country" : "PL",
            "countryname" : "Poland",
            "domain" : [
               "ovh.net"
            ],
            "isineu" : "true",
            "latitude" : "51.919438",
            "location" : "51.919438,19.145136",
            "longitude" : "19.145136",
            "netname" : "SD-1G-WAW1-W15A",
            "organization" : "OVH Sp. z o. o.",
            "subnet" : "51.75.52.0/22"
         },
         "host" : [
            "mail",
            "plasmon"
         ],
         "hostname" : [
            "mail.radiogwen.ch",
            "plasmon.radiogwen.ch"
         ],
         "ip" : "51.75.55.164",
         "ipv6" : "false",
         "issuer" : {
            "commonname" : "R10",
            "country" : "US",
            "organization" : "Let's Encrypt"
         },
         "keyusage" : [
            "digitalSignature",
            "keyEncipherment"
         ],
         "latitude" : "48.8582",
         "location" : "48.8582,2.3387",
         "longitude" : "2.3387",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "OVH SAS",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 25,
         "product" : "Postfix",
         "productvendor" : "Postfix",
         "protocol" : "smtp",
         "publickey" : {
            "algorithm" : "rsaEncryption",
            "length" : 2048
         },
         "reverse" : [
            "plasmon.radiogwen.ch"
         ],
         "seen_date" : "2024-11-07",
         "serial" : "03:3c:68:a7:4b:ef:77:19:84:4f:f9:ef:39:a5:95:7e:f2:dd",
         "signature" : {
            "algorithm" : "sha256WithRSAEncryption"
         },
         "source" : "datascan",
         "subject" : {
            "altname" : [
               "mail.radiogwen.ch"
            ],
            "commonname" : "mail.radiogwen.ch"
         },
         "subnet" : "51.75.0.0/16",
         "tag" : "<enterprise field>: tag",
         "tld" : [
            "ch"
         ],
         "tls" : "true",
         "transport" : "tcp",
         "validity" : {
            "notafter" : "2025-02-01T10:11:27Z",
            "notbefore" : "2024-11-03T10:11:28Z"
         },
         "version" : "v3",
         "wildcard" : "false"
      }
      
  • 89.240.15.30:25 (tcp/smtp/tls) - last seen on 2024-11-07 at 05:55:21 UTC

    • IP
      89.240.15.30
      Network
      89.240.0.0/14
      Domain(s)
      exatech.net
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      Reverse DNS
      server.exatech.net
      ASN
      AS13285
      Organization
      TalkTalk
      Protocol
      smtp Cert not expired smtp
      Source
      datascan
    • Operating System
      Linux Linux Kernel
    • Issuer Common Name
      R10
      Issuer Organization
      Let's Encrypt
      Subject Common Name
      server.exatech.net
      Subject Alt Name
      server.exatech.net
      SHA256 Fingerprint
      5ac63a775d55ab4338633cbad16fe267aa952d7957649b82ff8782cdacdf465e
      Validity Not Before
      2024-10-30T03:43:49Z
      Validity Not After
      2025-01-28T03:43:48Z
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      a6b8c50d17892abfba2a8c4c29be04b4
    • 220 server.exatech.net
      250-server.exatech.net Hello <hostname> [<srcip>]
      250-SIZE 52428800
      250-8BITMIME
      250-PIPELINING
      250-PIPE_CONNECT
      250-AUTH PLAIN LOGIN
      250-CHUNKING
      250-STARTTLS
      250 HELP
      220 TLS go ahead
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:55:21.000Z",
         "app" : {
            "length" : 218
         },
         "asn" : "AS13285",
         "basicconstraints" : "critical",
         "ca" : "false",
         "city" : "Greenwich",
         "country" : "GB",
         "data" : "220 server.exatech.net\r\n250-server.exatech.net Hello <hostname> [<srcip>]\r\n250-SIZE 52428800\r\n250-8BITMIME\r\n250-PIPELINING\r\n250-PIPE_CONNECT\r\n250-AUTH PLAIN LOGIN\r\n250-CHUNKING\r\n250-STARTTLS\r\n250 HELP\r\n220 TLS go ahead",
         "datamd5" : "a6b8c50d17892abfba2a8c4c29be04b4",
         "datammh3" : -448364215,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "exatech.net"
         ],
         "extkeyusage" : [
            "serverAuth",
            "clientAuth"
         ],
         "fingerprint" : {
            "md5" : "3cebaf817952a30662615bb9c383310f",
            "sha1" : "dd1b3c0486345437924fe1e1dbd34635eb1a4c9c",
            "sha256" : "5ac63a775d55ab4338633cbad16fe267aa952d7957649b82ff8782cdacdf465e"
         },
         "geolocus" : {
            "asn" : "AS13285",
            "continent" : "EU",
            "continentname" : "Europe",
            "country" : "GB",
            "countryname" : "United Kingdom",
            "domain" : [
               "as13285.net",
               "talktalkplc.com"
            ],
            "isineu" : "false",
            "latitude" : "55.378051",
            "location" : "55.378051,-3.435973",
            "longitude" : "-3.435973",
            "netname" : "OPAL-DSL",
            "organization" : "TalkTalk Communications Limited",
            "subnet" : "89.240.0.0/16"
         },
         "host" : [
            "server"
         ],
         "hostname" : [
            "server.exatech.net"
         ],
         "ip" : "89.240.15.30",
         "ipv6" : "false",
         "issuer" : {
            "commonname" : "R10",
            "country" : "US",
            "organization" : "Let's Encrypt"
         },
         "keyusage" : [
            "digitalSignature",
            "keyEncipherment"
         ],
         "latitude" : "51.4805",
         "location" : "51.4805,-0.0113",
         "longitude" : "-0.0113",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "TalkTalk",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 25,
         "protocol" : "smtp",
         "publickey" : {
            "algorithm" : "rsaEncryption",
            "length" : 4096
         },
         "reverse" : [
            "server.exatech.net"
         ],
         "seen_date" : "2024-11-07",
         "serial" : "03:df:c5:d5:6a:db:20:31:73:a8:f5:46:f3:73:dc:f8:3c:6c",
         "signature" : {
            "algorithm" : "sha256WithRSAEncryption"
         },
         "source" : "datascan",
         "subject" : {
            "altname" : [
               "server.exatech.net"
            ],
            "commonname" : "server.exatech.net"
         },
         "subnet" : "89.240.0.0/14",
         "tld" : [
            "net"
         ],
         "tls" : "true",
         "transport" : "tcp",
         "validity" : {
            "notafter" : "2025-01-28T03:43:48Z",
            "notbefore" : "2024-10-30T03:43:49Z"
         },
         "version" : "v3",
         "wildcard" : "false"
      }
      
  • 199.189.201.96:25 (tcp/smtp/tls) - last seen on 2024-11-07 at 05:52:30 UTC

    • IP
      199.189.201.96
      Alternative IP(s)
      104.21.12.107 172.67.194.98 2606:4700:3034:0:0:0:ac43:c262 2606:4700:3035:0:0:0:6815:c6b
      Network
      199.189.200.0/22
      Domain(s)
      opencube.ca
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      ASN
      AS30158
      Organization
      ARIMA-NETWORKS
      Protocol
      smtp Cert expired smtp
      Source
      datascan
    • Operating System
      Linux Linux Kernel
      Product
      Exim Exim 4.96
      CPE(s)

      <enterprise field>: cpe

    • Issuer Common Name
      R10
      Issuer Organization
      Let's Encrypt
      Subject Common Name
      shared.opencube.ca
      Subject Alt Name
      shared.opencube.ca
      SHA256 Fingerprint
      4d3edd30d04748d8a5471feec48512f9044e88e5c9048f5c61e1138212ca6fc4
      Validity Not Before
      2024-06-10T22:22:50Z
      Validity Not After
      2024-09-08T22:22:49Z
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      038e629623e00b0255c011ebaa0f8006
    • 220 shared.opencube.ca ESMTP Exim 4.96 Wed, 06 Nov 2024 21:52:20 -0800
      250-shared.opencube.ca Hello <hostname> [<srcip>]
      250-SIZE 52428800
      250-8BITMIME
      250-PIPELINING
      250-PIPECONNECT
      250-AUTH PLAIN LOGIN
      250-CHUNKING
      250-STARTTLS
      250 HELP
      220 TLS go ahead
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:52:30.000Z",
         "alternativeip" : [
            "104.21.12.107",
            "172.67.194.98",
            "2606:4700:3034:0:0:0:ac43:c262",
            "2606:4700:3035:0:0:0:6815:c6b"
         ],
         "app" : {
            "length" : 265
         },
         "asn" : "AS30158",
         "basicconstraints" : "critical",
         "ca" : "false",
         "country" : "CA",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "220 shared.opencube.ca ESMTP Exim 4.96 Wed, 06 Nov 2024 21:52:20 -0800\r\n250-shared.opencube.ca Hello <hostname> [<srcip>]\r\n250-SIZE 52428800\r\n250-8BITMIME\r\n250-PIPELINING\r\n250-PIPECONNECT\r\n250-AUTH PLAIN LOGIN\r\n250-CHUNKING\r\n250-STARTTLS\r\n250 HELP\r\n220 TLS go ahead",
         "datamd5" : "038e629623e00b0255c011ebaa0f8006",
         "datammh3" : 1753683750,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "opencube.ca"
         ],
         "extkeyusage" : [
            "serverAuth",
            "clientAuth"
         ],
         "fingerprint" : {
            "md5" : "454c4a782aa58143426b34c70d824c65",
            "sha1" : "86da9eeab4ffe57759f38df5e7e5a5ab6434292a",
            "sha256" : "4d3edd30d04748d8a5471feec48512f9044e88e5c9048f5c61e1138212ca6fc4"
         },
         "geolocus" : {
            "asn" : "AS30158",
            "continent" : "NA",
            "continentname" : "North America",
            "country" : "CA",
            "countryname" : "Canada",
            "domain" : [
               "dotalliance.com",
               "dynacloud.ca"
            ],
            "isineu" : "false",
            "latitude" : "56.130366",
            "location" : "56.130366,-106.346771",
            "longitude" : "-106.346771",
            "netname" : "DOTALLIANCE-IPV4-01",
            "organization" : "DotAlliance",
            "subnet" : "199.189.200.0/23"
         },
         "host" : [
            "shared"
         ],
         "hostname" : [
            "shared.opencube.ca"
         ],
         "ip" : "199.189.201.96",
         "ipv6" : "false",
         "issuer" : {
            "commonname" : "R10",
            "country" : "US",
            "organization" : "Let's Encrypt"
         },
         "keyusage" : [
            "digitalSignature",
            "keyEncipherment"
         ],
         "latitude" : "43.6319",
         "location" : "43.6319,-79.3716",
         "longitude" : "-79.3716",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "ARIMA-NETWORKS",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 25,
         "product" : "Exim",
         "productvendor" : "Exim",
         "productversion" : "4.96",
         "protocol" : "smtp",
         "publickey" : {
            "algorithm" : "rsaEncryption",
            "length" : 4096
         },
         "seen_date" : "2024-11-07",
         "serial" : "04:ce:8b:df:f0:4c:aa:fa:ae:94:bd:60:57:80:4f:18:dd:7c",
         "signature" : {
            "algorithm" : "sha256WithRSAEncryption"
         },
         "source" : "datascan",
         "subject" : {
            "altname" : [
               "shared.opencube.ca"
            ],
            "commonname" : "shared.opencube.ca"
         },
         "subnet" : "199.189.200.0/22",
         "tld" : [
            "ca"
         ],
         "tls" : "true",
         "transport" : "tcp",
         "validity" : {
            "notafter" : "2024-09-08T22:22:49Z",
            "notbefore" : "2024-06-10T22:22:50Z"
         },
         "version" : "v3",
         "wildcard" : "false"
      }
      
  • 151.252.12.210:25 (tcp/smtp/tls) - last seen on 2024-11-07 at 05:52:29 UTC

    • IP
      151.252.12.210
      Network
      151.252.8.0/21
      Domain(s)
      wserver.no
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      Reverse DNS
      m3.wserver.no
      ASN
      AS49788
      Organization
      Nexthop AS
      Protocol
      smtp Cert not expired smtp
      Source
      datascan
    • Operating System
      Linux Linux Kernel
      Product
      Postfix Postfix
      CPE(s)

      <enterprise field>: cpe

    • Issuer Common Name
      R10
      Issuer Organization
      Let's Encrypt
      Subject Common Name
      m3.wserver.no
      Subject Alt Name
      m3.wserver.no
      SHA256 Fingerprint
      c23058391a681974dc1d2d1dc758a058d6710e9808a0f925d0e50085856640f0
      Validity Not Before
      2024-10-20T20:18:44Z
      Validity Not After
      2025-01-18T20:18:43Z
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      d8580ced9079f14422c908bf2d7d148b
    • 220 m3.wserver.no ESMTP Postfix
      250-m3.wserver.no
      250-PIPELINING
      250-SIZE 10240000
      250-VRFY
      250-ETRN
      250-STARTTLS
      250-AUTH PLAIN LOGIN
      250-AUTH=PLAIN LOGIN
      250-ENHANCEDSTATUSCODES
      250-8BITMIME
      250 DSN
      220 2.0.0 Ready to start TLS
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:52:29.000Z",
         "app" : {
            "length" : 241
         },
         "asn" : "AS49788",
         "basicconstraints" : "critical",
         "ca" : "false",
         "country" : "NO",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "220 m3.wserver.no ESMTP Postfix\r\n250-m3.wserver.no\r\n250-PIPELINING\r\n250-SIZE 10240000\r\n250-VRFY\r\n250-ETRN\r\n250-STARTTLS\r\n250-AUTH PLAIN LOGIN\r\n250-AUTH=PLAIN LOGIN\r\n250-ENHANCEDSTATUSCODES\r\n250-8BITMIME\r\n250 DSN\r\n220 2.0.0 Ready to start TLS",
         "datamd5" : "d8580ced9079f14422c908bf2d7d148b",
         "datammh3" : -282047315,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "wserver.no"
         ],
         "extkeyusage" : [
            "serverAuth",
            "clientAuth"
         ],
         "fingerprint" : {
            "md5" : "aae70065bd7d7c9d44a0908a52f0d3c7",
            "sha1" : "92312e2d9c247e7b21d2f9f6aca5a9baefba912a",
            "sha256" : "c23058391a681974dc1d2d1dc758a058d6710e9808a0f925d0e50085856640f0"
         },
         "geolocus" : {
            "asn" : "AS49788",
            "continent" : "EU",
            "continentname" : "Europe",
            "country" : "NO",
            "countryname" : "Norway",
            "domain" : [
               "nexthop.no"
            ],
            "isineu" : "false",
            "latitude" : "60.472024",
            "location" : "60.472024,8.468946",
            "longitude" : "8.468946",
            "netname" : "NO-NEXTHOP-20120821",
            "organization" : "Nexthop AS",
            "subnet" : "151.252.8.0/21"
         },
         "host" : [
            "m3"
         ],
         "hostname" : [
            "m3.wserver.no"
         ],
         "ip" : "151.252.12.210",
         "ipv6" : "false",
         "issuer" : {
            "commonname" : "R10",
            "country" : "US",
            "organization" : "Let's Encrypt"
         },
         "keyusage" : [
            "digitalSignature",
            "keyEncipherment"
         ],
         "latitude" : "59.9452",
         "location" : "59.9452,10.7559",
         "longitude" : "10.7559",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "Nexthop AS",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 25,
         "product" : "Postfix",
         "productvendor" : "Postfix",
         "protocol" : "smtp",
         "publickey" : {
            "algorithm" : "rsaEncryption",
            "length" : 2048
         },
         "reverse" : [
            "m3.wserver.no"
         ],
         "seen_date" : "2024-11-07",
         "serial" : "04:1f:68:b1:5e:16:a5:06:c9:f8:cc:ce:48:52:e1:33:a4:57",
         "signature" : {
            "algorithm" : "sha256WithRSAEncryption"
         },
         "source" : "datascan",
         "subject" : {
            "altname" : [
               "m3.wserver.no"
            ],
            "commonname" : "m3.wserver.no"
         },
         "subnet" : "151.252.8.0/21",
         "tld" : [
            "no"
         ],
         "tls" : "true",
         "transport" : "tcp",
         "validity" : {
            "notafter" : "2025-01-18T20:18:43Z",
            "notbefore" : "2024-10-20T20:18:44Z"
         },
         "version" : "v3",
         "wildcard" : "false"
      }
      
