# IPDEBRIEF INTELLIGENCE BRIEFING
Target: 111.223.167.230/32
Date: 2026-07-29
Classification: Low Risk / Legitimate Infrastructure
---
## EXECUTIVE SUMMARY
IP 111.223.167.230 is a low-risk infrastructure address assigned to Dialog Sri Lanka (ASN 18001). The IP shows no active threat indicators, operates within a clean subnet environment, and has no services exposed. The address is classified as legitimate infrastructure with minimal operator risk scoring.
---
## OWNERSHIP & GEOLOCATION
- Organization: Dialog Sri Lanka (DIALOG-LK)
- ASN: 18001
- Network Block: 111.223.128.0/18
- Location: Colombo, Western Province, Sri Lanka (LK)
- Geolocation Confidence: High (geoPlausible: true, geoConsensus: true)
---
## RISK PROFILE
- Overall Risk Score: 15/100 (Low Risk)
- Reputation Status: Low Risk
- Operator Score: 0.1304 (Minimal)
- Abuse Confidence: Not applicable (no abuse detected)
Risk Breakdown
- Threat Indicators: None
- Blacklist Entries: 0
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
---
## NETWORK SERVICES
- Open Ports: None detected
- Service Type: Firewalled / No Services
- TLS Certificates: None
- HTTP Banner: None
- DNS Resolution: No forward resolution confirmed
- Hosted Domains: 0
---
## THREAT INTELLIGENCE
- DNSBL Listings: 1 of 8 total lists
- Control Plane Status: Route stability: false
- Threat Persistence: 0 days observed
- Campaign Correlation: 0 correlated IPs
- WAF Violations: 0
- Honeypot Hits: 0
---
## NEIGHBORHOOD ANALYSIS (111.223.167.0/24)
- Subnet Classification: Clean
- Abuse Density: 0.0
- Total Siblings: 10
- Active Siblings: 7
- Threat Siblings: 0
- Risk Distribution:
- High Risk: 0
- Medium Risk: 3
- Low Risk: 5
- Clean: 1
Notable Neighbors:
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 111.223.167.28 | 15 | 50 |
| 111.223.167.60 | 40 | 50 |
| 111.223.167.98 | 40 | 50 |
| 111.223.167.139 | 15 | 50 |
| 111.223.167.145 | 15 | 50 |
| 111.223.167.251 | 15 | 50 |
| 111.223.167.253 | 0 | 50 |
---
## OBSERVATION HISTORY
- Total Signals Observed: 13
- Latest Scan: 2026-07-29T03:35:00Z
- Ownership Changes: 0
- Threat Observation Count: 0
- Persistence Status: Not persistently malicious
Signal types captured include geolocation, subnet classification, traceroute validation, and service scanning. No escalation in threat profile observed over observation period.
---
## RELATIONSHIP GRAPH
- Primary Network: DIALOG-LK (111.223.128.0/18)
- Related Entities: 3 (all network associations)
- Certificate Associations: None
- Hostname Associations: None
---
## RECOMMENDATIONS
SOC Action: Monitor as legitimate infrastructure. No immediate blocking required.
Firewall Rules: No specific rules required. Standard egress filtering applies.
Additional Notes:
- Subnet shows minimal abuse density
- IP appears to be part of Dialog's network infrastructure
- No indicators of malicious activity
- Consider monitoring for service exposure if new ports appear
---
Report Generated: IPDebrief Intelligence Platform
Data Sources: Live network reconnaissance, threat intelligence feeds, geolocation databases
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | ip noc |
| ASN | AS18001 |
| Network Name | DIALOG-LK |
| CIDR Block | 111.223.128.0/18 |
| RIR | APNIC |
| Country | LK |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS18001 |
| Network Prefix | 111.223.128.0/18 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 34% | 2 | 6 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 34% | 2 | 6 |
| reputation | 23% | 1 | 4 |
| geolocation | 12% | 2 | 2 |
| Overall | 20% | 10 | 21 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-20 18:35:12 UTC |
| Last Seen | 2026-09-05 19:58:51 UTC |
| Profile Built | 2026-09-05 20:09:04 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 29 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 111.223.167.230
Who owns the IP address 111.223.167.230?
111.223.167.230 is registered to ip noc. The address falls within the 111.223.128.0/18 network block. Registration is held at APNIC.
Where is 111.223.167.230 located?
Geolocation data places 111.223.167.230 in Colombo, Western Province, LK. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 111.223.167.230 malicious or safe?
111.223.167.230 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.