IP INTELLIGENCE BRIEFING: 120.48.153.92
Subject: Threat Intelligence Summary for 120.48.153.92
Date: 2026-06-22
Analyst: IPDebrief SOC Intelligence Unit
---
**Executive Summary**
IP 120.48.153.92 is a low-risk infrastructure endpoint belonging to Baidu (ASN 38365), hosted within the 120.48.0.0/15 CIDR block in Beijing, China. The IP exhibits a risk score of 25/100 with minimal threat indicators. No active services or open ports were detected, and the endpoint is currently firewalled with no operational network exposure.
---
**Ownership & Classification**
- Organization: Baidu Noc (Baidu)
- ASN: 38365
- CIDR Block: 120.48.0.0/15
- Location: Beijing, China (CN)
- Network Classification: Infrastructure / CDN
- Registration: APNIC RIR
---
**Risk Assessment**
- Risk Score: 25/100 (Low Risk)
- Provider Score: 0
- Authority Score: 0
- Abuse Confidence: Not flagged as known attacker or spam source
- Blacklist Status: Not on major blacklists (blacklistCount: 0)
- DNSBL Listings: 1 of 8 lists (dnsblListedCount: 1)
- Tor/Proxy Status: Not a Tor exit node, proxy, or VPN endpoint
---
**Threat Indicators**
- Active Threats: None detected
- Malicious Campaigns: No matches
- Known Indicators: No threat indicators identified
- Threat Persistence: 0 days (not persistently malicious)
- Behavioral Flags: No honeypot hits, enumeration strikes, or WAF violations
---
**Network Observations**
- Services: No open ports detected (firewalled configuration)
- DNS: No PTR hostnames, no forward resolution
- SSL/TLS: No certificates detected
- Route Stability: Route changes observed (routeChanges30d: 0, isRouteStable: false)
---
**Historical Analysis**
Total observations: 17 signals across monitoring period
- Most Recent Signal: 2026-06-22 (confidence: 0.30)
- Geolocation Consistency: Consistent Beijing region attribution
- DNSBL Activity: Historical DNSBL listings observed (signal_type_id 2344)
- Threat Persistence: 1 threat observation recorded
- Status: Not persistently malicious
---
**Neighborhood Intelligence**
- Subnet: 120.48.153.0/24
- Abuse Density: 0.5 (Low)
- Classification: Mostly clean
- Total Siblings: 2
- Active Siblings: 1
- Threat Siblings: 1 (120.48.153.33 - Risk Score: 40, Authority Score: 50)
---
**Relationship Graph**
- Associated Networks: Baidu (20 relationship entries)
- Connection Type: Same Network / Infrastructure
- Network Consistency: High correlation with Baidu network assets
---
**Recommended Actions**
- Monitoring: Continue passive monitoring; no immediate blocking required
- Firewall Rules: No restrictive rules needed for this IP
- Threat Hunting: Monitor neighbor 120.48.153.33 for elevated risk activity
- Allow List Consideration: Risk profile supports whitelist for Baidu infrastructure
---
**Conclusion**
The IP 120.48.153.92 represents a low-risk Baidu infrastructure endpoint with minimal operational exposure. While DNSBL listings were historically observed, current threat indicators are absent. The subnet maintains low abuse density with minimal threat activity. No immediate defensive action required beyond standard network monitoring practices.
Classification: Low Risk - Infrastructure
Threat Level: Minimal
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Baidu Noc |
| ASN | AS38365 |
| Network Name | Baidu |
| CIDR Block | 120.48.0.0/15 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 19% | 2 | 2 |
| reputation | 24% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 22% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:35 UTC |
| Last Seen | 2026-06-22 11:29:50 UTC |
| Profile Built | 2026-06-22 11:48:03 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 25 |
Full dossier details are available via our API.