120.76.107.38 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 120.76.107.38 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Possibly Malicious Host 🟢 15/100

Host and Network Information

  • Country: China
  • Network: AS37963 hangzhou alibaba advertising co. ltd.
  • Noticed: 1 times
  • Protocols Attacked: SSH
  • Passive DNS Results: wylan.online x6seo.com jwdmould.com xn–6krs3k3x4bmyl.com family112.com 80yxwl.com www.xqc-papergoods.com shuotao.shop hercules1115.fun www.gooseller.com fiftyad.com lihuan9527.ltd anwall.com.cn hpsytz.com g.llll.vc 6686666.xyz dns22.hichina.com dns24.hichina.com dns20.hichina.com dns18.hichina.com

Open Ports Detected

10000 10001 10134 102 1022 1023 10250 104 10443 10554 10909 10911 1099 11 110 111 11112 11210 11211 113 11300 1153 1177 119 1200 12000 122 1234 12345 1311 1322 1337 135 13579 139 14147 14265 143 1433 14344 15 1515 1521 1599 1604 16993 17 1723 1741 175 179 1800 1801 18081 1820 18245 1883 19 19000 19071 1911 1926 195 20000 2002 2006 2008 2020 2022 20256 2051 20547 2068 2083 2086 2087 21 2121 2122 2126 21379 2150 2154 2181 221 2222 23 23023 2323 2404 2455 25 25001 25565 2559 2572 26 2602 2628 264 27015 2761 28015 2806 30003 3048 3050 3054 3061 3074 3092 3093 3094 3102 311 3110 3115 3117 31337 32400 3260 3268 3269 32764 3299 3301 3306 33060 3307 3332 3388 3389 3404 3409 3412 35000 3503 3524 3541 3542 3551 3554 3557 3560 35780 37 3749 37777 3790 389 3950 4000 4022 4063 4064 4118 4157 41800 4242 427 4282 4321 4369 443 4430 4433 444 4443 44818 4482 450 4500 4506 4550 465 4782 4786 47990 4840 4899 4911 49152 49153 4949 4999 5000 50000 5001 5005 5006 5007 5009 5010 50100 502 5025 503 51235 515 5201 522 5222 5269 53 54138 5432 5435 548 55000 554 55443 55553 55554 5560 5568 5595 5672 5822 5900 5906 5909 593 5938 5984 5986 6000 60001 6001 6002 60030 6010 60129 6080 61613 61616 631 636 6379 6443 646 6601 6605 6633 6653 6666 6667 6668 6697 685 70 7000 7001 7003 7022 7071 7081 7218 7415 7434 7443 7444 7465 7510 7548 771 772 789 79 7989 80 8001 8003 8007 8009 8014 8021 8022 8027 8032 8044 8045 805 8054 8058 806 8060 8066 8069 8081 8083 8086 8087 8088 8092 8095 8099 8100 8102 8112 8126 8139 8140 8143 8181 8200 8241 8243 8282 8291 8333 8383 84 8408 8414 8429 8442 8443 8444 8448 8500 8554 8575 8649 8663 8728 873 8784 8791 8806 8807 8813 8815 8820 8827 8834 8858 8863 8864 8880 8881 8889 8989 9000 9001 9002 9011 9033 9038 9039 9042 9049 9051 9090 9091 9100 9106 9119 9136 9151 9160 92 9210 9215 9304 9306 9443 95 9530 9600 9633 9761 9869 9876 992 993 9943 9966 9991 9998 9999

CVEs Detected

CVE-2007-2768 CVE-2008-3844 CVE-2010-4478 CVE-2010-4755 CVE-2010-5107 CVE-2011-4327 CVE-2011-5000 CVE-2012-0814 CVE-2014-1692 CVE-2014-2532 CVE-2014-2653 CVE-2015-5352 CVE-2015-5600 CVE-2015-6563 CVE-2015-6564 CVE-2016-0777 CVE-2016-10009 CVE-2016-10010 CVE-2016-10011 CVE-2016-10012 CVE-2016-10708 CVE-2016-1908 CVE-2016-20012 CVE-2016-3115 CVE-2017-15906 CVE-2018-15473 CVE-2018-15919 CVE-2018-20685 CVE-2019-16905 CVE-2019-6109 CVE-2019-6110 CVE-2019-6111 CVE-2020-14145 CVE-2020-15778 CVE-2021-36368 CVE-2021-41617 CVE-2023-38408 CVE-2023-48795 CVE-2023-51384 CVE-2023-51385 CVE-2023-51767

