# IP INTELLIGENCE BRIEFING: 47.93.118.200
Date: 2026-07-31
Classification: Moderate Risk
Risk Score: 50/100
---
## EXECUTIVE SUMMARY
IP address 47.93.118.200 presents a moderate risk profile with geolocation data indicating origin from China (Beijing). The IP is associated with ASN 37963 and operates within the 47.92.0.0/15 BGP prefix. While currently showing minimal active threat indicators, the IP is listed on 2 of 8 DNSBLs with maximum severity rating "high."
## KEY FINDINGS
Geolocation: Beijing, China (CN) - High confidence geo consensus achieved. RTT and distance validation pending.
Network Classification:
- ASN 37963 with BGP origin 47.92.0.0/15
- Service Purpose: Firewalled / No Services
- No active services detected (all open ports: [])
- No TLS certificates or HTTP banner information available
Threat Indicators:
- Blacklist count: 0 (current threat feed results)
- DNSBL listings: 2/8 total lists
- No known campaigns or threat feed matches
- Abuse Confidence Score: Not assigned
Neighborhood Analysis (47.93.118.0/24):
- Subnet classification: Mostly clean
- Abuse density: 1
- Inherited risk: 2
- No sibling IPs returned in neighbor query
Historical Observations (13 signals):
- Most recent signals from 2026-07-31
- DNSSEC validation confirmed as valid
- No persistent malicious behavior detected
- One threat observation recorded
## NETWORK BEHAVIOR
The IP shows no active service exposure and has been classified as firewalled with no open ports. Forward DNS resolution failed to resolve PTR records or hostnames. No email authentication mechanisms (SPF/DMARC) were configured for any associated domains.
## RECOMMENDED ACTIONS
Based on the risk profile, the following firewall rules are recommended:
| System | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 47.93.118.200 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 47.93.118.200 drop` |
| nginx | `deny 47.93.118.200;` |
| pfSense | `47.93.118.200/32` |
| Cloudflare WAF | Block IP with expression `ip.src eq 47.93.118.200` |
| AWS WAF | Add IP to whitelist with description "IPDebrief risk 50" |
## ANALYST NOTES
While the IP lacks active threat indicators and shows no open services, the presence on multiple DNSBLs with high severity rating warrants continued monitoring. The moderate risk score of 50 suggests potential for future malicious activity. Recommend adding to monitoring lists and implementing the recommended blocking rules, particularly for inbound traffic filtering.
Status: Monitor/Block
Priority: Medium
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | security trouble |
| ASN | AS37963 |
| Network Name | ALISOFT |
| CIDR Block | 47.92.0.0/14 |
| RIR | ARIN |
| Country | CN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 8% | 2 | 2 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-30 04:59:23 UTC |
| Last Seen | 2026-07-31 19:33:15 UTC |
| Profile Built | 2026-07-31 01:25:46 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 19 |
Full dossier details are available via our API.