106.11.249.99 Threat Intelligence and Host Information

General

IP Address
106.11.249.99
IPv4 Address
Location
🇨🇳 China
CN
Network
AS37963
Hangzhou Alibaba Advertising Co.,Ltd.
Threat Score
50/100
Medium Risk
0x1040x11a0x12b0x14a0x14e0x2280x970xc6
Attack Intelligence
MITRE ATT&CK Techniques
T1059 - Command and Scripting Interpreter
Open Ports Detected
100
Geographic Location
Country
China
City
Unknown
Region
Unknown
Coordinates
34.7732, 113.7220
Network Information
ASN
AS37963
Organization
Hangzhou Alibaba Advertising Co.,Ltd.
Network
AS37963 Hangzhou Alibaba Advertising Co.,Ltd.
WHOIS Information
inetnum
106.11.0.0 - 106.11.255.255
netname
Taobao
descr
China Internet Network Information Center
country
CN
admin-c
IP50-AP
tech-c
IP50-AP
abuse-c
AC1601-AP
status
ALLOCATED PORTABLE
mnt-by
MAINT-CNNIC-AP
mnt-irt
IRT-TAOBAO-CN
mnt-lower
MAINT-CNNIC-AP
mnt-routes
MAINT-CNNIC-AP
last-modified
2020-02-18T01:18:17Z
irt
IRT-Taobao-CN
address
Zhejiang, China, 310099
e-mail
guowei.pangw@alibaba-inc.com
abuse-mailbox
ipas@cnnic.cn
role
ABUSE CNNICCN
phone
+86-0571-85022088-30763
nic-hdl
ZM877-AP
person
Guowei Pan
fax-no
+86-0571-85022600
route
106.11.249.0/24
origin
AS45102

  • Country: China
  • Network: AS37963 hangzhou alibaba advertising co. ltd.
  • Noticed: 6 times
  • Protcols Attacked: SSH
  • Passive DNS Results: 3modi.com aliyun-adns.aliyun.com.vipgds.alibabadns.com aiis.tech aiis.love guru55.xyz fydch.com xn–8mrq2kk1b82dyt3ckdm.site hi-pwc.online hz-apush10.aliyuncs.com chenglong.fun xingjihao.com batit.aliyun.com zhjy2567.xyz gzklovezxp.xyz 145diyz.top hfgj2008.top 78su.com dccam.xyz gzyzqt.top samsamgiftshop.com zyj511223.top viptbsc.com 1688tbsc.xyz hfgj2016.top xzw.life timnuoo.com siluxiangtian.com z8j.xyz ai.aliyun.com msea.aliyun.com imtoken2016.us xggj2012.top 1688tbsc.shop xggj2012.us auth.o9q.cn alimail-cn.aliyuncs.com 002243.com www.pzqzpkj.com yunqi.aliyun.com tvka.cn ynding.fun mailopen-netdisk.aliyun.com alibaba-tam.com aliyun-ltd.com www.junnp03.xyz saas-accelerator.aliyun.com mailhelp.aliyun.com exmail.aliyun.com beian.aliyun.com ucc.aliyun.com acentric.eu.org usercenter.console.aliyun.com www.95bok.cn ht0428.xmcm168.com m.xmcm168.com caldav.aliyun.com sh.wagbridge.aliyun.aliyun.com www.jiufz.com www.misaya.ltd console.aliyun.com 16882020.xyz kdai.net choushabi.com fuliyun.net appjun.com hcmzj-gov.cn denglijunying.top domain.aliyun.com panda.www.net.cn dns.www.net.cn account.www.net.cn pandavip.www.net.cn aliyunk.top dmp.www.net.cn lengqie.live api.aliyun.com dgaddr.com cschat-ccs.aliyun.com tools.aliyun.com aicrowd.aliyun.com aliyun.it tracedm.aliyun.com feedback.console.aliyun.com help-ccs.aliyun.com bridge.aliyun.com microdingtalk.aliyun.com dc.www.net.cn huijiadizhi.xyz aliyun-adns.aliyun.com.gds.alibabadns.com aliyun.com

Malware Detected on Host

Count: 18 f7f37fbb7ac3de7a622161603a4c1a9e0dcd2b577a2ecef8e791859523dfb304 476d652dc399941c47f3fa6c351738666143f2897f50efd94a9cf8cdad4a6bc8 9234ccb69d53306c8bc5b1a2b1f217ceb2301d5dca553be32f9b370c0840ef5a 7e13f31366e0736be5257ecbfde5ae7a7eaac46f5fdd5e6581f95fc282574b1f d181b0bc8b71ea2d860a50e142dd739a684f837365d5ddf9cc8f7efa93c861cc 815545d9c728cc18b1f1210acd7c24d40f76e596ec4c8c43238b2b0bb6d684c7 db4b54aee0c2fce10a1b59d334151007758e5c2ba2faedc322bd1ffb5b7942d6 b91cd6685b412eec6ed55ca6788bbcf1235fd31701e7f1c82eb598118b8bfa31 84e7f66eb37e7a38b7c71f16ccab6ae8de84c6e10953c2a3b1bad381105780d3 934476ebaaacaee7dfbe93e4056385103a5ddef72d9df110ee33d7c719972712

CVEs Detected

CVE-2010-4478 CVE-2010-4755 CVE-2010-5107 CVE-2011-4327 CVE-2011-5000 CVE-2012-0814 CVE-2014-1692 CVE-2014-2532 CVE-2014-2653 CVE-2015-5352 CVE-2015-5600 CVE-2015-6563 CVE-2015-6564 CVE-2016-0777 CVE-2016-10009 CVE-2016-10010 CVE-2016-10011 CVE-2016-10012 CVE-2016-10708 CVE-2016-1908 CVE-2016-20012 CVE-2017-15906 CVE-2018-15473 CVE-2018-15919 CVE-2018-20685 CVE-2019-6109 CVE-2019-6110 CVE-2019-6111 CVE-2020-14145 CVE-2020-15778 CVE-2021-36368 CVE-2021-41617 CVE-2023-38408 CVE-2023-48795 CVE-2023-51384 CVE-2023-51385

Disclaimer
This page contains threat intelligence information for the IPv4 address 106.11.249.99 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.