47.98.170.137 Threat Intelligence and Host Information
General
This page contains threat intelligence information for the IPv4 address 47.98.170.137 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.
Potentially Malicious Host 🟡 45/100
Host and Network Information
-
Tags: blacklist, botnet, bruteforce, digital ocean, Malicious IP, mirai, port 23, scan, tcp, tcp/23, telnet, vultr
-
View other sources: Spamhaus VirusTotal
- Country: China
- Network:
- Noticed: 25 times
- Protocols Attacked: telnet
- Countries Attacked: Canada, France, Poland, United Kingdom, United States of America
- Passive DNS Results: healthymap.tzle1.com yh.mamingwang.cn
Open Ports Detected
10000 10001 10123 10134 102 10225 10302 10397 10399 10554 1080 10934 11 11007 111 1111 11112 11210 11288 113 1153 1177 1200 12108 12137 12149 12160 12167 12180 12185 12212 12264 12279 12300 12337 12345 12346 12353 12392 12404 12411 12430 12434 12438 12460 1250 12524 12530 12538 12552 12902 13 1337 135 14265 1455 15 1515 15555 1557 1599 16022 1604 16042 1605 16080 16085 16087 16088 16092 16094 16400 1650 16601 17 17000 1723 17770 1800 1801 18030 18034 18047 18081 18083 18089 18099 18109 18245 18802 1883 19 1911 19222 1926 195 1962 1965 1980 20 2002 2003 20053 2008 2010 20151 20325 20512 20547 2061 2064 2066 2070 2081 2087 20880 2101 21233 21234 21292 21296 21298 21323 21379 2202 225 23023 2323 2332 2362 2404 2455 25 25000 25001 25565 2562 26 2628 27017 2762 28015 30003 30006 3001 3010 3051 3071 3079 3090 3094 3096 3101 3113 3117 31337 31444 3299 33060 3389 340 3404 35002 35240 3555 35560 3559 3580 36505 37 37443 37777 3790 389 40000 4021 4042 4157 41800 427 4282 43 4321 4401 443 44307 4431 4433 4434 444 4443 4445 4451 450 4528 45677 4602 465 47984 47990 487 49121 49690 50000 50008 5001 5006 5010 502 503 5089 51434 5201 5222 5229 5235 5247 5262 53 5432 5435 548 55443 55553 57788 587 5904 5915 5918 5938 5986 5994 6001 6002 60129 61616 62078 62080 63210 63256 6352 6380 6605 6633 6667 6668 6697 6699 70 7006 7071 7085 7090 7171 7173 7218 7272 7302 7415 7434 7493 7535 772 7887 79 8009 8029 8035 8071 8075 808 8081 8085 8087 8099 8117 8125 8126 8139 8140 8145 8166 8175 8189 8193 8200 8291 8317 8333 8411 8455 8488 8515 8530 8553 8554 8580 8599 8607 8621 8640 8649 8728 873 8767 8829 8835 8846 8851 8862 8878 8884 8890 8891 8899 8916 8993 9001 9044 9051 9054 9061 9067 9073 9095 91 9100 9104 9107 9116 9119 9141 9151 9176 9179 9215 93 9300 9418 9488 9530 9633 98 9926 993 9943 9998 9999
CVEs Detected
CVE-2007-2768 CVE-2008-3844 CVE-2016-20012 CVE-2017-15906 CVE-2018-15473 CVE-2018-15919 CVE-2018-20685 CVE-2019-16905 CVE-2019-6109 CVE-2019-6110 CVE-2019-6111 CVE-2020-14145 CVE-2020-15778 CVE-2021-36368 CVE-2021-41617 CVE-2023-38408 CVE-2023-48795 CVE-2023-51385 CVE-2023-51767 CVE-2025-26465 CVE-2025-32728
Map
Whois Information
- NetRange: 47.98.0.0 - 47.112.255.255
- CIDR: 47.104.0.0/13, 47.98.0.0/15, 47.112.0.0/16, 47.100.0.0/14
- NetName: APNIC
- NetHandle: NET-47-98-0-0-1
- Parent: NET47 (NET-47-0-0-0-0)
- NetType: Early Registrations, Transferred to APNIC
- OriginAS:
- Organization: Asia Pacific Network Information Centre (APNIC)
- RegDate: 2015-04-01
- Updated: 2015-04-01
- Ref: https://rdap.arin.net/registry/ip/47.98.0.0
- OrgName: Asia Pacific Network Information Centre
- OrgId: APNIC
- Address: PO Box 3646
