47.94.166.81 Threat Intelligence and Host Information
General
This page contains threat intelligence information for the IPv4 address 47.94.166.81 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.
Potentially Malicious Host 🟡 45/100
Host and Network Information
-
Tags: cyber security, ioc, malicious, Nextray, phishing
-
View other sources: Spamhaus VirusTotal
- Country: China
- Network:
- Noticed: 32 times
- Protocols Attacked: redis
- Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
Open Ports Detected
CVEs Detected
CVE-2017-20005 CVE-2017-7529 CVE-2018-16843 CVE-2018-16844 CVE-2018-16845 CVE-2019-10352 CVE-2019-10353 CVE-2019-10354 CVE-2019-10383 CVE-2019-10384 CVE-2019-10401 CVE-2019-10402 CVE-2019-10403 CVE-2019-10404 CVE-2019-10405 CVE-2019-10406 CVE-2019-20372 CVE-2019-9511 CVE-2019-9513 CVE-2019-9516 CVE-2020-2099 CVE-2020-2100 CVE-2020-2101 CVE-2020-2102 CVE-2020-2103 CVE-2020-2104 CVE-2020-2105 CVE-2020-2160 CVE-2020-2161 CVE-2020-2162 CVE-2020-2163 CVE-2020-2220 CVE-2020-2221 CVE-2020-2222 CVE-2020-2223 CVE-2020-2229 CVE-2020-2230 CVE-2020-2231 CVE-2021-21602 CVE-2021-21603 CVE-2021-21604 CVE-2021-21605 CVE-2021-21606 CVE-2021-21607 CVE-2021-21608 CVE-2021-21609 CVE-2021-21610 CVE-2021-21611 CVE-2021-21615 CVE-2021-21639 CVE-2021-21640 CVE-2021-21670 CVE-2021-21682 CVE-2021-21683 CVE-2021-21685 CVE-2021-21686 CVE-2021-21687 CVE-2021-21688 CVE-2021-21689 CVE-2021-21690 CVE-2021-21691 CVE-2021-21692 CVE-2021-21693 CVE-2021-21694 CVE-2021-21695 CVE-2021-21696 CVE-2021-21697 CVE-2021-23017 CVE-2021-28165 CVE-2021-3618 CVE-2021-43859 CVE-2022-0538 CVE-2022-2048 CVE-2022-20612 CVE-2022-27201 CVE-2022-34174 CVE-2022-36899 CVE-2022-36900 CVE-2022-43416 CVE-2022-43423 CVE-2022-43424 CVE-2022-43428 CVE-2022-43429 CVE-2023-27899 CVE-2023-27900 CVE-2023-27901 CVE-2023-27902 CVE-2023-27903 CVE-2023-27904 CVE-2023-35141 CVE-2023-36478 CVE-2023-39151 CVE-2023-43494 CVE-2023-43495 CVE-2023-43496 CVE-2023-43497 CVE-2023-43498 CVE-2023-44487 CVE-2024-23897 CVE-2024-43044 CVE-2024-43045 CVE-2024-47803 CVE-2024-47804 CVE-2025-27622 CVE-2025-27623 CVE-2025-27624 CVE-2025-27625 CVE-2025-31720 CVE-2025-31721
Map
Whois Information
- NetRange: 47.92.0.0 - 47.97.255.255
- CIDR: 47.92.0.0/14, 47.96.0.0/15
- NetName: APNIC
- NetHandle: NET-47-92-0-0-1
- Parent: NET47 (NET-47-0-0-0-0)
- NetType: Early Registrations, Transferred to APNIC
- OriginAS:
- Organization: Asia Pacific Network Information Centre (APNIC)
- RegDate: 2015-03-02
- Updated: 2015-03-02
- Ref: https://rdap.arin.net/registry/ip/47.92.0.0
- OrgName: Asia Pacific Network Information Centre
- OrgId: APNIC
- Address: PO Box 3646
- City: South Brisbane
- StateProv: QLD
- PostalCode: 4101
- Country: AU
- RegDate:
- Updated: 2012-01-24
- Ref: https://rdap.arin.net/registry/entity/APNIC
- OrgTechHandle: AWC12-ARIN
- OrgTechName: APNIC Whois Contact
- OrgTechPhone: +61 7 3858 3188
- OrgTechEmail: search-apnic-not-arin@apnic.net
- OrgTechRef: https://rdap.arin.net/registry/entity/AWC12-ARIN
- OrgAbuseHandle: AWC12-ARIN
- OrgAbuseName: APNIC Whois Contact
