High-Risk NTP Servers and the Quiet Risks to Internet Time
Protective Intelligence Brief — Quantitative Security
The Network Time Protocol (NTP) Pool is one of the internet’s quietest critical infrastructures. It supplies accurate time to hundreds of millions of devices—from consumer routers and IoT systems to enterprise servers and cloud platforms. The pool relies almost entirely on volunteer operators who donate bandwidth and server capacity. While this distributed model has proven remarkably resilient, it also creates persistent security and reliability risks.
In late July 2026, a detailed reconnaissance session targeting vendor-specific NTP Pool zones (
,
, and related hosts) revealed a collection of volunteer servers with significant security deficiencies. Although none of the examined hosts could be definitively tied to active threat-actor infrastructure at the time of analysis, several exhibited configurations that make them high-value targets for compromise, abuse, or covert use. This brief examines those findings and the broader implications for organizations that depend on public time sources.
Background: How the NTP Pool Works
The NTP Pool uses GeoDNS to return a rotating set of volunteer servers based on the client’s approximate location. Vendor-specific zones further segment traffic for particular device populations. Servers are monitored for accuracy and responsiveness, but the monitoring system has known limitations, and participation requirements remain relatively low.
Historically, poorly configured NTP servers were heavily abused for amplification DDoS attacks. While the number of vulnerable amplifiers has declined sharply, the protocol and the pool itself continue to present opportunities for more sophisticated abuse, including covert command-and-control channels and monitoring-system deception.
Case Study Findings
A comprehensive session enumerated more than 140 unique IP addresses and dozens of associated domains and hostnames. Categories included primary NTP Pool participants, residential hosts also answering pool queries, professional colo and cloud VPS members, extensive transit infrastructure, and large numbers of enterprise email-security hosts.
Complete unique IP inventory observed:
0.3.1.1
1.10.20.172
1.112.95.208
101.5.54.154
105.47.54.154
106.22.12.49
108.61.215.221
109.234.111.200
109.40.54.154
110.207.250.129
110.95.54.154
125.168.32.38
126.204.250.129
129.250.2.159
129.250.204.126
129.250.204.214
129.250.207.110
129.250.3.243
129.250.3.29
129.250.4.238
129.250.5.208
129.250.5.246
129.250.9.164
13.43.54.154
133.237.239.213
139.177.202.26
140.222.19.237
143.42.229.153
143.42.229.154
150.189.179.152
152.179.189.150
153.5.54.154
154.24.38.166
154.54.161.30
154.54.163.205
154.54.164.230
154.54.165.25
154.54.165.29
154.54.166.57
154.54.166.69
154.54.169.2
154.54.169.65
154.54.40.109
154.54.40.250
154.54.41.54
154.54.43.13
154.54.43.9
154.54.44.85
154.54.45.161
154.54.47.105
154.54.5.101
154.54.5.153
154.54.82.206
154.54.82.210
154.54.95.110
154.54.95.98
159.2.250.129
159.203.82.102
161.45.54.154
164.65.33.45
164.9.250.129
165.160.32.149
166.38.24.154
172.233.177.198
172.235.154.118
177.169.83.69
183.160.83.69
186.169.83.69
190.44.0.192
192.0.32.59
192.0.47.59
192.161.83.69
192.205.36.61
192.30.45.30
192.34.234.30
198.12.222.208
2.169.54.154
2.48.58.38
205.163.54.154
206.82.54.154
207.58.172.126
208.5.250.129
208.91.196.105
208.95.112.1
209.1.54.154
210.82.54.154
214.204.250.129
216.229.0.49
216.240.36.24
216.250.115.174
221.215.61.108
23.168.24.210
23.186.168.131
230.164.54.154
237.19.222.140
238.4.250.129
24.36.240.216
242.14.28.99
243.3.250.129
246.5.250.129
25.165.54.154
250.40.54.154
29.165.54.154
29.3.250.129
30.161.54.154
30.234.34.192
37.169.54.154
38.32.168.125
38.58.48.2
4.10.20.172
45.33.53.84
45.33.65.164
49.0.229.216
49.12.22.106
54.215.111.135
54.41.54.154
57.166.54.154
59.32.0.192
59.47.0.192
61.36.205.192
64.69.216.61
64.99.62.11
