Skip to content

Instantly share code, notes, and snippets.

@haise0
Created December 30, 2021 10:13
Show Gist options
  • Save haise0/9fceb309b03442f66810e955c2909e7c to your computer and use it in GitHub Desktop.
Save haise0/9fceb309b03442f66810e955c2909e7c to your computer and use it in GitHub Desktop.

MALICIOUS LINK ANALYSIS

status: unreported, under investigation

whois

   Domain Name: DISCORDE-GIFTE.COM
   Registry Domain ID: 2664915652_DOMAIN_COM-VRSN
   Registrar WHOIS Server: whois.reg.com
   Registrar URL: http://www.reg.ru
   Updated Date: 2021-12-30T09:59:47Z
   Creation Date: 2021-12-30T09:59:45Z
   Registry Expiry Date: 2022-12-30T09:59:45Z
   Registrar: REGISTRAR OF DOMAIN NAMES REG.RU LLC
   Registrar IANA ID: 1606
   Registrar Abuse Contact Email:
   Registrar Abuse Contact Phone:
   Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
   Name Server: NS1.REG.RU
   Name Server: NS2.REG.RU
   DNSSEC: unsigned
   URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
>>> Last update of whois database: 2021-12-30T08:18:49Z <<<

For more information on Whois status codes, please visit https://icann.org/epp

NOTICE: The expiration date displayed in this record is the date the
registrar's sponsorship of the domain name registration in the registry is
currently set to expire. This date does not necessarily reflect the expiration
date of the domain name registrant's agreement with the sponsoring
registrar.  Users may consult the sponsoring registrar's Whois database to
view the registrar's reported date of expiration for this registration.

TERMS OF USE: You are not authorized to access or query our Whois
database through the use of electronic processes that are high-volume and
automated except as reasonably necessary to register domain names or
modify existing registrations; the Data in VeriSign Global Registry
Services' ("VeriSign") Whois database is provided by VeriSign for
information purposes only, and to assist persons in obtaining information
about or related to a domain name registration record. VeriSign does not
guarantee its accuracy. By submitting a Whois query, you agree to abide
by the following terms of use: You agree that you may use this Data only
for lawful purposes and that under no circumstances will you use this Data
to: (1) allow, enable, or otherwise support the transmission of mass
unsolicited, commercial advertising or solicitations via e-mail, telephone,
or facsimile; or (2) enable high volume, automated, electronic processes
that apply to VeriSign (or its computer systems). The compilation,
repackaging, dissemination or other use of this Data is expressly
prohibited without the prior written consent of VeriSign. You agree not to
use electronic processes that are automated and high-volume to access or
query the Whois database except as reasonably necessary to register
domain names or modify existing registrations. VeriSign reserves the right
to restrict your access to the Whois database in its sole discretion to ensure
operational stability.  VeriSign may restrict or terminate your access to the
Whois database for failure to abide by these terms of use. VeriSign
reserves the right to modify these terms at any time.

The Registry database contains ONLY .COM, .NET, .EDU domains and
Registrars.

Domain name: DISCORDE-GIFTE.COM
Registry Domain ID: 2664915652_DOMAIN_COM-VRSN
Registrar WHOIS Server: whois.reg.com
Registrar URL: https://www.reg.com
Registrar URL: https://www.reg.ru
Updated Date: 2021-12-30T09:59:47Z
Creation Date: 2021-12-30T09:59:45Z
Registrar Registration Expiration Date: 2022-12-30T09:59:45Z
Registrar: Registrar of domain names REG.RU LLC
Registrar IANA ID: 1606
Registrar Abuse Contact Email: [email protected]
Registrar Abuse Contact Phone: +7.4955801111
Status: clientTransferProhibited http://www.icann.org/epp#clientTransferProhibited
Registry Registrant ID:
Registrant Name: Pavel Morozov
Registrant Organization: Private Person
Registrant Street: Labyest,1,10
Registrant City: Laski
Registrant State/Province: Moscow
Registrant Postal Code: 101100
Registrant Country: RU
Registrant Phone: +7.9004952466
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email: [email protected]
Registry Admin ID:
Admin Name: Pavel Morozov
Admin Organization: Private Person
Admin Street: Labyest,1,10
Admin City: Laski
Admin State/Province: Moscow
Admin Postal Code: 101100
Admin Country: RU
Admin Phone: +7.9004952466
Admin Phone Ext:
Admin Fax: +7.9004952466
Admin Fax Ext:
Admin Email: [email protected]
Registry Tech ID:
Tech Name: Pavel Morozov
Tech Organization: Private Person
Tech Street: Labyest,1,10
Tech City: Laski
Tech State/Province: Moscow
Tech Postal Code: 101100
Tech Country: RU
Tech Phone: +7.9004952466
Tech Phone Ext:
Tech Fax: +7.9004952466
Tech Fax Ext:
Tech Email: [email protected]
Name Server: ns1.reg.ru
Name Server: ns2.reg.ru
DNSSEC: Unsigned
URL of the ICANN WHOIS Data Problem Reporting System: http://wdprs.internic.net/
>>> Last update of WHOIS database: 2021.12.30T13:06:39Z <<<

