## IP INTELLIGENCE BRIEFING: 117.60.127.79/32
Classification: MODERATE RISK | Timestamp: 2026-07-31
Executive Summary
IP 117.60.127.79 is a mobile-originated address assigned to China Telecom (ASN 4134, CHINANET-JS network) with a moderate risk score of 50. The IP shows no active threat indicators but maintains a firewalled profile with no open services. Geographic origin is China (CN) with validation challenges due to ICMP blocking.
Network Attribution
- ASN: 4134 (Chinanet)
- Organization: Chinanet Hostmaster
- Network Block: 117.60.0.0/14
- Geolocation: China (claimed coordinates: 34.7732°N, 113.722°E)
- Connection Type: Mobile (China Telecom, LTE/5G)
- Mobile MCC/MNC: 460/03
Threat Assessment
- Risk Score: 50 (Moderate)
- Abuse Confidence: None reported
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0
- Threat Campaigns: None correlated
- DNSBL Listings: 2 of 8 total lists (minor presence)
- Control Plane Status: Route unstable (false), minimal operator score (0.1304)
Service & Port Analysis
- Open Ports: None detected
- Service Classification: Firewalled / No Services
- DNS Resolution: No PTR records, no forward resolution
- TLS/HTTP: No certificates or web services detected
- Email Reputation: No data available
Neighborhood Analysis
Subnet: 117.60.127.79/24
- Abuse Density: 0.0 (clean)
- Classification: Clean
- Total Siblings: 4 (all active)
- Threat Siblings: 0
Neighbor Risk Distribution:
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 117.60.127.79 | 50 | 0 |
| 117.60.127.75 | 25 | 50 |
| 117.60.127.160 | 50 | 50 |
| 117.60.127.243 | 25 | 50 |
Temporal Intelligence
- Observation Count: 17 signals
- Ownership Changes: 0
- Threat Persistence Days: 0
- Is Persistently Malicious: No
- Recent Activity: Signals observed 2026-07-31
Relationship Graph
- Direct Relationships: 3 (all same network CHINANET-JS)
- Associated Hostnames: None
- Associated Organizations: None
- Associated Certificates: None
Recommended Actions
No specific firewall rules or mitigation actions recommended at this time. The IP shows no active malicious behavior or known attack patterns.
Analyst Notes
This IP represents mobile traffic from a legitimate Chinese telecommunications provider. The moderate risk score (50) is elevated primarily due to the risk model's treatment of mobile connections and geographic origin, not confirmed malicious activity. The subnet demonstrates clean classification with zero threat siblings. Monitoring for changes in service patterns or blacklist additions is recommended.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Chinanet Hostmaster |
| ASN | AS4134 |
| Network Name | CHINANET-JS |
| CIDR Block | 117.60.0.0/14 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-30 11:03:00 UTC |
| Last Seen | 2026-08-01 04:24:51 UTC |
| Profile Built | 2026-07-31 01:50:26 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.