65.169.54.154
66.175.236.237
66.187.4.132
67.215.249.229
67.231.157.136
68.94.159.98
69.10.208.170
69.166.54.154
69.83.160.183
69.83.161.192
69.83.169.177
69.83.169.186
69.89.207.199
75.19.222.140
80.153.195.191
80.239.221.134
85.44.54.154
9.43.54.154
98.159.94.68
98.95.54.154
99.28.14.242
Domains and hostnames observed:
Multiple NTT router hostnames (
ae-17.a04.lsanca07.us.bb.gin.ntt.net
,
ae-2.r26.snjsca04.us.bb.gin.ntt.net
,
ae-20.a03.sttlwa01.us.bb.gin.ntt.net
,
ce-0-2-2.a03.sttlwa01.us.ce.gin.ntt.net
, and related)
Extensive Proofpoint infrastructure (
through
, mx0a-, mx0b-, mx0d-, pe-,
mx1.proofpoint.com.gslb.pphosted.com
,
mx2.proofpoint.com.gslb.pphosted.com
, and others)
Highest-risk host details
216.240.36.24 (
)Nmap surface:
21/tcp open tcpwrapped
22/tcp open ssh OpenSSH 6.6 (protocol 2.0)
25/tcp open smtp Sendmail 8.15.1
37/tcp open time
80/tcp open http Apache httpd 2.4.10
111/tcp open rpcbind 2-4 (RPC #100000)
113/tcp open ident?
143/tcp open imap?
443/tcp open ssl/http Apache httpd 2.4.10 ((Mageia))
587/tcp open smtp Sendmail 8.15.1
993/tcp open imaps?
995/tcp open tcpwrapped
3306/tcp open mysql MariaDB 5.5.5-10.0.36
OS guess Mageia Linux. Estimated uptime approximately 419 days. Low-profile volunteer with no clear public individual attribution beyond the hostname.
99.28.14.242 (
)
AT&T residential (Lightspeed), Indianapolis, IN (AS7018). Domain registered 2014 via Namecheap. Ports observed: 21, 80 (302 redirect to HTTPS), 81, 443. Service: Apache Guacamole remote desktop gateway, build stamp 20240330042611 (1.5.x series). QSecPulse risk score 90 driven by risky open ports. PTR consistent with residential assignment (
99-28-14-242.lightspeed.iplsin.sbcglobal.net
).
Supporting pool members
216.229.0.49 (
) — Binary Net LLC, Lincoln, Nebraska. Data center inside former Federal Reserve vault. Only port 21 observed open. Clean long-term NTP Pool participant.
108.61.215.221 (Vultr) and 143.42.229.154 / 143.42.229.153 (Linode/Akamai) — standard cloud VPS members with limited surface.
HTML content recovered via QSecPulse clones
Guacamole application (build 20240330042611):
<!doctype html>
<html ng-app="index" ng-controller="indexController">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<meta name="build" content="20240330042611">
<link rel="stylesheet" href="1.guacamole.6f7b293d2dba5a891aa5.css">
<link rel="stylesheet" href="app.css?b=20240330042611">
<title ng-bind="page.title | translate"></title>
</head>
<body ng-cloak translate-cloak ng-class="page.bodyClassName" ng-switch="applicationState">
<div class="logged-out-modal" ng-switch-when="loggedOut">
<guac-modal>
<div class="notification">
<p translate="
_LOGGED_OUT"></p>
<p><button translate="APP.ACTION_LOGIN_AGAIN" ...></button></p>
</div>
</guac-modal>
</div>
<!-- Additional states: fatalError, automaticLoginRejected, awaitingCredentials, ready -->
<guac-login ng-switch-when="awaitingCredentials" ...></guac-login>
<script src="guacamole-common-js/all.min.js"></script>
<script src="angular.min.js"></script>
<script src="1.guacamole.7935cf403412cd79c600.js"></script>
<script src="app.js?b=20240330042611"></script>
</body>
</html>
Export Worldwide /
(
collision):
<title>Inbound international SEO tool and Multilingual content marketing platform | Export Worldwide</title>
<meta name="generator" content="Jekyll v4.0.1" />
<meta name="description" content="Export Worldwide, an inbound international SEO tool and Multilingual content marketing platform..." />
<meta property="og:site_name" content="Export Worldwide" />
{"url":"
","name":"Export Worldwide",...}
<img src="
https://www.exhol.com/assets/images/eww-logo-50.png
" ... />
Copyright © Export Worldwide 2020
ntpviz page:
<title>ntpviz</title>
<h1 style="margin-bottom:10px;">ntpviz</h1>
Additional fragments included default Caddy pages (<title>Caddy works!</title>), 302 Found redirects, and a redirect target of
(Austrian jazz/rock band site — pure content collision).
Cross-Reference Against Known Actors and IOCs
Cross-referencing the full set of IPs and domains against public threat intelligence sources produced no high-confidence active IOC or named threat-actor attributions for the primary hosts.
99.28.14.242 /
— no current public listings as C2, malware distribution, or attributed infrastructure.
216.240.36.24 /
— appears only as a normal (if poorly maintained) NTP Pool volunteer.
216.229.0.49 /
— clean professional participant.
/
— resolves to the Humane Society of Harrisburg Area (benign animal-shelter organization, domain registered 2003).
Supporting Vultr and Linode addresses — no current high-confidence hits; only historical low-confidence port-scan noise on nearby addresses.
Guacamole and similar remote-access tools remain a heavily abused class for initial access and persistence in ransomware and espionage campaigns. NTP itself continues to appear in research on amplification and rare C2-over-NTP techniques. None of the specific hosts in this session were linked to current high-profile actors (LAUNDRY BEAR / Void Blizzard, UAT-11795, Squidoor, Cloud Atlas, Sandworm RDP campaigns, or others reviewed).
Implications
Direct compromise risk
Servers running OpenSSH 6.6, decade-old database software, and outdated Apache versions remain vulnerable to well-documented remote and privilege-escalation exploits. Once compromised, an NTP server can be used for covert C2 channels that blend with legitimate time traffic, amplification or reflection attacks, lateral movement into the operator’s broader network, or manipulation of time data returned to clients—with cascading effects on authentication, logging, and certificate validation.
Ecosystem trust and monitoring weaknesses
The NTP Pool’s monitoring system has been shown in research to be susceptible to deception. A sophisticated adversary who can influence or impersonate monitoring checks could potentially remove legitimate servers or inflate the visibility of malicious ones. The voluntary nature of participation means many operators lack dedicated security resources.
Residential and hybrid exposure
The presence of a residential Guacamole instance answering pool queries demonstrates how personal remote-access infrastructure can become entangled with critical public services, expanding the attack surface for both the individual operator and any systems that rely on that time source.
Broader abuse patterns
Public reporting continues to document ransomware and APT groups abusing legitimate remote-access and RMM tools, occasional use of NTP as a stealthy C2 medium, and residual amplification potential on misconfigured servers. While the specific hosts examined showed no active attribution to known threat actors, they exemplify the conditions under which such abuse becomes feasible.
Recommendations
For NTP Pool operators
Maintain current, supported software versions. Restrict management interfaces (SSH, databases, web panels) to trusted networks or require strong authentication and multi-factor controls. Separate the NTP service from other applications whenever possible. Monitor for unexpected processes, open ports, and certificate anomalies.
For organizations relying on the pool
Prefer authenticated time sources (NTS) where available. Maintain internal stratum-1 or stratum-2 servers as primary references. Monitor outbound NTP destinations and query patterns for anomalies. Treat sudden changes in resolved pool members as a potential indicator.
For the broader ecosystem
Continue strengthening monitoring and scoring systems against deception. Encourage or require minimum security baselines for participation. Expand visibility into IPv6 and vendor-specific zones.
Closing
The reconnaissance did not uncover confirmed, actively compromised NTP servers attributed to known threat actors. It did surface multiple high-risk configurations—including long-uptime servers running end-of-life software and a residential remote-desktop gateway answering public time queries—that illustrate enduring structural weaknesses in the volunteer-based time infrastructure that underpins much of the internet.
As long as critical services depend on under-resourced volunteer operators running outdated software, the potential for compromise, covert abuse, and cascading failures remains real. Hardening individual servers, improving monitoring, and reducing reliance on purely unauthenticated public pool members are necessary steps to protect the integrity of global time synchronization.
Quantitative Security
Protective intelligence • Threat hunting • Custom tooling