- OrgAbusePhone: +61 7 3858 3188
- OrgAbuseEmail: search-apnic-not-arin@apnic.net
- OrgAbuseRef: https://rdap.arin.net/registry/entity/AWC12-ARIN
- inetnum: 47.92.0.0 - 47.95.255.255
- netname: ALISOFT
- descr: Aliyun Computing Co., LTD
- descr: 5F, Builing D, the West Lake International Plaza of S&T
- descr: No.391 Wen’er Road, Hangzhou, Zhejiang, China, 310099
- country: CN
- admin-c: ZM1015-AP
- tech-c: ZM877-AP
- tech-c: ZM876-AP
- tech-c: ZM875-AP
- abuse-c: AC1601-AP
- status: ALLOCATED PORTABLE
- mnt-by: MAINT-CNNIC-AP
- mnt-irt: IRT-ALISOFT-CN
- last-modified: 2023-11-28T00:58:17Z
- irt: IRT-ALISOFT-CN
- address: No.391 Wen’er Road, Hangzhou, Zhejiang, China, 310099
- e-mail: didong.jc@alibaba-inc.com
- abuse-mailbox: didong.jc@alibaba-inc.com
- admin-c: ZM877-AP
- tech-c: ZM877-AP
- mnt-by: MAINT-CNNIC-AP
- last-modified: 2021-09-05T23:38:36Z
- role: ABUSE CNNICCN
- country: ZZ
- address: Beijing, China
- phone: +000000000
- e-mail: ipas@cnnic.cn
- admin-c: IP50-AP
- tech-c: IP50-AP
- nic-hdl: AC1601-AP
- abuse-mailbox: ipas@cnnic.cn
- mnt-by: APNIC-ABUSE
- last-modified: 2024-07-30T11:55:46Z
- person: Li Jia
- address: NO.969 West Wen Yi Road, Yu Hang District, Hangzhou
- country: CN
- phone: +86-0571-85022088
- e-mail: jiali.jl@alibaba-inc.com
- nic-hdl: ZM1015-AP
- mnt-by: MAINT-CNNIC-AP
- last-modified: 2025-07-01T07:12:42Z
- person: Guoxin Gao
- address: 5F, Builing D, the West Lake International Plaza of S&T
- address: No.391 Wen’er Road, Hangzhou City
- address: Zhejiang, China, 310099
- country: CN
- phone: +86-0571-85022600
- fax-no: +86-0571-85022600
- e-mail: anti-spam@list.alibaba-inc.com
- nic-hdl: ZM875-AP
- mnt-by: MAINT-CNNIC-AP
- last-modified: 2014-07-30T01:56:01Z
- person: security trouble
- e-mail: abuse@alibaba-inc.com
- address: Hangzhou, Zhejiang, China
- phone: +86-0571-85022600
- country: CN
- mnt-by: MAINT-CNNIC-AP
- nic-hdl: ZM876-AP
- last-modified: 2025-07-01T07:06:11Z
- person: Guowei Pan
- address: 5F, Builing D, the West Lake International Plaza of S&T
- address: No.391 Wen’er Road, Hangzhou City
- address: Zhejiang, China, 310099
- country: CN
- phone: +86-0571-85022088-30763
- fax-no: +86-0571-85022600
- e-mail: abuse@alibaba-inc.com
- nic-hdl: ZM877-AP
- mnt-by: MAINT-CNNIC-AP
- last-modified: 2025-07-01T07:05:46Z
- route: 47.92.0.0/14
- descr: Hangzhou Alibaba Advertising Co.,Ltd.
- country: CN
- origin: AS37963
- mnt-by: MAINT-CNNIC-AP
- last-modified: 2019-08-07T23:28:06Z
- route: 47.92.0.0/14
- descr: Alibaba (US) Technology Co., Ltd.
- country: CN
- origin: AS45102
- mnt-by: MAINT-CNNIC-AP
- last-modified: 2019-08-07T23:28:04Z
Links to attack logs
vultrparis-redis-bruteforce-ip-list-2021-11-10 vultrparis-redis-bruteforce-ip-list-2021-12-27 dotoronto-redis-bruteforce-ip-list-2021-04-03 ****** redis-bruteforce-ip-list-2021-09-13 vultrparis-redis-bruteforce-ip-list-2021-11-26 awsau-redis-bruteforce-ip-list-2021-08-23 ****** vultrparis-redis-bruteforce-ip-list-2021-11-03 vultrparis-redis-bruteforce-ip-list-2021-12-01 ****** awsbah-redis-bruteforce-ip-list-2021-12-30
Share on: