120.76.107.42 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 120.76.107.42 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Possibly Malicious Host 🟢 15/100

Host and Network Information

  • Country: China
  • Network: AS37963 hangzhou alibaba advertising co. ltd.
  • Noticed: 1 times
  • Protocols Attacked: SSH
  • Passive DNS Results: haorn521.asia jhds1234.top 2377077706.xyz boengg.top gzgfx.top 130.run bbc88.top zhengbinbin.top www.lvtongzuishuai.top www.xn--vuqw0ed22axya889bof6a.icu shenghuo.cool devmeta.club flyerlace.com www.pro8617888112910.asia xn–fiqx7cp7qktad7h5ybo36e.com diyixy.shop yushen.shop www.ishatch.top ishatch.top dns11.hichina.com g.llll.vc dns13.hichina.com dns15.hichina.com dns9.hichina.com

Open Ports Detected

100 10001 10081 10134 102 1023 10250 104 10443 10554 1063 1080 10909 10911 1099 11 110 111 11112 11211 11300 11371 1153 1167 1177 119 1200 12000 1234 12345 1250 13 1322 1337 135 1400 14147 14265 143 1433 14344 15 1515 1521 1599 16010 1604 1660 16993 17 1723 175 179 1800 1801 18081 18245 1833 1883 19000 1911 1926 195 1962 2000 20000 2002 2008 2020 2022 20256 2051 20547 2067 2069 2080 2081 2083 2086 2087 21025 2121 21379 2154 2181 2200 2201 2202 221 2211 2222 2323 2332 2345 2352 2376 2404 2455 2550 2554 2555 25565 2557 2566 2570 2628 264 2701 27015 27017 2761 2762 28015 2985 30002 30003 3001 3050 3051 3054 3058 3071 3096 3097 311 3116 31337 3260 3268 3269 32764 3299 3301 3306 33060 3310 3311 3337 3388 340 3401 3479 35000 3521 3523 3551 3556 37 37215 3749 3780 3790 3793 389 3950 4000 4022 4063 4064 4157 41800 4242 4282 43 4321 4369 44158 443 4430 4433 444 4443 4445 44818 449 4500 4506 4524 4643 465 4786 47990 4840 4899 49 4911 49152 4949 50000 5003 5005 5006 5007 5009 5010 50100 502 503 5090 51106 51235 515 5150 5172 5190 5201 522 52869 53 5321 54138 5432 5435 5454 548 5500 55000 554 55442 55553 55554 5560 5591 5597 5605 56981 5858 587 5900 593 5984 6000 60001 6001 60010 6002 60129 6080 61613 61616 62078 6262 6308 631 636 6379 6443 6503 6550 6622 6633 6653 666 6664 6668 6697 70 7001 7070 7071 7081 7171 7218 7415 7434 7548 7634 7657 771 7778 7779 7887 79 80 800 8001 8009 8010 8015 8022 8027 8028 8029 8034 8046 8057 8080 8081 8083 8085 8086 8087 8094 8101 8112 8123 8126 8139 8140 8159 8181 8200 8243 8252 8291 8333 8334 8401 8408 8419 8421 8443 8446 85 8554 8575 8623 8649 8728 873 8782 8804 8815 8826 8827 8834 8840 8842 8844 8849 8850 8859 8860 8862 8889 8891 9000 9001 9002 9004 9012 9016 9018 9028 9038 9041 9042 9047 9048 9049 9051 9082 9090 9091 9095 9099 91 9160 9199 9214 9302 9305 9306 9307 9309 9418 9443 9530 9595 9600 9633 97 9761 9876 990 992 993 9943 995 9955 9998 9999

