IOC Radar
IPMediumSignal 68/100

120.26.164.174

Location
ChinaChina
Hangzhou, ZJ
ASN
AS37963
Alibaba.com LLC
First Seen
Jan 19, 2025
Last Seen
Apr 20, 2026
Jan 19
First Seen
511d ago
Apr 20
Last Seen
55d ago
16
Reports
source reports
68%
Confidence
medium
Found in 16 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
68%
Signal Score
68 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

47 techniques

Network Information

CountryCNChina
RegionHangzhou, ZJ
ASNAS37963
OrganizationAlibaba.com LLC

Feed Intelligence Summary

16 reports68% confidence
16
Source reports
68%
Confidence score
Category tags
abuseactive scanactive scanningadversary simulation toolagent teslaakamaialibabaandroidapi contactaptasiaattackbad reputationbeaconbeaconing activitybotnetbotnet activitybrute forcec2c2 communicationc2 frameworkcensyschinacncobaltcobalt strikecobaltstrikecommand & controlcommand and controlcompromised systemconfigcredential harvestingcredential stuffingdata encryptiondata exfiltrationdata store exposuredistributed attackse-commerceencryptioneuropeexecutable fileexploitation activityextortionfeedfindfraudglobalhackinghuaweiidentity & access exploitationindicatorindicators of compromiseinformation technologyinfrastructure acquisitionreconnaissanceinjection activityiociocsiotiot securityjquerylateral movementlateral movement techniqueslinkedin pagemalicious activitymalicious softwaremalwaremalware distributionmanualmedia & entertainmentmobile threatnanocore ratnation-state activitynetworknetwork traffic analysispayload deliverypayload deploymentpayload generationpenetration testing toolphishingphishing attackphppost-exploitationpost-exploitation activitiespost-exploitation activityprocess injectionprotectransomwareransomware feedreconnaissanceremote access trojanresearchedscams & fraudscannersecurity operationssentinel mispservershellcodeslugsocial engineeringstrongsurface websystem disruptiont1003t1005t1016t1018t1021t1027t1041t1047t1049t1053t1055t1059t1059.001t1068t1071t1071.001t1078t1083t1090t1090.001t1095t1105t1129t1134t1190t1210t1486t1490t1496t1499.002t1499.003t1543t1565t1566t1566.001t1566.002t1566.003t1567t1569.002t1573t1573.001t1574t1587.001t1590.001t1595.001t1595.002t1595.003telecommunicationthreat actorthreat feedthreat intelligencetor nodeunixvietnamvulnerability scan

Activity Timeline

1 total obs
Apr 20Apr 20

Threat Activity Heatmap

· Peak: 2026-04-20
Less
More
Mon
Wed
Fri
Jun
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreMedium Risk
68
SIGNAL
Signal Score
68%
Confidence
16
Reports
First seenJan 19, 2025
Last seenApr 20, 2026
GeolocationCN
CountryChina
LocationHangzhou, ZJ
ASNAS37963
OrgAlibaba.com LLC
Coords30.2994, 120.1612

VirusTotal

Not checked

WHOIS

description
CC=CN ASN=AS37963 Hangzhou Alibaba Advertising Co.,Ltd.
raw
inetnum: 120.24.0.0 - 120.27.255.255 netname: ALISOFT descr: Aliyun Computing Co., LTD descr: 5F, Builing D, the West Lake International Plaza of S&T descr: No.391 Wen'er Road, Hangzhou, Zhejiang, China, 310099 country: CN admin-c: ZM1015-AP tech-c: ZM877-AP tech-c: ZM876-AP tech-c: ZM875-AP abuse-c: AC1601-AP status: ALLOCATED PORTABLE mnt-by: MAINT-CNNIC-AP mnt-irt: IRT-ALISOFT-CN last-modified: 2023-11-28T00:57:00Z source: APNIC irt: IRT-ALISOFT-CN address: No.391 Wen'er Road, Hangzhou, Zhejiang, China, 310099 e-mail: [email protected] abuse-mailbox: [email protected] auth: # Filtered admin-c: ZM877-AP tech-c: ZM877-AP mnt-by: MAINT-CNNIC-AP last-modified: 2021-09-05T23:38:36Z source: APNIC role: ABUSE CNNICCN country: ZZ address: Beijing, China phone: +000000000 e-mail: [email protected] admin-c: IP50-AP tech-c: IP50-AP nic-hdl: AC1601-AP remarks: Generated from irt object IRT-CNNIC-CN abuse-mailbox: [email protected] mnt-by: APNIC-ABUSE last-modified: 2024-07-30T11:55:46Z source: APNIC person: Li Jia address: NO.969 West Wen Yi Road, Yu Hang District, Hangzhou country: CN phone: +86-0571-85022088 e-mail: [email protected] nic-hdl: ZM1015-AP mnt-by: MAINT-CNNIC-AP last-modified: 2025-07-01T07:12:42Z source: APNIC person: Guoxin Gao address: 5F, Builing D, the West Lake International Plaza of S&T address: No.391 Wen'er Road, Hangzhou City address: Zhejiang, China, 310099 country: CN phone: +86-0571-85022600 fax-no: +86-0571-85022600 e-mail: [email protected] nic-hdl: ZM875-AP mnt-by: MAINT-CNNIC-AP last-modified: 2014-07-30T01:56:01Z source: APNIC person: security trouble e-mail: [email protected] address: 5th,floor,Building D,the West Lake International Plaza of S&T,391#Wen??r Road address: Hangzhou, Zhejiang, China phone: +86-0571-85022600 country: CN mnt-by: MAINT-CNNIC-AP nic-hdl: ZM876-AP last-modified: 2025-07-01T07:06:11Z source: APNIC person: Guowei Pan address: 5F, Builing D, the West Lake International Plaza of S&T address: No.391 Wen'er Road, Hangzhou City address: Zhejiang, China, 310099 country: CN phone: +86-0571-85022088-30763 fax-no: +86-0571-85022600 e-mail: [email protected] nic-hdl: ZM877-AP mnt-by: MAINT-CNNIC-AP last-modified: 2025-07-01T07:05:46Z source: APNIC route: 120.26.0.0/15 descr: Addresses from CNNIC country: CN origin: AS37963 mnt-by: MAINT-CNNIC-AP last-modified: 2016-04-07T03:20:01Z source: APNIC
references
https://precisionsec.com/threat-intelligence-feeds/cobaltstrike/, https://threatfox.abuse.ch/export/csv/recent/

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 1 month ago
Appeared in 16 threat reports