106.11.249.99 Threat Intelligence and Host Information
General
This page contains threat intelligence information for the IPv4 address 106.11.249.99 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.
Potentially Malicious Host 🟡 50/100
Host and Network Information
-
Mitre ATT&CK IDs: T1059 - Command and Scripting Interpreter
-
Tags: 0x104, 0x11a, 0x12b, 0x14a, 0x14e, 0x228, 0x97, 0xc6, 0xe1, 0xf5, aafunction, afunction, android, april, array, array int8array, b1342177279, bad event, bad idp, child, class, closure library, cnzzdata, copyright, crios, customevent, czuuid, dafunction, date, edge, element, embed, error, fafafa, function, gc, gc3w7t6h5qw, gtmmdcvhgd, ienew ca, iframe, internal, invalid attempt, kafunction, kfunction, kkfunction, lh, meta, mit license, most, nkfunction, node, null, number, object, overlaylevel, p420, path, pseudo, public, qkfunction, quota, reduceright, regexp, rkfunction, sdkversion, skfunction, span, string, swiper, sxa0, symbol, template, this, trackevent, trackpageview, trident, typeerror, typeof, typeof b, typeof d, typeof define, typeof e, typeof enulle, typeof n, typeof r, typeof symbol, typeof t, ufunction, uint8array, umdistinctid, vd, version, void, win32, xlfunction, zdhxiong
-
View other sources: Spamhaus VirusTotal
- Country: China
- Network: AS37963 hangzhou alibaba advertising co. ltd.
- Noticed: 6 times
- Protcols Attacked: SSH
- Passive DNS Results: 3modi.com aliyun-adns.aliyun.com.vipgds.alibabadns.com aiis.tech aiis.love guru55.xyz fydch.com xn–8mrq2kk1b82dyt3ckdm.site hi-pwc.online hz-apush10.aliyuncs.com chenglong.fun xingjihao.com batit.aliyun.com zhjy2567.xyz gzklovezxp.xyz 145diyz.top hfgj2008.top 78su.com dccam.xyz gzyzqt.top samsamgiftshop.com zyj511223.top viptbsc.com 1688tbsc.xyz hfgj2016.top xzw.life timnuoo.com siluxiangtian.com z8j.xyz ai.aliyun.com msea.aliyun.com imtoken2016.us xggj2012.top 1688tbsc.shop xggj2012.us auth.o9q.cn alimail-cn.aliyuncs.com 002243.com www.pzqzpkj.com yunqi.aliyun.com tvka.cn ynding.fun mailopen-netdisk.aliyun.com alibaba-tam.com aliyun-ltd.com www.junnp03.xyz saas-accelerator.aliyun.com mailhelp.aliyun.com exmail.aliyun.com beian.aliyun.com ucc.aliyun.com acentric.eu.org usercenter.console.aliyun.com www.95bok.cn ht0428.xmcm168.com m.xmcm168.com caldav.aliyun.com sh.wagbridge.aliyun.aliyun.com www.jiufz.com www.misaya.ltd console.aliyun.com 16882020.xyz kdai.net choushabi.com fuliyun.net appjun.com hcmzj-gov.cn denglijunying.top domain.aliyun.com panda.www.net.cn dns.www.net.cn account.www.net.cn pandavip.www.net.cn aliyunk.top dmp.www.net.cn lengqie.live api.aliyun.com dgaddr.com cschat-ccs.aliyun.com tools.aliyun.com aicrowd.aliyun.com aliyun.it tracedm.aliyun.com feedback.console.aliyun.com help-ccs.aliyun.com bridge.aliyun.com microdingtalk.aliyun.com dc.www.net.cn huijiadizhi.xyz aliyun-adns.aliyun.com.gds.alibabadns.com aliyun.com
