Bhoot
tcp/443
The reply originated from a backend server, the originating frontend server has been included in the report for reference.
It is critical to patch log4j or the application using since the issues is exploited in the wild and leads to RCE.
Severity: critical
Fingerprint: aff4d642200b0639f8880459ed3e1aa4d3d0f35653745fc65ddb1c512201dcd6
Received reply after a Log4j payload from this host Ping was received because of X-Forwared-Host Reply took -985.958µs Orignal request was to 23.222.64.106:443 This event's HTTP and SSL details are preserved from the orignal request. Orignal reply: 5265636569766564207265706c792061667465722061204c6f67346a207061796c6f61642066726f6d207468697320686f73740a50696e67207761732072656365697665642062656361757365206f6620582d466f7277617265642d486f73740a5265706c7920746f6f6b202d3938352e393538c2b5730a4f7269676e616c20726571756573742077617320746f2032332e3232322e36342e3130363a3434330a54686973206576656e742773204854545020616e642053534c2064657461696c7320617265207072657365727665642066726f6d20746865206f7269676e616c20726571756573742e0a
Severity: critical
Fingerprint: aff4d642200b0639f8880459ed3e1aa4a5a126046acbcdf096719b370a687b94
Received reply after a Log4j payload from this host Ping was received because of X-Forwared-Host Reply took 411.976827ms Orignal request was to 23.222.64.106:443 This event's HTTP and SSL details are preserved from the orignal request. Orignal reply: 5265636569766564207265706c792061667465722061204c6f67346a207061796c6f61642066726f6d207468697320686f73740a50696e67207761732072656365697665642062656361757365206f6620582d466f7277617265642d486f73740a5265706c7920746f6f6b203431312e3937363832376d730a4f7269676e616c20726571756573742077617320746f2032332e3232322e36342e3130363a3434330a54686973206576656e742773204854545020616e642053534c2064657461696c7320617265207072657365727665642066726f6d20746865206f7269676e616c20726571756573742e0a
Severity: critical
Fingerprint: aff4d642200b0639f8880459ed3e1aa46afbf42237d7c55ae0e1802de7229270
Received reply after a Log4j payload from this host Ping was received because of X-Forwared-Host Reply took 826.008065ms Orignal request was to 23.222.64.106:443 This event's HTTP and SSL details are preserved from the orignal request. Orignal reply: 5265636569766564207265706c792061667465722061204c6f67346a207061796c6f61642066726f6d207468697320686f73740a50696e67207761732072656365697665642062656361757365206f6620582d466f7277617265642d486f73740a5265706c7920746f6f6b203832362e3030383036356d730a4f7269676e616c20726571756573742077617320746f2032332e3232322e36342e3130363a3434330a54686973206576656e742773204854545020616e642053534c2064657461696c7320617265207072657365727665642066726f6d20746865206f7269676e616c20726571756573742e0a
Severity: critical
Fingerprint: aff4d642200b0639f8880459ed3e1aa45cdb35e8c369b65cddc3d78b6a4fd702
Received reply after a Log4j payload from this host Ping was received because of X-Forwared-Host Reply took 1.213874983s Orignal request was to 23.222.64.106:443 This event's HTTP and SSL details are preserved from the orignal request. Orignal reply: 5265636569766564207265706c792061667465722061204c6f67346a207061796c6f61642066726f6d207468697320686f73740a50696e67207761732072656365697665642062656361757365206f6620582d466f7277617265642d486f73740a5265706c7920746f6f6b20312e323133383734393833730a4f7269676e616c20726571756573742077617320746f2032332e3232322e36342e3130363a3434330a54686973206576656e742773204854545020616e642053534c2064657461696c7320617265207072657365727665642066726f6d20746865206f7269676e616c20726571756573742e0a
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff431818dff1ab714ac2ab714ac2ab714ac2ab714ac2
Public Swagger UI/API detected at path: /swagger.json - sample paths:
GET /v1/{portal}/{entity}/details/{course_id}
GET /v1/{portal}/{entity}/{type}/{region}
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff431818dff1ab714ac2ab714ac2ab714ac2ab714ac2
