120.76.107.61 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 120.76.107.61 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Possibly Malicious Host 🟢 15/100

Host and Network Information

  • Country: China
  • Network: AS37963 hangzhou alibaba advertising co. ltd.
  • Noticed: 1 times
  • Protocols Attacked: SSH
  • Passive DNS Results: wylan.online x6seo.com xn–6krs3k3x4bmyl.com family112.com 80yxwl.com www.xqc-papergoods.com shuotao.shop hercules1115.fun dns22.hichina.com www.gooseller.com fiftyad.com lihuan9527.ltd dns18.hichina.com anwall.com.cn dns24.hichina.com hpsytz.com dns20.hichina.com

Open Ports Detected

10000 10001 10134 102 1025 1026 104 10443 1080 10911 1099 11 11000 111 11112 11210 11211 113 11300 1153 1177 119 1200 12000 12345 13 1322 1337 135 139 14147 143 1433 14344 1515 1521 1599 1604 16992 16993 17 1723 180 1800 1801 18081 18245 1883 19000 1911 1926 195 1962 1981 2000 20000 2008 2012 2053 2057 2058 2065 2067 2081 2082 2083 2087 21 21025 211 2121 21379 2154 2181 222 2220 2221 2222 2223 2232 225 23 23023 2320 2323 2332 2345 2375 2376 2404 2443 2455 25 25001 25565 2557 2563 263 264 2650 27015 27017 2761 2762 28015 28017 30002 3050 3061 3067 3076 311 3117 31337 3221 32400 3260 3268 32764 3299 3301 3306 33060 3310 3443 35000 3549 3550 3551 3552 3554 3566 3689 3690 37 3749 37777 3790 389 4000 4010 4042 4063 4064 4100 4157 41800 4200 4242 4282 43 4321 4369 44158 443 4430 444 4443 44818 449 450 4500 4506 465 4664 4782 4786 47990 4840 4848 4899 49 4911 49152 4949 4999 50000 5001 5006 5007 50070 5009 5010 50100 502 5025 503 5070 515 5172 5201 5222 5269 53 541 5432 5435 548 55000 554 55442 55443 55554 5560 5598 5602 5603 5609 5672 5673 5858 5900 593 5938 5984 6000 6001 6002 6003 6005 6006 6007 60129 61613 61616 62078 631 6352 636 6379 6443 6601 6605 6653 6666 6668 6697 6748 6955 70 7001 7002 7071 7171 7218 7415 7434 7443 7537 7547 7548 7634 771 777 7779 789 79 8001 8007 8009 8010 8039 8041 8051 8064 8081 8087 8089 8090 8092 8097 8099 8104 8109 8112 8123 8126 8139 8143 8181 8200 8238 8239 8252 8291 83 8333 8334 84 8421 8428 8443 8500 8513 8554 8575 8622 8623 8686 8700 873 8733 8767 8779 8788 8790 8791 8804 8807 8809 8827 8834 8838 8844 8857 8861 8867 8869 888 8880 8889 8899 8999 9000 9001 9002 9004 9017 9041 9051 9070 9091 9095 9100 9101 9102 9160 9191 9201 9208 9209 9212 9219 9221 9222 9306 9418 9443 9530 9600 9633 9743 9761 9861 9869 9899 992 9943 9955 9981 9998 9999

CVEs Detected

CVE-2007-2768 CVE-2008-3844 CVE-2010-4478 CVE-2010-4755 CVE-2010-5107 CVE-2011-4327 CVE-2011-5000 CVE-2012-0814 CVE-2014-1692 CVE-2014-2532 CVE-2014-2653 CVE-2015-5352 CVE-2015-5600 CVE-2015-6563 CVE-2015-6564 CVE-2016-0777 CVE-2016-10009 CVE-2016-10010 CVE-2016-10011 CVE-2016-10012 CVE-2016-10708 CVE-2016-1908 CVE-2016-20012 CVE-2016-3115 CVE-2017-15906 CVE-2018-15473 CVE-2018-15919 CVE-2018-20685 CVE-2019-6109 CVE-2019-6110 CVE-2019-6111 CVE-2020-14145 CVE-2020-15778 CVE-2021-36368 CVE-2021-41617 CVE-2023-38408 CVE-2023-48795 CVE-2023-51384 CVE-2023-51385 CVE-2023-51767

