133.167.115.39
Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.
Run a live full scan of 133.167.115.39
On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.
Autonomous System
Geolocation
Reverse DNS
Network
Open Ports
| Port | Proto | Service | Server | Last seen |
|---|---|---|---|---|
| 443 | tcp | https | Apache/2.2.3 (CentOS) | 2026-05-25 21:21:45.000 |
TLS Certificates
Known Vulnerabilities
Published CVEs matched to the software versions fingerprinted on this host. Matching is by product and version against the NVD dictionary — presence of a CVE does not confirm the host is exploitable (patches or backports may apply).
| CVE | Software | CVSS | Severity | Summary |
|---|---|---|---|---|
| CVE-2017-3169 | Apache 2.2.3 | 9.8 | N/A | In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_process_connection() d... |
| CVE-2007-6423 | Apache 2.2.3 | 7.8 | HIGH | Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attackers to trigger memor... |
| CVE-2008-2384 | Apache 2.2.3 | 7.5 | HIGH | SQL injection vulnerability in mod_auth_mysql.c in the mod-auth-mysql (aka libapache2-mod-auth-mysql) module for the Apache HTTP Server 2.x, when configured to... |
| CVE-2006-4154 | Apache 2.2.3 | 6.8 | MEDIUM | Format string vulnerability in the mod_tcl module 1.0 for Apache 2.x allows context-dependent attackers to execute arbitrary code via format string specifiers t... |
| CVE-2007-1741 | Apache 2.2.3 | 6.2 | MEDIUM | Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to gain privile... |
| CVE-2016-4975 | Apache 2.2.3 | 6.1 | N/A | Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 and 2.2.32... |
| CVE-2007-6750 | Apache 2.2.3 | 5.0 | MEDIUM | The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris,... |
| CVE-2010-0408 | Apache 2.2.3 | 5.0 | MEDIUM | The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain situations... |
| CVE-2011-3368 | Apache 2.2.3 | 5.0 | MEDIUM | The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) R... |
| CVE-2013-5704 | Apache 2.2.3 | 5.0 | MEDIUM | The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer po... |
| CVE-2009-1195 | Apache 2.2.3 | 4.9 | MEDIUM | The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users... |
| CVE-2007-1743 | Apache 2.2.3 | 4.4 | MEDIUM | suexec in Apache HTTP Server (httpd) 2.2.3 does not verify combinations of user and group IDs on the command line, which might allow local users to leverage oth... |
| CVE-2011-3607 | Apache 2.2.3 | 4.4 | MEDIUM | Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif modu... |
| CVE-2006-4110 | Apache 2.2.3 | 4.3 | MEDIUM | Apache 2.2.2, when running on Windows, allows remote attackers to read source code of CGI programs via a request that contains uppercase (or alternate case) cha... |
| CVE-2007-6203 | Apache 2.2.3 | 4.3 | MEDIUM | Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity To... |
| CVE-2007-6420 | Apache 2.2.3 | 4.3 | MEDIUM | Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2.2.x allows remote attackers to gain privi... |
| CVE-2008-2168 | Apache 2.2.3 | 4.3 | MEDIUM | Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that... |
| CVE-2011-3639 | Apache 2.2.3 | 4.3 | MEDIUM | The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x before 2.2.18, when the Revision 1179239 patch is in place, does not properly inte... |
| CVE-2011-4317 | Apache 2.2.3 | 4.3 | MEDIUM | The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision 1179239 patch is in place... |
| CVE-2012-3499 | Apache 2.2.3 | 4.3 | MEDIUM | Multiple cross-site scripting (XSS) vulnerabilities in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject ar... |
| CVE-2012-4558 | Apache 2.2.3 | 4.3 | MEDIUM | Multiple cross-site scripting (XSS) vulnerabilities in the balancer_handler function in the manager interface in mod_proxy_balancer.c in the mod_proxy_balancer... |
| CVE-2007-6422 | Apache 2.2.3 | 4.0 | MEDIUM | The balancer_handler function in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6, when a threaded Multi-Processing Module is used, allows remot... |
| CVE-2007-1742 | Apache 2.2.3 | 3.7 | LOW | suexec in Apache HTTP Server (httpd) 2.2.3 uses a partial comparison for verifying whether the current directory is within the document root, which might allow... |
| CVE-2007-6421 | Apache 2.2.3 | 3.5 | LOW | Cross-site scripting (XSS) vulnerability in balancer-manager in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inje... |
| CVE-2012-2687 | Apache 2.2.3 | 2.6 | LOW | Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Serv... |
| CVE-2011-4415 | Apache 2.2.3 | 1.2 | LOW | The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does... |
Tech Stack
Wappalyzer fingerprinting pending
HTTP-body analysis identifies web frameworks, CMS platforms, analytics, JS libraries and server-side languages from this host.
Origin / IP-Leak
When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.
No origin-leak candidates for this IP
When this IP serves a TLS cert for a domain that fronts behind a CDN, that domain surfaces here as an origin-leak candidate with a confidence score.
Hosted Domains
Multi-Vantage Check
Reachability accrued passively from real user-triggered checks across our 65+ probe nodes. Run a live check to add fresh data.
No accumulated reachability data yet
Reachability accrues from real user-triggered checks. Trigger a Ping or HTTP check from our 65+ probe nodes to contribute the first data point.
Threat Intelligence
No threat-intel matches
This IP doesn't appear in any of the feeds we mirror (Tor exits, FireHOL Level 1-3, Spamhaus DROP/EDROP, URLhaus, OpenPhish). Absence here doesn't prove the IP is clean — it just means none of our public-feed sources flag it.
Co-Hosted Domains
Domains this host references in its HTML AND whose DNS A/AAAA record resolves back to this IP — i.e. actually hosted here.
External References
Domains the body links to whose DNS does NOT resolve to this IP — usually CDN assets, embeds, or third-party services. Boilerplate (Google Fonts, jsDelivr, w3.org…) is already filtered.
History
The full change-log (ASN moves, cert rotations, port-state diffs) accumulates as our archives grow.