Reading the observatory store…
Reading the observatory store…
First seen 22 Sep 2026, last seen 24 Sep 2026 10:07 UTC (2h ago). 2 observations on record. Location is an estimate derived from registration data — the source and confidence are stated below.
| Port | Service | Product | Technologies | TLS | State | Banner | Last seen |
|---|---|---|---|---|---|---|---|
| 22 tcp / tcp | ssh | not identified | none detected | not negotiated | open | SSH-2.0-ROSSSH | 24 Sep 2026 2h ago |
| 80 tcp / tcp | http | Apache HTTP Server 2.4.29 |
| not negotiated | open | no banner captured | 24 Sep 2026 2h ago |
| 443 tcp / tcp | https | not identified | none detected | not negotiated | open | no banner captured | 24 Sep 2026 2h ago |
| Observed at | Source | Collector | Confidence | Changed | State | Content hash |
|---|---|---|---|---|---|---|
| 24 Sep 2026 10:07 UTC | fingerprint | fingerprint-1 | high | changed | {"services":{"22/tcp":{"state":"open","product":"","version":"","cert_sha256":"","tls_version":"","service_type":"ssh"},"80/tcp":{"state":"open","product":"Apa… | 969247b306a0172ada48b41d6a915f90f97f66f… |
| 22 Sep 2026 09:32 UTC | fingerprint | fingerprint-1 | high | changed | {} | d9739baa9eaeb16c9ccd718988a0aef0a4e6e6b… |
| Detected at | Type | Field | Previous | Current | Significance | Confidence |
|---|---|---|---|---|---|---|
| 24 Sep 2026 10:07 UTC | TECHNOLOGY CHANGED | — | — | apache-http-server | low | unknown |
| 24 Sep 2026 10:07 UTC | NEW SERVICE | service:80/tcp | — | Apache HTTP Server 2.4.29 | low | unknown |
| 24 Sep 2026 10:07 UTC | NEW SERVICE | service:443/tcp | — | https | low | unknown |
| 24 Sep 2026 10:07 UTC | NEW SERVICE | service:22/tcp | — | ssh | low | unknown |
| 22 Sep 2026 09:32 UTC | NEW ASSET | — | — | asset with no observed open endpoints | low | unknown |
2 matches on this asset, each one unverified. Treat these as leads for manual review, never as findings.
| Identifier | Severity | CVSS | Product / version | Status | Match confidence | Evidence | Detected |
|---|---|---|---|---|---|---|---|
CVE-2018-1312 In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster … | critical | 9.8 | Apache HTTP Server 2.4.29 | potential exposure — unverified | medium | {"match_reason":"keyword match on \"Apache HTTP Server 2.4.29\"","note":"version-string match only; not a confirmed exp… | 24 Sep 2026 |
CVE-2018-1283 In Apache httpd 2.4.0 to 2.4.29, when mod_session is configured to forward its session data to CGI applications (SessionEnv on, not the default), a remote user may influence their content by using a … | medium | 5.3 | Apache HTTP Server 2.4.29 | potential exposure — unverified | medium | {"match_reason":"keyword match on \"Apache HTTP Server 2.4.29\"","note":"version-string match only; not a confirmed exp… | 24 Sep 2026 |
| Field | Previous | Current | Reading |
|---|---|---|---|
| services.22/tcp.cert_sha256 | — | — | appeared |
| services.22/tcp.product | — | — | appeared |
| services.22/tcp.service_type | — | ssh | appeared |
| services.22/tcp.state | — | open | appeared |
| services.22/tcp.tls_version | — | — | appeared |
| services.22/tcp.version | — | — | appeared |
| services.443/tcp.cert_sha256 | — | — | appeared |
| services.443/tcp.product | — | — | appeared |
| services.443/tcp.service_type | — | https | appeared |
| services.443/tcp.state | — | open | appeared |
| services.443/tcp.tls_version | — | — | appeared |
| services.443/tcp.version | — | — | appeared |
| services.80/tcp.cert_sha256 | — | — | appeared |
| services.80/tcp.product | — | Apache HTTP Server | appeared |
| services.80/tcp.service_type | — | http | appeared |
| services.80/tcp.state | — | open | appeared |
| services.80/tcp.tls_version | — | — | appeared |
| services.80/tcp.version | — | 2.4.29 | appeared |
| technologies | — | ["apache-http-server"] | appeared |
{
"id": "c4204004d83071c7c14672c102e0e1529",
"type": "ipv4",
"value": "150.107.106.232",
"hostname": null,
"reverseDns": null,
"asn": {
"number": 45650,
"name": "VIANET-NP - VIA NET COMMUNICATION LTD."
},
"organization": {
"id": "cab06f284564735b512d5ccdf7339b220",
"name": "VIANET-NP - VIA NET COMMUNICATION LTD."
},
"location": {
"country": "NP",
"city": "Biratnagar",
"province": "Koshi",
"district": "",
"confidence": "low",
"source": "ip-api.com"
},
"scopeStatus": "in_scope",
"priority": "NORMAL",
"firstSeen": "2026-09-22T05:02:19.028Z",
"lastSeen": "2026-09-24T10:07:54.837Z",
"observationCount": 2,
"openServices": 3,
"serviceCount": 3,
"technologies": [
"apache-http-server"
],
"vulnerabilityMatches": [
{
"id": "c2e1c84f5df4f18f3122a6b1a1acac3b7",
"cve": "CVE-2018-1312",
"severity": "critical",
"cvssScore": 9.8,
"summary": "In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an attacker without detection.",
"product": "Apache HTTP Server",
"version": "2.4.29",
"status": "potential",
"matchConfidence": "medium",
"evidence": "{\"match_reason\":\"keyword match on \\\"Apache HTTP Server 2.4.29\\\"\",\"note\":\"version-string match only; not a confirmed exposure\",\"observed_product\":\"Apache HTTP Server\",\"observed_version\":\"2.4.29\",\"source\":\"nvd\"}",
"detectedAt": "2026-09-24T10:25:03.982Z",
"assetValue": "150.107.106.232",
"serviceId": "c98cdeae4c4010f6ae45a5097080a3ff9",
"port": 80,
"technologySlug": "apache-http-server"
},
{
"id": "c19bfef1c3d628d2bd7cc17926d08b1b2",
"cve": "CVE-2018-1283",
"severity": "medium",
"cvssScore": 5.3,
"summary": "In Apache httpd 2.4.0 to 2.4.29, when mod_session is configured to forward its session data to CGI applications (SessionEnv on, not the default), a remote user may influence their content by using a \"Session\" header. This comes from the \"HTTP_SESSION\" variable name used by mod_session to forward its data to CGIs, since the prefix \"HTTP_\" is also used by the Apache HTTP Server to pass HTTP header fields, per CGI specifications.",
"product": "Apache HTTP Server",
"version": "2.4.29",
"status": "potential",
"matchConfidence": "medium",
"evidence": "{\"match_reason\":\"keyword match on \\\"Apache HTTP Server 2.4.29\\\"\",\"note\":\"version-string match only; not a confirmed exposure\",\"observed_product\":\"Apache HTTP Server\",\"observed_version\":\"2.4.29\",\"source\":\"nvd\"}",
"detectedAt": "2026-09-24T10:25:03.980Z",
"assetValue": "150.107.106.232",
"serviceId": "c98cdeae4c4010f6ae45a5097080a3ff9",
"port": 80,
"technologySlug": "apache-http-server"
}
],
"network": {
"id": "cb2d6fa59b9a167c919bd2ce0b6fd4c5e",
"prefix": "150.107.106.0/24",
"ipVersion": 4
},
"services": [
{
"id": "c9b7b6fb9848b7216365504ba2202a286",
"assetId": "c4204004d83071c7c14672c102e0e1529",
"assetValue": null,
"port": 22,
"protocol": "tcp",
"transport": "tcp",
"serviceType": "ssh",
"product": null,
"productVersion": null,
"tlsVersion": null,
"banner": "SSH-2.0-ROSSSH",
"state": "open",
"firstSeen": "2026-09-24T10:07:54.792Z",
"lastSeen": "2026-09-24T10:07:54.792Z",
"observationCount": 0,
"technologies": [],
"certificate": null
},
{
"id": "c98cdeae4c4010f6ae45a5097080a3ff9",
"assetId": "c4204004d83071c7c14672c102e0e1529",
"assetValue": null,
"port": 80,
"protocol": "tcp",
"transport": "tcp",
"serviceType": "http",
"product": "Apache HTTP Server",
"productVersion": "2.4.29",
"tlsVersion": null,
"banner": null,
"state": "open",
"firstSeen": "2026-09-24T10:07:54.802Z",
"lastSeen": "2026-09-24T10:07:54.802Z",
"observationCount": 0,
"technologies": [
{
"slug": "apache-http-server",
"name": "Apache HTTP Server",
"category": "web-server",
"vendor": "Apache Software Foundation",
"version": "2.4.29",
"confidence": "high",
"evidence": "server: Apache/2.4.29 (Ubuntu)",
"detectedAt": "2026-09-24T10:07:54.807Z"
}
],
"certificate": null
},
{
"id": "c3eaa088c49c22096d8d0e58d6e5f8773",
"assetId": "c4204004d83071c7c14672c102e0e1529",
"assetValue": null,
"port": 443,
"protocol": "tcp",
"transport": "tcp",
"serviceType": "https",
"product": null,
"productVersion": null,
"tlsVersion": null,
"banner": null,
"state": "open",
"firstSeen": "2026-09-24T10:07:54.816Z",
"lastSeen": "2026-09-24T10:07:54.816Z",
"observationCount": 0,
"technologies": [],
"certificate": null
}
],
"certificates": [],
"recentObservations": [
{
"id": "c2defb1f824555bbb95bf176c7c08187a",
"observedAt": "2026-09-24T10:07:54.821Z",
"source": "fingerprint",
"collector": "fingerprint-1",
"confidence": "high",
"state": {
"services": {
"22/tcp": {
"state": "open",
"product": "",
"version": "",
"cert_sha256": "",
"tls_version": "",
"service_type": "ssh"
},
"80/tcp": {
"state": "open",
"product": "Apache HTTP Server",
"version": "2.4.29",
"cert_sha256": "",
"tls_version": "",
"service_type": "http"
},
"443/tcp": {
"state": "open",
"product": "",
"version": "",
"cert_sha256": "",
"tls_version": "",
"service_type": "https"
}
},
"technologies": [
"apache-http-server"
]
},
"evidence": {
"ports": [
21,
22,
23,
25,
53,
80,
110,
143,
443,
445,
465,
587,
993,
995,
1433,
1521,
3306,
3389,
5432,
5900,
6379,
8080,
8443,
8888,
9200,
27017
],
"services": 3,
"reachable": true,
"reverse_dns": "",
"ports_probed": 26,
"technologies": [
"apache-http-server"
],
"open_services": 3,
"probe_duration": 26448
},
"contentHash": "969247b306a0172ada48b41d6a915f90f97f66fa190f2829a0adadfeed1db015",
"changed": true
},
{
"id": "c9626bc3b18cac1dde13ea8d227301d06",
"observedAt": "2026-09-22T09:32:27.768Z",
"source": "fingerprint",
"collector": "fingerprint-1",
"confidence": "high",
"state": {},
"evidence": {
"ports": [
21,
22,
23,
25,
53,
80,
110,
143,
443,
445,
587,
993,
995,
1433,
1521,
3306,
3389,
5432,
5900,
6379,
8080,
8443,
8888,
9200,
27017
],
"services": 0,
"reachable": false,
"reverse_dns": "",
"ports_probed": 25,
"technologies": null,
"open_services": 0,
"probe_duration": 1505
},
"contentHash": "d9739baa9eaeb16c9ccd718988a0aef0a4e6e6bf87f946b149c881319f8400b9",
"changed": true
}
],
"recentChanges": [
{
"id": "c92fc882af296ae72f7206b70ada4b2ae",
"changeType": "TECHNOLOGY_CHANGED",
"assetId": "c4204004d83071c7c14672c102e0e1529",
"assetValue": null,
"field": null,
"previousValue": null,
"currentValue": "apache-http-server",
"detectedAt": "2026-09-24T10:07:54.834Z",
"significance": "low",
"severity": "info",
"confidence": null,
"detail": "technology detected: apache-http-server",
"serviceId": null
},
{
"id": "ce5044cbce73d8831aa7763dc9cb30097",
"changeType": "NEW_SERVICE",
"assetId": "c4204004d83071c7c14672c102e0e1529",
"assetValue": null,
"field": "service:80/tcp",
"previousValue": null,
"currentValue": "Apache HTTP Server 2.4.29",
"detectedAt": "2026-09-24T10:07:54.832Z",
"significance": "low",
"severity": "notice",
"confidence": null,
"detail": "newly observed open endpoint",
"serviceId": null
},
{
"id": "c515c905e543f56295991d1c8d5e0bf7f",
"changeType": "NEW_SERVICE",
"assetId": "c4204004d83071c7c14672c102e0e1529",
"assetValue": null,
"field": "service:443/tcp",
"previousValue": null,
"currentValue": "https",
"detectedAt": "2026-09-24T10:07:54.829Z",
"significance": "low",
"severity": "notice",
"confidence": null,
"detail": "newly observed open endpoint",
"serviceId": null
},
{
"id": "cf7c956f2792115c8220229c2eec6adbf",
"changeType": "NEW_SERVICE",
"assetId": "c4204004d83071c7c14672c102e0e1529",
"assetValue": null,
"field": "service:22/tcp",
"previousValue": null,
"currentValue": "ssh",
"detectedAt": "2026-09-24T10:07:54.825Z",
"significance": "low",
"severity": "notice",
"confidence": null,
"detail": "newly observed open endpoint",
"serviceId": null
},
{
"id": "c82f6f7eb133d6d6e837c59d344548927",
"changeType": "NEW_ASSET",
"assetId": "c4204004d83071c7c14672c102e0e1529",
"assetValue": null,
"field": null,
"previousValue": null,
"currentValue": "asset with no observed open endpoints",
"detectedAt": "2026-09-22T09:32:27.773Z",
"significance": "low",
"severity": "notice",
"confidence": null,
"detail": "asset observed for the first time",
"serviceId": null
}
],
"dnsRecords": [],
"state": {
"current": {
"services": {
"22/tcp": {
"state": "open",
"product": "",
"version": "",
"cert_sha256": "",
"tls_version": "",
"service_type": "ssh"
},
"80/tcp": {
"state": "open",
"product": "Apache HTTP Server",
"version": "2.4.29",
"cert_sha256": "",
"tls_version": "",
"service_type": "http"
},
"443/tcp": {
"state": "open",
"product": "",
"version": "",
"cert_sha256": "",
"tls_version": "",
"service_type": "https"
}
},
"technologies": [
"apache-http-server"
]
},
"previous": {},
"comparable": true
}
}