IPDebrief

111.55.120.8

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING: 111.55.120.8/32

Classification: Mobile Carrier Infrastructure • Risk Level: Low (15/100) • Date: 2026-07-27

---

## Executive Summary

IP address 111.55.120.8 is a legitimate Chinese mobile carrier endpoint with minimal threat indicators. The address belongs to China Mobile's CMNET infrastructure (ASN 24444) and shows no evidence of malicious activity. While the IP appears on one of eight DNSBL lists with medium severity, overall risk assessment remains low. No firewall action is recommended at this time.

---

## Ownership & Network Context

AttributeValue
ASN24444 (CHINANET MOBILE COMMUNICATIONS CO., LTD.)
OrganizationIRT-CHINAMOBILE-CN
Network NameCMNET
CIDR Block111.0.0.0/10
RIRAPNIC (Asia-Pacific)
Geographic OriginChina (Shandong)
Infrastructure TypeMobile Carrier
Connection TypeN/A (No services)

The IP is classified as mobile infrastructure with no open ports, HTTP services, or TLS certificates detected. This is consistent with carrier-grade network routing points.

---

## Threat Indicators

No known threat campaigns, attacker indicators, or malicious behavior have been observed.

---

## Neighborhood Analysis (111.55.120.0/24)

Subnet Profile: Clean classification with 0% abuse density

IP AddressRisk ScoreClassification
111.55.120.125Low
111.55.120.8 (Target)15Low
111.55.120.1125Low
111.55.120.400Clean
111.55.120.580Clean
111.55.120.6115Low

The /24 subnet contains 6 sibling IPs with 3 active. Risk scores across the subnet remain low, supporting the conclusion that this is benign mobile carrier infrastructure.

---

## Observation History

15 signals recorded over the observation period. Key findings:

No ownership changes or threat persistence observed.

---

## Relationships

---

## Recommended Actions

Current Risk Level: LOW – No immediate action required

The IP shows characteristics of legitimate mobile carrier infrastructure with no evidence of abuse. The single DNSBL listing is likely a false positive given the carrier network classification and low overall risk score.

Monitoring Recommendation: Continue standard passive observation. No firewall blocking or rate-limiting recommended at this time.

---

Intelligence Analyst: IPDebrief Automated Analysis

Data Sources: IPDebrief™ Threat Intelligence Platform

Last Updated: 2026-07-27

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇨🇳 China
RegionShandong
City29
Timezone—
Latitude36.53
Longitude118.99

🏢 Ownership & Registration

OrganizationIRT-CHINAMOBILE-CN
ASNAS24444
Network NameCMNET
CIDR Block111.0.0.0/10
RIRAPNIC
CountryCN
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)

🔐 DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureMobile
Service PurposeFirewalled / No Services
Network TierUnknown — Insufficient routing data to classify
Mobile

🔌 Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS24444
Network Prefix111.55.120.0/23
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
0%
00
services
0%
00
ownership
0%
00
reputation
25%
11
geolocation
25%
11
Overall12%33
Coverage: 3/6 dimensions · Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

📅 Observation Timeline 🔄 Live

First Seen2026-07-13 03:13:43 UTC
Last Seen2026-07-27 04:41:24 UTC
Profile Built2026-08-30 22:44:10 UTC
Data FreshnessLive
Signal Types17
Total Observations19
🔍 17 signal types · 19 observations collected
This report is generated from 17+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 111.55.120.8

Who owns the IP address 111.55.120.8?

111.55.120.8 is registered to IRT-CHINAMOBILE-CN. The address falls within the 111.0.0.0/10 network block. Registration is held at APNIC.

Where is 111.55.120.8 located?

Geolocation data places 111.55.120.8 in 29, Shandong, China. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 111.55.120.8 malicious or safe?

111.55.120.8 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.

Is 111.55.120.8 a VPN, proxy, or data center address?

111.55.120.8 is classified as a mobile network based on network ownership and behavioural analysis.

🏘️ Related IP Addresses

Nearby addresses in 111.0.0.0/10

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.