# IP Intelligence Briefing: 124.115.65.246
Classification: MODERATE RISK
Date: Intelligence compiled from multiple sources
Analyst: IPDebrief Intelligence Team
---
## Executive Summary
IP 124.115.65.246 presents a moderate risk profile (Risk Score: 55/100) associated with China Telecom mobile infrastructure. The IP is classified as mobile network traffic with no active services or open ports. Geographic signals consistently indicate China (Shanxi Province, Xi'an City), though ICMP validation is blocked. The subnet exhibits clean neighborhood characteristics with minimal abuse density.
---
## Ownership and Network Classification
| Attribute | Value |
|---|---|
| ASN | 4134 (CHINANET Hostmaster) |
| Organization | CHINANET-SN |
| CIDR Block | 124.114.0.0/15 |
| RIR | APNIC |
| IP Classification | Mobile (China Telecom LTE/5G) |
| Service Status | Firewalled / No Services |
The IP belongs to China Telecom's mobile network infrastructure (MCC: 460, MNC: 03), operating under the CHINANET backbone. No hosting, CDN, proxy, or VPN indicators detected.
---
## Geolocation Data
| Field | Value |
|---|---|
| Country | China (CN) |
| Region | Shanxi Province |
| City | Xi'an City |
| Coordinates | 34.77°N, 113.72°E |
| Timezone | Asia/Shanghai |
| Distance from Probe | 8,033.2 km |
| GeoValidation | ICMP blocked - unable to validate |
---
## Threat Intelligence Assessment
Risk Indicators:
- Abuse Confidence Score: Not available
- Blacklist Count: 0
- DNSBL Listings: 3 of 8 total lists
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Known Campaigns: None identified
Network Role Indicators:
- Infrastructure Type: Not classified
- Connection Type: Not classified
- Cloud Provider: No
- CDN: No
- Hosting Provider: No
- Mobile Network: Yes
---
## Control Plane Analysis
- BGP Prefix: 124.115.0.0/16
- Origin ASN: 4134
- RPKI State: Not verified
- IRR Consistency: Not verified
- Route Changes (30d): 0
- Route Stability: False
- MOAS Status: No
- DNSSEC Valid: Yes
- Operator Score: 0.1304 (Minimal)
- Delegation Age: Not available
---
## Observation History (16 Total Signals)
Recent observations (July 29, 2026) show:
- Geolocation: China (CN) with 52% confidence
- Network Scans: Ports scanned, no services detected
- Ownership: 0 changes observed
- Persistence: Not persistently malicious
- Subnet Analysis: Clean classification with 0 abuse density
The IP has exhibited consistent geographic signals from China with no escalation in threat indicators over the observation window.
---
## Neighborhood Analysis (124.115.65.0/24)
| Metric | Value |
|---|---|
| Total Siblings | 7 |
| Active Siblings | 3 |
| Threat Siblings | 0 |
| Abuse Density | 0 (Clean) |
| Overall Classification | Clean |
Neighbor Risk Distribution:
- High Risk (55+): 0
- Medium Risk (30-54): 4
- Low Risk (<30): 2
Notable neighbor: 124.115.65.174 (Risk Score: 55) shares similar risk characteristics.
---
## Relationships
Three relationships identified, all associated with CHINANET-SN network infrastructure. No connections to external hostnames, domains, organizations, or certificates.
---
## Technical Evidence
- Open Ports: None detected
- TLS Certificate: Not available
- HTTP Title: Not available
- PTR Hostnames: None
- Forward Resolution: Not confirmed
- Email Auth: No SPF/DMARC records (no hosted domain)
---
## Recommended Security Actions
Based on the moderate risk profile and mobile infrastructure classification:
1. Allow with Monitoring: Permitted for mobile network traffic patterns
2. Geographic Filtering: Consider allowing from China (CN) if business requires
3. Traffic Inspection: Monitor for unusual patterns given mobile carrier association
4. No Immediate Blocking: No active threat indicators warrant immediate block
Firewall Rule Example:
```
# Allow mobile network traffic with logging
iptables -A INPUT -s 124.115.65.246/32 -j LOG --log-prefix "MOBILE_IP:"
iptables -A INPUT -s 124.115.65.246/32 -j ACCEPT
```
---
## Threat Context
The IP does not show active malicious behavior, campaign associations, or persistent threat characteristics. The moderate risk score derives from:
- DNSBL listings (3/8)
- Control plane indicators
- Mobile network classification
No evidence of scanning, exploitation, or attack campaigns observed.
---
End of Briefing
*Generated by IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Chinanet Hostmaster |
| ASN | AS4134 |
| Network Name | CHINANET-SN |
| CIDR Block | 124.114.0.0/15 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-24 02:12:56 UTC |
| Last Seen | 2026-07-29 20:57:24 UTC |
| Profile Built | 2026-07-29 21:07:23 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.