# IP Intelligence Briefing: 49.86.180.157
Classification: Moderate Risk (Score: 40)
Date: 2026-07-29
Report Type: Full Profile Assessment
---
## Executive Summary
IP 49.86.180.157 is associated with CHINANET-JS Hostmaster (ASN 4134) and geolocated to Beijing, China. The IP operates over China Telecom mobile infrastructure (LTE/5G, MCC 460, MNC 03). Current assessment indicates moderate risk with no active threat indicators, but the IP exhibits DNSBL listings and operates with no exposed services.
---
## Technical Profile
Network Attribution:
- ASN: 4134
- Organization: CHINANET-JS Hostmaster
- Network: CHINANET-JS (49.64.0.0/11)
- RIR: APNIC
- Registration: China
Geolocation:
- Country: CN (China)
- Region: Beijing
- Coordinates: 35.86°N, 104.2°E (2500km radius)
- Geo-source consensus: Mixed sources with confidence 0.30-0.95
Connection Type:
- Mobile carrier: China Telecom Corp. Ltd.
- Technology: LTE/5G
- Classification: Mobile device, not residential
---
## Threat Assessment
Risk Indicators:
- Overall Risk Score: 40 (Moderate Risk)
- Abuse Confidence Score: Not reported
- Blacklist Count: 0
- DNSBL Listed: 2 of 8 total lists
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Service Analysis:
- Open Ports: None detected
- TLS Certificate: None
- HTTP Banner: None
- Status: Firewalled / No Services
Campaign Correlation:
- Known Campaign Matches: 0
- Certificate Matches: 0
- Correlated IPs: 0
---
## Neighborhood Analysis (49.86.180.0/24)
Subnet Classification: Clean
Abuse Density: 0
Total Siblings: 6
Active Siblings: 1
Threat Siblings: 0
Notable Neighbors:
- 49.86.180.189: Risk Score 0, Authority Score 50
- 49.86.180.193: Risk Score 40, Authority Score 50 (similar to target)
---
## Historical Observations
Thirteen observations recorded from 2026-07-29:
- Ownership signals: Consistent CHINANET-JS Hostmaster attribution (confidence 0.90-0.95)
- Geolocation signals: Beijing, China (confidence 0.70-0.95)
- Network signals: Mobile classification, non-proxy/non-VPN (confidence 0.30-0.70)
- Threat signals: No persistent malicious behavior detected
No ownership changes or threat persistence patterns observed.
---
## Relationships
- Same Network: CHINANET-JS (confirmed network affiliation)
---
## Recommended Actions
Firewall Rules (Risk Score 40):
```bash
# iptables
iptables -A INPUT -s 49.86.180.157 -j DROP
# nftables
nft add rule inet filter input ip saddr 49.86.180.157 drop
# nginx
deny 49.86.180.157;
# pfSense
49.86.180.157/32
# Cloudflare WAF
ip.src eq 49.86.180.157 โ BLOCK
# AWS WAF
Addresses: ["49.86.180.157/32"]
```
Assessment Notes:
- No specific threat indicators require immediate blocking
- Recommended rules are probabilistic and should be combined with additional contextual signals
- Mobile carrier connection suggests potential residential/mobile endpoint
- Consider allowing traffic if legitimate business relationship exists
---
## Intelligence Conclusion
IP 49.86.180.157 presents moderate risk with no active threat indicators. The IP operates on China Telecom mobile infrastructure with no exposed services. While DNSBL listings exist, the neighborhood remains clean with zero threat siblings. Current assessment suggests monitoring rather than immediate blocking, unless additional contextual indicators emerge.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | CHINANET-JS Hostmaster |
| ASN | AS4134 |
| Network Name | CHINANET-JS |
| CIDR Block | 49.64.0.0/11 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 18% | 5 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-22 19:33:17 UTC |
| Last Seen | 2026-07-29 15:27:31 UTC |
| Profile Built | 2026-07-29 15:42:23 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.