# IP Intelligence Briefing: 106.12.18.199/32
## Executive Summary
IP address 106.12.18.199 is assigned to Baidu (ASN 38365) in China and presents a moderate risk profile. The endpoint is currently firewalled with no active services, though it has been flagged on 2 of 8 DNS blacklists. Historical observations confirm consistent ownership under Baidu's network infrastructure since 2011.
## Ownership & Network Classification
- Organization: Baidu Noc (Baidu - Beijing Baidu Netcom Science and Technology Co., Ltd.)
- ASN: 38365
- Network Block: 106.12.0.0/19
- Registry: APNIC
- Registration Date: 2011-03-22
- Classification: Infrastructure endpoint with no active services
## Geolocation
- Country: China (CN)
- Geo Consensus: Confirmed across multiple sources
- Accuracy Radius: 2,500 km
## Threat Assessment
- Overall Risk Score: 50/100 (Moderate Risk)
- Abuse Confidence: Not explicitly scored
- DNSBL Listings: 2 out of 8 total lists
- Known Attacker Status: False
- Tor Exit Node: False
- Spam Source: False
## Network State
- Open Ports: None detected
- Service Status: Firewalled / No Services
- Connection Type: Not residential, cloud, CDN, proxy, or VPN
- HTTP/TLS: No active HTTP or TLS services observed
## Historical Observations
Sixteen observations recorded since 2026-06-02. Key observations include:
- ASN 38365 confirmed via team-cymru-dns
- Geolocation consistently resolved to China (CN)
- Operator score maintained at 0.1304 (Minimal)
- No ownership changes recorded
- Threat persistence: 0 days
- No persistent malicious activity detected
## Relationship Graph
The IP maintains 21 relationship entries, all classified as "Same Network" relationships with Baidu. This indicates the address is part of Baidu's broader network infrastructure.
## Neighborhood Analysis
- Subnet: 106.12.18.199/24
- Abuse Density: 1
- Classification: Mostly clean
- Threat Siblings: 1 identified
- Active Siblings: 1
## Recommended Actions
No specific security actions were generated by the system for this IP. However, given the DNSBL listings and moderate risk score, the following measures are recommended:
1. Monitor DNSBL activity: Track changes in blacklist status across the 8 known lists
2. Firewall rules: Consider rate-limiting inbound traffic if services are ever activated
3. Continue monitoring: Maintain observation history for changes in network role or threat indicators
## Intelligence Assessment
This IP address represents Baidu infrastructure with moderate risk characteristics. The DNSBL listings suggest past abuse activity, but current network state shows no active services. The moderate risk score (50) reflects the combination of blacklist presence and the known association with a major Chinese internet provider.
Threat Level: MODERATE
Priority: LOW-MEDIUM
Recommended Action: MONITOR
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Baidu Noc |
| ASN | AS38365 |
| Network Name | Baidu |
| CIDR Block | 106.12.0.0/15 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 17% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 24% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 20% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:28 UTC |
| Last Seen | 2026-06-26 18:10:19 UTC |
| Profile Built | 2026-06-22 08:12:08 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 25 |
Full dossier details are available via our API.