# IP INTELLIGENCE BRIEFING
Target: 119.6.59.233/32
Classification: Mobile Residential Infrastructure
Risk Level: Moderate (Score: 40)
Report Date: 2026-06-17
---
## EXECUTIVE SUMMARY
IP 119.6.59.233 is a mobile-residential address belonging to China Unicom (ASN 4837) with moderate risk scoring. The address shows no active service exposure and is currently firewalled. Historical data indicates consistent operational patterns without escalating threat behavior.
---
## OWNERSHIP AND INFRASTRUCTURE
- ASN: 4837 (UNICOM-SC)
- Organization: Xifei Xie
- Network Block: 119.4.0.0/14
- RIR: APNIC
- Geolocation: P.R. China (Region: 100033)
- Mobile Carrier: China Unicom (MCC 460, MNC 01)
- Connection Technology: LTE/5G
The IP is classified as mobile infrastructure with no residential, proxy, or hosting indicators.
---
## THREAT ASSESSMENT
Current Risk Profile: Moderate (40/100)
Threat Indicators:
- Blacklist Count: 0
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Known Campaigns: None detected
Control Plane Metrics:
- DNSBL Listings: 2 of 8 total lists
- Operator Score: 0.1304 (Minimal)
- Route Stability: Unstable
- BGP Prefix: 119.4.0.0/14
Services: No open ports detected. Services classification: Firewalled/No Services.
---
## NEIGHBORHOOD ANALYSIS
Subnet: 119.6.59.0/24
Abuse Density: 1 (Low)
Classification: Mostly Clean
Total Siblings: 1
Active Siblings: 0
Threat Siblings: 1
The /24 subnet demonstrates low abuse density with minimal inherited risk (Score: 2).
---
## OBSERVATION HISTORY
Total Observations: 18 signals tracked
Most Recent: 2026-06-17 07:13:54 UTC
Key Historical Signals:
- DNSSEC validation confirmed on 2026-06-17
- Operator score variations observed (0.1304โ0.30)
- No persistent malicious behavior detected
- Threat observation count: 1
The IP shows stable operational characteristics without escalating threat patterns over the observation period.
---
## RELATIONSHIP GRAPH
Connected Entities: 15 relationships identified
All relationships map to the UNICOM-SC network infrastructure, indicating consistent network-level association. No external organizational or hostname relationships detected beyond the primary network affiliation.
---
## RECOMMENDED ACTIONS
Firewall/Security Recommendations:
- No immediate blocking required
- Monitor for service activation on previously firewalled ports
- Track for any changes in network role classification
- Consider geolocation-based filtering if policy requires
Threat Hunting: No active threat indicators present. Standard monitoring procedures apply.
---
Analyst Notes: This IP represents legitimate mobile infrastructure from China Unicom with moderate risk scoring primarily due to DNSBL associations. No active malicious behavior detected. The address shows consistent operational patterns without evidence of abuse campaigns or threat actor activity.
Confidence Level: High
Data Sources: IPDebrief Intelligence Platform
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Xifei Xie |
| ASN | AS4837 |
| Network Name | UNICOM-SC |
| CIDR Block | 119.4.0.0/14 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 24% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 21% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:34 UTC |
| Last Seen | 2026-06-22 11:13:52 UTC |
| Profile Built | 2026-06-22 11:20:13 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 20 |
Full dossier details are available via our API.