Skip to main content
This is a single IPv4 address, assigned to ASN AS4837 (China Unicom) and originating from China: a Crime Score of 432, flagged Critical, backed by 16,199 reports from 28 Alliance members contributing 76 unique IoC points, first seen over a year ago, and last active 27 minutes before this lookup.

Zero local events, still Critical

The “Reported Events” panel on this card shows zero — this organization has never logged traffic from this address itself. The Critical classification comes entirely from the other 27 members who have. That’s the practical effect of cross-member correlation: an indicator can arrive at a perimeter pre-scored as dangerous, before it ever shows up in that organization’s own logs.

Protection isn’t uniform across the fleet

Ten enforcement agents are tracked against this indicator. Five show as Protected — a mix of Checkpoint deployments and a Fortinet device. Five show as Exposed, including a perimeter firewall in one data center. Same organization, same threat data, same score — but the block isn’t applied everywhere yet. That gap is exactly what a policy sync across the fleet is meant to close.

A year of activity, no decay

The historical chart behind this score covers 103 snapshots over roughly a year, trending upward rather than flattening out. Crime Scores decay when an indicator goes quiet; this one hasn’t, because it keeps generating fresh reports — the most recent one 27 minutes before this lookup. A year-old indicator that’s still active scores differently than one that spiked once and disappeared.
Proof of Value engagements surface indicators like this one already present in a client’s own traffic. Start a Proof of Value.