## THREAT INTELLIGENCE BRIEFING
Subject: IP Address 222.189.176.168/32
Classification: Low Risk - Mobile Network Infrastructure
Date: Current Analysis
Data Source: IPDebrief Intelligence Platform
---
EXECUTIVE SUMMARY
IP 222.189.176.168 is a low-risk address (Risk Score: 25/100) associated with China Telecom's mobile network infrastructure. The IP belongs to the CHINANET-JS network under China's CHINANET Hostmaster (ASN 4134). Analysis indicates mobile carrier connectivity via China Telecom's LTE/5G network with no active threat indicators or malicious campaigns detected.
---
NETWORK ATTRIBUTES
| Attribute | Value |
|---|---|
| **ASN** | 4134 (CHINANET-BACKBONE) |
| **Organization** | CHINANET-JS (Chinanet Hostmaster) |
| **Country** | China (CN) |
| **CIDR Block** | 222.184.0.0/13 |
| **Geolocation** | 34.77°N, 113.72°E |
| **Timezone** | Asia/Shanghai |
| **Network Role** | Mobile Carrier |
| **Mobile Carrier** | China Telecom (MCC: 460, MNC: 03) |
| **Connection Tech** | LTE/5G |
---
THREAT INDICATORS
Current Status: No active threats detected
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
- Blacklist Count: 0
- DNSBL Listed: 1 (of 8 total lists)
- Campaign Association: None detected
Historical Signals: 11 observations recorded. One blacklist listing signal observed on 2026-07-29 with high severity. Ownership and network registration data remain consistent across observation periods.
---
NETWORK ENVIRONMENT
/24 Subnet Analysis (222.189.176.0/24):
- Sibling IPs: 7 neighbors identified
- Abuse Density: 0 (no subnet-level abuse)
- Risk Distribution: 4 low-risk, 0 medium/high-risk
- Notable Neighbors: 222.189.176.45, 222.189.176.107, 222.189.176.188, 222.189.176.229 (Risk Score: 0, Authority Score: 50)
Control Plane:
- BGP Prefix: 222.184.0.0/13
- Route Stability: False (changes observed in last 30 days)
- DNSSEC: Valid
- Traceroute Hops: 30
---
SECURITY ASSESSMENT
The IP address presents minimal security risk. Key observations:
1. Mobile Network Context: The IP is assigned to China Telecom's mobile carrier network, indicating potential mobile device or cellular infrastructure origin.
2. No Service Exposure: No open ports or active services detected (Firewalled / No Services).
3. Clean Reputation: No evidence of malicious activity, spam distribution, or known attack campaigns.
4. Stable Ownership: Consistent registration under CHINANET-JS with no ownership changes.
---
RECOMMENDATIONS
Action: Monitor (No immediate blocking required)
The IP's low risk score (25), absence of threat indicators, and mobile carrier context suggest defensive monitoring is appropriate rather than active blocking. However, network defenders should:
- Consider logging traffic from this IP for baseline activity analysis
- Monitor for any changes in network behavior or reputation
- Review the single DNSBL listing for context if traffic patterns indicate concern
Firewall Rules: Not recommended based on current risk profile.
---
End of Briefing
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Chinanet Hostmaster |
| ASN | AS4134 |
| Network Name | CHINANET-JS |
| CIDR Block | 222.184.0.0/13 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 4% | 1 | 1 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-21 12:55:23 UTC |
| Last Seen | 2026-08-10 17:28:47 UTC |
| Profile Built | 2026-07-29 09:17:03 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 19 |
Full dossier details are available via our API.