# IP Intelligence Briefing: 119.51.241.46/32
Classification: Moderate Risk
Date of Analysis: 2026-07-29
Analyst: IPDebrief Intelligence Unit
---
## Executive Summary
IP 119.51.241.46 is a China-based residential connection associated with China Unicom Hostmaster (AS4837). The IP presents a moderate risk score of 55/100 with no active threat indicators but exhibits elevated monitoring concerns due to risk classification. The address shows inconsistent route stability and has been listed on 3 of 8 DNSBLs.
---
## Technical Profile
Ownership & Network:
- ASN: AS4837 (China Unicom China169 Backbone)
- BGP Prefix: 119.48.0.0/13
- Organization: ChinaUnicom Hostmaster
- Abuse Contact: zhaoyz3@chinaunicom.cn
Geolocation:
- Country: China (CN)
- Coordinates: 34.77°N, 113.72°E
- Timezone: Asia/Shanghai
- Distance from Probe: 8,033 km
Network Classification:
- Role: Firewalled / No Services
- Services: None detected (no open ports)
- Type: Residential/ISP connection
- Route Stability: Unstable (route changes observed)
---
## Threat Assessment
Risk Score: 55/100 (Moderate)
Threat Indicators:
- No known attack campaigns
- Not identified as Tor exit node
- Not flagged as known attacker or spam source
- No active threat indicators in primary feeds
- DNSBL: Listed on 3 of 8 reputation lists
Historical Signals (15 observations):
- Recent signals (2026-07-29) show consistent China geolocation
- AlienVault OTX data indicates threat presence with 3 associated pulse indicators
- RIR registration: APNIC
- Consistent ownership attribution to ChinaUnicom
---
## Relationship Analysis
DNS Associations:
- Hostname: 46.241.51.119.adsl-pool.jlccptt.net.cn
- Reverse DNS: Confirmed (forward resolution not verified)
No Organization or Certificate Relationships Identified
---
## Neighborhood Analysis
Subnet: 119.51.241.46/24
- Abuse Density: 0
- Sibling IPs: 1 identified
- Neighbor Risk: 119.51.241.214 (risk score: 40/100)
- Classification: Low abuse density
---
## Recommended Actions
Monitoring:
- Increase logging verbosity for traffic from this IP
- Review recent activity patterns
- Monitor for any changes in behavior
Firewall Rules (Recommended):
```bash
# iptables
iptables -A INPUT -s 119.51.241.46 -j DROP
# nftables
nft add rule inet filter input ip saddr 119.51.241.46 drop
# nginx
deny 119.51.241.46;
# pfSense
119.51.241.46/32
# Cloudflare WAF
Expression: ip.src eq 119.51.241.46 โ Block
# AWS WAF
Addresses: [119.51.241.46/32] โ Block
```
---
## Intelligence Narrative
IP 119.51.241.46 represents a China Unicom residential connection with moderate risk characteristics. While no active exploitation campaigns or known attacker signatures were identified, the combination of DNSBL listings, route instability, and elevated risk score warrants defensive monitoring. The IP's classification as "firewalled with no services" suggests it may be a passive endpoint rather than an active attacker infrastructure, but the risk classification supports a block policy for inbound traffic.
The neighborhood analysis shows low abuse density in the /24 subnet with a single neighbor IP (119.51.241.214) carrying a moderate risk score of 40. No cluster behavior was observed, indicating this IP may be isolated rather than part of a coordinated threat infrastructure.
Recommendation: Block inbound traffic at perimeter defenses while maintaining outbound monitoring capability. Review correlation with any observed malicious activity patterns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | ChinaUnicom Hostmaster |
| ASN | AS4837 |
| Network Name | UNICOM-JL |
| CIDR Block | 119.48.0.0/13 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 46.241.51.119.adsl-pool.jlccptt.net.cn |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 46.241.51.119.adsl-pool.jlccptt.net.cn |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-24 08:17:54 UTC |
| Last Seen | 2026-08-10 17:28:07 UTC |
| Profile Built | 2026-07-29 22:10:16 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 22 |
Full dossier details are available via our API.