PORT STATE SERVICE 21/tcp open ftp 53/tcp open domain 80/tcp open http 88/tcp open kerberos-sec 135/tcp open msrpc 139/tcp open netbios-ssn 389/tcp open ldap 443/tcp open https 445/tcp open microsoft-ds 464/tcp open kpasswd5 593/tcp open http-rpc-epmap 636/tcp open ldapssl 3268/tcp open globalcatLDAP 3269/tcp open globalcatLDAPssl 3389/tcp open ms-wbt-server 5985/tcp open wsman 9389/tcp open adws 49664/tcp open unknown 49669/tcp open unknown 50237/tcp open unknown 50242/tcp open unknown 50380/tcp open unknown 54311/tcp open unknown 54313/tcp open unknown
PORT STATE SERVICE VERSION 21/tcp open ftp Microsoft ftpd | ftp-anon: Anonymous FTP login allowed (FTP code 230) | 06-29-22 04:55PM <DIR> app | 06-29-22 04:33PM <DIR> benign | 06-29-22 01:41PM <DIR> malicious |_10-31-25 03:40PM <DIR> queue | ftp-syst: |_ SYST: Windows_NT 53/tcp open domain Simple DNS Plus 80/tcp open http Microsoft IIS httpd 10.0 |_http-server-header: Microsoft-IIS/10.0 | http-methods: |_ Potentially risky methods: TRACE |_http-title: IIS Windows Server 88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2025-10-31 17:02:17Z) 135/tcp open msrpc Microsoft Windows RPC 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: bruno.vl0., Site: Default-First-Site-Name) | ssl-cert: Subject: | Subject Alternative Name: DNS:brunodc.bruno.vl, DNS:bruno.vl, DNS:BRUNO | Not valid before: 2025-10-09T09:54:08 |_Not valid after: 2105-10-09T09:54:08 |_ssl-date: 2025-10-31T17:03:53+00:00; +1s from scanner time. 443/tcp open ssl/http Microsoft IIS httpd 10.0 | tls-alpn: |_ http/1.1 |_http-server-header: Microsoft-IIS/10.0 | ssl-cert: Subject: commonName=bruno-BRUNODC-CA | Not valid before: 2022-06-29T13:23:01 |_Not valid after: 2121-06-29T13:33:00 | http-methods: |_ Potentially risky methods: TRACE |_ssl-date: TLS randomness does not represent time |_http-title: IIS Windows Server 445/tcp open microsoft-ds? 464/tcp open kpasswd5? 593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 636/tcp open ssl/ldap |_ssl-date: 2025-10-31T17:03:52+00:00; 0s from scanner time. | ssl-cert: Subject: | Subject Alternative Name: DNS:brunodc.bruno.vl, DNS:bruno.vl, DNS:BRUNO | Not valid before: 2025-10-09T09:54:08 |_Not valid after: 2105-10-09T09:54:08 3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: bruno.vl0., Site: Default-First-Site-Name) | ssl-cert: Subject: | Subject Alternative Name: DNS:brunodc.bruno.vl, DNS:bruno.vl, DNS:BRUNO | Not valid before: 2025-10-09T09:54:08 |_Not valid after: 2105-10-09T09:54:08 |_ssl-date: 2025-10-31T17:03:52+00:00; 0s from scanner time. 3269/tcp open ssl/ldap Microsoft Windows Active Directory LDAP (Domain: bruno.vl0., Site: Default-First-Site-Name) | ssl-cert: Subject: | Subject Alternative Name: DNS:brunodc.bruno.vl, DNS:bruno.vl, DNS:BRUNO | Not valid before: 2025-10-09T09:54:08 |_Not valid after: 2105-10-09T09:54:08 |_ssl-date: 2025-10-31T17:03:52+00:00; 0s from scanner time. 3389/tcp open ms-wbt-server Microsoft Terminal Services |_ssl-date: 2025-10-31T17:03:52+00:00; 0s from scanner time. | ssl-cert: Subject: commonName=brunodc.bruno.vl | Not valid before: 2025-10-08T09:36:40 |_Not valid after: 2026-04-09T09:36:40 | rdp-ntlm-info: | Target_Name: BRUNO | NetBIOS_Domain_Name: BRUNO | NetBIOS_Computer_Name: BRUNODC | DNS_Domain_Name: bruno.vl | DNS_Computer_Name: brunodc.bruno.vl | DNS_Tree_Name: bruno.vl | Product_Version: 10.0.20348 |_ System_Time: 2025-10-31T17:03:14+00:00 5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-server-header: Microsoft-HTTPAPI/2.0 |_http-title: Not Found 9389/tcp open mc-nmf .NET Message Framing 49664/tcp open msrpc Microsoft Windows RPC 49669/tcp open msrpc Microsoft Windows RPC 50237/tcp open msrpc Microsoft Windows RPC 50242/tcp open msrpc Microsoft Windows RPC 50380/tcp open msrpc Microsoft Windows RPC 54311/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 54313/tcp open msrpc Microsoft Windows RPC Service Info: Host: BRUNODC; OS: Windows; CPE: cpe:/o:microsoft:windows
由此得出结论:
系统为 window 域环境,开放有 HTTP、FTP、WINRM 和 Windows 域控的一些默认服务。