IPDebrief

113.2.102.101

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

INTELLIGENCE BRIEFING: IP 113.2.102.101

Classification: High Risk (80/100)

Date of Analysis: Current

Status: Active Threat Indicator

---

Executive Summary

IP 113.2.102.101 is a high-risk mobile endpoint associated with ChinaUnicom (ASN 4837, UNICOM-HL). The address operates on a residential mobile connection (China Unicom LTE/5G) within the 113.0.0.0/13 BGP prefix. Despite lacking open services, the IP exhibits elevated threat characteristics including multiple DNSBL listings and unstable routing.

---

Network Identity & Infrastructure

Infrastructure Assessment

No services detected (firewalled/no open ports). No reverse DNS resolution. DNSSEC validation confirmed. Route stability flagged as unstable with zero route changes observed in the 30-day window.

---

Threat Indicators

Abuse Signals

The IP appears on multiple reputation feeds with high severity ratings. While no specific threat indicators were enumerated in the current profile, the DNSBL presence suggests prior malicious activity or association with abuse campaigns.

---

Historical Observations

Thirteen signal observations recorded as of 2026-07-30. Key observations include:

---

Network Relationships & Neighborhood

---

Recommended Security Actions

Immediate Actions:

1. Implement blocking rules across perimeter defenses

2. Increase logging verbosity for traffic from this IP

3. Review historical activity for any successful connections

Firewall Rules Provided:

---

Assessment

This IP represents a moderate to high-risk endpoint operating on ChinaUnicom's residential mobile network. While no active exploitation was detected, the combination of multiple DNSBL listings and unstable routing warrants defensive blocking. The lack of open services suggests either legitimate residential use or a dormant compromised endpoint. SOC analysts should maintain logging oversight and consider the IP for threat hunting correlation with other indicators from the ChinaUnicom network block.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡จ๐Ÿ‡ณ China
Regionโ€”
Cityโ€”
Timezoneโ€”
Latitudeโ€”
Longitudeโ€”

๐Ÿข Ownership & Registration

OrganizationChinaUnicom Hostmaster
ASNAS4837
Network NameUNICOM-HL
CIDR Block113.0.0.0/13
RIRAPNIC
CountryCN
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureMobile
Service PurposeFirewalled / No Services
Network TierUnknown โ€” Insufficient routing data to classify
Mobile

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
0%
00
services
0%
00
ownership
0%
00
reputation
25%
11
geolocation
25%
11
Overall12%33
Coverage: 3/6 dimensions ยท Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-07-26 09:11:40 UTC
Last Seen2026-07-30 06:53:52 UTC
Profile Built2026-07-30 07:04:50 UTC
Data FreshnessLive
Signal Types19
Total Observations19
๐Ÿ” 19 signal types ยท 19 observations collected
This report is generated from 19+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.