# IP Intelligence Briefing: 114.80.39.74/32
Classification: Moderate Risk โ No Active Threat Indicators
Date of Analysis: 2026-07-29
Analyst: IPDebrief Intelligence Team
---
## Executive Summary
IP address 114.80.39.74 is assigned to ASN 4811 (CHINANET-SH) under organization Weng Wen Qian. The IP is geolocated to Shanghai, China, and is classified as "Firewalled / No Services" with no open ports or active services detected. Risk scoring indicates moderate risk (50/100) primarily due to DNSBL listings (2 of 8), though no active threat indicators or malicious campaigns have been observed.
---
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **IP Address** | 114.80.39.74/32 |
| **ASN** | 4811 (CHINANET-SH) |
| **Organization** | Weng Wen Qian |
| **CIDR Block** | 114.80.0.0/12 |
| **Country/Region** | CN / Shanghai |
| **BGP Prefix** | 114.80.32.0/21 |
| **Route Stability** | Unstable (0 changes in 30d) |
Network Classification: Not classified as cloud, CDN, VPN, proxy, Tor exit, hosting, or residential infrastructure. No active services detected.
---
## Threat Intelligence Assessment
Risk Scoring
- Overall Risk Score: 50 (Moderate)
- Abuse Confidence Score: Not available
- Blacklist Count: 0 active listings
- Threat Feeds: None populated
Service Enumeration
- Open Ports: None
- TLS Certificates: None
- HTTP Services: None detected
- DNS Records: No PTR, no forward resolution, no hosted domains
- Email Authentication: SPF/DMARC not configured
Threat Indicators
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Campaign Association: None detected
- Total Incidents: 0
---
## Neighborhood Analysis
The /24 subnet (114.80.39.0/24) shows minimal activity:
- Total Siblings: 2
- Active Siblings: 0
- Threat Siblings: 0
- Abuse Density: 0 (clean classification)
- Neighbor Risk Profile: 1 sibling (114.80.39.66) with risk score 25/100
No elevated risk signals from neighboring IPs.
---
## Historical Observations
Observation Count: 15 signals recorded
Key historical signals include:
- 2026-07-29 12:24: Traceroute completed (30 hops, target not reached)
- 2026-07-29 12:20: Ownership stability confirmed (0 changes)
- 2026-07-29 12:18: Geographic inference to CN (Shanghai region, 52% confidence)
- 2026-07-29 12:17: Network classification confirmed (not CDN/Tor/VPN/hosting)
No persistent malicious behavior detected over observation window.
---
## Control Plane Data
- DNSBL Listings: 2 of 8 total lists
- RPKI State: Not validated
- IRR Consistency: Not determined
- Route Changes (30d): 0
- Operator Score: 0.1304 (Minimal)
- GeoValidation: ICMP blocked โ unable to validate
---
## Recommended Security Actions
Firewall Rules
| Platform | Rule |
|---|---|
| **iptables** | `iptables -A INPUT -s 114.80.39.74 -j DROP` |
| **nftables** | `nft add rule inet filter input ip saddr 114.80.39.74 drop` |
| **nginx** | `deny 114.80.39.74;` |
| **pfSense** | `114.80.39.74/32` |
| **Cloudflare WAF** | Block 114.80.39.74 (risk score 50) |
| **AWS WAF** | Add 114.80.39.74/32 to block list |
Note: These recommendations are probabilistic and should be combined with other signals before taking action.
---
## Intelligence Assessment
This IP address represents a low-to-moderate risk asset with no active malicious indicators. The moderate risk score (50) stems primarily from DNSBL presence rather than observed threat activity. The infrastructure shows no signs of being compromised or used for malicious purposes. The /24 neighborhood remains clean with minimal sibling activity.
Recommended Action: Monitor. No immediate blocking required unless additional threat indicators emerge. Standard logging and monitoring recommended.
---
*Report generated using IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Weng Wen Qian |
| ASN | AS4811 |
| Network Name | CHINANET-SH |
| CIDR Block | 114.80.0.0/12 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 25% | 1 | 1 |
| geolocation | 25% | 1 | 1 |
| Overall | 26% | 7 | 8 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-22 07:15:07 UTC |
| Last Seen | 2026-08-13 06:43:33 UTC |
| Profile Built | 2026-07-29 12:32:45 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.