Host

120.26.166.249

Tags: Blocklisted Hosting

As of our latest check on 2026-09-23, 120.26.166.249 (Hangzhou Alibaba Advertising Co.,Ltd., AS37963, China) had 2 open ports (22, 8080) and no known CVEs. It is on 1 current blocklist.

Known CVEs on this host

2open ports
0names pointing here
0known CVEs
0known exploited

Open ports and CVEs as of our latest check of this host, 2026-09-23.

No known CVEs now

Not counted: 39 on a distribution build — the fix may be backported (openssh 8.0). See them

Network
Hangzhou Alibaba Advertising Co.,Ltd. AS37963
Open ports
22, 8080 · at our latest check, 2026-09-23
Location
China CN
Route
120.26.0.0/16 · announced by Hangzhou Alibaba Advertising Co.,Ltd. AS37963 RPKI valid
Organisation
Alibaba Group · Content / hosting
Registry network
ALISOFT · 120.24.0.0 - 120.27.255.255 · APNIC
Abuse contact
[email protected] · for ALISOFT
First seen
2026-09-23 14:16 UTC
Last seen alive
2026-09-23 14:20 UTC
Hosted domains
No host name points here

Reputation

Blocklists
blocklisted on 1 current list About blocklists
ListCategoryListed networkSince
hosts serving malware downloads · CobaltStrike,shellcode malware distribution 120.26.166.249/32:8080 2024-12-04

Services (2)

22/tcp SSH OpenSSH_8.0 first 2026-09-23 · last 2026-09-23
Server
SSH-2.0-OpenSSH_8.0
Host key
ssh-ed25519 d0795204f0d4dcdb…
Raw response
SSH-2.0-OpenSSH_8.0
8080/tcp HTTP first 2026-09-23 · last 2026-09-23
Status
200
Raw response
HTTP/1.1 200 
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
X-Content-Type-Options: nosniff
X-XSS-Protection: 0
X-Frame-Options: SAMEORIGIN
Content-Type: text/plain;charset=UTF-8
Content-Length: 92
Date: Wed, 23 Sep 2026 14:16:42 GMT

欢迎使用RuoYi后台管理框架,当前版本:v3.9.2,请通过前端地址访问。
Distribution build — the fix may be backported (39)

These CVEs were matched on software built by an operating-system distribution whose package revision the service does not show. Distributions often fix a flaw without changing the upstream version number, so whether this build is affected cannot be told from its version. They are not counted.

CVEs by severity: CRITICAL 1 HIGH 7 MEDIUM 15 LOW 16

CVESoftware
CVE-2023-38408 CRITICAL 9.8 openssh 8.0 · port 22
CVE-2026-35385 HIGH 8.1 openssh 8.0 · port 22
CVE-2026-35414 HIGH 8.1 openssh 8.0 · port 22
CVE-2019-16905 HIGH 7.8 openssh 8.0 · port 22
CVE-2026-60002 HIGH 7.7 openssh 8.0 · port 22
CVE-2026-60000 HIGH 7.5 openssh 8.0 · port 22
CVE-2020-15778 HIGH 7.4 openssh 8.0 · port 22
CVE-2021-41617 HIGH 7.0 openssh 8.0 · port 22
CVE-2025-26465 MEDIUM 6.8 openssh 8.0 · port 22
CVE-2023-51385 MEDIUM 6.5 openssh 8.0 · port 22
CVE-2026-106585 MEDIUM 6.5 openssh 8.0 · port 22
CVE-2026-35387 MEDIUM 6.5 openssh 8.0 · port 22
CVE-2026-59998 MEDIUM 6.5 openssh 8.0 · port 22
CVE-2026-60001 MEDIUM 6.5 openssh 8.0 · port 22
CVE-2020-14145 MEDIUM 5.9 openssh 8.0 · port 22
CVE-2023-48795 MEDIUM 5.9 openssh 8.0 · port 22
CVE-2026-59999 MEDIUM 5.9 openssh 8.0 · port 22
CVE-2026-59995 MEDIUM 5.4 openssh 8.0 · port 22
CVE-2026-59996 MEDIUM 5.4 openssh 8.0 · port 22
CVE-2026-59997 MEDIUM 5.4 openssh 8.0 · port 22
CVE-2016-20012 MEDIUM 5.3 openssh 8.0 · port 22
CVE-2026-73282 MEDIUM 4.8 openssh 8.0 · port 22
CVE-2026-106552 MEDIUM 4.2 openssh 8.0 · port 22
CVE-2025-32728 LOW 3.8 openssh 8.0 · port 22
CVE-2021-36368 LOW 3.7 openssh 8.0 · port 22
CVE-2026-106582 LOW 3.7 openssh 8.0 · port 22
CVE-2025-61984 LOW 3.6 openssh 8.0 · port 22
CVE-2025-61985 LOW 3.6 openssh 8.0 · port 22
CVE-2026-73281 LOW 3.5 openssh 8.0 · port 22
CVE-2026-106587 LOW 3.3 openssh 8.0 · port 22
CVE-2026-106588 LOW 3.1 openssh 8.0 · port 22
CVE-2026-106589 LOW 2.9 openssh 8.0 · port 22
CVE-2026-106583 LOW 2.5 openssh 8.0 · port 22
CVE-2026-106584 LOW 2.5 openssh 8.0 · port 22
CVE-2026-106586 LOW 2.5 openssh 8.0 · port 22
CVE-2026-35388 LOW 2.5 openssh 8.0 · port 22
CVE-2026-73283 LOW 2.5 openssh 8.0 · port 22
CVE-2026-106553 LOW 2.2 openssh 8.0 · port 22
CVE-2026-106555 LOW 2.2 openssh 8.0 · port 22

Port history

Every port that has answered a connection on this address, and when. A port is listed as open above only when a service was identified on it. Times are UTC.