IPDebrief

111.70.27.30

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 111.70.27.30/32

## Executive Summary

IP address 111.70.27.30/32 is a high-risk address (risk score: 80) associated with Hinet (ASN 17421) in Taipei, Taiwan. The address resolves to a residential/dynamic IP assignment with multiple blacklist listings. While the /24 subnet shows low abuse density, this specific IP demonstrates persistent threat indicators and warrants defensive monitoring.

## Threat Profile

Risk Assessment:

Network Classification:

Geolocation:

## Threat Indicators

Observed Threat Activity:

Campaign Correlation:

## Network Context

Subnet Analysis (/24):

Related Entities:

DNS Intelligence:

## Observational History

Temporal Analysis:

Behavioral Patterns:

## Recommended Actions

Defensive Measures:

1. Firewall Rules:

- Block inbound traffic on standard web ports (80, 443) if not required

- Implement rate limiting for outbound connections

- Monitor for scanning activity from this IP

2. Threat Intelligence Integration:

- Add to blocklist based on high risk score (80)

- Monitor blacklist feed updates (currently on 6 of 8 lists)

- Watch for new certificate or banner matches

3. Network Monitoring:

- Alert on connection attempts from this IP range

- Track for any changes in DNS resolution or hostname associations

- Monitor for emergence of open services or port changes

4. Investigation Priorities:

- Verify legitimate vs. unauthorized use of Hinet residential allocation

- Check for lateral movement indicators

- Correlate with any incident reports involving similar Hinet IPs

## Risk Narrative

This IP address represents a medium-to-high risk indicator that originated from Taiwan's Hinet ISP infrastructure. The high risk score of 80 is driven primarily by extensive blacklist presence across 6 DNSBL sources. Despite the /24 subnet showing low abuse density, the individual IP demonstrates concerning behavior patterns including port scanning activity and persistent threat indicators.

The residential/emome-ip classification suggests this may be a compromised endpoint rather than infrastructure-level abuse. The absence of open services indicates the IP may be actively monitored or blocked, yet the persistent blacklist presence suggests ongoing threat activity. SOC analysts should treat this IP with caution and implement monitoring controls while avoiding immediate takedown actions that could disrupt legitimate end-user services.

---

*Report generated based on IPDebrief intelligence data. Data timestamp: Current analysis period. Risk scores subject to ongoing monitoring and may change with additional observations.*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡น๐Ÿ‡ผ Taiwan
RegionNWT
CityTaipei
TimezoneAsia/Taipei
Latitude23.70
Longitude120.96

๐Ÿข Ownership & Registration

OrganizationUnknown
ASNAS17421
Network Nameโ€”
CIDR Block111.70.0.0/18
RIRโ€”
Countryโ€”
Abuse Contactโ€”

๐ŸŒ DNS Intelligence

PTR111-70-27-30.emome-ip.hinet.net
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnames111-70-27-30.emome-ip.hinet.net

๐Ÿ” DNS Hygiene

Hygiene Score80% (Excellent)
SPFPresent
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAAPresent

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown โ€” Insufficient routing data to classify
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverlighttpd/1.4.30
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
37%
23
routing
13%
11
services
32%
23
ownership
19%
22
reputation
26%
13
geolocation
21%
22
Overall25%1014
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Fresh

First Seen2026-05-07 23:03:31 UTC
Last Seen2026-06-26 18:10:24 UTC
Profile Built2026-06-26 23:23:31 UTC
Data FreshnessFresh
Signal Types23
Total Observations23
๐Ÿ” 23 signal types ยท 23 observations collected
This report is generated from 23+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.