# IP INTELLIGENCE BRIEFING: 110.25.109.70/32
## Executive Summary
IP 110.25.109.70 presents a moderate risk profile (Risk Score: 40) originating from Taiwan. The IP is associated with FEG-MPLS-NETWORK-NET under ASN 9674. While the address itself shows no active open services, the /24 subnet exhibits high abuse density with 12 active neighbors, 9 of which are threat siblings.
## Ownership and Infrastructure
- Organization: Jeff Ho / FEG-MPLS-NETWORK-NET
- ASN: 9674 (APNIC RIR)
- CIDR Block: 110.25.0.0/16
- Geolocation: Panchiao, Taipei, Taiwan (23.7°N, 120.96°E)
- Reverse DNS: 110-25-109-70.adsl.fetnet.net
- Classification: Firewalled / No Services (no open ports or TLS certificates detected)
## Threat Indicators
- Risk Score: 40 (Moderate Risk)
- DNSBL Listings: 2 of 8 total lists
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Campaign Activity: None detected
- Threat Persistence: 0 days observed
## Neighborhood Analysis
The /24 subnet (110.25.109.70/24) demonstrates elevated abuse characteristics:
- Abuse Density: 0.6923 (High Abuse)
- Active Neighbors: 12
- Threat Siblings: 9
- Risk Distribution: 2 high-risk (70-80), 10 medium-risk (40-55), 0 low-risk
Notable high-risk neighbors:
- 110.25.109.52 (Risk: 80)
- 110.25.109.54 (Risk: 80)
- 110.25.109.53 (Risk: 70)
- 110.25.109.58 (Risk: 70)
## Temporal Analysis
Observation history indicates 24 recorded signals with consistent geographic attribution to Taiwan. The IP maintains moderate risk stability with no evidence of escalating malicious activity. Recent observations (June 2026 timeframe) show continued presence in blacklist databases.
## Recommended Actions
Based on the risk profile, the following blocking rules are recommended across security infrastructure:
Firewall Rules:
- `iptables -A INPUT -s 110.25.109.70 -j DROP`
- `nft add rule inet filter input ip saddr 110.25.109.70 drop`
- `nginx: deny 110.25.109.70;`
- `pfSense: 110.25.109.70/32`
- Cloudflare WAF: Block IP with expression `ip.src eq 110.25.109.70`
- AWS WAF: Include address `110.25.109.70/32`
## Intelligence Notes
1. Subnet Context: The parent /24 subnet shows high abuse density (0.6923), suggesting coordinated or shared infrastructure usage. Blocking the individual IP may not mitigate broader subnet-level risks.
2. No Active Services: The IP appears firewalled with no detectable open ports or web services, limiting direct exploitation vectors.
3. Geographic Consistency: Multiple observation signals confirm Taiwan origin with consistent reverse DNS resolution.
4. Blacklist Presence: Presence on 2 DNSBLs warrants continued monitoring but indicates limited spam distribution activity.
## Conclusion
IP 110.25.109.70 represents a moderate-risk infrastructure address from Taiwan with no active service exposure. The high-abuse density of the /24 subnet suggests potential for related malicious activity from neighboring addresses. Recommended action is blocking at perimeter defense layers with continued monitoring of subnet-level activity patterns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Jeff Ho |
| ASN | AS9674 |
| Network Name | FEG-MPLS-NETWORK-NET |
| CIDR Block | 110.25.0.0/16 |
| RIR | APNIC |
| Country | TW |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | 110-25-109-70.adsl.fetnet.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | 110-25-109-70.adsl.fetnet.net |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 24% | 2 | 3 |
| ownership | 19% | 2 | 2 |
| reputation | 26% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:30 UTC |
| Last Seen | 2026-06-22 08:47:19 UTC |
| Profile Built | 2026-06-22 08:56:08 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 24 |
Full dossier details are available via our API.