High-Risk NTP Servers and the Quiet Risks to Internet Time

Protective Intelligence Brief — Quantitative Security

The Network Time Protocol (NTP) Pool is one of the internet’s quietest critical infrastructures. It supplies accurate time to hundreds of millions of devices—from consumer routers and IoT systems to enterprise servers and cloud platforms. The pool relies almost entirely on volunteer operators who donate bandwidth and server capacity. While this distributed model has proven remarkably resilient, it also creates persistent security and reliability risks.

In late July 2026, a detailed reconnaissance session targeting vendor-specific NTP Pool zones (

2.fedora.pool.ntp.org

,

amazon.pool.ntp.org

, and related hosts) revealed a collection of volunteer servers with significant security deficiencies. Although none of the examined hosts could be definitively tied to active threat-actor infrastructure at the time of analysis, several exhibited configurations that make them high-value targets for compromise, abuse, or covert use. This brief examines those findings and the broader implications for organizations that depend on public time sources.

Background: How the NTP Pool Works

The NTP Pool uses GeoDNS to return a rotating set of volunteer servers based on the client’s approximate location. Vendor-specific zones further segment traffic for particular device populations. Servers are monitored for accuracy and responsiveness, but the monitoring system has known limitations, and participation requirements remain relatively low.

Historically, poorly configured NTP servers were heavily abused for amplification DDoS attacks. While the number of vulnerable amplifiers has declined sharply, the protocol and the pool itself continue to present opportunities for more sophisticated abuse, including covert command-and-control channels and monitoring-system deception.

Case Study Findings

A comprehensive session enumerated more than 140 unique IP addresses and dozens of associated domains and hostnames. Categories included primary NTP Pool participants, residential hosts also answering pool queries, professional colo and cloud VPS members, extensive transit infrastructure, and large numbers of enterprise email-security hosts.

Complete unique IP inventory observed:

  • 0.3.1.1

  • 1.10.20.172

  • 1.112.95.208

  • 101.5.54.154

  • 105.47.54.154

  • 106.22.12.49

  • 108.61.215.221

  • 109.234.111.200

  • 109.40.54.154

  • 110.207.250.129

  • 110.95.54.154

  • 125.168.32.38

  • 126.204.250.129

  • 129.250.2.159

  • 129.250.204.126

  • 129.250.204.214

  • 129.250.207.110

  • 129.250.3.243

  • 129.250.3.29

  • 129.250.4.238

  • 129.250.5.208

  • 129.250.5.246

  • 129.250.9.164

  • 13.43.54.154

  • 133.237.239.213

  • 139.177.202.26

  • 140.222.19.237

  • 143.42.229.153

  • 143.42.229.154

  • 150.189.179.152

  • 152.179.189.150

  • 153.5.54.154

  • 154.24.38.166

  • 154.54.161.30

  • 154.54.163.205

  • 154.54.164.230

  • 154.54.165.25

  • 154.54.165.29

  • 154.54.166.57

  • 154.54.166.69

  • 154.54.169.2

  • 154.54.169.65

  • 154.54.40.109

  • 154.54.40.250

  • 154.54.41.54

  • 154.54.43.13

  • 154.54.43.9

  • 154.54.44.85

  • 154.54.45.161

  • 154.54.47.105

  • 154.54.5.101

  • 154.54.5.153

  • 154.54.82.206

  • 154.54.82.210

  • 154.54.95.110

  • 154.54.95.98

  • 159.2.250.129

  • 159.203.82.102

  • 161.45.54.154

  • 164.65.33.45

  • 164.9.250.129

  • 165.160.32.149

  • 166.38.24.154

  • 172.233.177.198

  • 172.235.154.118

  • 177.169.83.69

  • 183.160.83.69

  • 186.169.83.69

  • 190.44.0.192

  • 192.0.32.59

  • 192.0.47.59

  • 192.161.83.69

  • 192.205.36.61

  • 192.30.45.30

  • 192.34.234.30

  • 198.12.222.208

  • 2.169.54.154

  • 2.48.58.38

  • 205.163.54.154

  • 206.82.54.154

  • 207.58.172.126

  • 208.5.250.129

  • 208.91.196.105

  • 208.95.112.1

  • 209.1.54.154

  • 210.82.54.154

  • 214.204.250.129

  • 216.229.0.49

  • 216.240.36.24

  • 216.250.115.174

  • 221.215.61.108

  • 23.168.24.210

  • 23.186.168.131

  • 230.164.54.154

  • 237.19.222.140

  • 238.4.250.129

  • 24.36.240.216

  • 242.14.28.99

  • 243.3.250.129

  • 246.5.250.129

  • 25.165.54.154

  • 250.40.54.154

  • 29.165.54.154

  • 29.3.250.129

  • 30.161.54.154

  • 30.234.34.192

  • 37.169.54.154

  • 38.32.168.125

  • 38.58.48.2

  • 4.10.20.172

  • 45.33.53.84

  • 45.33.65.164

  • 49.0.229.216

  • 49.12.22.106

  • 54.215.111.135

  • 54.41.54.154

  • 57.166.54.154

  • 59.32.0.192

  • 59.47.0.192

  • 61.36.205.192

  • 64.69.216.61

  • 64.99.62.11

  • 65.169.54.154

  • 66.175.236.237

  • 66.187.4.132

  • 67.215.249.229

  • 67.231.157.136

  • 68.94.159.98

  • 69.10.208.170

  • 69.166.54.154

  • 69.83.160.183

  • 69.83.161.192

  • 69.83.169.177

  • 69.83.169.186

  • 69.89.207.199

  • 75.19.222.140

  • 80.153.195.191

  • 80.239.221.134

  • 85.44.54.154

  • 9.43.54.154

  • 98.159.94.68

  • 98.95.54.154

  • 99.28.14.242

Domains and hostnames observed:

Highest-risk host details

216.240.36.24 (

ntp.speculation.org

)Nmap surface:

21/tcp open tcpwrapped

22/tcp open ssh OpenSSH 6.6 (protocol 2.0)

25/tcp open smtp Sendmail 8.15.1

37/tcp open time

80/tcp open http Apache httpd 2.4.10

111/tcp open rpcbind 2-4 (RPC #100000)

113/tcp open ident?

143/tcp open imap?

443/tcp open ssl/http Apache httpd 2.4.10 ((Mageia))

587/tcp open smtp Sendmail 8.15.1

993/tcp open imaps?

995/tcp open tcpwrapped

3306/tcp open mysql MariaDB 5.5.5-10.0.36

OS guess Mageia Linux. Estimated uptime approximately 419 days. Low-profile volunteer with no clear public individual attribution beyond the hostname.

99.28.14.242 (

remote.scottallenmiller.com

)

AT&T residential (Lightspeed), Indianapolis, IN (AS7018). Domain registered 2014 via Namecheap. Ports observed: 21, 80 (302 redirect to HTTPS), 81, 443. Service: Apache Guacamole remote desktop gateway, build stamp 20240330042611 (1.5.x series). QSecPulse risk score 90 driven by risky open ports. PTR consistent with residential assignment (

99-28-14-242.lightspeed.iplsin.sbcglobal.net

).

Supporting pool members

  • 216.229.0.49 (

    eterna.binary.net

    ) — Binary Net LLC, Lincoln, Nebraska. Data center inside former Federal Reserve vault. Only port 21 observed open. Clean long-term NTP Pool participant.

  • 108.61.215.221 (Vultr) and 143.42.229.154 / 143.42.229.153 (Linode/Akamai) — standard cloud VPS members with limited surface.

HTML content recovered via QSecPulse clones

Guacamole application (build 20240330042611):

<!doctype html>

<html ng-app="index" ng-controller="indexController">

<head>

<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">

<meta name="build" content="20240330042611">

<link rel="stylesheet" href="1.guacamole.6f7b293d2dba5a891aa5.css">

<link rel="stylesheet" href="app.css?b=20240330042611">

<title ng-bind="page.title | translate"></title>

</head>

<body ng-cloak translate-cloak ng-class="page.bodyClassName" ng-switch="applicationState">

<div class="logged-out-modal" ng-switch-when="loggedOut">

<guac-modal>

<div class="notification">

<p translate="

APP.INFO

_LOGGED_OUT"></p>

<p><button translate="APP.ACTION_LOGIN_AGAIN" ...></button></p>

</div>

</guac-modal>

</div>

<!-- Additional states: fatalError, automaticLoginRejected, awaitingCredentials, ready -->

<guac-login ng-switch-when="awaitingCredentials" ...></guac-login>

<script src="guacamole-common-js/all.min.js"></script>

<script src="angular.min.js"></script>

<script src="1.guacamole.7935cf403412cd79c600.js"></script>

<script src="app.js?b=20240330042611"></script>

</body>

</html>

Export Worldwide /

exhol.com

(

amazon.pool.ntp.org

collision):

<title>Inbound international SEO tool and Multilingual content marketing platform | Export Worldwide</title>

<meta name="generator" content="Jekyll v4.0.1" />

<meta name="description" content="Export Worldwide, an inbound international SEO tool and Multilingual content marketing platform..." />

<meta property="og:site_name" content="Export Worldwide" />

{"url":"

https://www.exhol.com/

","name":"Export Worldwide",...}

<img src="

https://www.exhol.com/assets/images/eww-logo-50.png

" ... />

Copyright &copy; Export Worldwide 2020

ntpviz page:

<title>ntpviz</title>

<h1 style="margin-bottom:10px;">ntpviz</h1>

Additional fragments included default Caddy pages (<title>Caddy works!</title>), 302 Found redirects, and a redirect target of

kernfusion.at

(Austrian jazz/rock band site — pure content collision).

