IPMediumSignal 37/100
8.148.6.140
Location
Hangzhou, Zhejiang
ASN
AS37963
Alibaba.com LLC
First Seen
Jan 9, 2025
Last Seen
Apr 7, 2026
Found in 11 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
37%
Signal Score
37 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Network Information
Country
China
RegionHangzhou, Zhejiang
ASNAS37963
OrganizationAlibaba.com LLC
Feed Intelligence Summary
11 reports37% confidence
11
Source reports
37%
Confidence score
Category tags
active scanadversary simulation toolaptasiabeaconbeaconing activitybotnetbotnet activitybrute forcec2c2 frameworkchinacncobaltstrikecommand & controlcommand and controlcredential harvestingcredential stuffingdata exfiltrationdata store exposuredistributed attacksexploitation activityidentity & access exploitationindicatorinfrastructure acquisitionreconnaissanceinjection activitylateral movementlateral movement techniquesmalicious softwaremalwaremanualnetworkpayload deploymentpayload generationpenetration testing toolphishingphishing attackpost-exploitationpost-exploitation activitiesprocess injectionransomwareresearchedsingaporesocial engineeringt1003t1016t1018t1027t1041t1047t1055t1059t1059.001t1071t1071.001t1078t1083t1090t1090.001t1105t1190t1210t1486t1496t1499.002t1499.003t1565t1566.001t1566.002t1566.003t1567t1573t1573.001t1587.001t1590.001threat actortor node
Activity Timeline
Apr 7Apr 7
Threat Activity Heatmap
· Peak: 2026-04-07LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreLow Risk
37
SIGNAL
Signal Score
37%
Confidence
11
Reports
First seenJan 9, 2025
Last seenApr 7, 2026
GeolocationCN
CountryChina
LocationHangzhou, Zhejiang
ASNAS37963
OrgAlibaba.com LLC
Coords1.3673, 103.8014
VirusTotal
Not checked
WHOIS
- raw
- inetnum: 8.128.0.0 - 8.159.255.255 netname: ALICLOUD descr: Aliyun Computing Co.LTD country: CN admin-c: ASEP1-AP tech-c: ASEP1-AP abuse-c: AA1926-AP status: ALLOCATED NON-PORTABLE mnt-by: MAINT-ASEPL-SG mnt-irt: IRT-ASEPL-SG last-modified: 2021-04-14T01:11:45Z source: APNIC irt: IRT-ASEPL-SG address: 1 Raffles Place # 59-00 One Raffles Place, Tower One Singapore, Singapore e-mail: [email protected] abuse-mailbox: [email protected] admin-c: ASEP1-AP tech-c: ASEP1-AP auth: # Filtered remarks: [email protected] was validated on 2024-10-08 mnt-by: MAINT-ASEPL-SG last-modified: 2024-10-08T07:53:08Z source: APNIC role: ABUSE ASEPLSG country: ZZ address: 1 Raffles Place # 59-00 One Raffles Place, Tower One Singapore, Singapore phone: +000000000 e-mail: [email protected] admin-c: ASEP1-AP tech-c: ASEP1-AP nic-hdl: AA1926-AP remarks: Generated from irt object IRT-ASEPL-SG remarks: [email protected] was validated on 2024-10-08 abuse-mailbox: [email protected] mnt-by: APNIC-ABUSE last-modified: 2024-10-08T08:00:34Z source: APNIC role: Alibabacom Singapore E-Commerce Private Limited a address: 1 Raffles Place #59-00 One Raffles Place, Tower One Singapore, Singapore country: SG phone: +86-571-85022088 fax-no: +86-571-85022088 e-mail: [email protected] admin-c: ASEP1-AP tech-c: ASEP1-AP nic-hdl: ASEP1-AP mnt-by: MAINT-ASEPL-SG last-modified: 2015-12-10T01:04:19Z source: APNIC route: 8.148.6.0/24 origin: AS37963 descr: Alibaba.com Singapore E-Commerce Private Limited 8 Shenton Way, #45-01 AXA Tower, Singapore 068811 mnt-by: MAINT-ASEPL-SG last-modified: 2020-02-25T10:06:07Z source: APNIC
- references
- https://threatfox.abuse.ch/export/csv/recent/
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 1 year ago · Last seen 2 months ago
Appeared in 11 threat reports