  • 185.86.166.52:25 (tcp/smtp/tls) - last seen on 2024-11-07 at 05:52:29 UTC

    • IP
      185.86.166.52
      Network
      185.86.164.0/22
      Domain(s)
      ab.net.tr somaolay.com.tr
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      Reverse DNS
      1858616652.ab.net.tr
      ASN
      AS29262
      Organization
      Ideal Hosting Teknoloji A.S.
      Protocol
      smtp Cert not expired smtp
      Source
      datascan
    • Operating System
      Linux Linux Kernel
      Product
      Postfix Postfix
      CPE(s)

      <enterprise field>: cpe

    • Issuer Common Name
      R10
      Issuer Organization
      Let's Encrypt
      Subject Common Name
      server.somaolay.com.tr
      Subject Alt Name
      server.somaolay.com.tr
      SHA256 Fingerprint
      e38dc834a1b47af7434fcf973674db4fa58fe1fc83b6121337a2d2ab31866252
      Validity Not Before
      2024-09-27T05:55:41Z
      Validity Not After
      2024-12-26T05:55:40Z
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      91d78fb0ed1171350d078bffabc0ef4e
    • 220 intelligent-jennings.185-85-239-50.plesk.page ESMTP Postfix
      250-intelligent-jennings.185-85-239-50.plesk.page
      250-PIPELINING
      250-SIZE 33554432
      250-ETRN
      250-STARTTLS
      250-AUTH DIGEST-MD5 CRAM-MD5 PLAIN LOGIN
      250-ENHANCEDSTATUSCODES
      250-8BITMIME
      250-DSN
      250 CHUNKING
      220 2.0.0 Ready to start TLS
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:52:29.000Z",
         "app" : {
            "length" : 307
         },
         "asn" : "AS29262",
         "basicconstraints" : "critical",
         "ca" : "false",
         "city" : "Istanbul",
         "country" : "TR",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "220 intelligent-jennings.185-85-239-50.plesk.page ESMTP Postfix\r\n250-intelligent-jennings.185-85-239-50.plesk.page\r\n250-PIPELINING\r\n250-SIZE 33554432\r\n250-ETRN\r\n250-STARTTLS\r\n250-AUTH DIGEST-MD5 CRAM-MD5 PLAIN LOGIN\r\n250-ENHANCEDSTATUSCODES\r\n250-8BITMIME\r\n250-DSN\r\n250 CHUNKING\r\n220 2.0.0 Ready to start TLS",
         "datamd5" : "91d78fb0ed1171350d078bffabc0ef4e",
         "datammh3" : 2018996214,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "ab.net.tr",
            "somaolay.com.tr"
         ],
         "extkeyusage" : [
            "serverAuth",
            "clientAuth"
         ],
         "fingerprint" : {
            "md5" : "e09dbfde20e941203ea4d4e6d7b3ba37",
            "sha1" : "bc04d6c05a2471a74f200f29d2f592425206de98",
            "sha256" : "e38dc834a1b47af7434fcf973674db4fa58fe1fc83b6121337a2d2ab31866252"
         },
         "host" : [
            1858616652,
            "server"
         ],
         "hostname" : [
            "1858616652.ab.net.tr",
            "server.somaolay.com.tr"
         ],
         "ip" : "185.86.166.52",
         "ipv6" : "false",
         "issuer" : {
            "commonname" : "R10",
            "country" : "US",
            "organization" : "Let's Encrypt"
         },
         "keyusage" : [
            "digitalSignature",
            "keyEncipherment"
         ],
         "latitude" : "41.0011",
         "location" : "41.0011,28.9675",
         "longitude" : "28.9675",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "Ideal Hosting Teknoloji A.S.",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 25,
         "product" : "Postfix",
         "productvendor" : "Postfix",
         "protocol" : "smtp",
         "publickey" : {
            "algorithm" : "rsaEncryption",
            "length" : 2048
         },
         "reverse" : [
            "1858616652.ab.net.tr"
         ],
         "seen_date" : "2024-11-07",
         "serial" : "03:67:39:69:b8:c0:96:0c:d2:9c:6c:5c:4b:af:4b:a9:68:0c",
         "signature" : {
            "algorithm" : "sha256WithRSAEncryption"
         },
         "source" : "datascan",
         "subject" : {
            "altname" : [
               "server.somaolay.com.tr"
            ],
            "commonname" : "server.somaolay.com.tr"
         },
         "subnet" : "185.86.164.0/22",
         "tld" : [
            "com.tr",
            "net.tr"
         ],
         "tls" : "true",
         "transport" : "tcp",
         "validity" : {
            "notafter" : "2024-12-26T05:55:40Z",
            "notbefore" : "2024-09-27T05:55:41Z"
         },
         "version" : "v3",
         "wildcard" : "false"
      }
      
