120.76.107.43 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 120.76.107.43 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Possibly Malicious Host 🟢 19/100

Host and Network Information

  • Country: China
  • Network: AS37963 hangzhou alibaba advertising co. ltd.
  • Noticed: 2 times
  • Protocols Attacked: SSH
  • Passive DNS Results: stargift.top scerring.com offersees.com badipinpai.com xzgpt.fun www.cksaas.com ns1.hichina.com szgintway.com huiyingsports.top jjdzdc.top numbnut.top www.carlacloud.com teslasofa.com sllc5514.com 888mh.fun ens12.bigwww.com ns16.bigwww.com ns12.bigwww.com ns2.thdns.com dns3.hichina.com heroti.xyz dns1.hichina.com dns7.hichina.com g.llll.vc

Open Ports Detected

10000 10001 10134 102 1023 1024 1025 10250 104 10443 10554 10909 10911 1099 11 110 11000 111 1110 11112 11210 11211 113 11300 11371 1153 1177 119 1200 12000 122 1234 12345 13 1311 1322 1337 135 13579 139 1400 14147 14265 143 1433 14344 1471 15 1515 1521 154 1588 1599 1604 16992 16993 17 1723 1741 175 179 180 1800 1801 18081 18245 1883 19 19000 1901 19071 1911 1925 1926 195 1950 1962 2000 20000 2002 2008 2022 20256 2050 2051 2054 20547 2061 2063 2067 2077 2081 2082 2083 2086 2087 21 21025 2111 2121 2126 21379 2154 2181 2202 221 2211 2222 2223 2233 225 23 23023 2323 2332 2345 2375 2376 24 2404 2455 2480 25 25001 2548 25565 2560 26 2626 2628 264 27015 27017 2761 2762 28015 28017 2806 30002 30003 3001 3050 3052 3054 3055 3059 3060 3061 3067 3089 3096 311 3112 3115 3121 31337 32400 3260 3268 3269 32764 3299 3301 3306 33060 3310 3337 3388 3389 3403 3404 3405 3408 35000 3524 3541 3542 3548 3549 3551 3554 3568 3570 35780 3689 37 3749 37777 3780 3790 3794 38 3838 389 3954 4000 4022 4040 4063 4064 4157 41800 4190 4242 427 4282 43 4321 4369 44158 443 4430 4433 444 4443 447 44818 449 4500 4505 4506 465 4664 4734 4782 4786 47990 4808 4840 4899 49 4911 49152 49153 4949 5000 50000 5001 5002 5004 5005 5006 5007 50070 5009 5010 50100 502 5025 503 5050 51235 515 5172 5201 5222 5269 5280 53 5321 54138 5432 5435 548 55000 554 55442 55443 555 55553 55554 5560 5567 5598 5672 5801 5853 5858 587 5900 5908 593 5938 5984 5985 5986 6000 6001 60010 6002 6003 60030 6008 60129 6080 6102 61613 61616 62078 6352 636 6379 6443 6622 6633 6653 666 6666 6667 6668 6697 6789 70 7001 7010 7071 7081 7170 7171 7218 7415 7434 7443 7474 7548 7634 7676 771 7788 789 79 7979 7989 7998 80 8001 8004 8007 8009 8020 8036 8053 8054 8080 8081 8083 8085 8086 8087 8089 8096 8099 81 8112 8123 8126 8139 8140 8181 82 8200 8236 8248 8249 8252 8282 8291 83 8333 84 8404 8414 8422 8443 8500 8545 8554 8575 8590 86 8649 8728 873 8787 8802 8810 8815 8817 8822 8827 8834 8867 8875 8879 8880 8889 8988 9000 9001 9002 9007 9014 9030 9035 9039 9040 9042 9047 9048 9050 9051 9089 9090 9091 9092 9093 9094 9095 9100 9101 9151 9160 9199 92 9206 9213 9306 9418 9443 9527 9530 9595 9600 9633 9761 9765 9876 99 992 993 9943 9944 995 9981 9993 9994 9998 9999

