# IP Intelligence Briefing: 111.61.176.245/32
## Executive Summary
IP address 111.61.176.245 is classified as HIGH RISK (Risk Score: 80/100) and associated with China Mobile's CMNET infrastructure in Hebei Province. The IP is part of a mobile carrier network with no active services exposed. Neighborhood analysis reveals 4 additional high-risk neighbors within the same /24 subnet, indicating concentrated abuse activity.
## Profile Overview
- Risk Score: 80 (High Risk)
- ASN: 24547 (IRT-CHINAMOBILE-CN / CMNET-V4HEBEI-AS-AP)
- Organization: Hebei Mobile Communication Company Limited
- Location: Zaoqiang, Hebei Province, China (CN)
- Network Classification: Mobile Carrier / Firewalled
- Service Status: No open ports, no active services
- DNSBL Listings: 5 out of 8 total lists
## Threat Indicators
- Known Attacker: Not flagged as known attacker
- Spam Source: Not flagged as spam source
- Tor Exit Node: No
- Blacklist Count: 0 (but 5 DNSBL entries present)
- Campaign Association: No known campaigns correlated
- Threat Persistence: Not persistently malicious
## Neighborhood Analysis
The /24 subnet (111.61.176.245/24) shows concentrated risk:
- Abuse Density: 1 (elevated)
- Total Siblings: 4
- High-Risk Neighbors: 4 (100% of subnet)
- Neighbor IPs: 111.61.176.58, 111.61.176.242, 111.61.176.243, 111.61.176.244
- Neighbor Risk Scores: All 4 neighbors scored 80 (High Risk)
## Historical Observations
- Observation Count: 15 signals recorded
- Latest Observation: 2026-06-17
- Network Registration: ASN 24547 allocated 2009-05-06
- Ownership Changes: 0 (stable registration)
- Threat Observation Count: 1
## Network Relationships
- Primary Association: CMNET (China Mobile CMNET network)
- Relationship Count: 11 relationships (all Same Network type)
- Network Scope: CMNET infrastructure
## Recommended Actions
Firewall Rules:
- Block inbound traffic from 111.61.176.0/22 (originating prefix)
- Consider blocking the entire /24 subnet (111.61.176.0/24) given 100% abuse density
- Implement geo-blocking for non-business China Mobile ranges if applicable
Monitoring:
- Add to blocklist with priority HIGH
- Monitor for connection attempts from neighborhood IPs
- Alert on any service exposure from this subnet
## SOC Analyst Notes
This IP belongs to China Mobile's CMNET infrastructure in Hebei. While no specific threat indicators (malware, spam, scanning) were flagged in the profile, the high risk score and 100% high-risk neighbor density suggest this subnet may be used for legitimate services with potential abuse vectors. The mobile carrier classification means this is infrastructure rather than a compromised endpoint. Recommend blocking at perimeter while monitoring for legitimate traffic patterns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-CHINAMOBILE-CN |
| ASN | AS24547 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | APNIC |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 15% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 27% | 2 | 3 |
| reputation | 15% | 1 | 2 |
| geolocation | 19% | 2 | 2 |
| Overall | 17% | 9 | 11 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Fresh
| First Seen | 2026-05-07 23:03:30 UTC |
| Last Seen | 2026-06-26 18:10:23 UTC |
| Profile Built | 2026-06-26 23:41:56 UTC |
| Data Freshness | Fresh |
| Signal Types | 15 |
| Total Observations | 15 |
Full dossier details are available via our API.