Host 18.239.18.105
United States
AMAZON-02
Software information

AmazonS3 AmazonS3

tcp/443

CloudFront

tcp/443 tcp/80

cloudflare cloudflare

tcp/443

nginx nginx

tcp/443 tcp/80

  • MacOS file listing through .DS_Store file
    First seen 2024-10-04 13:25
    Last seen 2024-10-08 17:32
    Open for 4 days
    • Severity: low
      Fingerprint: 5f32cf5d6962f09cccdd54a0ccdd54a0904d808d7e02e9ac8f638f0164866dd3

      Found 13 files trough .DS_Store spidering:
      
      /.git
      /.gitignore
      /collect_301.html
      /enter - 副本.html
      /enter.html
      /favicon.ico
      /iframe.html
      /index copy.html
      /index.html
      /QRcode - 副本.html
      /QRcode.html
      /README.md
      /static
      Found on 2024-10-08 17:32
  • Git configuration and history exposed
    First seen 2023-11-18 07:03
    Last seen 2024-09-30 19:54
    Open for 317 days
    • Severity: medium
      Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652201fa2920

      [core]
      	repositoryformatversion = 0
      	filemode = true
      	bare = false
      	logallrefupdates = true
      	hooksPath = /dev/null
      [remote "origin"]
      	url = http://ngit.2jsncsk2dxks.xyz/zhi/zhi-luodiye-guide.git
      	fetch = +refs/heads/*:refs/remotes/origin/*
      
      Found on 2024-09-30 19:54
      240 Bytes
    • Severity: medium
      Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65224a02fe66

      [core]
      	repositoryformatversion = 0
      	filemode = true
      	bare = false
      	logallrefupdates = true
      	hooksPath = /dev/null
      [remote "origin"]
      	url = http://git.2jsncsk2dxks.xyz/zhi/zhi-luodiye-guide.git
      	fetch = +refs/heads/*:refs/remotes/origin/*
      
      Found on 2024-09-08 22:05
      239 Bytes
  • Open service 18.239.18.105:443 · plazv8z5zyig.xyz

    2026-01-25 19:03

    HTTP/1.1 200 OK
    Content-Type: text/html
    Transfer-Encoding: chunked
    Connection: close
    Date: Sat, 24 Jan 2026 23:21:39 GMT
    cf-cache-status: DYNAMIC
    CF-RAY: 9c3344b18e8e78c3-FRA
    Server: cloudflare
    Last-Modified: Thu, 28 Aug 2025 06:42:25 GMT
    Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
    Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=9SUTh0wHEQ5oppRMmKPSvNm2rj1eV4fFiwtKJAi8g%2FfOV%2Bhl2JyfYKQuGiAw8igyTnjzYQ7bFWmEMk9OhggMCW%2Fd9l77%2BLZWD00YnA%3D%3D"}]}
    Accept-Ranges: bytes
    Vary: Accept-Encoding
    X-Cache: Hit from cloudfront
    Via: 1.1 552fc57e69ec905c4246244771e7453a.cloudfront.net (CloudFront)
    X-Amz-Cf-Pop: AMS58-P6
    X-Amz-Cf-Id: x0JFKZRLD9EFD4OjW1weH0t-ZnkO8dArZaTd3VeEjMarBShyFgejOg==
    Age: 70903
    
    Page title: P站视频
    
    <!DOCTYPE html><html lang=zh-CN><head><meta charset=utf-8><meta http-equiv=X-UA-Compatible content="IE=edge"><meta name=viewport content="width=device-width,initial-scale=1"><meta name=referrer content=no-referrer><meta name=theme-color content=#ffffff><link rel=icon href=favicon.ico><title>P站视频</title><script>var pathIndex = getCookie('pathIndex') || 0;
        var hadSetNext = false;
    
        function setCookie(name, value) {
          document.cookie = name + '=' + encodeURI(value);
        }
        function getCookie(name) {
          let arr, reg = new RegExp('(^| )' + name + '=([^;]*)(;|$)');
          if (arr = document.cookie.match(reg)) {
            return decodeURI(arr[2]);
          } else {
            return null;
          }
        }
        function loadError() {
          if (hadSetNext) return;
          if (pathIndex >= pathList.length - 1) {
            if (pathList[pathIndex] == './') {
              return;
            }
            pathIndex = 0;
          } else {
            pathIndex++;
          }
          hadSetNext = true;
          setCookie('pathIndex', pathIndex);
          window.location.reload();
        };</script><link href="static/cdn/css/element-ui/index.css?v=1.0.1" rel=stylesheet><link href="static/cdn/css/element-ui/display.css?v=1.0.1" rel=stylesheet><link href="static/cdn/css/nprogress.css?v=1.0.1" rel=stylesheet><link href=static/20250828143701/css/vendor~f3a3ebe1.css rel=stylesheet><link href=static/20250828143701/css/styles.css rel=stylesheet><link href=static/20250828143701/css/app.css rel=stylesheet></head><body><div id=app></div><script src="static/cdn/js/axios.min.js?v=1.0.1"></script><script src="static/cdn/js/lodash.min.js?v=1.0.1"></script><script src="static/cdn/js/nprogress.js?v=1.0.1"></script><script src="static/cdn/js/hls.min.js?v=1.0.1"></script><script src="static/cdn/js/DPlayer.min.js?v=1.0.1"></script><script src="static/cdn/js/jsjiami.js?v=1.0.1"></script><script>window.onload = function () {
              setTimeout(() => {
                loadJS("https://www.googletagmanager.com/gtag/js?id=G-YN9976Y17E", true)
                window.dataLayer = window.dataLayer || [];
                function gtag() { dataLayer.push(arguments); }
                gtag('js', new Date());
                gtag('config', 'G-YN9976Y17E');
              }, 5000)
            }
    
            function loadJS(url, bol = false) {
              var script = document.createElement('script')
              script.setAttribute("src", url);
              if (bol) {
                script.setAttribute("async", "async");
              }
              var first = document.getElementsByTagName('script');
              var here = first[first.length - 1];
              here.parentNode.appendChild(script);
            }
            function loadCSS(url) {
              var link = document.createElement('link'),
                head = document.head || document.getElementsByTagName("head")[0];
              link.setAttribute("rel", "stylesheet");
              link.setAttribute("href", url);
              head.appendChild(link);
            }</script><script src=static/20250828143701/js/vendor~f269b12e.js></script><script src=static/20250828143701/js/vendor~df4692b5.js></script><script src=static/20250828143701/js/vendor~9161a349.js></script><script src=static/20250828143701/js/vendor~7159bfa5.js></script><script src=static/20250828143701/js/vendor~3a70cbed.js></script><script src=static/20250828143701/js/vendor~9d675abe.js></script><script src=static/20250828143701/js/vendor~6cb95173.js></script><script src=static/20250828143701/js/vendor~64d248ce.js></script><script src=static/20250828143701/js/vendor~cc10276c.js></script><script src=static/20250828143701/js/vendor~6ba02bd5.js></script><script src=static/20250828143701/js/vendor~bf0f8b8f.js></script><script src=static/20250828143701/js/vendor~691ceb8b.js></script><script src=static/20250828143701/js/vendor~7e5e8261.js></script><script src=static/20250828143701/js/vendor~92c00e46.js></script><script src=static/20250828143701/js/vendor~93acefaf.js></script><script src=static/20250828143701/js/vendor~5793d01e.js></script><script src=static/20250828143701/js/vendor~909464d4.js></script><scri
    Found 2026-01-25 by HttpPlugin
    Create report
  • Open service 18.239.18.105:80 · plazv8z5zyig.xyz

    2026-01-25 19:03

    HTTP/1.1 301 Moved Permanently
    Server: CloudFront
    Date: Sun, 25 Jan 2026 19:03:22 GMT
    Content-Type: text/html
    Content-Length: 167
    Connection: close
    Location: https://plazv8z5zyig.xyz/
    X-Cache: Redirect from cloudfront
    Via: 1.1 c2905f891f96a0ec9c7fab16916dbb46.cloudfront.net (CloudFront)
    X-Amz-Cf-Pop: AMS58-P6
    X-Amz-Cf-Id: 9TzEPYFRMKOm8dtyPnV8bWugotjvEi7XoK3ezS4REEf7nFnF6Mt2XQ==
    
    Page title: 301 Moved Permanently
    
    <html>
    <head><title>301 Moved Permanently</title></head>
    <body>
    <center><h1>301 Moved Permanently</h1></center>
    <hr><center>CloudFront</center>
    </body>
    </html>
    
    Found 2026-01-25 by HttpPlugin
    Create report
  • Open service 18.239.18.105:443 · singnplaypiano.com

    2026-01-21 18:03

    HTTP/1.1 301 Redirecting
    Server: CloudFront
    Date: Wed, 21 Jan 2026 18:03:06 GMT
    Content-Length: 0
    Connection: close
    Location: https://www.singnplaypiano.com/
    X-Cache: FunctionGeneratedResponse from cloudfront
    Via: 1.1 297dc74786919df7ba1867fc37f80bb6.cloudfront.net (CloudFront)
    X-Amz-Cf-Pop: AMS58-P6
    X-Amz-Cf-Id: 8SMO1WFux8EBL4HAoHQTFnZZqaC8508T-VgupixmBY6chl7lBgIWnQ==
    
    Found 2026-01-21 by HttpPlugin
    Create report
  • Open service 18.239.18.105:80 · singnplaypiano.com

    2026-01-21 18:03

    HTTP/1.1 301 Moved Permanently
    Server: CloudFront
    Date: Wed, 21 Jan 2026 18:03:05 GMT
    Content-Type: text/html
    Content-Length: 167
    Connection: close
    Location: https://singnplaypiano.com/
    X-Cache: Redirect from cloudfront
    Via: 1.1 9dba3ae645587c3cf23f9d232c9cb4e8.cloudfront.net (CloudFront)
    X-Amz-Cf-Pop: AMS58-P6
    X-Amz-Cf-Id: m-I5Y19FSCrHm249MZtl-lid6VozgieANUKbhCTycGMga2uDElnztg==
    
    Page title: 301 Moved Permanently
    
    <html>
    <head><title>301 Moved Permanently</title></head>
    <body>
    <center><h1>301 Moved Permanently</h1></center>
    <hr><center>CloudFront</center>
    </body>
    </html>
    
    Found 2026-01-21 by HttpPlugin
    Create report
  • Open service 18.239.18.105:443 · nc3uxa.top

    2026-01-10 12:39

    HTTP/1.1 200 OK
    Content-Type: text/html
    Content-Length: 2557
    Connection: close
    Server: nginx
    Date: Sat, 10 Jan 2026 12:39:55 GMT
    Last-Modified: Sat, 19 Apr 2025 14:30:30 GMT
    Accept-Ranges: bytes
    ETag: "6803b386-9fd"
    Vary: Accept-Encoding
    X-Cache: Hit from cloudfront
    Via: 1.1 435254ceec69c136096ca9b455fd3534.cloudfront.net (CloudFront)
    X-Amz-Cf-Pop: AMS58-P6
    Alt-Svc: h3=":443"; ma=86400
    X-Amz-Cf-Id: J4rLIixBLT_inPS8__TBz5AA2YJ39YKYBoZdEBcIZ8WYb3tEega0iw==
    Age: 2
    
    Page title: Welcome
    
    
    <!DOCTYPE html>
    <html>
    <head>
        <meta charset="UTF-8">
        <meta http-equiv="X-UA-Compatible" content="IE=edge,chrome=1">
        <meta name="renderer" content="webkit">
        <meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=0">
        <title>Welcome</title>
        <link rel="stylesheet" href="css/swiper.4.3.3.min.css">
        <link rel="stylesheet" href="css/qp_style.css">
        <link rel="shortcut icon" type="image/x-icon" href="img/favicon.ico">
    <!-- Meta Pixel Code -->
    <script>
    !function(f,b,e,v,n,t,s)
    {if(f.fbq)return;n=f.fbq=function(){n.callMethod?
    n.callMethod.apply(n,arguments):n.queue.push(arguments)};
    if(!f._fbq)f._fbq=n;n.push=n;n.loaded=!0;n.version='2.0';
    n.queue=[];t=b.createElement(e);t.async=!0;
    t.src=v;s=b.getElementsByTagName(e)[0];
    s.parentNode.insertBefore(t,s)}(window, document,'script',
    'https://connect.facebook.net/en_US/fbevents.js');
    fbq('init', '1908940082845716');
    fbq('track', 'PageView');
    </script>
    <noscript><img height="1" width="1" style="display:none"
    src="https://www.facebook.com/tr?id=1908940082845716&ev=PageView&noscript=1"
    /></noscript>
    <!-- End Meta Pixel Code -->
        
        <style>
            body {
                /*background: url(./img/body_bg.jpg) ;*/
            }
            .game-cont{
                position:relative;
            }
            #but1 {
                position: absolute;
                width: 3.9rem;
                top: 5.6rem;
                left: 1.8rem;
            }
        </style>
    	<script>
    
            adaptation(750);
            function adaptation(size) {
                if (document.documentElement.clientWidth > size) {
                    document.documentElement.style.fontSize = size / 7.5 + "px"
                } else {
                    document.documentElement.style.fontSize = document.documentElement.clientWidth / 7.5 + "px"
                }
            }
            window.onresize = function () {
                adaptation(750)
            };
            
    
    		function getQueryVariable(variable)
    		{
    			var query = window.location.search.substring(1);
    			var vars = query.split("&");
    			for (var i=0;i<vars.length;i++) {
    				var pair = vars[i].split("=");
    				if(pair[0] == variable){return pair[1];}
    			}
    			return(0);
    		}
        </script>
    </head>
    <body onclick="bodyClick()" >
    <div class="warp">
        <div class="game-cont">
            <a href="#"><img src="img/bg.jpg" alt="" id="downloadButton3"></a>
        </div>
    </div>
    <script src="js/swiper.4.3.3.min.js"></script>
    <script>
    
        function bodyClick(){
    
            window.location.href = 'https://t.me/AgriBaron168';
    
        }
        
    
    </script>
    </body>
    </html>
    
    Found 2026-01-10 by HttpPlugin
    Create report
  • Open service 18.239.18.105:80 · mfe-detalheshistoricocreditopj.cloud.itau.com.br

    2026-01-10 09:28

    HTTP/1.1 403 Forbidden
    Server: CloudFront
    Date: Sat, 10 Jan 2026 09:28:27 GMT
    Content-Type: text/html
    Content-Length: 986
    Connection: close
    X-Cache: Error from cloudfront
    Via: 1.1 215e4a16b9afcb599baed4231992f516.cloudfront.net (CloudFront)
    X-Amz-Cf-Pop: AMS58-P6
    Alt-Svc: h3=":443"; ma=86400
    X-Amz-Cf-Id: EOCC06qgScEhjKkJgRgN2z48CUhFpMf14JgdH_xHXbeRhqyh2L62sw==
    X-XSS-Protection: 1; mode=block
    X-Frame-Options: SAMEORIGIN
    Referrer-Policy: strict-origin-when-cross-origin
    X-Content-Type-Options: nosniff
    
    Page title: ERROR: The request could not be satisfied
    
    <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
    <HTML><HEAD><META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
    <TITLE>ERROR: The request could not be satisfied</TITLE>
    </HEAD><BODY>
    <H1>403 ERROR</H1>
    <H2>The request could not be satisfied.</H2>
    <HR noshade size="1px">
    The Amazon CloudFront distribution is configured to block access from your country.
    We can't connect to the server for this app or website at this time. There might be too much traffic or a configuration error. Try again later, or contact the app or website owner.
    <BR clear="all">
    If you provide content to customers through CloudFront, you can find steps to troubleshoot and help prevent this error by reviewing the CloudFront documentation.
    <BR clear="all">
    <HR noshade size="1px">
    <PRE>
    Generated by cloudfront (CloudFront)
    Request ID: EOCC06qgScEhjKkJgRgN2z48CUhFpMf14JgdH_xHXbeRhqyh2L62sw==
    </PRE>
    <ADDRESS>
    </ADDRESS>
    </BODY></HTML>
    Found 2026-01-10 by HttpPlugin
    Create report
  • Open service 18.239.18.105:80 · marketingrpg.kr

    2026-01-10 06:59

    HTTP/1.1 301 Moved Permanently
    Content-Type: text/html; charset=utf-8
    Transfer-Encoding: chunked
    Connection: close
    Date: Sat, 10 Jan 2026 06:59:08 GMT
    Pragma: no-cache
    Location: https://www.marketingrpg.kr/
    Server: nginx
    P3P: CP="NOI CURa ADMa DEVa TAIa OUR DELa BUS IND PHY ONL UNI COM NAV INT DEM PRE"
    Set-Cookie: IMWEBVSSID=85ku8ae5ak3eke282akq9c47nav374hnd8jb2tu55fmnj2a20sld8csq0k23nojs4bqqkasqlhdr377t2dplmvlk76jj6a4rt7evj20; path=/; domain=marketingrpg.kr; HttpOnly
    Set-Cookie: al=KR; expires=Fri, 06-Nov-2026 06:59:08 GMT; Max-Age=25920000; path=/; domain=marketingrpg.kr; HttpOnly
    Expires: Thu, 19 Nov 1981 08:52:00 GMT
    Cache-Control: no-store, no-cache, must-revalidate
    X-Cache: Miss from cloudfront
    Via: 1.1 0bdea9339f79fea2216fd97b3f7856f2.cloudfront.net (CloudFront)
    X-Amz-Cf-Pop: AMS58-P6
    X-Amz-Cf-Id: LSB8Zbl5g_hRfZ62btyPpnVS7b3IkqlN9Dut7unyvnhB-r3CQtGLEA==
    
    Found 2026-01-10 by HttpPlugin
    Create report
  • Open service 18.239.18.105:443 · nbim.capital

    2026-01-10 06:27

    HTTP/1.1 301 Moved Permanently
    Content-Length: 0
    Connection: close
    Date: Sat, 10 Jan 2026 06:27:09 GMT
    Location: https://www.nbim.no/
    Server: AmazonS3
    X-Cache: Hit from cloudfront
    Via: 1.1 cc275df4032e534bfa7c3c156b598f5a.cloudfront.net (CloudFront)
    X-Amz-Cf-Pop: AMS58-P6
    X-Amz-Cf-Id: l2UNawjzkbbjJ2-r8y5qwAbc3hogtVVJPBWyUYZtPVaEh0CncwThRA==
    Age: 2
    
    Found 2026-01-10 by HttpPlugin
    Create report
  • Open service 18.239.18.105:80 · mastercard-ads-poc.gooddata.com

    2026-01-10 06:24

    HTTP/1.1 301 Moved Permanently
    Server: CloudFront
    Date: Sat, 10 Jan 2026 06:24:53 GMT
    Content-Type: text/html
    Content-Length: 167
    Connection: close
    Location: https://mastercard-ads-poc.gooddata.com/
    X-Cache: Redirect from cloudfront
    Via: 1.1 6c60742ba67aa10b881e511aba8e470a.cloudfront.net (CloudFront)
    X-Amz-Cf-Pop: AMS58-P6
    X-Amz-Cf-Id: xKxGhLBKOX9nrpPPEXx0Hpl7MznBbMoMqJ22TrBsQ8GmSLeO947Gjw==
    
    Page title: 301 Moved Permanently
    
    <html>
    <head><title>301 Moved Permanently</title></head>
    <body>
    <center><h1>301 Moved Permanently</h1></center>
    <hr><center>CloudFront</center>
    </body>
    </html>
    
    Found 2026-01-10 by HttpPlugin
    Create report
  • Open service 18.239.18.105:443 · images.caravanautotransport.com

    2026-01-10 03:43

    HTTP/1.1 403 Forbidden
    Content-Type: application/xml
    Transfer-Encoding: chunked
    Connection: close
    x-amz-bucket-region: us-west-1
    Server: AmazonS3
    Date: Sat, 10 Jan 2026 03:43:56 GMT
    X-Cache: Error from cloudfront
    Via: 1.1 32301bfd0e3b06c528ccd8abdb13411e.cloudfront.net (CloudFront)
    X-Amz-Cf-Pop: AMS58-P6
    X-Amz-Cf-Id: G8KVT4MS-boGQDhUYgevTepIIiEGI0X8lIr_pfqmwoa8R67WPc3g5w==
    
    
    <?xml version="1.0" encoding="UTF-8"?>
    <Error><Code>AccessDenied</Code><Message>Access Denied</Message></Error>
    Found 2026-01-10 by HttpPlugin
    Create report
  • Open service 18.239.18.105:443 · cdn.loyality.email.ikea.ae

    2026-01-10 02:40

    HTTP/1.1 403 Forbidden
    Content-Type: application/xml
    Transfer-Encoding: chunked
    Connection: close
    x-amz-bucket-region: eu-central-1
    Server: AmazonS3
    Date: Sat, 10 Jan 2026 02:40:58 GMT
    X-Cache: Error from cloudfront
    Via: 1.1 3a5e4105e7e14b13dcdcd3f0d9062fa0.cloudfront.net (CloudFront)
    X-Amz-Cf-Pop: AMS58-P6
    X-Amz-Cf-Id: ehA_RkWY3sbPdZiSU8C4FeRq8uLr1gBBdChiSBdCDbtpze-l2TiJCQ==
    
    
    <?xml version="1.0" encoding="UTF-8"?>
    <Error><Code>AccessDenied</Code><Message>Access Denied</Message></Error>
    Found 2026-01-10 by HttpPlugin
    Create report
  • Open service 18.239.18.105:80 · us1.status.getzowie.com

    2026-01-10 01:21

    HTTP/1.1 301 Moved Permanently
    Server: CloudFront
    Date: Sat, 10 Jan 2026 01:21:24 GMT
    Content-Type: text/html
    Content-Length: 167
    Connection: close
    Location: https://us1.status.getzowie.com/
    X-Cache: Redirect from cloudfront
    Via: 1.1 0bdea9339f79fea2216fd97b3f7856f2.cloudfront.net (CloudFront)
    X-Amz-Cf-Pop: AMS58-P6
    X-Amz-Cf-Id: BkdHl1A0-VUgMXgo8WVICCXVk0p1o49oIbtijaAet2Q6kU88jdB13w==
    
    Page title: 301 Moved Permanently
    
    <html>
    <head><title>301 Moved Permanently</title></head>
    <body>
    <center><h1>301 Moved Permanently</h1></center>
    <hr><center>CloudFront</center>
    </body>
    </html>
    
    Found 2026-01-10 by HttpPlugin
    Create report
ed97u6m9bxcy.xyzl85cd8xt374w.xyzxia7h4u90t5n.xyzszgcmv84hx63.xyzwduyv2wxmxt7.xyzhsj9g7euguhs.xyzp05x44x57w6d.xyzplazv8z5zyig.xyz0k86owltlhz6.xyz7zznvii1rrpx.xyz
CN:
ed97u6m9bxcy.xyz
Key:
RSA-2048
Issuer:
Not before:
2025-02-16 00:00
Not after:
2026-03-17 23:59
singnplaypiano.com*.singnplaypiano.com
CN:
singnplaypiano.com
Key:
RSA-2048
Issuer:
Not before:
2025-03-16 00:00
Not after:
2026-04-14 23:59
nc3uxa.topwww.nc3uxa.top
CN:
nc3uxa.top
Key:
RSA-2048
Issuer:
Not before:
2025-10-09 00:00
Not after:
2026-11-07 23:59
nbim.capitalwww.nbim.capital
CN:
nbim.capital
Key:
RSA-2048
Issuer:
Not before:
2025-03-18 00:00
Not after:
2026-04-16 23:59
images.caravanautotransport.com
CN:
images.caravanautotransport.com
Key:
RSA-2048
Issuer:
Not before:
2025-12-07 00:00
Not after:
2027-01-05 23:59
cdn.cloud.email.ikea.aecdn.loyality.email.ikea.qacdn.loyality.email.ikea.omcdn.loyality.email.ikea.aecdn.cloud.email.ikea.omcdn.loyality.email.ikea.egcdn.cloud.email.ikea.egcdn.cloud.email.ikea.qa
CN:
cdn.cloud.email.ikea.ae
Key:
RSA-2048
Issuer:
Not before:
2025-08-12 00:00
Not after:
2026-09-10 23:59