182.92.221.152 Threat Intelligence and Host Information
General
This page contains threat intelligence information for the IPv4 address 182.92.221.152 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.
Potentially Malicious Host 🟡 45/100
Host and Network Information
-
Tags: awsbah, awsindia, bruteforce, cyber security, ioc, malicious, Nextray, phishing, redis
-
View other sources: Spamhaus VirusTotal
- Country: China
- Network: AS37963 hangzhou alibaba advertising co. ltd.
- Noticed: 34 times
- Protocols Attacked: redis
- Countries Attacked: Bahrain, Canada, Czechia, Denmark, Estonia, France, Germany, India, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
Open Ports Detected
1000 10000 10073 10134 10143 102 1023 1024 1025 104 10554 1080 10909 1099 110 11000 111 11112 11211 113 11300 119 1200 12000 1224 12345 13 1311 1337 135 1388 1400 1414 14147 1433 14344 1442 15 1515 1521 1554 1599 1604 16285 1650 16993 17 175 179 18245 19 19000 1911 1925 1926 195 1962 2000 20000 2002 2008 20256 20547 2063 2067 2077 2081 2083 2087 20880 21 21025 2121 21379 2150 2154 2181 22067 221 2222 2233 2245 23 23023 2332 23424 2345 2404 2455 2480 25 25001 2553 25565 2568 2569 26 2628 263 264 27015 2761 2762 28015 3001 3050 3058 3074 3080 3107 311 3119 31337 3260 3268 3269 3299 3301 33060 3310 3388 3389 3410 35000 3521 3522 3552 3555 3562 37 37215 3749 37777 3780 3790 3791 38 389 39277 4000 4022 4063 4064 4157 41800 42398 4242 427 4282 43 4321 4369 44158 4434 444 4443 4444 450 4506 465 4786 4808 4840 4899 49 49153 4949 50000 5001 5004 5006 5007 50070 5009 5010 50100 502 5025 503 51106 51235 515 5172 5201 5222 5269 52869 53 5321 5400 54138 5432 5435 5446 55000 554 55443 55553 5568 5598 5603 5672 5697 5801 5822 593 5984 5985 5986 6001 6002 6010 60129 61613 61616 62078 63210 636 6379 6443 6580 6605 6633 6650 6653 666 6664 6666 6667 6697 675 6998 70 7071 7080 7171 7218 7316 7415 7434 7443 7474 7500 7548 7557 7700 772 789 79 8001 8009 8011 8015 8022 8030 8039 8051 8056 8060 8069 8081 8082 8083 8085 8086 8087 8093 8095 8099 8118 8126 8139 8140 8159 8181 8182 8200 8291 8416 8425 8432 8443 8448 8500 8545 8554 8575 8585 8622 8649 8700 8728 873 8733 8767 8809 8814 8831 8834 8839 8845 8868 8879 8880 8990 9000 9001 9002 9005 9008 902 9042 9051 9084 9091 9095 9100 9109 9151 9160 9209 9212 9306 9398 9418 9443 9445 9530 9600 9633 9761 9869 9876 9898 9899 99 995 9981 9998 9999
CVEs Detected
CVE-2007-2768 CVE-2008-3844 CVE-2010-4478 CVE-2010-4755 CVE-2010-5107 CVE-2011-4327 CVE-2011-5000 CVE-2012-0814 CVE-2014-1692 CVE-2014-2532 CVE-2014-2653 CVE-2015-5352 CVE-2015-5600 CVE-2015-6563 CVE-2015-6564 CVE-2016-0777 CVE-2016-10009 CVE-2016-10010 CVE-2016-10011 CVE-2016-10012 CVE-2016-10708 CVE-2016-1908 CVE-2016-20012 CVE-2016-3115 CVE-2017-15906 CVE-2018-15473 CVE-2018-15919 CVE-2018-20685 CVE-2019-16905 CVE-2019-6109 CVE-2019-6110 CVE-2019-6111 CVE-2020-14145 CVE-2020-15778 CVE-2021-36368 CVE-2021-41617 CVE-2023-38408 CVE-2023-48795 CVE-2023-51385 CVE-2023-51767 CVE-2024-6387