Malware Detected on Host
Count: 18 f7f37fbb7ac3de7a622161603a4c1a9e0dcd2b577a2ecef8e791859523dfb304 476d652dc399941c47f3fa6c351738666143f2897f50efd94a9cf8cdad4a6bc8 9234ccb69d53306c8bc5b1a2b1f217ceb2301d5dca553be32f9b370c0840ef5a 7e13f31366e0736be5257ecbfde5ae7a7eaac46f5fdd5e6581f95fc282574b1f d181b0bc8b71ea2d860a50e142dd739a684f837365d5ddf9cc8f7efa93c861cc 815545d9c728cc18b1f1210acd7c24d40f76e596ec4c8c43238b2b0bb6d684c7 db4b54aee0c2fce10a1b59d334151007758e5c2ba2faedc322bd1ffb5b7942d6 b91cd6685b412eec6ed55ca6788bbcf1235fd31701e7f1c82eb598118b8bfa31 84e7f66eb37e7a38b7c71f16ccab6ae8de84c6e10953c2a3b1bad381105780d3 934476ebaaacaee7dfbe93e4056385103a5ddef72d9df110ee33d7c719972712
Open Ports Detected
100 10000 10001 10134 102 1023 10243 1025 10250 104 10443 10554 10909 1099 11 110 11000 111 11112 11210 11211 113 11300 11371 1153 1167 1177 119 1200 12000 122 1234 12345 13 1311 1337 135 13579 14147 14265 143 14344 1515 1521 1554 1588 1599 1604 16993 17 17000 1723 1741 175 179 1800 1801 18081 18245 1883 19 19000 19071 1911 1925 1926 1935 195 1962 2000 20000 2002 2006 2008 20256 2048 2053 20547 2067 2081 2082 2083 2086 2087 2096 21025 2121 2122 21379 2154 2181 2201 221 2222 23 23023 2323 2332 23424 2345 2352 2376 2404 2443 2455 2480 25 25001 25105 25565 2558 2560 26 2628 264 27015 27017 2761 2762 28015 2806 3000 30002 30003 3001 3005 3050 3053 3098 3099 3116 3128 31337 3260 3268 32764 3299 3301 3306 33060 3310 3388 3389 3403 3407 35000 3523 3541 3542 3548 3551 3552 3689 37 37215 3749 37777 3780 3790 3793 3838 389 3951 4000 4022 4040 4063 4064 4157 41800 4242 427 4282 43 4321 4369 44158 443 4433 444 4443 4444 44818 4500 4506 465 4664 4700 47990 4840 4848 4899 49 4911 49152 49153 5000 50000 5001 50050 50070 5009 50100 502 5025 503 51235 515 5172 5201 5222 5269 53 5357 54138 5432 5435 5443 548 5494 5500 55000 554 55442 5555 55553 55554 5590 5601 5603 5672 5673 5858 587 5906 593 5938 59417 5984 5985 60001 6001 6002 60030 6102 61613 61616 62078 631 636 6443 64719 6580 6581 6602 6633 6653 666 6664 6666 6667 6668 6697 70 7001 7004 7005 7071 7171 7218 7415 7434 7443 7500 7537 7547 7548 7634 7654 7657 771 7777 7779 789 79 7989 80 800 8001 8009 8010 8025 8031 8036 8045 8060 8064 8069 8080 8081 8083 8085 8087 8089 8090 8096 8098 8099 8105 8106 8126 8139 8140 8182 8190 82 8200 8222 8282 8291 83 8333 8334 8402 8405 8410 8421 8443 8446 8500 8545 8554 8575 8649 8728 873 8766 8789 88 8800 8804 8811 8818 8834 8844 8852 8853 8854 8864 8880 8881 8888 8889 8999 9000 9001 9002 9006 9010 9019 9033 9042 9051 9080 9090 9091 9092 9095 9100 9136 9151 9160 9191 9200 9205 9212 9218 9295 9305 9306 9309 9310 9418 9443 9527 9530 9550 9600 9633 97 9761 9800 9869 9876 992 993 994 9943 9944 995 9981 999 9990 9998 9999
CVEs Detected
CVE-2010-4478 CVE-2010-4755 CVE-2010-5107 CVE-2011-4327 CVE-2011-5000 CVE-2012-0814 CVE-2014-1692 CVE-2014-2532 CVE-2014-2653 CVE-2015-5352 CVE-2015-5600 CVE-2015-6563 CVE-2015-6564 CVE-2016-0777 CVE-2016-10009 CVE-2016-10010 CVE-2016-10011 CVE-2016-10012 CVE-2016-10708 CVE-2016-1908 CVE-2016-20012 CVE-2017-15906 CVE-2018-15473 CVE-2018-15919 CVE-2018-20685 CVE-2019-6109 CVE-2019-6110 CVE-2019-6111 CVE-2020-14145 CVE-2020-15778 CVE-2021-36368 CVE-2021-41617 CVE-2023-38408 CVE-2023-48795 CVE-2023-51384 CVE-2023-51385
Map
Whois Information
- inetnum: 106.11.0.0 - 106.11.255.255
- netname: Taobao
- descr: Zhejiang Taobao Network Co.,Ltd
- descr: 2nd floor, Westlake International technology Building
- descr: 391Wener Road, Hangzhou, China
- country: CN
- admin-c: ZM678-AP
- tech-c: ZM877-AP
- tech-c: ZM876-AP
- abuse-c: AC1601-AP
- status: ALLOCATED PORTABLE
- mnt-by: MAINT-CNNIC-AP
- mnt-irt: IRT-TAOBAO-CN
- mnt-lower: MAINT-CNNIC-AP
- mnt-routes: MAINT-CNNIC-AP
- last-modified: 2023-11-28T00:56:50Z
- irt: IRT-Taobao-CN
- address: 2nd floor, Westlake International technology Building, 391 Wener Road, Hangzhou
- e-mail: didong.jc@alibaba-inc.com
- abuse-mailbox: didong.jc@alibaba-inc.com
- admin-c: ZM877-AP
- tech-c: ZM877-AP
- mnt-by: MAINT-CNNIC-AP
- last-modified: 2021-09-05T23:38:36Z
- role: ABUSE CNNICCN
- address: Beijing, China
- country: ZZ
- phone: +000000000
- e-mail: ipas@cnnic.cn
- admin-c: IP50-AP
- tech-c: IP50-AP
- nic-hdl: AC1601-AP
- abuse-mailbox: ipas@cnnic.cn
- mnt-by: APNIC-ABUSE
- last-modified: 2020-05-14T11:19:01Z
- person: Shuo Yu
- address: 5F, Builing D, the West Lake International Plaza of S&T
- address: No.391 Wen’er Road, Hangzhou City
- address: Zhejiang, China, 310099
- country: CN
- phone: +86-0571-85022600
- e-mail: anti-spam@list.alibaba-inc.com
- nic-hdl: ZM678-AP
- mnt-by: MAINT-CNNIC-AP
- last-modified: 2021-04-13T23:21:57Z
- person: security trouble
- e-mail: yitian.gaoyt@alibaba-inc.com
- address: Hangzhou, Zhejiang, China
- phone: +86-0571-85022600
- country: CN
- mnt-by: MAINT-CNNIC-AP
- nic-hdl: ZM876-AP
- last-modified: 2021-04-13T23:22:33Z
- person: Guowei Pan
- address: 5F, Builing D, the West Lake International Plaza of S&T
- address: No.391 Wen’er Road, Hangzhou City
- address: Zhejiang, China, 310099
- country: CN
- phone: +86-0571-85022088-30763
- fax-no: +86-0571-85022600
- e-mail: guowei.pangw@alibaba-inc.com
- nic-hdl: ZM877-AP
- mnt-by: MAINT-CNNIC-AP
- last-modified: 2013-07-09T01:34:02Z
- route: 106.11.249.0/24
- origin: AS37963
- descr: China Internet Network Information Center
- mnt-by: MAINT-CNNIC-AP
- last-modified: 2020-02-18T01:16:20Z
- route: 106.11.249.0/24
- origin: AS45102
- descr: China Internet Network Information Center
- mnt-by: MAINT-CNNIC-AP
- last-modified: 2020-02-18T01:18:17Z