# IP INTELLIGENCE BRIEFING
Target: 8.134.140.22/32
Classification: Low Risk | Status: Active | Date: 2026-07-29
---
## EXECUTIVE SUMMARY
IP address 8.134.140.22 is associated with ALICLOUD (ASN 37963) infrastructure in Guangzhou, China. Current risk assessment indicates LOW RISK with a risk score of 25/100. The IP demonstrates no active threat indicators, clean neighborhood classification, and minimal operator reputation. No immediate blocking or defensive action recommended.
---
## RISK PROFILE
| Metric | Value | Assessment |
|---|---|---|
| **Risk Score** | 25 | Low Risk |
| **Abuse Confidence** | Not Applicable | N/A |
| **Blacklist Count** | 0 | Clean |
| **Provider Score** | 0 | Neutral |
| **Authority Score** | 0 | Neutral |
| **Stability Score** | 0 | N/A |
---
## NETWORK ATTRIBUTES
- ASN: 37963 (IRT-ASEPL-SG)
- Organization: ALICLOUD
- CIDR Block: 8.128.0.0/11
- BGP Prefix: 8.134.128.0/17
- Geolocation: China (CN), Region: GD, City: Guangzhou
- DNSSEC: Valid
- Operator Score: 0.1304 (Minimal)
---
## NETWORK ROLE & SERVICES
- Service Classification: Firewalled / No Services
- Open Ports: None detected
- TLS Certificate: Not present
- HTTP Services: No banner data
- Not Classified As: CDN, VPN, Proxy, Tor, Hosting, Mobile, Residential, or Bogon
---
## THREAT INDICATORS
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Campaign Affiliation: None
- Correlated IPs: 0
- WAF Violations: 0
- Honeypot Hits: 0
---
## NEIGHBORHOOD ANALYSIS (8.134.140.22/24)
- Abuse Density: 0%
- Subnet Classification: Clean
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 0
- Inherited Risk: 0
The /24 subnet demonstrates zero abuse activity and clean classification across all sibling addresses.
---
## OBSERVATION HISTORY
Total Observations: 16 signals recorded
Latest Activity: 2026-07-29
Key temporal signals:
- Subnet Classification: Clean (0 abuse density)
- Ownership Stability: No changes detected
- Threat Persistence: None observed
- DNS Resolution: Forward resolution not confirmed
- Service Discovery: Ports scanned with no active services detected
No escalating threat patterns observed in signal history.
---
## RELATIONSHIP MAPPING
All identified relationships point to Same Network with target value ALICLOUD. No external entity associations detected (hostnames, certificates, or organizational links beyond network-level).
---
## CONTROL PLANE DATA
- Origin ASN: 37963
- Route Stability: False
- MOAS: No
- IRR Consistency: Not Available
- Route Changes (30d): 0
- DNSBL Listings: 1 of 8 total lists (minimal impact)
---
## RECOMMENDED ACTIONS
Status: No Action Required
- Firewall Rules: Not recommended (risk score below threshold)
- Monitoring Priority: Standard
- Investigation Priority: Low
---
## INTELLIGENCE NOTES
1. The IP appears to be part of firewalled cloud infrastructure with no exposed services.
2. GeoPlausible validation returned false despite CN geolocationβmay indicate routing anomalies or data discrepancy.
3. No DNS or email authentication records detected; IP does not appear to serve mail or domain resolution functions.
4. Clean neighborhood classification suggests the IP operates in isolation from broader abuse activity.
5. No evidence of malicious activity, campaign participation, or reputation degradation.
---
Prepared by: IPDebrief Intelligence Analysis
Data Freshness: Real-time as of 2026-07-29
Confidence Level: High (16 signal observations)
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | IRT-ASEPL-SG |
| ASN | AS37963 |
| Network Name | ALICLOUD |
| CIDR Block | 8.128.0.0/11 |
| RIR | ARIN |
| Country | CN |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-21 06:47:46 UTC |
| Last Seen | 2026-08-04 11:51:34 UTC |
| Profile Built | 2026-07-29 07:59:11 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.