NC4 Public1

National Cyber Threat Level

Low

Moderate

Caution

High

Critical

vulnerable service

No IOC Descriptions AS Name
1 58.71.197.214 This host is most likely exposing a Dropbear SSH daemon, which is vulnerable to a cryptographic downgrade attack known as terrapin. MAXIS-AS1-AP Binariang Berhad
2 111.90.151.67 This host is most likely an Exim SMTP server vulnerable to remote code execution. SHINJIRU-MY-AS-AP Shinjiru Technology Sdn Bhd
3 47.250.49.11 This host is most likely vulnerable to remote code execution via a vulnerability known as "misfortune cookie". ALIBABA-CN-NET Alibaba US Technology Co.
4 47.254.242.222 This host is most likely vulnerable to remote code execution via a vulnerability known as "misfortune cookie". ALIBABA-CN-NET Alibaba US Technology Co.
5 47.254.247.28 This host is most likely vulnerable to remote code execution via a vulnerability known as "misfortune cookie". ALIBABA-CN-NET Alibaba US Technology Co.
6 2407:f800::fffe:0:d This host is most likely running a vulnerable HTTP service, which may be abused by a third party. EXTREMEBB-AS-MY Extreme Broadband - Total Broadband Experience
7 2402:2200:3000:63::10 This host is most likely running a vulnerable HTTP service, which may be abused by a third party. -
8 2402:2200:3001:1::4 This host is most likely running a vulnerable HTTP service, which may be abused by a third party. -
9 211.24.12.163 This host is most likely exposing a vulnerable version of OpenSSH server, which may be abused by a third party. TTNET-MY TIME dotCom Berhad No. 14
10 47.250.39.134 This server is running an outdated TLS implementation. The clients connecting to this service are potentially vulnerable to a Man-In-The-Middle attack a.k.a. FREAK. ALIBABA-CN-NET Alibaba US Technology Co.
11 60.53.41.26 This host is most likely exposing a Dropbear SSH daemon, which is vulnerable to a cryptographic downgrade attack known as terrapin. TTSSB-MY TM TECHNOLOGY SERVICES SDN. BHD.
12 49.124.154.8 This web application contains a version of the jquery framework, which is most likely vulnerable to XSS. DIGIIX-AP DiGi Telecommunications Sdn. Bhd.
13 180.73.237.130 This web application contains a version of the jquery framework, which is most likely vulnerable to XSS. TTSSB-MY TM TECHNOLOGY SERVICES SDN. BHD.
14 49.124.154.21 This web application contains a version of the jquery framework, which is most likely vulnerable to XSS. DIGIIX-AP DiGi Telecommunications Sdn. Bhd.
15 175.138.231.50 This web application contains a version of the jquery framework, which is most likely vulnerable to XSS. TTSSB-MY TM TECHNOLOGY SERVICES SDN. BHD.
16 121.120.219.193 This host is most likely running a version of Microsoft IIS web server, which is vulnerable to remote code execution. MAXIS-AS1-AP Binariang Berhad
17 211.25.202.188 This host is most likely running a version of Microsoft IIS web server, which is vulnerable to remote code execution. TTNET-MY TIME dotCom Berhad No. 14
18 219.92.14.18 This host is most likely running a version of MikroTik RouterOS, which is vulnerable to remote code execution. TTSSB-MY TM TECHNOLOGY SERVICES SDN. BHD.
19 210.186.92.124 This host is most likely exposing a Dropbear SSH daemon, which is vulnerable to a cryptographic downgrade attack known as terrapin. TTSSB-MY TM TECHNOLOGY SERVICES SDN. BHD.
20 203.142.36.60 This host is most likely exposing a Dropbear SSH daemon, which is vulnerable to a cryptographic downgrade attack known as terrapin. CNXNET-AS-MY REDtone
Insert title here