INTELLIGENCE BRIEFING: IP 113.2.102.101
Classification: High Risk (80/100)
Date of Analysis: Current
Status: Active Threat Indicator
---
Executive Summary
IP 113.2.102.101 is a high-risk mobile endpoint associated with ChinaUnicom (ASN 4837, UNICOM-HL). The address operates on a residential mobile connection (China Unicom LTE/5G) within the 113.0.0.0/13 BGP prefix. Despite lacking open services, the IP exhibits elevated threat characteristics including multiple DNSBL listings and unstable routing.
---
Network Identity & Infrastructure
- ASN: 4837 (CHINA169-Backbone - China Unicom China169 Backbone)
- Organization: ChinaUnicom Hostmaster (UNICOM-HL)
- Network Block: 113.0.0.0/13 (APNIC RIR)
- Geolocation: China (CN) โ inferred with 52% confidence
- Connection Type: Residential Mobile (China Unicom, MCC 460, MNC 01)
- Subnet Classification: 113.2.102.101/24
Infrastructure Assessment
No services detected (firewalled/no open ports). No reverse DNS resolution. DNSSEC validation confirmed. Route stability flagged as unstable with zero route changes observed in the 30-day window.
---
Threat Indicators
- Risk Score: 80/100 (High Risk)
- DNSBL Status: Listed on 5 of 8 threat feeds (high severity)
- Campaign Correlation: No known campaigns matched
- Campaign Likelihood: Not assessed
- Known Attacker Status: Not flagged
- Tor Exit Node: No
Abuse Signals
The IP appears on multiple reputation feeds with high severity ratings. While no specific threat indicators were enumerated in the current profile, the DNSBL presence suggests prior malicious activity or association with abuse campaigns.
---
Historical Observations
Thirteen signal observations recorded as of 2026-07-30. Key observations include:
- Consistent country attribution to China (CN)
- ASN resolution maintained to ChinaUnicom
- DNSSEC validity confirmed
- No ownership changes detected
- No persistent malicious activity pattern established
---
Network Relationships & Neighborhood
- Relationship Graph: Two relationships identified, both referencing UNICOM-HL network
- Subnet Analysis: No neighboring IPs detected in the /24 subnet
- Abuse Density: Zero for the immediate subnet
- Threat Siblings: None identified
---
Recommended Security Actions
Immediate Actions:
1. Implement blocking rules across perimeter defenses
2. Increase logging verbosity for traffic from this IP
3. Review historical activity for any successful connections
Firewall Rules Provided:
- iptables: `iptables -A INPUT -s 113.2.102.101 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 113.2.102.101 drop`
- nginx: `deny 113.2.102.101;`
- pfSense: `113.2.102.101/32`
- Cloudflare WAF: Block with expression `ip.src eq 113.2.102.101`
- AWS WAF: Address block `113.2.102.101/32`
---
Assessment
This IP represents a moderate to high-risk endpoint operating on ChinaUnicom's residential mobile network. While no active exploitation was detected, the combination of multiple DNSBL listings and unstable routing warrants defensive blocking. The lack of open services suggests either legitimate residential use or a dormant compromised endpoint. SOC analysts should maintain logging oversight and consider the IP for threat hunting correlation with other indicators from the ChinaUnicom network block.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | ChinaUnicom Hostmaster |
| ASN | AS4837 |
| Network Name | UNICOM-HL |
| CIDR Block | 113.0.0.0/13 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 25% | 1 | 1 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-26 09:11:40 UTC |
| Last Seen | 2026-07-30 06:53:52 UTC |
| Profile Built | 2026-07-30 07:04:50 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 19 |
Full dossier details are available via our API.