# IP Intelligence Briefing: 202.85.222.190
## Executive Summary
IP address 202.85.222.190 is associated with the Elink-space network (CIDR: 202.85.208.0/20) operated by Lin Jia in Beijing, China. The IP presents a low-risk profile with a risk score of 25/100 and demonstrates minimal threat indicators across all observed signals.
## Network Classification
- Organization: Lin Jia / Elink-space
- ASN: Not assigned (null)
- Network Type: Firewalled / No Services
- Geolocation: Beijing, China (CN)
- Network Role: Infrastructure / Residential proxy indicators not detected
## Risk Assessment
The IP scored 25 on the overall risk metric, classified as Low Risk. Key risk indicators include:
- No known attacker attribution
- No spam source designation
- No Tor exit node status
- Zero blacklist entries (blacklist count: 0)
- Single DNSBL listing across 8 total lists
Control plane analysis revealed an operator score of 0.2174, labeled as "Minimal." The IP is not classified as a provider, CDN, VPN, proxy, hosting service, or mobile carrier.
## Behavioral Analysis
Historical observation records show 17 signal observations with the most recent activity captured in June 2026. The IP demonstrates:
- Threat Persistence: 0 days
- Threat Observation Count: 1
- Persistently Malicious Status: Not flagged
Geolocation signals consistently place the IP in China with inferred coordinates at latitude 35.86, longitude 104.2, though the accuracy radius remains at 2500 km. DNS resolution signals show valid DNSSEC validation in later observations.
## Network Environment
The /24 subnet (202.85.222.190/24) shows:
- Abuse Density: 0%
- Classification: Mostly clean
- Threat Siblings: 1
- Active Siblings: 0
- Total Siblings: 1
Relationship graph analysis identified 33 relationships, all mapping to the Elink-space network designation. No neighboring IPs were detected within the /24 subnet.
## Service Fingerprint
- Open Ports: None detected
- TLS Certificate: None
- HTTP Title: None
- Banner Grabs: None
- Forward Resolution: Not confirmed
- Hosted Domains: 0
## Recommended Actions
No specific firewall rules or action recommendations were generated. The low-risk profile suggests standard network policies are appropriate. The IP does not warrant immediate blocking or special handling based on current intelligence.
## SOC Analyst Notes
This IP address represents a firewalled endpoint with no active services. The single threat observation and minimal operator score indicate low malicious activity. The network environment (Elink-space) shows predominantly clean classification. Routine monitoring is recommended, but immediate defensive action is not warranted.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Lin Jia |
| ASN | โ |
| Network Name | Elink-space |
| CIDR Block | 202.85.208.0/20 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 19% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 18% | 10 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-10 10:13:40 UTC |
| Last Seen | 2026-06-26 00:48:10 UTC |
| Profile Built | 2026-06-26 00:54:30 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 19 |
Full dossier details are available via our API.