IP Intelligence Briefing: 222.186.68.154
Date: 2026-06-08
---
**1. Core Risk Profile**
- Risk Score: 80 (High Risk)
- Provider: China Telecom (ASN 4134)
- Ownership: Registered to SHENG WEI (Zhenjiang-Yiquan Hotel) under APNIC.
- Geolocation: China (CN), inferred with 2500km accuracy radius.
- Network Role: Mobile LTE/5G (China Telecom), no public services detected.
---
**2. Threat Indicators**
- DNSBL Listings: 6/8 DNSBLs (high-severity listings detected).
- Scan Activity:
- Open ports scanned (no services detected).
- TLS/HTTP checks inconclusive (no cert/http title found).
- No Malicious Campaigns: No known attacker/spam source indicators.
---
**3. Temporal Observations**
- Recent Activity (2026-06-08):
- Listed in 6 DNSBLs (high severity).
- Scanned for open ports (no active services).
- Historical Stability:
- Route instability (low operator score: 0.2174).
- Subnet abuse density: 1/100 (mostly clean, but inherited risk: 5).
---
**4. Network Relationships**
- Subnet: 222.186.68.154/24.
- Neighbors:
- 222.186.68.153 (risk score: 80).
- Shared Network: Linked to ZHENJIANG-YIQUAN-HOTEL (same ASN, likely internal network).
---
**5. Control Plane & DNS**
- DNSSEC: Validated.
- CAA Records: Present.
- BGP: Route stability low; no RPKI violations noted.
- Mobile Carrier: China Telecom (MCC 460, MNC 03).
---
**6. Recommended Actions**
- Block/Rate Limit: High-risk IP (score 80) with DNSBL history.
- Monitor Neighbors: 222.186.68.153 shows similar risk profile.
- Verify Ownership: Confirm SHENG WEIโs legitimacy; check for spoofing.
- Investigate Subnet: ZHENJIANG-YIQUAN-HOTEL may host additional risks.
---
Summary:
This IP is part of a high-risk mobile subnet under China Telecom, with multiple DNSBL listings and route instability. While no direct malicious activity is observed, its network context and inherited risk warrant close monitoring. Prioritize blocking and further investigation of neighboring IPs.
Tools Used: `ipdebrief_profile`, `ipdebrief_history`, `ipdebrief_relationships`, `ipdebrief_neighbors`.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | SHENG WEI |
| ASN | AS4134 |
| Network Name | ZHENJIANG-YIQUAN-HOTEL |
| CIDR Block | 222.186.68.152/29 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 24% | 2 | 3 |
| ownership | 15% | 2 | 2 |
| reputation | 23% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:14 UTC |
| Last Seen | 2026-06-26 18:11:10 UTC |
| Profile Built | 2026-06-23 09:01:27 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 24 |
Full dossier details are available via our API.