## INTELLIGENCE BRIEFING: 101.255.118.190
Classification: Low Risk / Web Server Infrastructure
Date: July 29, 2026
Analyst: Automated Intelligence System
---
EXECUTIVE SUMMARY
IP address 101.255.118.190 is a low-risk web server infrastructure endpoint located in Bekasi, West Java, Indonesia. The IP operates within a Tachyon client subnet (ASN 38511) and presents a risk score of 30. No active threat indicators or malicious behavior were observed during analysis.
---
OWNERSHIP AND INFRASTRUCTURE
| Attribute | Value |
|---|---|
| **ASN** | 38511 |
| **Organization** | IRT-ID-TACHYON |
| **Network Name** | TACHYON-SUBNET-CLIENT |
| **CIDR Block** | 101.255.118.188/30 |
| **RIR** | APNIC |
| **Country** | Indonesia (ID) |
| **Region** | West Java |
| **City** | Bekasi |
Control Plane Data:
- Origin ASN: 38511
- BGP Prefix: 101.255.118.0/24
- Route Stability: False (route changes detected)
- DNSSEC Valid: True
- Operator Score: 0.1304 (Minimal)
---
NETWORK SERVICES AND FINGERPRINT
Open Ports:
- 80/tcp (HTTP)
- 443/tcp (HTTPS)
- 8080/tcp (HTTP-ALT)
- 8443/tcp (HTTPS-ALT)
Server Fingerprint:
- Web Server: nginx/1.24.0
- TLS Cipher: TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
- TLS Certificate: UniFi (Ubiquiti Inc.)
---
THREAT ASSESSMENT
Risk Profile:
- Overall Risk Score: 30 (Low Risk)
- Reputation: Low Risk
- Abuse Confidence Score: Not applicable
- Blacklist Count: 0
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Threat Indicators:
- No known campaigns or threat feed associations
- No evidence of persistent malicious activity
- Historical threat observation count: 0
DNSBL Status:
- Listed on 1 of 8 total DNSBL feeds
---
OBSERVATION HISTORY
Signal History: 14 observations recorded
- Most Recent: July 29, 2026, 03:19 UTC
- Ownership Changes: 0
- Threat Persistence Days: 0
- Status: Not persistently malicious
Key Historical Signals:
- Ownership and network classification signals observed with confidence scores ranging 0.30-0.90
- TLS certificate and port scanning data confirmed
- No escalation in threat indicators observed
---
RELATIONSHIP ANALYSIS
Connected Entities: 4 relationships identified
- All relationships classified as "Same Network" (TACHYON-SUBNET-CLIENT)
- No external network associations detected
---
NEIGHBORHOOD ANALYSIS
Subnet: 101.255.118.190/24
- Abuse Density: 0
- Active Siblings: 0
- Threat Siblings: 0
- Risk Distribution: No high or medium risk neighbors identified
---
SECURITY RECOMMENDATIONS
Current Assessment: No immediate blocking or mitigations required.
Monitoring Recommendations:
- Monitor for route stability changes in BGP prefix 101.255.118.0/24
- Track DNSBL listing status (currently 1 of 8 lists)
- Observe for any changes in TLS certificate validity or issuer
Recommended Actions: None at this time. The IP demonstrates legitimate web server behavior with standard nginx configuration and UniFi certificate infrastructure.
---
END OF BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | IRT-ID-TACHYON |
| ASN | AS38511 |
| Network Name | TACHYON-SUBNET-CLIENT |
| CIDR Block | 101.255.118.188/30 |
| RIR | APNIC |
| Country | ID |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 443 | https | tcp | — |
| 8080 | http-alt | tcp | — |
| 8443 | https-alt | tcp | — |
| Closed Ports | 22, 25, 3389 (4 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | UniFi |
| Valid From | 2025-11-13T07:39:06+00:00 |
| Valid Until | 2028-02-16T07:39:06+00:00 |
| TLS Protocol | Tls12 |
| Cipher Suite | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256RSA |
| Validity Period | 825 days |
🛡️ Public Network Snapshot
| Origin ASN | AS38511 |
| Network Prefix | 101.255.118.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 13% | 1 | 2 |
| routing | 8% | 1 | 1 |
| services | 17% | 2 | 3 |
| ownership | 34% | 2 | 6 |
| reputation | 8% | 1 | 1 |
| geolocation | 32% | 2 | 3 |
| Overall | 19% | 9 | 16 |
| Data Coherence | Mixed Signals (68%) — 2 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
⚠ TLS certificate claims US but primary geo says ID
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-20 18:35:01 UTC |
| Last Seen | 2026-09-02 13:14:33 UTC |
| Profile Built | 2026-09-02 13:16:19 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 25 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 101.255.118.190
Who owns the IP address 101.255.118.190?
101.255.118.190 is registered to IRT-ID-TACHYON. The address falls within the 101.255.118.188/30 network block. Registration is held at APNIC.
Where is 101.255.118.190 located?
Geolocation data places 101.255.118.190 in Bekasi, West Java, Indonesia. The local time zone is Asia/Jakarta. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 101.255.118.190 malicious or safe?
101.255.118.190 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 101.255.118.190?
Responsive ports observed on 101.255.118.190 include 80, 443, 8080, 8443. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.