120.76.107.54 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 120.76.107.54 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Possibly Malicious Host 🟢 15/100

Host and Network Information

  • Country: China
  • Network: AS37963 hangzhou alibaba advertising co. ltd.
  • Noticed: 1 times
  • Protocols Attacked: SSH
  • Passive DNS Results: ns2.hichina.com sdamz.xyz ouhsuil.xyz 1ym.fun dns8.hichina.com dns2.hichina.com dns4.hichina.com

Malware Detected on Host

Count: 1 5be075a818408aec8194fa015e9fe45002336a11ff6cee22da089dbaf02aef93

Open Ports Detected

10000 10001 10134 102 1025 104 10443 10554 1063 10909 10911 1099 11 110 11000 111 11210 11211 113 11300 11371 1153 1167 1177 119 1200 12000 122 1234 12345 13 1311 1337 135 13579 1400 14265 143 1433 14344 15 1500 1515 1521 1599 16010 1604 16992 16993 17 1723 175 179 1800 1801 1820 18245 1883 19 19000 1925 1926 195 1962 1990 2000 20000 2001 2002 2008 2010 20256 2030 2049 20547 2057 2065 2067 2077 2081 2083 2087 21025 2121 21379 2181 2200 221 2211 222 2222 2250 23 23023 2323 2332 2345 2375 2376 24 2404 2443 2455 25001 25105 25565 2561 2562 2563 2569 2628 2701 27015 27017 2761 2762 30002 30003 3001 3050 3051 3053 3077 3085 3088 3097 3100 3101 3103 3104 3105 3107 3118 31337 3260 3268 3269 3270 32764 3299 3301 3306 33060 3307 3310 3388 3389 3402 35000 3541 3542 3551 3556 3569 37 37777 3780 3790 389 4000 4022 4043 4063 4064 4117 4118 4157 41800 4242 4282 43 4321 4369 44158 443 4430 4433 444 4443 44818 4500 4506 4524 4643 4786 47990 4899 49 4949 5000 50000 5001 5005 5006 5007 50070 5009 5010 50100 502 5025 5050 5080 5090 51235 515 5172 5190 5222 5269 53 54138 5432 5435 55000 55443 55553 5569 5591 5609 5672 5822 5858 593 5938 5984 6000 6001 6002 60030 60129 6080 61613 61616 62078 631 636 6443 6511 6561 6633 6653 666 6662 6666 6667 6668 70 7001 7005 7071 7080 7171 7218 7415 7433 7434 7443 7537 7634 771 7779 7887 789 79 80 8001 8009 801 8010 8016 8018 8027 8028 8036 8039 8040 8044 8046 8048 8058 8064 8081 8086 8089 8097 8099 81 8107 8110 8112 8118 8126 8139 8140 8181 8200 8239 8252 8291 8383 8414 8420 8443 8445 8500 8545 8554 8575 8649 8688 8728 873 8790 8804 8805 8833 8834 8857 8862 8866 888 8880 8889 8935 9000 9002 9003 9018 902 9021 9042 9043 9048 9051 9084 9089 9090 9091 9092 9095 9100 9104 9109 9110 9111 9151 9160 9191 9204 9211 9212 9251 9305 9306 9307 9311 9418 9433 9443 9444 9500 9530 96 9600 9633 9682 9743 9761 9869 9876 992 993 9943 995 9966 9981 9992 9998 9999

CVEs Detected

CVE-2007-2768 CVE-2007-3205 CVE-2008-3844 CVE-2010-4478 CVE-2010-4755 CVE-2010-5107 CVE-2011-4327 CVE-2011-5000 CVE-2012-0814 CVE-2013-2220 CVE-2014-1692 CVE-2014-2532 CVE-2014-2653 CVE-2015-5352 CVE-2015-5600 CVE-2015-6563 CVE-2015-6564 CVE-2016-0777 CVE-2016-10009 CVE-2016-10010 CVE-2016-10011 CVE-2016-10012 CVE-2016-10708 CVE-2016-1908 CVE-2016-20012 CVE-2017-15906 CVE-2018-15473 CVE-2018-15919 CVE-2018-20685 CVE-2019-16905 CVE-2019-6109 CVE-2019-6110 CVE-2019-6111 CVE-2020-14145 CVE-2020-15778 CVE-2021-36368 CVE-2021-41617 CVE-2023-38408 CVE-2023-48795 CVE-2023-51384 CVE-2023-51385 CVE-2023-51767

Map

Whois Information

  • inetnum: 120.76.0.0 - 120.79.255.255
  • netname: ALISOFT
  • descr: Aliyun Computing Co., LTD
  • descr: 5F, Builing D, the West Lake International Plaza of S&T
  • descr: No.391 Wen’er Road, Hangzhou, Zhejiang, China, 310099
  • country: CN
  • admin-c: ZM1015-AP
  • tech-c: ZM877-AP
  • tech-c: ZM876-AP
  • tech-c: ZM875-AP
  • abuse-c: AC1601-AP
  • status: ALLOCATED PORTABLE
  • mnt-by: MAINT-CNNIC-AP
  • mnt-irt: IRT-ALISOFT-CN
  • last-modified: 2023-11-28T00:57:00Z
  • irt: IRT-ALISOFT-CN
  • address: No.391 Wen’er Road, Hangzhou, Zhejiang, China, 310099
  • e-mail: didong.jc@alibaba-inc.com
  • abuse-mailbox: didong.jc@alibaba-inc.com
  • admin-c: ZM877-AP
  • tech-c: ZM877-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2021-09-05T23:38:36Z
  • role: ABUSE CNNICCN
  • address: Beijing, China
  • country: ZZ
  • phone: +000000000
  • e-mail: ipas@cnnic.cn
  • admin-c: IP50-AP
  • tech-c: IP50-AP
  • nic-hdl: AC1601-AP
  • abuse-mailbox: ipas@cnnic.cn
  • mnt-by: APNIC-ABUSE
  • last-modified: 2020-05-14T11:19:01Z
  • person: Li Jia
  • address: NO.969 West Wen Yi Road, Yu Hang District, Hangzhou
  • country: CN
  • phone: +86-0571-85022088
  • e-mail: jiali.jl@alibaba-inc.com
  • nic-hdl: ZM1015-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2014-07-30T02:02:01Z
  • person: Guoxin Gao
  • address: 5F, Builing D, the West Lake International Plaza of S&T
  • address: No.391 Wen’er Road, Hangzhou City
  • address: Zhejiang, China, 310099
  • country: CN
  • phone: +86-0571-85022600
  • fax-no: +86-0571-85022600
  • e-mail: anti-spam@list.alibaba-inc.com
  • nic-hdl: ZM875-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2014-07-30T01:56:01Z
  • person: security trouble
  • e-mail: yitian.gaoyt@alibaba-inc.com
  • address: Hangzhou, Zhejiang, China
  • phone: +86-0571-85022600
  • country: CN
  • mnt-by: MAINT-CNNIC-AP
  • nic-hdl: ZM876-AP
  • last-modified: 2021-04-13T23:22:33Z
  • person: Guowei Pan
  • address: 5F, Builing D, the West Lake International Plaza of S&T
  • address: No.391 Wen’er Road, Hangzhou City
  • address: Zhejiang, China, 310099
  • country: CN
  • phone: +86-0571-85022088-30763
  • fax-no: +86-0571-85022600
  • e-mail: guowei.pangw@alibaba-inc.com
  • nic-hdl: ZM877-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2013-07-09T01:34:02Z
  • route: 120.76.0.0/14
  • descr: Hangzhou Alibaba Advertising Co.,Ltd.
  • country: CN
  • origin: AS37963
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2019-08-06T02:28:03Z
  • route: 120.76.0.0/14
  • descr: Alibaba (US) Technology Co., Ltd.
  • country: CN
  • origin: AS45102
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2019-08-06T02:28:03Z

Links to attack logs

****** ****** ******

Share on: