# INTELLIGENCE BRIEFING: 165.154.36.110/32
Classification: Moderate Risk
Date: 2026-06-22
Assigned By: IPDebrief Intelligence Platform
---
## EXECUTIVE SUMMARY
IP address 165.154.36.110 is registered to UCLOUD INFORMATION TECHNOLOGY HK LIMITED (ASN: 135377) and is located in Los Angeles, US. The IP carries a moderate risk score of 40/100 with no active threat indicators but exhibits elevated neighborhood abuse density. The address is currently firewalled with no open services and shows no evidence of malicious activity in the profile.
---
## OWNERSHIP & GEOLOCATION
| Attribute | Value |
|---|---|
| ASN | 135377 |
| Organization | UCLOUD INFORMATION TECHNOLOGY HK LIMITED |
| Country | United States (US) |
| Region | California (CA) |
| City | Los Angeles |
| RIR | ARIN |
| Registration | 3,700 days ago |
The IP is associated with UCLOUD-US networks and routes through AS3257 β AS174 β AS135377. RPKI validation status is available; route stability is confirmed with zero route changes in the past 30 days.
---
## THREAT ASSESSMENT
Risk Score: 40/100 (Moderate)
Abuse Confidence: Not applicable (no active threats detected)
Threat Indicators:
- No known campaigns or correlated IPs
- Not a Tor exit node
- Not classified as a spam source or known attacker
- DNSBL: Listed on 2 of 8 available security lists
Network Role: Firewalled / No Services
- No open ports detected
- No TLS certificates or HTTP services
- No email authentication records (SPF, DMARC)
---
## NEIGHBORHOOD ANALYSIS (165.154.36.0/24)
Subnet Abuse Density: 0.4444 (44.44%)
Classification: Mixed
Total Siblings: 9
Threat Siblings: 4
Risk Distribution:
- High Risk: 1 IP (165.154.36.71, Risk Score: 80)
- Medium Risk: 5 IPs
- Low Risk: 2 IPs
Notable High-Risk Neighbor: 165.154.36.71 (Risk Score: 80, Authority Score: 50)
---
## OBSERVATION HISTORY
Total Observations: 22
Latest Signal: 2026-06-22 19:40:03 UTC
Temporal Trends:
- Operator score increased from 0.2174 to 0.3478
- Abuse density signals present in recent observations
- No persistent malicious behavior detected
- Single threat observation event recorded
---
## RECOMMENDED SECURITY ACTIONS
Firewall Rules:
- `iptables -A INPUT -s 165.154.36.110 -j DROP`
- `nft add rule inet filter input ip saddr 165.154.36.110 drop`
- `nginx deny 165.154.36.110;`
- Cloudflare WAF: Block with expression `ip.src eq 165.154.36.110`
- AWS WAF: Add 165.154.36.110/32 to block list
Note: These recommendations are probabilistic and should be combined with other threat intelligence signals before implementing blocking measures.
---
## ANALYST NOTES
1. The IP is currently firewalled with no active services; this reduces immediate exploitation risk.
2. Elevated neighborhood abuse density (44.44%) warrants monitoring of adjacent IPs, particularly 165.154.36.71.
3. No evidence of active malicious use against this specific address.
4. Consider blocking at perimeter if the IP appears in connection logs from untrusted sources.
---
End of Briefing
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | UCLOUD INFORMATION TECHNOLOGY HK LIMITED |
| ASN | AS135377 |
| Network Name | β |
| CIDR Block | 165.154.36.0/24 |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 3 |
| routing | 27% | 2 | 3 |
| services | 8% | 1 | 1 |
| ownership | 27% | 3 | 4 |
| reputation | 26% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 24% | 11 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:03:51 UTC |
| Last Seen | 2026-06-22 19:40:43 UTC |
| Profile Built | 2026-06-22 19:48:36 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.