Map

Whois Information

  • inetnum: 120.76.0.0 - 120.79.255.255
  • netname: ALISOFT
  • descr: Aliyun Computing Co., LTD
  • descr: 5F, Builing D, the West Lake International Plaza of S&T
  • descr: No.391 Wen’er Road, Hangzhou, Zhejiang, China, 310099
  • country: CN
  • admin-c: ZM1015-AP
  • tech-c: ZM877-AP
  • tech-c: ZM876-AP
  • tech-c: ZM875-AP
  • abuse-c: AC1601-AP
  • status: ALLOCATED PORTABLE
  • mnt-by: MAINT-CNNIC-AP
  • mnt-irt: IRT-ALISOFT-CN
  • last-modified: 2023-11-28T00:57:00Z
  • irt: IRT-ALISOFT-CN
  • address: No.391 Wen’er Road, Hangzhou, Zhejiang, China, 310099
  • e-mail: didong.jc@alibaba-inc.com
  • abuse-mailbox: didong.jc@alibaba-inc.com
  • admin-c: ZM877-AP
  • tech-c: ZM877-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2021-09-05T23:38:36Z
  • role: ABUSE CNNICCN
  • address: Beijing, China
  • country: ZZ
  • phone: +000000000
  • e-mail: ipas@cnnic.cn
  • admin-c: IP50-AP
  • tech-c: IP50-AP
  • nic-hdl: AC1601-AP
  • abuse-mailbox: ipas@cnnic.cn
  • mnt-by: APNIC-ABUSE
  • last-modified: 2020-05-14T11:19:01Z
  • person: Li Jia
  • address: NO.969 West Wen Yi Road, Yu Hang District, Hangzhou
  • country: CN
  • phone: +86-0571-85022088
  • e-mail: jiali.jl@alibaba-inc.com
  • nic-hdl: ZM1015-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2014-07-30T02:02:01Z
  • person: Guoxin Gao
  • address: 5F, Builing D, the West Lake International Plaza of S&T
  • address: No.391 Wen’er Road, Hangzhou City
  • address: Zhejiang, China, 310099
  • country: CN
  • phone: +86-0571-85022600
  • fax-no: +86-0571-85022600
  • e-mail: anti-spam@list.alibaba-inc.com
  • nic-hdl: ZM875-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2014-07-30T01:56:01Z
  • person: security trouble
  • e-mail: yitian.gaoyt@alibaba-inc.com
  • address: Hangzhou, Zhejiang, China
  • phone: +86-0571-85022600
  • country: CN
  • mnt-by: MAINT-CNNIC-AP
  • nic-hdl: ZM876-AP
  • last-modified: 2021-04-13T23:22:33Z
  • person: Guowei Pan
  • address: 5F, Builing D, the West Lake International Plaza of S&T
  • address: No.391 Wen’er Road, Hangzhou City
  • address: Zhejiang, China, 310099
  • country: CN
  • phone: +86-0571-85022088-30763
  • fax-no: +86-0571-85022600
  • e-mail: guowei.pangw@alibaba-inc.com
  • nic-hdl: ZM877-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2013-07-09T01:34:02Z
  • route: 120.76.0.0/14
  • descr: Hangzhou Alibaba Advertising Co.,Ltd.
  • country: CN
  • origin: AS37963
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2019-08-06T02:28:03Z
  • route: 120.76.0.0/14
  • descr: Alibaba (US) Technology Co., Ltd.
  • country: CN
  • origin: AS45102
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2019-08-06T02:28:03Z

Links to attack logs

****** ****** ******

Share on: