Reading the observatory store…
Reading the observatory store…
First seen 22 Sep 2026, last seen 22 Sep 2026 21:24 UTC (11h ago). 1 observations on record. Location is an estimate derived from registration data — the source and confidence are stated below.
| Port | Service | Product | Technologies | TLS | State | Banner | Last seen |
|---|---|---|---|---|---|---|---|
| 22 tcp / tcp | ssh | OpenSSH 9.7 |
| not negotiated | open | SSH-2.0-OpenSSH_9.7 with CVE-2024-6387,CVE-2024-39894 fixes | 22 Sep 2026 11h ago |
| Observed at | Source | Collector | Confidence | Changed | State | Content hash |
|---|---|---|---|---|---|---|
| 22 Sep 2026 21:24 UTC | fingerprint | fingerprint-1 | high | changed | {"services":{"22/tcp":{"state":"open","product":"OpenSSH","version":"9.7","cert_sha256":"","tls_version":"","service_type":"ssh"}},"technologies":["openssh"]} | 79ede7c0ec00b524529dfbc6002092c370556a2… |
| Detected at | Type | Field | Previous | Current | Significance | Confidence |
|---|---|---|---|---|---|---|
| 22 Sep 2026 21:24 UTC | NEW SERVICE | service:22/tcp | — | OpenSSH 9.7 | low | unknown |
| 22 Sep 2026 21:24 UTC | NEW ASSET | — | — | asset with 1 observed open endpoint(s) | low | unknown |
1 match on this asset, each one unverified. Treat these as leads for manual review, never as findings.
| Identifier | Severity | CVSS | Product / version | Status | Match confidence | Evidence | Detected |
|---|---|---|---|---|---|---|---|
CVE-2024-39894 OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing at… | high | 7.5 | OpenSSH 9.7 | potential exposure — unverified | medium | {"match_reason":"keyword match on \"OpenSSH 9.7\"","note":"version-string match only; not a confirmed exposure","observ… | 22 Sep 2026 |
Only one state has been recorded. The current document is shown without a predecessor — no comparison is implied.
{
"id": "c4843bd745841f12421435fda71d2f70c",
"type": "ipv4",
"value": "116.66.194.177",
"hostname": null,
"reverseDns": null,
"asn": {
"number": 4007,
"name": "SUBISU-CABLENET-AS-AP - Subisu Cablenet (Pvt) Ltd, Baluwatar, Kathmandu, Nepal"
},
"organization": {
"id": "c2b1f62bdc5a33a0c2f97cc3d4861dcd6",
"name": "SUBISU-CABLENET-AS-AP - Subisu Cablenet (Pvt) Ltd, Baluwatar, Kathmandu, Nepal"
},
"location": {
"country": "NP",
"city": "Kathmandu",
"province": "Bagmati Province",
"district": "",
"confidence": "low",
"source": "ip-api.com"
},
"scopeStatus": "in_scope",
"priority": "NORMAL",
"firstSeen": "2026-09-22T07:25:53.361Z",
"lastSeen": "2026-09-22T21:24:36.933Z",
"observationCount": 1,
"openServices": 1,
"serviceCount": 1,
"technologies": [
"openssh"
],
"vulnerabilityMatches": [
{
"id": "ccc141f1066cb5ee33248c4f07cfbf819",
"cve": "CVE-2024-39894",
"severity": "high",
"cvssScore": 7.5,
"summary": "OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.",
"product": "OpenSSH",
"version": "9.7",
"status": "potential",
"matchConfidence": "medium",
"evidence": "{\"match_reason\":\"keyword match on \\\"OpenSSH 9.7\\\"\",\"note\":\"version-string match only; not a confirmed exposure\",\"observed_product\":\"OpenSSH\",\"observed_version\":\"9.7\",\"source\":\"nvd\"}",
"detectedAt": "2026-09-22T21:33:49.716Z",
"assetValue": "116.66.194.177",
"serviceId": "c6b7296c37954ddb2262e1b80041c81ba",
"port": 22,
"technologySlug": "openssh"
}
],
"network": {
"id": "c0be2bbd289e1e80862945b5dbaf4fd38",
"prefix": "116.66.192.0/22",
"ipVersion": 4
},
"services": [
{
"id": "c6b7296c37954ddb2262e1b80041c81ba",
"assetId": "c4843bd745841f12421435fda71d2f70c",
"assetValue": null,
"port": 22,
"protocol": "tcp",
"transport": "tcp",
"serviceType": "ssh",
"product": "OpenSSH",
"productVersion": "9.7",
"tlsVersion": null,
"banner": "SSH-2.0-OpenSSH_9.7 with CVE-2024-6387,CVE-2024-39894 fixes",
"state": "open",
"firstSeen": "2026-09-22T21:24:36.915Z",
"lastSeen": "2026-09-22T21:24:36.915Z",
"observationCount": 0,
"technologies": [
{
"slug": "openssh",
"name": "OpenSSH",
"category": "remote-access",
"vendor": "OpenBSD Project",
"version": "9.7",
"confidence": "high",
"evidence": "SSH banner: SSH-2.0-OpenSSH_9.7 with CVE-2024-6387,CVE-2024-39894 fixes",
"detectedAt": "2026-09-22T21:24:36.921Z"
}
],
"certificate": null
}
],
"certificates": [],
"recentObservations": [
{
"id": "cd0969f839af4b8ccd6c58298a068dabb",
"observedAt": "2026-09-22T21:24:36.926Z",
"source": "fingerprint",
"collector": "fingerprint-1",
"confidence": "high",
"state": {
"services": {
"22/tcp": {
"state": "open",
"product": "OpenSSH",
"version": "9.7",
"cert_sha256": "",
"tls_version": "",
"service_type": "ssh"
}
},
"technologies": [
"openssh"
]
},
"evidence": {
"ports": [
21,
22,
23,
25,
53,
80,
110,
143,
443,
445,
465,
587,
993,
995,
1433,
1521,
3306,
3389,
5432,
5900,
6379,
8080,
8443,
8888,
9200,
27017
],
"services": 1,
"reachable": true,
"reverse_dns": "",
"ports_probed": 26,
"technologies": [
"openssh"
],
"open_services": 1,
"probe_duration": 48040
},
"contentHash": "79ede7c0ec00b524529dfbc6002092c370556a281fab6f1001b772b86018a3b6",
"changed": true
}
],
"recentChanges": [
{
"id": "cbb7ec28acab94dc503354fb3052f059f",
"changeType": "NEW_SERVICE",
"assetId": "c4843bd745841f12421435fda71d2f70c",
"assetValue": null,
"field": "service:22/tcp",
"previousValue": null,
"currentValue": "OpenSSH 9.7",
"detectedAt": "2026-09-22T21:24:36.931Z",
"significance": "low",
"severity": "notice",
"confidence": null,
"detail": "endpoint responded on first observation",
"serviceId": null
},
{
"id": "c257f56d12bd269b5bfaac0f67906aba4",
"changeType": "NEW_ASSET",
"assetId": "c4843bd745841f12421435fda71d2f70c",
"assetValue": null,
"field": null,
"previousValue": null,
"currentValue": "asset with 1 observed open endpoint(s)",
"detectedAt": "2026-09-22T21:24:36.929Z",
"significance": "low",
"severity": "notice",
"confidence": null,
"detail": "asset observed for the first time",
"serviceId": null
}
],
"dnsRecords": [],
"state": {
"current": {
"services": {
"22/tcp": {
"state": "open",
"product": "OpenSSH",
"version": "9.7",
"cert_sha256": "",
"tls_version": "",
"service_type": "ssh"
}
},
"technologies": [
"openssh"
]
},
"previous": null,
"comparable": false
}
}