# IP Intelligence Briefing: 47.242.158.155/32
Classification: Low Risk - Legitimate Cloud Infrastructure
Date: Current Analysis
Source: IPDebrief Intelligence Platform
---
## Executive Summary
IP address 47.242.158.155 is classified as Low Risk with an overall risk score of 15/100. The address is identified as legitimate Alibaba Cloud infrastructure hosting services in Hong Kong. No malicious threat indicators, blacklisting, or persistent malicious activity observed.
---
## Technical Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 15 (Low) |
| **Organization** | ALIBABA CLOUD - HK |
| **ASN** | 45102 |
| **CIDR Block** | 47.242.0.0/16 |
| **Location** | Hong Kong, China |
| **RIR** | ARIN |
| **Infrastructure Type** | CloudCompute |
| **DNSSEC Valid** | Yes |
---
## Network Services
| Port | Protocol | Service | Banner |
|---|---|---|---|
| 80/tcp | TCP | HTTP | nginx |
| 22/tcp | TCP | SSH | SSH-2.0-OpenSSH_8.0 |
---
## Threat Assessment
Threat Indicators: None detected
Blacklist Status: Not blacklisted (0/0 lists)
Tor Exit Node: No
Known Attacker: No
Spam Source: No
Control Plane Analysis:
- Route stability: Unstable
- Operator score: 0.1304 (Minimal)
- DNSBL listed: 1 of 8 total lists
- Route changes (30d): 0
---
## Historical Observations
Total Observations: 13 signals
Recent Activity: 2026-07-29
Threat Persistence: 0 days
Ownership Changes: 0
Recent signal timeline:
- 09:33:18 - Port scan activity detected (HTTP, SSH services)
- 09:31:56 - Ownership verification (no changes)
- 09:30:56 - Network classification: Cloud hosting confirmed
- 09:30:30 - Geolocation: Hong Kong, ASN 45102
- 09:29:08 - Geolocation: Hong Kong (MaxMind GeoLite2)
No evidence of persistent malicious behavior or escalating threat profile.
---
## Network Relationships
Connected Entities: 3 relationships identified
- All classified as "Same Network" - ALIBABA-CLOUD---HK
- No certificate, hostname, or organization relationships detected
---
## Neighborhood Analysis
Subnet: 47.242.158.155/24
Neighbor Count: 0
Abuse Density: 0%
Risk Distribution: 0 High, 0 Medium, 0 Low
The /24 subnet shows no sibling IPs with threat indicators, suggesting isolated infrastructure deployment.
---
## Recommended Actions
Current Status: No immediate blocking required
Risk Level: Low - Allow with monitoring
Suggested Firewall Rules: None (low-risk cloud infrastructure)
Monitoring Priority: Standard operational monitoring
---
## Intelligence Assessment
This IP belongs to Alibaba Cloud's Hong Kong infrastructure and presents a low-risk profile. Standard cloud hosting services (HTTP on port 80, SSH on port 22) are operational. The absence of threat indicators, blacklisting, or malicious campaign associations indicates legitimate cloud infrastructure usage.
Recommendation: Monitor as standard cloud infrastructure. No defensive blocking action required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | ALIBABA CLOUD - HK |
| ASN | AS45102 |
| Network Name | ALIBABA-CLOUD---HK |
| CIDR Block | 47.242.0.0/16 |
| RIR | ARIN |
| Country | Hong Kong |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Multi-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 443, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | nginx |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_8.0 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-21 12:55:37 UTC |
| Last Seen | 2026-08-13 06:45:04 UTC |
| Profile Built | 2026-08-05 18:29:21 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 16 |
Full dossier details are available via our API.