IPDebrief

111.223.167.135

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 111.223.167.135/32

Classification: Low Risk

Date: Current Analysis

Analysis Period: Historical observations through 2026-07-30

---

## Executive Summary

IP address 111.223.167.135 is a low-risk infrastructure endpoint registered to Sri Lankan hosting provider DIALOG-LK (ASN 18001). The IP shows no active threat indicators, no open services, and no associations with known malicious campaigns. Neighborhood analysis reveals a clean subnet classification with zero threat siblings. No immediate defensive action required.

---

## Ownership and Geolocation

AttributeValue
**Organization**ip noc
**ASN**18001 (DIALOG-LK)
**Country**Sri Lanka (LK)
**City**Colombo
**Region**Western Province
**CIDR Block**111.223.128.0/18
**RIR**APNIC

Geolocation validation indicates coordinates 6.93°N, 79.89°E with ICMP validation blocked. The IP resolves to a legitimate Sri Lankan hosting infrastructure network.

---

## Risk Assessment

Overall Risk Score: 15/100

Provider Score: 0/100

Authority Score: 0/100

Stability Score: 0/100

Threat Indicators

---

## Network Role and Services

AttributeValue
**Infrastructure Type**Not classified
**Cloud Provider**No
**CDN**No
**VPN**No
**Proxy**No
**Tor**No
**Hosting**No
**Mobile**No
**Residential**No
**Bogon**No
**Anycast**No
**Service Status**Firewalled / No Services

No open ports detected. IP appears to be behind firewall or firewall rules prevent service enumeration.

---

## Neighborhood Analysis (111.223.167.0/24)

Subnet Classification: Clean

Abuse Density: 0

Total Siblings: 10

Active Siblings: 8

Threat Siblings: 0

Risk Distribution in /24

All neighboring IPs show consistent authorityScore of 50, suggesting uniform provider classification across the subnet.

---

## Historical Observations

Total Observations: 17 signals recorded

Recent activity (2026-07-30) includes:

Temporal analysis shows no persistent malicious behavior. Threat observation count: 0.

---

## Relationships

All 5 relationship entries link to the same network entity: DIALOG-LK. No additional associations with external organizations, hostnames, or certificates detected.

---

## Control Plane Status

AttributeValue
**Origin ASN**18001
**BGP Prefix**111.223.128.0/18
**RPKI State:**Not available
**IRR Consistency:**Not available
**Route Changes (30d):**0
**Route Stability:**Unstable
**DNSSEC Valid:**True
**DNSBL Listed:**1 of 8 total lists
**Operator Score:**0.1304 (Minimal)

---

## Recommended Actions

Current Status: No Action Required

The IP demonstrates benign characteristics consistent with legitimate hosting infrastructure. Monitoring continues as part of standard threat intelligence operations. No firewall rules or blocking recommended.

Suggested Monitoring:

---

## Conclusion

IP 111.223.167.135 is a low-risk endpoint associated with DIALOG-LK hosting infrastructure in Colombo, Sri Lanka. The IP shows no evidence of malicious activity, no open services, and resides within a clean subnet. Historical data confirms consistent classification with no persistent threat behavior. No defensive action required.

*Intel produced by IPDebrief Intelligence Platform*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฌ๐Ÿ‡ง United Kingdom
RegionWestern Province
CityLondon
TimezoneEurope/London
Latitude6.93
Longitude79.89

๐Ÿข Ownership & Registration

Organizationip noc
ASNAS18001
Network NameDIALOG-LK
CIDR Block111.223.128.0/18
RIRAPNIC
CountryLK
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown โ€” Insufficient routing data to classify
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
0%
00
reputation
0%
00
geolocation
0%
00
Overall12%33
Coverage: 3/6 dimensions ยท Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-07-27 15:45:58 UTC
Last Seen2026-07-30 12:28:18 UTC
Profile Built2026-07-30 12:38:26 UTC
Data FreshnessLive
Signal Types19
Total Observations19
๐Ÿ” 19 signal types ยท 19 observations collected
This report is generated from 19+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.