# IP Intelligence Briefing: 101.126.71.100/32
## Executive Summary
IP address 101.126.71.100 presents a moderate risk profile (risk score: 50) with moderate abuse indicators. The address is owned by IRT-VOLCANO-ENGINE-CN (ASN 137718) in China and shows minimal active services. Two DNSBL listings indicate prior reputation issues, though current threat indicators are absent.
## Profile Overview
Ownership:
- ASN: 137718
- Organization: IRT-VOLCANO-ENGINE-CN
- RIR: APNIC
- CIDR Block: 101.126.64.0/21
Geolocation:
- Country: China (CN)
- Accuracy: 2,500km radius
- Geo Validation: Plausible (via multi-signal inference)
Reputation:
- Risk Score: 50 (Moderate Risk)
- Provider Score: 0
- Authority Score: 0
- Operator Score: 0.1304 (Minimal)
## Network Role
- Classification: Firewalled / No Services
- Open Ports: None detected
- Services: No HTTP/TLS banners captured
- Infrastructure: Not cloud, CDN, VPN, proxy, Tor, hosting, mobile, or residential
## Threat Indicators
- Blacklist Count: 0
- DNSBL Listed: 2 of 8 total lists
- Tor Exit: No
- Known Attacker: No
- Spam Source: No
- Active Threat Campaigns: None
- Known Campaign Matches: 0
## Neighborhood Analysis
- Subnet: 101.126.71.100/24
- Abuse Density: 1
- Classification: Mostly Clean
- Threat Siblings: 1
- Inherited Risk: 2
## Observation History
Twenty-two signals observed since June 2026. Key findings:
- June 8, 2026: DNSBL listings detected (2 of 8 lists, high severity)
- June 17, 2026: Recent signals show minimal operator risk (0.15 raw score)
- June 17, 2026: Geolocation confirmed as China (confidence: 0.52)
- Route stability: Stable (0 changes in 30 days)
- IRR Consistency: Match
## Relationships
Fifteen relationships detected, all classified as "Same Network" (VOLCANO-ENGINE), indicating consistent infrastructure association.
## Recommended Actions
Blocking Rules Ready for Deployment:
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 101.126.71.100 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 101.126.71.100 drop` |
| nginx | `deny 101.126.71.100;` |
| pfSense | `101.126.71.100/32` |
| Cloudflare WAF | Block with expression: `ip.src eq 101.126.71.100` |
| AWS WAF | Add `101.126.71.100/32` to rule |
## Assessment
This IP address shows moderate risk primarily driven by historical DNSBL listings. Current operational status indicates minimal threat activity with no open services. The lack of active threat indicators and firewalled status suggest this may be a dormant or controlled resource. However, the two DNSBL listings warrant continued monitoring. The neighborhood shows one threat sibling, indicating potential associated infrastructure requiring attention.
Recommended SOC Action: Block traffic to this IP address while monitoring for related activity in the /24 subnet. Maintain watch on the VOLCANO-ENGINE network for correlated incidents.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-VOLCANO-ENGINE-CN |
| ASN | AS137718 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | APNIC |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 5 |
| routing | 22% | 3 | 3 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 21% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 25% | 12 | 19 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (65%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:23 UTC |
| Last Seen | 2026-06-26 18:10:09 UTC |
| Profile Built | 2026-06-22 05:30:47 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 24 |
Full dossier details are available via our API.