120.76.107.56 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 120.76.107.56 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Possibly Malicious Host 🟢 15/100

Host and Network Information

  • Country: China
  • Network: AS37963 hangzhou alibaba advertising co. ltd.
  • Noticed: 1 times
  • Protocols Attacked: SSH
  • Passive DNS Results: idei.cf www.lolka.cc api.sizegene.com ns2.alidns.com

Open Ports Detected

10000 10001 10081 10134 102 1023 1025 1028 104 10443 1050 10554 1063 10909 10911 1099 11 11000 111 11210 11211 113 1153 1177 119 1200 12000 122 1234 12345 1250 1290 13 1322 1337 135 13579 14147 14265 143 1433 14344 1471 1515 1599 16010 16030 1604 16992 16993 17 175 179 1800 1801 18081 1883 19 19000 19071 1911 1926 1947 195 1962 2000 20000 2002 2008 20256 2030 2052 2057 2059 2063 2067 2068 2081 2083 2096 21 21025 2121 21379 2150 2154 2181 22 221 2222 225 2266 23 23023 2323 2332 23424 2345 2351 2352 2376 2404 2455 2480 25 25001 2548 2549 2550 2553 25565 2628 264 27015 27017 2709 2762 28015 2806 2985 30002 30003 3001 3050 3053 3054 3068 3076 3083 3094 3099 311 3117 3118 3120 31337 32400 3260 3268 3269 32764 3299 3301 3306 33060 3388 3389 3400 3402 3412 35000 3551 3559 3560 3561 3566 35771 3689 3690 37 37215 3780 3790 3793 38 389 3951 3952 3953 4000 4063 4157 41800 427 4282 43 4369 44158 443 4430 4433 444 4443 44818 4500 4505 4506 4545 465 47463 4747 4786 47990 4840 4899 49 4911 49152 4949 50000 5001 5005 5006 5007 50070 5009 5010 50100 502 5025 503 51 51235 515 5172 5222 5269 52869 53 5435 5446 548 55000 5542 55443 555 55553 55554 5596 5602 5672 5673 5858 5900 5907 5938 5984 5986 6000 6001 60010 6002 6006 60129 6080 61613 636 6379 6443 6603 6633 6653 666 6666 6668 6697 685 70 7001 7071 7218 7415 7434 7443 7474 7537 7547 7548 7634 7657 7700 771 777 7776 7779 7788 789 79 7979 80 8001 8007 8009 8011 8029 8032 8037 8038 8044 8051 8052 8054 8069 8081 8083 8085 8087 8088 8089 8090 8095 8099 8100 8108 8118 8123 8139 8140 8181 8190 8200 8241 8251 8291 83 8333 84 8408 8411 8418 8429 8430 8442 8443 8500 8545 8554 8586 8622 8649 8728 873 8766 8767 8779 8803 8816 8825 8834 8846 8851 8853 8862 8869 8880 8885 8889 8899 9001 9002 9008 9012 9018 902 9023 9032 9041 9042 9051 9070 9084 9091 9092 9095 9097 9100 9102 9151 9160 9216 9220 9221 9306 9309 9418 9443 9445 9530 9600 9633 9663 9761 9876 99 992 993 9943 995 9981 9992 9998 9999

CVEs Detected

CVE-2007-2768 CVE-2008-3844 CVE-2010-4478 CVE-2010-4755 CVE-2010-5107 CVE-2011-4327 CVE-2011-5000 CVE-2012-0814 CVE-2014-1692 CVE-2014-2532 CVE-2014-2653 CVE-2015-5352 CVE-2015-5600 CVE-2015-6563 CVE-2015-6564 CVE-2016-0777 CVE-2016-10009 CVE-2016-10010 CVE-2016-10011 CVE-2016-10012 CVE-2016-10708 CVE-2016-1908 CVE-2016-20012 CVE-2016-3115 CVE-2017-15906 CVE-2018-10088 CVE-2018-15473 CVE-2018-15919 CVE-2018-20685 CVE-2019-16905 CVE-2019-6109 CVE-2019-6110 CVE-2019-6111 CVE-2020-14145 CVE-2020-15778 CVE-2021-36368 CVE-2021-41617 CVE-2023-38408 CVE-2023-48795 CVE-2023-51384 CVE-2023-51385 CVE-2023-51767

