Host

103.97.91.202

Tags: Hosting Remote access Self-signed certificate

As of our latest check on 2026-08-24, 103.97.91.202 (Melbikomas UAB, AS8849, Nigeria) had 4 open ports (80, 3389, 8080, 8443) and 2 known CVEs, 1 known to be exploited.

Known CVEs on this host

4open ports
0names pointing here
2known CVEs
1known exploited

Open ports and CVEs as of our latest check of this host, 2026-08-24.

CVEs by severity: HIGH 1 MEDIUM 1

A match is an indication, not proof: it is based on the software version a service reported, and fixes are often backported without changing the version. See the list

All of them on a software version from an earlier observation: a service of that kind is open now.

Not counted: 7 from an older observation (openssh 9.6p1; matched 2026-06-08). See them

Network
Melbikomas UAB AS8849
Open ports
80, 3389, 8080, 8443 · at our latest check, 2026-08-24
Location
Nigeria NG
Hostname
padmoury.com · reverse DNS, checked 2026-10-04
Route
103.97.91.0/24 · announced by Melbikomas UAB AS8849 RPKI valid
Organisation
Melbikomas UAB · Content / hosting
Registry network
LT-MELBICOM-20170717 · 103.97.91.0 - 103.97.91.255 · Melbikomas UAB · RIPE
Abuse contact
[email protected] · for LT-MELBICOM-20170717
Hostnames
free.ds.melbicom.net, ng.snowfall.top
First seen
2025-11-21 17:45 UTC
Last seen alive
2026-08-24 20:05 UTC
Hosted domains
No host name points here

Reputation

Not a Tor relay, not a VPN or privacy relay address, and not on a current public blocklist.

Services (4)

80/tcp HTTP Microsoft-IIS/10.0 first 2026-08-24 · last 2026-08-24
Status
200 OK
Title
IIS Windows Server
Server
Microsoft-IIS/10.0
Raw response
HTTP/1.1 200 OK
Content-Type: text/html
Last-Modified: Sat, 01 Aug 2026 13:44:12 GMT
Accept-Ranges: bytes
ETag: "b76839d6bb21dd1:0"
Server: Microsoft-IIS/10.0
Date: Mon, 24 Aug 2026 20:02:27 GMT
Content-Length: 703

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" />
<title>IIS Windows Server</title>
<style type="text/css">
<!--
body {
	color:#000000;
	background-color:#0072C6;
	margin:0;
}

#container {
	margin-left:auto;
	margin-right:auto;
	text-align:center;
	}

a img {
	border:none;
}

-->
</style>
</head>
<body>
<div id="container">
<a href="http://go.microsoft.com/fwlink/?linkid=66138&amp;clcid=0x409"><img src="iisstart.png" alt="IIS" width="960" height="600" /></a>
</div>
</body>
</html>
3389/tcp TLS first 2026-08-24 · last 2026-08-24
TLS
TLSv1.2
Certificate for
WIN-LTJ0O78FNMM
Issued by
WIN-LTJ0O78FNMM
Valid
2026-07-26 → 2027-01-25
Note
self-signed certificate
Raw response
EMj��T��	A��,~��\"��u$!�A�2	` �/����VҪ�N��Cs]fG󄖓��35����0��0�ʠ#�ܤ�k{�J#
8g�H�0
	*�H��
010UWIN-LTJ0O78FNMM0
260726122508Z
270125122508Z010UWIN-LTJ0O78FNMM0�"0
	*�H��
�0�
�����	kL_R݆���x���E�C%*+�3�L�v�Z?�£W�yl���4`"����#�����{փ��e��R��`ozo�
�R�&�2���5�8�k7���y�����G��,���Jʦ+"qȂviVݍ�ĭ-������I.%�o���P�|�&�^�vs���H�~j������Z,��0�3�����W�C�[s<=:E�����/;�ÉV\R₴�@�W���e�Y��z�������������<���m�hr5�ˌz���m�$0"0U%0
+0U00
	*�H��
���3��2H��Kе�A�������7"?�埧jp�P�S»�l���b�Q%���;+8��Qŝ�UX@
�Ҽd�<�je���D��MBK�6���u{�b��K��
�����3Re7�}d]���	����...<truncated>
8080/tcp HTTP first 2026-08-24 · last 2026-08-24
Status
426 Upgrade Required
Raw response
HTTP/1.1 426 Upgrade Required
Content-Length: 16
Content-Type: text/plain
Date: Mon, 24 Aug 2026 20:02:27 GMT
Connection: keep-alive
Keep-Alive: timeout=5

Upgrade Required
8443/tcp HTTP first 2026-08-24 · last 2026-08-24
Raw response
HTTP/1.1 426 Upgrade Required
Content-Length: 16
Content-Type: text/plain
Date: Mon, 24 Aug 2026 20:02:27 GMT
Connection: keep-alive
Keep-Alive: timeout=5

Upgrade Required

Vulnerabilities

From an older observation (7)

These CVEs were matched on software this host reported in an earlier observation (matched 2026-06-08), not on a port that is open now, and no service of that kind was open at the latest check (2026-08-24). They are not counted above.

CVEs by severity: HIGH 3 MEDIUM 2 LOW 2

CVESoftware
CVE-2024-6387 HIGH 8.1 openssh 9.6p1
CVE-2026-35385 HIGH 8.1 openssh 9.6p1
CVE-2026-35414 HIGH 8.1 openssh 9.6p1
CVE-2025-26465 MEDIUM 6.8 openssh 9.6p1
CVE-2026-35387 MEDIUM 6.5 openssh 9.6p1
CVE-2025-32728 LOW 3.8 openssh 9.6p1
CVE-2026-35388 LOW 2.5 openssh 9.6p1

Port history

Every port that has answered a connection on this address, and when. A port is listed as open above only when a service was identified on it. Times are UTC.