# IP Intelligence Briefing: 106.37.170.66/32
Classification: High Risk
Date: 2026-07-23
Prepared for: SOC Operations Team
---
## Executive Summary
IP address 106.37.170.66 is classified as High Risk with a risk score of 70/100. The endpoint is associated with CHINANET-BJ (AS4847), a residential infrastructure network operated by China Telecom. Despite the elevated risk classification, no active threat indicators or known campaigns were identified during the current assessment.
---
## Technical Profile
| Attribute | Value |
|---|---|
| **IP Address** | 106.37.170.66/32 |
| **Risk Score** | 70/100 (High) |
| **ASN** | 4847 |
| **Organization** | Hostmaster of Beijing Telecom corporation CHINA TELECOM |
| **Network** | CHINANET-BJ (106.37.0.0/16) |
| **Country** | China (CN) |
| **Region/City** | Beijing, China |
| **Infrastructure Type** | Residential Endpoint |
| **ISP Classification** | Tier-1 ISP (China Telecom) |
---
## Threat Indicators Assessment
Current Status: No active threat indicators detected.
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Blacklist Count: 0
- DNSBL Listings: 4 of 8 total lists checked
- Active Campaigns: None identified
- Threat Persistence: 0 days observed
Observation History: 13 signals recorded across the observation window. Geolocation signals consistently resolve to China (Beijing region), with confidence levels between 0.40 and 0.85. No persistent malicious behavior detected over the observation period.
---
## Network Context
Subnet Analysis (106.37.170.0/24):
- Neighbor Count: 0 (isolated /24 assessment)
- Abuse Density: 0
- Active Threat Siblings: 0
- Classification: Clean subnet environment
Relationship Graph:
- Associated with CHINANET-BJ network
- No certificate or hostname relationships detected
- No correlated malicious IPs identified
---
## Recommended Security Actions
Priority: High Risk Score (70/100)
Monitoring Recommendations:
1. Increase logging verbosity and review recent activity from this IP
2. Monitor for any changes in behavior patterns or service openings
3. Correlate with other security events for context
Recommended Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 106.37.170.66 -j DROP
# nftables
nft add rule inet filter input ip saddr 106.37.170.66 drop
# nginx
deny 106.37.170.66;
# pfSense
106.37.170.66/32
# Cloudflare WAF
{"description":"Block 106.37.170.66 — IPDebrief risk score 70","action":"block"}
# AWS WAF
{"Addresses":["106.37.170.66/32"],"Description":"IPDebrief risk 70"}
```
---
## Operational Notes
This IP is a residential endpoint within a major Chinese ISP network. While the risk score indicates elevated concern, the absence of active threat indicators and known campaign associations suggests the classification may stem from historical data patterns or network-level risk factors rather than confirmed malicious activity.
Decision Framework: Apply blocking rules with monitoring for 7–14 days. Re-evaluate if any observed behavior changes or additional threat intelligence emerges.
---
*Report generated by IPDebrief Intelligence Platform. All data sourced from live network analysis and threat intelligence feeds.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Hostmaster of Beijing Telecom corporation CHINA TELECOM |
| ASN | AS4847 |
| Network Name | CHINANET-BJ |
| CIDR Block | 106.37.0.0/16 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Residential |
| Service Purpose | Residential Endpoint |
| Network Tier | End-User — Residential ISP endpoint |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS4847 |
| Network Prefix | 106.37.0.0/16 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-05 23:57:37 UTC |
| Last Seen | 2026-08-27 08:24:37 UTC |
| Profile Built | 2026-08-29 05:03:30 UTC |
| Data Freshness | Live |
| Signal Types | 14 |
| Total Observations | 16 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 106.37.170.66
Who owns the IP address 106.37.170.66?
106.37.170.66 is registered to Hostmaster of Beijing Telecom corporation CHINA TELECOM. The address falls within the 106.37.0.0/16 network block. Registration is held at APNIC.
Where is 106.37.170.66 located?
Geolocation data places 106.37.170.66 in Beijing, Beijing, China. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 106.37.170.66 malicious or safe?
106.37.170.66 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
Is 106.37.170.66 a VPN, proxy, or data center address?
106.37.170.66 is classified as a residential network based on network ownership and behavioural analysis.