# IP Intelligence Briefing: 113.65.249.32/32
## Executive Summary
IP address 113.65.249.32 presents a Moderate Risk profile (Risk Score: 55/100) from Guangdong Province, China. The address is assigned to IPMASTER CHINANET-GD (ASN 4134) under the China Telecom mobile carrier infrastructure. While no active threat indicators were detected, the elevated risk score combined with mobile carrier association warrants defensive monitoring and selective blocking.
## Profile Details
| Attribute | Value |
|---|---|
| **Organization** | IPMASTER CHINANET-GD |
| **ASN** | 4134 (CHINANET-GD) |
| **Country** | China (CN) |
| **Region** | Guangdong |
| **City** | Guangzhou |
| **Connection Type** | Mobile (China Telecom LTE/5G) |
| **Classification** | Mobile, Firewalled/No Services |
## Risk Assessment
- Overall Risk Score: 55/100 (Moderate Risk)
- Abuse Confidence Score: Not available
- Blacklist Count: 0
- Known Campaigns: None identified
- Threat Persistence: Not persistently malicious
## Technical Indicators
- Open Ports/Services: None detected (firewalled/no services)
- DNS: No PTR records, no hosted domains
- TLS Certificates: None
- BGP Route: 113.64.0.0/11 (Route stable)
- RPKI State: Not found
- DNSBL Listings: 3 of 8 lists
## Network Context
- Subnet Classification: Clean (113.65.249.32/24)
- Abuse Density: 0%
- Threat Siblings: 0
- Total Siblings: 1
- Control Plane: Route stable, no route changes in 30 days
## Historical Observations
Analysis of 25 historical observations reveals:
- Recent Activity: Certificate queries detected on 2026-06-22
- Geolocation Signals: Multi-signal inference consistently placing address in China (Guangzhou region)
- Threat Observations: 1 threat observation recorded
- Risk Trend: Stable with no escalation pattern detected
## Intelligence Relationships
- 30 network relationships identified, all mapping to CHINANET-GD infrastructure
- No external organizational or hostname relationships detected
- All relationships classified as "Same Network"
## Recommended Actions
Immediate (High Priority)
1. Increase Logging: Monitor all traffic from this IP source with enhanced verbosity
2. Selective Blocking: Implement firewall rules to drop traffic from 113.65.249.32/32
Firewall Rules
```bash
# iptables
iptables -A INPUT -s 113.65.249.32 -j DROP
# nftables
nft add rule inet filter input ip saddr 113.65.249.32 drop
# nginx
deny 113.65.249.32;
# Cloudflare WAF
{"description":"Block 113.65.249.32 โ IPDebrief risk score 55","action":"block","filter":{"expression":"ip.src eq 113.65.249.32"}}
# AWS WAF
{"Addresses":["113.65.249.32/32"],"Description":"IPDebrief risk 55"}
```
Operational Notes
- The mobile carrier association suggests potential for residential or IoT device activity
- Zero open services detected indicates the address may be a client endpoint or proxy
- Consider correlating with other mobile traffic patterns from the 113.64.0.0/11 prefix
## Conclusion
While this IP lacks direct threat indicators, the moderate risk score (55/100) combined with mobile carrier infrastructure warrants defensive posture. Recommend implementing blocking rules and monitoring for correlation with other malicious activity. Reassess after 7 days if no legitimate traffic patterns emerge.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IPMASTER CHINANET-GD |
| ASN | AS4134 |
| Network Name | CHINANET-GD |
| CIDR Block | 113.64.0.0/11 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 23% | 2 | 3 |
| routing | 30% | 3 | 4 |
| services | 8% | 1 | 1 |
| ownership | 27% | 3 | 4 |
| reputation | 23% | 1 | 3 |
| geolocation | 26% | 2 | 3 |
| Overall | 23% | 12 | 18 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:31 UTC |
| Last Seen | 2026-06-22 09:42:20 UTC |
| Profile Built | 2026-06-22 09:50:14 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 25 |
Full dossier details are available via our API.