IP Intelligence Briefing: 47.251.186.196
Date: 2026-06-07
---
**1. Risk Profile**
- Overall Risk Score: Low (25/100)
- Provider Score: 0 (no malicious provider indicators)
- Authority Score: 0 (no authoritative abuse indicators)
- Stability Score: 0 (no instability detected)
- Threat Indicators: No malicious activity, spam, or known attacker associations.
---
**2. Ownership & Network**
- ASN: 45102 (Alibaba Cloud - US)
- Organization: Alibaba Cloud - US
- Geolocation:
- Country: United States
- Region: California (CA)
- City: Los Angeles (coordinates match)
- ISP: Alibaba Cloud
- Network Role:
- Infrastructure: CloudCompute (virtual machine)
- Subnet: 47.251.0.0/16 (Alibaba Cloud allocation)
- Hosting: Yes (cloud provider)
---
**3. Threat & Behavioral Analysis**
- Observed Signals:
- Minimal threat indicators (confidence: 30%).
- Geo-plausibility flag: False (discrepancy between geolocation and IP origin).
- No DNSSEC violations, open ports, or TLS certificates.
- Behavioral Flags:
- No honeypot hits, enumeration attempts, or WAF violations.
- No known campaigns or malicious banners.
---
**4. Network Relationships**
- Linked Entities:
- Same network: Alibaba Cloud - US (repeated 12 times).
- No external subnets, domains, or certificates associated.
- Subnet Analysis:
- /24 Subnet: 47.251.186.196/24
- Abuse Density: 0 (no malicious siblings).
- Neighbor Count: 0 (no active IPs in subnet).
---
**5. Historical Observations**
- Latest Activity:
- June 7, 2026: Minimal risk signal (0.15 score).
- May 31, 2026: Geolocation confirmed (California, US).
- May 29, 2026: MaxMind geolocation data (Los Angeles).
- Trend: Consistent low-risk profile; no escalation detected.
---
**6. Recommendations**
- Monitoring:
- Track geo-plausibility discrepancies (potential misattribution).
- Monitor for unexpected subnet activity (no neighbors may indicate isolation).
- Security Actions:
- No immediate firewall rules required (low risk).
- Verify cloud instance legitimacy via Alibaba Cloud portal.
---
Conclusion:
47.251.186.196 is a legitimate Alibaba Cloud virtual machine with no detected malicious activity. While geo-plausibility flags raise minor concerns, the low risk score and absence of threats suggest it is benign. SOC teams should maintain passive monitoring for anomalies.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Alibaba Cloud - US |
| ASN | AS45102 |
| Network Name | ALIBABA CLOUD - US |
| CIDR Block | 47.251.0.0/16 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | β |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.15 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 21% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 13% | 1 | 1 |
| Overall | 21% | 8 | 11 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-15 14:46:31 UTC |
| Last Seen | 2026-06-07 14:52:24 UTC |
| Profile Built | 2026-06-07 15:36:22 UTC |
| Data Freshness | Live |
| Signal Types | 15 |
| Total Observations | 16 |
Full dossier details are available via our API.