Host

66.36.166.76

Tags: Self-signed certificate Expired certificate

As of our latest check on 2026-07-18, 66.36.166.76 (TPx Communications, AS14265, United States) had 4 open ports (21, 80, 443, 8443) and 2 known CVEs.

Known CVEs on this host

4open ports
0names pointing here
2known CVEs
0known exploited

Open ports and CVEs as of our latest check of this host, 2026-07-18.

CVEs by severity: MEDIUM 2

A match is an indication, not proof: it is based on the software version a service reported, and fixes are often backported without changing the version. See the list

Not counted: 1 only affects a particular platform; this host's is not known (php 7.4.33). See them

Network
TPx Communications AS14265
Open ports
21, 80, 443, 8443 · at our latest check, 2026-07-18
Location
United States US
Hostname
brownlowplastering.com · reverse DNS, checked 2026-10-04
Route
66.36.160.0/20 · announced by TPx Communications AS14265 no RPKI authorisation
Organisation
TelePacific Communications · Network service provider (transit)
Registry network
SITETURN-01 · 66.36.160.0 - 66.36.191.255 · SiteTurn Networks · ARIN
Abuse contact
[email protected] · for SITETURN-01
First seen
2026-07-18 20:35 UTC
Last seen alive
2026-07-18 20:37 UTC
Hosted domains
No host name points here

Reputation

Not a Tor relay, not a VPN or privacy relay address, and not on a current public blocklist.

Services (4)

21/tcp FTP first 2026-07-18 · last 2026-07-18
Banner
220 ProFTPD Server (ProFTPD) [66.36.166.76]
Raw response
220 ProFTPD Server (ProFTPD) [66.36.166.76]
80/tcp HTTP nginx 2 CVEs first 2026-07-18 · last 2026-07-18
Status
500 Internal Server Error
Server
nginx
Powered by
PHP/7.4.33
Raw response
HTTP/1.1 500 Internal Server Error
Server: nginx
Date: Sat, 18 Jul 2026 20:35:45 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 0
Connection: keep-alive
X-Powered-By: PHP/7.4.33
443/tcp TLS first 2026-07-18 · last 2026-07-18
TLS
TLSv1.2
Certificate for
Plesk
Issued by
Plesk
Valid
2020-10-13 → 2021-10-13
Note
self-signed certificate
Raw response
HTTP/1.1 400 Bad Request
Server: nginx
Date: Sat, 18 Jul 2026 20:35:45 GMT
Content-Type: text/html
Content-Length: 650
Connection: close

<html>
<head><title>400 The plain HTTP request was sent to HTTPS port</title></head>
<body>
<center><h1>400 Bad Request</h1></center>
<center>The plain HTTP request was sent to HTTPS port</center>
<hr><center>nginx</center>
</body>
</html>
<!-- a padding to disable MSIE and Chrome friendly error page -->
<!-- a padding to disable MSIE and Chrome friendly error page -->
<!-- a padding to disable MSIE and Chrome friendly error page -->
<!-- a padding to disable MSIE and Chrome friendly error page -->
<!-- a padding to disable MSIE and Chrome friendly error page -->
<!-- a padding to disable MSIE and Chrome friendly error page -->
8443/tcp HTTP nginx first 2026-07-18 · last 2026-07-18
Status
303 See Other
Server
nginx
Raw response
HTTP/1.1 302 Moved Temporarily
Server: sw-cp-server
Date: Sat, 18 Jul 2026 20:35:45 GMT
Content-Type: text/html
Content-Length: 138
Connection: close
Location: https://66.36.166.76:8443/
X-Content-Type-Options: nosniff

<html>
<head><title>302 Found</title></head>
<body>
<center><h1>302 Found</h1></center>
<hr><center>nginx</center>
</body>
</html>

Vulnerabilities

Only affects certain platforms (1)

These CVEs only apply when the software runs on a particular platform (for example Windows), and this host's platform is not known. They are not counted.

CVEs by severity: CRITICAL 1

CVESoftware
CVE-2024-3566 CRITICAL 9.8 php 7.4.33 · port 80

Port history

Every port that has answered a connection on this address, and when. A port is listed as open above only when a service was identified on it. Times are UTC.