IPDebrief

112.134.145.230

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 112.134.145.230

Classification: Moderate Risk / Infrastructure

Date: July 2026

Source: IPDebrief Intelligence Platform

---

## Executive Summary

IP address 112.134.145.230 is a Sri Lankan residential/ISP endpoint (ASN 9329, SLTADSL-SLT-LK) assigned to telecommunications provider Asela Eranda. The IP registers a risk score of 55/100 (Moderate Risk) with no active threat indicators. The address is associated with SLT infrastructure and shows evidence of route instability with 2 BGP changes within the 30-day observation window.

---

## Technical Profile

Ownership & Registration:

Geolocation:

Network Role Classification:

---

## Threat Intelligence Assessment

Risk Score: 55/100 (Moderate Risk)

Threat Indicators:

DNSBL Status:

Threat Persistence:

---

## Network Infrastructure Analysis

BGP Routing:

Control Plane:

DNS Infrastructure:

Services:

---

## Temporal Analysis & History

Observation Count: 16 signals recorded

Key Historical Signals:

Ownership Stability:

Threat Persistence:

---

## Neighborhood Analysis

Subnet: 112.134.145.230/24

---

## Relationship Graph

Identified Relationships (5 total):

No additional entities (organizations, certificates, related hosts) identified in the relationship graph.

---

## Recommended Actions

Primary Recommendation: Increase logging verbosity and review recent activity from this IP due to elevated risk score (55/100).

Firewall Rules:

```bash

# iptables

iptables -A INPUT -s 112.134.145.230 -j DROP

# nftables

nft add rule inet filter input ip saddr 112.134.145.230 drop

# nginx

deny 112.134.145.230;

# pfSense

112.134.145.230/32

# Cloudflare WAF

{"description":"Block 112.134.145.230 — IPDebrief risk score 55","action":"block","filter":{"expression":"ip.src eq 112.134.145.230"}}

# AWS WAF

{"Addresses":["112.134.145.230/32"],"Description":"IPDebrief risk 55"}

```

---

## Intelligence Narrative

The IP address 112.134.145.230 represents a Sri Lankan telecommunications endpoint within the SLTADSL-SLT-LK network infrastructure. The moderate risk score of 55 stems primarily from DNSBL listings (3 of 8 lists) and route instability (2 BGP changes in 30 days), rather than active malicious activity. The IP is not associated with known campaigns, threat actors, or persistent malicious behavior.

The infrastructure appears to be residential ISP infrastructure rather than a dedicated hosting or cloud service. The absence of open ports and services suggests either a residential endpoint with no active services, or a firewall-protected infrastructure component. The DNS associations point to SLT's internal DNS infrastructure (v4.dns.slt.lk).

Thinking Process:

1. Analyze the Request:

* Role: IP intelligence analyst for IPDebrief.

* Task: Continue the previous response exactly where it left off.

* Constraint: Do not repeat text already written. Finish the remaining answer only.

* Input: The previous response ended with a section titled "Intelligence Narrative" that cut off mid-sentence or just finished the narrative paragraph. Looking closely at the last paragraph of the previous output: "The DNS associations point to SLT's internal DNS infrastructure (v4.dns.slt.lk)."

* Data: I have the tool outputs from the first turn (ipdebrief_profile, ipdebrief_history, ipdebrief_relationships, ipdebrief_neighbors, ipdebrief_actions). I need to synthesize any remaining insights that fit the "concise, actionable threat intelligence narrative" format without repeating the previous text.

* Tone: Factual, professional, third person, past tense. No disclaimers.

* Goal: Complete the briefing. The previous section ended with "Intelligence Narrative". I should check if there are any other standard sections needed in such a briefing or if the narrative needs to conclude based on the available data. The previous output had sections: Executive Summary, Technical Profile, Threat Intelligence Assessment, Network Infrastructure Analysis, Temporal Analysis & History, Neighborhood Analysis, Relationship Graph, Recommended Actions, Intelligence Narrative.

* Observation: The previous output ended with the Intelligence Narrative paragraph. It seems complete enough as a narrative summary, but I need to ensure I don't just copy-paste. Wait, the instruction says "Continue exactly where you left off. Do not repeat text already written."

* Check Previous Output End: The last text was: "The DNS associations point to SLT's internal DNS infrastructure (v4.dns.slt.lk)."

* Strategy: I need to wrap up the briefing. Usually, a briefing ends with a conclusion or signature. However, since the prompt asks to "Finish the remaining answer only", I should ensure the content flows logically from where it stopped. The previous section was "Intelligence Narrative". I should conclude that section and close the document professionally, perhaps adding a "Conclusion" or "Assessment" paragraph if it feels incomplete, or simply ending the narrative with a strong closing statement based on the data.

* Data Review:

* Risk Score: 55 (Moderate).

* Reputation: Moderate.

* Threat Indicators: None active.

* Route Stability: Unstable (2 changes in 30d).

* DNSBL: 3/8 lists.

* Ownership: Long-standing (2003).

* Location: Panadura, LK.

* Missing Content: The previous output ended with a narrative paragraph. I should complete the narrative and then finalize the document. I need to make sure I don't regenerate the sections that were already written (Executive Summary, Technical Profile, etc.). I must pick up from the narrative conclusion.

* Refinement: The previous output ended with: "The DNS associations point to SLT's internal DNS infrastructure (v4.dns.slt.lk)."

* Next Step: Conclude the narrative based on the remaining data (risk score, recommendations context) and sign off the report.

*Wait, looking at the previous output:* It ended with the narrative. There isn't much more data to add. I should wrap up the narrative logically and close the report.

*Correction:* I need to check if the previous output was actually *truncated* or if it ended naturally. The prompt says "Continue exactly where you left off." The previous output ended with `The DNS associations point to SLT's internal DNS infrastructure (v4.dns.slt.lk).`. This looks like a complete sentence, but the section is titled "Intelligence Narrative". I should add a concluding sentence to that section or a new section like "Assessment" to wrap it up. Given the instruction "Finish the remaining answer only", I should avoid regenerating headers that might look like repeats if I'm not careful. But since the previous text was the end of the "Intelligence Narrative" section, I can continue writing that section or start a "Conclusion" section.

*Actually, the safest approach for "Continue exactly where you left off" is to append the next logical paragraph or closing statement to the existing flow, ensuring no repetition.*

*Let's draft the continuation:*

* The narrative currently ends with DNS info.

* Next logical point: Summarize the overall threat posture based on the risk score and lack of active indicators.

* Then close the document.

* I must not repeat the Executive Summary or Technical Profile.

* I must not repeat the recommendations already listed in the "Recommended Actions" section (though referencing them in the narrative is okay if phrased differently).

* I will focus on the synthesis of the Moderate Risk status.

*Drafting:*

... The DNS associations point to SLT's internal DNS infrastructure (v4.dns.slt.lk). Despite the presence of three DNSBL listings, no active exploit attempts or malicious payloads were observed in the historical record. The route instability suggests potential infrastructure adjustments or BGP hijacking attempts within the upstream transit path, which warrants monitoring but does not indicate direct compromise. The combination of long-term ownership stability and current moderate risk classification indicates this address functions as a legitimate endpoint or infrastructure component rather than an active threat actor. SOC analysts should maintain elevated logging for this IP while adhering to the recommended firewall rules to mitigate potential abuse vectors associated with the DNSBL listings.

*Wait, I need to check the previous output's ending again.*

It ended with: "The DNS associations point to SLT's internal DNS infrastructure (v4.dns.slt.lk)."

So I will continue from there.

*Wait, one more check:* The previous output included a "Recommended Actions" section with code blocks. The narrative section follows that. I should ensure I don't duplicate the "Recommended Actions" content in the narrative, but rather reference it as context for the assessment.

*Plan:*

1. Continue the narrative paragraph (or start a new concluding paragraph).

2. Provide a final closing statement.

3. Ensure no markdown headers are repeated unless necessary (usually better to avoid repeating "Intelligence Narrative" if I continue the text).

4. Keep it concise and professional.

*Wait, looking at the instruction:* "Finish the remaining answer only."

This implies I should output the text that follows the previous output.

Previous output last line: `The DNS associations point to SLT's internal DNS infrastructure (v4.dns.slt.lk).`

I will continue the paragraph and then close the document.

*Wait, I need to be careful about the "Continue exactly where you left off" instruction.*

If I add a newline, it might look like a new section.

I'll continue the paragraph logically.

Then I'll add a final "Conclusion" or "End of Briefing" line to signal completion.

Actually, since the previous output already had "Intelligence Narrative" as a header, I should probably not add another header unless I'm starting a new section. I'll just continue the text or close it.

Let's add a concluding paragraph to the narrative and then a brief footer.

*Wait, checking the tool outputs again.*

Are there any other insights?

- GeoValidation: geoPlausible: false (interesting).

- Traceroute: timedOutHops: 0.

- Fingerprint: statusCode: null, httpVersion: null.

- Behavioral: honeypotHits: 0.

- Campaign: likelihood: null.

I can incorporate the GeoValidation result (geoPlausible: false) into the narrative if I haven't mentioned it yet. I did mention location, but not the validation status.

I can mention the route instability more clearly.

*Revised Plan:*

1. Continue the narrative paragraph starting from the DNS sentence.

2. Mention GeoValidation status.

3. Mention Route Stability implications.

4. Conclude the narrative.

5. Close the report.

*Wait, I must not repeat the "Intelligence Narrative" header if it was already there.*

The previous output had:

`## Intelligence Narrative`

`The IP address...`

`...`

`The DNS associations point to SLT's internal DNS infrastructure (v4.dns.slt.lk).`

So I should just continue the text.

*Wait, looking at the previous output again.*

It ends with `The DNS associations point to SLT's internal DNS infrastructure (v4.dns.slt.lk).`

There is a trailing space or newline.

I will start with a newline to continue the paragraph or start a new one. Since it's a paragraph, a space or newline is fine. I'll use a newline to make it distinct visually if it's a new thought.

Actually, to "continue exactly where you left off", I should probably not add a double newline if the previous one didn't have one. But the previous one ended with a period. I'll add a newline and continue

While the geolocation data shows the IP is plausible for Sri Lanka, automated validation flags it as geoPlausible: false, which may indicate temporary infrastructure changes or measurement discrepancies rather than malicious behavior. The route instability (2 BGP changes in 30 days) suggests potential upstream routing adjustments, warranting monitoring for any anomalies during traffic flows.

Given the moderate risk score of 55/100 and the absence of active threat indicators, this IP should be monitored rather than immediately blocked, unless specific traffic patterns align with the recommended firewall rules. The combination of long-term ownership stability and current moderate risk classification indicates this address functions as a legitimate endpoint or infrastructure component rather than an active threat actor. SOC analysts should maintain elevated logging for this IP while adhering to the recommended firewall rules to mitigate potential abuse vectors associated with the DNSBL listings.

End of Briefing

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇱🇰 LK
RegionWestern Province
CityPanadura
Timezone—
Latitude6.72
Longitude79.90

🏢 Ownership & Registration

OrganizationIRT-LKTELECOM-LK
ASNAS9329
Network NameSLTADSL-SLT-LK
CIDR Block112.134.145.0/24
RIRAPNIC
CountryLK
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRv4.dns.slt.lk
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesv4.dns.slt.lk

🔐 DNS Hygiene

Hygiene Score60% (Good)
SPF2/2 domains
DMARC2/2 domains
FCrDNSNot verified
DNSSECValid
CAANot configured
Domains Checked2 domains

☁️ Network Classification

InfrastructureResidential
Service PurposeResidential Endpoint
Network TierEnd-User — Residential ISP endpoint
Residential

🔌 Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS9329
Network Prefix112.134.144.0/22
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
8%
11
routing
17%
23
services
8%
11
ownership
19%
34
reputation
8%
11
geolocation
12%
22
Overall12%1012
Coverage: 6/6 dimensions · Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

📅 Observation Timeline 🔄 Live

First Seen2026-07-08 19:10:20 UTC
Last Seen2026-08-27 04:47:09 UTC
Profile Built2026-08-29 05:55:07 UTC
Data FreshnessLive
Signal Types19
Total Observations21
🔍 19 signal types · 21 observations collected
This report is generated from 19+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 112.134.145.230

Who owns the IP address 112.134.145.230?

112.134.145.230 is registered to IRT-LKTELECOM-LK. The address falls within the 112.134.145.0/24 network block. Registration is held at APNIC.

Where is 112.134.145.230 located?

Geolocation data places 112.134.145.230 in Panadura, Western Province, LK. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 112.134.145.230 malicious or safe?

112.134.145.230 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.

What is the hostname for 112.134.145.230?

The reverse DNS (PTR) record for 112.134.145.230 is v4.dns.slt.lk. This hostname is not forward-confirmed, so it should be treated as a weak signal.

Is 112.134.145.230 a VPN, proxy, or data center address?

112.134.145.230 is classified as a residential network based on network ownership and behavioural analysis.

🏘️ Related IP Addresses

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.