IP Intelligence Briefing: 106.52.165.100
Date: 2026-06-17
---
**1. Risk Profile**
- Overall Risk Score: High (80/100)
- Threat Indicators:
- Listed on 4/8 DNSBLs (high-severity categories).
- No direct malware, phishing, or exploit indicators.
- Network Role: Firewalled / No Services (no open ports, no HTTP/TLS services).
- Ownership:
- ASN: 45090 (James Tian, Guangdong, China).
- Linked to TencentCloud infrastructure.
---
**2. Geolocation & Network Context**
- Location: Guangzhou, Guangdong, China (CN).
- Subnet: 106.52.165.0/24 (abuse density: 0%, no active neighbors).
- Routing:
- BGP prefix: 106.52.160.0/20.
- DNSSEC validated, but ICMP unreachable (traceroute failed).
---
**3. Threat Observations**
- Recent Activity (2026-06-17):
- 4/8 DNSBL listings (e.g., Spamhaus, Project Honey Pot).
- Minimal operator risk score (0.13).
- Historical Trends:
- No persistent malicious activity (0 threat persistence days).
- No service enumeration or port scanning detected.
---
**4. Relationships & Subnet**
- Network Affiliation:
- Same subnet as TencentCloud infrastructure.
- No linked hostnames, certificates, or organizations.
- Subnet Analysis:
- Clean subnet (abuse density 0%).
- Isolated IP with no active neighbors.
---
**5. Recommendations**
- Block/monitor: Due to DNSBL listings and high risk score, block this IP unless confirmed legitimate.
- Investigate DNSBLs: Verify validity of listings (e.g., false positives or misconfigured servers).
- Check Infrastructure: Confirm if the TencentCloud association is legitimate or a spoofed route.
- Monitor Subnet: Track for new neighbors or changes in abuse density.
---
Conclusion: This IP is associated with TencentCloud but exhibits suspicious DNSBL activity. While no direct malicious behavior is observed, its high risk score and isolated nature warrant further investigation.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | James Tian |
| ASN | AS45090 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | APNIC |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 30% | 2 | 3 |
| Overall | 22% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:29 UTC |
| Last Seen | 2026-06-26 18:10:20 UTC |
| Profile Built | 2026-06-22 08:13:18 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 20 |
Full dossier details are available via our API.