IP INTELLIGENCE BRIEFING: 1.191.223.84/32
Classification: High Risk
Risk Score: 80/100
Date: 2026-07-31
---
**Executive Summary**
IP address 1.191.223.84 is classified as high-risk with a risk score of 80/100. The address is assigned to ChinaUnicom Hostmaster (UNICOM-HL) within the 1.188.0.0/14 CIDR block and is associated with China (CN) mobile infrastructure. No active services are observed on the IP, but the elevated risk score warrants monitoring and defensive blocking.
---
**Ownership and Network Information**
- ASN: 4837 (ChinaUnicom Hostmaster)
- Organization: China United Network Communications
- CIDR Block: 1.188.0.0/14
- RIR: APNIC
- Network Classification: Mobile/Residential infrastructure (China Unicom LTE/5G)
---
**Geolocation Assessment**
- Country: China (CN)
- Coordinates: 35.86°N, 104.2°E (confidence: 52%)
- Geographic Accuracy: 2500km radius
- Validation Status: ICMP validation blocked; minimum possible RTT 160.7ms
- Distance from Reference Point: 8033.2km
---
**Threat Indicators**
- Abuse Confidence Score: Not reported
- Blacklist Status: Listed on 5 of 8 DNSBLs
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Campaign Associations: None identified
- Threat Feeds: No active indicators
---
**Network Services and DNS**
- Open Ports: None detected
- TLS Certificate: None
- Hosted Domains: 0
- PTR Records: None
- Forward Resolution: Not confirmed
- Email Authentication: SPF/DMARC not configured
- Service Status: Firewalled / No services detected
---
**Control Plane Analysis**
- Route Stability: Unstable (isRouteStable: false)
- Route Changes (30d): 0
- MoAS Status: No
- RPKI State: Not reported
- IRR Consistency: Not reported
- DNSSEC Validation: Valid
- Operator Score: 0.1304 (Minimal)
---
**Observation History**
Total observations: 12 (most recent: 2026-07-31)
- Signal Types: Geo, ownership, hop count, operator, overall assessment
- Threat Persistence: 0 days
- Ownership Changes: 0
- Persistently Malicious: No
---
**Neighborhood Analysis**
- Subnet: 1.191.223.84/24
- Neighbor Count: 0
- Abuse Density: 0
- High/Medium/Low Risk Neighbors: 0/0/0
- Threat Siblings: 0
---
**Relationship Graph**
- Related Entities: 3 relationships identified
- Type: Same Network (UNICOM-HL)
- Target: Network entities within UNICOM-HL infrastructure
---
**Recommended Security Actions**
Priority: Critical
Action: Block and monitor
Firewall Rules:
- iptables: `iptables -A INPUT -s 1.191.223.84 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 1.191.223.84 drop`
- nginx: `deny 1.191.223.84;`
- pfSense: `1.191.223.84/32`
- Cloudflare WAF: Block with expression `ip.src eq 1.191.223.84`
- AWS WAF: Add address `1.191.223.84/32`
Monitoring: Increase logging verbosity and review all recent activity from this IP due to elevated risk score (80/100).
---
**Conclusion**
The IP address 1.191.223.84 represents a high-risk threat profile with multiple DNSBL listings and a risk score of 80/100. Despite no active services or open ports being detected, the combination of mobile infrastructure classification, elevated risk scoring, and blacklist associations warrants immediate defensive blocking and enhanced logging for potential threat correlation.
Status: Block recommended pending further correlation with local threat intelligence.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | ChinaUnicom Hostmaster |
| ASN | AS4837 |
| Network Name | UNICOM-HL |
| CIDR Block | 1.188.0.0/14 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 20% | 5 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-30 17:10:51 UTC |
| Last Seen | 2026-08-01 10:24:24 UTC |
| Profile Built | 2026-07-31 03:00:07 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 16 |
Full dossier details are available via our API.