IOC Radar
IPMediumSignal 83/100

120.79.201.200

Location
ChinaChina
Shenzhen, Guangdong
ASN
AS37963
Aliyun Computing Co., LTD
First Seen
Jan 24, 2025
Last Seen
Feb 20, 2026
Jan 24
First Seen
505d ago
Feb 20
Last Seen
113d ago
14
Reports
source reports
83%
Confidence
medium
Found in 14 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
83%
Signal Score
83 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

36 techniques

Network Information

CountryCNChina
RegionShenzhen, Guangdong
ASNAS37963
OrganizationAliyun Computing Co., LTD

Feed Intelligence Summary

14 reports83% confidence
14
Source reports
83%
Confidence score
Category tags
abuseaccess controlactive scanningapplication layer protocolasiaattackauthenticationauthentication abuseauthentication attackauthentication attacksauthentication attemptsauthentication failurebad web botbotnetbotnet activity detectedbrute forcebrute force attackbrute force attemptbrute_forcec2 communicationc2 serverchinacncommand and controlcommunication protocolcompromised hostscredential accesscredential stuffingcredential_accessdata exfiltrationdata theftddosdenial of servicedistributed attackseuropeexploit attemptexploitation attemptsfail2ban triggerfail2ban triggeredfinlandftpftp brute forcegame_servergb-originating traffichackingindicatorioclogin attacklogin brute-forcelogin failurelogin failuresmalicious activitymalicious softwaremalwaremalware distributionnetworknetwork attacksnetwork intrusionnetwork intrusion detectionnetwork layer protocolnetwork protocolnetwork scanningnetwork securitynetwork service scanningnetwork sniffingnetwork trafficnetwork traffic analysispassword attackpassword attackspassword crackingprocess injectionratreconnaissanceremote accessresearchedscannerscanning activitysecurity operationssecurity policysocradar honeypotspamssh attackstaging_servert1021t1021.001t1040t1046t1055t1059t1059.004t1071t1071.001t1078t1078.001t1078.004t1105t1110t1110.001t1110.002t1110.003t1110.004t1133t1190t1203t1486t1496t1499.001t1499.002t1499.003t1565t1573t1588t1588.004t1589t1589.002t1595t1595.001t1595.002t1595.003tcp protocoltelecommunicationsthreat actorthreat intelligencethreat preventionudp port scanunauthorized access attemptsunauthorized login attemptsunited kingdomunusual network activityvalid accountsweb application attackweb brute forceweb exploitation

Activity Timeline

1 total obs
Feb 20Feb 20

Threat Activity Heatmap

· Peak: 2026-02-20
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Threat ScoreHigh Risk
83
SIGNAL
Signal Score
83%
Confidence
14
Reports
First seenJan 24, 2025
Last seenFeb 20, 2026
GeolocationCN
CountryChina
LocationShenzhen, Guangdong
ASNAS37963
OrgAliyun Computing Co., LTD
Coords22.5429, 114.0600

VirusTotal

Not checked

WHOIS

description
SSH brute force IOCs collected mainly from hosts located in Finland
raw
inetnum: 120.76.0.0 - 120.79.255.255 netname: ALISOFT descr: Aliyun Computing Co., LTD descr: 5F, Builing D, the West Lake International Plaza of S&T descr: No.391 Wen'er Road, Hangzhou, Zhejiang, China, 310099 country: CN admin-c: ZM1015-AP tech-c: ZM877-AP tech-c: ZM876-AP tech-c: ZM875-AP abuse-c: AC1601-AP status: ALLOCATED PORTABLE mnt-by: MAINT-CNNIC-AP mnt-irt: IRT-ALISOFT-CN last-modified: 2023-11-28T00:57:00Z source: APNIC irt: IRT-ALISOFT-CN address: No.391 Wen'er Road, Hangzhou, Zhejiang, China, 310099 e-mail: [email protected] abuse-mailbox: [email protected] auth: # Filtered admin-c: ZM877-AP tech-c: ZM877-AP mnt-by: MAINT-CNNIC-AP last-modified: 2021-09-05T23:38:36Z source: APNIC role: ABUSE CNNICCN country: ZZ address: Beijing, China phone: +000000000 e-mail: [email protected] admin-c: IP50-AP tech-c: IP50-AP nic-hdl: AC1601-AP remarks: Generated from irt object IRT-CNNIC-CN abuse-mailbox: [email protected] mnt-by: APNIC-ABUSE last-modified: 2024-07-30T11:55:46Z source: APNIC person: Li Jia address: NO.969 West Wen Yi Road, Yu Hang District, Hangzhou country: CN phone: +86-0571-85022088 e-mail: [email protected] nic-hdl: ZM1015-AP mnt-by: MAINT-CNNIC-AP last-modified: 2025-07-01T07:12:42Z source: APNIC person: Guoxin Gao address: 5F, Builing D, the West Lake International Plaza of S&T address: No.391 Wen'er Road, Hangzhou City address: Zhejiang, China, 310099 country: CN phone: +86-0571-85022600 fax-no: +86-0571-85022600 e-mail: [email protected] nic-hdl: ZM875-AP mnt-by: MAINT-CNNIC-AP last-modified: 2014-07-30T01:56:01Z source: APNIC person: security trouble e-mail: [email protected] address: 5th,floor,Building D,the West Lake International Plaza of S&T,391#Wen??r Road address: Hangzhou, Zhejiang, China phone: +86-0571-85022600 country: CN mnt-by: MAINT-CNNIC-AP nic-hdl: ZM876-AP last-modified: 2025-07-01T07:06:11Z source: APNIC person: Guowei Pan address: 5F, Builing D, the West Lake International Plaza of S&T address: No.391 Wen'er Road, Hangzhou City address: Zhejiang, China, 310099 country: CN phone: +86-0571-85022088-30763 fax-no: +86-0571-85022600 e-mail: [email protected] nic-hdl: ZM877-AP mnt-by: MAINT-CNNIC-AP last-modified: 2025-07-01T07:05:46Z source: APNIC route: 120.76.0.0/14 descr: Hangzhou Alibaba Advertising Co.,Ltd. country: CN origin: AS37963 mnt-by: MAINT-CNNIC-AP last-modified: 2019-08-06T02:28:03Z source: APNIC route: 120.76.0.0/14 descr: Alibaba (US) Technology Co., Ltd. country: CN origin: AS45102 mnt-by: MAINT-CNNIC-AP last-modified: 2019-08-06T02:28:03Z source: APNIC
references
https://malware-filter.gitlab.io/malware-filter/botnet-filter.txt, https://raw.githubusercontent.com/ahamed-rizvan/IOCs/refs/heads/main/Malicous%20IP%20Address.txt

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 3 months ago
Appeared in 14 threat reports