# IPDebrief Intelligence Briefing: 43.226.37.32/32
Classification: Low Risk / Passive Infrastructure
Date: Analysis conducted on current data snapshot
Primary Geography: Nanshan District, Shenzhen, Guangdong Province, China (CN)
---
## Executive Summary
IP 43.226.37.32 presents as a low-risk, firewalled endpoint with no active services. The IP is associated with APNIC registry (AS134762) and shows minimal threat activity. While the IP is geolocated to China, it demonstrates no persistent malicious behavior, no known attack campaigns, and no blacklist dominance beyond one medium-severity listing.
---
## Risk Profile
| Metric | Value |
|---|---|
| Risk Score | 15 / 100 |
| Reputation | Low Risk |
| Provider Score | 0 |
| Authority Score | 0 |
| Stability Score | 0 |
Threat Indicators:
- Is Tor Exit Node: No
- Is Known Attacker: No
- Is Spam Source: No
- Blacklist Count: 1 / 8 total DNSBL lists
- Pulsedive Risk: Not populated
---
## Network Characteristics
Infrastructure Type:
- BGP Prefix: 43.226.32.0/20
- Origin ASN: 134762
- Route Stability: Unstable (changes detected in 30-day window)
- Network Role: Firewalled / No Services Detected
- Cloud/CDN/VPN/Proxy: None identified
DNS Services:
- PTR Record: Not resolved
- Forward Resolution: Not confirmed
- Hosted Domains: 0
- DNSSEC Valid: Yes
- Email Authentication: No SPF/DMARC configured
---
## Observed Behavior
Signal History (12 observations):
- Recent geolocation signals indicate APNIC registration under organization "Lifen zhang"
- Abuse contact listed: ipas@cnnic.cn
- One blacklist listing observed with medium severity rating
- DNSSEC validation present on reverse zone records
Behavioral Indicators:
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
- Total Incidents: 0
- Persistently Malicious: No
---
## Neighborhood Analysis
Subnet: 43.226.37.0/24
- Total Sibling IPs: 4
- Abuse Density: 0
- Risk Distribution: 2 Medium, 2 Low
Notable Neighbors:
- 43.226.37.33: Risk Score 50 (highest risk in subnet)
- 43.226.37.138: Risk Score 40
- 43.226.37.214: Risk Score 25
- 43.226.37.9: Risk Score 0
---
## Relationships Graph
No direct relationships identified (hostnames, subnets, organizations, certificates).
---
## SOC Recommendations
Action: Monitor / Low Priority
Justification:
- Low risk score (15/100) with no active threat indicators
- Firewalled endpoint with no open services
- No evidence of attack campaigns or known malicious activity
- Single medium-severity blacklist listing (requires context verification)
Recommended Actions:
1. No immediate blocking required
2. Monitor for changes in risk profile or service emergence
3. Investigate if 43.226.37.33 (neighbor, Risk 50) generates alerts
4. Verify blacklist listing context if relevant to threat hunting
Firewall Rules: Not recommended for blocking at this time. If connection attempts occur, evaluate against organizational policy and correlate with other indicators.
---
*Intel generated by IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Lifen zhang |
| ASN | AS134762 |
| Network Name | Xiaoniaoyun |
| CIDR Block | 43.226.36.0/22 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS134762 |
| Network Prefix | 43.226.32.0/20 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 17% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 36% | 2 | 5 |
| reputation | 8% | 1 | 2 |
| geolocation | 17% | 2 | 3 |
| Overall | 16% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-14 03:40:23 UTC |
| Last Seen | 2026-08-31 15:11:28 UTC |
| Profile Built | 2026-08-31 15:24:29 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 27 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 43.226.37.32
Who owns the IP address 43.226.37.32?
43.226.37.32 is registered to Lifen zhang. The address falls within the 43.226.36.0/22 network block. Registration is held at APNIC.
Where is 43.226.37.32 located?
Geolocation data places 43.226.37.32 in Nanshan District Shenzhen city of Guangdong Province. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 43.226.37.32 malicious or safe?
43.226.37.32 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.