# IP Intelligence Briefing: 36.232.157.72/32
## Executive Summary
IP address 36.232.157.72 is a mobile-terminated residential IP from Taiwan's HINET network infrastructure with a moderate risk score of 40. The address is associated with Chunghwa Telecom mobile carrier and shows dynamic IP characteristics. While not flagged as a known attacker or Tor exit node, the IP has been listed on 2 of 8 DNSBLs with high severity ratings.
## Technical Profile
Ownership & Network Classification:
- ASN: 3462 (HINET Network-Adm)
- Organization: HINET Network-Adm
- Network: HINET-NET, 36.232.0.0/16
- RIR: APNIC
- Registration: APNIC registry
Geolocation:
- Country: Taiwan (TW)
- Region: NAN
- City: Nantou City
- Coordinates: 23.7°N, 120.96°E
- Timezone: Asia/Taipei
Connection Type:
- Mobile Carrier: Chunghwa Telecom Co., Ltd.
- Technology: LTE/5G
- Connection Type: Mobile (confirmed)
- Residential: No
- Hosting/Cloud/CDN: No
DNS Configuration:
- PTR Hostname: 36-232-157-72.dynamic-ip.hinet.net
- Forward Resolution: Confirmed
- SPF Record: Present
- DMARC Record: Absent
- Hosted Domains: None
## Threat Assessment
Risk Indicators:
- Risk Score: 40/100 (Moderate Risk)
- Blacklist Count: 0 (direct blacklists)
- DNSBL Listings: 2 of 8 lists (max severity: high)
- Is Tor Exit: No
- Is Known Attacker: No
- Is Spam Source: No
Services:
- Open Ports: None detected
- TLS Certificates: None
- HTTP Services: None
- Status: Firewalled/No Services
Campaign Correlation:
- Known Campaigns: None
- Cert Matches: 0
- Correlated IPs: 0
## Historical Analysis
The IP has generated 16 observations across recent monitoring periods. Key historical signals include:
- Geolocation Signals: Consistent Taiwan origin with Taipei and Nantou City references
- ASN Signals: AS3462 data communication business group
- Threat Indicators: One pulse detected from AlienVault OTX
- Blacklist Status: 2 DNSBL listings identified with high severity classification
- Ownership Stability: No ownership changes observed
## Network Neighborhood Analysis
Subnet Overview (36.232.157.0/24):
- Abuse Density: 0
- Total Siblings: 1
- Active Siblings: 0
- Threat Siblings: 0
Identified Neighbor:
- IP: 36.232.157.114
- Risk Score: 25
- Authority Score: 60
The subnet shows minimal abuse activity with only one sibling IP present.
## Relationship Graph
The IP maintains relationships primarily through DNS associations:
- DNS hostnames: 36-232-157-72.dynamic-ip.hinet.net (multiple entries)
- Network association: HINET-NET
- No external organizational relationships detected
## Recommended Security Actions
Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 36.232.157.72 -j DROP
# nftables
nft add rule inet filter input ip saddr 36.232.157.72 drop
# nginx
deny 36.232.157.72;
# pfSense
36.232.157.72/32
# Cloudflare WAF
{"description":"Block 36.232.157.72 — IPDebrief risk score 40","action":"block","filter":{"expression":"ip.src eq 36.232.157.72"}}
# AWS WAF
{"Addresses":["36.232.157.72/32"],"Description":"IPDebrief risk 40"}
```
Analysis Notes:
The IP should be evaluated based on observed threat context. While the risk score of 40 suggests moderate risk, the absence of open services and known attacker indicators suggests this may be a residential mobile IP. The DNSBL listings with high severity warrant monitoring. If this IP is generating suspicious traffic patterns, blocking is recommended. If legitimate traffic is observed, allowlisting with monitoring may be appropriate.
## Intelligence Conclusion
This IP represents a mobile residential connection from Taiwan's HINET infrastructure. The moderate risk classification stems from DNSBL listings rather than confirmed malicious activity. SOC analysts should monitor for anomalous behavior patterns while considering the residential/mobile nature of the address. No immediate threat indicators suggest active campaign participation or known attacker behavior.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | HINET Network-Adm |
| ASN | AS3462 |
| Network Name | HINET-NET |
| CIDR Block | 36.232.0.0/16 |
| RIR | APNIC |
| Country | TW |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR | 36-232-157-72.dynamic-ip.hinet.net |
| Forward Confirmed | Yes — FCrDNS verified |
| Forward Hostnames | 36-232-157-72.dynamic-ip.hinet.net |
🔐 DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
☁️ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS3462 |
| Network Prefix | 36.232.0.0/16 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 4% | 1 | 1 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-04 05:08:57 UTC |
| Last Seen | 2026-08-26 13:17:02 UTC |
| Profile Built | 2026-08-26 13:25:40 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 22 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 36.232.157.72
Who owns the IP address 36.232.157.72?
36.232.157.72 is registered to HINET Network-Adm. The address falls within the 36.232.0.0/16 network block. Registration is held at APNIC.
Where is 36.232.157.72 located?
Geolocation data places 36.232.157.72 in Nantou City, NAN, Taiwan. The local time zone is Asia/Taipei. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 36.232.157.72 malicious or safe?
36.232.157.72 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 36.232.157.72?
The reverse DNS (PTR) record for 36.232.157.72 is 36-232-157-72.dynamic-ip.hinet.net. This hostname is forward-confirmed, meaning it resolves back to the same address.
Is 36.232.157.72 a VPN, proxy, or data center address?
36.232.157.72 is classified as a mobile network based on network ownership and behavioural analysis.