Map

Whois Information

  • inetnum: 120.76.0.0 - 120.79.255.255
  • netname: ALISOFT
  • descr: Aliyun Computing Co., LTD
  • descr: 5F, Builing D, the West Lake International Plaza of S&T
  • descr: No.391 Wen’er Road, Hangzhou, Zhejiang, China, 310099
  • country: CN
  • admin-c: ZM1015-AP
  • tech-c: ZM877-AP
  • tech-c: ZM876-AP
  • tech-c: ZM875-AP
  • abuse-c: AC1601-AP
  • status: ALLOCATED PORTABLE
  • mnt-by: MAINT-CNNIC-AP
  • mnt-irt: IRT-ALISOFT-CN
  • last-modified: 2023-11-28T00:57:00Z
  • irt: IRT-ALISOFT-CN
  • address: No.391 Wen’er Road, Hangzhou, Zhejiang, China, 310099
  • e-mail: didong.jc@alibaba-inc.com
  • abuse-mailbox: didong.jc@alibaba-inc.com
  • admin-c: ZM877-AP
  • tech-c: ZM877-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2021-09-05T23:38:36Z
  • role: ABUSE CNNICCN
  • address: Beijing, China
  • country: ZZ
  • phone: +000000000
  • e-mail: ipas@cnnic.cn
  • admin-c: IP50-AP
  • tech-c: IP50-AP
  • nic-hdl: AC1601-AP
  • abuse-mailbox: ipas@cnnic.cn
  • mnt-by: APNIC-ABUSE
  • last-modified: 2020-05-14T11:19:01Z
  • person: Li Jia
  • address: NO.969 West Wen Yi Road, Yu Hang District, Hangzhou
  • country: CN
  • phone: +86-0571-85022088
  • e-mail: jiali.jl@alibaba-inc.com
  • nic-hdl: ZM1015-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2014-07-30T02:02:01Z
  • person: Guoxin Gao
  • address: 5F, Builing D, the West Lake International Plaza of S&T
  • address: No.391 Wen’er Road, Hangzhou City
  • address: Zhejiang, China, 310099
  • country: CN
  • phone: +86-0571-85022600
  • fax-no: +86-0571-85022600
  • e-mail: anti-spam@list.alibaba-inc.com
  • nic-hdl: ZM875-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2014-07-30T01:56:01Z
  • person: security trouble
  • e-mail: yitian.gaoyt@alibaba-inc.com
  • address: Hangzhou, Zhejiang, China
  • phone: +86-0571-85022600
  • country: CN
  • mnt-by: MAINT-CNNIC-AP
  • nic-hdl: ZM876-AP
  • last-modified: 2021-04-13T23:22:33Z
  • person: Guowei Pan
  • address: 5F, Builing D, the West Lake International Plaza of S&T
  • address: No.391 Wen’er Road, Hangzhou City
  • address: Zhejiang, China, 310099
  • country: CN
  • phone: +86-0571-85022088-30763
  • fax-no: +86-0571-85022600
  • e-mail: guowei.pangw@alibaba-inc.com
  • nic-hdl: ZM877-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2013-07-09T01:34:02Z
  • route: 120.76.0.0/14
  • descr: Hangzhou Alibaba Advertising Co.,Ltd.
  • country: CN
  • origin: AS37963
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2019-08-06T02:28:03Z
  • route: 120.76.0.0/14
  • descr: Alibaba (US) Technology Co., Ltd.
  • country: CN
  • origin: AS45102
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2019-08-06T02:28:03Z

Links to attack logs

****** ****** ******

Share on: