They scan and report what the servers advertise, so normally you’d see a list of services and it’d list versions which have known CVEs (obviously, this doesn’t say it’s actually vulnerable if e.g. a Linux distribution patched it without changing the advertised major version).
The “compromised” tag is only added after some confirmation of known malicious activity. I’m not sure what all that includes but I believe that can be things like 200 responses to known malware paths or a database reporting names used by common malware.
Comments
They scan and report what the servers advertise, so normally you’d see a list of services and it’d list versions which have known CVEs (obviously, this doesn’t say it’s actually vulnerable if e.g. a Linux distribution patched it without changing the advertised major version).
The “compromised” tag is only added after some confirmation of known malicious activity. I’m not sure what all that includes but I believe that can be things like 200 responses to known malware paths or a database reporting names used by common malware.