Public Swagger UI/API detected at path: /swagger.json - sample paths:
GET /v1/{portal}/{entity}/details/{course_id}
GET /v1/{portal}/{entity}/{type}/{region}
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff431818dff1ab714ac2ab714ac2ab714ac2ab714ac2
Public Swagger UI/API detected at path: /swagger.json - sample paths:
GET /v1/{portal}/{entity}/details/{course_id}
GET /v1/{portal}/{entity}/{type}/{region}
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff431818dff1ab714ac2ab714ac2ab714ac2ab714ac2
Public Swagger UI/API detected at path: /swagger.json - sample paths:
GET /v1/{portal}/{entity}/details/{course_id}
GET /v1/{portal}/{entity}/{type}/{region}
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff431818dff1ab714ac2ab714ac2ab714ac2ab714ac2
Public Swagger UI/API detected at path: /swagger.json - sample paths:
GET /v1/{portal}/{entity}/details/{course_id}
GET /v1/{portal}/{entity}/{type}/{region}
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff431818dff1ab714ac2ab714ac2ab714ac2ab714ac2
Public Swagger UI/API detected at path: /swagger.json - sample paths:
GET /v1/{portal}/{entity}/details/{course_id}
GET /v1/{portal}/{entity}/{type}/{region}
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff431818dff1ab714ac2ab714ac2ab714ac2ab714ac2
Public Swagger UI/API detected at path: /swagger.json - sample paths:
GET /v1/{portal}/{entity}/details/{course_id}
GET /v1/{portal}/{entity}/{type}/{region}
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff431818dff1ab714ac2ab714ac2ab714ac2ab714ac2
Public Swagger UI/API detected at path: /swagger.json - sample paths:
GET /v1/{portal}/{entity}/details/{course_id}
GET /v1/{portal}/{entity}/{type}/{region}
The reply originated from a backend server, the originating frontend server has been included in the report for reference.
It is critical to patch log4j or the application using since the issues is exploited in the wild and leads to RCE.
Severity: critical
Fingerprint: aff4d642200b0639f8880459ed3e1aa45152693139708cad40a25318a34481ce
Received reply after a Log4j payload from this host Ping was received because of X-Forwared-Host Reply took 162.304824ms Orignal request was to 23.222.64.106:443 This event's HTTP and SSL details are preserved from the orignal request. Orignal reply: 5265636569766564207265706c792061667465722061204c6f67346a207061796c6f61642066726f6d207468697320686f73740a50696e67207761732072656365697665642062656361757365206f6620582d466f7277617265642d486f73740a5265706c7920746f6f6b203136322e3330343832346d730a4f7269676e616c20726571756573742077617320746f2032332e3232322e36342e3130363a3434330a54686973206576656e742773204854545020616e642053534c2064657461696c7320617265207072657365727665642066726f6d20746865206f7269676e616c20726571756573742e0a
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff431818dff1ab714ac2ab714ac2ab714ac2ab714ac2
Public Swagger UI/API detected at path: /swagger.json - sample paths:
GET /v1/{portal}/{entity}/details/{course_id}
GET /v1/{portal}/{entity}/{type}/{region}
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff431818dff1ab714ac2ab714ac2ab714ac2ab714ac2
Public Swagger UI/API detected at path: /swagger.json - sample paths:
GET /v1/{portal}/{entity}/details/{course_id}
GET /v1/{portal}/{entity}/{type}/{region}
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff431818dff1ab714ac2ab714ac2ab714ac2ab714ac2
Public Swagger UI/API detected at path: /swagger.json - sample paths:
GET /v1/{portal}/{entity}/details/{course_id}
GET /v1/{portal}/{entity}/{type}/{region}
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff431818dff1ab714ac2ab714ac2ab714ac2ab714ac2
Public Swagger UI/API detected at path: /swagger.json - sample paths:
GET /v1/{portal}/{entity}/details/{course_id}
GET /v1/{portal}/{entity}/{type}/{region}
Open service 2.16.204.209:443 · mcst.etb2bimg.com
2026-01-23 03:29
