## Intelligence Briefing: 106.63.26.27/32
Date: 2026-07-26
Classification: Low Risk
Status: Active Monitoring
Executive Summary
IP address 106.63.26.27 presents a low-risk threat profile with an overall risk score of 25. The address is associated with CT-CLOUDYCOMPANY (AS141679) within the 106.63.0.0/17 CIDR block under APNIC registration. No active malicious indicators detected; the IP is classified as clean with no known campaigns or persistent threat behavior.
Technical Profile
Ownership & Registration:
- ASN: 141679
- Organization: zhiyong liu
- Netname: CT-CLOUDYCOMPANY
- RIR: APNIC
- CIDR Block: 106.63.0.0/17
Geolocation:
- Country: CN (China)
- Geo Validation: ICMP blocked - unable to validate
- Distance: 8033.2 km from probe origin
- Geo Consensus: True (plausible)
Network Role Classification:
- Firewalled / No Services detected
- Not classified as CDN, proxy, VPN, hosting, mobile, or cloud infrastructure
- Not identified as Tor exit node or known attacker
DNS & Services:
- No PTR hostnames resolved
- No forward DNS resolution confirmed
- Zero open ports detected
- No TLS certificates or HTTP banners observed
Threat Indicators:
- Abuse Confidence Score: Not applicable
- Blacklist Count: 0
- DNSBL Listed: 1 of 8 total lists
- Known Campaigns: None
- Threat Feeds: Empty
Neighborhood Analysis (106.63.26.0/24)
Subnet Statistics:
- Abuse Density: 0 (clean)
- Total Siblings: 7
- Active Siblings: 1
- Threat Siblings: 0
Neighbor Risk Distribution:
- High Risk: 0
- Medium Risk: 0
- Low Risk: 3
Notable Neighbors:
- 106.63.26.13: Risk Score 0
- 106.63.26.15: Risk Score 25
- Remaining neighbors (106.63.26.14, 106.63.26.131, 106.63.26.132, 106.63.26.156): Null risk scores
Observation History (18 Signals)
Recent monitoring activity indicates stable behavior with no escalation in threat indicators. Key historical signals include:
- Subnet classification consistently "clean" with inherited risk of 0
- No ownership changes detected
- No threat persistence patterns observed
- Geo validation challenges (ICMP blocked)
- No campaign likelihood or correlated IPs
Relationship Graph
All five detected relationships map to "Same Network" entries for CT-CLOUDYCOMPANY. No external relationships to organizations, hostnames, domains, or certificates identified.
Recommended Actions
Based on the low-risk profile and absence of active threat indicators, no immediate blocking or mitigation actions are required. The IP demonstrates:
- Low risk score (25)
- Clean subnet classification (0 abuse density)
- No blacklist presence
- No active malicious campaigns
Monitoring Recommendation: Continue standard observation. No firewall rules recommended at this time.
---
*Data source: IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | zhiyong liu |
| ASN | AS141679 |
| Network Name | CT-CLOUDYCOMPANY |
| CIDR Block | 106.63.0.0/17 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS141679 |
| Network Prefix | 106.63.0.0/17 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-11 08:21:27 UTC |
| Last Seen | 2026-09-02 23:31:23 UTC |
| Profile Built | 2026-09-02 23:35:43 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 24 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 106.63.26.27
Who owns the IP address 106.63.26.27?
106.63.26.27 is registered to zhiyong liu. The address falls within the 106.63.0.0/17 network block. Registration is held at APNIC.
Where is 106.63.26.27 located?
Geolocation data places 106.63.26.27 in China. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 106.63.26.27 malicious or safe?
106.63.26.27 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.