# IP Intelligence Briefing: 171.80.9.247/32
Date: 2026-07-23
Classification: Low Risk
Risk Score: 25/100
---
## Executive Summary
IP 171.80.9.247 is a low-risk address associated with CHINANET-HB infrastructure in China. The IP exhibits minimal threat characteristics, with no active services detected, no known malicious associations, and a clean neighborhood profile. The address shows only 1 of 8 DNSBL listings and maintains minimal operator score (0.1304).
---
## Ownership and Geolocation
| Attribute | Value |
|---|---|
| **Organization** | Zhengding Cai |
| **Network Name** | CHINANET-HB |
| **ASN** | 151185 |
| **Country** | China (CN) |
| **CIDR Block** | 171.80.0.0/14 |
| **RIR** | APNIC |
| **Abuse Contact** | anti-spam@chinatelecom.cn |
Geolocation: Coordinates 34.77°N, 113.72°E (P.R.China) with consensus validation confirmed across multiple sources.
---
## Network Classification
- Service Purpose: Firewalled / No Services
- Infrastructure Type: No services detected
- Cloud/CDN/Proxy/Vpn: Negative across all categories
- Mobile/Residential: Not applicable
- Bogon/Anycast: Not flagged
---
## Threat Indicators
| Indicator | Status |
|---|---|
| **Known Attacker** | No |
| **Spam Source** | No |
| **Tor Exit Node** | No |
| **Blacklist Count** | 0 |
| **DNSBL Listings** | 1 of 8 |
| **Campaign Associations** | None |
| **Threat Feeds** | Empty |
Abuse Confidence Score: Not calculated (insufficient threat signals)
---
## Services and Ports
- Open Ports: None detected
- TLS Certificate: Not detected
- HTTP Title: Not detected
- DNS Records: No PTR hostnames; forward resolution count: 0
- Email Authentication: SPF/DMARC not configured (no hosted domains)
---
## Control Plane Analysis
| Parameter | Value |
|---|---|
| **Origin ASN** | 151185 |
| **BGP Prefix** | 171.80.0.0/18 |
| **RPKI State** | Not evaluated |
| **IRR Consistency** | Not evaluated |
| **Route Stability** | Not stable (route changes detected) |
| **DNSSEC Valid** | Yes |
| **Operator Score** | 0.1304 (Minimal) |
| **Delegation Age** | Not available |
Traceroute: 30 hops; first/last hop RTT: 0.1ms; 29 timed out hops
---
## Temporal Analysis
| Metric | Value |
|---|---|
| **Ownership Changes** | 0 |
| **Threat Persistence Days** | 0 |
| **Threat Observation Count** | 1 |
| **Persistently Malicious** | No |
| **Honeypot Hits** | 0 |
| **Enumeration Strikes** | 0 |
| **WAF Violations** | 0 |
---
## Observation History (41 Total Observations)
Recent Activity (2026-07-23):
- Geolocation: China (CN) confirmed with 0.52 confidence; inferred coordinates 35.86°N, 104.2°E
- Organization: Zhengding Cai/APNIC registration confirmed (0.90 confidence)
- Network Details: CHINANET-HB / 171.80.0.0/14 confirmed (0.95 confidence)
- Blacklist Activity: 1 of 8 listings detected (high severity flag)
- Operator Score: Minimal (0.1304)
Risk Trend: Stable; no significant escalation observed. Only 1 threat observation recorded in history.
---
## Relationship Graph
| Relationship | Target |
|---|---|
| **Same Network** | CHINANET-HB |
No additional relationships detected (no associated hostnames, organizations, or certificates).
---
## Neighborhood Analysis (171.80.9.0/24)
| Metric | Value |
|---|---|
| **Total Siblings** | 4 |
| **Active Siblings** | 0 |
| **Threat Siblings** | 0 |
| **Abuse Density** | 0 |
| **High Risk Neighbors** | 0 |
| **Medium Risk Neighbors** | 0 |
| **Low Risk Neighbors** | 3 |
Neighbor Risk Scores:
- 171.80.9.94: 25 (Low)
- 171.80.9.113: 25 (Low)
- 171.80.9.211: 25 (Low)
- 171.80.9.245: Not evaluated
---
## Recommended Actions
Based on the low-risk profile, the following actions are recommended:
1. Allow Traffic: No blocking required; IP shows minimal threat indicators
2. Monitor DNSBL Status: One of eight DNSBL listings detected; continue monitoring for changes
3. Standard Logging: Apply standard network logging practices
4. No Immediate Mitigation: No firewall rules or WAF policies required
---
## Intelligence Assessment
The IP 171.80.9.247 presents minimal security concerns. The address belongs to a Chinese telecommunications infrastructure network with no active services exposed. The single DNSBL listing appears to be a false positive or non-malicious listing based on the overall low-risk profile. No threat campaigns, known attacker associations, or persistent malicious behavior were observed.
Threat Level: LOW
Action Required: Standard monitoring; no immediate mitigation needed.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | IRT-CHINANET-CN |
| ASN | AS151185 |
| Network Name | CHINANET-HB |
| CIDR Block | 171.80.0.0/14 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS151185 |
| Network Prefix | 171.80.0.0/18 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 17% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 17% | 2 | 3 |
| reputation | 16% | 1 | 3 |
| geolocation | 20% | 2 | 3 |
| Overall | 15% | 9 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-04 17:23:50 UTC |
| Last Seen | 2026-08-27 07:07:45 UTC |
| Profile Built | 2026-08-29 05:23:06 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 18 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 171.80.9.247
Who owns the IP address 171.80.9.247?
171.80.9.247 is registered to IRT-CHINANET-CN. The address falls within the 171.80.0.0/14 network block. Registration is held at APNIC.
Where is 171.80.9.247 located?
Geolocation data places 171.80.9.247 in P.R.China. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 171.80.9.247 malicious or safe?
171.80.9.247 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.