# IP Intelligence Briefing: 218.91.32.75/32
Classification: Low Risk - Residential/Mobile Infrastructure
Date: 2026-07-29
Analyst: IPDebrief Intelligence Team
---
## Executive Summary
IP address 218.91.32.75 is classified as low-risk (score: 25/100) and originates from China Telecom's mobile network infrastructure under AS4134 (Chinanet). The IP presents as a residential mobile endpoint with no active services, no open ports, and no threat indicators. Neighborhood analysis indicates a clean /24 subnet with zero abuse density and no malicious siblings.
---
## Network Ownership & Geolocation
- ASN: 4134 (Chinanet Hostmaster)
- Organization: CHINANET-JS
- Network Block: 218.94.0.0/16
- Country: China (CN)
- Provider: China Telecom Corp. Ltd. (MCC: 460, MNC: 03)
- Connection Type: LTE/5G Mobile Network
- IP Classification: Residential Mobile Endpoint
---
## Threat Intelligence Profile
| Indicator | Status |
|---|---|
| Risk Score | 25 (Low Risk) |
| Abuse Confidence | Not Available |
| Known Attacker | No |
| Spam Source | No |
| Tor Exit Node | No |
| VPN/Proxy | No |
| CDN/Cloud | No |
| Blacklist Count | 0 |
Threat Feed Status: No indicators in threat feeds, no known campaigns, zero blacklist matches.
---
## Network Services & Port Analysis
- Open Ports: None detected
- Service Purpose: Firewalled / No Services
- TLS Certificate: None
- HTTP Banner: None
- DNS: No PTR hostnames, no forward resolution
- Hosted Domains: 0
The IP is not resolving any DNS records and appears to be a mobile residential endpoint without active services.
---
## Neighborhood Analysis
- Subnet: 218.91.32.0.0/24
- Abuse Density: 0 (Clean)
- Total Siblings: 8
- Active Siblings: 2
- Threat Siblings: 0
Neighbor Risk Distribution:
- High Risk: 0
- Medium Risk: 0
- Low Risk: 5
- Null Scores: 2
The /24 subnet exhibits minimal activity with no threat siblings detected.
---
## Observation History (16 Signals)
Recent observations (2026-07-29) show:
- Network Classification: Standard residential mobile (confidence: 0.30)
- Geolocation: Claims location 34.7732, 113.722 (China) with ICMP validation failed (confidence: 0.50)
- Ownership: No changes detected (confidence: 0.85)
- Subnet Status: Clean classification, abuse density 0 (confidence: 0.75)
- Services: No open ports, standard scan results (confidence: 0.70)
Temporal analysis indicates no persistent malicious behavior and zero threat observation count.
---
## Control Plane & Route Stability
- BGP Prefix: 218.91.0.0/16
- Origin ASN: 4134
- Route Stability: Not stable (route changes: 0 in 30 days)
- RPKI State: Not Available
- DNSSEC: Valid
- DNSBL Listings: 1 of 8 total lists
---
## Recommended Actions
SOC/Defensive Recommendations:
1. Monitor: Track IP as mobile residential endpoint with low-risk profile
2. Block: No immediate blocking recommended; risk score below threshold
3. Investigate: If this IP appears in threat logs, verify against known attack patterns
4. Whitelist Consideration: IP shows legitimate carrier infrastructure characteristics
Firewall Rules:
- No actionable firewall rules generated (risk score 25 below action threshold)
---
## Conclusion
IP 218.91.32.75 is a low-risk mobile residential endpoint belonging to China Telecom's infrastructure under AS4134. No threat indicators, no malicious activity, and a clean neighborhood profile support continued monitoring without defensive intervention. The IP is classified as residential mobile with no services exposed.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Chinanet Hostmaster |
| ASN | AS4134 |
| Network Name | CHINANET-JS |
| CIDR Block | 218.94.0.0/16 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-22 13:24:18 UTC |
| Last Seen | 2026-07-29 13:51:19 UTC |
| Profile Built | 2026-07-29 14:05:00 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.