IP Intelligence Briefing: 111.31.134.95
Date: 2026-06-11
---
**1. Core Profile**
- Risk Score: 55 (Moderate Risk)
- Ownership:
- ASN: 38019
- Organization: IRT-CHINAMOBILE-CN (CMNET)
- Region: Beijing, China
- Geolocation:
- Country: China (CN)
- Coordinates: 34.77°N, 113.72°E
- Timezone: Asia/Shanghai
- Network Role: Mobile carrier (CMNET), no public services or hosting.
---
**2. Threat Indicators**
- No direct malicious activity: No indicators of spam, attacks, or known campaigns.
- DNSBL Listings:
- Listed in 3/8 DNSBLs (low-severity, likely false positives).
- BGP Data:
- Origin ASN: 38019 (CMNET)
- Route Stability: Unstable (route changes detected in 30 days).
---
**3. Observation History**
- Geolocation Inference:
- Confirmed as Beijing, China (confidence: 52%).
- DNS Security:
- DNSSEC valid, no RRSIG records.
- Operator Risk Score: Minimal (0.13), suggesting low operational risk.
---
**4. Network Relationships**
- Shared Network: Part of CMNET (ASN 38019), a major Chinese mobile carrier.
- Neighbors:
- 111.31.134.94: Risk score 40 (low risk, same subnet).
---
**5. Recommendations**
- Monitor DNSBL Listings: Investigate why this IP appears in 3 DNSBLs (potential misconfigurations or false positives).
- Track Route Stability: Monitor BGP changes for 111.31.134.95/24 subnet.
- Check Neighbors: 111.31.134.94 has low risk but should be reviewed for anomalies.
- Geolocation Validation: Verify consistency with CMNETβs infrastructure in Beijing.
---
Conclusion: 111.31.134.95 is associated with a legitimate Chinese mobile carrier but shows minor risks (DNSBL listings, unstable routing). No immediate threat detected, but ongoing monitoring is advised.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | IRT-CHINAMOBILE-CN |
| ASN | AS38019 |
| Network Name | CMNET |
| CIDR Block | 111.0.0.0/10 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 27% | 2 | 3 |
| reputation | 0% | 0 | 0 |
| geolocation | 13% | 1 | 1 |
| Overall | 15% | 5 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-28 23:50:32 UTC |
| Last Seen | 2026-06-11 18:15:03 UTC |
| Profile Built | 2026-06-11 18:23:25 UTC |
| Data Freshness | Live |
| Signal Types | 15 |
| Total Observations | 15 |
Full dossier details are available via our API.