# IP Intelligence Briefing: 112.46.213.89/32
## Executive Summary
IP 112.46.213.89 is a low-risk residential mobile endpoint associated with China Mobile's CMNET infrastructure. The address shows no active threat indicators, no open services, and minimal neighborhood abuse activity. Monitoring recommended but no immediate blocking action warranted.
---
## Risk Assessment
- Overall Risk Score: 25 (Low Risk)
- Reputation Classification: Low Risk
- Abuse Confidence Score: N/A
- Blacklist Status: 0 blacklistings
---
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **ASN** | 9808 |
| **Organization** | haijun li (CMNET) |
| **ISP/Provider** | China Mobile Communications Corp. |
| **CIDR Block** | 112.0.0.0/10 |
| **RIR** | APNIC |
| **Connection Type** | Mobile (LTE/5G) |
| **MCC/MNC** | 460/00 |
---
## Geolocation Data
- Country: China (CN)
- Region: Jinrong Ave., Xicheng District, Beijing
- Coordinates: 34.77°N, 113.72°E
- Timezone: Asia/Shanghai
- Geo Consensus: True (1 source)
---
## Network Role Classification
- Infrastructure Type: Mobile Endpoint
- Cloud/CDN/Proxy: No
- Tor Exit: No
- Known Attacker: No
- Spam Source: No
- Bogon: No
- Anycast: No
---
## Service Analysis
- Open Ports: None detected
- DNS Resolution: No reverse DNS records
- Forward Resolution: 0 hosts
- HTTP/HTTPS Services: None active
- TLS Certificates: None
- Email Reputation: No DNS email authentication configured (no SPF/DMARC)
---
## Control Plane Analysis
- BGP Prefix: 112.46.128.0/17
- Route Stability: Unstable
- DNSBL Listing: 1 of 8 total lists
- Operator Score: 0.1304 (Minimal)
- RPKI State: Not applicable
- IRR Consistency: Not verified
---
## Threat Intelligence Signals
- Known Campaigns: None
- Threat Feeds: No matches
- Pulsedive Risk: N/A
- Campaign Likelihood: N/A
- Cert Matches: 0
- Banner Matches: 0
- Correlated IPs: 0
---
## Historical Observation Data
Total Observations: 11 signals
Key observations from 2026-07-30:
- Multiple geolocation sources confirming China location
- ASN identified as China Mobile Communications Group Co. Ltd.
- Threat indicators present in some signals (pulse_count: 31)
- No persistent malicious activity detected
- Ownership changes: 0
- Threat persistence days: 0
---
## Relationship Graph
- Identified Relationships: 2
- Type: Same Network (CMNET)
- Related Networks: CMNET (both relationships)
---
## /24 Subnet Analysis (Neighborhood)
- Subnet: 112.46.213.0/24
- Neighbor Count: 3
- Abuse Density: 0
- Risk Distribution:
- High Risk: 0
- Medium Risk: 0
- Low Risk: 3
- Neighbor Risk Scores: All 3 neighbors scored 25 (Low Risk)
- Threat Siblings: 0
- Active Siblings: 0
---
## Recommended Actions
Based on the low-risk profile (score 25), no specific blocking actions are recommended. The IP represents a mobile endpoint with no active threat indicators.
Monitoring Recommendations:
- No immediate firewall rules required
- Continue passive observation
- Monitor for changes in service patterns
- Track neighborhood activity for emerging threats
---
## Conclusion
IP 112.46.213.89 is a low-risk residential mobile endpoint on China Mobile's CMNET infrastructure. The address shows no malicious activity, no active services, and minimal neighborhood abuse density. The IP should be monitored but does not warrant immediate defensive action. Standard logging and passive observation are sufficient for this asset.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | haijun li |
| ASN | AS9808 |
| Network Name | CMNET |
| CIDR Block | 112.0.0.0/10 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-27 15:45:59 UTC |
| Last Seen | 2026-07-30 12:28:48 UTC |
| Profile Built | 2026-07-30 12:38:26 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 19 |
Full dossier details are available via our API.