# IP Intelligence Briefing: 118.25.46.143/32
## Executive Summary
IP address 118.25.46.143 is associated with Tencent Cloud infrastructure (ASN 45090) and presents moderate risk (score: 40). The IP is firewalled with no active services detected but is listed on two DNS blacklists. Recent observations indicate high-severity DNSBL entries.
## Technical Profile
- Risk Score: 40 (Moderate Risk)
- Geolocation: Shanghai, China (CN)
- Network: 118.24.0.0/15 (TENCENT-CN)
- ASN: 45090 (TENCENT-NET-AP)
- Classification: Firewalled / No Services
- DNSBL Listings: 2 of 8 total lists
## Threat Indicators
- DNSBL Status: Listed on 2 blacklists with high-severity classification
- Abuse Confidence: Null
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaign Associations: None identified
## Network Behavior
- Services: No open ports detected
- TLS/HTTPS: No certificates or HTTP titles detected
- DNS: No PTR records or forward resolution
- Network Role: Infrastructure/cloud provider
- BGP Prefix: 118.25.44.0/22
## Temporal Analysis
- Observation Count: 12 signals recorded
- Ownership Changes: 0 (stable)
- Threat Persistence: 0 days
- Recent Activity: DNSBL listings observed as of 2026-07-29 with high severity
## Relationship Graph
- Same Network: TENCENT-CN (2 entries)
- Associated Domains: None
- Associated Organizations: None beyond network provider
## Neighborhood Analysis
- Subnet: 118.25.46.0/24
- Abuse Density: 0
- Threat Siblings: 0
- Total Siblings: 0
- Classification: No inherited risk from neighbors
## Recommended Actions
Based on the moderate risk profile and DNSBL listings, the following firewall rules are recommended:
| Platform | Recommended Rule |
|---|---|
| iptables | `iptables -A INPUT -s 118.25.46.143 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 118.25.46.143 drop` |
| nginx | `deny 118.25.46.143;` |
| pfSense | `118.25.46.143/32` |
| Cloudflare WAF | Block IP with expression `ip.src eq 118.25.46.143` |
| AWS WAF | Add address `118.25.46.143/32` with description "IPDebrief risk 40" |
## Analyst Notes
The IP is part of Tencent Cloud's infrastructure, which is a legitimate cloud provider. However, the presence of DNSBL listings and the moderate risk score warrant monitoring. The firewalled status with no open services reduces immediate threat but does not eliminate the possibility of the IP being used for malicious purposes such as spam or command-and-control operations. Recommend correlation with threat intelligence feeds for additional context before implementing permanent blocking policies.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Tencent Cloud administrator |
| ASN | AS45090 |
| Network Name | TENCENT-CN |
| CIDR Block | 118.24.0.0/15 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 8% | 2 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-23 13:56:01 UTC |
| Last Seen | 2026-07-29 18:09:01 UTC |
| Profile Built | 2026-07-29 18:22:04 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.