# IP INTELLIGENCE BRIEFING: 1.183.173.204/32
Date: 2026-07-17
Classification: Moderate Risk (Score: 55/100)
Jurisdiction: People's Republic of China (CN)
---
## EXECUTIVE SUMMARY
IP 1.183.173.204 is a moderate-risk address associated with China Telecom's mobile infrastructure. The IP shows no direct threat indicators but maintains a risk score of 55/100 due to DNSBL listings and mobile carrier association. No active threat campaigns, known attacker status, or spam source classification detected.
---
## OWNERSHIP & INFRASTRUCTURE
| Attribute | Value |
|---|---|
| ASN | 4134 |
| Organization | IRT-CHINANET-CN (China Telecom) |
| Network Block | 1.180.0.0/14 |
| RIR | APNIC |
| CIDR Block | 1.183.173.0/24 (neighborhood) |
| Service Role | Firewalled / No Services |
| Mobile Carrier | China Telecom (MCC: 460, MNC: 03) |
| Connection Type | LTE/5G Mobile |
Geolocation: China (CN), 34.7732°N, 113.722°E — confidence 0.70 (Multi-signal inference)
---
## THREAT INDICATORS
| Indicator | Status |
|---|---|
| Known Attacker | False |
| Spam Source | False |
| Tor Exit Node | False |
| Proxy/VPN/CDN | False |
| DNSBL Listings | 3 of 8 lists |
| Blacklist Count | 0 |
| Known Campaigns | None |
| Threat Persistence Days | 0 |
| Persistently Malicious | False |
Abuse Confidence: Not scored
Control Plane: Route stable (isRouteStable: false), BGP prefix 1.180.0.0/14
---
## NETWORK CONTEXT
Subnet Analysis (1.183.173.0/24):
- Abuse Density: 0
- Total Siblings: 1
- Threat Siblings: 0
- Neighbor: 1.183.173.116 (Risk: 25/100, Authority: 50)
Relationship Graph:
- 3 relationships identified, all to CHINANET-NM network block
- No external associations to hostnames, organizations, or certificates detected
---
## OBSERVATION HISTORY
Total Observations: 13
Recent Signals:
- 2026-07-17T23:45:25 — Geo: China (confidence 0.52), coordinates 35.86°N, 104.2°E
- 2026-07-17T23:41:44 — Ownership: IRT-CHINANET-CN (confidence 0.90)
- 2026-07-17T23:42:00 — Geo: China (confidence 0.70) via MaxMind GeoLite2
Temporal Analysis:
- Ownership changes: 0
- Threat observation count: 0
- Is persistently malicious: False
---
## SERVICES & PORTS
- Open Ports: None detected
- TLS Certificate: None
- HTTP Title: None
- Hosted Domains: 0
- DNS PTR Records: None
- Forward Resolution: 0
---
## RECOMMENDED ACTIONS
Primary Recommendation: Increase logging verbosity and monitor recent activity from this IP due to elevated risk score (55/100).
Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 1.183.173.204 -j DROP
# nftables
nft add rule inet filter input ip saddr 1.183.173.204 drop
# nginx
deny 1.183.173.204;
# pfSense
1.183.173.204/32
# Cloudflare WAF
{"description":"Block 1.183.173.204 — IPDebrief risk score 55","action":"block","filter":{"expression":"ip.src eq 1.183.173.204"}}
# AWS WAF
{"Addresses":["1.183.173.204/32"],"Description":"IPDebrief risk 55"}
```
---
## ANALYST NOTES
This IP resides within China Telecom's mobile network infrastructure (1.180.0.0/14 block). While no direct threat indicators are present, the moderate risk score derives from DNSBL listings and mobile carrier association. The subnet shows low abuse density with only one neighbor (1.183.173.116) showing low-risk classification. Monitor for any service activity or port scanning behavior. No immediate threat mitigation required unless observed network behavior aligns with threat actor patterns.
Status: Monitor — No immediate blocking required unless additional threat context emerges.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | IRT-CHINANET-CN |
| ASN | AS4134 |
| Network Name | CHINANET-NM |
| CIDR Block | 1.180.0.0/14 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS4134 |
| Network Prefix | 1.180.0.0/14 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-06-07 19:57:31 UTC |
| Last Seen | 2026-08-26 21:26:12 UTC |
| Profile Built | 2026-08-29 07:27:40 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 17 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 1.183.173.204
Who owns the IP address 1.183.173.204?
1.183.173.204 is registered to IRT-CHINANET-CN. The address falls within the 1.180.0.0/14 network block. Registration is held at APNIC.
Where is 1.183.173.204 located?
Geolocation data places 1.183.173.204 in China. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 1.183.173.204 malicious or safe?
1.183.173.204 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
Is 1.183.173.204 a VPN, proxy, or data center address?
1.183.173.204 is classified as a mobile network based on network ownership and behavioural analysis.