## IP Intelligence Briefing: 120.52.92.90/32
Classification: Low Risk
Date: Intelligence compiled from 2026-07-26
Risk Score: 25/100
---
EXECUTIVE SUMMARY
IP address 120.52.92.90 is classified as low risk with an overall risk score of 25. The address belongs to organization Xin Xing (AS133119) within the CU-CDC network block (120.52.0.0/16) under APNIC RIR. Current observations indicate no active threat activity, no open services, and no malicious indicators detected.
---
OWNERSHIP AND NETWORK CLASSIFICATION
| Attribute | Value |
|---|---|
| ASN | 133119 |
| Organization | Xin Xing |
| Network Name | CU-CDC |
| CIDR Block | 120.52.0.0/16 |
| Country | CN (China) |
| RIR | APNIC |
| Abuse Contact | xingxin2@chinaunicom.cn |
| Network Classification | Firewalled / No Services |
The IP address is not classified as cloud infrastructure, CDN, proxy, Tor exit node, VPN, hosting provider, mobile carrier, or residential IP.
---
THREAT INDICATORS ASSESSMENT
Current Threat Status: No Active Threat Indicators
- Blacklist Count: 0
- Pulsedive Risk: Not applicable
- Tor Exit Node: False
- Known Attacker: False
- Spam Source: False
- Abuse Confidence Score: Not applicable
- Associated Campaigns: None
The IP shows 0 honeypot hits, 0 enumeration strikes, 0 WAF violations, and 0 total incidents. No known threat campaigns or correlated IPs identified.
---
NETWORK SERVICES AND PORTS
Service Status: No Open Ports Detected
- Open Ports: [] (None)
- TLS Certificate: Not present
- HTTP Title: Not detected
- Server Banner: Not detected
- Certificate Authority: None
The IP is in a firewalled state with no accessible services. This classification is consistent with backend infrastructure or non-public-facing systems.
---
DNS AND EMAIL REPUTATION
DNS Status: Limited Resolution Data
- PTR Hostnames: None
- Forward Resolution: Not confirmed
- Hosted Domains: 0
- SPF Record: Not detected
- DMARC Record: Not detected
- TXT Record Count: 0
- DNSBL Listed: 1 of 8 total lists
Email Reputation: Not applicable (no domain-based email services)
---
CONTROL PLANE AND ROUTING
| Metric | Value |
|---|---|
| BGP Prefix | 120.52.0.0/17 |
| Route Stability | False (isRouteStable) |
| Route Changes (30d) | 0 |
| RPKI State | Not available |
| IRR Consistency | Not available |
| DNSSEC Valid | True |
| DNSBL Total Lists | 8 |
The routing prefix shows instability over the observation period, though no route changes were recorded in the past 30 days.
---
OBSERVATION HISTORY (13 Signals)
Recent observations (2026-07-26) confirm consistent classification:
- Geolocation: China (CN) - 52% confidence
- Network Classification: Multiple non-threatening categories verified
- Ownership Data: ASN and organization confirmed at 90-95% confidence
- Service Detection: Ports scanned with no active services
- Temporal Persistence: 0 threat persistence days, 0 threat observation count
The IP has demonstrated stable ownership with no changes recorded. No persistent malicious behavior has been observed.
---
NEIGHBORHOOD ANALYSIS (120.52.92.0/24)
Subnet Overview:
- Total Siblings: 18
- Active Siblings: Not quantified
- Threat Siblings: 0
- Abuse Density: 0
- Subnet Classification: Not classified
Risk Distribution:
- High Risk: 0 IPs
- Medium Risk: 3 IPs
- Low Risk: 13 IPs
Notable Neighbors:
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 120.52.92.99 | 50 | 50 |
| 120.52.92.118 | 55 | 50 |
| 120.52.92.136 | 50 | 50 |
| 120.52.92.18 | 25 | 50 |
| 120.52.92.51 | 25 | 50 |
| 120.52.92.237 | 25 | 50 |
The /24 subnet shows minimal abuse activity with a low overall abuse density of 0.
---
NETWORK RELATIONSHIPS
| Relationship Type | Target |
|---|---|
| Same Network | CU-CDC |
| Same Network | CU-CDC |
Two relationships detected, both indicating membership in the CU-CDC network.
---
RECOMMENDED ACTIONS
Current Firewall Policy:
- Recommendation: Monitor but no immediate blocking required
- Confidence Level: Low risk classification supports continued monitoring
- Rule Priority: Standard network baseline
Justification: The IP shows no active malicious indicators, no open services, and belongs to a low-abuse-density subnet. The firewalled state with no accessible services suggests legitimate backend infrastructure or non-public-facing systems.
---
SOC ANALYST NOTES
1. No Immediate Action Required: Risk score of 25 with no threat indicators supports maintaining current security posture.
2. Subnet Context: The /24 neighborhood shows minimal abuse activity (abuse density: 0), supporting the low-risk classification.
3. Monitoring Recommendation: Continue standard monitoring. The IP is firewalled with no active services, reducing immediate threat exposure.
4. Geolocation: China-based origin (CN) with 52% confidence from multi-signal inference.
5. Temporal Analysis: No ownership changes or persistent malicious behavior observed across 13 observation signals.
---
Report Generated: 2026-07-26
Data Sources: IPDebrief Intelligence Platform
Analysis Status: Complete
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Xin Xing |
| ASN | AS133119 |
| Network Name | CU-CDC |
| CIDR Block | 120.52.0.0/16 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS133119 |
| Network Prefix | 120.52.0.0/17 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 5 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 17% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 17% | 2 | 3 |
| Overall | 17% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-11 14:29:45 UTC |
| Last Seen | 2026-09-05 18:25:48 UTC |
| Profile Built | 2026-09-05 19:03:32 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 26 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 120.52.92.90
Who owns the IP address 120.52.92.90?
120.52.92.90 is registered to Xin Xing. The address falls within the 120.52.0.0/16 network block. Registration is held at APNIC.
Where is 120.52.92.90 located?
Geolocation data places 120.52.92.90 in China. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 120.52.92.90 malicious or safe?
120.52.92.90 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.