# IP Intelligence Briefing: 50.114.55.14/32
## Executive Summary
IP 50.114.55.14 was assessed as Moderate Risk with a risk score of 40. The address belongs to Nearoute Limited (ASN 61112) and is classified as a Single-Service Host. No active threat indicators were identified during analysis, though the IP showed 2 DNSBL listings across 8 total blacklists.
## Ownership and Infrastructure
- ASN: 61112 (Nearoute Limited)
- Network Block: 50.114.55.0/24
- RIR: ARIN
- Geolocation: US (reported city: MONGKOK)
- Network Role: Single-Service Host
- Service Classification: Not identified as cloud, CDN, VPN, proxy, Tor, hosting, mobile, or residential infrastructure
## Threat Assessment
- Risk Score: 40 (Moderate)
- Abuse Confidence: Not explicitly scored
- Blacklist Status: 2 DNSBL listings out of 8 total lists
- Threat Indicators: None detected
- Known Campaigns: No matches
- Known Attacker/Spam Source: No
- Tor Exit Node: No
## Network Services
- Open Ports: TCP/22 (SSH - OpenSSH_8.2p1 Ubuntu-4ubuntu0.9)
- TLS Certificate: None detected
- HTTP Service: None detected
- Forward DNS Resolution: Unresolved (0 forward hostnames)
- Email Authentication: No SPF or DMARC records
## Control Plane and Routing
- Route Stability: Route changes detected within 30 days (not stable)
- RPKI State: Not assessed
- DNSSEC: Valid
- Hop Count: 15 (Comcast, Cogent transit networks)
- Operator Score: 0.1304 (Minimal)
## Neighborhood Analysis
- Subnet: 50.114.55.0/24
- Abuse Density: 0
- Total Siblings: 0
- Threat Siblings: 0
- Inherited Risk: 0
## Observation History (Last 15 Observations)
Recent observations (2026-07-23) showed:
- Classification: Clean with 0.40 confidence
- Ownership changes: 0
- Threat persistence: Not persistent
- Ports scanned: Multiple ports including SSH
- Geolocation signals: Inconsistencies noted (city reported as MONGKOK with US country code)
## Relationships
- Network Associations: NET-50-114-55-0-24 (Nearoute Limited)
- External Entities: No organization, hostname, or certificate relationships detected
## Recommended Actions
Firewall rules were generated for blocking the IP across multiple platforms:
iptables: `iptables -A INPUT -s 50.114.55.14 -j DROP`
nftables: `nft add rule inet filter input ip saddr 50.114.55.14 drop`
nginx: `deny 50.114.55.14;`
pfSense: `50.114.55.14/32`
Cloudflare WAF: Block with expression `ip.src eq 50.114.55.14`
AWS WAF: Address `50.114.55.14/32` with description "IPDebrief risk 40"
## Analyst Notes
While the IP showed no active malicious indicators, the moderate risk score (40) combined with multiple DNSBL listings warrants monitoring. The route instability and geolocation inconsistencies suggest potential data quality issues in upstream registries. No immediate blocking is required based on threat indicators alone, but the recommended firewall rules provide a defensive posture. Continue monitoring for changes in behavior or network activity patterns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Nearoute Limited |
| ASN | AS61112 |
| Network Name | NET-50-114-55-0-24 |
| CIDR Block | 50.114.55.0/24 |
| RIR | ARIN |
| Country | Hong Kong |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS61112 |
| Network Prefix | 50.114.55.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 17% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 12% | 2 | 2 |
| reputation | 8% | 1 | 2 |
| geolocation | 12% | 2 | 2 |
| Overall | 11% | 10 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-03 10:49:34 UTC |
| Last Seen | 2026-08-24 16:00:21 UTC |
| Profile Built | 2026-08-29 09:36:20 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 20 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 50.114.55.14
Who owns the IP address 50.114.55.14?
50.114.55.14 is registered to Nearoute Limited. The address falls within the 50.114.55.0/24 network block. Registration is held at ARIN.
Where is 50.114.55.14 located?
Geolocation data places 50.114.55.14 in Boston, MA, United States. The local time zone is America/New_York. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 50.114.55.14 malicious or safe?
50.114.55.14 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 50.114.55.14?
Responsive ports observed on 50.114.55.14 include 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.