IP Profile

🖥 152.32.252.233 — UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED

UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED · AS135377 · HK · 152.32.252.0/24 · IP Blocklists · threat 0.50 · 27x · 16 sources · PTR No PTR record

reputation 41.6 (ELEVATED) · first seen 2d ago · last seen 1d ago
No special flags ip medium-severity auto-tagged

Reputation

41.6
ELEVATED

Threat Score

0.50
27 sightings

ASN

AS135377
from indicator

Peers on ASN

4
malicious co-tenants

Bad neighborhood

2
152.32.252.0/24

Country

HK
from indicator

🕵 Team Cymru Scout

Team Cymru Scout not configured — add config.scout.php or set cymruscout in API Config.

🌐 Network & Geo (local-first)

IP152.32.252.233
OrganizationUCLOUD INFORMATION TECHNOLOGY (HK) LIMITED
ASNAS135377
Netname
Netblock
Reverse DNS (PTR)No PTR record
CountryHK country intel
Abuse contactsearch-apnic-not-arin@apnic.net

Identity resolves from the indicator's own columns first, then on demand from the local ip_ranges dataset by integer range — complete even before the bulk resolver runs.

🔥 Threat severity (AS135377 neighborhood)

High (.5-.75)
5
Avg threat 0.5 · peak 0.5 across 5 local IPs on AS135377

📁 Categories (ASN neighborhood)

🦠 Malware families (ASN neighborhood)

No local data.

🏷 Tags (ASN neighborhood)

ip
5
auto-tagged
5
medium-severity
5

🔌 Sources (ASN neighborhood)

FireHOL: firehol_level2.netset
4
Blocklist.de: all
4
IPsum Level 1
4
IPsum Level 2
4
IPsum Level 3
4
IPsum Level 4
4
CI Army
4
Blocklist.de All
4
CINSscore Bad Guys
4
IPsum level 1 (all)
4
FireHOL level2
4
FireHOL level3
4
stamparm ipsum
4
FireHOL: firehol_level3.netset
3

🌎 Geographic spread

📅 First-seen timeline

2026-08
5

Reporting Sources for this IP (16)

FireHOL: firehol_level2.netsetIP Blocklists
FireHOL: iblocklist_ciarmy_malicious.netsetIP Blocklists
Blocklist.de: allIP Blocklists
Blocklist.de: sshIP Blocklists
ThreatView IPIP Blocklists
IPsum Level 1IP Blocklists
IPsum Level 2IP Blocklists
IPsum Level 3IP Blocklists
IPsum Level 4IP Blocklists
CI ArmyIP Blocklists
Blocklist.de AllIP Reputation
CINSscore Bad GuysIP Reputation
IPsum level 1 (all)IP Reputation
FireHOL level2IP Reputation
Blocklist.de SSHIP Reputation
stamparm ipsumReputation

Passive DNS — domains resolving here (0)

No passive DNS yet. Run DNS audit.

🏠 Same /24 — 152.32.252.0/24 (2 other malicious IPs)

Other flagged IPs in the same /24 — a concentration here suggests a compromised or abused block.

IPCategoryFamilyThreat
152.32.252.94 IP Blocklists- dossier
152.32.252.65 IP Blocklists- dossier
All in this subnet Bulk takedown

Case & Takedown Links

No cases or takedowns yet.

+ Case Takedown

Enrichments

ipinfo

Stored Enrichment Data Enrich Now

1 enrichment records on file (history preserved).

📁 Case Management

+ New case from this
Identity resolves local-first: the indicator's own asn/country columns, else on-demand integer-range lookup against the local ip_ranges dataset — so ASN, org and country populate even before the bulk resolver finishes and even for IPs not yet ingested. Analytics, neighborhood and graph render entirely from the local database; live reputation providers augment only when keys and outbound access are available.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php