IOC Radar
IPMediumSignal 43/100

47.92.27.213

Location
ChinaChina
Beijing, BJ
ASN
AS37963
Aliyun Computing Co., LTD
First Seen
Jul 7, 2024
Last Seen
Apr 29, 2026
Jul 7
First Seen
715d ago
Apr 29
Last Seen
53d ago
16
Reports
source reports
43%
Confidence
medium
Found in 16 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
43%
Signal Score
43 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

52 techniques

Network Information

CountryCNChina
RegionBeijing, BJ
ASNAS37963
OrganizationAliyun Computing Co., LTD

Feed Intelligence Summary

16 reports43% confidence
16
Source reports
43%
Confidence score
Category tags
abuseaccessaccess controlactionactive scanactive scanningadbhoney honeypotasiaattackauto-generated securitybad reputationbanner grabbing attemptbotnetbotnet activitybrute forcebrute force attackbrute force attacksc2certchinacncommand & controlcommand and controlcommunication protocolcompromise attemptconfigconnectcowriecowrie honeypotcowrie ssh attackscredential accesscredential harvestingcredential stuffingcssdata exfiltrationdata store exposuredatabase enumerationdatabase securityddosdecoy systemdenial of servicedionaeadionaea honeypotdionaea malware detectiondistributed attacksemailexecutable fileexploitexploit attemptexploit attemptsexploitation activityfailed loginfin scanftpftp brute forcegithubgroupshoneytrap honeypotidentity & access exploitationindicatorinfoinfrastructure acquisitionreconnaissanceinitial accessinjection activitylamplateral movementlinuxlogin attemptmailoney honeypotmalicious activitymalicious softwaremalicious trafficmalwaremalware behaviourmalware capturemanualmass scanning activitynetworknetwork activitynetwork intrusion attemptsnetwork probingnetwork reconnaissancenetwork scannetwork scanningnetwork securitynull scanopen port detectionpassword attackpassword attacksphishingphishing attackphishing trappingpotential reconnaissance activitypotential vulnerability scanningprocess injectionpythonransomwarereconnaissanceredis honeypotredishoneypotresearchedresource hijackingrtbhscannerscriptsecurity policysentrypeer botnetserverservice discoveryservice enumerationservice scansftpsftp access attemptssftp attacksftp attemptsftp intrusion attemptsipsip brute forcesip scanningsip vulnerability exploitationslugsocial engineeringsocradarsshssh attackssh monitoringstealth scansurface websyn scant1016t1018t1021t1021.001t1021.002t1021.006t1040t1041t1046t1055t1059t1068t1071t1071.001t1078t1078.004t1083t1110t1110.001t1110.002t1110.003t1110.004t1133t1190t1203t1204.002t1486t1496t1499.001t1499.002t1499.003t1555t1565t1566t1566.001t1566.002t1566.003t1566.004t1587.001t1588t1588.002t1589t1589.001t1589.002t1590t1590.001t1590.002t1592t1595t1595.001t1595.002t1595.003tannertargeting databasetelecommunicationsthreat actorthreat detectionthreat intelligencethreat preventiontor nodeudp port scanvoipvoip attackvulnerability scanxmas scan

Activity Timeline

1 total obs
Apr 29Apr 29

Threat Activity Heatmap

· Peak: 2026-04-29
Less
More
Mon
Wed
Fri
Jun
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreMedium Risk
43
SIGNAL
Signal Score
43%
Confidence
16
Reports
First seenJul 7, 2024
Last seenApr 29, 2026
GeolocationCN
CountryChina
LocationBeijing, BJ
ASNAS37963
OrgAliyun Computing Co., LTD
Coords39.9285, 116.3850

VirusTotal

Not checked

WHOIS

description
2025-05-05T09:27:54.000Z Honeypot : Redishoneypot : Source: 47.92.27.213 : Port: 6379 Action: NewConnect Message:
raw
inetnum: 47.92.0.0 - 47.95.255.255 netname: ALISOFT descr: Aliyun Computing Co., LTD descr: 5F, Builing D, the West Lake International Plaza of S&T descr: No.391 Wen'er Road, Hangzhou, Zhejiang, China, 310099 country: CN admin-c: ZM1015-AP tech-c: ZM877-AP tech-c: ZM876-AP tech-c: ZM875-AP abuse-c: AC1601-AP status: ALLOCATED PORTABLE mnt-by: MAINT-CNNIC-AP mnt-irt: IRT-ALISOFT-CN last-modified: 2023-11-28T00:58:17Z source: APNIC irt: IRT-ALISOFT-CN address: No.391 Wen'er Road, Hangzhou, Zhejiang, China, 310099 e-mail: [email protected] abuse-mailbox: [email protected] auth: # Filtered admin-c: ZM877-AP tech-c: ZM877-AP mnt-by: MAINT-CNNIC-AP last-modified: 2021-09-05T23:38:36Z source: APNIC role: ABUSE CNNICCN country: ZZ address: Beijing, China phone: +000000000 e-mail: [email protected] admin-c: IP50-AP tech-c: IP50-AP nic-hdl: AC1601-AP remarks: Generated from irt object IRT-CNNIC-CN abuse-mailbox: [email protected] mnt-by: APNIC-ABUSE last-modified: 2024-07-30T11:55:46Z source: APNIC person: Li Jia address: NO.969 West Wen Yi Road, Yu Hang District, Hangzhou country: CN phone: +86-0571-85022088 e-mail: [email protected] nic-hdl: ZM1015-AP mnt-by: MAINT-CNNIC-AP last-modified: 2025-07-01T07:12:42Z source: APNIC person: Guoxin Gao address: 5F, Builing D, the West Lake International Plaza of S&T address: No.391 Wen'er Road, Hangzhou City address: Zhejiang, China, 310099 country: CN phone: +86-0571-85022600 fax-no: +86-0571-85022600 e-mail: [email protected] nic-hdl: ZM875-AP mnt-by: MAINT-CNNIC-AP last-modified: 2014-07-30T01:56:01Z source: APNIC person: security trouble e-mail: [email protected] address: 5th,floor,Building D,the West Lake International Plaza of S&T,391#Wen??r Road address: Hangzhou, Zhejiang, China phone: +86-0571-85022600 country: CN mnt-by: MAINT-CNNIC-AP nic-hdl: ZM876-AP last-modified: 2025-07-01T07:06:11Z source: APNIC person: Guowei Pan address: 5F, Builing D, the West Lake International Plaza of S&T address: No.391 Wen'er Road, Hangzhou City address: Zhejiang, China, 310099 country: CN phone: +86-0571-85022088-30763 fax-no: +86-0571-85022600 e-mail: [email protected] nic-hdl: ZM877-AP mnt-by: MAINT-CNNIC-AP last-modified: 2025-07-01T07:05:46Z source: APNIC route: 47.92.0.0/14 descr: Hangzhou Alibaba Advertising Co.,Ltd. country: CN origin: AS37963 mnt-by: MAINT-CNNIC-AP last-modified: 2019-08-07T23:28:06Z source: APNIC route: 47.92.0.0/14 descr: Alibaba (US) Technology Co., Ltd. country: CN origin: AS45102 mnt-by: MAINT-CNNIC-AP last-modified: 2019-08-07T23:28:04Z source: APNIC
references
https://github.com/telekom-security/tpotce, https://list.rtbh.com.tr/output.txt, http://cinsscore.com/list/ci-badguys.txt

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 1 month ago
Appeared in 16 threat reports