Reading the observatory store…
Reading the observatory store…
First seen 22 Sep 2026, last seen 24 Sep 2026 02:40 UTC (18h ago). 1 observations on record. Location is an estimate derived from registration data — the source and confidence are stated below.
| Port | Service | Product | Technologies | TLS | State | Banner | Last seen |
|---|---|---|---|---|---|---|---|
| 80 tcp / tcp | http | Apache HTTP Server 2.4.52 |
| not negotiated | open | no banner captured | 24 Sep 2026 18h ago |
| 443 tcp / tcp | https | Apache HTTP Server 2.4.52 |
| TLSv1.3certificate
| open | no banner captured | 24 Sep 2026 18h ago |
| Observed at | Source | Collector | Confidence | Changed | State | Content hash |
|---|---|---|---|---|---|---|
| 24 Sep 2026 02:40 UTC | fingerprint | fingerprint-1 | high | changed | {"services":{"80/tcp":{"state":"open","product":"Apache HTTP Server","version":"2.4.52","cert_sha256":"","tls_version":"","service_type":"http"},"443/tcp":{"st… | 1e7e561ad5ccb6b1b02706dd6480da84ee535e7… |
| Detected at | Type | Field | Previous | Current | Significance | Confidence |
|---|---|---|---|---|---|---|
| 24 Sep 2026 02:40 UTC | NEW SERVICE | service:80/tcp | — | Apache HTTP Server 2.4.52 | low | unknown |
| 24 Sep 2026 02:40 UTC | NEW SERVICE | service:443/tcp | — | Apache HTTP Server 2.4.52 / TLSv1.3 | low | unknown |
| 24 Sep 2026 02:40 UTC | NEW ASSET | — | — | asset with 2 observed open endpoint(s) | low | unknown |
4 matches on this asset, each one unverified. Treat these as leads for manual review, never as findings.
| Identifier | Severity | CVSS | Product / version | Status | Match confidence | Evidence | Detected |
|---|---|---|---|---|---|---|---|
CVE-2022-23943 Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version … | critical | 9.8 | Apache HTTP Server 2.4.52 | potential exposure — unverified | medium | {"match_reason":"keyword match on \"Apache HTTP Server 2.4.52\"","note":"version-string match only; not a confirmed exp… | 24 Sep 2026 |
CVE-2022-22721 If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apac… | critical | 9.1 | Apache HTTP Server 2.4.52 | potential exposure — unverified | medium | {"match_reason":"keyword match on \"Apache HTTP Server 2.4.52\"","note":"version-string match only; not a confirmed exp… | 24 Sep 2026 |
CVE-2022-22720 Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling | critical | 9.8 | Apache HTTP Server 2.4.52 | potential exposure — unverified | medium | {"match_reason":"keyword match on \"Apache HTTP Server 2.4.52\"","note":"version-string match only; not a confirmed exp… | 24 Sep 2026 |
CVE-2022-22719 A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier. | high | 7.5 | Apache HTTP Server 2.4.52 | potential exposure — unverified | medium | {"match_reason":"keyword match on \"Apache HTTP Server 2.4.52\"","note":"version-string match only; not a confirmed exp… | 24 Sep 2026 |
Only one state has been recorded. The current document is shown without a predecessor — no comparison is implied.
