# IP Intelligence Briefing: 114.98.230.202/32
Classification: Moderate Risk | Report Date: 2026-06-22
## Executive Summary
IP 114.98.230.202 is a China-based residential address within CHINANET-AH (ASN 140527) infrastructure. The address demonstrates moderate risk (score 65) with historical DNSBL listings and a single documented threat observation. No active services detected; the IP is currently firewalled with no open ports.
## Ownership & Network Context
- Organization: Jinneng Wang
- AS Number: 140527 (CHINANET-AH)
- CIDR Block: 114.96.0.0/13
- Geolocation: China (CN) โ Hefei region
- Network Classification: Residential endpoint, not cloud/CDN/proxy infrastructure
## Threat Indicators
- Risk Score: 65/100 (Moderate)
- DNSBL Status: Listed on 3 of 8 total DNSBL feeds
- Threat Observations: 1 recorded threat observation
- Campaign Correlation: No campaign matches identified
- Tor Exit/Proxy: No
## Behavioral Profile
- Service Status: Firewalled / No services exposed
- Open Ports: None detected
- DNS Resolution: No PTR hostnames; no forward resolution
- Email Reputation: No mail activity detected
- Certificate Activity: No TLS certificates associated
## Observation History
The IP has accumulated 26 historical observations. Notable recent activity includes:
- 2026-06-22: Listed on 8 blacklists with 2 high-severity listings
- Geolocation Confidence: 52% (inferred China location with 2km accuracy radius)
- Threat Persistence: Single observation; not classified as persistently malicious
## Neighborhood Analysis (114.98.230.0/24)
- Subnet Classification: Mostly clean
- Abuse Density: Low (0)
- Sibling IPs: 1 active sibling IP in subnet
- Threat Siblings: 1 threat sibling identified within the /24
- Risk Distribution: No high or medium risk neighbors detected
## Relationship Graph
46 relationships identified, all mapping to CHINANET-AH network infrastructure. No external hostname, organizational, or certificate associations detected.
## Recommended Actions
Based on the moderate risk profile and DNSBL history, the following defensive measures are recommended:
Network-Level Mitigation:
```
# Block IP (recommended for moderate risk)
iptables -A INPUT -s 114.98.230.202 -j DROP
```
Subnet-Level Consideration:
Monitor the 114.98.230.0/24 subnet for correlated activity. One threat sibling IP was identified; consider reviewing that address for potential lateral association.
Monitoring Thresholds:
- Track for future DNSBL additions
- Monitor for service activation (currently firewalled)
- Alert on new threat observations
## Risk Assessment Summary
This IP presents moderate risk primarily due to blacklist presence and residential nature. The absence of open services reduces immediate exploitation risk, but the blacklist history suggests prior policy violations or reputation issues. Recommend blocking at network perimeter and monitoring for activity changes.
---
*Intelligence generated by IPDebrief. Data current as of 2026-06-22.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Jinneng Wang |
| ASN | AS140527 |
| Network Name | CHINANET-AH |
| CIDR Block | 114.96.0.0/13 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 24% | 2 | 3 |
| ownership | 24% | 2 | 3 |
| reputation | 23% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 22% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:32 UTC |
| Last Seen | 2026-06-26 18:10:26 UTC |
| Profile Built | 2026-06-22 10:02:14 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 25 |
Full dossier details are available via our API.