# IP Intelligence Briefing: 111.68.6.142/32
Date: 2026-07-28
Classification: Routine Infrastructure
## Executive Summary
IP address 111.68.6.142 is a web server infrastructure asset associated with Netsec (AS45753) in Hong Kong. Current analysis indicates LOW RISK with no active threat indicators. The IP operates as part of a clean subnet with minimal abuse density and no observed malicious activity.
## Technical Profile
Network Identification:
- ASN: AS45753 (IRT-APACSERVER-HK)
- Organization: Netsec
- CIDR Block: 111.68.6.0/24
- RIR: APNIC
- Geolocation: Hong Kong (22.4°N, 114.11°E)
Risk Metrics:
- Overall Risk Score: 0/100
- Provider Score: 0
- Authority Score: 0
- Abuse Confidence Score: None
- Reputation: Low Risk
## Network Role & Services
Classification: Web Server
Open Ports:
- TCP 443 (HTTPS)
- TCP 8080 (HTTP-alt)
- TCP 8443 (HTTPS-alt)
TLS Certificate:
- Issuer: CN=ManageEngineCA, O=Zoho Corporation, OU=ManageEngine, S=CA, C=US
- Subject: CN=ManageEngine, O=Zoho Corporation, OU=ManageEngine, S=CA, C=US
- Cipher Suite: TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
- Protocol: TLS 1.2
## Threat Indicators
Current Status: Clean
- Blacklist Count: 0
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Known Campaigns: None
- Threat Feeds: None active
DNSBL Status: Not listed (8 total checks performed)
## Neighborhood Analysis
Subnet: 111.68.6.0/24
- Abuse Density: 0 (clean)
- Classification: Clean
- Total Siblings: 2
- Active Siblings: 1
- Threat Siblings: 0
Neighbor IP: 111.68.6.102
- Risk Score: 0
- Status: Low Risk
## Observation History
Total Signals: 18 observations
Recent Activity (2026-07-28):
- Connection failures observed during HTTPS probing
- ASN reputation flagged as potentially concerning in one feed (AS45753 netsec limited)
- TLS certificate and port scanning activity confirmed
- Organization identified as Zoho Corporation in certificate data
Temporal Analysis:
- No persistent malicious activity detected
- Ownership stability: No changes recorded
- Threat persistence days: 0
- Threat observation count: 0
## Control Plane Assessment
- Route Stability: False
- DNSSEC: Valid
- IR Consistency: Not verified
- BGP Prefix: 111.68.6.0/24
- Route Changes (30d): 0
## Relationship Graph
Connected Entities: 4 relationship links
- Type: Same Network (Netsec)
- Target Type: Network
- Connections: Primarily intra-subnet associations
## Security Assessment
The IP address 111.68.6.142 presents minimal threat to defensive security operations. Technical indicators confirm operation as legitimate web server infrastructure with standard HTTPS services. The absence of blacklist entries, threat indicators, and malicious activity correlates with routine infrastructure behavior.
Recommended Action: No blocking required. Monitor for changes in risk profile if threat indicators emerge.
---
*Intel generated by IPDebrief threat intelligence platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | IRT-APACSERVER-HK |
| ASN | AS45753 |
| Network Name | Netsec |
| CIDR Block | 111.68.6.0/24 |
| RIR | APNIC |
| Country | HK |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | — |
| 8080 | http-alt | tcp | — |
| 8443 | https-alt | tcp | — |
| Closed Ports | 22, 25, 80, 3389 (3 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | WIN-TE63F9O7CVS |
| Valid From | 2026-07-10T09:56:45+00:00 |
| Valid Until | 2027-07-10T09:56:45+00:00 |
| TLS Protocol | Tls12 |
| Cipher Suite | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 365 days |
🛡️ Public Network Snapshot
| Origin ASN | AS45753 |
| Network Prefix | 111.68.6.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 25% | 1 | 1 |
| geolocation | 25% | 1 | 1 |
| Overall | 26% | 7 | 8 |
| Data Coherence | Mixed Signals (68%) — 2 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
⚠ TLS certificate claims US but primary geo says HK
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-18 23:50:06 UTC |
| Last Seen | 2026-09-02 18:44:44 UTC |
| Profile Built | 2026-08-31 22:58:16 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 29 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 111.68.6.142
Who owns the IP address 111.68.6.142?
111.68.6.142 is registered to IRT-APACSERVER-HK. The address falls within the 111.68.6.0/24 network block. Registration is held at APNIC.
Where is 111.68.6.142 located?
Geolocation data places 111.68.6.142 in Hong Kong, HK, Hong Kong. The local time zone is Asia/Hong_Kong. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 111.68.6.142 malicious or safe?
111.68.6.142 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 111.68.6.142?
Responsive ports observed on 111.68.6.142 include 443, 8080, 8443. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.