# IP INTELLIGENCE BRIEFING
Target IP: 123.245.85.221/32
Classification: Residential Mobile Endpoint
Report Date: 2026-07-30
Analyst: IPDebrief Intelligence Team
---
## EXECUTIVE SUMMARY
IP 123.245.85.221 is a residential mobile endpoint associated with China Telecom's Liaoning branch (ASN 4134). The IP carries a low risk score of 25 and no active threat indicators. No malicious activity, blacklisting, or known campaign associations were detected. The address operates within a benign residential subnet with minimal neighborhood abuse density.
---
## NETWORK OWNERSHIP & GEOLOCATION
| Attribute | Value |
|---|---|
| **ASN** | 4134 (CHINANET-LN) |
| **Organization** | China Telecom Corp. Ltd. |
| **Location** | Heping, Liaoning Province, China (CN) |
| **Coordinates** | 40.82°N, 124.2°E |
| **CIDR Block** | 123.245.64.0/19 |
| **Network Name** | JunQu2 |
The IP is classified as a residential mobile endpoint on China Telecom's LTE/5G network (MCC: 460, MNC: 03).
---
## RISK ASSESSMENT
| Metric | Score | Assessment |
|---|---|---|
| Overall Risk | 25 | Low Risk |
| Provider Score | 0 | Neutral |
| Authority Score | 0 | Neutral |
| Stability Score | 0 | N/A |
| Abuse Confidence | N/A | Not Applicable |
| DNSBL Listed | 1/8 | Minor |
| Operator Score | 0.1304 | Minimal |
Threat Indicators:
- No known attacker designation
- No Tor/VPN/Proxy classification
- No CDN or hosting infrastructure
- No active spam source indicators
- No associated threat campaigns
---
## OBSERVATION HISTORY (12 RECORDS)
Recent observations from 2026-07-30 indicate:
- Consistent geolocation attribution to China (CN)
- ASN 4134 (chinanet) confirmed
- Residential infrastructure classification maintained
- Traceroute attempts (30 hops) with target reachability pending
- Port scanning activity detected
- No persistent malicious behavior observed
---
## NEIGHBORHOOD ANALYSIS
Subnet: 123.245.85.221/24
Total Neighbors: 49 IPs
Abuse Density: 0 (Minimal)
Risk Distribution: 48 Low Risk, 0 Medium Risk, 0 High Risk
The /24 subnet shows predominantly benign activity with no high-risk neighbors. Several sibling IPs (including 123.245.85.16, 123.245.85.17, 123.245.85.19) share the same risk score of 25, consistent with residential mobile characteristics.
---
## RELATIONSHIP GRAPH
- Same Network: JunQu2 (2 entries)
- No associated hostnames, certificates, or external entities detected
---
## SERVICES & PORTS
- Open Ports: None detected
- TLS Certificate: Not present
- HTTP Title: Not detected
- DNS Resolution: Not confirmed
- Email Authentication: No SPF/DMARC records
---
## RECOMMENDED ACTIONS
Given the low-risk classification and residential/mobile nature, the following posture is recommended:
1. Default Allow - No immediate blocking required
2. Monitor - Continue observing for behavioral changes
3. Contextual Review - If this IP appears in malicious activity logs, evaluate against observed traffic patterns
4. No Firewall Rules - No specific iptables/nftables rules generated
---
## SOC ANALYST NOTES
This IP represents a legitimate residential mobile endpoint with no current threat indicators. The low risk score and benign neighborhood profile suggest this address poses minimal threat to network security. If observed in suspicious activity, consider the context of the traffic rather than IP-based blocking alone.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | CHINANET-LN Network Administrater Chinatelecom Liaoning Branch |
| ASN | AS4134 |
| Network Name | JunQu2 |
| CIDR Block | 123.245.64.0/19 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Residential |
| Service Purpose | Residential Endpoint |
| Network Tier | End-User โ Residential ISP endpoint |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 1 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-28 04:02:27 UTC |
| Last Seen | 2026-07-30 15:01:06 UTC |
| Profile Built | 2026-07-30 15:09:37 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.