# IP Intelligence Briefing: 220.154.130.81/32
## Executive Summary
IP address 220.154.130.81 was assessed as Moderate Risk with an overall risk score of 50. The IP is registered to ASN 134756 (IRT-CTXXQD-CN) within the APNIC RIR region and is geolocated to China. Current activity shows no active open services, but historical data indicates blacklist listing activity detected on June 25, 2026.
## Technical Profile
- IP Address: 220.154.130.81
- ASN: 134756
- Organization: IRT-CTXXQD-CN
- Country: CN (China)
- Geolocation Accuracy: 2500 km radius
- Network Role: Firewalled / No Services Detected
- DNS Resolution: Forward confirmed: false; No PTR hostnames
- Services: No open ports, no TLS certificates, no HTTP banner
- Control Plane: BGP prefix 220.154.130.0/24; Route stability: false; RPKI state: unavailable
## Threat Assessment
- Risk Score: 50 (Moderate)
- Abuse Confidence Score: Not available
- Known Attacker: false
- Spam Source: false
- Tor Exit Node: false
- Blacklist Status: 2 listings out of 8 total DNSBL lists
- Max Severity: High (from recent observations)
- Campaign Likelihood: none
- Persistent Malicious Activity: false
## Network Context
The IP resides within subnet 220.154.130.0/24. Neighborhood analysis indicates:
- Total Siblings: 2
- Active Siblings: 1
- Threat Siblings: 0
- Abuse Density: 0 (clean)
- Neighboring IP: 220.154.130.30 (risk score: 25, authority score: 50)
## Historical Activity
Observation history reveals 16 total signals across multiple dates:
- 2026-06-25: Blacklist listing activity detected (8 total lists, high severity)
- 2026-06-05: Ownership and threat observation signals recorded
- Geographic Inference: China (35.86°N, 104.2°E) with 52% confidence
- Operator Score: 0.1304 (Minimal risk classification)
- Threat Persistence: 0 days
- Ownership Changes: 0
## Related Infrastructure
Relationship graph indicates 13 connections, all classified as "Same Network" type targeting network identifier CTXXQD. No additional organizational, hostname, or certificate relationships were identified.
## Recommendations
No specific firewall rules or blocking actions are currently recommended based on the IP's risk profile. The IP demonstrates low neighborhood abuse density and lacks active service exposure. Monitoring is advised due to historical blacklist activity and moderate risk classification. Integration with existing threat intelligence platforms is recommended for correlation with additional indicators from the same network.
---
*This briefing was generated from IPDebrief intelligence data. All metrics reflect observed signals as of the most recent available data.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-CTXXQD-CN |
| ASN | AS134756 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | APNIC |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 21% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-10 04:11:52 UTC |
| Last Seen | 2026-06-25 22:57:09 UTC |
| Profile Built | 2026-06-25 23:02:47 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.