  • 129.154.200.0:25 (tcp/smtp/tls) - last seen on 2024-11-07 at 05:52:28 UTC

    • IP
      129.154.200.0
      Network
      129.154.192.0/18
      Domain(s)
      tevinzhang.com
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      ASN
      AS31898
      Organization
      ORACLE-BMC-31898
      Protocol
      smtp Cert not expired smtp
      Source
      datascan
    • Operating System
      Linux Linux Kernel
    • Issuer Common Name
      R10
      Issuer Organization
      Let's Encrypt
      Subject Common Name
      y.tevinzhang.com
      Subject Alt Name
      y.tevinzhang.com
      SHA256 Fingerprint
      69997dce39c355ce56d8838c70895167cc838820bc4537b51d67bc74aa63e7b7
      Validity Not Before
      2024-09-05T21:27:28Z
      Validity Not After
      2024-12-04T21:27:27Z
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      0ba132a63a206755681f42f40c4d62b9
    • 220 y.tevinzhang.com Service ready
      250-y.tevinzhang.com
      250-PIPELINING
      250-SIZE 35914708
      250-ETRN
      250-STARTTLS
      250-ENHANCEDSTATUSCODES
      250-8BITMIME
      250-DSN
      250 CHUNKING
      220 2.0.0 Ready to start TLS
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:52:28.000Z",
         "app" : {
            "length" : 207
         },
         "asn" : "AS31898",
         "basicconstraints" : "critical",
         "ca" : "false",
         "city" : "Seoul",
         "country" : "KR",
         "data" : "220 y.tevinzhang.com Service ready\r\n250-y.tevinzhang.com\r\n250-PIPELINING\r\n250-SIZE 35914708\r\n250-ETRN\r\n250-STARTTLS\r\n250-ENHANCEDSTATUSCODES\r\n250-8BITMIME\r\n250-DSN\r\n250 CHUNKING\r\n220 2.0.0 Ready to start TLS",
         "datamd5" : "0ba132a63a206755681f42f40c4d62b9",
         "datammh3" : -1743737003,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "tevinzhang.com"
         ],
         "extkeyusage" : [
            "serverAuth",
            "clientAuth"
         ],
         "fingerprint" : {
            "md5" : "d5f45b1196683bdf8c50e74ef9218842",
            "sha1" : "656d3c69b930a3e5c75553b9a71c85ac64c5854e",
            "sha256" : "69997dce39c355ce56d8838c70895167cc838820bc4537b51d67bc74aa63e7b7"
         },
         "geolocus" : {
            "asn" : "AS31898",
            "continent" : "NA",
            "continentname" : "North America",
            "country" : "US",
            "countryname" : "United States",
            "domain" : [
               "oracle.com"
            ],
            "isineu" : "false",
            "latitude" : "37.09024",
            "location" : "37.09024,-95.712891",
            "longitude" : "-95.712891",
            "netname" : "OPC1",
            "organization" : "Oracle Corporation",
            "subnet" : "129.154.192.0/19"
         },
         "host" : [
            "y"
         ],
         "hostname" : [
            "y.tevinzhang.com"
         ],
         "ip" : "129.154.200.0",
         "ipv6" : "false",
         "issuer" : {
            "commonname" : "R10",
            "country" : "US",
            "organization" : "Let's Encrypt"
         },
         "keyusage" : [
            "digitalSignature",
            "keyEncipherment"
         ],
         "latitude" : "37.5450",
         "location" : "37.5450,126.8078",
         "longitude" : "126.8078",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "ORACLE-BMC-31898",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 25,
         "protocol" : "smtp",
         "publickey" : {
            "algorithm" : "rsaEncryption",
            "length" : 3072
         },
         "seen_date" : "2024-11-07",
         "serial" : "03:d4:52:01:86:a4:43:20:e3:2c:ce:eb:08:1e:63:c6:f7:d8",
         "signature" : {
            "algorithm" : "sha256WithRSAEncryption"
         },
         "source" : "datascan",
         "subject" : {
            "altname" : [
               "y.tevinzhang.com"
            ],
            "commonname" : "y.tevinzhang.com"
         },
         "subnet" : "129.154.192.0/18",
         "tld" : [
            "com"
         ],
         "tls" : "true",
         "transport" : "tcp",
         "validity" : {
            "notafter" : "2024-12-04T21:27:27Z",
            "notbefore" : "2024-09-05T21:27:28Z"
         },
         "version" : "v3",
         "wildcard" : "false"
      }
      
  • 79.99.237.116:25 (tcp/smtp/tls) - last seen on 2024-11-07 at 05:52:28 UTC

    • IP
      79.99.237.116
      Alternative IP(s)
      79.99.237.118
      Network
      79.99.232.0/21
      Domain(s)
      ipbroadcasting.nl
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      Reverse DNS
      mx.ipbroadcasting.nl
      ASN
      AS25418
      Organization
      CQ International B.V.
      Protocol
      smtp Cert not expired smtp
      Source
      datascan
    • Operating System
      Linux Linux Kernel
    • Issuer Common Name
      R10
      Issuer Organization
      Let's Encrypt
      Subject Common Name
      *.ipbroadcasting.nl
      Subject Alt Name
      *.ipbroadcasting.nl ipbroadcasting.nl
      SHA256 Fingerprint
      98540519f24802406a9887c039991d4b87404198749c3214f9f3e941c6fc2e6e
      Validity Not Before
      2024-11-05T23:33:43Z
      Validity Not After
      2025-02-03T23:33:42Z
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      cb900471b57758f75b8c422b58da6943
    • 220-mx.ipbroadcasting.nl ESMTP
      250-mx.ipbroadcasting.nl
      250-SIZE 41943040
      250-ETRN
      250-STARTTLS
      250-ENHANCEDSTATUSCODES
      250 8BITMIME
      220 2.0.0 Ready to start TLS
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:52:28.000Z",
         "alternativeip" : [
            "79.99.237.118"
         ],
         "app" : {
            "length" : 168
         },
         "asn" : "AS25418",
         "basicconstraints" : "critical",
         "ca" : "false",
         "country" : "NL",
         "data" : "220-mx.ipbroadcasting.nl ESMTP\r\n250-mx.ipbroadcasting.nl\r\n250-SIZE 41943040\r\n250-ETRN\r\n250-STARTTLS\r\n250-ENHANCEDSTATUSCODES\r\n250 8BITMIME\r\n220 2.0.0 Ready to start TLS",
         "datamd5" : "cb900471b57758f75b8c422b58da6943",
         "datammh3" : -403603503,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "ipbroadcasting.nl"
         ],
         "extkeyusage" : [
            "serverAuth",
            "clientAuth"
         ],
         "fingerprint" : {
            "md5" : "747c82bdd1e8c0cc32d20ba04a640e35",
            "sha1" : "8bfe0a64097857dc07ed1fa6da0cc709193845a1",
            "sha256" : "98540519f24802406a9887c039991d4b87404198749c3214f9f3e941c6fc2e6e"
         },
         "host" : [
            "mx"
         ],
         "hostname" : [
            "ipbroadcasting.nl",
            "mx.ipbroadcasting.nl"
         ],
         "ip" : "79.99.237.116",
         "ipv6" : "false",
         "issuer" : {
            "commonname" : "R10",
            "country" : "US",
            "organization" : "Let's Encrypt"
         },
         "keyusage" : [
            "digitalSignature",
            "keyEncipherment"
         ],
         "latitude" : "52.3824",
         "location" : "52.3824,4.8995",
         "longitude" : "4.8995",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "CQ International B.V.",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 25,
         "protocol" : "smtp",
         "publickey" : {
            "algorithm" : "rsaEncryption",
            "length" : 2048
         },
         "reverse" : [
            "mx.ipbroadcasting.nl"
         ],
         "seen_date" : "2024-11-07",
         "serial" : "04:f5:2e:28:32:aa:ee:97:83:f8:5c:29:53:6e:f2:51:75:ea",
         "signature" : {
            "algorithm" : "sha256WithRSAEncryption"
         },
         "source" : "datascan",
         "subject" : {
            "altname" : [
               "*.ipbroadcasting.nl",
               "ipbroadcasting.nl"
            ],
            "commonname" : "*.ipbroadcasting.nl"
         },
         "subnet" : "79.99.232.0/21",
         "tld" : [
            "nl"
         ],
         "tls" : "true",
         "transport" : "tcp",
         "validity" : {
            "notafter" : "2025-02-03T23:33:42Z",
            "notbefore" : "2024-11-05T23:33:43Z"
         },
         "version" : "v3",
         "wildcard" : "true"
      }
      
  • 176.31.59.39:25 (tcp/smtp/tls) - last seen on 2024-11-07 at 05:52:28 UTC

    • IP
      176.31.59.39
      Network
      176.31.0.0/16
      Domain(s)
      campusremotouvigo.gal
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Debian
      Reverse DNS
      mail.campusremotouvigo.gal
      ASN
      AS16276
      Organization
      OVH SAS
      Protocol
      smtp Cert not expired smtp
      Source
      datascan
    • Operating System
      Linux Linux Debian
      Product
      Postfix Postfix
      CPE(s)

      <enterprise field>: cpe

    • Issuer Common Name
      R10
      Issuer Organization
      Let's Encrypt
      Subject Common Name
      mail.campusremotouvigo.gal
      Subject Alt Name
      mail.campusremotouvigo.gal
      SHA256 Fingerprint
      3c3d1380898e3b4108956b474780761874c11fd8439b17324ea9a9db59216a41
      Validity Not Before
      2024-09-18T08:26:01Z
      Validity Not After
      2024-12-17T08:26:00Z
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      ec9e63513b0b4751543a99513d8bf6ba
    • 220-mail.campusremotouvigo.gal ESMTP Postfix (Debian)
      250-mail.campusremotouvigo.gal
      250-SIZE 10240000
      250-ETRN
      250-STARTTLS
      250-ENHANCEDSTATUSCODES
      250-8BITMIME
      250-DSN
      250 CHUNKING
      220 2.0.0 Ready to start TLS
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:52:28.000Z",
         "app" : {
            "length" : 220
         },
         "asn" : "AS16276",
         "basicconstraints" : "critical",
         "ca" : "false",
         "country" : "FR",
         "cpe" : "<enterprise field>: cpe",
         "cpecount" : "<enterprise field>: cpecount",
         "data" : "220-mail.campusremotouvigo.gal ESMTP Postfix (Debian)\r\n250-mail.campusremotouvigo.gal\r\n250-SIZE 10240000\r\n250-ETRN\r\n250-STARTTLS\r\n250-ENHANCEDSTATUSCODES\r\n250-8BITMIME\r\n250-DSN\r\n250 CHUNKING\r\n220 2.0.0 Ready to start TLS",
         "datamd5" : "ec9e63513b0b4751543a99513d8bf6ba",
         "datammh3" : 942622590,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "campusremotouvigo.gal"
         ],
         "extkeyusage" : [
            "serverAuth",
            "clientAuth"
         ],
         "fingerprint" : {
            "md5" : "1dc42c94908d186bee5eb8e94157379e",
            "sha1" : "0d1ad56fc09b2f439a64e19671ba8b660bf4f5e7",
            "sha256" : "3c3d1380898e3b4108956b474780761874c11fd8439b17324ea9a9db59216a41"
         },
         "geolocus" : {
            "asn" : "AS16276",
            "continent" : "EU",
            "continentname" : "Europe",
            "country" : "FR",
            "countryname" : "France",
            "domain" : [
               "ovh.net"
            ],
            "isineu" : "true",
            "latitude" : "46.227638",
            "location" : "46.227638,2.213749",
            "longitude" : "2.213749",
            "netname" : "OVH_69154095",
            "organization" : "EFFICAWEB",
            "subnet" : "176.31.56.0/22"
         },
         "host" : [
            "mail"
         ],
         "hostname" : [
            "mail.campusremotouvigo.gal"
         ],
         "ip" : "176.31.59.39",
         "ipv6" : "false",
         "issuer" : {
            "commonname" : "R10",
            "country" : "US",
            "organization" : "Let's Encrypt"
         },
         "keyusage" : [
            "digitalSignature",
            "keyEncipherment"
         ],
         "latitude" : "48.8582",
         "location" : "48.8582,2.3387",
         "longitude" : "2.3387",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "OVH SAS",
         "os" : "Linux",
         "osdistribution" : "Debian",
         "osvendor" : "Linux",
         "port" : 25,
         "product" : "Postfix",
         "productvendor" : "Postfix",
         "protocol" : "smtp",
         "publickey" : {
            "algorithm" : "rsaEncryption",
            "length" : 2048
         },
         "reverse" : [
            "mail.campusremotouvigo.gal"
         ],
         "seen_date" : "2024-11-07",
         "serial" : "03:5c:10:2f:11:2a:38:24:37:e3:ee:7d:16:71:4f:81:b8:32",
         "signature" : {
            "algorithm" : "sha256WithRSAEncryption"
         },
         "source" : "datascan",
         "subject" : {
            "altname" : [
               "mail.campusremotouvigo.gal"
            ],
            "commonname" : "mail.campusremotouvigo.gal"
         },
         "subnet" : "176.31.0.0/16",
         "tag" : "<enterprise field>: tag",
         "tld" : [
            "gal"
         ],
         "tls" : "true",
         "transport" : "tcp",
         "validity" : {
            "notafter" : "2024-12-17T08:26:00Z",
            "notbefore" : "2024-09-18T08:26:01Z"
         },
         "version" : "v3",
         "wildcard" : "false"
      }
      
  • 187.108.197.138:25 (tcp/smtp/tls) - last seen on 2024-11-07 at 05:52:28 UTC

    • IP
      187.108.197.138
      Alternative IP(s)
      177.93.105.102
      Network
      187.108.192.0/20
      Domain(s)
      live-ibramerc.com system-octamail.com
      Device

