# Intelligence Briefing: IP 1.34.229.12
Classification: High Risk (80/100)
Date: July 2026
Analyst: IPDebrief Intelligence Team
Status: Actionable Intelligence
---
## Executive Summary
IP 1.34.229.12 is a Taiwanese mobile carrier IP address associated with Chunghwa Telecom operating over HINET's infrastructure. The address is classified as High Risk with a risk score of 80/100, primarily driven by DNSBL listings (5/8 lists) and operator scoring. The IP serves as a firewalled endpoint with no active services detected, though historical observations indicate TLS and SSH services were recently observed.
---
## Technical Profile
Network Ownership:
- ASN: 3462 (HINET Network-Adm)
- Organization: HINET Network-Adm
- CIDR Block: 1.34.0.0/16
- RIR: APNIC (Asia Pacific)
- Network Name: HINET-NET
Geolocation:
- Country: Taiwan (TW)
- Region: Taipei City
- Coordinates: 23.7°N, 120.96°E
- Distance from Probe: 9,348.8 km
- Average RTT: 219.6 ms (min: 215 ms)
Network Classification:
- Mobile Carrier: Chunghwa Telecom Co., Ltd. (MCC: 466, MNC: 92)
- Connection Type: LTE/5G
- Service Purpose: Firewalled / No Services
- Status: No open ports, no TLS certificates, no HTTP services
DNS Analysis:
- PTR Record: 1-34-229-12.hinet-ip.hinet.net
- Forward Resolution: Confirmed
- Email Authentication: SPF present, DMARC not configured
- DNSBL Status: Listed on 5 of 8 threat feeds
---
## Threat Assessment
Current Risk Indicators:
- Reputation Score: 80/100 (High Risk)
- Blacklist Count: 0 (current scan)
- Known Attacks/Spam: None identified
- Tor Exit Node: False
- Known Attacker: False
- Campaign Affiliation: None identified
Risk Drivers:
1. DNSBL listings across 5 threat feeds
2. High operator score (0.3478) indicating basic classification
3. Historical service observations showing TLS/SSH activity
Control Plane Assessment:
- BGP Prefix: 1.34.0.0/16
- Route Stability: Unstable
- DNSSEC Valid: Yes
- CAA Records: Present
---
## Observation History (17 Signals)
Recent Activity (2026-07-27):
- TLS Certificate: Observed (Tls1.3, TLS_AES_256_GCM_SHA384 cipher)
- SSH Service: OpenSSH 8.2 detected
- Server Banner: nginx
- Ports Scanned: Multiple ports identified in recent scans
- Geolocation: Confirmed Taiwan (TW), confidence 0.52
Temporal Analysis:
- Threat Persistence Days: 0
- Ownership Changes: 0
- Threat Observation Count: 0
- Persistently Malicious: False
---
## Network Relationships
DNS Associations:
- 1-34-229-12.hinet-ip.hinet.net (multiple records)
- Forward resolution: hinet.net
Network Connections:
- Same Network: HINET-NET (repeated associations)
---
## Neighborhood Analysis
Subnet: 1.34.229.12/24
- Total Siblings: 0
- Active Siblings: 0
- Threat Siblings: 0
- Abuse Density: 0%
- Classification: No inheritance
---
## Security Actions
Recommended Controls:
1. DNSBL Monitoring: Continue monitoring for new blacklist additions
2. Traffic Analysis: Review inbound connections for TLS/SSH services
3. Geolocation Validation: Confirm Taiwan origin during incident response
4. Provider Contact: HINET Network-Adm for abuse reporting
Firewall Considerations:
- Mobile carrier IP may indicate IoT or mobile device traffic
- TLS 1.3 with strong cipher suite detected
- No active web services (nginx banner historical only)
---
## Conclusion
IP 1.34.229.12 is a legitimate Taiwanese mobile carrier endpoint with elevated risk scoring primarily due to DNSBL presence. The IP is currently firewalled with no active services, but historical data confirms recent TLS and SSH activity. No active malicious campaigns or persistent threats detected. SOC teams should monitor for service activation and investigate any inbound connection attempts, particularly from mobile networks.
Priority: Medium
Action: Monitor DNSBL status and review traffic patterns
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | HINET Network-Adm |
| ASN | AS3462 |
| Network Name | HINET-NET |
| CIDR Block | 1.34.0.0/16 |
| RIR | APNIC |
| Country | TW |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR | 1-34-229-12.hinet-ip.hinet.net |
| Forward Confirmed | Yes — FCrDNS verified |
| Forward Hostnames | 1-34-229-12.hinet-ip.hinet.net |
🔐 DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | 2/5 domains |
| DMARC | 0/5 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
| Domains Checked | 5 domains |
☁️ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Web Server |
| Network Tier | Tier 3 — Basic operator with some routing infrastructure |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 443 | https | tcp | — |
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
CN=crazydb911.synology.me was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.| SANs | *.crazydb911.synology.mecrazydb911.synology.me |
| Valid From | 2026-06-16T23:09:38+00:00 |
| Valid Until | 2026-09-14T23:09:37+00:00 (expired) |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
🛡️ Public Network Snapshot
| Origin ASN | AS3462 |
| Network Prefix | 1.34.0.0/16 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Enabled |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-13 09:16:35 UTC |
| Last Seen | 2026-09-25 20:28:12 UTC |
| Profile Built | 2026-09-19 19:49:21 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 29 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 1.34.229.12
Who owns the IP address 1.34.229.12?
1.34.229.12 is registered to HINET Network-Adm. The address falls within the 1.34.0.0/16 network block. Registration is held at APNIC.
Where is 1.34.229.12 located?
Geolocation data places 1.34.229.12 in Taipei, Taipei City, Taiwan. The local time zone is Asia/Taipei. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 1.34.229.12 malicious or safe?
1.34.229.12 currently carries a high risk assessment, meaning indicators associated with malicious or abusive activity have been observed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 1.34.229.12?
The reverse DNS (PTR) record for 1.34.229.12 is 1-34-229-12.hinet-ip.hinet.net. This hostname is forward-confirmed, meaning it resolves back to the same address.
What ports are open on 1.34.229.12?
Responsive ports observed on 1.34.229.12 include 80, 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.
Is 1.34.229.12 a VPN, proxy, or data center address?
1.34.229.12 is classified as a mobile network based on network ownership and behavioural analysis.