IPDebrief

36.106.78.209

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 36.106.78.209/32

## Executive Summary

IP 36.106.78.209 is assessed as LOW RISK with an overall risk score of 25. The address belongs to CHINANET-TJ (China Telecom Tianjin), a Tier-1 ISP network. No active malicious indicators, open services, or known threat associations detected. Recommended action: Monitor without blocking.

---

## Technical Profile

Ownership & Registration

Geolocation

Network Classification

---

## Threat Indicators

Risk Assessment

Threat Status

Behavioral Signals

---

## Observation History (11 Records)

Temporal Analysis

Historical Signals

---

## Relationship Graph

Connected Entities

External Correlations:

---

## Neighborhood Analysis (36.106.78.0/24)

Subnet Assessment

Conclusion: No neighboring IPs with threat activity detected in the /24 block.

---

## Control Plane Analysis

BGP & Routing

DNS Security

---

## Recommended Actions

Security Posture: MONITOR

ActionPriorityRationale
Allow trafficLOWNo active threats detected; legitimate ISP infrastructure
Log connectionsMEDIUMStandard SOC practice for all traffic
Block trafficN/ANo evidence of malicious activity
InvestigateLOWOnly if observed suspicious patterns from this IP

Firewall Rule Recommendations

---

## SOC Analyst Notes

This IP represents standard Chinese telecom infrastructure with no malicious indicators. The single DNSBL listing is minor and may relate to historical or false-positive classification. Route instability is noted but does not indicate active threat behavior. No services are running from this address, suggesting it may be a residential or enterprise endpoint rather than a server.

Final Risk Assessment: LOW RISK

Recommended Handling: Monitor; no immediate action required

Last Updated: 2026-07-22

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇨🇳 China
RegionTianjin
CityTianjin
Timezone—
Latitude39.14
Longitude117.17

🏢 Ownership & Registration

OrganizationIRT-CHINANET-CN
ASNAS17638
Network NameCHINANET-TJ
CIDR Block36.106.0.0/16
RIRAPNIC
CountryCN
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)

🔐 DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS17638
Network Prefix36.106.0.0/17
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
25%
12
reputation
0%
00
geolocation
0%
00
Overall16%45
Coverage: 4/6 dimensions · Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

📅 Observation Timeline 🔄 Live

First Seen2026-07-02 04:21:49 UTC
Last Seen2026-08-26 20:22:48 UTC
Profile Built2026-08-29 07:34:11 UTC
Data FreshnessLive
Signal Types17
Total Observations19
🔍 17 signal types · 19 observations collected
This report is generated from 17+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 36.106.78.209

Who owns the IP address 36.106.78.209?

36.106.78.209 is registered to IRT-CHINANET-CN. The address falls within the 36.106.0.0/16 network block. Registration is held at APNIC.

Where is 36.106.78.209 located?

Geolocation data places 36.106.78.209 in Tianjin, Tianjin, China. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 36.106.78.209 malicious or safe?

36.106.78.209 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.

🏘️ Related IP Addresses

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.