{
"id": "cf5430f5b559518ae3c57e117553b6339",
"type": "ipv4",
"value": "157.10.100.92",
"hostname": null,
"reverseDns": "dristi.com.np",
"asn": {
"number": 152307,
"name": "DWPL-AS-AP - DataWorld"
},
"organization": {
"id": "c1a0a10e6449ce8c3bc94ab7de42f4a72",
"name": "DWPL-AS-AP - DataWorld"
},
"location": {
"country": "NP",
"city": "Patan",
"province": "Bagmati Province",
"district": "",
"confidence": "low",
"source": "ip-api.com"
},
"scopeStatus": "in_scope",
"priority": "NORMAL",
"firstSeen": "2026-09-22T07:25:57.316Z",
"lastSeen": "2026-09-24T02:40:02.210Z",
"observationCount": 1,
"openServices": 2,
"serviceCount": 2,
"technologies": [
"apache-http-server",
"lets-encrypt",
"wordpress"
],
"vulnerabilityMatches": [
{
"id": "c567bc12504031c662c40756ad84806eb",
"cve": "CVE-2022-23943",
"severity": "critical",
"cvssScore": 9.8,
"summary": "Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions.",
"product": "Apache HTTP Server",
"version": "2.4.52",
"status": "potential",
"matchConfidence": "medium",
"evidence": "{\"match_reason\":\"keyword match on \\\"Apache HTTP Server 2.4.52\\\"\",\"note\":\"version-string match only; not a confirmed exposure\",\"observed_product\":\"Apache HTTP Server\",\"observed_version\":\"2.4.52\",\"source\":\"nvd\"}",
"detectedAt": "2026-09-24T02:55:20.485Z",
"assetValue": "157.10.100.92",
"serviceId": "cbaeaef736be5fee33a0ba99e424d25db",
"port": 443,
"technologySlug": "wordpress"
},
{
"id": "cbca99c970882e81a1f4273dadfbb62d2",
"cve": "CVE-2022-22721",
"severity": "critical",
"cvssScore": 9.1,
"summary": "If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.",
"product": "Apache HTTP Server",
"version": "2.4.52",
"status": "potential",
"matchConfidence": "medium",
"evidence": "{\"match_reason\":\"keyword match on \\\"Apache HTTP Server 2.4.52\\\"\",\"note\":\"version-string match only; not a confirmed exposure\",\"observed_product\":\"Apache HTTP Server\",\"observed_version\":\"2.4.52\",\"source\":\"nvd\"}",
"detectedAt": "2026-09-24T02:55:20.482Z",
"assetValue": "157.10.100.92",
"serviceId": "cbaeaef736be5fee33a0ba99e424d25db",
"port": 443,
"technologySlug": "wordpress"
},
{
"id": "c9413fb3c91de1ca25053ab3471774a97",
"cve": "CVE-2022-22720",
"severity": "critical",
"cvssScore": 9.8,
"summary": "Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling",
"product": "Apache HTTP Server",
"version": "2.4.52",
"status": "potential",
"matchConfidence": "medium",
"evidence": "{\"match_reason\":\"keyword match on \\\"Apache HTTP Server 2.4.52\\\"\",\"note\":\"version-string match only; not a confirmed exposure\",\"observed_product\":\"Apache HTTP Server\",\"observed_version\":\"2.4.52\",\"source\":\"nvd\"}",
"detectedAt": "2026-09-24T02:55:20.480Z",
"assetValue": "157.10.100.92",
"serviceId": "cbaeaef736be5fee33a0ba99e424d25db",
"port": 443,
"technologySlug": "wordpress"
},
{
"id": "c8f6647da4022c023dda3309f30a04542",
"cve": "CVE-2022-22719",
"severity": "high",
"cvssScore": 7.5,
"summary": "A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier.",
"product": "Apache HTTP Server",
"version": "2.4.52",
"status": "potential",
"matchConfidence": "medium",
"evidence": "{\"match_reason\":\"keyword match on \\\"Apache HTTP Server 2.4.52\\\"\",\"note\":\"version-string match only; not a confirmed exposure\",\"observed_product\":\"Apache HTTP Server\",\"observed_version\":\"2.4.52\",\"source\":\"nvd\"}",
"detectedAt": "2026-09-24T02:55:20.476Z",
"assetValue": "157.10.100.92",
"serviceId": "cbaeaef736be5fee33a0ba99e424d25db",
"port": 443,
"technologySlug": "wordpress"
}
],
"network": {
"id": "ca9954c2de1e5959b2ec58546fc78f971",
"prefix": "157.10.100.0/23",
"ipVersion": 4
},
"services": [
{
"id": "c84c71fe57b90943c9786cc0b319bced4",
"assetId": "cf5430f5b559518ae3c57e117553b6339",
"assetValue": null,
"port": 80,
"protocol": "tcp",
"transport": "tcp",
"serviceType": "http",
"product": "Apache HTTP Server",
"productVersion": "2.4.52",
"tlsVersion": null,
"banner": null,
"state": "open",
"firstSeen": "2026-09-24T02:40:02.192Z",
"lastSeen": "2026-09-24T02:40:02.192Z",
"observationCount": 0,
"technologies": [
{
"slug": "apache-http-server",
"name": "Apache HTTP Server",
"category": "web-server",
"vendor": "Apache Software Foundation",
"version": "2.4.52",
"confidence": "high",
"evidence": "server: Apache/2.4.52 (Ubuntu)",
"detectedAt": "2026-09-24T02:40:02.193Z"
},
{
"slug": "wordpress",
"name": "WordPress",
"category": "cms",
"vendor": "WordPress Foundation",
"version": null,
"confidence": "medium",
"evidence": "HTML references /wp-content/ or /wp-includes/",
"detectedAt": "2026-09-24T02:40:02.196Z"
}
],
"certificate": null
},
{
"id": "cbaeaef736be5fee33a0ba99e424d25db",
"assetId": "cf5430f5b559518ae3c57e117553b6339",
"assetValue": null,
"port": 443,
"protocol": "tcp",
"transport": "tcp",
"serviceType": "https",
"product": "Apache HTTP Server",
"productVersion": "2.4.52",
"tlsVersion": "TLSv1.3",
"banner": null,
"state": "open",
"firstSeen": "2026-09-24T02:40:02.198Z",
"lastSeen": "2026-09-24T02:40:02.198Z",
"observationCount": 0,
"technologies": [
{
"slug": "apache-http-server",
"name": "Apache HTTP Server",
"category": "web-server",
"vendor": "Apache Software Foundation",
"version": "2.4.52",
"confidence": "high",
"evidence": "server: Apache/2.4.52 (Ubuntu)",
"detectedAt": "2026-09-24T02:40:02.200Z"
},
{
"slug": "wordpress",
"name": "WordPress",
"category": "cms",
"vendor": "WordPress Foundation",
"version": null,
"confidence": "medium",
"evidence": "HTML references /wp-content/ or /wp-includes/",
"detectedAt": "2026-09-24T02:40:02.202Z"
},
{
"slug": "lets-encrypt",
"name": "Let's Encrypt",
"category": "certificate-authority",
"vendor": "Internet Security Research Group",
"version": null,
"confidence": "medium",
"evidence": "TLS certificate issuer: CN=YR1,O=Let's Encrypt,C=US",
"detectedAt": "2026-09-24T02:40:02.203Z"
}
],
"certificate": {
"id": "ce97de4cc6d95318ca7d1c80868200bdb",
"sha256": "b2badc6ac1853e5a6f25ee2d1e803212b68b5cec829fbe8dffe262e740a41b1b",
"subject": "CN=dristi.com.np",
"issuer": "CN=YR1,O=Let's Encrypt,C=US",
"commonName": "dristi.com.np",
"notBefore": "2026-07-28T14:04:49.000Z",
"notAfter": "2026-10-26T14:04:48.000Z",
"sans": [
"dristi.com.np",
"www.dristi.com.np"
],
"keyAlgo": "RSA",
"sigAlgo": "SHA256-RSA"
}
}
],
"certificates": [
{
"id": "ce97de4cc6d95318ca7d1c80868200bdb",
"sha256": "b2badc6ac1853e5a6f25ee2d1e803212b68b5cec829fbe8dffe262e740a41b1b",
"subject": "CN=dristi.com.np",
"issuer": "CN=YR1,O=Let's Encrypt,C=US",
"commonName": "dristi.com.np",
"notBefore": "2026-07-28T14:04:49.000Z",
"notAfter": "2026-10-26T14:04:48.000Z",
"sans": [
"dristi.com.np",
"www.dristi.com.np"
],
"keyAlgo": "RSA",
"sigAlgo": "SHA256-RSA"
}
],
"recentObservations": [
{
"id": "c0feb5384171e2cefff6ef7ff9b0ab063",
"observedAt": "2026-09-24T02:40:02.204Z",
"source": "fingerprint",
"collector": "fingerprint-1",
"confidence": "high",
"state": {
"services": {
"80/tcp": {
"state": "open",
"product": "Apache HTTP Server",
"version": "2.4.52",
"cert_sha256": "",
"tls_version": "",
"service_type": "http"
},
"443/tcp": {
"state": "open",
"product": "Apache HTTP Server",
"version": "2.4.52",
"cert_sha256": "b2badc6ac1853e5a6f25ee2d1e803212b68b5cec829fbe8dffe262e740a41b1b",
"tls_version": "TLSv1.3",
"service_type": "https"
}
},
"reverse_dns": "dristi.com.np",
"technologies": [
"apache-http-server",
"lets-encrypt",
"wordpress"
]
},
"evidence": {
"ports": [
21,
22,
23,
25,
53,
80,
110,
143,
443,
445,
465,
587,
993,
995,
1433,
1521,
3306,
3389,
5432,
5900,
6379,
8080,
8443,
8888,
9200,
27017
],
"services": 2,
"reachable": true,
"reverse_dns": "dristi.com.np",
"ports_probed": 26,
"technologies": [
"apache-http-server",
"lets-encrypt",
"wordpress"
],
"open_services": 2,
"probe_duration": 29037
},
"contentHash": "1e7e561ad5ccb6b1b02706dd6480da84ee535e75aa795e54c64404d82f1d26e3",
"changed": true
}
],
"recentChanges": [
{
"id": "cdba3b0d663e678e159d461a55d1b07f4",
"changeType": "NEW_SERVICE",
"assetId": "cf5430f5b559518ae3c57e117553b6339",
"assetValue": null,
"field": "service:80/tcp",
"previousValue": null,
"currentValue": "Apache HTTP Server 2.4.52",
"detectedAt": "2026-09-24T02:40:02.209Z",
"significance": "low",
"severity": "notice",
"confidence": null,
"detail": "endpoint responded on first observation",
"serviceId": null
},
{
"id": "c0558c7a78e5cf42ffd2243e4c3dd691b",
"changeType": "NEW_SERVICE",
"assetId": "cf5430f5b559518ae3c57e117553b6339",
"assetValue": null,
"field": "service:443/tcp",
"previousValue": null,
"currentValue": "Apache HTTP Server 2.4.52 / TLSv1.3",
"detectedAt": "2026-09-24T02:40:02.207Z",
"significance": "low",
"severity": "notice",
"confidence": null,
"detail": "endpoint responded on first observation",
"serviceId": null
},
{
"id": "c59a9ad55f0038edb0cdfa9ca454f4862",
"changeType": "NEW_ASSET",
"assetId": "cf5430f5b559518ae3c57e117553b6339",
"assetValue": null,
"field": null,
"previousValue": null,
"currentValue": "asset with 2 observed open endpoint(s)",
"detectedAt": "2026-09-24T02:40:02.206Z",
"significance": "low",
"severity": "notice",
"confidence": null,
"detail": "asset observed for the first time",
"serviceId": null
}
],
"dnsRecords": [],
"state": {
"current": {
"services": {
"80/tcp": {
"state": "open",
"product": "Apache HTTP Server",
"version": "2.4.52",
"cert_sha256": "",
"tls_version": "",
"service_type": "http"
},
"443/tcp": {
"state": "open",
"product": "Apache HTTP Server",
"version": "2.4.52",
"cert_sha256": "b2badc6ac1853e5a6f25ee2d1e803212b68b5cec829fbe8dffe262e740a41b1b",
"tls_version": "TLSv1.3",
"service_type": "https"
}
},
"reverse_dns": "dristi.com.np",
"technologies": [
"apache-http-server",
"lets-encrypt",
"wordpress"
]
},
"previous": null,
"comparable": false
}
}