# IP Intelligence Briefing: 123.139.117.65/32
## Executive Summary
The IP address 123.139.117.65 is assessed as Low Risk with a risk score of 25/100. The address shows no malicious indicators, no open services, and is located in China. No threat activity or suspicious behavior has been observed in the monitoring history.
## Network Profile
- IP Address: 123.139.117.65/32
- Geolocation: China, Shaanxi Province, Xi'an City
- Origin ASN: 4837
- BGP Prefix: 123.138.0.0/15
- Network Classification: Firewalled / No Services
- Infrastructure Type: Not Cloud, CDN, VPN, Proxy, Hosting, Mobile, or Residential
- DNS Resolution: No forward resolution available; no PTR records
- Email Authentication: No SPF or DMARC records configured
## Threat Indicators
- Abuse Confidence: None detected
- Known Attacker Status: False
- Spam Source: False
- Tor Exit Node: False
- Blacklist Status: Listed on 1 of 8 DNSBL checks
- Known Campaigns: None associated
- Threat Feeds: No detections
## Network Activity
- Open Ports: None detected
- TLS Certificate: Not configured
- HTTP Title: Not detected
- Server Banner: None observed
- Certificate Authorities: None found
## Control Plane Assessment
- Route Stability: Unstable
- DNSSEC Validation: Valid
- DNSBL Listings: 1 of 8 total lists
- Operator Score: 0.1304 (Minimal)
- Route Changes (30-day): 0
- IRR Consistency: Not verified
## Neighborhood Analysis (123.139.117.0/24)
- Abuse Density: 0
- Subnet Classification: Clean
- Total Sibling IPs: 1
- Active Siblings: 0
- Threat Siblings: 0
- Risk Distribution: No high, medium, or risk flagged siblings
## Historical Observations
Ten historical observations recorded from 2026-07-30:
- Geolocation Signals: Consistent reporting from China (Xi'an)
- Subnet Classification: Continuously classified as clean
- Operator Assessment: Stable minimal risk profile
- Threat Persistence: 0 days observed
- Ownership Changes: None detected
- Average Observation Confidence: 0.35 (medium confidence)
## Relationships
No linked entities identified:
- No associated subnets
- No linked hostnames
- No connected organizations
- No certificate associations
## Recommended Security Actions
Based on the low-risk profile and lack of malicious indicators, no immediate firewall rules or blocking actions are recommended. The IP does not meet thresholds for automated takedown or blocking.
## Intelligence Narrative
IP 123.139.117.65 presents a benign network posture. The address is geolocated to Xi'an, China and operates under ASN 4837. Network analysis confirms no active services, no open ports, and no evidence of compromise or malicious activity. The subnet demonstrates minimal abuse density with no correlated threat indicators from neighboring addresses. Historical observations show consistent, stable characteristics with no escalation in risk profile over the monitoring period. The single DNSBL listing appears to be a routine classification rather than a malicious indicator. SOC analysts should monitor for changes in service status or geolocation shifts, but current risk assessment supports passive monitoring without intervention.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | CNCGroup-SN Hostmaster |
| ASN | AS4837 |
| Network Name | PPPoe |
| CIDR Block | 123.139.117.0/24 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-29 10:33:19 UTC |
| Last Seen | 2026-07-30 23:19:46 UTC |
| Profile Built | 2026-07-30 20:57:59 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 16 |
Full dossier details are available via our API.