AmazonS3
tcp/443
CloudFront
tcp/443 tcp/80
cloudflare
tcp/443
nginx
tcp/443 tcp/80
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09cccdd54a0ccdd54a0904d808d7e02e9ac8f638f0164866dd3
Found 13 files trough .DS_Store spidering: /.git /.gitignore /collect_301.html /enter - 副本.html /enter.html /favicon.ico /iframe.html /index copy.html /index.html /QRcode - 副本.html /QRcode.html /README.md /static
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652201fa2920
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true hooksPath = /dev/null [remote "origin"] url = http://ngit.2jsncsk2dxks.xyz/zhi/zhi-luodiye-guide.git fetch = +refs/heads/*:refs/remotes/origin/*
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65224a02fe66
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true hooksPath = /dev/null [remote "origin"] url = http://git.2jsncsk2dxks.xyz/zhi/zhi-luodiye-guide.git fetch = +refs/heads/*:refs/remotes/origin/*
Open service 18.239.18.105:443 · plazv8z5zyig.xyz
2026-01-25 19:03
HTTP/1.1 200 OK
Content-Type: text/html
Transfer-Encoding: chunked
Connection: close
Date: Sat, 24 Jan 2026 23:21:39 GMT
cf-cache-status: DYNAMIC
CF-RAY: 9c3344b18e8e78c3-FRA
Server: cloudflare
Last-Modified: Thu, 28 Aug 2025 06:42:25 GMT
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=9SUTh0wHEQ5oppRMmKPSvNm2rj1eV4fFiwtKJAi8g%2FfOV%2Bhl2JyfYKQuGiAw8igyTnjzYQ7bFWmEMk9OhggMCW%2Fd9l77%2BLZWD00YnA%3D%3D"}]}
Accept-Ranges: bytes
Vary: Accept-Encoding
X-Cache: Hit from cloudfront
Via: 1.1 552fc57e69ec905c4246244771e7453a.cloudfront.net (CloudFront)
X-Amz-Cf-Pop: AMS58-P6
X-Amz-Cf-Id: x0JFKZRLD9EFD4OjW1weH0t-ZnkO8dArZaTd3VeEjMarBShyFgejOg==
Age: 70903
Page title: P站视频
<!DOCTYPE html><html lang=zh-CN><head><meta charset=utf-8><meta http-equiv=X-UA-Compatible content="IE=edge"><meta name=viewport content="width=device-width,initial-scale=1"><meta name=referrer content=no-referrer><meta name=theme-color content=#ffffff><link rel=icon href=favicon.ico><title>P站视频</title><script>var pathIndex = getCookie('pathIndex') || 0;
var hadSetNext = false;
function setCookie(name, value) {
document.cookie = name + '=' + encodeURI(value);
}
function getCookie(name) {
let arr, reg = new RegExp('(^| )' + name + '=([^;]*)(;|$)');
if (arr = document.cookie.match(reg)) {
return decodeURI(arr[2]);
} else {
return null;
}
}
function loadError() {
if (hadSetNext) return;
if (pathIndex >= pathList.length - 1) {
if (pathList[pathIndex] == './') {
return;
}
pathIndex = 0;
} else {
pathIndex++;
}
hadSetNext = true;
setCookie('pathIndex', pathIndex);
window.location.reload();
};</script><link href="static/cdn/css/element-ui/index.css?v=1.0.1" rel=stylesheet><link href="static/cdn/css/element-ui/display.css?v=1.0.1" rel=stylesheet><link href="static/cdn/css/nprogress.css?v=1.0.1" rel=stylesheet><link href=static/20250828143701/css/vendor~f3a3ebe1.css rel=stylesheet><link href=static/20250828143701/css/styles.css rel=stylesheet><link href=static/20250828143701/css/app.css rel=stylesheet></head><body><div id=app></div><script src="static/cdn/js/axios.min.js?v=1.0.1"></script><script src="static/cdn/js/lodash.min.js?v=1.0.1"></script><script src="static/cdn/js/nprogress.js?v=1.0.1"></script><script src="static/cdn/js/hls.min.js?v=1.0.1"></script><script src="static/cdn/js/DPlayer.min.js?v=1.0.1"></script><script src="static/cdn/js/jsjiami.js?v=1.0.1"></script><script>window.onload = function () {
setTimeout(() => {
loadJS("https://www.googletagmanager.com/gtag/js?id=G-YN9976Y17E", true)
window.dataLayer = window.dataLayer || [];
function gtag() { dataLayer.push(arguments); }
gtag('js', new Date());
gtag('config', 'G-YN9976Y17E');
}, 5000)
}
function loadJS(url, bol = false) {
var script = document.createElement('script')
script.setAttribute("src", url);
if (bol) {
script.setAttribute("async", "async");
}
var first = document.getElementsByTagName('script');
var here = first[first.length - 1];
here.parentNode.appendChild(script);
}
function loadCSS(url) {
var link = document.createElement('link'),
head = document.head || document.getElementsByTagName("head")[0];
link.setAttribute("rel", "stylesheet");
link.setAttribute("href", url);
head.appendChild(link);
}</script><script src=static/20250828143701/js/vendor~f269b12e.js></script><script src=static/20250828143701/js/vendor~df4692b5.js></script><script src=static/20250828143701/js/vendor~9161a349.js></script><script src=static/20250828143701/js/vendor~7159bfa5.js></script><script src=static/20250828143701/js/vendor~3a70cbed.js></script><script src=static/20250828143701/js/vendor~9d675abe.js></script><script src=static/20250828143701/js/vendor~6cb95173.js></script><script src=static/20250828143701/js/vendor~64d248ce.js></script><script src=static/20250828143701/js/vendor~cc10276c.js></script><script src=static/20250828143701/js/vendor~6ba02bd5.js></script><script src=static/20250828143701/js/vendor~bf0f8b8f.js></script><script src=static/20250828143701/js/vendor~691ceb8b.js></script><script src=static/20250828143701/js/vendor~7e5e8261.js></script><script src=static/20250828143701/js/vendor~92c00e46.js></script><script src=static/20250828143701/js/vendor~93acefaf.js></script><script src=static/20250828143701/js/vendor~5793d01e.js></script><script src=static/20250828143701/js/vendor~909464d4.js></script><scri
Open service 18.239.18.105:80 · plazv8z5zyig.xyz
2026-01-25 19:03
HTTP/1.1 301 Moved Permanently Server: CloudFront Date: Sun, 25 Jan 2026 19:03:22 GMT Content-Type: text/html Content-Length: 167 Connection: close Location: https://plazv8z5zyig.xyz/ X-Cache: Redirect from cloudfront Via: 1.1 c2905f891f96a0ec9c7fab16916dbb46.cloudfront.net (CloudFront) X-Amz-Cf-Pop: AMS58-P6 X-Amz-Cf-Id: 9TzEPYFRMKOm8dtyPnV8bWugotjvEi7XoK3ezS4REEf7nFnF6Mt2XQ== Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>CloudFront</center> </body> </html>
Open service 18.239.18.105:443 · singnplaypiano.com
2026-01-21 18:03
HTTP/1.1 301 Redirecting Server: CloudFront Date: Wed, 21 Jan 2026 18:03:06 GMT Content-Length: 0 Connection: close Location: https://www.singnplaypiano.com/ X-Cache: FunctionGeneratedResponse from cloudfront Via: 1.1 297dc74786919df7ba1867fc37f80bb6.cloudfront.net (CloudFront) X-Amz-Cf-Pop: AMS58-P6 X-Amz-Cf-Id: 8SMO1WFux8EBL4HAoHQTFnZZqaC8508T-VgupixmBY6chl7lBgIWnQ==
Open service 18.239.18.105:80 · singnplaypiano.com
2026-01-21 18:03
HTTP/1.1 301 Moved Permanently Server: CloudFront Date: Wed, 21 Jan 2026 18:03:05 GMT Content-Type: text/html Content-Length: 167 Connection: close Location: https://singnplaypiano.com/ X-Cache: Redirect from cloudfront Via: 1.1 9dba3ae645587c3cf23f9d232c9cb4e8.cloudfront.net (CloudFront) X-Amz-Cf-Pop: AMS58-P6 X-Amz-Cf-Id: m-I5Y19FSCrHm249MZtl-lid6VozgieANUKbhCTycGMga2uDElnztg== Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>CloudFront</center> </body> </html>
Open service 18.239.18.105:443 · nc3uxa.top
2026-01-10 12:39
HTTP/1.1 200 OK
Content-Type: text/html
Content-Length: 2557
Connection: close
Server: nginx
Date: Sat, 10 Jan 2026 12:39:55 GMT
Last-Modified: Sat, 19 Apr 2025 14:30:30 GMT
Accept-Ranges: bytes
ETag: "6803b386-9fd"
Vary: Accept-Encoding
X-Cache: Hit from cloudfront
Via: 1.1 435254ceec69c136096ca9b455fd3534.cloudfront.net (CloudFront)
X-Amz-Cf-Pop: AMS58-P6
Alt-Svc: h3=":443"; ma=86400
X-Amz-Cf-Id: J4rLIixBLT_inPS8__TBz5AA2YJ39YKYBoZdEBcIZ8WYb3tEega0iw==
Age: 2
Page title: Welcome
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge,chrome=1">
<meta name="renderer" content="webkit">
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=0">
<title>Welcome</title>
<link rel="stylesheet" href="css/swiper.4.3.3.min.css">
<link rel="stylesheet" href="css/qp_style.css">
<link rel="shortcut icon" type="image/x-icon" href="img/favicon.ico">
<!-- Meta Pixel Code -->
<script>
!function(f,b,e,v,n,t,s)
{if(f.fbq)return;n=f.fbq=function(){n.callMethod?
