47.94.88.97 Threat Intelligence and Host Information

General

This page contains threat intelligence information for the IPv4 address 47.94.88.97 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.

Potentially Malicious Host 🟡 45/100

Host and Network Information

  • Tags: awsindia, bruteforce, cyber security, ioc, malicious, Nextray, phishing, redis, tsec

  • View other sources: Spamhaus VirusTotal

  • Country: China
  • Network:
  • Noticed: 36 times
  • Protocols Attacked: redis
  • Countries Attacked: Canada, Czechia, Denmark, Estonia, France, Germany, India, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
  • Passive DNS Results: xunliaoaaa.com

Open Ports Detected

100 10000 10001 10050 10051 10134 102 1023 10250 104 10443 10554 1080 10909 10911 1099 11 110 111 11210 11211 11288 113 11300 1153 1177 119 1200 12000 1234 13047 131 1337 135 139 1414 14147 14265 143 14344 1443 1471 15 1515 1521 15443 1599 1604 16993 17 17000 1723 175 179 1800 1801 18080 18245 1883 19 19000 19200 195 1962 2000 20000 2002 2003 2008 20256 2050 2052 2062 2081 2083 2087 20880 21 21025 21379 2154 2181 22 22000 22001 22069 221 222 2222 22222 2225 22556 2259 23 2323 2332 23424 2345 2376 2404 2455 25 25001 25565 2560 2563 2568 2628 264 27015 2761 2762 28015 28080 3001 30122 30301 30303 30422 3058 30722 30822 30922 3093 3106 311 31122 3113 3120 3121 31222 31322 31337 31422 3211 32222 32322 3260 32764 3301 3306 33060 3310 33122 33322 33338 33422 33522 33622 33722 3389 3404 3407 34422 3479 35022 3522 3551 3557 35922 36722 37 37215 37522 37777 3780 38322 38333 38422 38522 38622 38722 389 3952 4000 4022 4063 4064 41122 41222 4150 41522 4157 41622 41822 42222 4242 42422 42522 427 43 43022 43322 43422 4369 43722 44022 44122 443 44322 4433 4434 444 4444 44522 44622 44722 44818 4482 44822 4500 4506 45322 45722 45822 46122 46422 465 47022 47122 47422 4747 47522 47808 47822 4786 47922 47990 48122 48222 48322 4840 48822 48922 4899 49 49022 491 4911 49322 49522 49622 49722 49822 49922 50000 5001 5006 5007 5009 5010 50100 502 5025 50322 50722 50922 51106 51235 515 51722 51822 52022 52122 5222 52322 52422 52522 52622 5269 52722 52822 52869 53 53322 53413 53522 53722 54138 54222 5432 5435 548 54922 54984 55000 55222 55322 554 55422 55442 55522 55553 55554 55622 55722 55822 5590 55922 5606 56222 56322 56422 56522 5672 56722 56822 56922 57222 57422 57522 58122 58222 58422 58522 5858 587 58722 58822 59122 593 59322 5938 5986 6000 6001 6002 6007 6010 60129 6080 61613 61616 62078 6262 63210 63256 63260 636 64295 6464 64738 6601 6603 666 6667 6668 6697 70 7001 7070 7071 7218 7415 7433 7443 7445 7548 7634 771 7777 789 8002 8005 8009 8020 8027 805 8072 8081 8085 8089 8099 8126 8139 8140 8188 8200 8333 8401 8418 8430 8443 8500 8554 8575 8649 8765 8779 8801 8829 8834 8864 8870 8889 8899 8988 8999 9000 9001 902 9021 9042 9051 9091 9092 9111 9160 9206 9302 9306 9389 9398 9418 9527 9600 9633 97 9761 9869 992 993 994 9944 9998 9999

CVEs Detected

CVE-2007-2768 CVE-2008-3844 CVE-2010-4478 CVE-2010-4755 CVE-2010-5107 CVE-2011-4327 CVE-2011-5000 CVE-2012-0814 CVE-2014-1692 CVE-2014-2532 CVE-2014-2653 CVE-2015-5352 CVE-2015-5600 CVE-2015-6563 CVE-2015-6564 CVE-2016-0777 CVE-2016-10009 CVE-2016-10010 CVE-2016-10011 CVE-2016-10012 CVE-2016-10708 CVE-2016-1908 CVE-2016-20012 CVE-2016-3115 CVE-2017-15906 CVE-2018-15473 CVE-2018-15919 CVE-2018-20685 CVE-2019-16905 CVE-2019-6109 CVE-2019-6110 CVE-2019-6111 CVE-2020-14145 CVE-2020-15778 CVE-2021-36368 CVE-2021-41617 CVE-2023-38408 CVE-2023-48795 CVE-2023-51385 CVE-2023-51767 CVE-2024-6387

Whois Information

  • NetRange: 47.92.0.0 - 47.97.255.255
  • CIDR: 47.96.0.0/15, 47.92.0.0/14
  • NetName: APNIC
  • NetHandle: NET-47-92-0-0-1
  • Parent: NET47 (NET-47-0-0-0-0)
  • NetType: Early Registrations, Transferred to APNIC
  • OriginAS:
  • Organization: Asia Pacific Network Information Centre (APNIC)
  • RegDate: 2015-03-02
  • Updated: 2015-03-02
  • Ref: https://rdap.arin.net/registry/ip/47.92.0.0
  • OrgName: Asia Pacific Network Information Centre
  • OrgId: APNIC
  • Address: PO Box 3646
  • City: South Brisbane
  • StateProv: QLD
  • PostalCode: 4101
  • Country: AU
  • RegDate:
  • Updated: 2012-01-24
  • Ref: https://rdap.arin.net/registry/entity/APNIC
  • OrgAbuseHandle: AWC12-ARIN
  • OrgAbuseName: APNIC Whois Contact
  • OrgAbusePhone: +61 7 3858 3188
  • OrgAbuseEmail: search-apnic-not-arin@apnic.net
  • OrgAbuseRef: https://rdap.arin.net/registry/entity/AWC12-ARIN
  • OrgTechHandle: AWC12-ARIN
  • OrgTechName: APNIC Whois Contact
  • OrgTechPhone: +61 7 3858 3188
  • OrgTechEmail: search-apnic-not-arin@apnic.net
  • OrgTechRef: https://rdap.arin.net/registry/entity/AWC12-ARIN
  • inetnum: 47.92.0.0 - 47.95.255.255
  • netname: ALISOFT
  • descr: Aliyun Computing Co., LTD
  • descr: 5F, Builing D, the West Lake International Plaza of S&T
  • descr: No.391 Wen’er Road, Hangzhou, Zhejiang, China, 310099
  • country: CN
  • admin-c: ZM1015-AP
  • tech-c: ZM877-AP
  • tech-c: ZM876-AP
  • tech-c: ZM875-AP
  • abuse-c: AC1601-AP
  • status: ALLOCATED PORTABLE
  • mnt-by: MAINT-CNNIC-AP
  • mnt-irt: IRT-ALISOFT-CN
  • last-modified: 2023-11-28T00:58:17Z
  • irt: IRT-ALISOFT-CN
  • address: No.391 Wen’er Road, Hangzhou, Zhejiang, China, 310099
  • e-mail: didong.jc@alibaba-inc.com
  • abuse-mailbox: didong.jc@alibaba-inc.com
  • admin-c: ZM877-AP
  • tech-c: ZM877-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2021-09-05T23:38:36Z
  • role: ABUSE CNNICCN
  • country: ZZ
  • address: Beijing, China
  • phone: +000000000
  • e-mail: ipas@cnnic.cn
  • admin-c: IP50-AP
  • tech-c: IP50-AP
  • nic-hdl: AC1601-AP
  • abuse-mailbox: ipas@cnnic.cn
  • mnt-by: APNIC-ABUSE
  • last-modified: 2024-07-30T11:55:46Z
  • person: Li Jia
  • address: NO.969 West Wen Yi Road, Yu Hang District, Hangzhou
  • country: CN
  • phone: +86-0571-85022088
  • e-mail: jiali.jl@alibaba-inc.com
  • nic-hdl: ZM1015-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2014-07-30T02:02:01Z
  • person: Guoxin Gao
  • address: 5F, Builing D, the West Lake International Plaza of S&T
  • address: No.391 Wen’er Road, Hangzhou City
  • address: Zhejiang, China, 310099
  • country: CN
  • phone: +86-0571-85022600
  • fax-no: +86-0571-85022600
  • e-mail: anti-spam@list.alibaba-inc.com
  • nic-hdl: ZM875-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2014-07-30T01:56:01Z
  • person: security trouble
  • e-mail: yitian.gaoyt@alibaba-inc.com
  • address: Hangzhou, Zhejiang, China
  • phone: +86-0571-85022600
  • country: CN
  • mnt-by: MAINT-CNNIC-AP
  • nic-hdl: ZM876-AP
  • last-modified: 2021-04-13T23:22:33Z
  • person: Guowei Pan
  • address: 5F, Builing D, the West Lake International Plaza of S&T
  • address: No.391 Wen’er Road, Hangzhou City
  • address: Zhejiang, China, 310099
  • country: CN
  • phone: +86-0571-85022088-30763
  • fax-no: +86-0571-85022600
  • e-mail: guowei.pangw@alibaba-inc.com
  • nic-hdl: ZM877-AP
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2013-07-09T01:34:02Z
  • route: 47.92.0.0/14
  • descr: Hangzhou Alibaba Advertising Co.,Ltd.
  • country: CN
  • origin: AS37963
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2019-08-07T23:28:06Z
  • route: 47.92.0.0/14
  • descr: Alibaba (US) Technology Co., Ltd.
  • country: CN
  • origin: AS45102
  • mnt-by: MAINT-CNNIC-AP
  • last-modified: 2019-08-07T23:28:04Z

Links to attack logs

awsindia-redis-bruteforce-ip-list-2022-03-01 ****** ****** ******

Share on: