Reading the observatory store…
Reading the observatory store…
First seen 22 Sep 2026, last seen 22 Sep 2026 07:50 UTC (1h ago). 1 observations on record. Location is an estimate derived from registration data — the source and confidence are stated below.
| Port | Service | Product | Technologies | TLS | State | Banner | Last seen |
|---|---|---|---|---|---|---|---|
| 80 tcp / tcp | http | Apache HTTP Server 2.4.58 |
| not negotiated | open | no banner captured | 22 Sep 2026 1h ago |
| 443 tcp / tcp | https | Apache HTTP Server 2.4.58 |
| TLSv1.3certificate
| open | no banner captured | 22 Sep 2026 1h ago |
| Observed at | Source | Collector | Confidence | Changed | State | Content hash |
|---|---|---|---|---|---|---|
| 22 Sep 2026 07:50 UTC | fingerprint | fingerprint-1 | high | changed | {"services":{"80/tcp":{"state":"open","product":"Apache HTTP Server","version":"2.4.58","cert_sha256":"","tls_version":"","service_type":"http"},"443/tcp":{"st… | e66abdbc651da364ecf556c521a4903d7f6da95… |
| Detected at | Type | Field | Previous | Current | Significance | Confidence |
|---|---|---|---|---|---|---|
| 22 Sep 2026 07:50 UTC | NEW SERVICE | service:80/tcp | — | Apache HTTP Server 2.4.58 | low | unknown |
| 22 Sep 2026 07:50 UTC | NEW SERVICE | service:443/tcp | — | Apache HTTP Server 2.4.58 / TLSv1.3 | low | unknown |
| 22 Sep 2026 07:50 UTC | NEW ASSET | — | — | asset with 2 observed open endpoint(s) | low | unknown |
4 matches on this asset, each one unverified. Treat these as leads for manual review, never as findings.
| Identifier | Severity | CVSS | Product / version | Status | Match confidence | Evidence | Detected |
|---|---|---|---|---|---|---|---|
CVE-2023-38709 Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58. | high | 7.3 | Apache HTTP Server 2.4.58 | potential exposure — unverified | medium | {"match_reason":"keyword match on \"Apache HTTP Server 2.4.58\"","note":"version-string match only; not a confirmed exp… | 22 Sep 2026 |
CVE-2023-43622 An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection indefinitely in Apache HTTP Server. This could be used to exhaust worker resou… | high | 7.5 | Apache HTTP Server 2.4.58 | potential exposure — unverified | medium | {"match_reason":"keyword match on \"Apache HTTP Server 2.4.58\"","note":"version-string match only; not a confirmed exp… | 22 Sep 2026 |
CVE-2023-38709 Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58. | high | 7.3 | Apache HTTP Server 2.4.58 | potential exposure — unverified | medium | {"match_reason":"keyword match on \"Apache HTTP Server 2.4.58\"","note":"version-string match only; not a confirmed exp… | 22 Sep 2026 |
CVE-2023-43622 An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection indefinitely in Apache HTTP Server. This could be used to exhaust worker resou… | high | 7.5 | Apache HTTP Server 2.4.58 | potential exposure — unverified | medium | {"match_reason":"keyword match on \"Apache HTTP Server 2.4.58\"","note":"version-string match only; not a confirmed exp… | 22 Sep 2026 |
Only one state has been recorded. The current document is shown without a predecessor — no comparison is implied.
{
"id": "c9403448a6d2f4c72113c2c1ad32299fb",
"type": "ipv4",
"value": "103.213.124.232",
"hostname": null,
"reverseDns": null,
"asn": {
"number": 45424,
"name": "HONS-AS-NP - Network Pool Allocated for HONS Network"
},
"organization": {
"id": "c2db79ade5758eafe532a675fa34e295d",
"name": "HONS-AS-NP - Network Pool Allocated for HONS Network"
},
"location": {
"country": "NP",
"city": "Chapali Bhadrakali",
"province": "Bagmati Province",
"district": "",
"confidence": "low",
"source": "ip-api.com"
},
"scopeStatus": "in_scope",
"priority": "NORMAL",
"firstSeen": "2026-09-22T04:32:34.954Z",
"lastSeen": "2026-09-22T07:50:23.685Z",
"observationCount": 1,
"openServices": 2,
"serviceCount": 2,
"technologies": [
"apache-http-server",
"jquery",
"lets-encrypt"
],
"vulnerabilityMatches": [
{
"id": "cec36da1ef2600b4d9f052e96e58fed7b",
"cve": "CVE-2023-38709",
"severity": "high",
"cvssScore": 7.3,
"summary": "Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses.\n\nThis issue affects Apache HTTP Server: through 2.4.58.",
"product": "Apache HTTP Server",
"version": "2.4.58",
"status": "potential",
"matchConfidence": "medium",
"evidence": "{\"match_reason\":\"keyword match on \\\"Apache HTTP Server 2.4.58\\\"\",\"note\":\"version-string match only; not a confirmed exposure\",\"observed_product\":\"Apache HTTP Server\",\"observed_version\":\"2.4.58\",\"source\":\"nvd\"}",
"detectedAt": "2026-09-22T08:14:59.237Z",
"assetValue": "103.213.124.232",
"serviceId": "c3539d8918ef02033cf5fafcdb31e45a8",
"port": 80,
"technologySlug": "apache-http-server"
},
{
"id": "cf9c63c0b27b7e1e67fd0ca695ff84d54",
"cve": "CVE-2023-43622",
"severity": "high",
"cvssScore": 7.5,
"summary": "An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection indefinitely in Apache HTTP Server. This could be used to exhaust worker resources in the server, similar to the well known \"slow loris\" attack pattern.\nThis has been fixed in version 2.4.58, so that such connection are terminated properly after the configured connection timeout.\n\nThis issue affects Apache HTTP Server: from 2.4.55 through 2.4.57.\n\nUsers are recommended to upgrade to version 2.4.58, which fixes the issue.",
"product": "Apache HTTP Server",
"version": "2.4.58",
"status": "potential",
"matchConfidence": "medium",
"evidence": "{\"match_reason\":\"keyword match on \\\"Apache HTTP Server 2.4.58\\\"\",\"note\":\"version-string match only; not a confirmed exposure\",\"observed_product\":\"Apache HTTP Server\",\"observed_version\":\"2.4.58\",\"source\":\"nvd\"}",
"detectedAt": "2026-09-22T08:14:59.235Z",
"assetValue": "103.213.124.232",
"serviceId": "c3539d8918ef02033cf5fafcdb31e45a8",
"port": 80,
"technologySlug": "apache-http-server"
},
{
"id": "c7d786dbbb3bb23e5d0d29e28443a574b",
"cve": "CVE-2023-38709",
"severity": "high",
"cvssScore": 7.3,
"summary": "Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses.\n\nThis issue affects Apache HTTP Server: through 2.4.58.",
"product": "Apache HTTP Server",
"version": "2.4.58",
"status": "potential",
"matchConfidence": "medium",
"evidence": "{\"match_reason\":\"keyword match on \\\"Apache HTTP Server 2.4.58\\\"\",\"note\":\"version-string match only; not a confirmed exposure\",\"observed_product\":\"Apache HTTP Server\",\"observed_version\":\"2.4.58\",\"source\":\"nvd\"}",
"detectedAt": "2026-09-22T08:14:57.065Z",
"assetValue": "103.213.124.232",
"serviceId": "cd9cffa383b41d8542e720ce5c8dd5f60",
"port": 443,
"technologySlug": "lets-encrypt"
},
{
"id": "c6b63a5668debf53ed8e6c67d71fac828",
"cve": "CVE-2023-43622",
"severity": "high",
"cvssScore": 7.5,
"summary": "An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection indefinitely in Apache HTTP Server. This could be used to exhaust worker resources in the server, similar to the well known \"slow loris\" attack pattern.\nThis has been fixed in version 2.4.58, so that such connection are terminated properly after the configured connection timeout.\n\nThis issue affects Apache HTTP Server: from 2.4.55 through 2.4.57.\n\nUsers are recommended to upgrade to version 2.4.58, which fixes the issue.",
"product": "Apache HTTP Server",
"version": "2.4.58",
"status": "potential",
"matchConfidence": "medium",
"evidence": "{\"match_reason\":\"keyword match on \\\"Apache HTTP Server 2.4.58\\\"\",\"note\":\"version-string match only; not a confirmed exposure\",\"observed_product\":\"Apache HTTP Server\",\"observed_version\":\"2.4.58\",\"source\":\"nvd\"}",
"detectedAt": "2026-09-22T08:14:57.062Z",
"assetValue": "103.213.124.232",
"serviceId": "cd9cffa383b41d8542e720ce5c8dd5f60",
"port": 443,
"technologySlug": "lets-encrypt"
}
],
"network": {
"id": "c14e669c68cd56b95c80c41842f5f8e47",
"prefix": "103.213.124.0/24",
"ipVersion": 4
},
"services": [
{
"id": "c3539d8918ef02033cf5fafcdb31e45a8",
"assetId": "c9403448a6d2f4c72113c2c1ad32299fb",
"assetValue": null,
"port": 80,
"protocol": "tcp",
"transport": "tcp",
"serviceType": "http",
"product": "Apache HTTP Server",
"productVersion": "2.4.58",
"tlsVersion": null,
"banner": null,
"state": "open",
"firstSeen": "2026-09-22T07:50:23.655Z",
"lastSeen": "2026-09-22T07:50:23.655Z",
"observationCount": 0,
"technologies": [
{
"slug": "apache-http-server",
"name": "Apache HTTP Server",
"category": "web-server",
"vendor": "Apache Software Foundation",
"version": "2.4.58",
"confidence": "high",
"evidence": "server: Apache/2.4.58 (Ubuntu)",
"detectedAt": "2026-09-22T07:50:23.658Z"
}
],
"certificate": null
},
{
"id": "cd9cffa383b41d8542e720ce5c8dd5f60",
"assetId": "c9403448a6d2f4c72113c2c1ad32299fb",
"assetValue": null,
"port": 443,
"protocol": "tcp",
"transport": "tcp",
"serviceType": "https",
"product": "Apache HTTP Server",
"productVersion": "2.4.58",
"tlsVersion": "TLSv1.3",
"banner": null,
"state": "open",
"firstSeen": "2026-09-22T07:50:23.666Z",
"lastSeen": "2026-09-22T07:50:23.666Z",
"observationCount": 0,
"technologies": [
{
"slug": "apache-http-server",
"name": "Apache HTTP Server",
"category": "web-server",
"vendor": "Apache Software Foundation",
"version": "2.4.58",
"confidence": "high",
"evidence": "server: Apache/2.4.58 (Ubuntu)",
"detectedAt": "2026-09-22T07:50:23.669Z"
},
{
"slug": "jquery",
"name": "jQuery",
"category": "javascript-library",
"vendor": "OpenJS Foundation",
"version": "3.7.0",
"confidence": "medium",
"evidence": "jQuery script reference: jquery-3.7.0.min.js",
"detectedAt": "2026-09-22T07:50:23.673Z"
},
{
"slug": "lets-encrypt",
"name": "Let's Encrypt",
"category": "certificate-authority",
"vendor": "Internet Security Research Group",
"version": null,
"confidence": "medium",
"evidence": "TLS certificate issuer: CN=YE1,O=Let's Encrypt,C=US",
"detectedAt": "2026-09-22T07:50:23.676Z"
}
],
"certificate": {
"id": "c733cf3fa93c164231c7245dcfa4bf1fd",
"sha256": "9a336a9a4dc24a5af2da744203366489501a3f9936d8f8b107abf6639d7fdcf8",
"subject": "CN=helpdesk.oucrunp.org.np",
"issuer": "CN=YE1,O=Let's Encrypt,C=US",
"commonName": "helpdesk.oucrunp.org.np",
"notBefore": "2026-07-31T17:28:50.000Z",
"notAfter": "2026-10-29T17:28:49.000Z",
"sans": [
"helpdesk.oucrunp.org.np"
],
"keyAlgo": "ECDSA",
"sigAlgo": "ECDSA-SHA384"
}
}
],
"certificates": [
{
"id": "c733cf3fa93c164231c7245dcfa4bf1fd",
"sha256": "9a336a9a4dc24a5af2da744203366489501a3f9936d8f8b107abf6639d7fdcf8",
"subject": "CN=helpdesk.oucrunp.org.np",
"issuer": "CN=YE1,O=Let's Encrypt,C=US",
"commonName": "helpdesk.oucrunp.org.np",
"notBefore": "2026-07-31T17:28:50.000Z",
"notAfter": "2026-10-29T17:28:49.000Z",
"sans": [
"helpdesk.oucrunp.org.np"
],
"keyAlgo": "ECDSA",
"sigAlgo": "ECDSA-SHA384"
}
],
"recentObservations": [
{
"id": "ca233ca4555971697b9d6f722ff248c22",
"observedAt": "2026-09-22T07:50:23.679Z",
"source": "fingerprint",
"collector": "fingerprint-1",
"confidence": "high",
"state": {
"services": {
"80/tcp": {
"state": "open",
"product": "Apache HTTP Server",
"version": "2.4.58",
"cert_sha256": "",
"tls_version": "",
"service_type": "http"
},
"443/tcp": {
"state": "open",
"product": "Apache HTTP Server",
"version": "2.4.58",
"cert_sha256": "9a336a9a4dc24a5af2da744203366489501a3f9936d8f8b107abf6639d7fdcf8",
"tls_version": "TLSv1.3",
"service_type": "https"
}
},
"technologies": [
"apache-http-server",
"jquery",
"lets-encrypt"
]
},
"evidence": {
"ports": [
21,
22,
23,
25,
53,
80,
110,
143,
443,
445,
587,
993,
995,
1433,
1521,
3306,
3389,
5432,
5900,
6379,
8080,
8443,
8888,
9200,
27017
],
"services": 2,
"reachable": true,
"reverse_dns": "",
"ports_probed": 25,
"technologies": [
"apache-http-server",
"jquery",
"lets-encrypt"
],
"open_services": 2,
"probe_duration": 32002
},
"contentHash": "e66abdbc651da364ecf556c521a4903d7f6da95fb2a80ef2a997ae7d40796e14",
"changed": true
}
],
"recentChanges": [
{
"id": "c30d35788b8bf9b2e9a4ea9b599e7da6b",
"changeType": "NEW_SERVICE",
"assetId": "c9403448a6d2f4c72113c2c1ad32299fb",
"assetValue": null,
"field": "service:80/tcp",
"previousValue": null,
"currentValue": "Apache HTTP Server 2.4.58",
"detectedAt": "2026-09-22T07:50:23.684Z",
"significance": "low",
"severity": "notice",
"confidence": null,
"detail": "endpoint responded on first observation",
"serviceId": null
},
{
"id": "ca667a7632a363ab1ff85b36c08e5cd4d",
"changeType": "NEW_SERVICE",
"assetId": "c9403448a6d2f4c72113c2c1ad32299fb",
"assetValue": null,
"field": "service:443/tcp",
"previousValue": null,
"currentValue": "Apache HTTP Server 2.4.58 / TLSv1.3",
"detectedAt": "2026-09-22T07:50:23.682Z",
"significance": "low",
"severity": "notice",
"confidence": null,
"detail": "endpoint responded on first observation",
"serviceId": null
},
{
"id": "c8536d8e97b0aab4823016844d1cc74d6",
"changeType": "NEW_ASSET",
"assetId": "c9403448a6d2f4c72113c2c1ad32299fb",
"assetValue": null,
"field": null,
"previousValue": null,
"currentValue": "asset with 2 observed open endpoint(s)",
"detectedAt": "2026-09-22T07:50:23.681Z",
"significance": "low",
"severity": "notice",
"confidence": null,
"detail": "asset observed for the first time",
"serviceId": null
}
],
"dnsRecords": [],
"state": {
"current": {
"services": {
"80/tcp": {
"state": "open",
"product": "Apache HTTP Server",
"version": "2.4.58",
"cert_sha256": "",
"tls_version": "",
"service_type": "http"
},
"443/tcp": {
"state": "open",
"product": "Apache HTTP Server",
"version": "2.4.58",
"cert_sha256": "9a336a9a4dc24a5af2da744203366489501a3f9936d8f8b107abf6639d7fdcf8",
"tls_version": "TLSv1.3",
"service_type": "https"
}
},
"technologies": [
"apache-http-server",
"jquery",
"lets-encrypt"
]
},
"previous": null,
"comparable": false
}
}