HTTP/1.1 200 OK Server: Bhoot Content-Type: text/html; charset=UTF-8 Pragma: no-cache Last-Modified: Thu, 16 Oct 2025 08:25:32 GMT X-Cool: 22.61 Content-Language: en X-Frame-Options: sameorigin Strict-Transport-Security: max-age=25920000; includeSubdomains X-Xss-Protection: 1; mode=block X-Content-Type-Options: nosniff Cache-Control: public, max-age=86400 Expires: Sat, 24 Jan 2026 03:29:31 GMT Date: Fri, 23 Jan 2026 03:29:31 GMT Alt-Svc: h3=":443"; ma=93600 Transfer-Encoding: chunked Connection: close Connection: Transfer-Encoding Access-Control-Allow-Origin: * Access-Control-Max-Age: 86400 Access-Control-Allow-Credentials: true Access-Control-Allow-Headers: * Access-Control-Allow-Methods: GET,POST
Open service 92.122.106.222:443 · js.etb2bimg.com
2026-01-23 02:09
HTTP/1.1 200 OK Content-Type: text/html; charset=UTF-8 Last-Modified: Thu, 22 Jan 2026 13:38:42 GMT Content-Language: en X-Frame-Options: sameorigin Strict-Transport-Security: max-age=25920000; includeSubdomains X-Xss-Protection: 1; mode=block X-Content-Type-Options: nosniff Cache-Control: public, max-age=180 Expires: Fri, 23 Jan 2026 02:12:54 GMT Date: Fri, 23 Jan 2026 02:09:54 GMT Transfer-Encoding: chunked Connection: close Connection: Transfer-Encoding Access-Control-Allow-Origin: * Access-Control-Max-Age: 86400 Access-Control-Allow-Credentials: true Access-Control-Allow-Headers: * Access-Control-Allow-Methods: GET,POST
Open service 92.122.106.222:443 · img.etb2bimg.com
2026-01-23 02:09
HTTP/1.1 200 OK Content-Type: text/html; charset=UTF-8 Last-Modified: Thu, 22 Jan 2026 13:38:42 GMT Content-Language: en X-Frame-Options: sameorigin Strict-Transport-Security: max-age=25920000; includeSubdomains X-Xss-Protection: 1; mode=block X-Content-Type-Options: nosniff Cache-Control: public, max-age=180 Expires: Fri, 23 Jan 2026 02:12:55 GMT Date: Fri, 23 Jan 2026 02:09:55 GMT Transfer-Encoding: chunked Connection: close Connection: Transfer-Encoding Access-Control-Max-Age: 86400 Access-Control-Allow-Credentials: false Access-Control-Allow-Headers: * Access-Control-Allow-Methods: GET,POST Access-Control-Allow-Origin: * Akamai-GRN: 0.a95e6cc1.1769134195.d19b82e
Open service 92.122.106.222:443 · st.etb2bimg.com
2026-01-23 02:06
HTTP/1.1 200 OK Content-Type: text/html; charset=UTF-8 Last-Modified: Thu, 22 Jan 2026 13:38:42 GMT Content-Language: en X-Frame-Options: sameorigin Strict-Transport-Security: max-age=25920000; includeSubdomains X-Xss-Protection: 1; mode=block X-Content-Type-Options: nosniff Cache-Control: public, max-age=180 Expires: Fri, 23 Jan 2026 02:09:50 GMT Date: Fri, 23 Jan 2026 02:06:50 GMT Transfer-Encoding: chunked Connection: close Connection: Transfer-Encoding Access-Control-Allow-Origin: * Access-Control-Max-Age: 86400 Access-Control-Allow-Credentials: true Access-Control-Allow-Headers: * Access-Control-Allow-Methods: GET,POST
Open service 2.16.206.18:443 · tl-css.etb2bimg.com
2026-01-23 01:28
HTTP/1.1 200 OK Content-Type: text/html; charset=UTF-8 Pragma: no-cache Last-Modified: Thu, 04 Dec 2025 02:56:30 GMT X-Cool: 22.144 Content-Language: en X-Frame-Options: sameorigin Strict-Transport-Security: max-age=25920000; includeSubdomains X-Xss-Protection: 1; mode=block X-Content-Type-Options: nosniff Cache-Control: public, max-age=180 Expires: Fri, 23 Jan 2026 01:31:08 GMT Date: Fri, 23 Jan 2026 01:28:08 GMT Transfer-Encoding: chunked Connection: close Connection: Transfer-Encoding Access-Control-Allow-Origin: * Access-Control-Max-Age: 86400 Access-Control-Allow-Credentials: true Access-Control-Allow-Headers: * Access-Control-Allow-Methods: GET,POST
Open service 2.16.204.216:443 · mcjs.etb2bimg.com
2026-01-23 01:09
