The server is accepting NTLM anonymous credentials.
This allows for authentication bypass to access the underlying application.
https://blog.leakix.net/2022/03/bypassing-ntlm-auth-over-http/
Fingerprint: 40fea8e6a9bd2c3671ce48dbe86f199c98a4427ab4a22ea0be670e4d25c9b3c8
Server didn't refuse ANONYMOUS NTLM connection Found NTLM information: Running Windows 10.0 build 20348 MsvAvNbComputerName: WIN-01TZVO4KEJV MsvAvNbDomainName: XMLL MsvAvDNSComputerName: WIN-01TZVO4KEJV.XMLL.LOCAL MsvAvDNSDomainName: XMLL.LOCAL MsvAvDNSTreeName: XMLL.LOCAL 200 OK Content-Length: 0 Content-Type: text/html Date: Mon, 12 Aug 2024 08:15:18 GMT Server: Microsoft-IIS/10.0 Www-Authenticate: NTLM