# INTELLIGENCE BRIEFING: IP 123.57.73.112
Classification: Moderate Risk (Risk Score: 50)
Date: 2026-06-25
Report ID: IP-1235773112-20260625
---
## EXECUTIVE SUMMARY
IP address 123.57.73.112 presents a moderate risk profile with a risk score of 50. The address is geolocated to Beijing, China, and is associated with ASN 37963 (ALISOFT). No active threat indicators were detected during profile analysis, but the moderate risk classification warrants defensive monitoring.
---
## OWNERSHIP & NETWORK CLASSIFICATION
| Attribute | Value |
|---|---|
| **ASN** | 37963 |
| **Organization** | ALISOFT |
| **Network Name** | ALISOFT |
| **CIDR Block** | 123.56.0.0/15 |
| **Country** | CN (China) |
| **Region** | Beijing |
| **RIR** | APNIC |
| **Registration Date** | Not available |
Network Role: Firewalled / No Services
Infrastructure Type: Not cloud, not CDN, not VPN, not proxy, not hosting infrastructure
---
## THREAT ASSESSMENT
Overall Risk Score: 50 (Moderate Risk)
Abuse Confidence Score: Not available
Blacklist Status: Not listed on threat feeds
Tor Exit Node: No
Known Attacker: No
Spam Source: No
Threat Indicators: None detected
Known Campaigns: None associated
DNSBL Listings: 2 out of 8 total lists
---
## OBSERVATION HISTORY
The IP has been observed across 15 signal observations spanning multiple dates. Key observations include:
- 2026-06-25: Multiple signals observed with confidence levels ranging from 0.21 to 0.30, including reputation (Minimal), routing, services, ownership, and geolocation assessments.
- 2026-06-04: ASN 37963 resolution with prefix 123.56.0.0/15, confirming Alibaba China Network origin. Network classification signals confirmed non-cloud, non-Tor, non-proxy status.
- Service Scanning: Port scans conducted on 2026-06-04 with no open ports detected.
Threat Persistence: 0 days
Ownership Changes: 0
Persistent Malicious Activity: False
---
## RELATIONSHIP ANALYSIS
The IP exhibits 15 relationships, all classified as "Same Network" pointing to the ALISOFT network infrastructure. This indicates the IP operates within a larger network block with consistent network classification. No external entity relationships (hostnames, certificates, organizations outside the network) were identified.
---
## NEIGHBORHOOD ANALYSIS
Subnet: 123.57.73.112/24
Abuse Density: 0 (Low)
Classification: Mostly Clean
Total Siblings: 1
Active Siblings: 0
Threat Siblings: 1
The neighboring subnet shows low abuse density with minimal threat concentration, suggesting this IP does not operate in a highly compromised network environment.
---
## CONTROL PLANE DATA
- Origin ASN: 37963
- BGP Prefix: 123.56.0.0/15
- Route Stability: Unstable (isRouteStable: false)
- Route Changes (30d): 0
- MOAS: False
- DNSSEC Valid: True
- HAS CAA: False
- Operator Score: 0.1304 (Minimal)
- DNSBL Listed Count: 2
---
## RECOMMENDED ACTIONS
Based on the moderate risk profile, the following defensive measures are recommended:
Firewall Rules
| Platform | Rule |
|---|---|
| **iptables** | `iptables -A INPUT -s 123.57.73.112 -j DROP` |
| **nftables** | `nft add rule inet filter input ip saddr 123.57.73.112 drop` |
| **nginx** | `deny 123.57.73.112;` |
| **pfSense** | `123.57.73.112/32` |
| **Cloudflare WAF** | Block IP 123.57.73.112 with expression `ip.src eq 123.57.73.112` |
| **AWS WAF** | Add address `123.57.73.112/32` to protection rules |
Priority Assessment
Immediate Action: Recommended blocking due to moderate risk score
Monitoring: Continue surveillance for threat indicator emergence
Context: IP appears dormant with no open services; blocking is precautionary
---
## ANALYST NOTES
This IP address presents a moderate risk profile without active malicious indicators. The moderate risk score (50) suggests defensive caution is warranted. The absence of open services and threat indicators indicates the IP may be dormant or part of a larger network infrastructure. Continued monitoring is recommended, particularly given the moderate risk classification and the presence of 2 DNSBL listings. The low abuse density in the neighboring subnet provides context that this IP is not operating in a highly compromised network environment.
---
Report Generated: 2026-06-25
Data Sources: IPDebrief Intelligence Platform
Classification: SOC Analyst Briefing
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | security trouble |
| ASN | AS37963 |
| Network Name | ALISOFT |
| CIDR Block | 123.56.0.0/15 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 20% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-08 05:01:35 UTC |
| Last Seen | 2026-06-25 01:59:07 UTC |
| Profile Built | 2026-06-25 02:07:26 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 16 |
Full dossier details are available via our API.