140.205.60.46 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 140.205.60.46 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Potentially Malicious Host 🟡 42/100

Host and Network Information

  • Mitre ATT&CK IDs: T1059 - Command and Scripting Interpreter

  • Tags: 0x104, 0x11a, 0x12b, 0x14a, 0x14e, 0x228, 0x97, 0xc6, 0xe1, 0xf5, aafunction, afunction, android, april, array, array int8array, b1342177279, bad event, bad idp, child, class, closure library, cnzzdata, copyright, crios, customevent, czuuid, dafunction, date, edge, element, embed, error, fafafa, function, gc, gc3w7t6h5qw, gtmmdcvhgd, ienew ca, iframe, internal, invalid attempt, kafunction, kfunction, kkfunction, lh, meta, mit license, most, nkfunction, node, null, number, object, overlaylevel, p420, path, pseudo, public, qkfunction, quota, reduceright, regexp, rkfunction, sdkversion, skfunction, span, string, swiper, sxa0, symbol, template, this, trackevent, trackpageview, trident, typeerror, typeof, typeof b, typeof d, typeof define, typeof e, typeof enulle, typeof n, typeof r, typeof symbol, typeof t, ufunction, uint8array, umdistinctid, vd, version, void, win32, xlfunction, zdhxiong

  • View other sources: Spamhaus VirusTotal

  • Country: China
  • Network: AS37963 hangzhou alibaba advertising co. ltd.
  • Noticed: 1 times
  • Protocols Attacked: SSH
  • Passive DNS Results: hbucm.com maxim-automation.top ceshi2024.xyz hcucumber.top lishujin.love yinghuangyl8.com btrmaketi.com 3modi.com aliyun-adns.aliyun.com.vipgds.alibabadns.com aiis.tech aiis.love domainapi.aliyun.com careers.aliyun.com guru55.xyz fydch.com xn–8mrq2kk1b82dyt3ckdm.site hi-pwc.online chenglong.fun xingjihao.com zhjy2567.xyz gzklovezxp.xyz hfgj2008.top 78su.com dccam.xyz gzyzqt.top samsamgiftshop.com zyj511223.top viptbsc.com 1688tbsc.xyz hfgj2016.top xzw.life timnuoo.com imtoken2016.us xggj2012.top ai.aliyun.com 1688tbsc.shop xggj2012.us auth.o9q.cn alimail-sg.aliyuncs.com alimail-personal.aliyuncs.com 002243.com exmail.aliyun.com msea.aliyun.com tvka.cn ynding.fun alibaba-tam.com aliyun-ltd.com beian.aliyun.com www.junnp03.xyz mailsso.aliyun.com mailhelp.aliyun.com yunqi.aliyun.com ucc.aliyun.com beian.gein.cn ba.gein.cn www.95bok.cn acentric.eu.org ht0428.xmcm168.com m.xmcm168.com mailopen-netdisk.aliyun.com yunmall.aliyun.com www.misaya.ltd kdai.net 912889.com fuliyun.net appjun.com denglijunying.top cschat-ccs.aliyun.com aliyunk.top alicloudemea.com lengqie.live dgaddr.com aiyufeifei.com 330618.com tools.aliyun.com domain.aliyun.com aliyun.it help-ccs.aliyun.com microdingtalk.aliyun.com pandavip.www.net.cn console.aliyun.com dns.www.net.cn dmp.www.net.cn bridge.aliyun.com aicrowd.aliyun.com dc.www.net.cn account.www.net.cn panda.www.net.cn feedback.console.aliyun.com api.aliyun.com huijiadizhi.xyz easn.yishutech.cn zehr.yishutech.cn hi8m.yishutech.cn aliyun-adns.aliyun.com.gds.alibabadns.com aliyun.com bbs.aliyun.com

Malware Detected on Host

Count: 14 4ca123c419c07e12ad646842f8cede08501c676a888f4b5c5d107c012f2a6a52 10e60890bb94ac217937cb5505864244fff275539f3047b8c6c84ecf61cc8324 720f1cdf3749f6232c908b4fd6ea1b085884bb270cdaa5dd5f98dc317c095101 56ae1a00a80653bace99a859e1c1f5c25623607012736a9c0bcb6ab02007cc1c d38550cc6e10551904d25dc9768437574b748aefb253bbfdec26ccf6aae32da6 6ece4917562ddd9492333854f2ba73dad6db79454150662ef41a4481939c30a8 85d0a99a00dd35b0f2598d6be440f4a9dcadf57ec856203c9e86e6b55dd5f390 1dd44909f863aa5af7206f94c8f8b21140472358a73108eb591498b2e98757b6 2b02a5b7f675de3af4068755f902563aa7b18e3d8f9e1c0f234c35538919e852 d97bfa301bbfe04c9d2c72f351b14e2d0721aaec8b69202d10c59a995fd01eb1

Open Ports Detected

10000 10001 10134 102 1023 1024 1025 10250 1027 10344 104 10443 1050 10554 1063 1099 11 110 11000 111 11112 11210 11211 113 11300 11371 11434 1153 1177 119 1200 12000 122 1234 13 1311 1337 13443 135 13579 1400 14147 14265 143 1433 14344 1471 15 1500 1515 1521 1599 1604 16992 16993 17 17000 1723 1741 175 179 180 1800 1801 18081 18245 1883 19 19000 19071 1911 1925 1926 195 1962 20 2000 20000 2002 2006 2012 2021 20256 20547 2061 2067 2081 2082 2083 2086 2087 2096 21 21025 211 2121 21379 2154 2181 221 2222 2232 22443 23 23023 2323 2332 23424 2345 2375 2376 24 2404 2455 2480 25 25001 2506 25105 25565 2557 2558 2572 26 2601 2628 264 2701 27015 27017 2761 2762 28015 28017 28080 30002 30003 3001 3049 3050 3054 3055 3058 3066 3073 3076 3079 3081 3082 3084 3086 3093 3103 311 3111 3121 31337 32400 3260 3268 3269 32764 3299 3301 3306 33060 3310 3388 3389 35000 3541 3542 3548 3549 3551 3568 3689 37 37215 37777 3780 3790 38 389 3922 3954 4000 4022 4040 4063 4064 4118 4157 41800 4242 427 4282 43 4321 4369 44158 443 4430 4433 444 4443 4444 44818 4500 4506 4646 465 4664 4782 47990 4840 4899 49 491 4911 49152 49153 4949 5000 50000 5001 5005 5006 5007 50070 5009 5010 50100 502 5025 503 51106 51235 515 5172 5201 5209 5222 5269 5280 53 54138 5432 5435 5454 548 5494 55000 554 5542 55442 55443 55553 55554 5560 5590 5599 5601 5672 5801 5858 5900 5908 593 5938 5984 5985 5986 6000 60001 6001 60010 6002 6003 60030 6004 60129 6036 6080 6161 61613 61616 62078 6308 631 636 6379 6443 6464 6550 6581 6588 6590 6601 6633 6653 666 6664 6666 6667 6668 6697 685 70 7001 7070 7071 7080 7170 7171 7218 7443 7465 7474 7547 7548 7634 7657 771 7779 789 79 7989 80 8001 8009 801 8010 8014 8016 8025 8038 8039 8040 8048 8060 8069 8080 8081 8083 8085 8086 8087 8089 8090 8094 8098 8099 81 8111 8112 8123 8126 8139 8140 8181 82 8200 8241 8282 8291 83 8333 8334 84 8403 8407 8426 8443 8444 8500 8545 8553 8554 8575 8649 8728 873 8779 8782 8790 8812 8817 8831 8834 8836 8844 8848 8866 8871 8873 8880 8881 8889 8989 8990 8991 9000 9001 9002 9019 9032 9042 9043 9046 9051 9070 9084 9090 9091 9092 9095 9099 9100 9101 9110 9151 9160 9191 9200 9211 9214 9295 9300 9306 9389 9418 9443 9530 9595 9600 9633 9682 9690 9761 9800 9869 9876 992 993 9943 9944 995 9981 9998 9999

CVEs Detected

CVE-2007-2768 CVE-2007-3205 CVE-2008-3844 CVE-2013-2220 CVE-2016-20012 CVE-2017-15906 CVE-2017-8923 CVE-2018-15473 CVE-2018-15919 CVE-2018-20685 CVE-2019-16905 CVE-2019-6109 CVE-2019-6110 CVE-2019-6111 CVE-2020-14145 CVE-2020-15778 CVE-2021-21703 CVE-2021-21704 CVE-2021-21705 CVE-2021-21706 CVE-2021-21707 CVE-2021-36368 CVE-2021-41617 CVE-2022-31628 CVE-2022-31629 CVE-2022-37454 CVE-2023-38408 CVE-2023-48795 CVE-2023-51384 CVE-2023-51385 CVE-2023-51767

Map

Whois Information

  • NetRange: 140.205.0.0 - 140.205.255.255
  • CIDR: 140.205.0.0/16
  • NetName: APNIC-ERX-140-205-0-0
  • NetHandle: NET-140-205-0-0-1
  • Parent: NET140 (NET-140-0-0-0-0)
  • NetType: Early Registrations, Transferred to APNIC
  • OriginAS:
  • Organization: Asia Pacific Network Information Centre (APNIC)
  • RegDate: 2010-11-03
  • Updated: 2010-11-17
  • Comment: This IP address range is not registered in the ARIN database.
  • Comment: This range was transferred to the APNIC Whois Database as
  • Comment: part of the ERX (Early Registration Transfer) project.
  • Comment: For details, refer to the APNIC Whois Database via
  • Comment:
  • Comment: ** IMPORTANT NOTE: APNIC is the Regional Internet Registry
  • Comment: for the Asia Pacific region. APNIC does not operate networks
  • Comment: using this IP address range and is not able to investigate
  • Comment: spam or abuse reports relating to these addresses. For more
  • Ref: https://rdap.arin.net/registry/ip/140.205.0.0
  • OrgName: Asia Pacific Network Information Centre
  • OrgId: APNIC
  • Address: PO Box 3646
  • City: South Brisbane
  • StateProv: QLD
  • PostalCode: 4101
  • Country: AU
  • RegDate:
  • Updated: 2012-01-24
  • Ref: https://rdap.arin.net/registry/entity/APNIC
  • OrgAbuseHandle: AWC12-ARIN
  • OrgAbuseName: APNIC Whois Contact
  • OrgAbusePhone: +61 7 3858 3188
  • OrgAbuseEmail: search-apnic-not-arin@apnic.net
  • OrgAbuseRef: https://rdap.arin.net/registry/entity/AWC12-ARIN
  • OrgTechHandle: AWC12-ARIN
  • OrgTechName: APNIC Whois Contact
  • OrgTechPhone: +61 7 3858 3188
  • OrgTechEmail: search-apnic-not-arin@apnic.net
  • OrgTechRef: https://rdap.arin.net/registry/entity/AWC12-ARIN
  • inetnum: 140.205.0.0 - 140.205.255.255
  • netname: Taobao
  • descr: Zhejiang Taobao Network Co.,Ltd
  • descr: 2nd floor, Westlake International technology Building
  • descr: 391Wener Road, Hangzhou, China
  • country: CN
  • admin-c: ZM678-AP
  • tech-c: ZM877-AP
  • tech-c: ZM876-AP
  • abuse-c: AC1601-AP
  • status: ALLOCATED PORTABLE
  • mnt-by: MAINT-CNNIC-AP
  • mnt-irt: IRT-TAOBAO-CN
  • mnt-lower: MAINT-CNNIC-AP
  • mnt-routes: MAINT-CNNIC-AP
  • last-modified: 2023-11-28T00:57:06Z
  • irt: IRT-Taobao-CN
  • address: 2nd floor, Westlake International technology Building, 391 Wener Road, Hangzhou
  • e-mail: didong.jc@alibaba-inc.com
  • abuse-mailbox: didong.jc@alibaba-inc.com
  • admin-c: ZM877-AP
  • tech-c: ZM877-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2021-09-05T23:38:36Z
  • role: ABUSE CNNICCN
  • address: Beijing, China
  • country: ZZ
  • phone: +000000000
  • e-mail: ipas@cnnic.cn
  • admin-c: IP50-AP
  • tech-c: IP50-AP
  • nic-hdl: AC1601-AP
  • abuse-mailbox: ipas@cnnic.cn
  • mnt-by: APNIC-ABUSE
  • last-modified: 2020-05-14T11:19:01Z
  • person: Shuo Yu
  • address: 5F, Builing D, the West Lake International Plaza of S&T
  • address: No.391 Wen’er Road, Hangzhou City
  • address: Zhejiang, China, 310099
  • country: CN
  • phone: +86-0571-85022600
  • e-mail: anti-spam@list.alibaba-inc.com
  • nic-hdl: ZM678-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2021-04-13T23:21:57Z
  • person: security trouble
  • e-mail: yitian.gaoyt@alibaba-inc.com
  • address: Hangzhou, Zhejiang, China
  • phone: +86-0571-85022600
  • country: CN
  • mnt-by: MAINT-CNNIC-AP
  • nic-hdl: ZM876-AP
  • last-modified: 2021-04-13T23:22:33Z
  • person: Guowei Pan
  • address: 5F, Builing D, the West Lake International Plaza of S&T
  • address: No.391 Wen’er Road, Hangzhou City
  • address: Zhejiang, China, 310099
  • country: CN
  • phone: +86-0571-85022088-30763
  • fax-no: +86-0571-85022600
  • e-mail: guowei.pangw@alibaba-inc.com
  • nic-hdl: ZM877-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2013-07-09T01:34:02Z
  • route: 140.205.60.0/24
  • origin: AS37963
  • descr: China Internet Network Information Center
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2020-02-18T01:10:21Z
  • route: 140.205.60.0/24
  • origin: AS45102
  • descr: China Internet Network Information Center
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2020-02-18T01:12:56Z

Links to attack logs

****** ****** ******

Share on: