# IP Intelligence Briefing: 39.97.253.71
Classification: LOW RISK
Risk Score: 25/100
Date: Current
Analyst: Automated Intelligence System
---
## Executive Summary
IP address 39.97.253.71 is a low-risk address associated with Chinese network infrastructure provider ALISOFT (ASN 37963). The IP shows no active threat indicators, no open services, and minimal reputation concerns. The address is geolocated to Beijing, China, and operates within the 39.96.0.0/14 BGP prefix.
---
## Ownership and Network Profile
| Attribute | Value |
|---|---|
| ASN | 37963 |
| Organization | security trouble |
| Netname | ALISOFT |
| RIR | APNIC |
| CIDR Block | 39.108.0.0/16 |
| Country | CN (China) |
| City | Beijing |
| BGP Prefix | 39.96.0.0/14 |
The IP is associated with APNIC-registered infrastructure with a stable network classification. No provider-level abuse indicators detected.
---
## Threat Intelligence Assessment
Threat Indicators:
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0
- DNSBL Listed: 1 of 8 lists
Network Role:
- Infrastructure Type: Not classified
- Connection Type: Not classified
- Cloud/CDN/VPN: No
- Hosting/Proxy: No
- Service Status: Firewalled / No Services
Abuse Confidence: Not elevated. No abuse indicators present in threat feeds.
---
## Services and DNS Analysis
Open Ports: None detected
DNS Resolution: No PTR hostnames, no forward resolution
Email Authentication: No SPF/DMARC records
HTTP Services: No active HTTP endpoints
TLS Certificates: None
The IP shows no active service exposure, consistent with a firewalled infrastructure configuration.
---
## Neighborhood Analysis (39.97.253.0/24)
| Metric | Value |
|---|---|
| Subnet | 39.97.253.0/24 |
| Abuse Density | 1 (Minimal) |
| Classification | Mostly Clean |
| Active Siblings | 1 |
| Threat Siblings | 1 |
| Inherited Risk | 2/100 |
The /24 subnet shows minimal abuse density with a "mostly_clean" classification. One threat sibling detected in the neighborhood.
---
## Historical Observations
Observation Count: 20 signals
Most Recent: 2026-06-23
Threat Persistence: 0 days
Ownership Changes: 0
Key Historical Signals:
- 2026-06-23: Reputation signal (Minimal), routing/services/ownership assessment
- 2026-06-18: Subnet abuse density (1), geolocation inference (CN, Beijing), campaign likelihood (none)
The IP has maintained a stable risk profile with no significant escalation in threat observations. No campaign correlation detected.
---
## Recommended Security Actions
Current Status: No immediate action required.
Recommendations:
- No firewall rules generated due to low risk profile
- No blocking recommended at this time
- Standard monitoring protocols sufficient
Note: Recommendations are probabilistic and should be combined with other threat intelligence signals before taking action.
---
## Operational Notes
Control Plane:
- Operator Score: 0.1304 (Minimal)
- Route Stability: Not stable
- MoAS: No
- RPKI State: Not available
Geolocation Validation:
- Status: ICMP blocked - unable to validate
- Distance: 7,726 km from probe origin
- RTT Minimum Possible: 154.5ms
Behavioral:
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
- Total Incidents: 0
---
## Conclusion
IP 39.97.253.71 represents low-risk infrastructure with no active malicious indicators. The address is properly classified under ALISOFT network operations with firewalled services and no threat feed matches. No immediate defensive actions required beyond standard monitoring.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | security trouble |
| ASN | AS37963 |
| Network Name | ALISOFT |
| CIDR Block | 39.108.0.0/16 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 24% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:18 UTC |
| Last Seen | 2026-06-23 11:45:11 UTC |
| Profile Built | 2026-06-23 11:52:40 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 20 |
Full dossier details are available via our API.