IPDebrief

59.36.254.224

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

THREAT INTELLIGENCE BRIEFING

Target: 59.36.254.224/32

Classification: Moderate Risk Infrastructure

Date: Current

---

EXECUTIVE SUMMARY

IP 59.36.254.224 operates within China under APNIC RIR allocation. The address demonstrates moderate risk characteristics with a risk score of 50, listed on two DNS blacklists. No active threat indicators or open services were detected during the assessment period.

NETWORK OWNERSHIP & GEOLOCATION

The IP belongs to IPMASTER CHINANET-GD (ASN 136199) within CIDR block 59.42.0.0/16. Geolocation data indicates China (CN) with multiple geolocation source validations. Origin BGP prefix: 59.36.240.0/20. Route stability shows false state, indicating potential routing changes.

THREAT PROFILE

SERVICE & INFRASTRUCTURE ANALYSIS

No open ports detected. Network role classified as "Firewalled / No Services." DNS configuration shows no forward resolution capability. PTR records empty. No TLS certificates or HTTP services observed.

CONTROL PLANE DATA

RPKI state and IRR consistency not validated. Route changes observed over 30-day period. MOAS status: false. Operator score: 0.1304 (Minimal).

OBSERVATION HISTORY (16 Signals)

Recent observations from 2026-07-29 show:

NETWORK NEIGHBORHOOD (59.36.254.0/24)

Subnet classification: Mostly clean. Abuse density: 0. Risk inheritance score: 2. No active sibling IPs detected. Network appears isolated with minimal lateral risk.

RELATIONSHIP GRAPH

Two relationship entries identified, both mapping to CHINANET-GD network. No external hostnames, organizations, or certificate relationships detected.

RECOMMENDATIONS

1. Monitor DNSBL listing status for changes

2. Apply rate limiting if attempting inbound connections

3. No immediate blocking required; moderate risk threshold

4. Continue monitoring for service emergence

RISK ASSESSMENT

The IP presents moderate risk primarily through blacklist presence without active threat indicators. Infrastructure appears defensive (firewalled) with no open services. Recommended for monitoring rather than immediate mitigation.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇨🇳 China
Region—
City—
Timezone—
Latitude—
Longitude—

🏢 Ownership & Registration

OrganizationIPMASTER CHINANET-GD
ASNAS136199
Network NameCHINANET-GD
CIDR Block59.42.0.0/16
RIRAPNIC
CountryCN
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)

🔐 DNS Hygiene

Hygiene Score0% (None)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECNot signed
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS136199
Network Prefix59.36.240.0/20
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
50%
23
routing
25%
11
services
25%
11
ownership
0%
00
reputation
25%
12
geolocation
0%
00
Overall20%57
Coverage: 4/6 dimensions · Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

📅 Observation Timeline 🔄 Live

First Seen2026-07-21 00:44:18 UTC
Last Seen2026-09-29 03:08:39 UTC
Profile Built2026-09-27 20:53:20 UTC
Data FreshnessLive
Signal Types18
Total Observations22
🔍 18 signal types · 22 observations collected
This report is generated from 18+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 59.36.254.224

Who owns the IP address 59.36.254.224?

59.36.254.224 is registered to IPMASTER CHINANET-GD. The address falls within the 59.42.0.0/16 network block. Registration is held at APNIC.

Where is 59.36.254.224 located?

Geolocation data places 59.36.254.224 in China. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 59.36.254.224 malicious or safe?

59.36.254.224 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.

🏘️ Related IP Addresses

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.