Map
Whois Information
- inetnum: 182.92.0.0 - 182.92.255.255
- netname: ALISOFT
- descr: Aliyun Computing Co., LTD
- descr: 5F, Builing D, the West Lake International Plaza of S&T
- descr: No.391 Wen’er Road, Hangzhou, Zhejiang, China, 310099
- country: CN
- admin-c: ZM1015-AP
- tech-c: ZM877-AP
- tech-c: ZM876-AP
- tech-c: ZM875-AP
- abuse-c: AC1601-AP
- status: ALLOCATED PORTABLE
- mnt-by: MAINT-CNNIC-AP
- mnt-irt: IRT-ALISOFT-CN
- last-modified: 2023-11-28T00:57:12Z
- irt: IRT-ALISOFT-CN
- address: No.391 Wen’er Road, Hangzhou, Zhejiang, China, 310099
- e-mail: didong.jc@alibaba-inc.com
- abuse-mailbox: didong.jc@alibaba-inc.com
- admin-c: ZM877-AP
- tech-c: ZM877-AP
- mnt-by: MAINT-CNNIC-AP
- last-modified: 2021-09-05T23:38:36Z
- role: ABUSE CNNICCN
- country: ZZ
- address: Beijing, China
- phone: +000000000
- e-mail: ipas@cnnic.cn
- admin-c: IP50-AP
- tech-c: IP50-AP
- nic-hdl: AC1601-AP
- abuse-mailbox: ipas@cnnic.cn
- mnt-by: APNIC-ABUSE
- last-modified: 2024-07-30T11:55:46Z
- person: Li Jia
- address: NO.969 West Wen Yi Road, Yu Hang District, Hangzhou
- country: CN
- phone: +86-0571-85022088
- e-mail: jiali.jl@alibaba-inc.com
- nic-hdl: ZM1015-AP
- mnt-by: MAINT-CNNIC-AP
- last-modified: 2014-07-30T02:02:01Z
- person: Guoxin Gao
- address: 5F, Builing D, the West Lake International Plaza of S&T
- address: No.391 Wen’er Road, Hangzhou City
- address: Zhejiang, China, 310099
- country: CN
- phone: +86-0571-85022600
- fax-no: +86-0571-85022600
- e-mail: anti-spam@list.alibaba-inc.com
- nic-hdl: ZM875-AP
- mnt-by: MAINT-CNNIC-AP
- last-modified: 2014-07-30T01:56:01Z
- person: security trouble
- e-mail: yitian.gaoyt@alibaba-inc.com
- address: Hangzhou, Zhejiang, China
- phone: +86-0571-85022600
- country: CN
- mnt-by: MAINT-CNNIC-AP
- nic-hdl: ZM876-AP
- last-modified: 2021-04-13T23:22:33Z
- person: Guowei Pan
- address: 5F, Builing D, the West Lake International Plaza of S&T
- address: No.391 Wen’er Road, Hangzhou City
- address: Zhejiang, China, 310099
- country: CN
- phone: +86-0571-85022088-30763
- fax-no: +86-0571-85022600
- e-mail: guowei.pangw@alibaba-inc.com
- nic-hdl: ZM877-AP
- mnt-by: MAINT-CNNIC-AP
- last-modified: 2013-07-09T01:34:02Z
- route: 182.92.221.0/24
- origin: AS37963
- descr: China Internet Network Information Center
- mnt-by: MAINT-CNNIC-AP
- last-modified: 2020-02-18T01:36:19Z
- route: 182.92.221.0/24
- origin: AS45102
- descr: China Internet Network Information Center
- mnt-by: MAINT-CNNIC-AP
- last-modified: 2020-02-18T01:38:01Z
Links to attack logs
****** awsindia-redis-bruteforce-ip-list-2022-01-15 awsbah-redis-bruteforce-ip-list-2021-12-24 awsbah-redis-bruteforce-ip-list-2022-01-17 ****** ******
Share on: