# IP INTELLIGENCE BRIEFING
Target IP: 23.177.184.248/32
Classification: Moderate Risk
Date: 2026-07-26
---
## EXECUTIVE SUMMARY
IP 23.177.184.248 is assigned to ZhouyiSat Communications (ASN: 400992) under the network block ZHOUYISAT-COMMUNICATIONS-NAT64. The IP carries a risk score of 40 (Moderate Risk) and is currently listed on 2 of 8 DNS blacklists. Despite showing no active threat indicators, geovalidation anomalies and DNSBL listings warrant continued monitoring. The subnet exhibits clean neighborhood characteristics with zero abuse density.
---
## OWNERSHIP AND REGISTRATION
| Attribute | Value |
|---|---|
| Organization | ZhouyiSat Communications |
| Netname | ZHOUYISAT-COMMUNICATIONS-NAT64 |
| ASN | 400992 |
| CIDR Block | 23.177.184.0/23 |
| RIR | ARIN |
| Abuse Contact | Available via RDAP |
---
## GEOLOCATION ANALYSIS
Reported Location: Fremont, California, US
Validation Status: INCONSISTENT
*Critical Findings:*
- Geovalidation flagged as implausible (GeoPlausible: false)
- Distance discrepancy: 8,843.6 km reported
- RTT violation: Observed 86.0ms vs minimum possible 176.9ms for stated distance
- Probe count: 5 probes completed
- Minimum possible RTT for reported distance: 176.9ms
The geolocation data appears unreliable. Traceroute analysis shows 18 hops with Comcast and HE Networks as transit providers, suggesting the IP may be routing through US infrastructure but actual endpoint location is uncertain.
---
## THREAT INDICATORS
Active Threat Signals: None Detected
| Indicator | Status |
|---|---|
| Known Attacker | No |
| Tor Exit Node | No |
| Spam Source | No |
| Blacklist Count | 2 of 8 lists |
| DNSBL Listed | Yes (High severity) |
| Known Campaigns | None |
| Threat Feeds | None |
DNSBL Enumeration:
- Listed on 2 of 8 total blacklists
- Maximum severity: High
- Forward resolution count: 0
- No PTR records resolved
---
## NETWORK PROFILE
Service Status: Firewalled / No Services Detected
- Open Ports: None
- TLS Certificate: None
- HTTP Banner: None
- Hosted Domains: 0
- Email Auth (SPF/DMARC): Not configured
- DNSSEC Valid: Yes
Behavioral Analysis:
- No honeypot hits recorded
- No persistent malicious activity detected
- Threat persistence days: 0
- Ownership changes: 0
---
## SUBNET ANALYSIS (23.177.184.0/24)
Neighborhood Classification: CLEAN
| Metric | Value |
|---|---|
| Abuse Density | 0.0 |
| Active Siblings | 0 |
| Threat Siblings | 0 |
| Total Siblings | 2 |
| Risk Distribution | Low: 1, Medium: 0, High: 0 |
Neighbor IP: 23.177.184.40 (Risk Score: 0)
The /24 subnet demonstrates low-risk characteristics with a single neighbor IP showing zero risk score.
---
## OBSERVATION HISTORY (16 Records)
Recent observations indicate:
- Consistent DNSSEC validation (confidence: 90%)
- Persistent geolocation inconsistencies
- Occasional DNSBL listings with high severity
- No ownership changes recorded
---
## RECOMMENDED ACTIONS
Risk Score: 40 (Moderate Risk)
Recommendation: Monitor or block based on threat context
Firewall Rules Generated:
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 23.177.184.248 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 23.177.184.248 drop` |
| nginx | `deny 23.177.184.248;` |
| pfSense | `23.177.184.248/32` |
| Cloudflare WAF | `ip.src eq 23.177.184.248` (Block) |
| AWS WAF | `Addresses: ["23.177.184.248/32"]` |
---
## ANALYST NOTES
1. Geolocation reliability is low – The 8,844 km distance and RTT violation indicate the geolocation data should not be used for physical location verification.
2. DNSBL listings present – Two blacklist entries with high severity require investigation into listing reasons and removal procedures.
3. No active threat indicators – Despite DNSBL presence, no evidence of active malicious activity, known campaigns, or attacker signatures.
4. Subnet context favorable – The /24 subnet shows clean neighborhood characteristics, suggesting this IP may be an isolated issue rather than part of a larger threat infrastructure.
5. Recommended action: Block at perimeter firewall level if no legitimate business relationship exists. Monitor for any changes in threat posture or DNSBL status.
---
Report Generated: 2026-07-26
Data Sources: IPDebrief Intelligence Platform
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | ZhouyiSat Communications |
| ASN | AS400992 |
| Network Name | ZHOUYISAT-COMMUNICATIONS-NAT64 |
| CIDR Block | 23.177.184.0/23 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS400992 |
| Network Prefix | 23.177.184.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 8% | 2 | 3 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-11 02:18:48 UTC |
| Last Seen | 2026-07-26 17:07:49 UTC |
| Profile Built | 2026-08-30 22:23:44 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 22 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 23.177.184.248
Who owns the IP address 23.177.184.248?
23.177.184.248 is registered to ZhouyiSat Communications. The address falls within the 23.177.184.0/23 network block. Registration is held at ARIN.
Where is 23.177.184.248 located?
Geolocation data places 23.177.184.248 in Fremont, California, United States. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 23.177.184.248 malicious or safe?
23.177.184.248 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 23.177.184.248?
Responsive ports observed on 23.177.184.248 include 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.