# INTELLIGENCE BRIEFING: 81.71.96.41/32
## EXECUTIVE SUMMARY
IP 81.71.96.41 is a Tencent Cloud infrastructure address classified as Moderate Risk (50/100). The IP is associated with cloud hosting services in Guangzhou, China, and presents limited direct threat indicators. Network activity indicates minimal service exposure with firewalled ports only.
## OWNERSHIP & GEOLOCATION
- Organization: Tencent Cloud administrator (AS45090)
- Location: Guangzhou, Guangdong, China
- Network Block: 81.71.64.0/18
- Registration: RIR RIPE
## THREAT INDICATORS
- Risk Score: 50 (Moderate)
- Blacklist Status: Listed on 2 of 8 DNSBLs
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Campaign Involvement: None detected
## NETWORK POSTURE
- Service Exposure: Firewalled / No Services
- Open Ports: None
- DNS Configuration: No PTR records, no forward resolution
- SSL/TLS: No certificates detected
- Operator Score: 0.2174 (Minimal)
## NEIGHBORHOOD ANALYSIS
Subnet 81.71.96.0/24 shows:
- Abuse Density: 1 (low)
- Classification: Mostly clean
- Neighbor Count: 1 active sibling (81.71.96.210, Risk: 25)
- Threat Siblings: 2 within subnet
- Inherited Risk: 5
## OBSERVATION HISTORY
- Total Observations: 23 signals
- Recent Activity: Multiple DNSBL listings detected as of 2026-06-23
- Threat Persistence: No persistent malicious behavior observed
- Ownership Stability: No ownership changes recorded
## RELATIONSHIP GRAPH
- Primary Association: 31 relationships to TENCENT-CN network
- DNS Associations: Minimal (communications errors to internal addresses)
- No Correlated IPs: No additional related threat entities identified
## RECOMMENDED ACTIONS
1. Monitor: Continue monitoring for DNSBL listing changes
2. Block if Required: Consider blocking if traffic from this subnet correlates with malicious activity
3. Investigate: Monitor for any service exposure changes on firewalled ports
4. Context: Low-priority threat; treat as cloud infrastructure rather than direct attack vector
## RISK ASSESSMENT
This IP represents cloud infrastructure with moderate reputation risk. Primary concerns stem from DNSBL listings rather than active threat indicators. The subnet shows low abuse density, suggesting the IP is likely legitimate cloud hosting. SOC teams should monitor for any changes in service exposure or escalation in threat indicators.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Tencent Cloud administrator |
| ASN | AS45090 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 24% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 23% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 22% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:36 UTC |
| Last Seen | 2026-06-26 18:11:37 UTC |
| Profile Built | 2026-06-23 22:36:16 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.