## INTELLIGENCE BRIEFING: 218.78.75.160/32
Classification: Moderate Risk / No Active Threat Indicators
Date: 2026-07-30
Analyst: IPDebrief SOC Intelligence
---
Executive Summary
IP 218.78.75.160 is a China Telecom (CHINANET-SH) residential/ISP address from Shanghai, China (ASN 4811). Despite a baseline risk score of 50 (Moderate Risk), no active threat indicators were detected. The IP shows no open services, no blacklist entries, and operates in a clean neighborhood. Risk appears to stem from geographic location rather than malicious activity.
---
Network Ownership & Geolocation
- ASN: 4811 (China Telecom CHINANET-SH)
- Organization: Wu Xiao Li
- Location: Shanghai, China (CN)
- CIDR Block: 218.78.0.0/15
- Classification: Firewalled / No Services
- Contact: abuse@chinatelecom.cn (anti-spam)
---
Threat Intelligence Findings
- Risk Score: 50 (Moderate Risk)
- Abuse Confidence: Not detected
- Blacklist Status: 0 DNSBL listings (of 8 total checked)
- Threat Campaigns: None correlated
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
---
Technical Observations
- Open Ports: None detected
- DNS Resolution: No PTR records; forward resolution unconfirmed
- Services: No HTTP/HTTPS services active
- TLS Certificates: None
- Network Role: ISP/Residential endpoint
---
Neighborhood Analysis
- Subnet: 218.78.75.160/24
- Abuse Density: 0.0 (Clean)
- Neighbor Count: 0
- Threat Siblings: 0
- Overall Classification: Clean subnet
---
Historical Signals (12 observations)
Recent observations (2026-07-30) confirm:
- Consistent Shanghai, China geolocation
- ASN and organization stable
- Abuse density: 0 across observations
- Classification: "clean" in subnet analysis
---
Recommended Actions
Block Recommended: Yes (Probabilistic)
Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 218.78.75.160 -j DROP
# nftables
nft add rule inet filter input ip saddr 218.78.75.160 drop
# Cloudflare WAF
ip.src eq 218.78.75.160 โ BLOCK
```
Note: Risk score appears to be baseline geographic risk rather than active malicious activity. Consider allowing traffic if no other threat signals are present.
---
Intelligence Assessment
This IP exhibits typical ISP-residential behavior from a high-traffic Chinese telecom network. The moderate risk score reflects geographic risk posture rather than confirmed malicious activity. No evidence of abuse, scanning, or exploitation campaigns. SOC teams may monitor but blocking is not strictly warranted absent additional threat signals.
Confidence Level: Medium (based on clean neighborhood and lack of active threats)
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Wu Xiao Li |
| ASN | AS4811 |
| Network Name | CHINANET-SH |
| CIDR Block | 218.78.0.0/15 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-26 03:09:00 UTC |
| Last Seen | 2026-07-31 07:31:38 UTC |
| Profile Built | 2026-07-30 06:43:45 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.