THREAT INTELLIGENCE BRIEFING
Target: 59.36.254.224/32
Classification: Moderate Risk Infrastructure
Date: Current
---
EXECUTIVE SUMMARY
IP 59.36.254.224 operates within China under APNIC RIR allocation. The address demonstrates moderate risk characteristics with a risk score of 50, listed on two DNS blacklists. No active threat indicators or open services were detected during the assessment period.
NETWORK OWNERSHIP & GEOLOCATION
The IP belongs to IPMASTER CHINANET-GD (ASN 136199) within CIDR block 59.42.0.0/16. Geolocation data indicates China (CN) with multiple geolocation source validations. Origin BGP prefix: 59.36.240.0/20. Route stability shows false state, indicating potential routing changes.
THREAT PROFILE
- Risk Score: 50 (Moderate)
- DNSBL Listings: 2 out of 8 total lists checked
- Threat Indicators: None detected
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Campaign Correlation: None identified
SERVICE & INFRASTRUCTURE ANALYSIS
No open ports detected. Network role classified as "Firewalled / No Services." DNS configuration shows no forward resolution capability. PTR records empty. No TLS certificates or HTTP services observed.
CONTROL PLANE DATA
RPKI state and IRR consistency not validated. Route changes observed over 30-day period. MOAS status: false. Operator score: 0.1304 (Minimal).
OBSERVATION HISTORY (16 Signals)
Recent observations from 2026-07-29 show:
- ICMP validation failures with geo discrepancies
- Consistent ownership attribution to IPMASTER CHINANET-GD
- Geolocation signals from multiple sources confirming China presence
- Single threat observation recorded
- No persistent malicious activity detected
NETWORK NEIGHBORHOOD (59.36.254.0/24)
Subnet classification: Mostly clean. Abuse density: 0. Risk inheritance score: 2. No active sibling IPs detected. Network appears isolated with minimal lateral risk.
RELATIONSHIP GRAPH
Two relationship entries identified, both mapping to CHINANET-GD network. No external hostnames, organizations, or certificate relationships detected.
RECOMMENDATIONS
1. Monitor DNSBL listing status for changes
2. Apply rate limiting if attempting inbound connections
3. No immediate blocking required; moderate risk threshold
4. Continue monitoring for service emergence
RISK ASSESSMENT
The IP presents moderate risk primarily through blacklist presence without active threat indicators. Infrastructure appears defensive (firewalled) with no open services. Recommended for monitoring rather than immediate mitigation.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | IPMASTER CHINANET-GD |
| ASN | AS136199 |
| Network Name | CHINANET-GD |
| CIDR Block | 59.42.0.0/16 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 0% (None) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS136199 |
| Network Prefix | 59.36.240.0/20 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 50% | 2 | 3 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 2 |
| geolocation | 0% | 0 | 0 |
| Overall | 20% | 5 | 7 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-21 00:44:18 UTC |
| Last Seen | 2026-09-29 03:08:39 UTC |
| Profile Built | 2026-09-27 20:53:20 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 22 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 59.36.254.224
Who owns the IP address 59.36.254.224?
59.36.254.224 is registered to IPMASTER CHINANET-GD. The address falls within the 59.42.0.0/16 network block. Registration is held at APNIC.
Where is 59.36.254.224 located?
Geolocation data places 59.36.254.224 in China. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 59.36.254.224 malicious or safe?
59.36.254.224 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.