1.117.96.162 Threat Intelligence and Host Information
General
This page contains threat intelligence information for the IPv4 address 1.117.96.162 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.
Possibly Malicious Host 🟢 30/100
Host and Network Information
-
Tags: Nextray, cyber security, ioc, malicious, phishing
-
View other sources: Spamhaus VirusTotal
- Country: China
- Network: AS45090 shenzhen tencent computer systems company limited
- Noticed: 1 times
- Protcols Attacked: redis
- Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
Open Ports Detected
1012 1023 1024 1025 1029 1063 1099 1153 1200 123 1234 1311 1388 1400 1433 1471 1515 1521 1599 1723 1741 1800 1801 1830 1883 1911 1925 1935 1962 1990 2000 2002 2008 2021 2022 2051 2052 2058 2063 2065 2067 2068 2081 2082 2083 2086 2087 2096 2121 2122 2154 2181 22 2200 2222 2323 2375 2379 2404 2443 2455 2480 2551 2555 2560 2572 2761 2762 3000 82
CVEs Detected
CVE-2016-20012 CVE-2017-15906 CVE-2018-15473 CVE-2018-15919 CVE-2018-20685 CVE-2019-6109 CVE-2019-6110 CVE-2019-6111 CVE-2020-14145 CVE-2020-15778 CVE-2021-36368 CVE-2021-41617 CVE-2023-38408
Map
Whois Information
- inetnum: 1.116.0.0 - 1.117.255.255
- netname: TencentCloud
- descr: Tencent cloud computing (Beijing) Co., Ltd.
- descr: Floor 6, Yinke Building,38 Haidian St,
- descr: Haidian District Beijing
- country: CN
- admin-c: JT1125-AP
- tech-c: JX1747-AP
- abuse-c: AC1601-AP
- status: ALLOCATED PORTABLE
- mnt-by: MAINT-CNNIC-AP
- mnt-lower: MAINT-CNNIC-AP
- mnt-routes: MAINT-CNNIC-AP
- mnt-irt: IRT-CNNIC-CN
- last-modified: 2021-06-16T01:32:18Z
- irt: IRT-CNNIC-CN
- address: Beijing, China
- e-mail: ipas@cnnic.cn
- abuse-mailbox: ipas@cnnic.cn
- admin-c: IP50-AP
- tech-c: IP50-AP
- mnt-by: MAINT-CNNIC-AP
- last-modified: 2021-06-16T01:39:57Z
- role: ABUSE CNNICCN
- address: Beijing, China
- country: ZZ
- phone: +000000000
- e-mail: ipas@cnnic.cn
- admin-c: IP50-AP
- tech-c: IP50-AP
- nic-hdl: AC1601-AP
- abuse-mailbox: ipas@cnnic.cn
- mnt-by: APNIC-ABUSE
- last-modified: 2020-05-14T11:19:01Z
- person: James Tian
- address: 9F, FIYTA Building, Gaoxinnanyi Road,Southern
- address: District of Hi-tech Park, Shenzhen
- country: CN
- phone: +86-755-86013388-84952
- e-mail: clarkcheng@tencent.com
- nic-hdl: JT1125-AP
- mnt-by: MAINT-CNNIC-AP
- last-modified: 2021-09-17T00:37:15Z
- person: Jimmy Xiao
- address: 9F, FIYTA Building, Gaoxinnanyi Road,Southern
- address: District of Hi-tech Park, Shenzhen
- country: CN
- phone: +86-755-86013388-80224
- e-mail: klayliang@tencent.com
- nic-hdl: JX1747-AP
- mnt-by: MAINT-CNNIC-AP
- last-modified: 2021-09-17T00:38:09Z
- route: 1.116.0.0/15
- origin: AS45090
- descr: China Internet Network Information Center
- mnt-by: MAINT-CNNIC-AP
- last-modified: 2020-02-25T01:14:45Z
Links to attack logs
awsau-redis-bruteforce-ip-list-2021-08-25 awsau-redis-bruteforce-ip-list-2021-08-29 awsau-redis-bruteforce-ip-list-2021-09-03
Share on: