# IP Intelligence Briefing: 106.14.30.244/32
Classification: Moderate Risk โ Requires Monitoring
Date: Analysis completed via IPDebrief intelligence platform
## Executive Summary
IP 106.14.30.244 is a Chinese-origin address associated with ALISOFT network (ASN 37963) operating from Shanghai. The address demonstrates moderate-risk characteristics (score: 65) with historical blacklist associations, though currently shows minimal active service exposure. No open ports or public services are detected on the address.
## Ownership and Registration
- AS Number: 37963 (ALISOFT)
- Organization: security trouble / ALISOFT
- Network Block: 106.14.0.0/15 (APNIC RIR)
- Geolocation: Shanghai, China
- Registration Date: Not available
## Network Classification
- Services: None detected (Firewalled / No Services)
- Network Role: Infrastructure
- Infrastructure Type: Not classified as CDN, Cloud, VPN, or Proxy
- Tor Exit Node: No
- Mobile/Residential: No
## Threat Intelligence Indicators
- Abuse Confidence: Historical listings detected
- Blacklist Status: 2 of 8 total DNSBL lists (historical)
- Known Campaigns: None identified
- Threat Feeds: No active indicators
- Historical Observations: 22 signal observations recorded
## Neighborhood Analysis
- Subnet: 106.14.30.244/24
- Abuse Density: 0
- Subnet Classification: Clean
- Threat Siblings: 1 (historical)
- Active Siblings: 0
- Total Siblings: 1
## Observed Behavioral Patterns
- DNS Reputation: No forward resolution confirmed
- PTR Records: None
- Email Authentication: No SPF/DMARC records
- WAF Violations: 0
- Honeypot Hits: 0
- Enumeration Strikes: 0
## Historical Signal Trends
Recent observations indicate:
- Operator score: 0.2174 (minimal operator activity)
- Historical abuse density: 1 (mostly_clean classification)
- Inherited risk from subnet: 2
- Multiple blacklist listings with high severity noted in historical signals
## Recommended Actions
Based on the moderate-risk profile and historical blacklist associations, the following actions are recommended:
1. Monitor: Add to SIEM monitoring for outbound connections
2. Block: Consider blocking inbound traffic to internal services
3. Rate Limit: Implement rate limiting for any permitted outbound connections
4. Blocklist: Add to organizational threat intelligence blocklists
## Conclusion
The IP address 106.14.30.244 warrants defensive monitoring due to its moderate-risk classification and historical blacklist associations. However, the absence of active services, low operator score, and clean neighborhood classification suggest limited active threat potential. Continued monitoring is recommended to detect any changes in behavior or service activation.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | security trouble |
| ASN | AS37963 |
| Network Name | ALISOFT |
| CIDR Block | 106.14.0.0/15 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 49% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 11% | 1 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 4 |
| geolocation | 19% | 2 | 2 |
| Overall | 24% | 9 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-11 02:49:57 UTC |
| Last Seen | 2026-06-26 06:22:17 UTC |
| Profile Built | 2026-06-26 06:42:33 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 25 |
Full dossier details are available via our API.