- City: South Brisbane
- StateProv: QLD
- PostalCode: 4101
- Country: AU
- RegDate:
- Updated: 2012-01-24
- Ref: https://rdap.arin.net/registry/entity/APNIC
- OrgTechHandle: AWC12-ARIN
- OrgTechName: APNIC Whois Contact
- OrgTechPhone: +61 7 3858 3188
- OrgTechEmail: search-apnic-not-arin@apnic.net
- OrgTechRef: https://rdap.arin.net/registry/entity/AWC12-ARIN
- OrgAbuseHandle: AWC12-ARIN
- OrgAbuseName: APNIC Whois Contact
- OrgAbusePhone: +61 7 3858 3188
- OrgAbuseEmail: search-apnic-not-arin@apnic.net
- OrgAbuseRef: https://rdap.arin.net/registry/entity/AWC12-ARIN
- inetnum: 47.98.0.0 - 47.99.255.255
- netname: ALISOFT
- descr: Aliyun Computing Co., LTD
- descr: 5F, Builing D, the West Lake International Plaza of S&T
- descr: No.391 Wen’er Road, Hangzhou, Zhejiang, China, 310099
- country: CN
- admin-c: ZM1015-AP
- tech-c: ZM877-AP
- tech-c: ZM876-AP
- tech-c: ZM875-AP
- abuse-c: AC1601-AP
- status: ALLOCATED PORTABLE
- mnt-by: MAINT-CNNIC-AP
- mnt-irt: IRT-ALISOFT-CN
- mnt-lower: MAINT-CNNIC-AP
- mnt-routes: MAINT-CNNIC-AP
- last-modified: 2023-11-28T00:58:18Z
- irt: IRT-ALISOFT-CN
- address: No.391 Wen’er Road, Hangzhou, Zhejiang, China, 310099
- e-mail: didong.jc@alibaba-inc.com
- abuse-mailbox: didong.jc@alibaba-inc.com
- admin-c: ZM877-AP
- tech-c: ZM877-AP
- mnt-by: MAINT-CNNIC-AP
- last-modified: 2021-09-05T23:38:36Z
- role: ABUSE CNNICCN
- country: ZZ
- address: Beijing, China
- phone: +000000000
- e-mail: ipas@cnnic.cn
- admin-c: IP50-AP
- tech-c: IP50-AP
- nic-hdl: AC1601-AP
- abuse-mailbox: ipas@cnnic.cn
- mnt-by: APNIC-ABUSE
- last-modified: 2025-09-19T17:20:32Z
- person: Li Jia
- address: NO.969 West Wen Yi Road, Yu Hang District, Hangzhou
- country: CN
- phone: +86-0571-85022088
- e-mail: jiali.jl@alibaba-inc.com
- nic-hdl: ZM1015-AP
- mnt-by: MAINT-CNNIC-AP
- last-modified: 2025-07-01T07:12:42Z
- person: Guoxin Gao
- address: 5F, Builing D, the West Lake International Plaza of S&T
- address: No.391 Wen’er Road, Hangzhou City
- address: Zhejiang, China, 310099
- country: CN
- phone: +86-0571-85022600
- fax-no: +86-0571-85022600
- e-mail: anti-spam@list.alibaba-inc.com
- nic-hdl: ZM875-AP
- mnt-by: MAINT-CNNIC-AP
- last-modified: 2014-07-30T01:56:01Z
- person: security trouble
- e-mail: abuse@alibaba-inc.com
- address: Hangzhou, Zhejiang, China
- phone: +86-0571-85022600
- country: CN
- mnt-by: MAINT-CNNIC-AP
- nic-hdl: ZM876-AP
- last-modified: 2025-07-01T07:06:11Z
- person: Guowei Pan
- address: 5F, Builing D, the West Lake International Plaza of S&T
- address: No.391 Wen’er Road, Hangzhou City
- address: Zhejiang, China, 310099
- country: CN
- phone: +86-0571-85022088-30763
- fax-no: +86-0571-85022600
- e-mail: abuse@alibaba-inc.com
- nic-hdl: ZM877-AP
- mnt-by: MAINT-CNNIC-AP
- last-modified: 2025-07-01T07:05:46Z
- route: 47.98.0.0/15
- descr: Hangzhou Alibaba Advertising Co.,Ltd.
- country: CN
- origin: AS37963
- mnt-by: MAINT-CNNIC-AP
- last-modified: 2019-08-07T23:28:06Z
Links to attack logs
dolondon-telnet-bruteforce-ip-list-2023-07-22 ****** doamsterdam-telnet-bruteforce-ip-list-2023-07-22 vultrparis-telnet-bruteforce-ip-list-2023-07-22 dobengaluru-telnet-bruteforce-ip-list-2023-07-21 dobengaluru-telnet-bruteforce-ip-list-2023-07-19 dotoronto-telnet-bruteforce-ip-list-2023-07-19 ****** ****** vultrwarsaw-telnet-bruteforce-ip-list-2023-07-23
Share on: