# IPDebrief Intelligence Briefing
Target: 14.155.244.253/32
Date: 2026-07-29
Risk Level: Moderate Risk (Score: 55/100)
## Executive Summary
IP 14.155.244.253 is a mobile carrier address associated with China Telecom operating within the CHINANET-GD network infrastructure. The address exhibits moderate risk characteristics with elevated logging recommended but no active threat indicators observed.
## Network Classification & Ownership
- ASN: 4134 (IPMASTER CHINANET-GD)
- Organization: CHINANET-GD (APNIC RIR)
- CIDR Block: 14.144.0.0/12
- Geolocation: Shenzhen, Guangdong Province, China
- Mobile Carrier: China Telecom Corp. Ltd. (MCC: 460, MNC: 03)
- Connection Type: LTE/5G Mobile Network
- Infrastructure Type: Mobile/Carrier Network
## Risk Profile
- Overall Risk Score: 55/100 (Moderate Risk)
- Abuse Confidence: No active threat indicators
- Known Attacker Status: Not flagged
- Spam Source: Not flagged
- Tor Exit Node: No
- Proxy/VPN: No
- DNSBL Listings: 3 of 8 total lists
- Network Classification: Firewalled / No Services
- Route Stability: Unstable (route changes detected)
## Historical Observations
Fourteen signal observations recorded. Key findings include:
- Geolocation Signals: Multiple geolocation probes confirmed China/China (Shenzhen, Guangdong) with confidence levels 0.30-0.85
- Network Classification: Consistent mobile carrier classification across observations
- Ownership: Zero ownership changes detected; network assignment stable
- Threat Persistence: No persistent malicious behavior observed
- Scanning Activity: Multiple port scanning events detected
## Relationship Analysis
- Network Associations: CHINANET-GD (same network)
- Hostname Relationships: None detected
- Certificate Relationships: None detected
- Correlated Entities: Limited relationship graph
## Neighborhood Analysis
Subnet 14.155.244.0/24 contains 3 additional sibling IPs:
| IP Address | Risk Score | Authority Score | Classification |
|---|---|---|---|
| 14.155.244.118 | 25 | 50 | Low |
| 14.155.244.150 | 0 | 50 | Low |
| 14.155.244.152 | 30 | 50 | Low |
- Subnet Abuse Density: 0
- Active Threat Siblings: 0
- Overall Neighborhood Risk: Low to Moderate
## Recommended Actions
Immediate Monitoring
- Increase logging verbosity for traffic from 14.155.244.253
- Review recent activity patterns for anomalous behavior
- Monitor for changes in service patterns or port activity
Firewall Rules
iptables:
```
iptables -A INPUT -s 14.155.244.253 -j DROP
```
nftables:
```
nft add rule inet filter input ip saddr 14.155.244.253 drop
```
nginx:
```
deny 14.155.244.253;
```
pfSense:
```
14.155.244.253/32
```
Cloudflare WAF:
```json
{
"description": "Block 14.155.244.253 โ IPDebrief risk score 55",
"action": "block",
"filter": {"expression": "ip.src eq 14.155.244.253"}
}
```
AWS WAF:
```json
{
"Addresses": ["14.155.244.253/32"],
"Description": "IPDebrief risk 55"
}
```
## Intelligence Assessment
The IP address belongs to legitimate China Telecom mobile infrastructure with no confirmed malicious activity. The moderate risk score (55) is primarily driven by DNSBL listings and route instability rather than active threat indicators. SOC analysts should treat this as a monitoring priority rather than an immediate threat, with emphasis on behavioral analysis rather than hard blocking. The mobile carrier classification and geolocation consistency suggest legitimate network traffic patterns typical of China Telecom's LTE/5G infrastructure.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IPMASTER CHINANET-GD |
| ASN | AS4134 |
| Network Name | CHINANET-GD |
| CIDR Block | 14.144.0.0/12 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-21 19:02:47 UTC |
| Last Seen | 2026-07-29 10:10:30 UTC |
| Profile Built | 2026-07-29 10:18:31 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.