INTELLIGENCE BRIEFING: 8.136.39.170/32
Classification: LOW RISK โ Cloud Infrastructure
Executive Summary:
The target IP 8.136.39.170 is identified as Alibaba Cloud (ALICLOUD) infrastructure in Hangzhou, China (AS37963). Risk scoring indicates low threat posture with no known abuse indicators. The address operates as a firewalled cloud compute resource with no exposed services.
---
Infrastructure Profile:
- Network: 8.136.39.170/24 (subnet analysis: 0 neighboring IPs, 0% abuse density)
- ASN: 37963 (IRT-ASEPL-SG)
- Organization: ALICLOUD / Alibaba Cloud
- Geolocation: China, Zhejiang, Hangzhou
- Infrastructure Type: Cloud Compute (hosting enabled)
- Service Status: Firewalled / No Services โ no open ports detected
---
Threat Assessment:
- Risk Score: 0 (Low Risk)
- Threat Indicators: None detected
- Blacklist Status: Not listed (0 DNSBL entries)
- Known Attacker: False
- Tor Exit Node: False
- Campaign Association: No known campaigns
---
Observation History (Last 13 Signals):
Recent activity dated July 30, 2026 shows consistent ownership attribution to Alibaba Cloud infrastructure. No behavioral anomalies or threat signal escalation observed. Stability metrics indicate persistent low-risk classification.
---
Relationship Network:
- 2 network-level relationships identified (ALICLOUD)
- No hostname, certificate, or organizational relationships beyond network attribution
---
Recommended Actions:
No immediate defensive actions required. IP is classified as benign cloud infrastructure.
SOC Analyst Guidance:
- Allow/Log: Standard permitting with logging recommended for forensic baseline
- No Block Required: No firewall rules generated
- Monitoring: Standard cloud infrastructure monitoring applies
- Context: Legitimate Alibaba Cloud compute infrastructure with no exposed services
Intelligence Confidence: High โ Consistent cloud provider attribution, no threat signals, stable infrastructure profile.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-ASEPL-SG |
| ASN | AS37963 |
| Network Name | ALICLOUD |
| CIDR Block | 8.128.0.0/11 |
| RIR | ARIN |
| Country | CN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 21% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-27 09:39:47 UTC |
| Last Seen | 2026-08-09 04:43:27 UTC |
| Profile Built | 2026-08-08 04:24:24 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.