IPDebrief

139.159.142.7

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 139.159.142.7/32

Classification: Moderate Risk / Cloud Infrastructure Endpoint

Date: 2026-07-30

Risk Score: 40/100

## Executive Summary

IP address 139.159.142.7 presents a moderate risk profile (40/100) with no active threat indicators. The address resolves to Huawei Cloud DNS infrastructure and is part of a cloud-hosted BGP prefix. No open services were detected, and the IP is currently firewalled.

## Technical Profile

Network Classification: Cloud infrastructure endpoint with "Firewalled / No Services" designation. ASN 55990 (Huawei Cloud) owns BGP prefix 139.159.136.0/21.

DNS Resolution:

Control Plane Status:

## Geolocation Analysis

Historical geolocation data indicates the IP is associated with Guangzhou, Guangdong Province, China (23.1181°N, 113.2539°E). This aligns with Huawei Cloud's geographic footprint.

## Threat Assessment

Threat Indicators: None detected

Historical Signals: 10 observations recorded over the monitoring period. Recent activity includes DNS-related signals and operator scoring assessments.

## Neighborhood Analysis

The /24 subnet (139.159.142.0/24) shows:

## Relationship Graph

Two DNS association relationships identified, both pointing to the same hostname: ecs-139-159-142-7.compute.hwclouds-dns.com. No organizational, subnet, or certificate relationships were detected beyond DNS associations.

## Recommended Actions

Immediate: No immediate action required. The IP presents moderate risk with no active threat indicators.

Monitoring: Continue passive monitoring given:

Allow Rules (if traffic required):

Block Rules (if blocking advised):

## Conclusion

IP 139.159.142.7 is a cloud infrastructure endpoint with moderate risk classification. The absence of active threat indicators, combined with the cloud hosting nature and lack of open services, suggests this is legitimate infrastructure or a dormant address. SOC analysts should maintain passive monitoring but no immediate blocking is warranted absent additional contextual information.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡จ๐Ÿ‡ณ China
RegionGuangdong
CityGuangzhou
Timezoneโ€”
Latitude23.12
Longitude113.25

๐Ÿข Ownership & Registration

OrganizationLiu Liqun
ASNAS55990
Network NameHWCSNET
CIDR Block139.159.128.0/17
RIRARIN
CountryCN
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRecs-139-159-142-7.compute.hwclouds-dns.com
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamesecs-139-159-142-7.compute.hwclouds-dns.com

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierTier 3 โ€” Basic operator with some routing infrastructure
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
0%
00
reputation
0%
00
geolocation
0%
00
Overall12%33
Coverage: 3/6 dimensions ยท Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-07-26 21:27:44 UTC
Last Seen2026-08-13 06:43:47 UTC
Profile Built2026-08-05 06:15:11 UTC
Data FreshnessLive
Signal Types21
Total Observations21
๐Ÿ” 21 signal types ยท 21 observations collected
This report is generated from 21+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.