IP Intelligence Briefing: 110.52.44.17
Date: 2026-06-06
---
**1. Core Profile**
- Risk Score: 40 (Moderate Risk)
- Ownership: ChinaUnicom Hostmaster (ASN 4837, APNIC)
- Geolocation: Hunan, Chenzhou, China (25.7993°N, 113.0387°E)
- Network Role: Mobile LTE/5G IP (China Unicom)
- Threat Indicators: No malicious activity detected (no abuse reports, blacklists, or campaigns).
---
**2. Observation History**
- Last 15 Days:
- Stable ownership (no changes).
- Geolocation consistency (MaxMind, Cymru DNS).
- No spikes in threat signals or DNS anomalies.
- Mobile carrier activity (China Unicom) persists.
---
**3. Relationships**
- Network Affiliation: Linked to "UNICOM-HN" network (China Unicom).
- No Known Threat Associations: No correlated malicious IPs or campaigns.
---
**4. Neighborhood Analysis**
- Subnet: 110.52.44.17/24
- Abuse Density: 0% (clean subnet).
- Neighbors: No active sibling IPs in the subnet (likely a single-host /32 allocation).
---
**5. Recommendations**
- Firewall Actions:
- Block via iptables: `iptables -A INPUT -s 110.52.44.17 -j DROP`
- AWS WAF: Add `110.52.44.17/32` to a rule with description "IPDebrief risk 40".
- Monitoring: Track for unexpected traffic spikes or geolocation shifts.
---
**6. Summary**
This IP is a legitimate mobile LTE/5G assignment under China Unicom, with no malicious indicators. While the moderate risk score suggests limited suspicious activity, the lack of concrete threats (no abuse reports, DNS anomalies, or campaign ties) indicates it is likely benign. Monitor for deviations from its established behavior.
Next Steps: Validate against internal threat feeds; consider blocking if used in unusual contexts.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | ChinaUnicom Hostmaster |
| ASN | AS4837 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | APNIC |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 24% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 33% | 2 | 4 |
| Overall | 20% | 9 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-11 15:03:43 UTC |
| Last Seen | 2026-06-26 09:48:39 UTC |
| Profile Built | 2026-06-26 09:52:35 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.