IP Profile

🖥 47.251.89.134 — Alibaba (US) Technology Co., Ltd.

Alibaba (US) Technology Co., Ltd. · AS45102 · US · 47.251.89.0/24 · Reputation · threat 0.50 · 1x · 1 sources

reputation 34 (GUARDED) · first seen 10h ago · last seen 10h ago
No special flags

Reputation

34
GUARDED

Threat Score

0.50
1 sightings

ASN

AS45102
from indicator

Peers on ASN

2
malicious co-tenants

Bad neighborhood

2
47.251.89.0/24

Country

US
from indicator

🕵 Team Cymru Scout

Team Cymru Scout not configured — add config.scout.php or set cymruscout in API Config.

🌐 Network & Geo (local-first)

IP47.251.89.134
OrganizationAlibaba (US) Technology Co., Ltd.
ASNAS45102
Netname
Netblock
Reverse DNS (PTR)
CountryUS country intel

Identity resolves from the indicator's own columns first, then on demand from the local ip_ranges dataset by integer range — complete even before the bulk resolver runs.

🔥 Threat severity (AS45102 neighborhood)

High (.5-.75)
3
Avg threat 0.5 · peak 0.5 across 3 local IPs on AS45102

📁 Categories (ASN neighborhood)

🦠 Malware families (ASN neighborhood)

No local data.

🏷 Tags (ASN neighborhood)

auto-tagged
1
medium-severity
1
ip
1

🔌 Sources (ASN neighborhood)

stamparm ipsum
3
IPsum Level 3
1
IPsum Level 4
1
CI Army
1
Blocklist.de All
1
CINSscore Bad Guys
1
IPsum level 1 (all)
1
FireHOL level2
1
Blocklist.de SSH
1
FireHOL: firehol_level2.netset
1
FireHOL: firehol_level3.netset
1
FireHOL: ciarmy.ipset
1
Blocklist.de: all
1
Blocklist.de: ssh
1

🌎 Geographic spread

📅 First-seen timeline

2026-08
3

Reporting Sources for this IP (1)

stamparm ipsumReputation

Passive DNS — domains resolving here (0)

No passive DNS yet. Run DNS audit.

🏠 Same /24 — 47.251.89.0/24 (2 other malicious IPs)

Other flagged IPs in the same /24 — a concentration here suggests a compromised or abused block.

IPCategoryFamilyThreat
47.251.89.71 IP Blocklists- dossier
47.251.89.204 IP Blocklists- dossier
All in this subnet Bulk takedown

📡 Related indicators on AS45102 (2 total, 2 shown)

IPCategoryCountryThreat
47.239.15.182 ReputationHK dossier
47.74.213.140 IP BlocklistsSG dossier
Full ASN dossier →

Case & Takedown Links

No cases or takedowns yet.

+ Case Takedown

Enrichments

ipinfo

Stored Enrichment Data Enrich Now

Pulled 1 provider(s) just now.

1 enrichment records on file (history preserved).

Identity resolves local-first: the indicator's own asn/country columns, else on-demand integer-range lookup against the local ip_ranges dataset — so ASN, org and country populate even before the bulk resolver finishes and even for IPs not yet ingested. Analytics, neighborhood and graph render entirely from the local database; live reputation providers augment only when keys and outbound access are available.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php