IPDebrief

110.49.146.23

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

IP Intelligence Briefing: 110.49.146.23

*Generated using IPDebrief threat intelligence tools*

---

**Risk Profile**

---

**Ownership & Geolocation**

- Country: Thailand

- Region: Bangkok, Phayathai

- Coordinates: Unavailable (geo-approximation within 500km radius)

---

**Network & Service Analysis**

- HTTP (80), HTTPS (443), SSH (22), HTTP-alt (8080)

- TLS Certificate:

- Issuer: *Teltonika* (Vilnius, Lithuania)

- SAN: *Teltonika209727261CBA*

- Self-signed (no CA validation errors)

---

**Threat Observations**

- 14 observations over 30 days (last 2 weeks).

- Mixed confidence levels (0.23–0.85).

- No persistent malicious activity (threat persistence: 0 days).

- Subnet abuse density: 0% (neighbors: 0 abuse cases).

- No known Tor exit nodes, spam sources, or botnet activity.

---

**Security Recommendations**

1. Block/monitor:

- Firewall: Drop traffic from `110.49.146.23/32` (iptables/nftables/Cloudflare/AWS WAF).

- Logging: Increase verbosity for SSH/HTTP activity to detect anomalous behavior.

2. Investigate:

- Verify TLS certificate validity (self-signed, no CA chain).

- Check if *Teltonika* devices are authorized in your network.

---

**Conclusion**

This IP is flagged as high-risk due to its association with a Thai mobile carrier and potential IoT device infrastructure. While no direct malicious activity is detected, the TLS certificate’s origin (Lithuania) and lack of DNSSEC validation warrant further scrutiny. Block the IP and monitor for unusual traffic patterns.

Tools Used: `ipdebrief_profile`, `ipdebrief_history`, `ipdebrief_relationships`, `ipdebrief_neighbors`, `ipdebrief_actions`.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΉπŸ‡­ Thailand
RegionBangkok
CityPhayathai
TimezoneAsia/Bangkok
Latitude13.74
Longitude100.46

🏒 Ownership & Registration

OrganizationSBN Co Ltd IP Planning
ASNAS38444
Network NameTH_AIS_Mobile_Internet
CIDR Block110.49.144.0/20
RIRAPNIC
CountryTH
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)

πŸ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierUnknown β€” Insufficient routing data to classify
No specific classification

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpβ€”
443httpstcpβ€”
Closed Ports22, 25, 3389, 8080, 8443 (2 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

An expired certificate for CN=Teltonika, O=Teltonika2ec51de4, L=Vilnius, S=Vilnius, C=LT was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.
⚠️
CN=Teltonika, O=Teltonika2ec51de4, L=Vilnius, S=Vilnius, C=LT
Issued by CN=Teltonika, O=Teltonika2ec51de4, L=Vilnius, S=Vilnius, C=LT
Self-signed: Yes
SANsTeltonika2097277FF7BB
Valid From2023-09-28T14:05:43+00:00
Valid Until2025-09-27T14:05:43+00:00 (expired)
TLS ProtocolTls13
Cipher SuiteTLS_CHACHA20_POLY1305_SHA256
Signature Algorithmsha256ECDSA
Validity Period730 days
Serial Number51CCBE04C78A907627848CE3C36BDB92C6743511
Thumbprint02015C58B9D6C5B838DAECD49A9A2CD63AFAA91E

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
29%
24
routing
13%
11
services
26%
23
ownership
27%
23
reputation
24%
13
geolocation
21%
22
Overall23%1016
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceMixed Signals (68%) β€” 2 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Geo sources disagree on country: LT, TH
⚠ TLS certificate claims LT but primary geo says TH

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-07 23:03:30 UTC
Last Seen2026-06-22 08:50:19 UTC
Profile Built2026-06-22 09:08:19 UTC
Data FreshnessLive
Signal Types21
Total Observations23
πŸ” 21 signal types Β· 23 observations collected
This report is generated from 21+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.