For more information on Whois status codes, please visit
https://www.icann.org/resources/pages/epp-status-codes-2014-06-16-en.

TERMS OF USE: The Whois and RDAP services are provided by REG.RU, and contain
information pertaining to Internet domain names registered by our
customers. By using this service you are agreeing (1) not to use any
information presented here for any purpose other than determining
ownership of domain names, (2) not to store or reproduce this data in
any way, (3) not to use any high-volume, automated, electronic processes
to obtain data from this service. Abuse of this service is monitored and
actions in contravention of these terms will result in being permanently
blacklisted. All data is (c) Registrar of Domain Names REG.RU LLC (https://www.reg.com)```

## discord message
### to those reading, **DON'T** click this!
`"airdrop discord nitro by steam, take it https://discorde-gifte.com/best"`

## behavior
typical. link dm'ed to all people in messages

@haise0
Copy link
Author

haise0 commented Dec 30, 2021

ping:

64 bytes from 190.115.18.153 (190.115.18.153): icmp_seq=1 ttl=47 time=198 ms
64 bytes from 190.115.18.153 (190.115.18.153): icmp_seq=2 ttl=47 time=196 ms
--- discorde-gifte.com ping statistics ---
2 packets transmitted, 2 received, 0% packet loss, time 1236ms
rtt min/avg/max/mdev = 195.582/196.982/198.383/1.400 ms```

@haise0
Copy link
Author

haise0 commented Dec 30, 2021

SHODAN info on ip

  "area_code": null,
  "asn": "AS262254",
  "city": "Belize City",
  "country_code": "BZ",
  "country_name": "Belize",
  "data": [
    {
      "_shodan": {
        "crawler": "0d90a5501831fb4236df86ef4689a0ef1c133823",
        "id": "6d921f22-3b4c-4e0c-99d8-00ce6258a468",
        "module": "ssh",
        "options": {
          "scan": "XuBCEtjOmychPMni"
        },
        "ptr": true
      },
      "asn": "AS262254",
      "cpe": [
        "cpe:/a:openbsd:openssh:7.9p1",
        "cpe:/o:debian:debian_linux",
        "cpe:/o:linux:linux_kernel"
      ],
      "cpe23": [
        "cpe:2.3:a:openbsd:openssh:7.9p1",
        "cpe:2.3:o:debian:debian_linux",
        "cpe:2.3:o:linux:linux_kernel"
      ],
      "data": "SSH-2.0-OpenSSH_7.9p1 Debian-10+deb10u2\nKey type: ssh-rsa\nKey: AAAAB3NzaC1yc2EAAAADAQABAAABAQDJh5t5mTTaDQcIsk2UREVn0jCuLZrM9HomWIhnJaHk7eLD\n8/mkg2jh1gKvNzyE/22svv85CmUFefhOxHWjUN8nLQ5SCCbGPeuOoQnVJncLF8Q1x2ulCsxWPduu\nvAcFEkI0B+x4vht9/UEihiMXT2cJnBs5XQoA5/KIyBNE2z7aaGZi1I9TxcvrfpIUFbNf9UaOIKnl\nO7CblUV3r5oC8GcsbuUXRJrtBCyBP8Zhfxn5BYhznHkaZssfhys8Kqec3itDOB6v9hkil1BZbJz/\naREF1gQFpPgMYiY/Owugr8ZuowElTFoPzoHHxT6peRKziYU0iR4pIIFUu6ldPGNJNvnv\nFingerprint: e0:ac:c9:44:4c:63:98:8c:01:e8:8f:23:57:d5:63:4e\n\nKex Algorithms:\n curve25519-sha256\n [email protected]\n ecdh-sha2-nistp256\n ecdh-sha2-nistp384\n ecdh-sha2-nistp521\n diffie-hellman-group-exchange-sha256\n diffie-hellman-group16-sha512\n diffie-hellman-group18-sha512\n diffie-hellman-group14-sha256\n diffie-hellman-group14-sha1\n\nServer Host Key Algorithms:\n rsa-sha2-512\n rsa-sha2-256\n ssh-rsa\n ecdsa-sha2-nistp256\n ssh-ed25519\n\nEncryption Algorithms:\n [email protected]\n aes128-ctr\n aes192-ctr\n aes256-ctr\n [email protected]\n [email protected]\n\nMAC Algorithms:\n [email protected]\n [email protected]\n [email protected]\n [email protected]\n [email protected]\n [email protected]\n [email protected]\n hmac-sha2-256\n hmac-sha2-512\n hmac-sha1\n\nCompression Algorithms:\n none\n [email protected]\n\n",
      "domains": [],
      "hash": -2120651652,
      "hostnames": [],
      "info": "protocol 2.0",
      "ip": 3195212441,
      "ip_str": "190.115.18.153",
      "isp": "DDOS-GUARD CORP.",
      "location": {
        "area_code": null,
        "city": "Belize City",
        "country_code": "BZ",
        "country_name": "Belize",
        "latitude": 17.49952,
        "longitude": -88.19756,
        "postal_code": null,
        "region_code": "BZ"
      },
      "opts": {},
      "org": "DDOS-GUARD CORP.",
      "os": "Debian",
      "port": 22,
      "product": "OpenSSH",
      "ssh": {
        "cipher": "aes128-ctr",
        "fingerprint": "e0:ac:c9:44:4c:63:98:8c:01:e8:8f:23:57:d5:63:4e",
        "hassh": "b12d2871a1189eff20364cf5333619ee",
        "kex": {
          "compression_algorithms": [
            "none",
            "[email protected]"
          ],
          "encryption_algorithms": [
            "[email protected]",
            "aes128-ctr",
            "aes192-ctr",
            "aes256-ctr",
            "[email protected]",
            "[email protected]"
          ],
          "kex_algorithms": [
            "curve25519-sha256",
            "[email protected]",
            "ecdh-sha2-nistp256",
            "ecdh-sha2-nistp384",
            "ecdh-sha2-nistp521",
            "diffie-hellman-group-exchange-sha256",
            "diffie-hellman-group16-sha512",
            "diffie-hellman-group18-sha512",
            "diffie-hellman-group14-sha256",
            "diffie-hellman-group14-sha1"
          ],
          "kex_follows": false,
          "languages": [
            ""
          ],
          "mac_algorithms": [
            "[email protected]",
            "[email protected]",
            "[email protected]",
            "[email protected]",
            "[email protected]",
            "[email protected]",
            "[email protected]",
            "hmac-sha2-256",
            "hmac-sha2-512",
            "hmac-sha1"
          ],
          "server_host_key_algorithms": [
            "rsa-sha2-512",
            "rsa-sha2-256",
            "ssh-rsa",
            "ecdsa-sha2-nistp256",
            "ssh-ed25519"
          ],
          "unused": 0
        },
        "key": "AAAAB3NzaC1yc2EAAAADAQABAAABAQDJh5t5mTTaDQcIsk2UREVn0jCuLZrM9HomWIhnJaHk7eLD\n8/mkg2jh1gKvNzyE/22svv85CmUFefhOxHWjUN8nLQ5SCCbGPeuOoQnVJncLF8Q1x2ulCsxWPduu\nvAcFEkI0B+x4vht9/UEihiMXT2cJnBs5XQoA5/KIyBNE2z7aaGZi1I9TxcvrfpIUFbNf9UaOIKnl\nO7CblUV3r5oC8GcsbuUXRJrtBCyBP8Zhfxn5BYhznHkaZssfhys8Kqec3itDOB6v9hkil1BZbJz/\naREF1gQFpPgMYiY/Owugr8ZuowElTFoPzoHHxT6peRKziYU0iR4pIIFUu6ldPGNJNvnv\n",
        "mac": "hmac-sha2-256",
        "type": "ssh-rsa"
      },
      "timestamp": "2021-12-29T20:55:42.294570",
      "transport": "tcp",
      "version": "7.9p1 Debian 10+deb10u2"
    },
    {
      "_shodan": {
        "crawler": "2f5130275f52c94d38258ee96eca67b55cafa776",
        "id": "de44550a-e82c-4d79-8297-8dbc8c3566d2",
        "module": "https",
        "options": {
          "referrer": "beaa0341-4865-460a-b3ff-0de599889c50",
          "scan": "IIcmsHk5hKXJyyrH",
          "xrun": true
        },
        "ptr": true
      },
      "asn": "AS262254",
      "data": "HTTP/1.1 502 Bad Gateway\r\nServer: ddos-guard\r\nDate: Tue, 28 Dec 2021 20:02:29 GMT\r\nConnection: keep-alive\r\nKeep-Alive: timeout=60\r\nContent-Type: text/html; charset=utf8\r\nContent-Length: 585\r\n\r\n",
      "domains": [],
      "hash": 523285768,
      "hostnames": [],
      "http": {
        "components": {},
        "host": "190.115.18.153",
        "html": "<!DOCTYPE html><html lang=en><meta charset=utf-8><meta name=viewport content=\"initial-scale=1, minimum-scale=1, width=device-width\"><title>Error 502</title><style>*{margin:0;padding:0}html{font:15px/22px arial,sans-serif;background: #fff;color:#222;padding:15px}body{margin:7% auto 0;max-width:390px;min-height:180px;padding:30px 0 15px}p{margin:11px 0 22px;overflow :hidden}ins{color:#777;text-decoration :none;}</style><p><b>502 - Bad Gateway .</b> <ins>That’s an error.</ins><p>Looks like we have got an invalid response from the upstream server.  <ins>That’s all we know.</ins>",
        "html_hash": 537678256,
        "location": "/",
        "redirects": [],
        "robots": null,
        "robots_hash": null,
        "securitytxt": null,
        "securitytxt_hash": null,
        "server": "ddos-guard",
        "sitemap": null,
        "sitemap_hash": null,
        "status": 502,
        "title": "Error 502"
      },
      "ip": 3195212441,
      "ip_str": "190.115.18.153",
      "isp": "DDOS-GUARD CORP.",
      "location": {
        "area_code": null,
        "city": "Belize City",
        "country_code": "BZ",
        "country_name": "Belize",
        "latitude": 17.49952,
        "longitude": -88.19756,
        "postal_code": null,
        "region_code": "BZ"
      },
      "opts": {
        "heartbleed": "2021/12/28 20:02:33 190.115.18.153:443 - SAFE\n",
        "vulns": []
      },
      "org": "DDOS-GUARD CORP.",
      "os": null,
      "port": 443,
      "product": "DDoS-Guard",
      "ssl": {
        "acceptable_cas": [],
        "alpn": [],
        "cert": {
          "expired": false,
          "expires": "20280325192613Z",
          "extensions": [],
          "fingerprint": {
            "sha1": "d4ea61c561c05087ed2ca531d351df8f6d854af0",
            "sha256": "c0e5e374c107df953a89ffe23189e52be7ebaf1df0fc1f9713e68d7b4eef86e4"
          },
          "issued": "20180328192613Z",
          "issuer": {
            "C": "EU",
            "O": "ddos-guard",
            "ST": "*"
          },
          "pubkey": {
            "bits": 2048,
            "type": "rsa"
          },
          "serial": 18045988440546770000,
          "sig_alg": "sha256WithRSAEncryption",
          "subject": {
            "C": "EU",
            "O": "ddos-guard",
            "ST": "*"
          },
          "version": 0
        },
        "chain": [
          "-----BEGIN CERTIFICATE-----\nMIIC2DCCAcACCQD6cDrf+5h8CTANBgkqhkiG9w0BAQsFADAuMQswCQYDVQQGEwJF\nVTEKMAgGA1UECAwBKjETMBEGA1UECgwKZGRvcy1ndWFyZDAeFw0xODAzMjgxOTI2\nMTNaFw0yODAzMjUxOTI2MTNaMC4xCzAJBgNVBAYTAkVVMQowCAYDVQQIDAEqMRMw\nEQYDVQQKDApkZG9zLWd1YXJkMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKC\nAQEAzKzaWH/6SlOzAEg9angONqEF1Oj6XUY0bD7r0RLD4LFCJz+ijj8tvYMrnAud\nRV29cPsd81XvdC+ig7TQG6GMwpNMGf6LkBWpIyhzxpJBi5bkrF9XcgivOhR4vn2T\nPDjtKdL8gnivv1NOcJCPlCkgBHTWQjWmtz2mVT4F63kWySGYLqp6I7W/9Rx8eMDM\nL+o7zFnP0kh6ywOJa4yHWQPwWMvfdXy9uY4EL6Q0Tx3Mh5wGTZ9Q1cQLiGznsKau\nbY9rzH6u2ib/ZN3ZgtH8JtzD8A8V0s6e3cQlzLvNUrMc7yLPnpc738ZgEM2EkL3a\nZyGo8CkpAwcH6JOUJKmrOQ7TewIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQAxdiUM\nbtMJxd5fd9nXNAVy6F032z4xhAeDoNe5wVGHEJ8uqxiX3TVsSPJJnAJGWi/5E79S\n44TP+gst/MwwXZXB4CsRwy3QqB5s1NmedFM9BOBue2YPEuFc20RwHj2i6S4+doHJ\neLuQK3wHiO+/5eUu9KB5OVrY9BT8cBmxj6pzFwiJWgNRXfLzr4SUm6fQMqm13cyC\nCzRahrGQFdPU2TkRlrXgmQwhoOavHnvBogrzD4U8j0I8yOebSGprpKehwGhzTozg\n19/Imahru19aOD42v2C75tWIU/WSzOjFw3za5TxywfaBDLszAmjoTflAid/RM1SD\nAzuxI494CzdwGm1p\n-----END CERTIFICATE-----\n"
        ],
        "chain_sha256": [
          "c0e5e374c107df953a89ffe23189e52be7ebaf1df0fc1f9713e68d7b4eef86e4"
        ],
        "cipher": {
          "bits": 128,
          "name": "TLS_AES_128_GCM_SHA256",
          "version": "TLSv1.3"
        },
        "dhparams": null,
        "handshake_states": [
          "before SSL initialization",
          "SSLv3/TLS write client hello",
          "SSLv3/TLS read server hello",
          "TLSv1.3 read encrypted extensions",
          "SSLv3/TLS read server certificate",
          "TLSv1.3 read server certificate verify",
          "SSLv3/TLS read finished",
          "SSLv3/TLS write change cipher spec",
          "SSLv3/TLS write finished",
          "SSL negotiation finished successfully"
        ],
        "ja3s": "e964448a5b7d6c7cc7d54176ea4271a6",
        "jarm": "29d29d00029d29d21c41d41d000000307ee0eb468e9fdb5cfcd698a80a67ef",
        "ocsp": {},
        "tlsext": [
          {
            "id": 65281,
            "name": "renegotiation_info"
          },
          {
            "id": 11,
            "name": "ec_point_formats"
          },
          {
            "id": 35,
            "name": "session_ticket"
          }
        ],
        "trust": {
          "browser": null,
          "revoked": false
        },
        "versions": [
          "TLSv1",
          "-SSLv2",
          "-SSLv3",
          "TLSv1.1",
          "TLSv1.2",
          "TLSv1.3"
        ]
      },
      "timestamp": "2021-12-28T20:02:29.748927",
      "transport": "tcp"
    },
    {
      "_shodan": {
        "crawler": "2f5130275f52c94d38258ee96eca67b55cafa776",
        "id": "beaa0341-4865-460a-b3ff-0de599889c50",
        "module": "http",
        "options": {
          "scan": "IIcmsHk5hKXJyyrH"
        },
        "ptr": true
      },
      "asn": "AS262254",
      "data": "HTTP/1.1 301 Moved Permanently\r\nServer: ddos-guard\r\nDate: Tue, 28 Dec 2021 20:02:14 GMT\r\nConnection: keep-alive\r\nKeep-Alive: timeout=60\r\nLocation: https://190.115.18.153/\r\nContent-Type: text/html; charset=utf8\r\nContent-Length: 568\r\n\r\n",
      "domains": [],
      "hash": 945507280,
      "hostnames": [],
      "http": {
        "components": {},
        "host": "190.115.18.153",
        "html": "<!DOCTYPE html><html lang=en><meta charset=utf-8><meta name=viewport content=\"initial-scale=1, minimum-scale=1, width=device-width\"><title>Error 301</title><style>*{margin:0;padding:0}html{font:15px/22px arial,sans-serif;background: #fff;color:#222;padding:15px}body{margin:7% auto 0;max-width:390px;min-height:180px;padding:30px 0 15px}p{margin:11px 0 22px;overflow :hidden}ins{color:#777;text-decoration :none;}</style><p><b>301 - Moved Permanently .</b> <ins>That’s an error.</ins><p>Requested content has been permanently moved.  <ins>That’s all we know.</ins>",
        "html_hash": -1087387431,
        "location": "/",
        "redirects": [],
        "robots": null,
        "robots_hash": null,
        "securitytxt": null,
        "securitytxt_hash": null,
        "server": "ddos-guard",
        "sitemap": null,
        "sitemap_hash": null,
        "status": 301,
        "title": "Error 301"
      },
      "ip": 3195212441,
      "ip_str": "190.115.18.153",
      "isp": "DDOS-GUARD CORP.",
      "location": {
        "area_code": null,
        "city": "Belize City",
        "country_code": "BZ",
        "country_name": "Belize",
        "latitude": 17.49952,
        "longitude": -88.19756,
        "postal_code": null,
        "region_code": "BZ"
      },
      "opts": {},
      "org": "DDOS-GUARD CORP.",
      "os": null,
      "port": 80,
      "product": "DDoS-Guard",
      "timestamp": "2021-12-28T20:02:15.018673",
      "transport": "tcp"
    }
  ],
  "domains": [],
  "hostnames": [],
  "ip": 3195212441,
  "ip_str": "190.115.18.153",
  "isp": "DDOS-GUARD CORP.",
  "last_update": "2021-12-29T20:55:42.294570",
  "latitude": 17.49952,
  "longitude": -88.19756,
  "org": "DDOS-GUARD CORP.",
  "os": "Debian",
  "ports": [
    80,
    443,
    22
  ],
  "postal_code": null,
  "region_code": "BZ",
  "tags": []
}```

@haise0
Copy link
Author

haise0 commented Dec 30, 2021

SHODAN - port 443 header info

port 443 header info:

DDoS-Guard

HTTP/1.1 502 Bad Gateway
Server: ddos-guard
Date: Tue, 28 Dec 2021 20:02:29 GMT
Connection: keep-alive
Keep-Alive: timeout=60
Content-Type: text/html; charset=utf8
Content-Length: 585

SSL Certificate

Certificate:
    Data:
        Version: 1 (0x0)
        Serial Number:
            fa:70:3a:df:fb:98:7c:09
        Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=EU, ST=*, O=ddos-guard
        Validity
            Not Before: Mar 28 19:26:13 2018 GMT
            Not After : Mar 25 19:26:13 2028 GMT
        Subject: C=EU, ST=*, O=ddos-guard
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:cc:ac:da:58:7f:fa:4a:53:b3:00:48:3d:6a:78:
                    0e:36:a1:05:d4:e8:fa:5d:46:34:6c:3e:eb:d1:12:
                    c3:e0:b1:42:27:3f:a2:8e:3f:2d:bd:83:2b:9c:0b:
                    9d:45:5d:bd:70:fb:1d:f3:55:ef:74:2f:a2:83:b4:
                    d0:1b:a1:8c:c2:93:4c:19:fe:8b:90:15:a9:23:28:
                    73:c6:92:41:8b:96:e4:ac:5f:57:72:08:af:3a:14:
                    78:be:7d:93:3c:38:ed:29:d2:fc:82:78:af:bf:53:
                    4e:70:90:8f:94:29:20:04:74:d6:42:35:a6:b7:3d:
                    a6:55:3e:05:eb:79:16:c9:21:98:2e:aa:7a:23:b5:
                    bf:f5:1c:7c:78:c0:cc:2f:ea:3b:cc:59:cf:d2:48:
                    7a:cb:03:89:6b:8c:87:59:03:f0:58:cb:df:75:7c:
                    bd:b9:8e:04:2f:a4:34:4f:1d:cc:87:9c:06:4d:9f:
                    50:d5:c4:0b:88:6c:e7:b0:a6:ae:6d:8f:6b:cc:7e:
                    ae:da:26:ff:64:dd:d9:82:d1:fc:26:dc:c3:f0:0f:
                    15:d2:ce:9e:dd:c4:25:cc:bb:cd:52:b3:1c:ef:22:
                    cf:9e:97:3b:df:c6:60:10:cd:84:90:bd:da:67:21:
                    a8:f0:29:29:03:07:07:e8:93:94:24:a9:ab:39:0e:
                    d3:7b
                Exponent: 65537 (0x10001)
    Signature Algorithm: sha256WithRSAEncryption
         31:76:25:0c:6e:d3:09:c5:de:5f:77:d9:d7:34:05:72:e8:5d:
         37:db:3e:31:84:07:83:a0:d7:b9:c1:51:87:10:9f:2e:ab:18:
         97:dd:35:6c:48:f2:49:9c:02:46:5a:2f:f9:13:bf:52:e3:84:
         cf:fa:0b:2d:fc:cc:30:5d:95:c1:e0:2b:11:c3:2d:d0:a8:1e:
         6c:d4:d9:9e:74:53:3d:04:e0:6e:7b:66:0f:12:e1:5c:db:44:
         70:1e:3d:a2:e9:2e:3e:76:81:c9:78:bb:90:2b:7c:07:88:ef:
         bf:e5:e5:2e:f4:a0:79:39:5a:d8:f4:14:fc:70:19:b1:8f:aa:
         73:17:08:89:5a:03:51:5d:f2:f3:af:84:94:9b:a7:d0:32:a9:
         b5:dd:cc:82:0b:34:5a:86:b1:90:15:d3:d4:d9:39:11:96:b5:
         e0:99:0c:21:a0:e6:af:1e:7b:c1:a2:0a:f3:0f:85:3c:8f:42:
         3c:c8:e7:9b:48:6a:6b:a4:a7:a1:c0:68:73:4e:8c:e0:d7:df:
         c8:99:a8:6b:bb:5f:5a:38:3e:36:bf:60:bb:e6:d5:88:53:f5:
         92:cc:e8:c5:c3:7c:da:e5:3c:72:c1:f6:81:0c:bb:33:02:68:
         e8:4d:f9:40:89:df:d1:33:54:83:03:3b:b1:23:8f:78:0b:37:
         70:1a:6d:69

@haise0
Copy link
Author

haise0 commented Dec 30, 2021

SHODAN - port 22 info

OpenSSH 7.9p1 Debian 10+deb10u2

SSH-2.0-OpenSSH_7.9p1 Debian-10+deb10u2
Key type: ssh-rsa
Key: AAAAB3NzaC1yc2EAAAADAQABAAABAQDJh5t5mTTaDQcIsk2UREVn0jCuLZrM9HomWIhnJaHk7eLD
8/mkg2jh1gKvNzyE/22svv85CmUFefhOxHWjUN8nLQ5SCCbGPeuOoQnVJncLF8Q1x2ulCsxWPduu
vAcFEkI0B+x4vht9/UEihiMXT2cJnBs5XQoA5/KIyBNE2z7aaGZi1I9TxcvrfpIUFbNf9UaOIKnl
O7CblUV3r5oC8GcsbuUXRJrtBCyBP8Zhfxn5BYhznHkaZssfhys8Kqec3itDOB6v9hkil1BZbJz/
aREF1gQFpPgMYiY/Owugr8ZuowElTFoPzoHHxT6peRKziYU0iR4pIIFUu6ldPGNJNvnv
Fingerprint: e0:ac:c9:44:4c:63:98:8c:01:e8:8f:23:57:d5:63:4e

Kex Algorithms:
	curve25519-sha256
	[email protected]
	ecdh-sha2-nistp256
	ecdh-sha2-nistp384
	ecdh-sha2-nistp521
	diffie-hellman-group-exchange-sha256
	diffie-hellman-group16-sha512
	diffie-hellman-group18-sha512
	diffie-hellman-group14-sha256
	diffie-hellman-group14-sha1

Server Host Key Algorithms:
	rsa-sha2-512
	rsa-sha2-256
	ssh-rsa
	ecdsa-sha2-nistp256
	ssh-ed25519

Encryption Algorithms:
	[email protected]
	aes128-ctr
	aes192-ctr
	aes256-ctr
	[email protected]
	[email protected]

MAC Algorithms:
	[email protected]
	[email protected]
	[email protected]
	[email protected]
	[email protected]
	[email protected]
	[email protected]
	hmac-sha2-256
	hmac-sha2-512
	hmac-sha1

Compression Algorithms:
	none
	[email protected]

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment