# Threat Intelligence Briefing: 114.214.164.242
Classification: Low Risk | Risk Score: 15/100
## Executive Summary
IP 114.214.164.242 presents a low-risk threat profile with no active malicious indicators. The address is classified as a firewalled endpoint with no accessible services. No threat campaigns, blacklists, or abuse indicators have been identified. The IP belongs to China's academic/research network infrastructure (NJR-CERNET).
## Infrastructure Profile
- ASN: 4538 (IRT-CERNET-AP)
- Network: NJR-CERNET (114.214.0.0/16)
- Country: China (CN)
- Network Type: Academic/Research Infrastructure
- Service Status: Firewalled / No Services
- DNSSEC: Valid
## Threat Assessment
| Indicator | Status |
|---|---|
| Known Attacker | False |
| Spam Source | False |
| Tor Exit Node | False |
| Known Campaign | None |
| Blacklist Count | 0 |
| Abuse Confidence | Not Applicable |
| Persistent Malicious Activity | False |
## Network Behavior
- Open Ports: None detected
- TLS Certificates: None
- HTTP Services: None
- Scanned: No service enumeration strikes recorded
- Honeypot Hits: 0
- WAF Violations: 0
## Neighborhood Analysis
The /24 subnet (114.214.164.0/24) shows clean characteristics:
- Abuse Density: 0
- Threat Siblings: 0
- Active Siblings: 0
- Classification: Clean
## Control Plane Observations
- Route Stability: Stable (0 changes in 30 days)
- DNSBL Listings: 1/8 total lists
- Operator Score: 0.1304 (Minimal)
- BGP Origin: 114.214.0.0/16
- MOAS: False
## Temporal Analysis
- Ownership Changes: 0
- Threat Persistence Days: 0
- Threat Observation Count: 0
- Observation Count: 17 historical signals
## Recommended Actions
No immediate firewall or blocking actions recommended. The IP exhibits benign network characteristics consistent with residential or academic infrastructure.
Suggested Monitoring:
- Add to passive monitoring list for baseline activity
- Monitor for service enumeration or port scanning activity
- Review if this IP appears in security event logs
## SOC Analyst Notes
This IP represents legitimate academic/research network infrastructure in China. The address has no active threat indicators, no associated malicious campaigns, and operates within a clean subnet environment. No defensive action is currently warranted.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | IRT-CERNET-AP |
| ASN | AS4538 |
| Network Name | NJR-CERNET |
| CIDR Block | 114.214.0.0/16 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS4538 |
| Network Prefix | 114.214.0.0/16 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 34% | 2 | 5 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 36% | 2 | 7 |
| reputation | 25% | 1 | 4 |
| geolocation | 25% | 2 | 4 |
| Overall | 23% | 10 | 23 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-13 15:24:01 UTC |
| Last Seen | 2026-09-03 14:44:02 UTC |
| Profile Built | 2026-09-03 14:46:19 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 28 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 114.214.164.242
Who owns the IP address 114.214.164.242?
114.214.164.242 is registered to IRT-CERNET-AP. The address falls within the 114.214.0.0/16 network block. Registration is held at APNIC.
Where is 114.214.164.242 located?
Geolocation data places 114.214.164.242 in China. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 114.214.164.242 malicious or safe?
114.214.164.242 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.