IP Profile

🖥 152.32.213.86 — UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED

UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED · AS135377 · HK · 152.32.213.0/24 · IP Blocklists · threat 0.50 · 34x · 19 sources

reputation 44.1 (ELEVATED) · first seen 20h ago · last seen 13h ago
No special flags ip medium-severity auto-tagged

Reputation

44.1
ELEVATED

Threat Score

0.50
34 sightings

ASN

AS135377
from indicator

Peers on ASN

3
malicious co-tenants

Bad neighborhood

5
152.32.213.0/24

Country

HK
from indicator

🕵 Team Cymru Scout

Team Cymru Scout not configured — add config.scout.php or set cymruscout in API Config.

🌐 Network & Geo (local-first)

IP152.32.213.86
OrganizationUCLOUD INFORMATION TECHNOLOGY (HK) LIMITED
ASNAS135377
Netname
Netblock
Reverse DNS (PTR)
CountryHK country intel

Identity resolves from the indicator's own columns first, then on demand from the local ip_ranges dataset by integer range — complete even before the bulk resolver runs.

🔥 Threat severity (AS135377 neighborhood)

High (.5-.75)
4
Avg threat 0.5 · peak 0.5 across 4 local IPs on AS135377

📁 Categories (ASN neighborhood)

🦠 Malware families (ASN neighborhood)

No local data.

🏷 Tags (ASN neighborhood)

ip
4
auto-tagged
4
medium-severity
4

🔌 Sources (ASN neighborhood)

FireHOL: firehol_level2.netset
4
Blocklist.de: all
4
IPsum Level 1
4
IPsum Level 2
4
IPsum Level 3
4
IPsum Level 4
4
CI Army
4
Blocklist.de All
4
CINSscore Bad Guys
4
IPsum level 1 (all)
4
FireHOL level2
4
stamparm ipsum
4
Blocklist.de: ssh
3
IPsum level 5
3

🌎 Geographic spread

📅 First-seen timeline

2026-08
4

Reporting Sources for this IP (19)

FireHOL: firehol_level2.netsetIP Blocklists
FireHOL: firehol_level3.netsetIP Blocklists
FireHOL: ciarmy.ipsetIP Blocklists
Blocklist.de: allIP Blocklists
Blocklist.de: sshIP Blocklists
ThreatView IPIP Blocklists
IPsum Level 1IP Blocklists
IPsum Level 2IP Blocklists
IPsum Level 3IP Blocklists
IPsum Level 4IP Blocklists
CI ArmyIP Blocklists
Blocklist.de AllIP Reputation
CINSscore Bad GuysIP Reputation
IPsum level 1 (all)IP Reputation
IPsum level 5IP Reputation
FireHOL level2IP Reputation
FireHOL level3IP Reputation
Blocklist.de SSHIP Reputation
stamparm ipsumReputation

Passive DNS — domains resolving here (0)

No passive DNS yet. Run DNS audit.

🏠 Same /24 — 152.32.213.0/24 (5 other malicious IPs)

Other flagged IPs in the same /24 — a concentration here suggests a compromised or abused block.

IPCategoryFamilyThreat
152.32.213.13 IP Blocklists- dossier
152.32.213.68 IP Blocklists- dossier
152.32.213.67 IP Blocklists- dossier
152.32.213.95 Reputation- dossier
152.32.213.85 IP Blocklists- dossier
All in this subnet Bulk takedown

📡 Related indicators on AS135377 (3 total, 3 shown)

IPCategoryCountryThreat
152.32.252.233 IP BlocklistsHK dossier
152.32.206.35 IP BlocklistsUS dossier
152.32.151.128 IP BlocklistsUS dossier
Full ASN dossier →

Case & Takedown Links

No cases or takedowns yet.

+ Case Takedown

Enrichments

ipinfo

Stored Enrichment Data Enrich Now

1 enrichment records on file (history preserved).

Identity resolves local-first: the indicator's own asn/country columns, else on-demand integer-range lookup against the local ip_ranges dataset — so ASN, org and country populate even before the bulk resolver finishes and even for IPs not yet ingested. Analytics, neighborhood and graph render entirely from the local database; live reputation providers augment only when keys and outbound access are available.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php