IPDebrief

1.55.41.145

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

## INTELLIGENCE BRIEFING: 1.55.41.145/32

Classification: Moderate Risk (55/100)

Report Date: Current

Assessment: Static Infrastructure with Regional Risk Indicators

---

EXECUTIVE SUMMARY

IP 1.55.41.145 is a static infrastructure address allocated to FPTDYNAMICIP-NET (ASN 18403, IRT-VNNIC-AP) within the APNIC RIR registry. Current risk assessment identifies moderate threat potential (55/100) primarily due to DNSBL listings and regional IP allocation patterns. The address currently operates with no open services, minimal operator reputation concerns (0.1304), and no active threat campaign indicators.

---

INFRASTRUCTURE PROFILE

AttributeValue
**IP Address**1.55.41.145/32
**Netblock**1.55.32.0/20
**Organization**IRT-VNNIC-AP
**ASN**18403
**Country**Vietnam (VN)
**City**Hanoi
**Service State**Firewalled / No Services

Ownership & Registration:

---

THREAT INDICATORS

Current Status:

Threat Feed Analysis:

Risk Composition:

---

NETWORK CLASSIFICATION

Control Plane:

---

OBSERVATION HISTORY (10 Signals)

Latest Observation: 2026-07-25T00:19:17+00:00

Key Historical Signals:

1. Geolocation: Consistent Vietnam (VN) attribution across all observations

2. Organization: Persistent IRT-VNNIC-AP association

3. Netblock: 1.55.32.0/20 maintained

4. Operator Score: 0.1304 (Minimal)

5. Service Detection: No CDN, Tor, VPN, or proxy indicators

Temporal Analysis:

---

NETWORK RELATIONSHIPS

Identified Connections:

---

NEIGHBORHOOD ANALYSIS

Subnet: 1.55.41.145/24

Abuse Density: 0

Risk Distribution: High=0, Medium=0, Low=0

Active Siblings: 0

Threat Siblings: 0

Assessment: No neighboring IP activity detected within the immediate /24 subnet. Abuse density at zero indicates isolated address behavior.

---

SERVICE ENUMERATION

CategoryStatus
Open PortsNone
TLS CertificateNone
HTTP TitleNone
Server BannerNone
Forward Resolution0 hostnames
PTR RecordsNone
Email Auth (SPF/DMARC)Not configured

Service Purpose: Firewalled / No Services

---

RECOMMENDED SECURITY ACTIONS

Immediate Actions:

1. Firewall Blocking: Recommended for immediate implementation

- iptables: `iptables -A INPUT -s 1.55.41.145 -j DROP`

- nftables: `nft add rule inet filter input ip saddr 1.55.41.145 drop`

- Cloudflare WAF: Block with expression `ip.src eq 1.55.41.145`

- AWS WAF: Add 1.55.41.145/32 to block list

2. Monitoring Enhancement: Increase logging verbosity and review recent activity from this IP

- Severity: High

- Rationale: Elevated risk score (55/100)

Action Rationale:

While no active threat indicators are present, the moderate risk score (55/100) combined with DNSBL listings and regional IP allocation patterns warrants defensive blocking and enhanced monitoring. The absence of open services suggests the IP is not currently serving as an active attack source.

---

INTELLIGENCE JUDGMENT

This IP represents low-to-moderate threat potential. The address is registered to a legitimate Vietnamese ISP infrastructure (FPTDYNAMICIP-NET) with no evidence of active malicious activity. Primary concerns are:

Recommendation: Block at perimeter firewall with logging enabled for future analysis. No immediate incident correlation required. Monitor for behavioral changes or service activation.

---

END OF BRIEFING

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇻🇳 Vietnam
RegionHanoi
CityHanoi
TimezoneAsia/Ho_Chi_Minh
Latitude21.02
Longitude105.85

🏢 Ownership & Registration

OrganizationNetwork Operation Center
ASNAS18403
Network NameFPTDYNAMICIP-NET
CIDR Block1.55.32.0/20
RIRAPNIC
CountryVN
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)

🔐 DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS18403
Network Prefix1.55.41.0/24
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
0%
00
reputation
0%
00
geolocation
0%
00
Overall12%33
Coverage: 3/6 dimensions · Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

📅 Observation Timeline 🔄 Live

First Seen2026-07-08 19:10:05 UTC
Last Seen2026-08-27 00:27:15 UTC
Profile Built2026-08-29 06:50:27 UTC
Data FreshnessLive
Signal Types20
Total Observations22
🔍 20 signal types · 22 observations collected
This report is generated from 20+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 1.55.41.145

Who owns the IP address 1.55.41.145?

1.55.41.145 is registered to Network Operation Center. The address falls within the 1.55.32.0/20 network block. Registration is held at APNIC.

Where is 1.55.41.145 located?

Geolocation data places 1.55.41.145 in Hanoi, Hanoi, Vietnam. The local time zone is Asia/Ho_Chi_Minh. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 1.55.41.145 malicious or safe?

1.55.41.145 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.

🏘️ Related IP Addresses

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.