## IP INTELLIGENCE BRIEFING: 120.48.144.5/32
Date: 2026-07-31
Classification: Defensive Security Intelligence
Analyst: IPDebrief Intelligence Platform
---
EXECUTIVE SUMMARY
IP address 120.48.144.5 belongs to Baidu Noc (ASN 38365) within the 120.48.0.0/15 CIDR block in Beijing, China. The address exhibits a moderate risk profile (score: 65) with no active threat indicators, no open services, and a clean neighborhood. The IP is classified as "Firewalled / No Services" with no evidence of malicious activity or association with known campaigns.
---
OWNERSHIP & ATTRIBUTION
- Organization: Baidu Noc (Baidu)
- ASN: 38365
- Netname: Baidu
- CIDR Block: 120.48.0.0/15
- RIR: APNIC
- Geolocation: Beijing, China (CN)
- BGP Prefix: 120.48.128.0/19
---
RISK ASSESSMENT
| Metric | Value | Assessment |
|---|---|---|
| Overall Risk Score | 65 | Moderate |
| Provider Risk | 0 | Clean |
| Authority Risk | 0 | Clean |
| Stability Score | 0 | N/A |
| Abuse Confidence | N/A | N/A |
| DNSBL Listings | 3/8 | Low |
| Threat Indicators | 0 | None |
| Known Campaigns | 0 | None |
Risk Determination: The moderate risk score of 65 stems primarily from DNSBL presence rather than active malicious behavior. No threat indicators, blacklists, or known attacker associations detected.
---
NETWORK BEHAVIOR
- Service Status: Firewalled / No Services
- Open Ports: None detected
- DNS Resolution: No PTR records, no forward resolution
- Email Authentication: No SPF/DMARC records configured
- TLS/HTTP: No certificates, no HTTP content detected
- Control Plane: Route unstable (isRouteStable: false), DNSSEC valid
---
NEIGHBORHOOD ANALYSIS (120.48.144.5/24)
- Abuse Density: 0% (Clean)
- Classification: Clean
- Total Siblings: 1
- Active Siblings: 0
- Threat Siblings: 0
- Risk Distribution: High: 0, Medium: 0, Low: 0
The /24 subnet shows no abuse activity. No neighboring IPs flagged as threats.
---
OBSERVATION HISTORY
- Total Signals: 14 observations
- Latest: 2026-07-31T03:08:24 UTC
- Threat Observation Count: 0
- Is Persistently Malicious: False
- Ownership Changes: 0
Observations show consistent Baidu network attribution with no degradation in risk posture over time.
---
RELATIONSHIP GRAPH
- Relationship Count: 2
- Type: Same Network (Baidu) × 2
- Associated Entities: Baidu (network)
No relationships to external organizations, hostnames, or certificates detected.
---
THREAT INTELLIGENCE
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Proxy Service: No
- Hosting Provider: No
- VPN Service: No
- Mobile Carrier: No
- Campaign Likelihood: None detected
---
ACTIONABLE RECOMMENDATIONS
Classification: Low Threat / Baidu Infrastructure
Recommended Actions:
1. Traffic Policy: Allow traffic from Baidu infrastructure. No blocking required.
2. Firewall Rules: No specific firewall rules needed for this IP.
3. Monitoring: Standard monitoring sufficient. No elevated threat level detected.
4. DNSBL Review: Verify legitimate purpose of 3 DNSBL listings. May require removal if false positive.
SOC Analyst Notes: This IP represents legitimate Baidu infrastructure with no malicious activity detected. The moderate risk score appears to be an artifact of DNSBL presence rather than actual threat behavior. No immediate action required beyond standard logging.
---
End of Briefing
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Baidu Noc |
| ASN | AS38365 |
| Network Name | Baidu |
| CIDR Block | 120.48.0.0/15 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-30 17:11:11 UTC |
| Last Seen | 2026-08-01 10:24:38 UTC |
| Profile Built | 2026-07-31 03:19:02 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.