## IP Intelligence Briefing: 60.219.107.42
Classification: High Risk | Risk Score: 80/100
Date Generated: 2026-07-30
---
**Executive Summary**
IP address 60.219.107.42 is associated with China Unicom mobile infrastructure and presents a high-risk profile (score 80). While the subnet shows minimal abuse density and no persistent malicious activity, the IP is listed on 5 of 8 DNSBLs and operates on mobile carrier infrastructure, warranting defensive monitoring and connection controls.
---
**Network Ownership & Geolocation**
- ASN: 4837 (China Unicom)
- Organization: ChinaUnicom Hostmaster (UNICOM-HL)
- CIDR Block: 60.218.0.0/15
- Country: China (CN)
- RIR: APNIC
---
**Technical Profile**
- Classification: Mobile carrier traffic (China Unicom LTE/5G; MCC 460, MNC 01)
- Service Status: Firewalled / No Services detected
- Open Ports: None observed
- DNS Resolution: No PTR hostnames; forward resolution confirmed false
- DNSBL Status: Listed on 5 of 8 threat feeds
---
**Threat Indicators**
- Reputation Sources: 0 external reputation sources
- Known Campaigns: None identified
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Abuse Confidence Score: Not provided
---
**Relationship Analysis**
- Network Relationships: 2 relationships identified (both to UNICOM-HL network)
- External Entities: No associated hostnames, organizations, or certificates
- Correlated IPs: 0 correlated IPs in campaign correlation
---
**Neighborhood Assessment (60.219.107.42/24)**
- Abuse Density: 0
- Total Siblings: 0
- Active Siblings: 0
- Threat Siblings: 0
- High-Risk Neighbors: 0
---
**Temporal Analysis (11 Observations)**
- Ownership Stability: 0 changes (stable ownership)
- Threat Persistence: 0 days
- Threat Observation Count: 0
- Persistently Malicious: No
- Route Stability: False
- Recent Signals (2026-07-30): Subnet classified as clean with 0 inherited risk
---
**Recommended Security Actions**
| Action | Priority | Rule Type |
|---|---|---|
| Monitor mobile carrier traffic | Medium | Log all connections from this ASN |
| Block DNSBL-listed IPs | High | Apply to iptables/nftables |
| Rate limit mobile connections | Medium | Implement in WAF/firewall |
| Block inbound connections | High | Default deny for this IP |
Sample iptables Rule:
```bash
iptables -A INPUT -s 60.219.107.42 -j DROP
```
---
**Operational Notes**
- IP operates on mobile carrier infrastructure (China Unicom)
- No open services detected; traffic may be transient
- DNSBL listings suggest reputation issues despite clean subnet metrics
- No evidence of coordinated malicious activity or campaign participation
- Consider blocking at perimeter firewall level due to DNSBL presence and high risk score
Analyst Notes: While the subnet shows minimal abuse density, the individual IP's DNSBL listings and mobile carrier association warrant defensive blocking. No evidence of persistent malicious infrastructure, but connection logging recommended for forensic visibility.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | ChinaUnicom Hostmaster |
| ASN | AS4837 |
| Network Name | UNICOM-HL |
| CIDR Block | 60.218.0.0/15 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-29 04:30:47 UTC |
| Last Seen | 2026-07-30 23:20:57 UTC |
| Profile Built | 2026-07-30 20:19:17 UTC |
| Data Freshness | Live |
| Signal Types | 14 |
| Total Observations | 14 |
Full dossier details are available via our API.