IPDebrief

106.37.170.66

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 106.37.170.66/32

Classification: High Risk

Date: 2026-07-23

Prepared for: SOC Operations Team

---

## Executive Summary

IP address 106.37.170.66 is classified as High Risk with a risk score of 70/100. The endpoint is associated with CHINANET-BJ (AS4847), a residential infrastructure network operated by China Telecom. Despite the elevated risk classification, no active threat indicators or known campaigns were identified during the current assessment.

---

## Technical Profile

AttributeValue
**IP Address**106.37.170.66/32
**Risk Score**70/100 (High)
**ASN**4847
**Organization**Hostmaster of Beijing Telecom corporation CHINA TELECOM
**Network**CHINANET-BJ (106.37.0.0/16)
**Country**China (CN)
**Region/City**Beijing, China
**Infrastructure Type**Residential Endpoint
**ISP Classification**Tier-1 ISP (China Telecom)

---

## Threat Indicators Assessment

Current Status: No active threat indicators detected.

Observation History: 13 signals recorded across the observation window. Geolocation signals consistently resolve to China (Beijing region), with confidence levels between 0.40 and 0.85. No persistent malicious behavior detected over the observation period.

---

## Network Context

Subnet Analysis (106.37.170.0/24):

Relationship Graph:

---

## Recommended Security Actions

Priority: High Risk Score (70/100)

Monitoring Recommendations:

1. Increase logging verbosity and review recent activity from this IP

2. Monitor for any changes in behavior patterns or service openings

3. Correlate with other security events for context

Recommended Firewall Rules:

```bash

# iptables

iptables -A INPUT -s 106.37.170.66 -j DROP

# nftables

nft add rule inet filter input ip saddr 106.37.170.66 drop

# nginx

deny 106.37.170.66;

# pfSense

106.37.170.66/32

# Cloudflare WAF

{"description":"Block 106.37.170.66 — IPDebrief risk score 70","action":"block"}

# AWS WAF

{"Addresses":["106.37.170.66/32"],"Description":"IPDebrief risk 70"}

```

---

## Operational Notes

This IP is a residential endpoint within a major Chinese ISP network. While the risk score indicates elevated concern, the absence of active threat indicators and known campaign associations suggests the classification may stem from historical data patterns or network-level risk factors rather than confirmed malicious activity.

Decision Framework: Apply blocking rules with monitoring for 7–14 days. Re-evaluate if any observed behavior changes or additional threat intelligence emerges.

---

*Report generated by IPDebrief Intelligence Platform. All data sourced from live network analysis and threat intelligence feeds.*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇨🇳 China
RegionBeijing
CityBeijing
Timezone—
Latitude39.91
Longitude116.40

🏢 Ownership & Registration

OrganizationHostmaster of Beijing Telecom corporation CHINA TELECOM
ASNAS4847
Network NameCHINANET-BJ
CIDR Block106.37.0.0/16
RIRAPNIC
CountryCN
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)

🔐 DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureResidential
Service PurposeResidential Endpoint
Network TierEnd-User — Residential ISP endpoint
Residential

🔌 Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS4847
Network Prefix106.37.0.0/16
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
25%
12
reputation
0%
00
geolocation
0%
00
Overall16%45
Coverage: 4/6 dimensions · Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

📅 Observation Timeline 🔄 Live

First Seen2026-07-05 23:57:37 UTC
Last Seen2026-08-27 08:24:37 UTC
Profile Built2026-08-29 05:03:30 UTC
Data FreshnessLive
Signal Types14
Total Observations16
🔍 14 signal types · 16 observations collected
This report is generated from 14+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 106.37.170.66

Who owns the IP address 106.37.170.66?

106.37.170.66 is registered to Hostmaster of Beijing Telecom corporation CHINA TELECOM. The address falls within the 106.37.0.0/16 network block. Registration is held at APNIC.

Where is 106.37.170.66 located?

Geolocation data places 106.37.170.66 in Beijing, Beijing, China. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 106.37.170.66 malicious or safe?

106.37.170.66 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.

Is 106.37.170.66 a VPN, proxy, or data center address?

106.37.170.66 is classified as a residential network based on network ownership and behavioural analysis.

🏘️ Related IP Addresses

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.