# IP Intelligence Briefing: 106.15.238.36/32
Date: 2026-06-25
Analyst: IPDebrief Intelligence Team
Classification: Defensive Security Intelligence
---
## Executive Summary
The IP address 106.15.238.36 was classified as Moderate Risk (risk score: 65/100) based on comprehensive threat intelligence analysis. The address belongs to the ALISOFT network (ASN 37963) registered under "security trouble" within the APNIC RIR region. The IP demonstrated historical blacklist activity with high-severity listings and currently carries no active service exposure.
---
## Technical Profile
Ownership & Registration:
- ASN: 37963
- Organization: security trouble (ALISOFT)
- CIDR Block: 106.14.0.0/15
- RIR: APNIC
- Abuse Contact: Available via RDAP
Geolocation:
- Country: China (CN)
- Region: Shanghai
- City: Shanghai
- Geographic accuracy radius: 2,500km
Network Role:
- Service Status: Firewalled / No Services
- Infrastructure Type: Not classified as CDN, Cloud, VPN, Proxy, or Tor exit
- Mobile Carrier: Not applicable
---
## Threat Indicators
Blacklist Status:
- DNSBL Listings: 2 listings (8 total lists indexed)
- Maximum Severity: High
- Pulsedive Risk: Not scored
- Known Campaigns: None detected
Abuse Confidence:
- Not flagged as known attacker
- Not flagged as spam source
- Not Tor exit node
- IsTor: False
---
## Historical Observations
Signal observation history revealed 16 observations across multiple time periods. Key temporal patterns:
- 2026-06-25: Multiple blacklist detections with high-severity listings (confidence: 0.85)
- 2026-06-14: Additional blacklist activity with 2 listings detected
- 2026-06-04: Network classification confirmed as residential/infrastructure
- Total: Persistent threat observation activity noted
The IP demonstrated consistent blacklist presence over the observation period, with severity levels maintained at high during recent detection windows.
---
## Network Relationships
The IP maintains relationships exclusively within the ALISOFT network footprint. All 11 relationship entries indicate same-network associations with ALISOFT. No external organizational, certificate, or hostname relationships were identified beyond the parent network.
---
## Neighborhood Analysis
Subnet: 106.15.238.36/24
- Abuse Density: 0 (classified as clean)
- Total Siblings: 1
- Active Siblings: 0
- Threat Siblings: 0
- Risk Distribution: No high, medium, or low risk neighbors detected
The /24 subnet shows no inherited risk from neighboring addresses.
---
## Recommended Actions
Based on the risk profile (65/100), the following security controls are recommended:
Monitoring:
- Increase logging verbosity and review recent activity from this IP
- Severity: High
Firewall Rule Implementation:
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 106.15.238.36 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 106.15.238.36 drop` |
| nginx | `deny 106.15.238.36;` |
| pfSense | `106.15.238.36/32` |
| Cloudflare WAF | Block IP with expression: `ip.src eq 106.15.238.36` |
| AWS WAF | Add to blocklist: `106.15.238.36/32` |
---
## Intelligence Assessment
The IP 106.15.238.36 presents a moderate risk threat profile driven by persistent blacklist activity. While no active services were detected and the immediate neighborhood showed clean abuse density, the historical pattern of high-severity blacklist listings warrants defensive blocking. The lack of service exposure reduces immediate exploitation risk, but the blacklist footprint suggests prior malicious activity or abuse. SOC teams should implement the recommended blocking rules and monitor for any service activation or behavioral changes.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | security trouble |
| ASN | AS37963 |
| Network Name | ALISOFT |
| CIDR Block | 106.14.0.0/15 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 19% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 27% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 18% | 9 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-08 11:09:41 UTC |
| Last Seen | 2026-06-25 20:08:43 UTC |
| Profile Built | 2026-06-25 04:34:01 UTC |
| Data Freshness | Live |
| Signal Types | 15 |
| Total Observations | 16 |
Full dossier details are available via our API.