# IP Intelligence Briefing: 120.52.92.118/32
## Executive Summary
IP address 120.52.92.118 presents moderate risk (Score: 55) with no active services detected. The IP belongs to Xin Xing (ASN 133119) within the CU-CDC network block (120.52.0.0/16) in China. No active threat indicators or campaign affiliations observed.
---
## Network Ownership & Classification
| Attribute | Value |
|---|---|
| ASN | 133119 |
| Organization | Xin Xing |
| Network Name | CU-CDC |
| CIDR Block | 120.52.0.0/16 |
| RIR | APNIC |
| Abuse Contact | xingxin2@chinaunicom.cn |
Classification:
- Service Purpose: Firewalled / No Services
- Provider/Infrastructure Type: Not classified as CDN, cloud, proxy, VPN, or hosting
- Not a known Tor exit node or residential IP
---
## Risk Assessment
Overall Risk Score: 55 (Moderate Risk)
Control Plane Indicators:
- BGP Prefix: 120.52.0.0/17
- Route Stability: Unstable
- DNSSEC Valid: Yes
- DNSBL Listings: 3 out of 8 total lists
- Operator Score: 0.1304 (Minimal)
Threat Indicators:
- Active Attacker: No
- Known Campaign: No
- Spam Source: No
- Blacklist Count: 0
- Pulsedive Risk: Not applicable
---
## Geolocation Data
| Attribute | Value |
|---|---|
| Country | China (CN) |
| Region | Not specified |
| Coordinates | 35.86°N, 104.2°E |
| Accuracy Radius | 2,500 km |
| Geo Confidence | 0.52 (Medium) |
| Geo Validation | Not Plausible |
---
## Network Services & DNS
Open Ports: None detected
TLS Certificates: None
HTTP Services: None
PTR Resolution: None
Forward Resolution: None
Email Authentication: SPF/DMARC not configured
---
## Observation History Analysis
13 observations recorded. Key temporal patterns:
- Most Recent (2026-07-26): Multi-signal inference confirmed Chinese geolocation with medium confidence (0.52)
- Ownership Signals: APNIC registry assignment confirmed with high confidence (0.90-0.95)
- Service Scans: Ports scanned with no open services detected
- Stability: No ownership changes, zero threat persistence days
- Behavioral: No honeypot hits, no enumeration strikes, no WAF violations
The IP demonstrates stable ownership characteristics with no persistent malicious activity patterns.
---
## Relationship Graph
Two relationships identified:
- Same Network: CU-CDC (network-level association)
No cross-entity links to hostnames, organizations, or certificates detected.
---
## Neighborhood Analysis (120.52.92.0/24)
Subnet Summary:
- Total Neighbors: 18
- Abuse Density: 0
- Risk Distribution: 0 High, 2 Medium, 14 Low
Notable Risk Neighbors:
| IP | Risk Score | Authority Score |
|---|---|---|
| 120.52.92.99 | 50 | 50 |
| 120.52.92.136 | 50 | 50 |
| 120.52.92.18 | 25 | 50 |
| 120.52.92.51 | 25 | 50 |
| 120.52.92.90 | 25 | 50 |
| 120.52.92.237 | 25 | 50 |
Subnet-level abuse density remains low (0), indicating the target IP is not part of a broadly compromised subnet.
---
## Recommended Actions
Monitoring:
- Monitor for service activation (ports opening)
- Track DNSBL listing changes
- Watch for geolocation inconsistencies
Blocking Decision:
- Current risk profile does not warrant immediate blocking
- Medium risk score (55) without active threat indicators suggests allow-listing with monitoring
Firewall Rules:
- No specific block rules recommended at this time
- Consider logging all traffic for baseline establishment
- Add to watchlist if service banners appear
---
## Threat Intelligence Conclusion
120.52.92.118 is a Chinese-origin IP (ASN 133119/Xin Xing) presenting moderate risk with no active malicious indicators. The IP is firewalled with no open services, suggesting legitimate infrastructure use. No correlation to known attack campaigns or threat actor infrastructure. Neighborhood analysis confirms low subnet-level abuse density. Recommendation: Monitor with standard logging; no immediate defensive action required.
---
*Report Generated: IPDebrief Intelligence Analysis Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Xin Xing |
| ASN | AS133119 |
| Network Name | CU-CDC |
| CIDR Block | 120.52.0.0/16 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS133119 |
| Network Prefix | 120.52.0.0/17 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 6 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 23% | 2 | 4 |
| reputation | 35% | 1 | 5 |
| geolocation | 17% | 2 | 3 |
| Overall | 22% | 10 | 21 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-11 14:29:45 UTC |
| Last Seen | 2026-09-03 16:58:16 UTC |
| Profile Built | 2026-09-03 17:02:12 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 28 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 120.52.92.118
Who owns the IP address 120.52.92.118?
120.52.92.118 is registered to Xin Xing. The address falls within the 120.52.0.0/16 network block. Registration is held at APNIC.
Where is 120.52.92.118 located?
Geolocation data places 120.52.92.118 in China. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 120.52.92.118 malicious or safe?
120.52.92.118 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.