Device using China Mobile DNS server querying for what appears to be VoIP address
I'm using PF (on FreeBSD) to filter outbound traffic on my network and caught a device trying to use a DNS server assigned to China Mobile:
IP: 110.100.101.49
inetnum: 110.100.0.0 - 110.100.255.255
netname: CTTNET
descr: China Mobile Communications Group Co., Ltd.
descr: Mobile Communications Network Operator in China
descr: Internet Service Provider in China
country: CN
admin-c: CT74-AP
tech-c: CT74-AP
abuse-c: AC1601-AP
status: ALLOCATED NON-PORTABLE
mnt-by: MAINT-CN-CRTC
mnt-irt: IRT-CNNIC-CN
last-modified: 2023-09-18T02:27:04Z
source: APNIC
irt: IRT-CNNIC-CN
address: Beijing, China
e-mail: ipas@cnnic.cn
abuse-mailbox: ipas@cnnic.cn
admin-c: IP50-AP
tech-c: IP50-AP
auth: # Filtered
remarks: Please note that CNNIC is not an ISP and is not
remarks: empowered to investigate complaints of network abuse.
remarks: Please contact the tech-c or admin-c of the network.
mnt-by: MAINT-CNNIC-AP
last-modified: 2021-06-16T01:39:57Z
source: APNIC
role: ABUSE CNNICCN
country: ZZ
address: Beijing, China
phone: +000000000
e-mail: ipas@cnnic.cn
admin-c: IP50-AP
tech-c: IP50-AP
nic-hdl: AC1601-AP
remarks: Generated from irt object IRT-CNNIC-CN
abuse-mailbox: ipas@cnnic.cn
mnt-by: APNIC-ABUSE
last-modified: 2024-07-30T11:55:46Z
source: APNIC
role: chinamobile tech
address: 29, Jinrong Ave.,Xicheng district
address: Beijing
country: CN
phone: +86 5268 6688
fax-no: +86 5261 6187
e-mail: hostmaster@chinamobile.com
admin-c: HL1318-AP
tech-c: HL1318-AP
nic-hdl: ct74-AP
notify: hostmaster@chinamobile.com
mnt-by: MAINT-cn-cmcc
abuse-mailbox: abuse@chinamobile.com
last-modified: 2016-11-29T09:37:27Z
source: APNIC
It is looking for: ss.epdg.epc.mnc260.mcc310.pub.3gppnetwork.org.
I probably would not have seen this, but I temporarily added the printer to my network yesterday and re-provisioned devices on the network today resulting in the IP address I assigned temporarily to the printer yesterday being assigned to my TV. My printer is still using the IP from yesterday resulting in my TV not working.
Why is my device using this specific DNS server and more interestingly, why is it looking for what appears to be a VoIP server? Is it quite literally phoning home?
Is this something I should be worried about? I am half tempted to redirect that query to my local DNS server and have it send the payload to a server on my network so that I might be able to inspect it though I would imagine that would be futile as it would be encrypted and the connection would not work as the certificates wouldn't exist.
How can I troubleshoot this further?