Reading the observatory store…
Reading the observatory store…
First seen 22 Sep 2026, last seen 22 Sep 2026 06:35 UTC (3h ago). 1 observations on record. Location is an estimate derived from registration data — the source and confidence are stated below.
| Port | Service | Product | Technologies | TLS | State | Banner | Last seen |
|---|---|---|---|---|---|---|---|
| 21 tcp / tcp | ftp | vsftpd 3.0.2 |
| not negotiated | open | 220 (vsFTPd 3.0.2) | 22 Sep 2026 3h ago |
| 80 tcp / tcp | http | nginx 1.20.1 |
| not negotiated | open | no banner captured | 22 Sep 2026 3h ago |
| Observed at | Source | Collector | Confidence | Changed | State | Content hash |
|---|---|---|---|---|---|---|
| 22 Sep 2026 06:35 UTC | fingerprint | fingerprint-1 | high | changed | {"services":{"21/tcp":{"state":"open","product":"vsftpd","version":"3.0.2","cert_sha256":"","tls_version":"","service_type":"ftp"},"80/tcp":{"state":"open","pr… | ee66e4ceea0b41c18ba5a0866b3121b07d6faa1… |
| Detected at | Type | Field | Previous | Current | Significance | Confidence |
|---|---|---|---|---|---|---|
| 22 Sep 2026 06:35 UTC | NEW SERVICE | service:80/tcp | — | nginx 1.20.1 | low | unknown |
| 22 Sep 2026 06:35 UTC | NEW SERVICE | service:21/tcp | — | vsftpd 3.0.2 | low | unknown |
| 22 Sep 2026 06:35 UTC | NEW ASSET | — | — | asset with 2 observed open endpoint(s) | low | unknown |
1 match on this asset, each one unverified. Treat these as leads for manual review, never as findings.
| Identifier | Severity | CVSS | Product / version | Status | Match confidence | Evidence | Detected |
|---|---|---|---|---|---|---|---|
CVE-2015-1419 Unspecified vulnerability in vsftpd 3.0.2 and earlier allows remote attackers to bypass access restrictions via unknown vectors, related to deny_file parsing. | medium | 5.0 | vsftpd 3.0.2 | potential exposure — unverified | medium | {"match_reason":"keyword match on \"vsftpd 3.0.2\"","note":"version-string match only; not a confirmed exposure","obser… | 22 Sep 2026 |
Only one state has been recorded. The current document is shown without a predecessor — no comparison is implied.
{
"id": "ce29e9ce78906717ff1a580085a0fe468",
"type": "ipv4",
"value": "103.74.15.76",
"hostname": null,
"reverseDns": null,
"asn": {
"number": 132799,
"name": "DMNPL-AS-AP - DISH MEDIA NETWORK PUBLIC LIMITED"
},
"organization": {
"id": "c35431c1103a6cf65d5ab165e348b0e87",
"name": "DMNPL-AS-AP - DISH MEDIA NETWORK PUBLIC LIMITED"
},
"location": {
"country": "NP",
"city": "Kathmandu",
"province": "Bagmati Province",
"district": "",
"confidence": "low",
"source": "ip-api.com"
},
"scopeStatus": "in_scope",
"priority": "NORMAL",
"firstSeen": "2026-09-22T04:18:42.444Z",
"lastSeen": "2026-09-22T06:35:45.477Z",
"observationCount": 1,
"openServices": 2,
"serviceCount": 2,
"technologies": [
"nginx",
"vsftpd"
],
"vulnerabilityMatches": [
{
"id": "c2a9f55c450b04d28264380fb4b41a47e",
"cve": "CVE-2015-1419",
"severity": "medium",
"cvssScore": 5,
"summary": "Unspecified vulnerability in vsftpd 3.0.2 and earlier allows remote attackers to bypass access restrictions via unknown vectors, related to deny_file parsing.",
"product": "vsftpd",
"version": "3.0.2",
"status": "potential",
"matchConfidence": "medium",
"evidence": "{\"match_reason\":\"keyword match on \\\"vsftpd 3.0.2\\\"\",\"note\":\"version-string match only; not a confirmed exposure\",\"observed_product\":\"vsftpd\",\"observed_version\":\"3.0.2\",\"source\":\"nvd\"}",
"detectedAt": "2026-09-22T06:46:13.251Z",
"assetValue": "103.74.15.76",
"serviceId": "cbbb86e9f27cc623b47b6859ae9ccce4f",
"port": 21,
"technologySlug": "vsftpd"
}
],
"network": {
"id": "c82b35e750bc0560bc5d8716ea84c4136",
"prefix": "103.74.15.0/24",
"ipVersion": 4
},
"services": [
{
"id": "cbbb86e9f27cc623b47b6859ae9ccce4f",
"assetId": "ce29e9ce78906717ff1a580085a0fe468",
"assetValue": null,
"port": 21,
"protocol": "tcp",
"transport": "tcp",
"serviceType": "ftp",
"product": "vsftpd",
"productVersion": "3.0.2",
"tlsVersion": null,
"banner": "220 (vsFTPd 3.0.2)",
"state": "open",
"firstSeen": "2026-09-22T06:35:45.455Z",
"lastSeen": "2026-09-22T06:35:45.455Z",
"observationCount": 0,
"technologies": [
{
"slug": "vsftpd",
"name": "vsftpd",
"category": "ftp-server",
"vendor": "vsftpd",
"version": "3.0.2",
"confidence": "high",
"evidence": "FTP banner: 220 (vsFTPd 3.0.2)",
"detectedAt": "2026-09-22T06:35:45.460Z"
}
],
"certificate": null
},
{
"id": "cd8c8fd818d0373a0bf2336134cf403a3",
"assetId": "ce29e9ce78906717ff1a580085a0fe468",
"assetValue": null,
"port": 80,
"protocol": "tcp",
"transport": "tcp",
"serviceType": "http",
"product": "nginx",
"productVersion": "1.20.1",
"tlsVersion": null,
"banner": null,
"state": "open",
"firstSeen": "2026-09-22T06:35:45.464Z",
"lastSeen": "2026-09-22T06:35:45.464Z",
"observationCount": 0,
"technologies": [
{
"slug": "nginx",
"name": "nginx",
"category": "web-server",
"vendor": "NGINX, Inc.",
"version": "1.20.1",
"confidence": "high",
"evidence": "server: nginx/1.20.1",
"detectedAt": "2026-09-22T06:35:45.467Z"
}
],
"certificate": null
}
],
"certificates": [],
"recentObservations": [
{
"id": "c99f1124f3fc95dd7cf6556885fdccf47",
"observedAt": "2026-09-22T06:35:45.471Z",
"source": "fingerprint",
"collector": "fingerprint-1",
"confidence": "high",
"state": {
"services": {
"21/tcp": {
"state": "open",
"product": "vsftpd",
"version": "3.0.2",
"cert_sha256": "",
"tls_version": "",
"service_type": "ftp"
},
"80/tcp": {
"state": "open",
"product": "nginx",
"version": "1.20.1",
"cert_sha256": "",
"tls_version": "",
"service_type": "http"
}
},
"technologies": [
"nginx",
"vsftpd"
]
},
"evidence": {
"ports": [
21,
22,
23,
25,
53,
80,
110,
143,
443,
445,
587,
993,
995,
1433,
1521,
3306,
3389,
5432,
5900,
6379,
8080,
8443,
8888,
9200,
27017
],
"services": 2,
"reachable": true,
"reverse_dns": "",
"ports_probed": 25,
"technologies": [
"nginx",
"vsftpd"
],
"open_services": 2,
"probe_duration": 10049
},
"contentHash": "ee66e4ceea0b41c18ba5a0866b3121b07d6faa10b511b74663377ba676b87351",
"changed": true
}
],
"recentChanges": [
{
"id": "c0877d70c4445ef50a6baf5237a64b5d7",
"changeType": "NEW_SERVICE",
"assetId": "ce29e9ce78906717ff1a580085a0fe468",
"assetValue": null,
"field": "service:80/tcp",
"previousValue": null,
"currentValue": "nginx 1.20.1",
"detectedAt": "2026-09-22T06:35:45.475Z",
"significance": "low",
"severity": "notice",
"confidence": null,
"detail": "endpoint responded on first observation",
"serviceId": null
},
{
"id": "cf3c24020d68289235b387dba446fb6fa",
"changeType": "NEW_SERVICE",
"assetId": "ce29e9ce78906717ff1a580085a0fe468",
"assetValue": null,
"field": "service:21/tcp",
"previousValue": null,
"currentValue": "vsftpd 3.0.2",
"detectedAt": "2026-09-22T06:35:45.474Z",
"significance": "low",
"severity": "notice",
"confidence": null,
"detail": "endpoint responded on first observation",
"serviceId": null
},
{
"id": "c69fbac6484a6952d1cc617efdf56b01b",
"changeType": "NEW_ASSET",
"assetId": "ce29e9ce78906717ff1a580085a0fe468",
"assetValue": null,
"field": null,
"previousValue": null,
"currentValue": "asset with 2 observed open endpoint(s)",
"detectedAt": "2026-09-22T06:35:45.472Z",
"significance": "low",
"severity": "notice",
"confidence": null,
"detail": "asset observed for the first time",
"serviceId": null
}
],
"dnsRecords": [],
"state": {
"current": {
"services": {
"21/tcp": {
"state": "open",
"product": "vsftpd",
"version": "3.0.2",
"cert_sha256": "",
"tls_version": "",
"service_type": "ftp"
},
"80/tcp": {
"state": "open",
"product": "nginx",
"version": "1.20.1",
"cert_sha256": "",
"tls_version": "",
"service_type": "http"
}
},
"technologies": [
"nginx",
"vsftpd"
]
},
"previous": null,
"comparable": false
}
}