139.224.142.107 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 139.224.142.107 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Possibly Malicious Host 🟢 15/100

Host and Network Information

  • Country: China
  • Network: AS37963 hangzhou alibaba advertising co. ltd.
  • Noticed: 1 times
  • Protocols Attacked: SSH
  • Passive DNS Results: yuanmashidai.top qxy666.top lhdaliyun.xyz e-teckoffer.net testpapers.fun luckdog.tech ixmmm.com dollss.xyz qianxunmc.online boldstern.net g.llll.vc dns28.hichina.com dns30.hichina.com dns26.hichina.com dns32.hichina.com

Open Ports Detected

100 10000 10001 102 1023 1025 10250 10344 10443 10554 10909 110 11000 111 1111 11112 11210 113 11300 11371 1153 1177 119 1200 1234 12345 1250 13 1311 13443 135 1400 14265 143 1433 14344 15 1515 1521 1599 16010 16030 16992 16993 17 1723 175 179 1800 1801 18081 18245 19000 1911 1925 1926 1935 195 2000 20000 2002 2003 2006 2008 2020 20547 2061 2063 2067 2068 2083 2087 21025 2121 2122 21379 2154 2181 22021 2211 2222 2223 2250 23 23023 2323 2332 2352 2375 2376 2404 2455 25 25001 2554 25565 2566 26 264 27015 27017 2761 2762 28015 28017 2806 28080 30002 30003 3001 3049 3055 3057 3070 3072 3085 3086 3103 3107 311 3114 31337 32400 3260 3269 32764 3299 3306 33060 3310 3388 340 3405 35000 3541 3542 3551 3558 35780 37 37777 3780 3790 3791 389 3951 4000 4022 4064 4117 4157 427 4282 43 4321 4369 44158 4433 444 4443 4444 4445 44818 449 4500 4506 4545 465 47463 4747 47990 4840 4899 49 49153 4949 50000 5001 5007 5009 5010 50100 5025 503 5080 515 5190 5201 5222 5269 53 54138 5435 5446 548 55000 554 55443 55553 55554 5560 5569 5592 5599 5603 5672 5673 5801 5858 587 5910 5984 5986 6000 60001 6001 6002 60030 6008 60129 6036 6161 61613 61616 62078 6264 6308 636 6443 646 6503 6511 6512 6561 6602 6633 666 6666 6667 6668 6697 70 7001 7081 7171 7218 7415 7434 7443 7634 7657 771 772 7776 789 79 7979 7998 8001 8003 8009 8013 8014 8015 8017 8040 8047 8050 8052 8056 8083 8085 8086 8090 8095 8099 81 8103 8109 8123 8139 8140 8182 8200 8222 8241 8251 8291 830 8334 8405 8416 8420 8433 8443 8444 8447 8545 8554 8575 8649 8728 873 8811 8812 8816 8826 8828 8842 8853 8856 8874 8880 8885 8888 8889 8891 8969 9000 9003 9004 9011 902 9042 9051 9091 9092 9095 9098 9100 9107 9151 9160 9200 9203 9209 9221 9302 9303 9308 9389 9418 9443 95 9530 9595 9600 9633 9761 9876 992 993 9943 995 9981 9997 9998 9999

CVEs Detected

CVE-2007-2768 CVE-2008-3844 CVE-2010-4478 CVE-2010-4755 CVE-2010-5107 CVE-2011-4327 CVE-2011-5000 CVE-2012-0814 CVE-2014-1692 CVE-2014-2532 CVE-2014-2653 CVE-2015-5352 CVE-2015-5600 CVE-2015-6563 CVE-2015-6564 CVE-2016-0777 CVE-2016-10009 CVE-2016-10010 CVE-2016-10011 CVE-2016-10012 CVE-2016-10708 CVE-2016-1908 CVE-2016-20012 CVE-2016-3115 CVE-2017-15906 CVE-2018-15473 CVE-2018-15919 CVE-2018-20685 CVE-2019-16905 CVE-2019-6109 CVE-2019-6110 CVE-2019-6111 CVE-2020-14145 CVE-2020-15778 CVE-2021-36368 CVE-2021-41617 CVE-2023-38408 CVE-2023-48795 CVE-2023-51384 CVE-2023-51385 CVE-2023-51767

Map

Whois Information

  • NetRange: 139.224.0.0 - 139.224.255.255
  • CIDR: 139.224.0.0/16
  • NetName: APNIC-ERX-139-224-0-0
  • NetHandle: NET-139-224-0-0-1
  • Parent: NET139 (NET-139-0-0-0-0)
  • NetType: Early Registrations, Transferred to APNIC
  • OriginAS:
  • Organization: Asia Pacific Network Information Centre (APNIC)
  • RegDate: 2010-11-03
  • Updated: 2010-11-17
  • Comment: This IP address range is not registered in the ARIN database.
  • Comment: This range was transferred to the APNIC Whois Database as
  • Comment: part of the ERX (Early Registration Transfer) project.
  • Comment: For details, refer to the APNIC Whois Database via
  • Comment:
  • Comment: ** IMPORTANT NOTE: APNIC is the Regional Internet Registry
  • Comment: for the Asia Pacific region. APNIC does not operate networks
  • Comment: using this IP address range and is not able to investigate
  • Comment: spam or abuse reports relating to these addresses. For more
  • Ref: https://rdap.arin.net/registry/ip/139.224.0.0
  • OrgName: Asia Pacific Network Information Centre
  • OrgId: APNIC
  • Address: PO Box 3646
  • City: South Brisbane
  • StateProv: QLD
  • PostalCode: 4101
  • Country: AU
  • RegDate:
  • Updated: 2012-01-24
  • Ref: https://rdap.arin.net/registry/entity/APNIC
  • OrgTechHandle: AWC12-ARIN
  • OrgTechName: APNIC Whois Contact
  • OrgTechPhone: +61 7 3858 3188
  • OrgTechEmail: search-apnic-not-arin@apnic.net
  • OrgTechRef: https://rdap.arin.net/registry/entity/AWC12-ARIN
  • OrgAbuseHandle: AWC12-ARIN
  • OrgAbuseName: APNIC Whois Contact
  • OrgAbusePhone: +61 7 3858 3188
  • OrgAbuseEmail: search-apnic-not-arin@apnic.net
  • OrgAbuseRef: https://rdap.arin.net/registry/entity/AWC12-ARIN
  • inetnum: 139.224.0.0 - 139.224.255.255
  • netname: ALISOFT
  • descr: Aliyun Computing Co., LTD
  • descr: 5F, Builing D, the West Lake International Plaza of S&T
  • descr: No.391 Wen’er Road, Hangzhou, Zhejiang, China, 310099
  • country: CN
  • admin-c: ZM1015-AP
  • tech-c: ZM877-AP
  • tech-c: ZM876-AP
  • tech-c: ZM875-AP
  • abuse-c: AC1601-AP
  • status: ALLOCATED PORTABLE
  • mnt-by: MAINT-CNNIC-AP
  • mnt-irt: IRT-ALISOFT-CN
  • last-modified: 2023-11-28T00:57:06Z
  • irt: IRT-ALISOFT-CN
  • address: No.391 Wen’er Road, Hangzhou, Zhejiang, China, 310099
  • e-mail: didong.jc@alibaba-inc.com
  • abuse-mailbox: didong.jc@alibaba-inc.com
  • admin-c: ZM877-AP
  • tech-c: ZM877-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2021-09-05T23:38:36Z
  • role: ABUSE CNNICCN
  • address: Beijing, China
  • country: ZZ
  • phone: +000000000
  • e-mail: ipas@cnnic.cn
  • admin-c: IP50-AP
  • tech-c: IP50-AP
  • nic-hdl: AC1601-AP
  • abuse-mailbox: ipas@cnnic.cn
  • mnt-by: APNIC-ABUSE
  • last-modified: 2020-05-14T11:19:01Z
  • person: Li Jia
  • address: NO.969 West Wen Yi Road, Yu Hang District, Hangzhou
  • country: CN
  • phone: +86-0571-85022088
  • e-mail: jiali.jl@alibaba-inc.com
  • nic-hdl: ZM1015-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2014-07-30T02:02:01Z
  • person: Guoxin Gao
  • address: 5F, Builing D, the West Lake International Plaza of S&T
  • address: No.391 Wen’er Road, Hangzhou City
  • address: Zhejiang, China, 310099
  • country: CN
  • phone: +86-0571-85022600
  • fax-no: +86-0571-85022600
  • e-mail: anti-spam@list.alibaba-inc.com
  • nic-hdl: ZM875-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2014-07-30T01:56:01Z
  • person: security trouble
  • e-mail: yitian.gaoyt@alibaba-inc.com
  • address: Hangzhou, Zhejiang, China
  • phone: +86-0571-85022600
  • country: CN
  • mnt-by: MAINT-CNNIC-AP
  • nic-hdl: ZM876-AP
  • last-modified: 2021-04-13T23:22:33Z
  • person: Guowei Pan
  • address: 5F, Builing D, the West Lake International Plaza of S&T
  • address: No.391 Wen’er Road, Hangzhou City
  • address: Zhejiang, China, 310099
  • country: CN
  • phone: +86-0571-85022088-30763
  • fax-no: +86-0571-85022600
  • e-mail: guowei.pangw@alibaba-inc.com
  • nic-hdl: ZM877-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2013-07-09T01:34:02Z
  • route: 139.224.142.0/24
  • origin: AS37963
  • descr: China Internet Network Information Center
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2020-02-18T01:31:57Z
  • route: 139.224.142.0/24
  • origin: AS45102
  • descr: China Internet Network Information Center
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2020-02-18T01:33:17Z

Links to attack logs

****** ****** ******

Share on: