The server is accepting NTLM anonymous credentials.
This allows for authentication bypass to access the underlying application.
https://blog.leakix.net/2022/03/bypassing-ntlm-auth-over-http/
Fingerprint: 40fea8e6a9bd2c3671ce48dbe86f199c98a4427a41a1e8cd9bbc4affa3bb6100
Server didn't refuse ANONYMOUS NTLM connection Found NTLM information: Running Windows 10.0 build 20348 MsvAvNbComputerName: WIN-WAV3D8YYF7E MsvAvNbDomainName: 6H8F MsvAvDNSComputerName: WIN-WAV3D8YYF7E.6H8F.LOCAL MsvAvDNSDomainName: 6H8F.LOCAL MsvAvDNSTreeName: 6H8F.LOCAL 200 OK Content-Length: 0 Content-Type: text/html Date: Mon, 02 Sep 2024 09:54:37 GMT Server: Microsoft-IIS/10.0 Www-Authenticate: NTLM