# IP Intelligence Briefing: 47.236.148.6/32
## Executive Summary
IP address 47.236.148.6 is a cloud infrastructure endpoint associated with Alibaba Cloud LLC (ASN 45102) assigned to the AL-3 network block. The address carries a moderate risk score of 55/100 with elevated operator score and multiple DNSBL listings. Infrastructure classification indicates single-service hosting with SSH exposure.
## Ownership and Network Classification
- Provider: Alibaba Cloud LLC
- ASN: 45102
- Network Block: 47.235.0.0/16 (AL-3)
- Infrastructure Type: CloudCompute
- Classification: Hosting provider, Cloud infrastructure
- Registration: ARIN registry
## Geolocation Analysis
Geolocation data showed inconsistent reporting with primary consensus indicating Denver, Colorado (US), though observation history recorded Singapore (SG) in multiple probes. Geo consensus flag remains false, indicating conflicting geolocation signals across data sources.
## Threat Indicators and Reputation
- Risk Score: 55/100 (Moderate Risk)
- DNSBL Listings: 3 listings across 8 total lists
- Abuse Confidence Score: Not available
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
- Threat Persistence Days: 0
- Campaign Correlation: 0 correlated IPs
## Network Services and Exposure
- Open Ports: TCP/22 (SSH) - OpenSSH 8.0
- TLS Certificate: None detected
- HTTP Service: None detected
- DNS Records: No PTR hostnames, 0 forward resolutions
## Control Plane Analysis
- Route Stability: False
- MOAS Status: False
- BGP Prefix: 47.236.0.0/16
- Operator Score: 0.1304 (Minimal)
- RPKI State: Not verified
- IRR Consistency: Not evaluated
## Neighborhood Analysis
The /24 subnet (47.236.148.0/24) shows:
- Abuse Density: 0
- Total Neighbors: 1
- Risk Distribution: 1 low-risk, 0 medium-risk, 0 high-risk
- Notable Neighbor: 47.236.148.155 (Risk Score: 25/100, Authority Score: 50)
## Observation History (15 Signals)
Recent observations indicate:
- SSH service confirmed with OpenSSH 8.0 banner
- Geolocation signals varied between US and Singapore
- Operator score consistently rated as "Minimal" (0.1304)
- No threat observation count recorded
- No persistent malicious behavior detected
## Relationship Graph
Five relationship records identified, all classified as "Same Network" type pointing to network identifier AL-3. No hostname, organization, or certificate relationships detected beyond network-level associations.
## Recommended Security Actions
Based on risk profile assessment:
Monitoring Recommendations:
- Increase logging verbosity and review recent activity from this IP (High severity due to elevated risk score)
Firewall Rules:
- iptables: `iptables -A INPUT -s 47.236.148.6 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 47.236.148.6 drop`
- nginx: `deny 47.236.148.6;`
- pfSense: `47.236.148.6/32`
- Cloudflare WAF: Block with expression `ip.src eq 47.236.148.6`
- AWS WAF: Add `47.236.148.6/32` to blocked addresses
## SOC Analyst Notes
This IP represents a cloud hosting endpoint with moderate risk characteristics. The inconsistent geolocation data and presence in multiple DNSBL lists warrant monitoring. While SSH exposure is confirmed, no active malicious indicators were observed. The recommendation leans toward blocking due to elevated risk score, though operational context should be considered. Neighbor 47.236.148.155 presents lower risk (25/100) and may warrant separate evaluation if traffic patterns suggest relationship.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Alibaba Cloud LLC |
| ASN | AS45102 |
| Network Name | AL-3 |
| CIDR Block | 47.235.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_8.0 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-21 12:55:37 UTC |
| Last Seen | 2026-08-13 06:45:04 UTC |
| Profile Built | 2026-08-12 18:32:30 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.