IPDebrief

116.178.131.109

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING

Target: 116.178.131.109/32

Classification: Low Risk / Mobile Infrastructure

Date: 2026-06-17

Analyst: IPDebrief Intelligence System

---

## EXECUTIVE SUMMARY

IP 116.178.131.109 is a low-risk mobile infrastructure endpoint operated by China Unicom (ASN 4837, IRT-UNICOM-CN). The IP demonstrates minimal threat activity with no known malicious indicators, no blacklist associations, and no open network services. Classification indicates mobile carrier infrastructure with residential connectivity patterns.

---

## OWNERSHIP & GELOCATION

AttributeValue
**ASN**4837
**Organization**IRT-UNICOM-CN
**Country**China (CN)
**Region/City**Shanghai (SH)
**Network Block**116.178.0.0/16
**Provider**China Unicom / China United Network Communications
**Connection Type**Mobile (LTE/5G)
**Mobile Carrier**China Unicom (MCC: 460, MNC: 01)
**IP Class**Mobile Infrastructure

---

## RISK ASSESSMENT

MetricScoreAssessment
**Overall Risk**25/100LOW RISK
**Provider Score**0No provider-level concerns
**Authority Score**0No authority concerns
**Operator Score**0.1304Minimal operator risk
**DNSBL Listings**1/8Minimal listing presence

Threat Indicators

---

## NETWORK BEHAVIOR & SERVICES

---

## CONTROL PLANE ANALYSIS

---

## NEIGHBORHOOD ANALYSIS (116.178.131.0/24)

MetricValue
**Subnet**116.178.131.0/24
**Abuse Density**1 (Low)
**Classification**Mostly Clean
**Total Siblings**1
**Active Siblings**0
**Threat Siblings**1
**Risk Distribution**High: 0, Medium: 0, Low: 0

*Note: Neighborhood shows minimal abuse activity with one sibling threat indicator.*

---

## OBSERVATION HISTORY

Total Observations: 15 signals recorded

Recent Signal Timeline:

1. 2026-06-17 06:22:26 UTC - Ownership stability assessment (Confidence: 85%)

2. 2026-06-17 06:20:52 UTC - Neighborhood analysis - Abuse density: 1, Classification: mostly_clean (Confidence: 40%)

3. 2026-06-17 06:19:14 UTC - Threat assessment - Not attacker, Not spam source, Blacklist count: 0 (Confidence: 20%)

4. 2026-06-17 06:16:53 UTC - Geolocation - Country: CN, Confidence: 52% (Confidence: 52%)

5. 2026-06-17 06:14:24 UTC - Operator score assessment - Label: Minimal (Confidence: 30%)

Threat Persistence: 0 days

Persistent Malicious Status: No

Ownership Changes: 0

---

## RELATIONSHIP GRAPH

---

## SECURITY ACTIONS RECOMMENDATION

Risk Level: LOW

Action Priority: MONITOR / LOW PRIORITY

Based on the risk profile, this IP presents minimal threat to network security:

Recommended Handling:

---

## CONCLUSION

IP 116.178.131.109 is classified as low-risk mobile infrastructure under China Unicom's operational network. No actionable threat indicators or malicious behavior observed. Standard network operations procedures apply.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡จ๐Ÿ‡ณ China
RegionSH
CityShanghai
Timezoneโ€”
Latitude34.77
Longitude113.72

๐Ÿข Ownership & Registration

OrganizationIRT-UNICOM-CN
ASNAS4837
Network Nameโ€”
CIDR Blockโ€”
RIRAPNIC
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureMobile
Service PurposeFirewalled / No Services
Network TierUnknown โ€” Insufficient routing data to classify
Mobile

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
29%
23
routing
13%
11
services
8%
11
ownership
26%
23
reputation
28%
13
geolocation
21%
22
Overall21%913
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-07 23:03:32 UTC
Last Seen2026-06-22 10:14:19 UTC
Profile Built2026-06-22 10:21:59 UTC
Data FreshnessLive
Signal Types17
Total Observations18
๐Ÿ” 17 signal types ยท 18 observations collected
This report is generated from 17+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.