CVEs Detected

CVE-2007-2768 CVE-2008-3844 CVE-2010-4478 CVE-2010-4755 CVE-2010-5107 CVE-2011-4327 CVE-2011-5000 CVE-2012-0814 CVE-2014-1692 CVE-2014-2532 CVE-2014-2653 CVE-2015-5352 CVE-2015-5600 CVE-2015-6563 CVE-2015-6564 CVE-2016-0777 CVE-2016-10009 CVE-2016-10010 CVE-2016-10011 CVE-2016-10012 CVE-2016-10708 CVE-2016-1908 CVE-2016-20012 CVE-2016-3115 CVE-2017-15906 CVE-2018-15473 CVE-2018-15919 CVE-2018-20685 CVE-2019-6109 CVE-2019-6110 CVE-2019-6111 CVE-2020-14145 CVE-2020-15778 CVE-2021-36368 CVE-2021-41617 CVE-2023-38408 CVE-2023-48795 CVE-2023-51384 CVE-2023-51385 CVE-2023-51767

Map

Whois Information

  • inetnum: 120.76.0.0 - 120.79.255.255
  • netname: ALISOFT
  • descr: Aliyun Computing Co., LTD
  • descr: 5F, Builing D, the West Lake International Plaza of S&T
  • descr: No.391 Wen’er Road, Hangzhou, Zhejiang, China, 310099
  • country: CN
  • admin-c: ZM1015-AP
  • tech-c: ZM877-AP
  • tech-c: ZM876-AP
  • tech-c: ZM875-AP
  • abuse-c: AC1601-AP
  • status: ALLOCATED PORTABLE
  • mnt-by: MAINT-CNNIC-AP
  • mnt-irt: IRT-ALISOFT-CN
  • last-modified: 2023-11-28T00:57:00Z
  • irt: IRT-ALISOFT-CN
  • address: No.391 Wen’er Road, Hangzhou, Zhejiang, China, 310099
  • e-mail: didong.jc@alibaba-inc.com
  • abuse-mailbox: didong.jc@alibaba-inc.com
  • admin-c: ZM877-AP
  • tech-c: ZM877-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2021-09-05T23:38:36Z
  • role: ABUSE CNNICCN
  • address: Beijing, China
  • country: ZZ
  • phone: +000000000
  • e-mail: ipas@cnnic.cn
  • admin-c: IP50-AP
  • tech-c: IP50-AP
  • nic-hdl: AC1601-AP
  • abuse-mailbox: ipas@cnnic.cn
  • mnt-by: APNIC-ABUSE
  • last-modified: 2020-05-14T11:19:01Z
  • person: Li Jia
  • address: NO.969 West Wen Yi Road, Yu Hang District, Hangzhou
  • country: CN
  • phone: +86-0571-85022088
  • e-mail: jiali.jl@alibaba-inc.com
  • nic-hdl: ZM1015-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2014-07-30T02:02:01Z
  • person: Guoxin Gao
  • address: 5F, Builing D, the West Lake International Plaza of S&T
  • address: No.391 Wen’er Road, Hangzhou City
  • address: Zhejiang, China, 310099
  • country: CN
  • phone: +86-0571-85022600
  • fax-no: +86-0571-85022600
  • e-mail: anti-spam@list.alibaba-inc.com
  • nic-hdl: ZM875-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2014-07-30T01:56:01Z
  • person: security trouble
  • e-mail: yitian.gaoyt@alibaba-inc.com
  • address: Hangzhou, Zhejiang, China
  • phone: +86-0571-85022600
  • country: CN
  • mnt-by: MAINT-CNNIC-AP
  • nic-hdl: ZM876-AP
  • last-modified: 2021-04-13T23:22:33Z
  • person: Guowei Pan
  • address: 5F, Builing D, the West Lake International Plaza of S&T
  • address: No.391 Wen’er Road, Hangzhou City
  • address: Zhejiang, China, 310099
  • country: CN
  • phone: +86-0571-85022088-30763
  • fax-no: +86-0571-85022600
  • e-mail: guowei.pangw@alibaba-inc.com
  • nic-hdl: ZM877-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2013-07-09T01:34:02Z
  • route: 120.76.0.0/14
  • descr: Hangzhou Alibaba Advertising Co.,Ltd.
  • country: CN
  • origin: AS37963
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2019-08-06T02:28:03Z
  • route: 120.76.0.0/14
  • descr: Alibaba (US) Technology Co., Ltd.
  • country: CN
  • origin: AS45102
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2019-08-06T02:28:03Z

Links to attack logs

****** ****** ******

Share on: