In case , compromised machine(172.56.1.1) has multiple internal networks(192.162.1.1 & 162.65.1.1) and ports , then dynamic port fowarding on attacker machine(111.11.11.11) is used for both local and remote method

proxychains nmap -sV 162.65.1.1