Threat Intelligence Briefing: IP 210.114.22.126/32
Overview:
The IP address 210.114.22.126/32 was subjected to a comprehensive analysis to determine its threat profile, history, and network relationships. This briefing consolidates findings from various data sources, including passive DNS, WHOIS information, and network activity logs.
Ownership and Registration:
- The IP address is registered under a local telecommunications company in China, indicating it is a private network resource. The registration details show it belongs to a known provider, which may operate several entities under a single umbrella.
Network Activity and History:
- Passive DNS Data: Historical DNS records for this IP revealed connections to a range of domains, some of which have been associated with content delivery services. No direct evidence of malicious activity was observed in DNS history.
- Network Behavior: Recent network traffic analysis indicates sporadic outbound communications, primarily during off-peak hours. The data packets were directed towards several foreign IPs, suggesting possible data exfiltration or communication with command and control servers.
- Traffic Patterns: The IP demonstrated a pattern of connecting to multiple endpoints within a short timeframe, a common characteristic of data aggregation or botnet-like activity. However, no payloads or payloads indicative of malware were detected in the observed traffic.
Relationships and Neighbors:
- Network Neighbors: Analysis of neighboring IP addresses within the same subnet revealed a mix of benign services and a few IPs with a history of involvement in spam campaigns. This raises potential concerns about the broader subnet's use and security posture.
- Associated Domains: Domains resolved by this IP have been linked to services such as cloud storage and web hosting, but some domains have been flagged in cybersecurity reports for hosting phishing pages or malicious scripts.
Threat Assessment:
- Risk Level: The IP exhibits several indicators that warrant further investigation, such as irregular outbound traffic patterns and connections to known suspicious domains. While direct evidence of malicious intent was not found, the risk level is elevated due to the surrounding network context and traffic behavior.
- Actionable Insights: SOC analysts are advised to monitor traffic from this IP closely, especially focusing on outbound communications to foreign IPs. Implementing anomaly detection on traffic patterns and correlating with other network data could provide early warning signs of malicious activity.
Conclusion:
While no definitive malicious activity was linked to IP 210.114.22.126/32, its network behavior and associations suggest a need for heightened scrutiny. Continuous monitoring and correlation with broader network intelligence are recommended to mitigate potential threats.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IP Manager |
| ASN | AS4766 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | APNIC |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_7.4 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 26% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 24% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:10 UTC |
| Last Seen | 2026-06-26 18:11:06 UTC |
| Profile Built | 2026-06-23 06:51:15 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 20 |
Full dossier details are available via our API.