IP Intelligence Briefing: 222.172.32.246/32
*Last Updated: 2026-05-30*
---
**1. Risk Assessment**
- Overall Risk Score: High (80/100)
- Threat Indicators: No direct malware/campaign associations detected.
- DNSBL Listings: 4/8 total lists (moderate risk).
- Network Stability: Unstable (route changes in last 30 days).
- Mobile Carrier: China Telecom (LTE/5G).
---
**2. Ownership & Geolocation**
- ASN: 4134 (CHINANET-HL, China)
- Organization: LIJUAN ZHENG (assigned to China Mobile International Limited).
- Geolocation: Kunming, Yunnan, China (latitude/longitude unconfirmed).
- Subnet: 222.172.32.246/24 (abuse density: 1/100).
---
**3. Observation History**
- ICMP Validation: Blocked (unable to confirm geo-accuracy).
- Threat Trends: No persistent malicious activity detected in last 30 days.
- Network Changes: Subnet classification shifted from "mostly_clean" to "unknown" due to 1 threat sibling.
---
**4. Relationships & Neighbors**
- Linked Entities:
- Same network: CHINANET-HL (4134).
- DNSSEC: Validated.
- CAA Records: Present.
- Neighboring IPs:
- Subnet 222.172.32.0/24 has 1 active threat sibling (low risk).
- No other active neighbors detected.
---
**5. Recommendations**
1. Monitor Subnet: Track 222.172.32.0/24 for emerging threats due to 1 threat sibling.
2. DNSBL Investigation: Verify relevance of 4 DNSBL listings (e.g., Spamhaus, Cisco Talos).
3. Mobile Network Context: Consider China Telecomβs infrastructure as a potential vector for mobile-specific attacks.
4. Geolocation Validation: Use alternative methods (e.g., TLS fingerprints) to confirm Kunming, Yunnan location.
5. Firewall Rules: Block IP via iptables/nftables to mitigate potential lateral movement risks.
---
*End of Briefing*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | LIJUAN ZHENG |
| ASN | AS4134 |
| Network Name | CHINANET-HL |
| CIDR Block | 222.172.0.0/17 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 22% | 9 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-15 08:44:11 UTC |
| Last Seen | 2026-06-13 03:45:35 UTC |
| Profile Built | 2026-06-07 13:23:06 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.