# IP Intelligence Briefing: 111.31.165.206/32
Classification: High Risk (Risk Score: 80/100)
Date: 2026-07-30
---
## Executive Summary
IP address 111.31.165.206 was assessed as high-risk with a risk score of 80/100. The IP is listed on 5 out of 8 DNSBLs with high-severity classifications. Geoconsensus indicates China (CN), though geolocation data showed inconsistencies (geoPlausible=false). No active services were detectedβthe IP is classified as "Firewalled / No Services."
---
## Technical Profile
- ASN: 38019
- BGP Prefix: 111.31.160.0/21
- Network Role: Residential/Hosting (classification flags: not provider, CDN, cloud, VPN, proxy, Tor, or mobile)
- Open Ports: None detected
- TLS/HTTP: No certificates, no HTTP title or banner
- DNS: PTR record exists in zone 206.165.31.111.in-addr.arpa; DNSSEC valid; no forward resolution
- Email: No SPF/DMARC records detected
---
## Threat Indicators
- DNSBL Listings: 5 confirmed listings across 8 total blacklist feeds
- Maximum Severity: High
- Known Campaigns: None identified
- Tor Exit/VPN/Proxy: Not flagged
- Active Attacker Status: Not currently marked as actively malicious
- Threat Persistence: 0 days observed
---
## Observation History
Eight signals were recorded, with the most recent activity from 2026-07-30T03:56:28 UTC. Geolocation signals consistently mapped to China (CN) with coordinates 34.7732, 113.722. DNSSEC validation was confirmed for the PTR record. No significant temporal changes in threat persistence were observed.
---
## Neighborhood Analysis (111.31.165.0/24)
The /24 subnet contains 11 sibling IPs with an overall abuse density of 0. Risk distribution shows 5 medium-risk neighbors (scores: 15, 15, 30, 40, 40, 40) and 5 low-risk neighbors (scores: 15, 15, 15). Two neighbors (111.31.165.109, 111.31.165.186) share elevated risk scores of 55. No inherited risk was detected for the target IP.
---
## Recommended Actions
Based on the elevated risk profile, the following security controls are recommended:
Monitoring: Increase logging verbosity and review recent activity from this IP.
Firewall Rules:
- iptables: `iptables -A INPUT -s 111.31.165.206 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 111.31.165.206 drop`
- nginx: `deny 111.31.165.206;`
- pfSense: Add 111.31.165.206/32 to blocklist
- Cloudflare WAF: Block IP with expression `ip.src eq 111.31.165.206`
- AWS WAF: Add 111.31.165.206/32 to protected resource
---
## Notes
Relationship graph analysis returned no related entities (no associated hostnames, organizations, or certificates). The IP's classification as "Firewalled / No Services" suggests defensive blocking or inactive status, though DNSBL listings indicate prior abusive activity. SOC teams should correlate with internal logs for any historical connections.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | IRT-CHINAMOBILE-CN |
| ASN | AS38019 |
| Network Name | CMNET |
| CIDR Block | 111.0.0.0/10 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 8% | 2 | 2 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-25 14:52:18 UTC |
| Last Seen | 2026-08-04 11:50:13 UTC |
| Profile Built | 2026-07-30 04:00:50 UTC |
| Data Freshness | Live |
| Signal Types | 13 |
| Total Observations | 13 |
Full dossier details are available via our API.