Cross-Reference Against Known Actors and IOCs

Cross-referencing the full set of IPs and domains against public threat intelligence sources produced no high-confidence active IOC or named threat-actor attributions for the primary hosts.

  • 99.28.14.242 /

    remote.scottallenmiller.com

    — no current public listings as C2, malware distribution, or attributed infrastructure.

  • 216.240.36.24 /

    ntp.speculation.org

    — appears only as a normal (if poorly maintained) NTP Pool volunteer.

  • 216.229.0.49 /

    eterna.binary.net

    — clean professional participant.

  • t1.hshh.org

    /

    hshh.org

    — resolves to the Humane Society of Harrisburg Area (benign animal-shelter organization, domain registered 2003).

  • Supporting Vultr and Linode addresses — no current high-confidence hits; only historical low-confidence port-scan noise on nearby addresses.

Guacamole and similar remote-access tools remain a heavily abused class for initial access and persistence in ransomware and espionage campaigns. NTP itself continues to appear in research on amplification and rare C2-over-NTP techniques. None of the specific hosts in this session were linked to current high-profile actors (LAUNDRY BEAR / Void Blizzard, UAT-11795, Squidoor, Cloud Atlas, Sandworm RDP campaigns, or others reviewed).

Implications

Direct compromise risk

Servers running OpenSSH 6.6, decade-old database software, and outdated Apache versions remain vulnerable to well-documented remote and privilege-escalation exploits. Once compromised, an NTP server can be used for covert C2 channels that blend with legitimate time traffic, amplification or reflection attacks, lateral movement into the operator’s broader network, or manipulation of time data returned to clients—with cascading effects on authentication, logging, and certificate validation.

Ecosystem trust and monitoring weaknesses

The NTP Pool’s monitoring system has been shown in research to be susceptible to deception. A sophisticated adversary who can influence or impersonate monitoring checks could potentially remove legitimate servers or inflate the visibility of malicious ones. The voluntary nature of participation means many operators lack dedicated security resources.

Residential and hybrid exposure

The presence of a residential Guacamole instance answering pool queries demonstrates how personal remote-access infrastructure can become entangled with critical public services, expanding the attack surface for both the individual operator and any systems that rely on that time source.

Broader abuse patterns

Public reporting continues to document ransomware and APT groups abusing legitimate remote-access and RMM tools, occasional use of NTP as a stealthy C2 medium, and residual amplification potential on misconfigured servers. While the specific hosts examined showed no active attribution to known threat actors, they exemplify the conditions under which such abuse becomes feasible.

Recommendations

For NTP Pool operators

Maintain current, supported software versions. Restrict management interfaces (SSH, databases, web panels) to trusted networks or require strong authentication and multi-factor controls. Separate the NTP service from other applications whenever possible. Monitor for unexpected processes, open ports, and certificate anomalies.

For organizations relying on the pool

Prefer authenticated time sources (NTS) where available. Maintain internal stratum-1 or stratum-2 servers as primary references. Monitor outbound NTP destinations and query patterns for anomalies. Treat sudden changes in resolved pool members as a potential indicator.

For the broader ecosystem

Continue strengthening monitoring and scoring systems against deception. Encourage or require minimum security baselines for participation. Expand visibility into IPv6 and vendor-specific zones.

Closing

The reconnaissance did not uncover confirmed, actively compromised NTP servers attributed to known threat actors. It did surface multiple high-risk configurations—including long-uptime servers running end-of-life software and a residential remote-desktop gateway answering public time queries—that illustrate enduring structural weaknesses in the volunteer-based time infrastructure that underpins much of the internet.

As long as critical services depend on under-resourced volunteer operators running outdated software, the potential for compromise, covert abuse, and cascading failures remains real. Hardening individual servers, improving monitoring, and reducing reliance on purely unauthenticated public pool members are necessary steps to protect the integrity of global time synchronization.

Quantitative Security

Protective intelligence • Threat hunting • Custom tooling

Previous
Previous

Threat Intelligence: Dual-Use NTP Infrastructure, Scanner Farms, and Certificate-Related Disruptions