## IP Intelligence Briefing: 222.189.176.45/32
Executive Summary
IP 222.189.176.45 is a low-risk endpoint associated with China Telecom mobile infrastructure under the CHINANET-JS network block. The address demonstrates minimal threat indicators, no active malicious campaigns, and operates within a predominantly clean /24 subnet. Recommended security posture: monitor but no immediate blocking required.
Technical Profile
- Risk Score: 25 (Low Risk)
- Ownership: ASN 4134 | Chinanet Hostmaster | CHINANET-JS
- Geolocation: China (CN) | 34.77°N, 113.72°E | Asia/Shanghai timezone
- RIR: APNIC | CIDR Block: 222.184.0.0/13
- Network Role: Mobile carrier infrastructure (China Telecom LTE/5G)
- Service Status: Firewalled / No Services exposed
- DNS Resolution: Forward resolution not confirmed | No PTR records
Threat Assessment
- Abuse Confidence Score: Not available
- Blacklist Status: 0 blacklist entries
- Campaign Indicators: No known campaigns matched
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
- DNSBL Listings: 1 of 8 lists (likely minimal impact)
- Threat Persistence: 0 days observed
- Threat Observation Count: 0
Neighborhood Analysis (222.189.176.0/24)
- Abuse Density: 0.125 (12.5%)
- Subnet Classification: mostly_clean
- Total Siblings: 8
- Active Siblings: 2
- Threat Siblings: 1
- Risk Distribution: 4 low, 0 medium, 0 high
- Notable Neighbors: 222.189.176.168 (Risk: 25), 222.189.176.188 (Risk: 25)
Observed Relationships
- Same Network: CHINANET-JS
- Control Plane: BGP Prefix 222.184.0.0/13 | Origin ASN 4134 | Route stability: Unstable
- RPKI State: Not available
- IRR Consistency: Not available
Observation History (Last 11 Signals)
Most recent observations from 2026-07-29:
- Geolocation: China (CN) via MaxMind GeoLite2 | Confidence: 70%
- Organization: Chinanet Hostmaster | Confidence: 90%
- ASN/RIR: APNIC | CIDR: 222.184.0.0/13 | Confidence: 95%
- Subnet Analysis: Abuse density 0.125 | Classification: mostly_clean | Confidence: 75%
Recommended Security Actions
No specific firewall rules recommended due to low risk profile. Current actions:
- Block Lists: Monitor existing DNSBL listings
- Firewall Policy: No immediate action required
- Monitoring: Continue observation for campaign correlation
SOC Analyst Notes
This IP represents mobile carrier infrastructure traffic from China. The low risk score (25) and clean neighborhood profile indicate legitimate carrier activity. The single threat sibling in the /24 (222.189.176.168 or 222.189.176.188) suggests minimal localized threat activity. No correlation with known APTs or criminal campaigns. Monitor for lateral movement if this IP appears in threat indicators, but no immediate containment recommended.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Chinanet Hostmaster |
| ASN | AS4134 |
| Network Name | CHINANET-JS |
| CIDR Block | 222.184.0.0/13 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-23 07:48:55 UTC |
| Last Seen | 2026-07-29 17:26:13 UTC |
| Profile Built | 2026-07-29 17:37:31 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.