IOC Radar
IPMediumSignal 100/100

47.121.120.18

Location
ChinaChina
Shenzhen, GD
ASN
AS37963
Alibaba.com LLC
First Seen
Jun 17, 2024
Last Seen
Feb 16, 2026
Jun 17
First Seen
723d ago
Feb 16
Last Seen
115d ago
12
Reports
source reports
99%
Confidence
medium
8/91
VirusTotal
detections
Found in 12 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
99%
Signal Score
100 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

45 techniques

Network Information

CountryCNChina
RegionShenzhen, GD
ASNAS37963
OrganizationAlibaba.com LLC

Feed Intelligence Summary

12 reports99% confidence
12
Source reports
99%
Confidence score
Category tags
active scanningapixaptasiaasyncratbianlianbotnetbrazilc2c2 domainc2 frontedc2 frontingcensyschinacncobalt strikecobaltstrikecommand and controlcommunication protocolcredential harvestingdata encryptiondata exfiltrationdcratdistributed attackseuropeeurope/asiaextortionfronted domainfronting domaingo trojanhackinghak5_cloud_c2havochttp scannerhttpsindicatorinfrastructure acquisitionreconnaissanceiocitalymalicious filemalicious linksmalicious softwaremalwaremanualmd5mozimythicmythic ipnetsupportratnetworkphishingphishing attackpossible cobaltpossible dcratpossible deimospossible havocpossible pupypossible qakbotpossible sliverpossible viperprocess injectionpushqakbotquasarransomwareratrat ipreconnaissanceremcos trojanremote accessremote servicesresearchedreverse_sshrussiascannersecurity operationssha valuessliversocial engineeringsocial media exploitationsouth americastrike c2supershellsystem disruptiont1005t1016t1021t1021.001t1027t1036t1047t1053t1055t1059t1059.001t1059.003t1068t1071t1071.001t1078t1083t1105t1190t1204t1204.001t1486t1490t1496t1499.002t1499.003t1547t1565t1566t1566.001t1566.002t1566.003t1569.002t1572t1583t1584t1587.001t1588t1590.001t1592t1595t1595.001t1595.002t1595.003t1598threat intelligenceturkeyukraineurlhausurls httpurls httpsvulnerabilityweb securityweb traffic

Activity Timeline

1 total obs
Feb 16Feb 16

Threat Activity Heatmap

· Peak: 2026-02-16
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Threat ScoreHigh Risk
100
SIGNAL
Signal Score
99%
Confidence
12
Reports
First seenJun 17, 2024
Last seenFeb 16, 2026
GeolocationCN
CountryChina
LocationShenzhen, GD
ASNAS37963
OrgAlibaba.com LLC
Coords22.5318, 114.1374

VirusTotal

8/ 91vendors flagged
9% detection rateJun 8, 2026

WHOIS

description
ip:port combination that is used for botnet Command&control (C&C)
raw
inetnum: 47.120.0.0 - 47.127.255.255 netname: ALISOFT descr: Aliyun Computing Co., LTD descr: 5F, Builing D, the West Lake International Plaza of S&T descr: No.391 Wen'er Road, Hangzhou, Zhejiang, China, 310099 country: CN admin-c: ZM1015-AP tech-c: ZM877-AP tech-c: ZM876-AP tech-c: ZM875-AP abuse-c: AC1601-AP status: ALLOCATED PORTABLE mnt-by: MAINT-CNNIC-AP mnt-irt: IRT-CNNIC-CN last-modified: 2022-09-04T21:47:58Z source: APNIC irt: IRT-CNNIC-CN address: Beijing, China e-mail: [email protected] abuse-mailbox: [email protected] admin-c: IP50-AP tech-c: IP50-AP auth: # Filtered remarks: Please note that CNNIC is not an ISP and is not remarks: empowered to investigate complaints of network abuse. remarks: Please contact the tech-c or admin-c of the network. remarks: [email protected] is invalid mnt-by: MAINT-CNNIC-AP last-modified: 2025-09-19T17:19:56Z source: APNIC role: ABUSE CNNICCN country: ZZ address: Beijing, China phone: +000000000 e-mail: [email protected] admin-c: IP50-AP tech-c: IP50-AP nic-hdl: AC1601-AP remarks: Generated from irt object IRT-CNNIC-CN remarks: [email protected] is invalid abuse-mailbox: [email protected] mnt-by: APNIC-ABUSE last-modified: 2025-09-19T17:20:32Z source: APNIC person: Li Jia address: NO.969 West Wen Yi Road, Yu Hang District, Hangzhou country: CN phone: +86-0571-85022088 e-mail: [email protected] nic-hdl: ZM1015-AP mnt-by: MAINT-CNNIC-AP last-modified: 2025-07-01T07:12:42Z source: APNIC person: Guoxin Gao address: 5F, Builing D, the West Lake International Plaza of S&T address: No.391 Wen'er Road, Hangzhou City address: Zhejiang, China, 310099 country: CN phone: +86-0571-85022600 fax-no: +86-0571-85022600 e-mail: [email protected] nic-hdl: ZM875-AP mnt-by: MAINT-CNNIC-AP last-modified: 2014-07-30T01:56:01Z source: APNIC person: security trouble e-mail: [email protected] address: 5th,floor,Building D,the West Lake International Plaza of S&T,391#Wen??r Road address: Hangzhou, Zhejiang, China phone: +86-0571-85022600 country: CN mnt-by: MAINT-CNNIC-AP nic-hdl: ZM876-AP last-modified: 2025-07-01T07:06:11Z source: APNIC person: Guowei Pan address: 5F, Builing D, the West Lake International Plaza of S&T address: No.391 Wen'er Road, Hangzhou City address: Zhejiang, China, 310099 country: CN phone: +86-0571-85022088-30763 fax-no: +86-0571-85022600 e-mail: [email protected] nic-hdl: ZM877-AP mnt-by: MAINT-CNNIC-AP last-modified: 2025-07-01T07:05:46Z source: APNIC route: 47.121.120.0/24 descr: Alibaba (US) Technology Co., Ltd. origin: AS37963 mnt-by: MAINT-CNNIC-AP last-modified: 2020-07-10T06:00:34Z source: APNIC route: 47.121.120.0/24 descr: Alibaba (US) Technology Co., Ltd. origin: AS45102 mnt-by: MAINT-CNNIC-AP last-modified: 2020-07-10T06:02:50Z source: APNIC
references
https://any.run/malware-trends/, https://urlhaus.abuse.ch/, https://threatfox.abuse.ch/export/csv/recent/, https://x.com/drb_ra/status/1910148738238054618, https://x.com/drb_ra/status/1910222573872284010, https://x.com/drb_ra/status/1910222598555791704, https://x.com/drb_ra/status/1910222624833090030, https://x.com/drb_ra/status/1910222648249823375, https://x.com/drb_ra/status/1910223168997896487, https://x.com/drb_ra/status/1910223189940019501, https://x.com/drb_ra/status/1910223210899009772, https://x.com/drb_ra/status/1910223232046612770, https://x.com/drb_ra/status/1910223253550801021, https://x.com/drb_ra/status/1910223275159937220, https://x.com/drb_ra/status/1910223296173387977, https://x.com/drb_ra/status/1910223317396500959, https://x.com/drb_ra/status/1910223338535891048, https://x.com/drb_ra/status/1910223370530025889, https://x.com/drb_ra/status/1910223402335416334, https://x.com/drb_ra/status/1910223428923142243, https://x.com/drb_ra/status/1910223456081228153, https://x.com/drb_ra/status/1910223479460274522, https://x.com/drb_ra/status/1910223504219263198, https://x.com/drb_ra/status/1910223528525254947, https://x.com/drb_ra/status/1910224046899319245, https://x.com/drb_ra/status/1910224065631056223, https://x.com/drb_ra/status/1910242292251664433, https://x.com/drb_ra/status/1910283271977460203, https://x.com/drb_ra/status/1910283291271327953, https://x.com/drb_ra/status/1910283309977907389, https://x.com/drb_ra/status/1910283327656894895, https://x.com/drb_ra/status/1910283345998528679, https://x.com/drb_ra/status/1910283365506297867, https://x.com/drb_ra/status/1910287422606242092, https://x.com/drb_ra/status/1910287440805245424, https://x.com/drb_ra/status/1910287458790482197, https://x.com/drb_ra/status/1910287477320843603, https://x.com/drb_ra/status/1910287496388260190, https://x.com/drb_ra/status/1910403813460078602, https://x.com/drb_ra/status/1910403831260684574, https://x.com/drb_ra/status/1910403848407240758, https://x.com/drb_ra/status/1910403866161471601, https://x.com/drb_ra/status/1910404383302430738, https://x.com/drb_ra/status/1910404401082360188, https://x.com/drb_ra/status/1910404419058819434, https://x.com/drb_ra/status/1910404437455077693, https://x.com/drb_ra/status/1910404456585498790, https://x.com/drb_ra/status/1910404475208294614, https://x.com/drb_ra/status/1910404494682448186, https://x.com/drb_ra/status/1910404515649511442, https://x.com/drb_ra/status/1910404536574869757, https://x.com/drb_ra/status/1910404558561362245, https://x.com/drb_ra/status/1910404579415511478, https://x.com/drb_ra/status/1910404601183895801, https://x.com/drb_ra/status/1910404622084170174, https://x.com/drb_ra/status/1910404642879455664, https://x.com/drb_ra/status/1910404666128560450, https://x.com/drb_ra/status/1910404687083294964, https://x.com/drb_ra/status/1910404708620972467, https://x.com/drb_ra/status/1910404730201002244, https://x.com/drb_ra/status/1910404751340064975, https://x.com/drb_ra/status/1910404772412452915, https://x.com/drb_ra/status/1910404792981348787, https://x.com/drb_ra/status/1910405311867097514, https://x.com/drb_ra/status/1910405331232186577, https://x.com/drb_ra/status/1910405352404766782, https://x.com/drb_ra/status/1910405373129064764, https://x.com/drb_ra/status/1910405394700394935, https://x.com/drb_ra/status/1910405416669892646, https://x.com/drb_ra/status/1910424181424177566, https://x.com/drb_ra/status/1910424200130478579, https://x.com/drb_ra/status/1910424220007309729

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 2 years ago · Last seen 3 months ago
Appeared in 12 threat reports