IP Intelligence Briefing: 121.199.4.44
Date: 2026-06-07
---
**1. Risk Profile**
- Overall Risk Score: Low (25/100)
- Threat Indicators: No malicious activity detected (no indicators, spam, or campaigns).
- Network Classification: Firewalled / No Services (no open ports or TLS services).
- Provider/Organization: Registered under ASN 37963 ("ALIBABA-CN-NET") with netname "ALISOFT" (Hangzhou Alibaba Advertising Co., Ltd.).
- Geolocation: Zhejiang, Hangzhou, China (latitude 35.86, longitude 104.2, accuracy radius 2500 km).
---
**2. Network Context**
- Subnet: 121.199.4.44/24 (abuse density: 0%, clean classification).
- Neighbors: No active or malicious sibling IPs in the subnet.
- BGP/Control Plane:
- Origin ASN: 37963 (ALIBABA-CN-NET).
- BGP prefix: 121.196.0.0/14.
- Route stability: Unstable (route changes detected in 30 days).
- DNSSEC: Validated.
---
**3. Temporal Observations**
- Historical Signals (Last 90 Days):
- Consistent association with Alibaba's ASN (since 2007).
- No spikes in threat activity or ownership changes.
- Geolocation signals consistently point to Hangzhou, China.
---
**4. Actionable Recommendations**
- Firewall Rules: No specific rules recommended (low risk, no malicious indicators).
- Monitoring: Track for sudden ownership changes or unexpected service exposure.
- Context: Legitimate infrastructure (Alibaba-owned) with no signs of compromise.
---
**5. Summary**
The IP 121.199.4.44 is part of a low-risk network managed by Alibaba Group. No malicious activity, threat indicators, or anomalous behavior were detected. The subnet is clean, and the IPโs geolocation and ownership history are consistent. No immediate mitigation is required, but ongoing monitoring is advised for any deviations.
Threat Level: Low | Recommended Action: No action needed.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | security trouble |
| ASN | AS37963 |
| Network Name | ALISOFT |
| CIDR Block | 121.196.0.0/14 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 19% | 1 | 2 |
| services | 13% | 1 | 1 |
| ownership | 27% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 23% | 9 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-14 23:34:34 UTC |
| Last Seen | 2026-06-07 09:35:10 UTC |
| Profile Built | 2026-06-07 10:21:45 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 16 |
Full dossier details are available via our API.