IPDebrief

171.80.9.247

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 171.80.9.247/32

Date: 2026-07-23

Classification: Low Risk

Risk Score: 25/100

---

## Executive Summary

IP 171.80.9.247 is a low-risk address associated with CHINANET-HB infrastructure in China. The IP exhibits minimal threat characteristics, with no active services detected, no known malicious associations, and a clean neighborhood profile. The address shows only 1 of 8 DNSBL listings and maintains minimal operator score (0.1304).

---

## Ownership and Geolocation

AttributeValue
**Organization**Zhengding Cai
**Network Name**CHINANET-HB
**ASN**151185
**Country**China (CN)
**CIDR Block**171.80.0.0/14
**RIR**APNIC
**Abuse Contact**anti-spam@chinatelecom.cn

Geolocation: Coordinates 34.77°N, 113.72°E (P.R.China) with consensus validation confirmed across multiple sources.

---

## Network Classification

---

## Threat Indicators

IndicatorStatus
**Known Attacker**No
**Spam Source**No
**Tor Exit Node**No
**Blacklist Count**0
**DNSBL Listings**1 of 8
**Campaign Associations**None
**Threat Feeds**Empty

Abuse Confidence Score: Not calculated (insufficient threat signals)

---

## Services and Ports

---

## Control Plane Analysis

ParameterValue
**Origin ASN**151185
**BGP Prefix**171.80.0.0/18
**RPKI State**Not evaluated
**IRR Consistency**Not evaluated
**Route Stability**Not stable (route changes detected)
**DNSSEC Valid**Yes
**Operator Score**0.1304 (Minimal)
**Delegation Age**Not available

Traceroute: 30 hops; first/last hop RTT: 0.1ms; 29 timed out hops

---

## Temporal Analysis

MetricValue
**Ownership Changes**0
**Threat Persistence Days**0
**Threat Observation Count**1
**Persistently Malicious**No
**Honeypot Hits**0
**Enumeration Strikes**0
**WAF Violations**0

---

## Observation History (41 Total Observations)

Recent Activity (2026-07-23):

Risk Trend: Stable; no significant escalation observed. Only 1 threat observation recorded in history.

---

## Relationship Graph

RelationshipTarget
**Same Network**CHINANET-HB

No additional relationships detected (no associated hostnames, organizations, or certificates).

---

## Neighborhood Analysis (171.80.9.0/24)

MetricValue
**Total Siblings**4
**Active Siblings**0
**Threat Siblings**0
**Abuse Density**0
**High Risk Neighbors**0
**Medium Risk Neighbors**0
**Low Risk Neighbors**3

Neighbor Risk Scores:

---

## Recommended Actions

Based on the low-risk profile, the following actions are recommended:

1. Allow Traffic: No blocking required; IP shows minimal threat indicators

2. Monitor DNSBL Status: One of eight DNSBL listings detected; continue monitoring for changes

3. Standard Logging: Apply standard network logging practices

4. No Immediate Mitigation: No firewall rules or WAF policies required

---

## Intelligence Assessment

The IP 171.80.9.247 presents minimal security concerns. The address belongs to a Chinese telecommunications infrastructure network with no active services exposed. The single DNSBL listing appears to be a false positive or non-malicious listing based on the overall low-risk profile. No threat campaigns, known attacker associations, or persistent malicious behavior were observed.

Threat Level: LOW

Action Required: Standard monitoring; no immediate mitigation needed.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇨🇳 China
Region—
CityP.R.China
Timezone—
Latitude—
Longitude—

🏢 Ownership & Registration

OrganizationIRT-CHINANET-CN
ASNAS151185
Network NameCHINANET-HB
CIDR Block171.80.0.0/14
RIRAPNIC
CountryCN
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)

🔐 DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS151185
Network Prefix171.80.0.0/18
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
17%
23
routing
8%
11
services
8%
11
ownership
17%
23
reputation
16%
13
geolocation
20%
23
Overall15%914
Coverage: 6/6 dimensions · Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

📅 Observation Timeline 🔄 Live

First Seen2026-07-04 17:23:50 UTC
Last Seen2026-08-27 07:07:45 UTC
Profile Built2026-08-29 05:23:06 UTC
Data FreshnessLive
Signal Types17
Total Observations18
🔍 17 signal types · 18 observations collected
This report is generated from 17+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 171.80.9.247

Who owns the IP address 171.80.9.247?

171.80.9.247 is registered to IRT-CHINANET-CN. The address falls within the 171.80.0.0/14 network block. Registration is held at APNIC.

Where is 171.80.9.247 located?

Geolocation data places 171.80.9.247 in P.R.China. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 171.80.9.247 malicious or safe?

171.80.9.247 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.

🏘️ Related IP Addresses

Nearby addresses in 171.80.0.0/14

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.