IP Intelligence Briefing: 121.26.29.66/32
*Generated via IPDebrief tools: Profile, History, Relationships, Neighbors*
---
**1. Core Profile**
- Risk Score: 70 (High Risk)
- Ownership: ChinaUnicom Hostmaster (ASN 4837, APNIC)
- Geolocation: China (CN), mobile LTE/5G, no specific city/region.
- Network Role: Mobile infrastructure (not residential, not cloud/CDN).
- Threat Indicators: No direct malicious activity (no malware, phishing, or known attacker labels).
---
**2. Observation History**
- Last 30 Days:
- 16 observations, including DNS, geolocation, and network metadata.
- DNS: No PTR records or domain resolution.
- Geolocation: Consistent China origin (MaxMind).
- Network: Linked to ChinaUnicomβs backbone (121.24.0.0/14).
- DNSBL: Listed in 4/8 DNSBLs (potential spam or abuse risk).
---
**3. Relationships**
- Network: Part of UNICOM-HE (ChinaUnicomβs network).
- Subnet: 121.26.29.0/24, linked to ChinaUnicomβs infrastructure.
- No External Hostnames/Certificates: No DNS or TLS records tied to this IP.
---
**4. Subnet Analysis**
- Subnet: 121.26.29.0/24
- Abuse Density: 0% (clean subnet).
- Neighbors: No active IPs in the subnet (0 siblings).
---
**5. Actionable Insights**
- Monitor for Anomalies: Despite low abuse density, the IPβs DNSBL listings and mobile network association warrant closer scrutiny.
- Check for Traffic Patterns: Investigate if this IP is involved in data exfiltration or unusual traffic flows.
- Network Segmentation: Ensure mobile infrastructure is isolated from internal systems.
- Provider Collaboration: Engage ChinaUnicom for further details on network activity.
---
Conclusion: This IP is part of ChinaUnicomβs mobile network and shows no direct malicious activity. However, its DNSBL listings and lack of DNS resolution suggest potential misuse. SOC teams should monitor for lateral movement or unexpected traffic.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | ChinaUnicom Hostmaster |
| ASN | AS4837 |
| Network Name | β |
| CIDR Block | β |
| RIR | APNIC |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 19% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 27% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 19% | 2 | 2 |
| Overall | 17% | 9 | 11 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-11 15:03:54 UTC |
| Last Seen | 2026-06-26 09:54:20 UTC |
| Profile Built | 2026-06-26 09:59:25 UTC |
| Data Freshness | Live |
| Signal Types | 14 |
| Total Observations | 16 |
Full dossier details are available via our API.