# IP Intelligence Briefing: 101.47.8.188/32
## Executive Summary
IP 101.47.8.188 operates within the BYTEPLUS-SG network (ASN 150436) and presents a moderate risk profile (risk score: 50). The address is geolocated to Singapore with no active services detected. Current threat indicators show minimal malicious activity, though historical observations include conflicting geolocation signals and one DNSBL listing across eight threat intelligence feeds.
## Network Ownership and Classification
- Organization: IRT-BYTEPLUS-SG (BYTEPLUS-AS-AP)
- Network Name: BYTEPLUS-SG
- CIDR Block: 101.47.0.0/18
- RIR: APNIC
- Registration Date: 2010-12-14
- Abuse Contact: Available via RDAP
The IP is classified as firewalled with no services detected. No open ports, TLS certificates, or HTTP endpoints were observed. DNS resolution failed to return PTR hostnames or forward resolution data.
## Geolocation Data
- Country: Singapore (SG)
- Coordinates: 1.35°N, 103.82°E
- Timezone: Asia/Singapore
- Accuracy Radius: 30 km
- Geo Consensus: Confirmed
## Threat Assessment
- Risk Score: 50 (Moderate Risk)
- Abuse Confidence Score: Not available
- Blacklist Count: 0
- Known Campaigns: None identified
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Control plane analysis showed the IP belongs to BGP prefix 101.47.8.0/21 with RPKI state unknown. IRR consistency matched, though route stability is marked as false. DNSBL listings included 1 of 8 total lists checked.
## Historical Observations
Analysis captured 21 signal observations. Geolocation signals consistently placed the IP in Singapore, though one observation from June 2026 showed conflicting China (CN) geolocation with 50 threat pulses across multiple feeds. ASN 150436 was confirmed through team-cymru-dns resolution.
## Neighborhood Analysis
The /24 subnet (101.47.8.0/24) showed:
- Abuse Density: 0
- Classification: Mostly clean
- Total Siblings: 2
- Active Siblings: 0
- Threat Siblings: 2
- Neighbor IP: 101.47.8.187 (risk score: 50, authority score: 50)
## Relationship Graph
Twenty relationships were identified, all linking to the BYTEPLUS-SG network entity.
## Recommended Security Actions
Based on the risk profile, the following firewall rules were generated:
iptables:
```
iptables -A INPUT -s 101.47.8.188 -j DROP
```
nftables:
```
nft add rule inet filter input ip saddr 101.47.8.188 drop
```
nginx:
```
deny 101.47.8.188;
```
pfSense:
```
101.47.8.188/32
```
Cloudflare WAF:
```
{"description": "Block 101.47.8.188 β IPDebrief risk score 50", "action": "block", "filter": {"expression": "ip.src eq 101.47.8.188"}}
```
AWS WAF:
```
{"Addresses": ["101.47.8.188/32"], "Description": "IPDebrief risk 50"}
```
## Analyst Notes
Despite the moderate risk score, the IP shows no active malicious behavior indicators. The conflicting geolocation signals and minimal operator score warrant continued monitoring. Recommended actions should be combined with other threat intelligence signals before implementation.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | IRT-BYTEPLUS-SG |
| ASN | AS150436 |
| Network Name | BYTEPLUS-SG |
| CIDR Block | 101.47.0.0/18 |
| RIR | APNIC |
| Country | SG |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 25% | 3 | 3 |
| services | 8% | 1 | 1 |
| ownership | 30% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 24% | 11 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (65%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Recent
| First Seen | 2026-05-07 23:03:24 UTC |
| Last Seen | 2026-06-26 18:10:09 UTC |
| Profile Built | 2026-06-25 14:01:31 UTC |
| Data Freshness | Recent |
| Signal Types | 20 |
| Total Observations | 20 |
Full dossier details are available via our API.