n.callMethod.apply(n,arguments):n.queue.push(arguments)};
if(!f._fbq)f._fbq=n;n.push=n;n.loaded=!0;n.version='2.0';
n.queue=[];t=b.createElement(e);t.async=!0;
t.src=v;s=b.getElementsByTagName(e)[0];
s.parentNode.insertBefore(t,s)}(window, document,'script',
'https://connect.facebook.net/en_US/fbevents.js');
fbq('init', '1908940082845716');
fbq('track', 'PageView');
</script>
<noscript><img height="1" width="1" style="display:none"
src="https://www.facebook.com/tr?id=1908940082845716&ev=PageView&noscript=1"
/></noscript>
<!-- End Meta Pixel Code -->
<style>
body {
/*background: url(./img/body_bg.jpg) ;*/
}
.game-cont{
position:relative;
}
#but1 {
position: absolute;
width: 3.9rem;
top: 5.6rem;
left: 1.8rem;
}
</style>
<script>
adaptation(750);
function adaptation(size) {
if (document.documentElement.clientWidth > size) {
document.documentElement.style.fontSize = size / 7.5 + "px"
} else {
document.documentElement.style.fontSize = document.documentElement.clientWidth / 7.5 + "px"
}
}
window.onresize = function () {
adaptation(750)
};
function getQueryVariable(variable)
{
var query = window.location.search.substring(1);
var vars = query.split("&");
for (var i=0;i<vars.length;i++) {
var pair = vars[i].split("=");
if(pair[0] == variable){return pair[1];}
}
return(0);
}
</script>
</head>
<body onclick="bodyClick()" >
<div class="warp">
<div class="game-cont">
<a href="#"><img src="img/bg.jpg" alt="" id="downloadButton3"></a>
</div>
</div>
<script src="js/swiper.4.3.3.min.js"></script>
<script>
function bodyClick(){
window.location.href = 'https://t.me/AgriBaron168';
}
</script>
</body>
</html>
Open service 18.239.18.105:80 · mfe-detalheshistoricocreditopj.cloud.itau.com.br
2026-01-10 09:28
HTTP/1.1 403 Forbidden Server: CloudFront Date: Sat, 10 Jan 2026 09:28:27 GMT Content-Type: text/html Content-Length: 986 Connection: close X-Cache: Error from cloudfront Via: 1.1 215e4a16b9afcb599baed4231992f516.cloudfront.net (CloudFront) X-Amz-Cf-Pop: AMS58-P6 Alt-Svc: h3=":443"; ma=86400 X-Amz-Cf-Id: EOCC06qgScEhjKkJgRgN2z48CUhFpMf14JgdH_xHXbeRhqyh2L62sw== X-XSS-Protection: 1; mode=block X-Frame-Options: SAMEORIGIN Referrer-Policy: strict-origin-when-cross-origin X-Content-Type-Options: nosniff Page title: ERROR: The request could not be satisfied <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"> <HTML><HEAD><META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1"> <TITLE>ERROR: The request could not be satisfied</TITLE> </HEAD><BODY> <H1>403 ERROR</H1> <H2>The request could not be satisfied.</H2> <HR noshade size="1px"> The Amazon CloudFront distribution is configured to block access from your country. We can't connect to the server for this app or website at this time. There might be too much traffic or a configuration error. Try again later, or contact the app or website owner. <BR clear="all"> If you provide content to customers through CloudFront, you can find steps to troubleshoot and help prevent this error by reviewing the CloudFront documentation. <BR clear="all"> <HR noshade size="1px"> <PRE> Generated by cloudfront (CloudFront) Request ID: EOCC06qgScEhjKkJgRgN2z48CUhFpMf14JgdH_xHXbeRhqyh2L62sw== </PRE> <ADDRESS> </ADDRESS> </BODY></HTML>
Open service 18.239.18.105:80 · marketingrpg.kr
2026-01-10 06:59
HTTP/1.1 301 Moved Permanently Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Date: Sat, 10 Jan 2026 06:59:08 GMT Pragma: no-cache Location: https://www.marketingrpg.kr/ Server: nginx P3P: CP="NOI CURa ADMa DEVa TAIa OUR DELa BUS IND PHY ONL UNI COM NAV INT DEM PRE" Set-Cookie: IMWEBVSSID=85ku8ae5ak3eke282akq9c47nav374hnd8jb2tu55fmnj2a20sld8csq0k23nojs4bqqkasqlhdr377t2dplmvlk76jj6a4rt7evj20; path=/; domain=marketingrpg.kr; HttpOnly Set-Cookie: al=KR; expires=Fri, 06-Nov-2026 06:59:08 GMT; Max-Age=25920000; path=/; domain=marketingrpg.kr; HttpOnly Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate X-Cache: Miss from cloudfront Via: 1.1 0bdea9339f79fea2216fd97b3f7856f2.cloudfront.net (CloudFront) X-Amz-Cf-Pop: AMS58-P6 X-Amz-Cf-Id: LSB8Zbl5g_hRfZ62btyPpnVS7b3IkqlN9Dut7unyvnhB-r3CQtGLEA==
Open service 18.239.18.105:443 · nbim.capital
2026-01-10 06:27
HTTP/1.1 301 Moved Permanently Content-Length: 0 Connection: close Date: Sat, 10 Jan 2026 06:27:09 GMT Location: https://www.nbim.no/ Server: AmazonS3 X-Cache: Hit from cloudfront Via: 1.1 cc275df4032e534bfa7c3c156b598f5a.cloudfront.net (CloudFront) X-Amz-Cf-Pop: AMS58-P6 X-Amz-Cf-Id: l2UNawjzkbbjJ2-r8y5qwAbc3hogtVVJPBWyUYZtPVaEh0CncwThRA== Age: 2
Open service 18.239.18.105:80 · mastercard-ads-poc.gooddata.com
2026-01-10 06:24
HTTP/1.1 301 Moved Permanently Server: CloudFront Date: Sat, 10 Jan 2026 06:24:53 GMT Content-Type: text/html Content-Length: 167 Connection: close Location: https://mastercard-ads-poc.gooddata.com/ X-Cache: Redirect from cloudfront Via: 1.1 6c60742ba67aa10b881e511aba8e470a.cloudfront.net (CloudFront) X-Amz-Cf-Pop: AMS58-P6 X-Amz-Cf-Id: xKxGhLBKOX9nrpPPEXx0Hpl7MznBbMoMqJ22TrBsQ8GmSLeO947Gjw== Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>CloudFront</center> </body> </html>
Open service 18.239.18.105:443 · images.caravanautotransport.com
2026-01-10 03:43
HTTP/1.1 403 Forbidden Content-Type: application/xml Transfer-Encoding: chunked Connection: close x-amz-bucket-region: us-west-1 Server: AmazonS3 Date: Sat, 10 Jan 2026 03:43:56 GMT X-Cache: Error from cloudfront Via: 1.1 32301bfd0e3b06c528ccd8abdb13411e.cloudfront.net (CloudFront) X-Amz-Cf-Pop: AMS58-P6 X-Amz-Cf-Id: G8KVT4MS-boGQDhUYgevTepIIiEGI0X8lIr_pfqmwoa8R67WPc3g5w== <?xml version="1.0" encoding="UTF-8"?> <Error><Code>AccessDenied</Code><Message>Access Denied</Message></Error>
Open service 18.239.18.105:443 · cdn.loyality.email.ikea.ae
2026-01-10 02:40
HTTP/1.1 403 Forbidden Content-Type: application/xml Transfer-Encoding: chunked Connection: close x-amz-bucket-region: eu-central-1 Server: AmazonS3 Date: Sat, 10 Jan 2026 02:40:58 GMT X-Cache: Error from cloudfront Via: 1.1 3a5e4105e7e14b13dcdcd3f0d9062fa0.cloudfront.net (CloudFront) X-Amz-Cf-Pop: AMS58-P6 X-Amz-Cf-Id: ehA_RkWY3sbPdZiSU8C4FeRq8uLr1gBBdChiSBdCDbtpze-l2TiJCQ== <?xml version="1.0" encoding="UTF-8"?> <Error><Code>AccessDenied</Code><Message>Access Denied</Message></Error>
Open service 18.239.18.105:80 · us1.status.getzowie.com
2026-01-10 01:21
HTTP/1.1 301 Moved Permanently Server: CloudFront Date: Sat, 10 Jan 2026 01:21:24 GMT Content-Type: text/html Content-Length: 167 Connection: close Location: https://us1.status.getzowie.com/ X-Cache: Redirect from cloudfront Via: 1.1 0bdea9339f79fea2216fd97b3f7856f2.cloudfront.net (CloudFront) X-Amz-Cf-Pop: AMS58-P6 X-Amz-Cf-Id: BkdHl1A0-VUgMXgo8WVICCXVk0p1o49oIbtijaAet2Q6kU88jdB13w== Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>CloudFront</center> </body> </html>