# IP Intelligence Briefing: 220.172.55.66/32
## Executive Summary
IP address 220.172.55.66 presents a moderate risk profile with no active threat indicators. The address is associated with China Telecom's mobile network infrastructure within the CHINANET-GZ network (AS4134). Current observations indicate clean subnet classification with zero abuse density in the /24 neighborhood.
## Risk Assessment
- Risk Score: 50/100 (Moderate Risk)
- Reputation: Moderate Risk
- Threat Indicators: None detected
- Blacklist Status: 0 lists
- Known Campaigns: None identified
## Infrastructure Details
- ASN: 4134 (Chinanet Hostmaster)
- Network: 220.172.0.0/16 (CHINANET-GZ)
- Organization: Chinanet Hostmaster
- Country: China (CN)
- Mobile Carrier: China Telecom Corp. Ltd. (LTE/5G)
- Service Classification: Firewalled / No Services
- Network Role: Mobile infrastructure endpoint
## Technical Profile
- Open Ports: None detected
- DNS Resolution: No PTR records, no forward resolution
- Email Authentication: No SPF/DMARC records
- HTTP Services: No active web services
- TLS Certificates: None detected
- Connection Type: Mobile (China Telecom)
## Neighborhood Analysis
- Subnet: 220.172.55.66/24
- Abuse Density: 0%
- Classification: Clean
- Active Siblings: 0
- Threat Siblings: 0
- Risk Distribution: No high or medium risk neighbors detected
## Historical Observations
12 observation records captured. Recent signals show consistent ASN and geolocation data (China, APNIC RIR) with stable network classification. No escalation in threat indicators or abuse patterns observed. The IP maintains a clean classification with zero threat persistence.
## Related Entities
- Network Relationship: CHINANET-GZ (same network)
- Campaign Correlations: None identified
## Control Plane Data
- Route Stability: Unstable (false)
- DNSBL Listings: 2 of 8 total lists
- RPKI State: Not verified
- IRR Consistency: Not verified
## SOC Action Recommendations
Current Status: No immediate action required.
Monitoring Actions:
1. Include in passive monitoring queue for mobile network activity
2. No firewall blocking recommended; IP does not meet threat threshold
3. No WAF rules required; no web services detected
4. Routine intelligence correlation with CHINANET-GZ network activity
Escalation Triggers:
- New threat indicators appear
- Blacklist additions
- Service enumeration reveals open ports
- Abnormal traffic patterns detected
## Intelligence Conclusion
220.172.55.66 is a mobile infrastructure endpoint on China Telecom's LTE/5G network within the CHINANET-GZ block. The IP shows moderate risk scoring due to its mobile carrier association but presents no active threat indicators, blacklist entries, or known malicious activity. The /24 subnet demonstrates clean classification with zero abuse density. No immediate defensive actions are warranted; maintain passive monitoring posture.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Chinanet Hostmaster |
| ASN | AS4134 |
| Network Name | CHINANET-GZ |
| CIDR Block | 220.172.0.0/16 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-28 16:14:21 UTC |
| Last Seen | 2026-07-30 23:20:31 UTC |
| Profile Built | 2026-07-30 18:14:04 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 16 |
Full dossier details are available via our API.