Threat Intelligence Briefing: IP 47.76.78.115/32
Date of Analysis: [Insert Date of Analysis]
Summary:
IP address 47.76.78.115/32 was analyzed using a variety of network intelligence tools. This briefing provides a comprehensive overview of the IP's profile, observation history, relationships, and neighborhood data.
1. General Information:
- IP Address: 47.76.78.115/32
- Geolocation: [Insert Geolocation Data if available]
- ASN: [Insert ASN Details]
- Organization: [Insert Associated Organization if available]
2. Profile:
- Domain Association: [List any associated domains or websites]
- Service Information: [Details on services running on this IP, if available]
3. Observation History:
- Past Activity: [Summarize historical data, including any significant patterns or anomalies]
- Threat Indicators: [List any known threat indicators or malicious activity associated with this IP]
4. Relationships:
- Related IPs: [List of IPs with known associations or interactions]
- Known Compromises: [Details of any known compromises or breaches involving this IP]
5. Neighborhood Data:
- Subnet Analysis: [Analysis of the subnet to which this IP belongs, including any known malicious activity]
- Neighbor IPs: [Information on neighboring IPs, highlighting any suspicious or known malicious entities]
6. Threat Intelligence:
- Threat Level: [Assess the threat level based on observed data]
- Recommended Actions: [Provide actionable recommendations for SOC teams, such as monitoring, blocking, or further investigation]
Conclusion:
IP 47.76.78.115/32 has been analyzed for potential security risks. Based on the gathered data, [insert conclusion based on findings, e.g., "the IP is associated with suspicious activity and should be monitored closely"].
Note: This briefing is based on available data as of the analysis date. Continuous monitoring and updated intelligence are recommended to maintain security posture.
---
This briefing is intended for use by SOC analysts and network defenders. For further detailed analysis or updates, refer to the latest intelligence feeds and reports.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Alibaba Cloud - HK |
| ASN | AS45102 |
| Network Name | ALIBABA CLOUD - HK |
| CIDR Block | 47.76.0.0/16 |
| RIR | ARIN |
| Country | China |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_8.0 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 20% | 2 | 3 |
| ownership | 15% | 2 | 2 |
| reputation | 19% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 20% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-11 15:05:20 UTC |
| Last Seen | 2026-06-26 11:00:42 UTC |
| Profile Built | 2026-06-26 11:08:44 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 23 |
Full dossier details are available via our API.