# INTELLIGENCE BRIEFING: IP 47.250.115.134/32
Classification: Moderate Risk Infrastructure IP
Date: 2026-07-25
Intel Source: IPDebrief Threat Intelligence Platform
---
## EXECUTIVE SUMMARY
IP 47.250.115.134 is a cloud infrastructure address associated with Alibaba Cloud Malaysia. The IP presents a moderate risk score of 40, with no active threat indicators, no open services, and a clean neighborhood profile. While the IP has been DNSBL-listed on 2 of 8 threat feeds, it shows no evidence of malicious activity, campaign participation, or active exploitation.
---
## OWNERSHIP & INFRASTRUCTURE PROFILE
| Attribute | Value |
|---|---|
| **ASN** | 45102 |
| **Organization** | Alibaba Cloud - MY |
| **Netname** | ALIBABA CLOUD - MY |
| **CIDR Block** | 47.250.0.0/17 |
| **RIR** | ARIN |
| **Geolocation** | Kuala Lumpur, Malaysia (US geolocation signal detected) |
| **IP Type** | Cloud Infrastructure |
| **Network Role** | Firewalled / No Services |
The IP is part of a large cloud provider subnet with BGP prefix 47.250.64.0/18. Routing analysis indicates the prefix is stable with no recent route changes.
---
## THREAT INDICATORS
Active Threat Signals: None detected
| Indicator | Status |
|---|---|
| Tor Exit Node | No |
| Known Attacker | No |
| Spam Source | No |
| Blacklist Count | 0 |
| Known Campaigns | None |
| Threat Feeds | Empty |
| Pulsedive Risk | Not Available |
Control Plane Signals:
- DNSBL Listed: 2 of 8 total lists
- Operator Score: 0.1304 (Minimal)
- Route Stability: False
- DNSSEC Valid: True
---
## OBSERVATION HISTORY
Total Observations: 13 signals recorded
Recent Activity (2026-07-25):
- Multiple geolocation signals with conflicting data (US and Malaysia)
- Consistent ASN attribution to Alibaba Cloud - MY (0.95 confidence)
- Operator classification: Minimal threat posture
- No persistent malicious behavior detected
The IP exhibits stable ownership with zero ownership changes. Threat persistence days recorded at 0, indicating no long-term malicious presence.
---
## NETWORK NEIGHBORHOOD ANALYSIS
Subnet: 47.250.115.134/24
| Metric | Value |
|---|---|
| Abuse Density | 0.0 |
| Classification | Clean |
| Total Siblings | 3 |
| Active Siblings | 2 |
| Threat Siblings | 0 |
Neighbor Risk Profile:
- 47.250.115.79: Risk Score 0 (Clean)
- 47.250.115.147: Risk Score 25 (Low)
The neighborhood demonstrates minimal abuse activity with no high-risk or medium-risk neighbors.
---
## RELATIONSHIP MAPPING
Connected Entities: 2 relationships identified
- Same Network: ALIBABA CLOUD - MY (Network classification)
- Same Network: ALIBABA CLOUD - MY (Network classification)
No organizational, hostname, or certificate relationships detected beyond network-level associations.
---
## RECOMMENDED SECURITY ACTIONS
Risk Score: 40 (Moderate Risk)
Recommended Firewall Actions:
```bash
# iptables
iptables -A INPUT -s 47.250.115.134 -j DROP
# nftables
nft add rule inet filter input ip saddr 47.250.115.134 drop
# Nginx
deny 47.250.115.134;
# pfSense
47.250.115.134/32
# Cloudflare WAF
{"description":"Block 47.250.115.134 — IPDebrief risk score 40",
"action":"block",
"filter":{"expression":"ip.src eq 47.250.115.134"}}
# AWS WAF
{"Addresses":["47.250.115.134/32"], "Description":"IPDebrief risk 40"}
```
Note: These recommendations are probabilistic and should be combined with other signals before taking action.
---
## ANALYST ASSESSMENT
IP 47.250.115.134 presents as a legitimate cloud infrastructure address with no evidence of malicious activity. The moderate risk score (40) stems primarily from DNSBL listings rather than active threat indicators. The IP is part of a clean neighborhood with minimal abuse density.
Key Findings:
- No active exploitation or attack indicators
- No open services or listening ports
- Clean neighborhood with low-risk neighbors
- Stable cloud provider infrastructure
- No campaign associations or known attacker patterns
Recommendation: Monitor but do not immediately block. The IP's risk profile suggests it may be a false positive or used for benign infrastructure purposes. However, implement monitoring rules to detect any changes in behavior or new threat associations.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Alibaba Cloud - MY |
| ASN | AS45102 |
| Network Name | ALIBABA CLOUD - MY |
| CIDR Block | 47.250.0.0/17 |
| RIR | ARIN |
| Country | Malaysia |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting — Infrastructure provider without advanced routing |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS45102 |
| Network Prefix | 47.250.64.0/18 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 25% | 1 | 1 |
| Overall | 22% | 6 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-09 01:19:53 UTC |
| Last Seen | 2026-08-26 16:39:17 UTC |
| Profile Built | 2026-08-29 07:52:17 UTC |
| Data Freshness | Live |
| Signal Types | 15 |
| Total Observations | 18 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 47.250.115.134
Who owns the IP address 47.250.115.134?
47.250.115.134 is registered to Alibaba Cloud - MY. The address falls within the 47.250.0.0/17 network block. Registration is held at ARIN.
Where is 47.250.115.134 located?
Geolocation data places 47.250.115.134 in Kuala Lumpur, Kuala Lumpur, Malaysia. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 47.250.115.134 malicious or safe?
47.250.115.134 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
Is 47.250.115.134 a VPN, proxy, or data center address?
47.250.115.134 is classified as cloud infrastructure and hosting infrastructure based on network ownership and behavioural analysis.