# INTELLIGENCE BRIEFING: IP 14.103.50.128/32
Classification: LOW RISK | Date: 2026-07-29 | Analyst: IPDebrief Intelligence Team
---
## EXECUTIVE SUMMARY
IP 14.103.50.128 presents a low-risk threat profile with a risk score of 25/100. The address belongs to the VOLCANO-ENGINE provider network (ASN: 4811) registered to IRT-VOLCANO-ENGINE-CN in China. No active threat indicators were identified during analysis. The IP exhibits stable ownership patterns and minimal operational risk characteristics.
---
## TECHNICAL PROFILE
Ownership & Network Classification
- ASN: 4811 (China Telecom/ChinaNet infrastructure)
- Organization: IRT-VOLCANO-ENGINE-CN
- Netname: VOLCANO-ENGINE
- CIDR Block: 14.103.0.0/16
- Network Type: Provider Network
- BGP Prefix: 14.103.48.0/21
- Route Stability: Not stable (route changes detected)
Geolocation
- Country: China (CN)
- Coordinates: 35.86, 104.2 (2,500km accuracy radius)
- Validation Status: Plausible (ICMP validation blocked)
- Distance from Reference Point: 8,033.2 km
---
## THREAT ASSESSMENT
Risk Indicators
| Indicator | Status | Details |
|---|---|---|
| **Risk Score** | 25/100 | Low Risk |
| **Abuse Confidence** | N/A | Not scored |
| **Blacklist Count** | 0 | Clean |
| **DNSBL Listed** | 1/8 | Minor listing |
| **Known Attacker** | False | No matches |
| **Spam Source** | False | Not identified |
| **Tor Exit Node** | False | Not a Tor node |
Network Behavior
- Open Ports: None detected
- TLS Certificate: None
- HTTP Title: None
- Service Purpose: Firewalled / No Services
- Honeypot Hits: 0
- WAF Violations: 0
- Enumeration Strikes: 0
---
## OBSERVATION HISTORY
Analysis of 16 historical observations (most recent: 2026-07-29) reveals:
- Signal Consistency: Stable network classification signals
- Geolocation Consistency: Consistent China-based geolocation inference
- Threat Persistence: 0 days of persistent malicious activity
- Threat Observation Count: 0
- Ownership Changes: 0
The IP demonstrates no escalation of risk over time. Historical signals include consistent provider network classification and geolocation inference with 52% confidence.
---
## NEIGHBORHOOD ANALYSIS
Subnet: 14.103.50.128/24
- Abuse Density: 0 (Clean)
- Classification: Clean
- Inherited Risk: 0
- Total Siblings: 2
- Active Siblings: 1
- Threat Siblings: 0
Neighbor Profile:
- 14.103.50.32: Risk Score 25 (Low Risk), Authority Score 50
The /24 subnet exhibits minimal abuse activity with no threat-identified neighboring IPs.
---
## RELATIONSHIP MAPPING
Five relationships detected, all classified as "Same Network" connections to VOLCANO-ENGINE. No external relationships to organizations, certificates, or hostnames were identified. This indicates an isolated network infrastructure without known inter-IP associations.
---
## CONTROL PLANE ANALYSIS
- DNSSEC Valid: Yes
- RIR Registry: APNIC
- Operator Score: 0.1304 (Minimal)
- Delegation Age: Not available
- MoAS Status: False
---
## RECOMMENDED ACTIONS
No specific firewall rules or security recommendations were generated by automated analysis. The IP presents low-risk characteristics consistent with a provider network endpoint.
SOC Analyst Guidance:
- Block Recommendation: Not required based on current risk profile
- Monitoring: Standard network monitoring sufficient
- Exception Handling: If this IP generates traffic to your infrastructure, no immediate blocking is warranted
- Future Review: Re-evaluate only if threat indicators change or risk score exceeds 50
---
## CONCLUSION
IP 14.103.50.128 represents a low-risk infrastructure address associated with a Chinese provider network. The absence of threat indicators, clean neighborhood profile, and lack of service exposure suggest benign operational use. No immediate defensive actions are required. Continue standard monitoring protocols.
---
Report Generated: IPDebrief Intelligence Platform
Data Sources: Full profile, observation history, relationship graph, neighborhood analysis, action recommendations
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Liu Nian |
| ASN | AS4811 |
| Network Name | VOLCANO-ENGINE |
| CIDR Block | 14.103.0.0/16 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 0% (None) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS4811 |
| Network Prefix | 14.103.48.0/21 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 35% | 2 | 3 |
| services | 24% | 2 | 2 |
| ownership | 38% | 3 | 4 |
| reputation | 17% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 30% | 12 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-20 12:27:50 UTC |
| Last Seen | 2026-09-29 03:06:16 UTC |
| Profile Built | 2026-09-22 12:36:02 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 14.103.50.128
Who owns the IP address 14.103.50.128?
14.103.50.128 is registered to Liu Nian. The address falls within the 14.103.0.0/16 network block. Registration is held at APNIC.
Where is 14.103.50.128 located?
Geolocation data places 14.103.50.128 in China. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 14.103.50.128 malicious or safe?
14.103.50.128 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.