      <enterprise field>: device.class

      Operating System
      Linux Linux Kernel
      Reverse DNS
      smtp-i3.click.live-ibramerc.com
      ASN
      AS53107
      Organization
      EVEO S.A.
      Protocol
      smtp Cert not expired smtp
      Source
      datascan
    • Operating System
      Linux Linux Kernel
    • Issuer Common Name
      R10
      Issuer Organization
      Let's Encrypt
      Subject Common Name
      system-octamail.com
      Subject Alt Name
      system-octamail.com
      SHA256 Fingerprint
      c13ffd61952e32373bb8576c1e84d87f0209662690f5916a7ccc35af4d28c1d5
      Validity Not Before
      2024-09-21T00:01:09Z
      Validity Not After
      2024-12-20T00:01:08Z
    • This feature requires at least a "Lion View" to unlock. Go to our Pricing page for more.

    • Data MD5
      b9455013203f37407ff62ddd527e3114
    • 220 system-octamail.com ESMTP
      250-system-octamail.com
      250-STARTTLS
      250-AUTH LOGIN PLAIN
      250-AUTH=LOGIN PLAIN
      250-PIPELINING
      250 8BITMIME
      220 ready for tls
    • {
         "@category" : "datascan",
         "@timestamp" : "2024-11-07T05:52:28.000Z",
         "alternativeip" : [
            "177.93.105.102"
         ],
         "app" : {
            "length" : 161
         },
         "asn" : "AS53107",
         "basicconstraints" : "critical",
         "ca" : "false",
         "country" : "BR",
         "data" : "220 system-octamail.com ESMTP\r\n250-system-octamail.com\r\n250-STARTTLS\r\n250-AUTH LOGIN PLAIN\r\n250-AUTH=LOGIN PLAIN\r\n250-PIPELINING\r\n250 8BITMIME\r\n220 ready for tls",
         "datamd5" : "b9455013203f37407ff62ddd527e3114",
         "datammh3" : 1108453784,
         "device" : {
            "class" : "<enterprise field>: device.class"
         },
         "domain" : [
            "live-ibramerc.com",
            "system-octamail.com"
         ],
         "extkeyusage" : [
            "serverAuth",
            "clientAuth"
         ],
         "fingerprint" : {
            "md5" : "8e1ecb2fc9fb5a060a44ed50318c14c2",
            "sha1" : "d29386fe471c1f52c4d5830a286b81d3172205eb",
            "sha256" : "c13ffd61952e32373bb8576c1e84d87f0209662690f5916a7ccc35af4d28c1d5"
         },
         "geolocus" : {
            "asn" : "AS53107",
            "continent" : "SA",
            "continentname" : "South America",
            "country" : "BR",
            "countryname" : "Brazil",
            "domain" : [
               "cert.br",
               "eveo.com.br",
               "eveocloud.net"
            ],
            "isineu" : "false",
            "latitude" : "-14.235004",
            "location" : "-14.235004,-51.92528",
            "longitude" : "-51.92528",
            "netname" : "07.358.108/0001-08",
            "organization" : "EVEO S.A.",
            "subnet" : "187.108.192.0/20"
         },
         "host" : [
            "smtp-i3"
         ],
         "hostname" : [
            "smtp-i3.click.live-ibramerc.com",
            "system-octamail.com"
         ],
         "ip" : "187.108.197.138",
         "ipv6" : "false",
         "issuer" : {
            "commonname" : "R10",
            "country" : "US",
            "organization" : "Let's Encrypt"
         },
         "keyusage" : [
            "digitalSignature",
            "keyEncipherment"
         ],
         "latitude" : "-22.8305",
         "location" : "-22.8305,-43.2192",
         "longitude" : "-43.2192",
         "node" : {
            "country" : "<enterprise field>: node.country",
            "groupid" : "<enterprise field>: node.groupid",
            "id" : "<enterprise field>: node.id",
            "physicalcountry" : "<enterprise field>: node.physicalcountry"
         },
         "organization" : "EVEO S.A.",
         "os" : "Linux Kernel",
         "osvendor" : "Linux",
         "port" : 25,
         "protocol" : "smtp",
         "publickey" : {
            "algorithm" : "rsaEncryption",
            "length" : 2048
         },
         "reverse" : [
            "smtp-i3.click.live-ibramerc.com"
         ],
         "seen_date" : "2024-11-07",
         "serial" : "04:00:3f:75:df:8d:a6:44:45:2f:8e:b4:ad:a1:0b:56:09:2b",
         "signature" : {
            "algorithm" : "sha256WithRSAEncryption"
         },
         "source" : "datascan",
         "subdomains" : [
            "click.live-ibramerc.com"
         ],
         "subject" : {
            "altname" : [
               "system-octamail.com"
            ],
            "commonname" : "system-octamail.com"
         },
         "subnet" : "187.108.192.0/20",
         "tld" : [
            "com"
         ],
         "tls" : "true",
         "transport" : "tcp",
         "validity" : {
            "notafter" : "2024-12-20T00:01:08Z",
            "notbefore" : "2024-09-21T00:01:09Z"
         },
         "version" : "v3",
         "wildcard" : "false"
      }