HTTP/1.1 200 OK Server: Bhoot Content-Type: text/html; charset=UTF-8 Pragma: no-cache Last-Modified: Wed, 16 Oct 2024 07:40:49 GMT X-Cool: 55.56 Content-Language: en X-Frame-Options: sameorigin Strict-Transport-Security: max-age=25920000; includeSubdomains X-Xss-Protection: 1; mode=block X-Content-Type-Options: nosniff Cache-Control: public, max-age=86400 Expires: Sat, 24 Jan 2026 01:09:16 GMT Date: Fri, 23 Jan 2026 01:09:16 GMT Alt-Svc: h3=":443"; ma=93600 Transfer-Encoding: chunked Connection: close Connection: Transfer-Encoding Access-Control-Allow-Origin: * Access-Control-Max-Age: 86400 Access-Control-Allow-Credentials: true Access-Control-Allow-Headers: * Access-Control-Allow-Methods: GET,POST
Open service 103.10.76.148:443 · etb2bimg.com
2026-01-23 00:17
HTTP/1.1 200 OK Date: Fri, 23 Jan 2026 00:23:54 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Expires: Fri, 23 Jan 2026 00:20:59 GMT Cache-Control: public, max-age=180 Access-Control-Allow-Origin: * Last-Modified: Fri, 23 Jan 2026 00:17:59 GMT Vary: Accept-Encoding Content-Language: en Access-Control-Allow-Credentials: true X-Frame-Options: sameorigin Strict-Transport-Security: max-age=25920000; includeSubdomains X-Xss-Protection: 1; mode=block X-Content-Type-Options: nosniff
Open service 2.16.206.15:443 · tl-js.etb2bimg.com
2026-01-22 11:52
HTTP/1.1 200 OK Content-Type: text/html; charset=UTF-8 Pragma: no-cache Last-Modified: Tue, 09 Dec 2025 09:12:45 GMT X-Cool: 22.144 Content-Language: en X-Frame-Options: sameorigin Strict-Transport-Security: max-age=25920000; includeSubdomains X-Xss-Protection: 1; mode=block X-Content-Type-Options: nosniff Cache-Control: public, max-age=180 Expires: Thu, 22 Jan 2026 11:55:02 GMT Date: Thu, 22 Jan 2026 11:52:02 GMT Transfer-Encoding: chunked Connection: close Connection: Transfer-Encoding Access-Control-Allow-Origin: * Access-Control-Max-Age: 86400 Access-Control-Allow-Credentials: true Access-Control-Allow-Headers: * Access-Control-Allow-Methods: GET,POST
Open service 92.122.106.222:443 · js.etb2bimg.com
2026-01-10 01:33
HTTP/1.1 200 OK Content-Type: text/html; charset=UTF-8 Last-Modified: Fri, 09 Jan 2026 19:47:16 GMT Content-Language: en X-Frame-Options: sameorigin Strict-Transport-Security: max-age=25920000; includeSubdomains X-Xss-Protection: 1; mode=block X-Content-Type-Options: nosniff Cache-Control: public, max-age=180 Expires: Sat, 10 Jan 2026 01:36:50 GMT Date: Sat, 10 Jan 2026 01:33:50 GMT Transfer-Encoding: chunked Connection: close Connection: Transfer-Encoding Access-Control-Allow-Origin: * Access-Control-Max-Age: 86400 Access-Control-Allow-Credentials: true Access-Control-Allow-Headers: * Access-Control-Allow-Methods: GET,POST
Open service 92.122.106.222:443 · img.etb2bimg.com
2026-01-10 01:33
HTTP/1.1 200 OK Content-Type: text/html; charset=UTF-8 Last-Modified: Fri, 09 Jan 2026 19:47:16 GMT Content-Language: en X-Frame-Options: sameorigin Strict-Transport-Security: max-age=25920000; includeSubdomains X-Xss-Protection: 1; mode=block X-Content-Type-Options: nosniff Cache-Control: public, max-age=180 Expires: Sat, 10 Jan 2026 01:36:50 GMT Date: Sat, 10 Jan 2026 01:33:50 GMT Transfer-Encoding: chunked Connection: close Connection: Transfer-Encoding Access-Control-Max-Age: 86400 Access-Control-Allow-Credentials: false Access-Control-Allow-Headers: * Access-Control-Allow-Methods: GET,POST Access-Control-Allow-Origin: * Akamai-GRN: 0.a95e6cc1.1768008830.224c25a8
Open service 2.16.206.18:443 · tl-css.etb2bimg.com
2026-01-10 01:21
HTTP/1.1 200 OK Content-Type: text/html; charset=UTF-8 Pragma: no-cache Last-Modified: Thu, 04 Dec 2025 02:56:30 GMT X-Cool: 22.144 Content-Language: en X-Frame-Options: sameorigin Strict-Transport-Security: max-age=25920000; includeSubdomains X-Xss-Protection: 1; mode=block X-Content-Type-Options: nosniff Cache-Control: public, max-age=180 Expires: Sat, 10 Jan 2026 01:24:43 GMT Date: Sat, 10 Jan 2026 01:21:43 GMT Transfer-Encoding: chunked Connection: close Connection: Transfer-Encoding Access-Control-Allow-Origin: * Access-Control-Max-Age: 86400 Access-Control-Allow-Credentials: true Access-Control-Allow-Headers: * Access-Control-Allow-Methods: GET,POST