IPDebrief

101.13.5.50

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

Threat Intelligence Briefing: IP 101.13.5.50/32

Date: 2026-06-17

**Summary**

The IP 101.13.5.50/32 is associated with high-risk activity, including potential command-and-control (C2) infrastructure. It is registered to Johnny Wang under TAIWANMOBILE-NET (APNIC) and geolocated to Taipei, Taiwan. The subnet 101.13.5.0/24 has an abuse density of 81.8%, with 9 of 11 neighboring IPs classified as high-risk.

---

**Key Findings**

1. Reputation & Risk

- Risk Score: 80/100 (High Risk)

- Threat Indicators: DNSBL listings (5/8 lists), potential C2 activity, and high subnet abuse density.

- Network Role: Single-service host (HTTPS-alt on port 8443).

2. Ownership & Geolocation

- ISP: TAIWANMOBILE-NET (APNIC)

- Location: Taipei, Taiwan (23.7°N, 120.96°E)

- ASN: 24158

3. Network Activity

- Subnet Abuse: 9/11 neighbors are high-risk, with 8 active and 9 flagged for threats.

- DNS Issues: Multiple failed DNS resolution attempts (timeout errors).

- Routing Anomalies: High RTT (250โ€“255 ms) and inferred geographic plausibility discrepancies.

4. Historical Observations

- Recent Activity: Observed in June 2026 with DNSBL listings (5/8 lists) and traceroute anomalies.

- Persistence: No persistent malicious activity detected, but short-term threats noted.

---

**Actionable Recommendations**

1. Block the IP: Implement firewall rules to block 101.13.5.50 using iptables, nftables, or cloud WAFs (e.g., AWS/Azure).

2. Monitor Subnet: Investigate high-risk neighbors in 101.13.5.0/24 for coordinated attacks or botnet activity.

3. DNS Investigation: Verify DNS resolution for associated domains (if available) to detect evasion tactics.

4. Threat Intelligence Feed Updates: Add the IP to DNSBLs and threat feeds for continuous monitoring.

Note: The IPโ€™s association with a mobile carrier and high abuse density suggests potential misuse of network resources. Immediate containment is advised.

---

*Generated by IPDebrief | Copyright © 2026 Jason Alberino. All rights reserved.*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡น๐Ÿ‡ผ Taiwan
Region106,
CityTaipei
TimezoneAsia/Taipei
Latitude23.70
Longitude120.96

๐Ÿข Ownership & Registration

OrganizationJohnny Wang
ASNAS24158
Network NameTAIWANMOBILE-NET
CIDR Block101.8.0.0/13
RIRAPNIC
CountryTW
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAAPresent

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeSingle-Service Host
Network TierTier 3 โ€” Basic operator with some routing infrastructure
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
8443https-alttcpโ€”
Closed Ports22, 25, 80, 443, 3389, 8080 (1 open / 7 scanned)
Serverlighttpd/1.4.64
HTTP Titleโ€”

๐Ÿ” TLS Certificate

A self-signed certificate was detected. This is common for development servers, internal services, or IoT devices.
โš ๏ธ
CN=localhost
Issued by CN=localhost
Self-signed: Yes
SANsNone
Valid From2022-11-22T18:47:37+00:00
Valid Until2032-11-19T18:47:37+00:00
TLS ProtocolTls13
Cipher SuiteTLS_CHACHA20_POLY1305_SHA256
Signature Algorithmsha256RSA
Validity Period3650 days
Serial Number6D84D1635859AF383666AD8C84FA75222EBCAF88
Thumbprint5AE1816DB5CC29C600313C001A79CBF3146537CA

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
28%
24
routing
22%
33
services
24%
23
ownership
24%
23
reputation
23%
13
geolocation
32%
23
Overall25%1219
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (65%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-07 23:03:24 UTC
Last Seen2026-06-26 02:14:27 UTC
Profile Built2026-06-22 05:35:09 UTC
Data FreshnessLive
Signal Types26
Total Observations28
๐Ÿ” 26 signal types ยท 28 observations collected
This report is generated from 26+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.