Map

Whois Information

  • inetnum: 120.76.0.0 - 120.79.255.255
  • netname: ALISOFT
  • descr: Aliyun Computing Co., LTD
  • descr: 5F, Builing D, the West Lake International Plaza of S&T
  • descr: No.391 Wen’er Road, Hangzhou, Zhejiang, China, 310099
  • country: CN
  • admin-c: ZM1015-AP
  • tech-c: ZM877-AP
  • tech-c: ZM876-AP
  • tech-c: ZM875-AP
  • abuse-c: AC1601-AP
  • status: ALLOCATED PORTABLE
  • mnt-by: MAINT-CNNIC-AP
  • mnt-irt: IRT-ALISOFT-CN
  • last-modified: 2023-11-28T00:57:00Z
  • irt: IRT-ALISOFT-CN
  • address: No.391 Wen’er Road, Hangzhou, Zhejiang, China, 310099
  • e-mail: didong.jc@alibaba-inc.com
  • abuse-mailbox: didong.jc@alibaba-inc.com
  • admin-c: ZM877-AP
  • tech-c: ZM877-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2021-09-05T23:38:36Z
  • role: ABUSE CNNICCN
  • address: Beijing, China
  • country: ZZ
  • phone: +000000000
  • e-mail: ipas@cnnic.cn
  • admin-c: IP50-AP
  • tech-c: IP50-AP
  • nic-hdl: AC1601-AP
  • abuse-mailbox: ipas@cnnic.cn
  • mnt-by: APNIC-ABUSE
  • last-modified: 2020-05-14T11:19:01Z
  • person: Li Jia
  • address: NO.969 West Wen Yi Road, Yu Hang District, Hangzhou
  • country: CN
  • phone: +86-0571-85022088
  • e-mail: jiali.jl@alibaba-inc.com
  • nic-hdl: ZM1015-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2014-07-30T02:02:01Z
  • person: Guoxin Gao
  • address: 5F, Builing D, the West Lake International Plaza of S&T
  • address: No.391 Wen’er Road, Hangzhou City
  • address: Zhejiang, China, 310099
  • country: CN
  • phone: +86-0571-85022600
  • fax-no: +86-0571-85022600
  • e-mail: anti-spam@list.alibaba-inc.com
  • nic-hdl: ZM875-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2014-07-30T01:56:01Z
  • person: security trouble
  • e-mail: yitian.gaoyt@alibaba-inc.com
  • address: Hangzhou, Zhejiang, China
  • phone: +86-0571-85022600
  • country: CN
  • mnt-by: MAINT-CNNIC-AP
  • nic-hdl: ZM876-AP
  • last-modified: 2021-04-13T23:22:33Z
  • person: Guowei Pan
  • address: 5F, Builing D, the West Lake International Plaza of S&T
  • address: No.391 Wen’er Road, Hangzhou City
  • address: Zhejiang, China, 310099
  • country: CN
  • phone: +86-0571-85022088-30763
  • fax-no: +86-0571-85022600
  • e-mail: guowei.pangw@alibaba-inc.com
  • nic-hdl: ZM877-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2013-07-09T01:34:02Z
  • route: 120.76.0.0/14
  • descr: Hangzhou Alibaba Advertising Co.,Ltd.
  • country: CN
  • origin: AS37963
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2019-08-06T02:28:03Z
  • route: 120.76.0.0/14
  • descr: Alibaba (US) Technology Co., Ltd.
  • country: CN
  • origin: AS45102
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2019-08-06T02:28:03Z

Links to attack logs

****** ****** ******

Share on: