# Threat Intelligence Briefing: 218.4.91.163/32
## Executive Summary
IP 218.4.91.163 is a Chinese mobile-registered address assigned to pan zhen (SUZHOU-CS-TRADE-ADMIN) with an elevated risk score of 65/100. The address shows no open services and is classified as firewalled/no services. While not listed on known threat feeds, the IP has been observed on 3 of 8 DNSBL lists with high severity in recent monitoring.
## Risk Assessment
- Risk Score: 65/100 (Moderate Risk)
- Classification: Mobile device connection (China Telecom LTE/5G)
- Geolocation: China (CN), Jiangsu Province, Suzhou City
- ASN: 4134 (China Telecom)
- Block: 218.4.91.160/29
## Threat Indicators
- Blacklist Status: Listed on 3 DNSBL entries (out of 8 total)
- Campaign Association: No known campaigns correlated
- Attacker Status: Not flagged as known attacker or spam source
- Tor/Proxy: Not a Tor exit node or proxy
- Recent Activity: 14 observations recorded, with most recent listing on 2026-06-22 showing high severity
## Network Context
- Subnet Risk: 218.4.91.163/24 exhibits 0.5 abuse density (mostly clean classification)
- Sibling IP: 218.4.91.162 (risk score: 50, authority score: 50)
- Control Plane: Origin ASN 4134, BGP prefix 218.4.0.0/16, route stability compromised
- DNSBL Presence: 3 listings across 8 lists
## Technical Observations
- Services: No open ports detected; classified as firewalled/no services
- DNS: No PTR records, no forward resolution, no email authentication (SPF/DMARC absent)
- Geolocation: Distance 8,722 km from probe origin; ICMP validation blocked
- Fingerprint: No HTTP/HTTPS services detected
## Recommended Actions
Immediate:
1. Implement blocking rules for 218.4.91.163/32 across perimeter infrastructure
2. Increase logging verbosity for traffic from this IP address
3. Review historical activity logs for any anomalous behavior
Firewall Rules:
- iptables: `iptables -A INPUT -s 218.4.91.163 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 218.4.91.163 drop`
- nginx: `deny 218.4.91.163;`
- pfSense: Add 218.4.91.163/32 to block list
- Cloudflare WAF: Block IP with expression `ip.src eq 218.4.91.163`
- AWS WAF: Add 218.4.91.163/32 to block list
## Intelligence Notes
The IP shows moderate risk elevation without clear malicious indicators. The mobile carrier classification and lack of open services suggest this may be a consumer or enterprise mobile connection. Continued monitoring of the sibling IP (218.4.91.162) is recommended given its proximity and associated risk. The subnet's "mostly clean" classification with one threat sibling warrants periodic review but does not indicate coordinated infrastructure.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | pan zhen |
| ASN | AS4134 |
| Network Name | SUZHOU-CS-TRADE-ADMIN |
| CIDR Block | 218.4.91.160/29 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 19% | 2 | 2 |
| reputation | 24% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 21% | 9 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:12 UTC |
| Last Seen | 2026-06-26 18:11:09 UTC |
| Profile Built | 2026-06-23 08:49:08 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 18 |
Full dossier details are available via our API.