CVEs Detected

CVE-2007-2768 CVE-2008-3844 CVE-2010-4478 CVE-2010-4755 CVE-2010-5107 CVE-2011-4327 CVE-2011-5000 CVE-2012-0814 CVE-2014-1692 CVE-2014-2532 CVE-2014-2653 CVE-2015-5352 CVE-2015-5600 CVE-2015-6563 CVE-2015-6564 CVE-2016-0777 CVE-2016-10009 CVE-2016-10010 CVE-2016-10011 CVE-2016-10012 CVE-2016-10708 CVE-2016-20012 CVE-2016-3115 CVE-2017-15906 CVE-2018-15473 CVE-2018-15919 CVE-2018-20685 CVE-2019-16905 CVE-2019-6109 CVE-2019-6110 CVE-2019-6111 CVE-2020-14145 CVE-2020-15778 CVE-2021-36368 CVE-2021-41617 CVE-2023-38408 CVE-2023-48795 CVE-2023-51384 CVE-2023-51385 CVE-2023-51767

Map

Whois Information

  • inetnum: 120.76.0.0 - 120.79.255.255
  • netname: ALISOFT
  • descr: Aliyun Computing Co., LTD
  • descr: 5F, Builing D, the West Lake International Plaza of S&T
  • descr: No.391 Wen’er Road, Hangzhou, Zhejiang, China, 310099
  • country: CN
  • admin-c: ZM1015-AP
  • tech-c: ZM877-AP
  • tech-c: ZM876-AP
  • tech-c: ZM875-AP
  • abuse-c: AC1601-AP
  • status: ALLOCATED PORTABLE
  • mnt-by: MAINT-CNNIC-AP
  • mnt-irt: IRT-ALISOFT-CN
  • last-modified: 2023-11-28T00:57:00Z
  • irt: IRT-ALISOFT-CN
  • address: No.391 Wen’er Road, Hangzhou, Zhejiang, China, 310099
  • e-mail: didong.jc@alibaba-inc.com
  • abuse-mailbox: didong.jc@alibaba-inc.com
  • admin-c: ZM877-AP
  • tech-c: ZM877-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2021-09-05T23:38:36Z
  • role: ABUSE CNNICCN
  • address: Beijing, China
  • country: ZZ
  • phone: +000000000
  • e-mail: ipas@cnnic.cn
  • admin-c: IP50-AP
  • tech-c: IP50-AP
  • nic-hdl: AC1601-AP
  • abuse-mailbox: ipas@cnnic.cn
  • mnt-by: APNIC-ABUSE
  • last-modified: 2020-05-14T11:19:01Z
  • person: Li Jia
  • address: NO.969 West Wen Yi Road, Yu Hang District, Hangzhou
  • country: CN
  • phone: +86-0571-85022088
  • e-mail: jiali.jl@alibaba-inc.com
  • nic-hdl: ZM1015-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2014-07-30T02:02:01Z
  • person: Guoxin Gao
  • address: 5F, Builing D, the West Lake International Plaza of S&T
  • address: No.391 Wen’er Road, Hangzhou City
  • address: Zhejiang, China, 310099
  • country: CN
  • phone: +86-0571-85022600
  • fax-no: +86-0571-85022600
  • e-mail: anti-spam@list.alibaba-inc.com
  • nic-hdl: ZM875-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2014-07-30T01:56:01Z
  • person: security trouble
  • e-mail: yitian.gaoyt@alibaba-inc.com
  • address: Hangzhou, Zhejiang, China
  • phone: +86-0571-85022600
  • country: CN
  • mnt-by: MAINT-CNNIC-AP
  • nic-hdl: ZM876-AP
  • last-modified: 2021-04-13T23:22:33Z
  • person: Guowei Pan
  • address: 5F, Builing D, the West Lake International Plaza of S&T
  • address: No.391 Wen’er Road, Hangzhou City
  • address: Zhejiang, China, 310099
  • country: CN
  • phone: +86-0571-85022088-30763
  • fax-no: +86-0571-85022600
  • e-mail: guowei.pangw@alibaba-inc.com
  • nic-hdl: ZM877-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2013-07-09T01:34:02Z
  • route: 120.76.0.0/14
  • descr: Hangzhou Alibaba Advertising Co.,Ltd.
  • country: CN
  • origin: AS37963
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2019-08-06T02:28:03Z
  • route: 120.76.0.0/14
  • descr: Alibaba (US) Technology Co., Ltd.
  • country: CN
  • origin: AS45102
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2019-08-06T02:28:03Z

Links to attack logs

****** ****** ******

Share on: