{"success":true,"ip":"109.160.2.3","family":"IPv4","data":{"open_ports":[{"port":5666,"proto":"tcp","last_seen":"2026-07-21 04:56:42.000","service":""},{"port":8080,"proto":"tcp","last_seen":"2026-07-19 10:52:53.000","service":"http-proxy"}],"banners":[{"port":8080,"server_str":"Apache\/2.2.14 (Ubuntu)","observed_at":"2026-07-19 10:53:09.767"}],"tls_certs":[],"co_hosted_domains":[],"external_refs":[{"ref_domain":"www.ispconfig.org","source":"href","total":1}],"leak_candidates":[],"titles":[{"target":"109.160.2.3:8080","title":"ISPConfig","status":200,"login_flag":0,"last_seen":"2026-07-19 10:53:09.767"}],"login_ports":[],"icmp_reachable":{"last_seen":"2026-08-29 05:37:39","hits":1},"tracking":{"first_seen":"2026-07-19 10:52:49.000","last_seen":"2026-07-21 04:56:42.000","observations":4},"techs":[{"technology":"YUI","version":"","category":"cat59","confidence":1,"sample_target":"109.160.2.3:8080"},{"technology":"jQuery","version":"","category":"cat59","confidence":1,"sample_target":"109.160.2.3:8080"}],"ptr":null,"bgp":{"asn":56906,"as_name":null,"prefix":"109.160.2.0\/24","rpki_status":null,"observed_at":"2026-08-30 18:06:38","country_code":"BG","registry":"ripencc","allocated":"2011-06-08"},"allocation":{"registry":"ripencc","country_code":"BG","status":"allocated","allocated_date":"20090827","start_ip":"109.160.0.0","block_size":1024},"geo":{"country_code":"BG","country_name":"Bulgaria","continent_code":"EU"},"honeypot":null,"honeypot_recent":[],"honeypot_actor":null,"honeypot_ja":null,"honeypot_classes":[],"hosted_domains":[],"hosted_domains_count":0,"hosted_is_bulk":false,"cves":[{"cve_id":"CVE-2017-3169","cvss_score":9.8,"cvss_severity":"","description":"In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_process_connection() during an HTTP request to an HTTPS port.","software":"Apache 2.2.14"},{"cve_id":"CVE-2016-4975","cvss_score":6.1,"cvss_severity":"","description":"Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 and 2.2.32 which prohibit CR or LF injection into the \"Location\" or other outbound header key or value. Fixed in Apache HTTP Server 2.4.25 (Affected 2.4.1-2.4.23). Fixed in Apache HTTP Server 2.2.32 (Affected 2.2.0-2.2.31).","software":"Apache 2.2.14"},{"cve_id":"CVE-2010-0408","cvss_score":5,"cvss_severity":"MEDIUM","description":"The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain situations in which a client sends no request body, which allows remote attackers to cause a denial of service (backend server outage) via a crafted request, related to use of a 500 error code instead of the appropriate 400 error code.","software":"Apache 2.2.14"},{"cve_id":"CVE-2010-2068","cvss_score":5,"cvss_severity":"MEDIUM","description":"mod_proxy_http.c in mod_proxy_http in the Apache HTTP Server 2.2.9 through 2.2.15, 2.3.4-alpha, and 2.3.5-alpha on Windows, NetWare, and OS\/2, in certain configurations involving proxy worker pools, does not properly detect timeouts, which allows remote attackers to obtain a potentially sensitive response intended for a different client in opportunistic circumstances via a normal HTTP request.","software":"Apache 2.2.14"},{"cve_id":"CVE-2011-3368","cvss_score":5,"cvss_severity":"MEDIUM","description":"The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an initial @ (at sign) character.","software":"Apache 2.2.14"},{"cve_id":"CVE-2012-4557","cvss_score":5,"cvss_severity":"MEDIUM","description":"The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive request.","software":"Apache 2.2.14"},{"cve_id":"CVE-2013-5704","cvss_score":5,"cvss_severity":"MEDIUM","description":"The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass \"RequestHeader unset\" directives by placing a header in the trailer portion of data sent with chunked transfer coding.  NOTE: the vendor states \"this is not a security issue in httpd as such.\"","software":"Apache 2.2.14"},{"cve_id":"CVE-2011-3607","cvss_score":4.4,"cvss_severity":"MEDIUM","description":"Integer overflow in the ap_pregsub function in server\/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, allows local users to gain privileges via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, leading to a heap-based buffer overflow.","software":"Apache 2.2.14"},{"cve_id":"CVE-2011-3639","cvss_score":4.3,"cvss_severity":"MEDIUM","description":"The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x before 2.2.18, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers by using the HTTP\/0.9 protocol with a malformed URI containing an initial @ (at sign) character.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3368.","software":"Apache 2.2.14"},{"cve_id":"CVE-2011-4317","cvss_score":4.3,"cvss_severity":"MEDIUM","description":"The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an @ (at sign) character and a : (colon) character in invalid positions.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3368.","software":"Apache 2.2.14"},{"cve_id":"CVE-2012-3499","cvss_score":4.3,"cvss_severity":"MEDIUM","description":"Multiple cross-site scripting (XSS) vulnerabilities in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving hostnames and URIs in the (1) mod_imagemap, (2) mod_info, (3) mod_ldap, (4) mod_proxy_ftp, and (5) mod_status modules.","software":"Apache 2.2.14"},{"cve_id":"CVE-2012-4558","cvss_score":4.3,"cvss_severity":"MEDIUM","description":"Multiple cross-site scripting (XSS) vulnerabilities in the balancer_handler function in the manager interface in mod_proxy_balancer.c in the mod_proxy_balancer module in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via a crafted string.","software":"Apache 2.2.14"},{"cve_id":"CVE-2012-2687","cvss_score":2.6,"cvss_severity":"LOW","description":"Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is not properly handled during construction of a variant list.","software":"Apache 2.2.14"},{"cve_id":"CVE-2011-4415","cvss_score":1.2,"cvss_severity":"LOW","description":"The ap_pregsub function in server\/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the size of values of environment variables, which allows local users to cause a denial of service (memory consumption or NULL pointer dereference) via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, related to (1) the \"len +=\" statement and (2) the apr_pcalloc function call, a different vulnerability than CVE-2011-3607.","software":"Apache 2.2.14"}],"probe_findings":[],"threat_matches":[],"threat_count":0}}