# IP INTELLIGENCE BRIEFING
Target: 114.94.211.10/32
Classification: High Risk
Report Date: Current
---
## EXECUTIVE SUMMARY
IP address 114.94.211.10 is registered to APNIC RIR region and geolocated to Hangzhou, Zhejiang, China (ASN 4812). The IP exhibits an elevated risk score of 80/100 despite showing minimal active network services. Control plane analysis indicates route instability with five DNSBL listings across eight major reputation feeds. Current classification shows the subnet as "clean" with zero threat siblings, suggesting the risk profile may be derived from historical reputation rather than active malicious behavior.
## TECHNICAL PROFILE
Geolocation:
- Country: China (CN)
- Region: Zhejiang Province
- City: Hangzhou
- Coordinates: 30.29°N, 120.17°E
- Timezone: Asia/Shanghai
Network Classification:
- ASN: 4812
- BGP Prefix: 114.94.0.0/16
- Control Plane Status: Unstable (isRouteStable: false)
- MOAS Status: Negative
- RPKI State: Not evaluated
- Route Changes (30d): 0
DNS & Reputation:
- DNSBL Listed: 5 of 8 total lists
- Forward Resolution: Confirmed negative
- PTR Hostnames: None
- Abuse Contact: anti-spam@chinatelecom.cn
- Historical Organization: Weng Wen Qian
Network Services:
- Open Ports: None detected
- TLS/HTTP: No services available
- Classification: Firewalled / No Services
Subnet Analysis (114.94.211.0/24):
- Abuse Density: 0%
- Classification: Clean
- Active Siblings: 0
- Threat Siblings: 0
- Total Siblings: 1
## OBSERVATION HISTORY
Eleven signal observations recorded as of 2026-07-27:
- RIR Registration: APNIC (APNIC RIR)
- Organization: Weng Wen Qian
- Geographic Signals: Consistent Hangzhou, Zhejiang location
- Operator Score: 0.1304 (Minimal)
- DNSSEC: Valid
- No persistent malicious activity indicators detected
## RELATIONSHIP ANALYSIS
No external relationships identified. No associated hostnames, organizations, certificates, or related subnets detected in the relationship graph.
## THREAT INDICATORS
- Risk Score: 80/100 (High Risk)
- Abuse Confidence: Not applicable
- Campaign Correlation: None
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Honeypot Hits: 0
- WAF Violations: 0
## RECOMMENDED ACTIONS
Immediate:
1. Increase logging verbosity for traffic from this IP address
2. Review recent activity logs for any suspicious patterns
Firewall Recommendations:
- iptables: `iptables -A INPUT -s 114.94.211.10 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 114.94.211.10 drop`
- nginx: `deny 114.94.211.10;`
- pfSense: Block 114.94.211.10/32
- Cloudflare WAF: Block with expression `ip.src eq 114.94.211.10`
- AWS WAF: Add 114.94.211.10/32 to block list
Assessment: The elevated risk score warrants monitoring despite the clean subnet classification. The absence of open services suggests this IP may be part of a broader infrastructure network rather than an active attack vector. Consider implementing monitoring rules to detect any service enumeration or port scanning activity from this address.
---
*This briefing is generated from IPDebrief intelligence platform data. All recommendations should be validated against internal security policies and complementary threat intelligence sources before implementation.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | IRT-CHINANET-CN |
| ASN | AS4812 |
| Network Name | CHINANET-SH |
| CIDR Block | 114.80.0.0/12 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 0% (None) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS4812 |
| Network Prefix | 114.94.0.0/16 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 23% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 17% | 2 | 3 |
| reputation | 8% | 1 | 2 |
| geolocation | 17% | 2 | 3 |
| Overall | 14% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-13 15:24:01 UTC |
| Last Seen | 2026-09-29 20:34:45 UTC |
| Profile Built | 2026-09-23 19:59:26 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 22 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 114.94.211.10
Who owns the IP address 114.94.211.10?
114.94.211.10 is registered to IRT-CHINANET-CN. The address falls within the 114.80.0.0/12 network block. Registration is held at APNIC.
Where is 114.94.211.10 located?
Geolocation data places 114.94.211.10 in Hangzhou, Zhejiang, China. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 114.94.211.10 malicious or safe?
114.94.211.10 currently carries a high risk assessment, meaning indicators associated with malicious or abusive activity have been observed. This assessment is generated from continuously collected signals and can change over time.