# IP Intelligence Briefing: 125.73.32.184/32
Classification: Mobile Infrastructure / Low Risk
Date: 2026-07-29
Analyst: IPDebrief Intelligence Team
---
## Executive Summary
IP address 125.73.32.184 is a Chinese mobile network endpoint operated by China Telecom (ASN 4134) within the CHINANET-GX network block. Current risk assessment indicates low threat profile (risk score: 25/100). No active malicious indicators, blacklists, or known campaign associations were detected. The IP is classified as mobile infrastructure with firewalled/no service activity.
---
## Ownership & Network Context
| Attribute | Value |
|---|---|
| **ASN** | 4134 |
| **Organization** | Chinanet Hostmaster |
| **Network** | CHINANET-GX (125.73.0.0/16) |
| **ISP** | China Telecom Corp. Ltd. |
| **Country** | China (CN) |
| **Connection Type** | LTE/5G Mobile |
| **Mobile Carrier** | China Telecom (MCC: 460, MNC: 03) |
Geolocation: Country-level precision indicates China. Geo-validation attempted but ICMP blocked; distance from observation point: 8,033 km.
---
## Risk Assessment
- Overall Risk Score: 25 (Low Risk)
- Abuse Confidence: Not applicable
- Blacklist Status: Clean (0 lists)
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
Mobile Classification: Confirmed mobile endpoint (not residential, cloud, CDN, VPN, proxy, hosting, or anycast).
---
## Threat Indicators
- Active Threat Indicators: None detected
- Known Campaigns: None
- Threat Feeds: Empty
- DNSBL Listings: 1 of 8 (minimal impact)
Temporal Analysis: No threat persistence days recorded. IP not flagged as persistently malicious. No ownership changes observed.
---
## Network Neighborhood Analysis
Subnet: 125.73.32.0/24
Abuse Density: 0 (clean)
Neighbor Count: 2
| Neighbor IP | Risk Score | Authority Score |
|---|---|---|
| 125.73.32.153 | 25 | 50 |
| 125.73.32.179 | 50 | 50 |
Assessment: Subnet shows mixed risk profile with one medium-risk neighbor (50). Target IP (184) maintains low-risk profile consistent with mobile infrastructure classification.
---
## Relationship Graph
Direct Relationships: 4
All targets: CHINANET-GX (same network block)
External associations: None detected
The IP shows only internal network relationships to the CHINANET-GX block with no connections to external organizations, hostnames, or certificates.
---
## Service & DNS Status
- Open Ports: None detected
- DNS Resolution: No PTR records, no forward resolution
- Hosted Domains: 0
- Email Authentication: No SPF/DMARC records
- HTTP/TLS: No services responding
---
## Historical Observations (15 signals)
Recent observations confirm:
- Subnet classification: Clean (abuse density: 0)
- Active siblings: 1 out of 3
- Threat siblings: 0
- Geo inference: China (52% confidence)
- ICMP validation: Blocked
- No ownership or threat persistence signals
---
## Recommended Actions
No immediate action required. The IP presents a low-risk profile consistent with legitimate mobile infrastructure. No firewall rules or blocking recommendations generated.
Monitoring Considerations:
- Monitor for service activation (open ports)
- Track neighborhood risk changes in 125.73.32.0/24
- Verify mobile carrier activity patterns
---
## Intelligence Narrative for SOC
This IP represents benign mobile network infrastructure within China Telecom's CHINANET-GX block. The low risk score (25) reflects no malicious activity, blacklist associations, or threat indicators. Mobile classification combined with clean neighborhood analysis and no service exposure indicates this IP is not actively exploited. No immediate defensive action recommended. Maintain awareness of neighborhood risk changes and monitor for service activation patterns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Chinanet Hostmaster |
| ASN | AS4134 |
| Network Name | CHINANET-GX |
| CIDR Block | 125.73.0.0/16 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-23 07:48:13 UTC |
| Last Seen | 2026-07-29 17:01:08 UTC |
| Profile Built | 2026-07-29 17:17:02 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.