# IPDebrief Intelligence Briefing: 47.90.137.149/32
Date: 2026-07-30
Status: Intelligence Complete
---
## Executive Summary
IP address 47.90.137.149 operates as a cloud-based infrastructure endpoint with moderate risk rating (50/100). The IP shows no active threat indicators but is listed on 2 of 8 DNS blacklists. No services are currently open; the endpoint appears firewalled.
---
## Risk Assessment
| Metric | Value | Assessment |
|---|---|---|
| Risk Score | 50 | Moderate Risk |
| Reputation | Moderate Risk | β |
| DNSBL Listed | 2/8 | Low-Moderate |
| Threat Persistence | 0 days | Non-persistent |
| Abuse Confidence | β | Not assessed |
Risk Breakdown: The IP exhibits moderate risk primarily driven by DNSBL listings and cloud infrastructure classification. No active threat indicators, known campaigns, or attacker signatures detected.
---
## Geolocation & Ownership
- Country: United States (US)
- Region: Virginia
- Coordinates: 38.69°N, -77.3°W
- Timezone: America/New_York
- Infrastructure: Cloud (CloudCompute)
- ASN: 45102
- BGP Prefix: 47.90.128.0/18
- Route Stability: False (routing changes observed)
---
## Network Classification
- Type: Cloud Infrastructure / Hosting
- Connection: Cloud-based
- Service Purpose: Firewalled / No Services
- Open Ports: None detected
- DNS Resolution: No forward resolution
- Hosted Domains: 0
- Email Auth: No SPF/DMARC records
---
## Threat Indicators
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Active Campaign: No
- WAF Violations: 0
- Honeypot Hits: 0
- Enumeration Strikes: 0
- Auto-Banned: No
---
## Neighborhood Analysis (47.90.137.0/24)
- Subnet Classification: Clean
- Abuse Density: 0%
- Total Siblings: 1
- Active Siblings: 0
- Threat Siblings: 0
- Risk Distribution: No high/medium/low risk neighbors
---
## Observation History (11 Signals)
Recent observations indicate consistent cloud infrastructure behavior:
- 2026-07-30 23:07:11 UTC: Cloud/Hosting classification confirmed
- 2026-07-30 23:06:52 UTC: ASN/Geolocation data confirmed (Alibaba Cloud - US)
- 2026-07-30 23:06:00 UTC: Virginia geolocation confirmed
- 2026-07-30 23:05:58 UTC: Subnet classified as clean
No escalation in threat behavior observed; signals remain stable over observation window.
---
## Relationships Graph
No entity relationships detected (subnets, hostnames, organizations, certificates).
---
## Recommended Security Actions
Firewall Rules (Immediate):
```bash
iptables -A INPUT -s 47.90.137.149 -j DROP
```
Cloud Platform Recommendations:
- Cloudflare WAF: Block 47.90.137.149 (risk score 50)
- AWS WAF: Add 47.90.137.149/32 to blocked addresses list
Note: Recommendations are probabilistic. Combine with additional threat intelligence signals before enforcement.
---
## Threat Intel Narrative
47.90.137.149 is a cloud-based infrastructure endpoint operating from Virginia, United States. The IP shows no evidence of malicious activity and no active threat indicators. However, the moderate risk score (50) and presence on 2 DNS blacklists suggest caution. The endpoint is firewalled with no open services, indicating legitimate hosting infrastructure rather than an active attack platform. The subnet environment remains clean with zero threat siblings. No routing stability is observed, which may warrant monitoring for infrastructure changes.
Priority: Low-Monitor
Action: Continue monitoring; no immediate threat response required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Alibaba Cloud - US |
| ASN | AS45102 |
| Network Name | ALIBABA CLOUD - US |
| CIDR Block | 47.90.128.0/17 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | β |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Single-Service Host |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-29 16:42:15 UTC |
| Last Seen | 2026-08-06 00:36:24 UTC |
| Profile Built | 2026-08-05 18:29:21 UTC |
| Data Freshness | Live |
| Signal Types | 15 |
| Total Observations | 16 |
Full dossier details are available via our API.