# IP Intelligence Briefing: 36.106.78.209/32
## Executive Summary
IP 36.106.78.209 is assessed as LOW RISK with an overall risk score of 25. The address belongs to CHINANET-TJ (China Telecom Tianjin), a Tier-1 ISP network. No active malicious indicators, open services, or known threat associations detected. Recommended action: Monitor without blocking.
---
## Technical Profile
Ownership & Registration
- ASN: 17638 (Chinanet Hostmaster)
- Network: CHINANET-TJ (36.106.0.0/16)
- Organization: China Telecom Tianjin
- RIR: APNIC
- Abuse Contact: anti-spam@chinatelecom.cn
Geolocation
- Country: China (CN)
- Region/City: Tianjin
- Coordinates: 39.14°N, 117.17°E
- Timezone: Asia/Shanghai
Network Classification
- Infrastructure Type: Firewalled / No Services
- Open Ports: None detected
- DNS Resolution: No PTR hostnames; no forward resolution
- TLS/HTTP: No certificates or HTTP banners observed
---
## Threat Indicators
Risk Assessment
- Overall Risk Score: 25 (Low Risk)
- Abuse Confidence Score: Not applicable
- DNSBL Listings: 1 of 8 lists (minimal impact)
- Blacklist Count: 0
Threat Status
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
- Known Campaigns: None identified
- Persistent Threat Activity: False
Behavioral Signals
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
- Total Incidents: 0
---
## Observation History (11 Records)
Temporal Analysis
- Latest Observation: 2026-07-22T14:09:26 UTC
- Geolocation Consistency: Stable (Tianjin, China)
- Ownership Changes: 0 (stable)
- Threat Observation Count: 0
Historical Signals
- Geolocation data consistently from MaxMind GeoLite2
- Operator score maintained at 0.1304 (Minimal)
- No threat persistence or escalation patterns detected
---
## Relationship Graph
Connected Entities
- Network: CHINANET-TJ (36.106.76.0/22)
- Hostnames: None associated
- Organizations: None beyond ISP registration
- Certificates: None
External Correlations:
- Subnet Abuse Density: 0
- Related Threat IPs: 0
- Campaign Correlations: 0
---
## Neighborhood Analysis (36.106.78.0/24)
Subnet Assessment
- Total Neighbors: 0
- High-Risk Neighbors: 0
- Medium-Risk Neighbors: 0
- Low-Risk Neighbors: 0
- Abuse Density: 0
Conclusion: No neighboring IPs with threat activity detected in the /24 block.
---
## Control Plane Analysis
BGP & Routing
- Origin ASN: 17638
- BGP Prefix: 36.106.76.0/22
- Route Stability: False (route changes noted)
- RPKI State: Not available
- IRR Consistency: Not available
DNS Security
- DNSSEC Valid: True
- CAA Records: None
- DNSBL Listed: 1 list
---
## Recommended Actions
Security Posture: MONITOR
| Action | Priority | Rationale |
|---|---|---|
| Allow traffic | LOW | No active threats detected; legitimate ISP infrastructure |
| Log connections | MEDIUM | Standard SOC practice for all traffic |
| Block traffic | N/A | No evidence of malicious activity |
| Investigate | LOW | Only if observed suspicious patterns from this IP |
Firewall Rule Recommendations
- Default: Permit with logging
- No specific deny rules warranted
---
## SOC Analyst Notes
This IP represents standard Chinese telecom infrastructure with no malicious indicators. The single DNSBL listing is minor and may relate to historical or false-positive classification. Route instability is noted but does not indicate active threat behavior. No services are running from this address, suggesting it may be a residential or enterprise endpoint rather than a server.
Final Risk Assessment: LOW RISK
Recommended Handling: Monitor; no immediate action required
Last Updated: 2026-07-22
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | IRT-CHINANET-CN |
| ASN | AS17638 |
| Network Name | CHINANET-TJ |
| CIDR Block | 36.106.0.0/16 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS17638 |
| Network Prefix | 36.106.0.0/17 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-02 04:21:49 UTC |
| Last Seen | 2026-08-26 20:22:48 UTC |
| Profile Built | 2026-08-29 07:34:11 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 19 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 36.106.78.209
Who owns the IP address 36.106.78.209?
36.106.78.209 is registered to IRT-CHINANET-CN. The address falls within the 36.106.0.0/16 network block. Registration is held at APNIC.
Where is 36.106.78.209 located?
Geolocation data places 36.106.78.209 in Tianjin, Tianjin, China. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 36.106.78.209 malicious or safe?
36.106.78.209 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.