# IP Intelligence Briefing: 106.89.51.228/32
Date: 2026-07-29
Classification: High Risk
Source: IPDebrief Intelligence Platform
---
## Executive Summary
IP address 106.89.51.228 presents an elevated threat profile with a risk score of 70/100. The IP is registered to CHINANET CQ (China Telecom) under ASN 141739 and is associated with multiple DNSBL listings. Current network classification indicates the IP is firewalled with no active services detected. Despite the high-risk classification, the subnet shows 0% abuse density with no active threat siblings observed in the /24 range.
---
## Risk Assessment
| Metric | Value | Assessment |
|---|---|---|
| Risk Score | 70/100 | High Risk |
| Provider Score | 0/100 | Neutral |
| Authority Score | 0/100 | Neutral |
| Stability Score | 0/100 | Data Limited |
| DNSBL Listed | 4/8 lists | Elevated Concern |
| Active Services | None | Firewalled |
---
## Ownership & Network Attribution
- Organization: CHINANET CQ (CT-CHONGQING-MAN2-AP)
- ASN: 141739
- Country: China (CN)
- CIDR Block: 106.80.0.0/12
- RIR: APNIC
- Registration Date: 2011-03-18 (BGP Prefix)
- Control Plane: BGP prefix 106.89.48.0/20; Route stability: false
---
## Threat Indicators
- Blacklist Count: 4 DNSBL listings across 8 total lists
- Maximum Severity: High
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaign Association: None detected
- Honeypot Hits: 0
- WAF Violations: 0
---
## Geolocation & Network Data
- Country: China (CN)
- Coordinates: 34.7732, 113.722
- Geolocation Confidence: 0.70
- DNSSEC Valid: Yes
- Traceroute Hops: 30 (29 timeouts)
- RTT: First hop 0.1ms; Last hop 0.1ms
---
## Service & DNS Analysis
- Open Ports: None detected
- TLS Certificate: Not present
- Reverse DNS PTR: Not configured
- Forward Resolution: Failed
- Hosted Domains: 0
- Email Authentication: SPF/DMARC not configured
---
## Temporal & Historical Analysis
Observation History (11 total observations):
Recent signals (2026-07-29):
- Subnet Classification: Clean with 0 inherited risk
- Geolocation: China (maxmind-geolite2-city source)
- ASN: 141739 (CT-CHONGQING-MAN2-AP)
- Blacklist Status: 4 listings, max severity high
- DNSSEC: Valid
- Ownership Changes: 0
- Threat Persistence Days: 0
- Observation Count: 0 (persistent malicious activity)
- Is Persistently Malicious: False
---
## Neighborhood Analysis
Subnet: 106.89.51.228/24
| Metric | Value |
|---|---|
| Neighbor Count | 0 |
| Abuse Density | 0% |
| High Risk Neighbors | 0 |
| Medium Risk Neighbors | 0 |
| Low Risk Neighbors | 0 |
| Threat Siblings | 0 |
Assessment: No neighboring IPs detected in the immediate /24 range. The subnet shows no inherited risk, suggesting this IP is an outlier within its assigned block.
---
## Relationship Graph
Connected Entities:
- Same Network: CHINANET-CQ
No additional relationships detected (subnets, hostnames, organizations, or certificates).
---
## Recommended Security Actions
Immediate Actions (High Severity)
1. Increase Logging Verbosity
- Review recent activity from this IP address
- Monitor for any connection attempts or scanning behavior
Firewall Rules
Deploy the following blocking rules across security infrastructure:
| Platform | Rule |
|---|---|
| **iptables** | `iptables -A INPUT -s 106.89.51.228 -j DROP` |
| **nftables** | `nft add rule inet filter input ip saddr 106.89.51.228 drop` |
| **nginx** | `deny 106.89.51.228;` |
| **pfSense** | `106.89.51.228/32` |
| **Cloudflare WAF** | Block IP 106.89.51.228 |
| **AWS WAF** | Address: 106.89.51.228/32 |
---
## Intelligence Assessment & Context
The IP address 106.89.51.228 registers as a high-risk entity (70/100) primarily due to DNSBL listings (4/8 total). The IP is associated with China Telecom's CHINANET CQ infrastructure. Despite the elevated risk score, no active services or open ports are detected, and the subnet shows zero abuse density.
The 4 DNSBL listings with "high" severity represent the primary threat signal. This pattern may indicate the IP was used in past malicious activity or has been flagged by reputation services. The absence of active services suggests the IP may be dormant, reserved, or part of a residential/business infrastructure rather than an active C2 or scanning endpoint.
Recommended Monitoring Strategy:
- Implement the recommended blocking rules
- Monitor for any traffic activity from this IP
- Investigate the origin of DNSBL listings if not already documented
- Consider broader monitoring of the 106.89.48.0/20 prefix given the route instability flag
---
Briefing Prepared: IPDebrief Intelligence Platform
Confidence Level: Medium (limited historical data points)
Action Required: Implement firewall rules; monitor for activity
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | CHINANET CQ |
| ASN | AS141739 |
| Network Name | CHINANET-CQ |
| CIDR Block | 106.80.0.0/12 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 4% | 1 | 2 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-22 01:10:49 UTC |
| Last Seen | 2026-07-29 11:24:14 UTC |
| Profile Built | 2026-07-29 11:38:55 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.