THREAT INTELLIGENCE BRIEFING
IP Address: 116.62.115.97/32
Assessment Date: 2026-07-29
Risk Level: LOW (Risk Score: 25/100)
---
EXECUTIVE SUMMARY
IP address 116.62.115.97 presents minimal threat indicators. The address is classified as "Low Risk" with no active malicious campaigns or known attacker signatures detected. No services are currently exposed on the host.
CONTROL PLANE ANALYSIS
- Origin ASN: 37963
- BGP Prefix: 116.62.0.0/17
- Route Stability: Unstable (0 route changes in 30-day window)
- DNSSEC: Valid
- DNSBL Status: 1 listing out of 8 total checks
GEOLOCATION & OWNERSHIP
- Region: Hangzhou, Zhejiang, China (based on MaxMind GeoLite2)
- ASN/Organization: Registration data unavailable (null values in profile)
- Network Classification: Firewalled / No Services
THREAT INDICATORS
- Active Threats: None detected
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Blacklist Count: 0 (current scan)
- Campaign Correlation: No matches
NETWORK BEHAVIOR
- Open Ports: None detected
- Active Services: None
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
NEIGHBORHOOD ANALYSIS (116.62.115.0/24)
- Subnet Risk Distribution: 0 high, 0 medium, 0 low
- Abuse Density: 0%
- Threat Siblings: 0
- Active Siblings: 0
OBSERVATION HISTORY
Eight signal observations recorded between 2026-07-29T15:54:52 and 2026-07-29T15:56:21 UTC. Key signals include:
- DNSSEC validation confirmed (true)
- High-severity DNSBL listing detected at time of scan
- Geolocation consensus: China (Hangzhou)
- Overall confidence level: 0.125 (low data sufficiency)
---
SOC ACTIONS RECOMMENDED
1. Monitoring: No immediate blocking recommended. IP presents low-risk profile.
2. Firewall Policy: Standard allow rules may apply; no specific deny rules required.
3. Investigation Priority: LOW โ No actionable threat indicators.
4. Correlation: No relationships detected to correlate with other malicious entities.
NOTES:
- One DNSBL listing detected but current blacklist count shows 0
- Control plane data indicates route instability (potential routing anomalies)
- No services exposed suggests this may be a residential or data-center endpoint behind firewall
CONCLUSION: This IP address exhibits benign network characteristics with no evidence of active malicious activity. Routine monitoring is sufficient; no immediate defensive actions required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | security trouble |
| ASN | AS37963 |
| Network Name | ALISOFT |
| CIDR Block | 116.62.0.0/16 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-23 01:40:35 UTC |
| Last Seen | 2026-07-29 15:54:45 UTC |
| Profile Built | 2026-07-29 16:08:28 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 19 |
Full dossier details are available via our API.