## IP Intelligence Briefing: 61.153.104.6/32
Classification: Moderate Risk
Date: Current
Analysis: Full profile compiled from IPDebrief intelligence platform
Executive Summary
IP 61.153.104.6 is a Chinese-based address in Hangzhou with a moderate risk score (50/100). The IP belongs to HANGZHOU-SRT-TECHNOLOGY-CO-LTD (ASN 58461) and is currently firewalled with no active services detected. The address shows stable network characteristics with no persistent malicious activity.
Network Attribution
- Organization: HANGZHOU-SRT-TECHNOLOGY-CO-LTD
- Network Name: HANGZHOU-SRT-TECHNOLOGY-CO-LTD
- ASN: 58461
- IP Block: 61.153.104.0/23
- RIR: APNIC (Asia-Pacific)
- Geolocation: Hangzhou, China (CN)
- Registration: APNIC RIR registry
Threat Indicators
- Risk Score: 50 (Moderate Risk)
- Blacklist Count: 0
- Known Campaigns: None
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Abuse Confidence Score: Not applicable
Network Services & Infrastructure
- Open Ports: None detected
- TLS Certificate: None
- HTTP Title: None
- DNS Resolution: No PTR hostnames, no forward resolution
- Email Authentication: No SPF/DMARC records
- Network Role: Firewalled / No Services
- Infrastructure Type: Not cloud, CDN, VPN, proxy, or hosting service
Neighborhood Analysis
- Subnet: 61.153.104.6/24
- Abuse Density: 0 (mostly clean)
- Classification: mostly_clean
- Total Siblings: 0
- Active Siblings: 0
- Threat Siblings: 0
- Inherited Risk: 2
The /24 subnet contains no neighboring IPs with threat indicators, suggesting this address is not part of a coordinated abuse cluster.
Observation History
- Total Observations: 34 signals recorded
- Recent Activity: Signals observed through June 2026
- Threat Persistence: 0 days
- Ownership Changes: 0
- Threat Observation Count: 1
- Persistently Malicious: No
The IP demonstrates stable ownership and routing characteristics with no evidence of escalating threat behavior over time.
Control Plane & Routing
- Origin ASN: 58461
- BGP Prefix: 61.153.104.0/23
- AS Path: 3303 4134 58461
- Route Stability: Stable
- MOAS: No
- Route Changes (30d): 0
- RPKI State: Not verified
- IRR Consistency: Not verified
- DNSSEC Valid: Yes
- Delegation Age: 5,299 days
Recommended Actions
Based on the risk profile, the following firewall rules are recommended:
iptables:
```
iptables -A INPUT -s 61.153.104.6 -j DROP
```
nftables:
```
nft add rule inet filter input ip saddr 61.153.104.6 drop
```
nginx:
```
deny 61.153.104.6;
```
pfSense:
```
61.153.104.6/32
```
Cloudflare WAF:
```json
{"description":"Block 61.153.104.6 โ IPDebrief risk score 50","action":"block","filter":{"expression":"ip.src eq 61.153.104.6"}}
```
AWS WAF:
```json
{"Addresses":["61.153.104.6/32"],"Description":"IPDebrief risk 50"}
```
Intelligence Assessment
This IP represents a moderate-risk address from a Chinese technology company network. The absence of open services, zero blacklist entries, and clean neighborhood profile suggest low immediate threat potential. However, the moderate risk score warrants monitoring. SOC analysts should treat traffic from this IP with standard caution but the lack of active threat indicators reduces priority for immediate investigation.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Bing Bai |
| ASN | AS58461 |
| Network Name | HANGZHOU-SRT-TECHNOLOGY-CO-LTD |
| CIDR Block | 61.153.104.0/23 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 22% | 2 | 4 |
| routing | 27% | 2 | 3 |
| services | 20% | 2 | 3 |
| ownership | 27% | 3 | 4 |
| reputation | 19% | 1 | 3 |
| geolocation | 30% | 2 | 4 |
| Overall | 24% | 12 | 21 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:05:39 UTC |
| Last Seen | 2026-06-25 01:27:11 UTC |
| Profile Built | 2026-06-25 01:37:19 UTC |
| Data Freshness | Live |
| Signal Types | 30 |
| Total Observations | 31 |
Full dossier details are available via our API.