## IP INTELLIGENCE BRIEFING
Subject: 117.72.76.203/32
Classification: Moderate Risk
Date: 2026-07-30
---
EXECUTIVE SUMMARY
IP address 117.72.76.203 presents a moderate-risk profile (score: 50) with no active threat indicators. The IP belongs to a residential or private network allocation under Li Yunfei (ASN 141679) within the JDCOM network block (117.72.0.0/16). The endpoint is currently firewalled with no open services. While the IP appears on two DNSBL lists, neighborhood analysis indicates clean subnet classification with zero abuse density and no correlated threats.
OWNERSHIP & GEOLOCATION
- Organization: Li Yunfei
- ASN: 141679 (JDCOM)
- CIDR Block: 117.72.0.0/16
- RIR: APNIC
- Country: CN (China)
- Route Stability: Route flagged as unstable over last 30 days
- Operator Score: 0.1304 (Minimal)
THREAT ASSESSMENT
- Risk Score: 50 (Moderate)
- Abuse Confidence: Not applicable (no active indicators)
- Blacklist Status: Listed on 2 of 8 DNSBL feeds
- Known Campaigns: None detected
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
NETWORK PROFILE
- Service Purpose: Firewalled / No Services
- Open Ports: None detected
- TLS Certificate: None
- DNS Records: No PTR records, no forward resolution
- Email Reputation: Not evaluated (no email services)
NEIGHBORHOOD ANALYSIS (117.72.76.0/24)
- Abuse Density: 0
- Classification: Clean
- Threat Siblings: 0
- Active Siblings: 1 (subject IP)
- Risk Distribution: No high/medium/low risk neighbors detected
OBSERVATION HISTORY (18 Signals)
Recent observations (July 30, 2026) indicate:
- Network Role: Consistently classified as non-infrastructure (no CDN, VPN, proxy, hosting)
- Geolocation Validation: ICMP blocked preventing direct validation; geo-plausible data points to China (claimed: 34.7732°N, 113.722°E, distance: 8,033 km)
- Traceroute: 30 hops recorded; target not reached
- Subnet Classification: Maintained as clean throughout observation window
- No Campaign Correlation: Zero correlated IPs, zero certificate matches
RELATIONSHIP GRAPH
All five relationships identify as "Same Network" pointing to JDCOM network infrastructure. No external associations (hostnames, organizations, certificates) detected beyond network-level data.
SECURITY ACTIONS & RECOMMENDATIONS
- Firewall Rules: No immediate blocking required. IP shows no active malicious behavior.
- Monitoring: Monitor for route stabilization; current instability may indicate infrastructure changes.
- DNSBL Review: Two DNSBL listings require investigation if IP begins generating outbound traffic.
- Threat Level: Low. The moderate risk score derives from historical DNSBL presence rather than active threat activity.
INTELLIGENCE JUDGMENT
NOT A THREAT โ The IP address represents a static, firewalled endpoint with no open services. The moderate risk classification is attributable to historical DNSBL listings rather than current malicious activity. No immediate defensive actions required beyond standard monitoring.
---
END OF BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Li Yunfei |
| ASN | AS141679 |
| Network Name | JDCOM |
| CIDR Block | 117.72.0.0/16 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 20% | 5 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-28 04:02:23 UTC |
| Last Seen | 2026-08-13 06:43:36 UTC |
| Profile Built | 2026-07-30 15:11:46 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 19 |
Full dossier details are available via our API.