Host

104.237.2.89

Tags: Database Expired certificate

As of our latest check on 2026-08-27, 104.237.2.89 (Nodisto IT, LLC, AS394727, United States) had 3 open ports (80, 443, 3306) and 8 known CVEs.

Known CVEs on this host

3open ports
0names pointing here
8known CVEs
0known exploited

Open ports and CVEs as of our latest check of this host, 2026-08-27.

CVEs by severity: CRITICAL 1 HIGH 4 MEDIUM 3

A match is an indication, not proof: it is based on the software version a service reported, and fixes are often backported without changing the version. See the list

Not counted: 7 on a distribution build — the fix may be backported (nginx 1.18.0, mariadb 10.6.23). See them

Network
Nodisto IT, LLC AS394727
Open ports
80, 443, 3306 · at our latest check, 2026-08-27
Location
United States US
Route
104.237.2.0/24 · announced by Nodisto IT, LLC AS394727 no RPKI authorisation
Organisation
Nodisto IT, LLC
Registry network
HOSTEROS · 104.237.0.0 - 104.237.15.255 · Hosteros LLC · ARIN
First seen
2026-08-27 20:20 UTC
Last seen alive
2026-08-27 20:24 UTC
Hosted domains
No host name points here

Reputation

Not a Tor relay, not a VPN or privacy relay address, and not on a current public blocklist.

Services (3)

80/tcp HTTP nginx/1.18.0 (Ubuntu) first 2026-08-27 · last 2026-08-27
Status
404 Not Found
Title
Error
Server
nginx/1.18.0 (Ubuntu)
Powered by
Express
Raw response
HTTP/1.1 404 Not Found
Server: nginx/1.18.0 (Ubuntu)
Date: Thu, 27 Aug 2026 20:21:17 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
X-Powered-By: Express
Access-Control-Allow-Origin: *
Content-Security-Policy: default-src 'none'
X-Content-Type-Options: nosniff
Content-Encoding: gzip

80
��Qt�w�pU�(�ͱ��Q
9�y��J�yJ ��� ��Z�����XT�Zb�TZ��k�-�,�I�s-*�/�чp�l��z��S*�j
�R�����K�]C�m�A"@ePy}���O#T�
0
443/tcp TLS first 2026-08-27 · last 2026-08-27
TLS
TLSv1.2
Certificate for
evofibra.arsoftware.site
Issued by
R13
Valid
2026-02-01 → 2026-05-02
Raw response
HTTP/1.1 400 Bad Request
Server: nginx/1.18.0 (Ubuntu)
Date: Thu, 27 Aug 2026 20:21:17 GMT
Content-Type: text/html
Content-Length: 666
Connection: close

<html>
<head><title>400 The plain HTTP request was sent to HTTPS port</title></head>
<body>
<center><h1>400 Bad Request</h1></center>
<center>The plain HTTP request was sent to HTTPS port</center>
<hr><center>nginx/1.18.0 (Ubuntu)</center>
</body>
</html>
<!-- a padding to disable MSIE and Chrome friendly error page -->
<!-- a padding to disable MSIE and Chrome friendly error page -->
<!-- a padding to disable MSIE and Chrome friendly error page -->
<!-- a padding to disable MSIE and Chrome friendly error page -->
<!-- a padding to disable MSIE and Chrome friendly error page -->
<!-- a padding to disable MSIE and Chrome friendly error page -->
3306/tcp MYSQL mariadb 10.6.23 8 CVEs first 2026-08-27 · last 2026-08-27
Protocol
5.5.5-10.6.23-MariaDB-0ubuntu0.22.04.1
Raw response
j
5.5.5-10.6.23-MariaDB-0ubuntu0.22.04.1pL/u"Do$`;��-��Bzc_3~E|cWm?mysql_native_password

Vulnerabilities

Distribution build — the fix may be backported (7)

These CVEs were matched on software built by an operating-system distribution whose package revision the service does not show. Distributions often fix a flaw without changing the upstream version number, so whether this build is affected cannot be told from its version. They are not counted. 1 of them is known to be exploited.

CVEs by severity: CRITICAL 1 HIGH 5 MEDIUM 1

CVESoftware
CVE-2023-44487 HIGH 7.5 known exploited nginx 1.18.0 · port 80
CVE-2026-44170 CRITICAL 9.8 mariadb 10.6.23 · port 3306
CVE-2022-41741 HIGH 7.8 nginx 1.18.0 · port 80
CVE-2021-23017 HIGH 7.7 nginx 1.18.0 · port 80
CVE-2021-3618 HIGH 7.4 nginx 1.18.0 · port 80
CVE-2022-41742 HIGH 7.1 nginx 1.18.0 · port 80
CVE-2025-23419 MEDIUM 5.3 nginx 1.18.0 · port 80

Port history

Every port that has answered a connection on this address, and when. A port is listed as open above only when a service was identified on it. Times are UTC.