# IP Intelligence Briefing: 120.26.64.17/32
## Executive Summary
IP address 120.26.64.17 presents a low-risk profile with a risk score of 25. The address is assigned to ALISOFT (ALIBABA-CN-NET - Hangzhou Alibaba Advertising Co., Ltd.) within the APNIC region and is geolocated to Hangzhou, Zhejiang, China (CN). No active services or open ports were detected; the system appears firewalled. While historical signal observations indicate threat activity (6 pulse events), current network classification shows the subnet as mostly clean with minimal abuse density.
## Profile Overview
- Risk Score: 25 (Low Risk)
- ASN: 37963 (ALISOFT)
- Organization: ALISOFT
- Network Block: 120.24.0.0/14
- Geolocation: China (CN), Zhejiang Province, Hangzhou
- RIR: APNIC
- DNSBL Status: Listed on 1 of 8 DNSBLs
- Service Status: Firewalled / No Services Detected
## Threat Indicators
Historical signal analysis reveals 6 threat pulses associated with this IP address. The IP has been flagged in threat feeds with varying confidence levels (0.22โ0.85). DNSBL enumeration confirms listing on at least one blacklist. However, no active attacker indicators, Tor exit node activity, or spam source classification was detected in current observations. The IP is not associated with any known malicious campaigns.
## Network Neighborhood Analysis
The /24 subnet (120.26.64.0/24) containing this IP shows:
- Abuse Density: Minimal (0โ1)
- Classification: Mostly Clean
- Active Siblings: 0 detected
- Threat Siblings: 1 identified
- Total Siblings: 1
The neighborhood exhibits low abuse density, suggesting isolated rather than coordinated malicious activity.
## Observed Relationships
Twenty-four relationships were identified, all classified as "Same Network" type, referencing the network name "ALISOFT." This indicates the IP is part of a larger network infrastructure block commonly associated with Alibaba advertising services in China.
## Historical Signal Timeline
Recent observations from June 2026 show:
- ASN 37963 confirmed as "Hangzhou Alibaba Advertising Co., Ltd."
- Geolocation signals consistently point to Hangzhou, ZJ, CN
- Threat signals detected with 0.85 confidence confidence
- Operator score: 0.1304 (Minimal)
- Routing stability: False (route changes observed)
## Recommended Security Actions
Based on the current low-risk profile and lack of actionable threat indicators, no immediate firewall or WAF rules are recommended. However, the following monitoring practices are advised:
1. Passive Monitoring: Continue passive traffic analysis to detect any service changes
2. DNSBL Review: Investigate the reason for the single DNSBL listing
3. Traffic Baseline: Establish normal traffic patterns for this subnet
4. Threat Pulse Review: Analyze the 6 historical threat pulses for context
## Risk Assessment
Current Risk Level: LOW
Threat Level: LOW-MEDIUM
Recommended Action: Monitor, No Immediate Block
The IP presents a low-risk profile with historical threat indicators but no current active malicious behavior. The absence of open services and minimal neighborhood abuse density support continued monitoring rather than immediate blocking. SOC analysts should correlate any traffic from this IP with broader threat intelligence before taking blocking actions.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | security trouble |
| ASN | AS37963 |
| Network Name | ALISOFT |
| CIDR Block | 120.24.0.0/14 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 3 |
| routing | 17% | 1 | 1 |
| services | 18% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 24% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 22% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:35 UTC |
| Last Seen | 2026-06-22 11:23:49 UTC |
| Profile Built | 2026-06-22 11:30:15 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 20 |
Full dossier details are available via our API.