# Intelligence Briefing: 222.214.141.12/32
## Executive Summary
IP 222.214.141.12 is a mobile network address (China Telecom, MCC 460/MNC 03) assigned to AS4134 (CHINANET-SC). The address carries a high-risk reputation score of 80, driven primarily by DNSBL listings (6 of 8 blacklists). No active services or open ports detected. Geolocation confirms China (CN) with 2,500km accuracy radius.
## Technical Profile
- Risk Score: 80 (High Risk)
- ASN: 4134 (Chinanet Hostmaster)
- Network: 222.208.0.0/13
- Classification: Mobile carrier, Firewalled/No Services
- Mobile Carrier: China Telecom (LTE/5G technology)
- DNS: Dynamic residential hostname (12.141.214.222.broad.ab.sc.dynamic.163data.com.cn)
- Services: None detected (no open ports)
- DNSBL Status: Listed on 6 of 8 threat feeds
## Threat Indicators
- Abuse Confidence: Blacklist count of 6, max severity "high"
- Threat Feeds: No active campaign associations
- Known Attacker Status: Not flagged as known attacker
- Tor Exit: No
- Spam Source: No
## Behavioral Analysis
Observation history shows 23 signals collected between 2026-06-18 and 2026-06-23. The IP demonstrates:
- Stable geolocation (China) across all observations
- Consistent mobile network classification
- One significant blacklist listing event detected on 2026-06-23 (5 of 8 lists, high severity)
- No persistent malicious activity pattern identified
- Operator score of 0.1304 (Minimal risk)
## Network Context
- Neighborhood (222.214.141.0/24): Mostly clean classification, 0 abuse density
- Related Entities: Multiple CHINANET-SC network associations
- DNS Relationships: Dynamic residential hostname pattern with 163data.com.cn infrastructure
- Route Stability: False (routing changes observed)
## Recommended Actions
1. Monitor Closely: IP shows elevated risk due to DNSBL listings but lacks confirmed malicious indicators
2. Contextual Analysis: Verify if traffic correlates with known spam/scanning campaigns
3. Network-Level Review: Assess if broader CHINANET-SC segment requires attention
4. Mobile Traffic Profile: Consider whether mobile carrier traffic patterns are legitimate for your environment
## Conclusion
This IP represents a mobile network address with elevated risk ratings due to blacklist associations. No open services or active exploitation indicators detected. The high-risk classification appears driven by reputation data rather than observed malicious activity. Recommend monitoring while maintaining standard mobile network traffic handling procedures.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Chinanet Hostmaster |
| ASN | AS4134 |
| Network Name | CHINANET-SC |
| CIDR Block | 222.208.0.0/13 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 12.141.214.222.broad.ab.sc.dynamic.163data.com.cn |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 12.141.214.222.broad.ab.sc.dynamic.163data.com.cn |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 24% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 24% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 24% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:14 UTC |
| Last Seen | 2026-06-26 18:11:10 UTC |
| Profile Built | 2026-06-23 09:07:05 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 24 |
Full dossier details are available via our API.