IP INTELLIGENCE BRIEFING: 39.144.130.199/32
Executive Summary:
IP 39.144.130.199 is a low-risk address belonging to China Mobile (IRT-CHINAMOBILE-CN, ASN 56041), operating as mobile carrier infrastructure in Beijing, China. The IP shows no active threat indicators, open services, or malicious behavior. The subnet exhibits mixed abuse density (25%) with 14 of 56 sibling IPs flagged as threats.
---
Technical Profile:
- Risk Score: 25 (Low Risk)
- Organization: IRT-CHINAMOBILE-CN (China Mobile)
- ASN: 56041
- Geolocation: China, Beijing (Xicheng District)
- Network Role: Mobile Carrier (Mobile)
- Services: None detected (firewalled/no services)
- DNS: No PTR records, no forward resolution
- Open Ports: None
Threat Indicators:
- Blacklist Count: 0
- Tor Exit: No
- Known Attacker: No
- Spam Source: No
- Campaign Associations: None
- Abuse Confidence Score: Not applicable (legitimate carrier infrastructure)
Control Plane Analysis:
- BGP Prefix: 39.144.130.0/24
- AS Path: 3303 โ 58453 โ 9808 โ 56041
- IRR Consistency: Match
- Route Stability: Stable (no route changes in 30 days)
- DNSBL Listed: 1 of 8 total lists
- Operator Score: 0.5217 (Moderate)
---
Neighborhood Context (39.144.130.0/24):
- Total Siblings: 56
- Active Siblings: 31
- Threat Siblings: 14
- Abuse Density: 0.25 (25%)
- Classification: Mixed
- Inherited Risk: 10
- Risk Distribution: High: 0, Medium: 3, Low: 52
---
Observation History:
- Total Observations: 21 signals
- Recent Signals: June 2026
- Threat Persistence: 0 days (not persistently malicious)
- Ownership Changes: 0
- Observed Geolocation: China (consistent with carrier infrastructure)
---
Relationships:
- Network Relationships: 9 connections to CMNET network
- Organizational Links: None
- Hostname Associations: None
- Certificate Associations: None
---
Recommended Actions:
- No immediate blocking required โ IP is legitimate carrier infrastructure
- Monitoring: Track subnet-level activity due to 25% abuse density
- Context: Traffic from this IP is expected to be mobile carrier data traffic
- Classification: Legitimate infrastructure, not threat actor origin
---
Threat Intelligence Narrative:
This IP address represents legitimate China Mobile carrier infrastructure with a low-risk profile. The IP has no open services, no threat indicators, and no blacklist associations. While the subnet shows 25% abuse density with 14 threat siblings, the IP itself shows no malicious activity. SOC teams should treat traffic from this IP as legitimate mobile carrier data but maintain awareness of subnet-level threat activity. No firewall rules or blocking actions are recommended for this specific IP address.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-CHINAMOBILE-CN |
| ASN | AS56041 |
| Network Name | โ |
| CIDR Block | 39.144.130.0/24 |
| RIR | APNIC |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 4 |
| routing | 30% | 3 | 4 |
| services | 8% | 1 | 1 |
| ownership | 27% | 2 | 3 |
| reputation | 26% | 1 | 4 |
| geolocation | 35% | 2 | 3 |
| Overall | 26% | 11 | 19 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (65%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-10 22:17:39 UTC |
| Last Seen | 2026-06-26 05:21:33 UTC |
| Profile Built | 2026-06-26 05:32:14 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.