IPDebrief

1.94.17.74

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING: 1.94.17.74/32

Classification: Low Risk / Infrastructure

Date: 2026-07-17

Analysis Status: Complete

---

## EXECUTIVE SUMMARY

IP address 1.94.17.74 is a low-risk infrastructure endpoint originating from China. The address operates under a Chinese internet registry operator with no observed malicious activity. Current risk assessment indicates minimal threat, with the IP showing stable ownership and geolocation attributes over the observation period.

---

## PROFILE DATA

AttributeValue
**Risk Score**25/100
**ASN**55990
**Organization**IRT-CNNIC-CN
**Network Name**DXTNET
**CIDR Block**1.94.0.0/16
**Country/Region**China / Shanghai
**RIR**APNIC
**DNS Hostname**ecs-1-94-17-74.compute.hwclouds-dns.com
**Service Status**Firewalled / No Services

---

## THREAT ASSESSMENT

Threat Indicators: None detected

Abuse Confidence: Not elevated

Blacklist Status: 1 DNSBL listing among 8 total lists (dnsblListedCount: 1, dnsblTotalLists: 8)

---

## NETWORK CONTEXT

Neighborhood Analysis (1.94.17.0/24):

Route Stability: Unstable (isRouteStable: false)

RPKI State: Not validated

---

## OBSERVATION HISTORY

Total Observations: 14 signals recorded

Latest Observation: 2026-07-17T23:43:31 UTC

Temporal Analysis:

Signal Consistency: Geolocation (Shanghai, China) and ownership (IRT-CNNIC-CN, APNIC, 1.94.0.0/16) remain consistent across all historical observations with high confidence scores (0.70-0.95).

---

## RELATIONSHIP GRAPH

Identified Associations (5):

No organizational or certificate relationships identified beyond DNS and network-level associations.

---

## RECOMMENDED ACTIONS

Firewall/Security Recommendations: None

Rationale: The IP address presents a low risk profile with no active threat indicators, no service exposure, and no observed malicious behavior. Standard network access controls are sufficient; no blocking or rate-limiting actions are warranted at this time.

Monitoring: Continue routine traffic observation. No special alerting thresholds recommended.

---

## ANALYST NOTES

This IP represents a benign infrastructure endpoint with no indicators of compromise. The absence of open ports and services suggests this is either an internal management address, a firewall interface, or a reserved address. The single DNSBL listing does not correlate with active threat activity.

Confidence Level: High (based on 14 historical observations and consistent signal patterns)

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇨🇳 China
RegionShanghai
CityShanghai
Timezone—
Latitude31.22
Longitude121.46

🏢 Ownership & Registration

OrganizationIRT-CNNIC-CN
ASNAS55990
Network NameDXTNET
CIDR Block1.94.0.0/16
RIRAPNIC
CountryCN
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRecs-1-94-17-74.compute.hwclouds-dns.com
Forward ConfirmedYes — FCrDNS verified
Forward Hostnamesecs-1-94-17-74.compute.hwclouds-dns.com

🔐 DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierTier 3 — Basic operator with some routing infrastructure
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS55990
Network Prefix1.94.0.0/18
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
0%
00
reputation
0%
00
geolocation
0%
00
Overall12%33
Coverage: 3/6 dimensions · Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

📅 Observation Timeline 🔄 Live

First Seen2026-06-07 19:57:32 UTC
Last Seen2026-07-17 23:40:58 UTC
Profile Built2026-08-30 11:18:32 UTC
Data FreshnessLive
Signal Types19
Total Observations21
🔍 19 signal types · 21 observations collected
This report is generated from 19+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 1.94.17.74

Who owns the IP address 1.94.17.74?

1.94.17.74 is registered to IRT-CNNIC-CN. The address falls within the 1.94.0.0/16 network block. Registration is held at APNIC.

Where is 1.94.17.74 located?

Geolocation data places 1.94.17.74 in Shanghai, Shanghai, China. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 1.94.17.74 malicious or safe?

1.94.17.74 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.

What is the hostname for 1.94.17.74?

The reverse DNS (PTR) record for 1.94.17.74 is ecs-1-94-17-74.compute.hwclouds-dns.com. This hostname is forward-confirmed, meaning it resolves back to the same address.

🏘️ Related IP Addresses

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.