47.102.114.133 Threat Intelligence and Host Information
General
This page contains threat intelligence information for the IPv4 address 47.102.114.133 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.
Potentially Malicious Host 🟡 45/100
Host and Network Information
-
Mitre ATT&CK IDs: TA0011 - Command and Control
-
Tags: anna paula, associated, beacon, beijing, changsha, cloud service, cloudvsp, cobalt strike, Cobalt Strike, computing, contact, copy, currc3adculo, cyber security, digitalocean, footer, from email, headers, huawei public, huawei software, ioc, krypt, malicious, malspam email, msi file, Nextray, open, phishing, solid, star, strike beacon, tencent cloud, tuesday, unknown, utf8, zip archive
-
View other sources: Spamhaus VirusTotal
- Country: China
- Network: AS37963 hangzhou alibaba advertising co. ltd.
- Noticed: 50 times
- Protocols Attacked: redis
- Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
Open Ports Detected
10134 104 10911 1099 11 110 11000 11211 113 11300 1177 13 1311 135 14265 1433 154 1604 175 1911 20000 2008 2083 2086 2087 21379 2154 22069 2323 2332 2345 2455 2525 2628 264 27015 30002 3268 3306 33060 3388 3389 3790 4063 4242 427 4506 465 49 49152 49153 5007 50100 5172 5201 5222 53 5432 548 5595 5596 5672 5907 6002 61616 636 7090 7218 7434 7474 8009 8048 8054 8060 8085 8126 8200 8252 8401 8402 8443 8649 8728 8806 8827 8834 8839 9001 9012 9016 9090 9092 9099 9109 95 9800 993 9994
CVEs Detected
CVE-2007-2768 CVE-2008-3844 CVE-2010-4478 CVE-2010-4755 CVE-2010-5107 CVE-2011-4327 CVE-2011-5000 CVE-2012-0814 CVE-2014-1692 CVE-2014-2653 CVE-2015-5352 CVE-2015-5600 CVE-2015-6563 CVE-2015-6564 CVE-2016-0777 CVE-2016-10708 CVE-2016-1908 CVE-2016-20012 CVE-2016-3115 CVE-2017-15906 CVE-2018-15473 CVE-2018-15919 CVE-2018-20685 CVE-2019-6109 CVE-2019-6110 CVE-2019-6111 CVE-2020-14145 CVE-2020-15778 CVE-2021-36368 CVE-2021-41617 CVE-2023-38408 CVE-2023-48795 CVE-2023-51385 CVE-2023-51767
Map
Whois Information
- NetRange: 47.98.0.0 - 47.112.255.255
- CIDR: 47.98.0.0/15, 47.112.0.0/16, 47.100.0.0/14, 47.104.0.0/13
- NetName: APNIC
- NetHandle: NET-47-98-0-0-1
- Parent: NET47 (NET-47-0-0-0-0)
- NetType: Early Registrations, Transferred to APNIC
- OriginAS:
- Organization: Asia Pacific Network Information Centre (APNIC)
- RegDate: 2015-04-01
- Updated: 2015-04-01
- Ref: https://rdap.arin.net/registry/ip/47.98.0.0
- OrgName: Asia Pacific Network Information Centre
- OrgId: APNIC
- Address: PO Box 3646
- City: South Brisbane
- StateProv: QLD
- PostalCode: 4101
- Country: AU
- RegDate:
- Updated: 2012-01-24
- Ref: https://rdap.arin.net/registry/entity/APNIC
- OrgAbuseHandle: AWC12-ARIN
- OrgAbuseName: APNIC Whois Contact
- OrgAbusePhone: +61 7 3858 3188
- OrgAbuseEmail: search-apnic-not-arin@apnic.net
- OrgAbuseRef: https://rdap.arin.net/registry/entity/AWC12-ARIN
- OrgTechHandle: AWC12-ARIN
- OrgTechName: APNIC Whois Contact
- OrgTechPhone: +61 7 3858 3188
- OrgTechEmail: search-apnic-not-arin@apnic.net
- OrgTechRef: https://rdap.arin.net/registry/entity/AWC12-ARIN
- inetnum: 47.100.0.0 - 47.103.255.255
- netname: ALISOFT
- descr: Aliyun Computing Co., LTD
- descr: 5F, Builing D, the West Lake International Plaza of S&T
- descr: No.391 Wen’er Road, Hangzhou, Zhejiang, China, 310099
- country: CN
- admin-c: ZM1015-AP
- tech-c: ZM877-AP
- tech-c: ZM876-AP
- tech-c: ZM875-AP
- abuse-c: AC1601-AP
- status: ALLOCATED PORTABLE
- mnt-by: MAINT-CNNIC-AP
- mnt-irt: IRT-ALISOFT-CN
- last-modified: 2023-11-28T00:58:17Z
- irt: IRT-ALISOFT-CN
- address: No.391 Wen’er Road, Hangzhou, Zhejiang, China, 310099
- e-mail: didong.jc@alibaba-inc.com
- abuse-mailbox: didong.jc@alibaba-inc.com
- admin-c: ZM877-AP
- tech-c: ZM877-AP
- mnt-by: MAINT-CNNIC-AP
- last-modified: 2021-09-05T23:38:36Z
- role: ABUSE CNNICCN
- address: Beijing, China
- country: ZZ
- phone: +000000000
- e-mail: ipas@cnnic.cn
- admin-c: IP50-AP
- tech-c: IP50-AP
- nic-hdl: AC1601-AP
- abuse-mailbox: ipas@cnnic.cn
- mnt-by: APNIC-ABUSE
- last-modified: 2020-05-14T11:19:01Z
- person: Li Jia
- address: NO.969 West Wen Yi Road, Yu Hang District, Hangzhou
- country: CN
- phone: +86-0571-85022088
- e-mail: jiali.jl@alibaba-inc.com
- nic-hdl: ZM1015-AP
- mnt-by: MAINT-CNNIC-AP
- last-modified: 2014-07-30T02:02:01Z
- person: Guoxin Gao
- address: 5F, Builing D, the West Lake International Plaza of S&T
- address: No.391 Wen’er Road, Hangzhou City
- address: Zhejiang, China, 310099
- country: CN
- phone: +86-0571-85022600
- fax-no: +86-0571-85022600
- e-mail: anti-spam@list.alibaba-inc.com
- nic-hdl: ZM875-AP
- mnt-by: MAINT-CNNIC-AP
- last-modified: 2014-07-30T01:56:01Z
- person: security trouble
- e-mail: yitian.gaoyt@alibaba-inc.com
- address: Hangzhou, Zhejiang, China
- phone: +86-0571-85022600
- country: CN
- mnt-by: MAINT-CNNIC-AP
- nic-hdl: ZM876-AP
- last-modified: 2021-04-13T23:22:33Z
- person: Guowei Pan
- address: 5F, Builing D, the West Lake International Plaza of S&T
- address: No.391 Wen’er Road, Hangzhou City
- address: Zhejiang, China, 310099
- country: CN
- phone: +86-0571-85022088-30763
- fax-no: +86-0571-85022600
- e-mail: guowei.pangw@alibaba-inc.com
- nic-hdl: ZM877-AP
- mnt-by: MAINT-CNNIC-AP
- last-modified: 2013-07-09T01:34:02Z
- route: 47.102.114.0/24
- descr: Alibaba (US) Technology Co., Ltd.
- origin: AS37963
- mnt-by: MAINT-CNNIC-AP
- last-modified: 2020-06-28T00:38:43Z
- route: 47.102.114.0/24
- descr: Alibaba (US) Technology Co., Ltd.
- origin: AS45102
- mnt-by: MAINT-CNNIC-AP
- last-modified: 2020-06-28T00:39:07Z
Links to attack logs
****** awsindia-redis-bruteforce-ip-list-2022-05-04 ****** ******
Share on: