# IP Intelligence Briefing: 27.128.160.208/32
Classification: Moderate Risk (Score: 65/100)
Date: 2026-06-23
Report Type: Threat Intelligence Assessment
---
## Executive Summary
IP address 27.128.160.208 presents a moderate risk threat profile originating from China Telecom's mobile network infrastructure. The IP is registered to CHINANET-HE (ASN 4134) and demonstrates historical DNSBL listing activity. Network classification indicates firewalled status with no active services, though connection type is identified as mobile (China Telecom LTE/5G). SOC teams should implement monitoring controls and consider blocking based on risk score.
---
## Network Ownership & Infrastructure
| Attribute | Value |
|---|---|
| **ASN** | 4134 (Chinanet Hostmaster) |
| **Organization** | CHINANET-HE |
| **CIDR Block** | 27.128.0.0/15 |
| **Country** | CN (China) |
| **Network Type** | Mobile (China Telecom) |
| **Technology** | LTE/5G |
---
## Threat Indicators
- Risk Score: 65/100 (Moderate)
- Abuse Confidence: Elevated based on historical patterns
- Blacklist Status: Listed on 2 of 8 DNSBL feeds (historical data)
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Campaign Affiliation: None detected
Historical Abuse Pattern: Signal history reveals DNSBL listings with high severity ratings across multiple observation periods (June 18, 2026 and June 23, 2026). Three to eight blacklist listings observed per probe with maximum severity marked as "high."
---
## Neighborhood Analysis
Subnet: 27.128.160.208/24
- Abuse Density: 0
- Risk Distribution: No high/medium/low risk siblings detected
- Active Siblings: 1
- Threat Siblings: 1
The immediate /24 subnet shows minimal abuse activity, though the IP maintains a moderate risk score independent of neighborhood classification.
---
## Relationships
Primary Association: CHINANET-HE (43 relationship entries)
All detected relationships indicate membership within the China Telecom network infrastructure. No external hostnames, certificates, or organizational links identified.
---
## Observation History Summary
- Total Observations: 24
- Most Recent Signal: 2026-06-23T09:34:02
- Signal Consistency: DNSBL listings with high severity observed across multiple timestamps
- Geo Validation: Distance 8,033.2km from probe origin (consistent with China location); ICMP validation blocked
- Threat Persistence: No persistent malicious behavior detected
---
## Recommended Actions
Primary Action: Increase logging verbosity and review recent activity from this IP (Severity: High)
Firewall Rules Implemented:
- iptables: `iptables -A INPUT -s 27.128.160.208 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 27.128.160.208 drop`
- nginx: `deny 27.128.160.208;`
- pfSense: `27.128.160.208/32`
- Cloudflare WAF: Block with expression `ip.src eq 27.128.160.208`
- AWS WAF: Address `27.128.160.208/32`
---
## Conclusion
IP 27.128.160.208 is a mobile network address from China Telecom's LTE/5G infrastructure under CHINANET-HE ownership. The moderate risk score (65/100) combined with historical DNSBL listings warrants defensive blocking. No active services or open ports detected; connection shows as firewalled. SOC teams should implement the recommended firewall rules and monitor for any activity changes.
Recommendation: Block IP address at perimeter firewall. Maintain logs for forensic review.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Chinanet Hostmaster |
| ASN | AS4134 |
| Network Name | CHINANET-HE |
| CIDR Block | 27.128.0.0/15 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 37% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 24% | 2 | 3 |
| ownership | 24% | 2 | 3 |
| reputation | 21% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 25% | 10 | 18 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:15 UTC |
| Last Seen | 2026-06-26 18:11:11 UTC |
| Profile Built | 2026-06-23 09:48:09 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 27 |
Full dossier details are available via our API.