# IP Intelligence Briefing: 139.159.142.7/32
Classification: Moderate Risk / Cloud Infrastructure Endpoint
Date: 2026-07-30
Risk Score: 40/100
## Executive Summary
IP address 139.159.142.7 presents a moderate risk profile (40/100) with no active threat indicators. The address resolves to Huawei Cloud DNS infrastructure and is part of a cloud-hosted BGP prefix. No open services were detected, and the IP is currently firewalled.
## Technical Profile
Network Classification: Cloud infrastructure endpoint with "Firewalled / No Services" designation. ASN 55990 (Huawei Cloud) owns BGP prefix 139.159.136.0/21.
DNS Resolution:
- PTR Record: ecs-139-159-142-7.compute.hwclouds-dns.com
- Forward Resolution: hwclouds-dns.com
- Hosted Domain: hwclouds-dns.com
Control Plane Status:
- Route stability: False (route changes observed)
- DNSBL listings: 2 of 8 total lists (2 DNSBL entries)
- Operator Score: 0.2609 (Basic)
- RPKI State: Not applicable
- DNSSEC: Valid
## Geolocation Analysis
Historical geolocation data indicates the IP is associated with Guangzhou, Guangdong Province, China (23.1181°N, 113.2539°E). This aligns with Huawei Cloud's geographic footprint.
## Threat Assessment
Threat Indicators: None detected
- Known attacker: No
- Spam source: No
- Tor exit node: No
- Blacklist count: 0 active threat indicators
- Known campaigns: None
Historical Signals: 10 observations recorded over the monitoring period. Recent activity includes DNS-related signals and operator scoring assessments.
## Neighborhood Analysis
The /24 subnet (139.159.142.0/24) shows:
- Neighbor count: 0
- Abuse density: 0%
- Risk distribution: No high/medium/low risk neighbors detected
- No correlated threat activity in adjacent addresses
## Relationship Graph
Two DNS association relationships identified, both pointing to the same hostname: ecs-139-159-142-7.compute.hwclouds-dns.com. No organizational, subnet, or certificate relationships were detected beyond DNS associations.
## Recommended Actions
Immediate: No immediate action required. The IP presents moderate risk with no active threat indicators.
Monitoring: Continue passive monitoring given:
- DNSBL presence (2 listings)
- Route instability (route changes observed)
- Cloud infrastructure nature may indicate compromised or repurposed resources
Allow Rules (if traffic required):
- Permit outbound only if necessary for business operations
- No inbound connections recommended
Block Rules (if blocking advised):
- Consider blocking if the organization does not have legitimate business with Huawei Cloud infrastructure
- No aggressive blocking recommended due to lack of active threat indicators
## Conclusion
IP 139.159.142.7 is a cloud infrastructure endpoint with moderate risk classification. The absence of active threat indicators, combined with the cloud hosting nature and lack of open services, suggests this is legitimate infrastructure or a dormant address. SOC analysts should maintain passive monitoring but no immediate blocking is warranted absent additional contextual information.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Liu Liqun |
| ASN | AS55990 |
| Network Name | HWCSNET |
| CIDR Block | 139.159.128.0/17 |
| RIR | ARIN |
| Country | CN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | ecs-139-159-142-7.compute.hwclouds-dns.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | ecs-139-159-142-7.compute.hwclouds-dns.com |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-26 21:27:44 UTC |
| Last Seen | 2026-08-13 06:43:47 UTC |
| Profile Built | 2026-08-05 06:15:11 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 21 |
Full dossier details are available via our API.