IPDebrief

220.165.85.39

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

## IP INTELLIGENCE BRIEFING: 220.165.85.39/32

Executive Summary

IP address 220.165.85.39 presents a HIGH RISK profile (80/100) originating from China's Chinanet infrastructure. The address is associated with mobile carrier China Telecom and classified as a residential/mobile endpoint. While the broader subnet shows low abuse density, this specific IP exhibits elevated threat indicators including DNSBL listings and historical blacklist activity requiring defensive attention.

---

Technical Profile

AttributeValue
**Risk Score**80/100 (High Risk)
**ASN**4134 (Chinanet Hostmaster)
**Organization**CHINANET-YN
**Country/Region**China (CN) - Yunnan Province
**City**Kunming
**Network Type**Mobile (China Telecom, LTE/5G)
**Infrastructure**Firewalled / No Services

---

Threat Indicators

---

Network Context

---

DNS & Service Analysis

---

Historical Activity

Signal observation history indicates 21 total observations. Recent activity from June 18-23, 2026 shows:

---

Recommended Actions

Based on risk profile analysis, the following defensive measures are recommended:

Immediate Actions:

1. Block at perimeter firewall (recommended for iptables, nftables, pfSense, Cloudflare WAF, AWS WAF)

2. Increase logging verbosity for any traffic from this IP

3. Review recent activity from this address for potential compromise indicators

Firewall Rules:

```bash

# iptables

iptables -A INPUT -s 220.165.85.39 -j DROP

# nftables

nft add rule inet filter input ip saddr 220.165.85.39 drop

# nginx

deny 220.165.85.39;

```

---

Intelligence Assessment

This IP address represents a high-risk mobile endpoint from Chinese infrastructure with historical blacklist activity. The combination of elevated risk score (80), multiple DNSBL listings, and mobile carrier attribution suggests potential abuse activity. While the broader subnet maintains low abuse density, this specific address warrants blocking at the network perimeter and enhanced monitoring on any systems that may have interacted with this IP.

Classification: High Risk - Block and Monitor

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡จ๐Ÿ‡ณ China
RegionYunnan
CityKunming
Timezoneโ€”
Latitude34.77
Longitude113.72

๐Ÿข Ownership & Registration

OrganizationChinanet Hostmaster
ASNAS4134
Network NameCHINANET-YN
CIDR Block220.163.0.0/16
RIRAPNIC
CountryCN
Abuse Contactโ€”

๐ŸŒ DNS Intelligence

PTR39.85.165.220.broad.yx.yn.dynamic.163data.com.cn
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnames39.85.165.220.broad.yx.yn.dynamic.163data.com.cn

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureMobile
Service PurposeFirewalled / No Services
Network TierUnknown โ€” Insufficient routing data to classify
Mobile

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
24
routing
13%
11
services
24%
23
ownership
15%
22
reputation
21%
13
geolocation
21%
22
Overall20%1015
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-07 23:04:13 UTC
Last Seen2026-06-26 14:31:36 UTC
Profile Built2026-06-23 08:31:16 UTC
Data FreshnessLive
Signal Types20
Total Observations24
๐Ÿ” 20 signal types ยท 24 observations collected
This report is generated from 20+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.