# IP Intelligence Briefing: 112.134.145.230
Classification: Moderate Risk / Infrastructure
Date: July 2026
Source: IPDebrief Intelligence Platform
---
## Executive Summary
IP address 112.134.145.230 is a Sri Lankan residential/ISP endpoint (ASN 9329, SLTADSL-SLT-LK) assigned to telecommunications provider Asela Eranda. The IP registers a risk score of 55/100 (Moderate Risk) with no active threat indicators. The address is associated with SLT infrastructure and shows evidence of route instability with 2 BGP changes within the 30-day observation window.
---
## Technical Profile
Ownership & Registration:
- ASN: 9329 (Asela Eranda)
- Network Block: 112.134.145.0/24
- RIR: APNIC
- Registration Date: May 2, 2003 (8,485 days)
- CIDR Block: 112.134.145.0/24
Geolocation:
- Country: Sri Lanka (LK)
- Region: Western Province
- City: Panadura
- Coordinates: 6.72°N, 79.9°E
Network Role Classification:
- Service Purpose: Firewalled / No Services
- Not classified as cloud, CDN, VPN, proxy, Tor, hosting, mobile, or residential endpoint
- Bogon status: False
---
## Threat Intelligence Assessment
Risk Score: 55/100 (Moderate Risk)
Threat Indicators:
- Known Attacker: False
- Tor Exit Node: False
- Spam Source: False
- Known Campaigns: None detected
- Blacklist Count: 0
- Pulsedive Risk: Not scored
DNSBL Status:
- Listed on 3 of 8 total DNSBL lists
- DNSBL Listing Count: 3
- Operator Score: 0.1304 (Minimal)
Threat Persistence:
- Threat Persistence Days: 0
- Is Persistently Malicious: False
- Threat Observation Count: 0
---
## Network Infrastructure Analysis
BGP Routing:
- Origin ASN: 9329
- BGP Prefix: 112.134.144.0/22
- AS Path: 34549 → 45489 → 9329
- Route Stability: Unstable (2 changes in 30 days)
- Route Changes (30d): 2
Control Plane:
- RPKI State: Not verified
- IRR Consistency: Not assessed
- Route Stable: False
DNS Infrastructure:
- PTR Hostnames: v4.dns.slt.lk
- Forward Resolution Count: 1
- Forward Hostnames: v4.dns.slt.lk
- Email Auth: SPF enabled, DMARC enabled
- Domain: slt.lk
- Forward Confirmation: False
Services:
- Open Ports: None detected
- TLS Certificate: None
- HTTP Title: None
- Server Banner: None
---
## Temporal Analysis & History
Observation Count: 16 signals recorded
Key Historical Signals:
- ASN allocation: 2003-05-02 (legacy infrastructure)
- Registry: APNIC
- Registry Consistency: True
- Route changes detected within observation window
Ownership Stability:
- Ownership Changes: 0
- Average Ownership Days: Not applicable
Threat Persistence:
- Not persistently malicious
- No sustained threat observation pattern
---
## Neighborhood Analysis
Subnet: 112.134.145.230/24
- Neighbor Count: 0
- Abuse Density: 0
- Risk Distribution: High: 0, Medium: 0, Low: 0
- Active Siblings: 0
- Threat Siblings: 0
---
## Relationship Graph
Identified Relationships (5 total):
- Same Network: SLTADSL-SLT-LK (multiple network associations)
- DNS Association: v4.dns.slt.lk
No additional entities (organizations, certificates, related hosts) identified in the relationship graph.
---
## Recommended Actions
Primary Recommendation: Increase logging verbosity and review recent activity from this IP due to elevated risk score (55/100).
Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 112.134.145.230 -j DROP
# nftables
nft add rule inet filter input ip saddr 112.134.145.230 drop
# nginx
deny 112.134.145.230;
# pfSense
112.134.145.230/32
# Cloudflare WAF
{"description":"Block 112.134.145.230 — IPDebrief risk score 55","action":"block","filter":{"expression":"ip.src eq 112.134.145.230"}}
# AWS WAF
{"Addresses":["112.134.145.230/32"],"Description":"IPDebrief risk 55"}
```
---
## Intelligence Narrative
The IP address 112.134.145.230 represents a Sri Lankan telecommunications endpoint within the SLTADSL-SLT-LK network infrastructure. The moderate risk score of 55 stems primarily from DNSBL listings (3 of 8 lists) and route instability (2 BGP changes in 30 days), rather than active malicious activity. The IP is not associated with known campaigns, threat actors, or persistent malicious behavior.
The infrastructure appears to be residential ISP infrastructure rather than a dedicated hosting or cloud service. The absence of open ports and services suggests either a residential endpoint with no active services, or a firewall-protected infrastructure component. The DNS associations point to SLT's internal DNS infrastructure (v4.dns.slt.lk).
Thinking Process:
1. Analyze the Request:
* Role: IP intelligence analyst for IPDebrief.
* Task: Continue the previous response exactly where it left off.
* Constraint: Do not repeat text already written. Finish the remaining answer only.
* Input: The previous response ended with a section titled "Intelligence Narrative" that cut off mid-sentence or just finished the narrative paragraph. Looking closely at the last paragraph of the previous output: "The DNS associations point to SLT's internal DNS infrastructure (v4.dns.slt.lk)."
* Data: I have the tool outputs from the first turn (ipdebrief_profile, ipdebrief_history, ipdebrief_relationships, ipdebrief_neighbors, ipdebrief_actions). I need to synthesize any remaining insights that fit the "concise, actionable threat intelligence narrative" format without repeating the previous text.
* Tone: Factual, professional, third person, past tense. No disclaimers.
* Goal: Complete the briefing. The previous section ended with "Intelligence Narrative". I should check if there are any other standard sections needed in such a briefing or if the narrative needs to conclude based on the available data. The previous output had sections: Executive Summary, Technical Profile, Threat Intelligence Assessment, Network Infrastructure Analysis, Temporal Analysis & History, Neighborhood Analysis, Relationship Graph, Recommended Actions, Intelligence Narrative.
* Observation: The previous output ended with the Intelligence Narrative paragraph. It seems complete enough as a narrative summary, but I need to ensure I don't just copy-paste. Wait, the instruction says "Continue exactly where you left off. Do not repeat text already written."
* Check Previous Output End: The last text was: "The DNS associations point to SLT's internal DNS infrastructure (v4.dns.slt.lk)."
* Strategy: I need to wrap up the briefing. Usually, a briefing ends with a conclusion or signature. However, since the prompt asks to "Finish the remaining answer only", I should ensure the content flows logically from where it stopped. The previous section was "Intelligence Narrative". I should conclude that section and close the document professionally, perhaps adding a "Conclusion" or "Assessment" paragraph if it feels incomplete, or simply ending the narrative with a strong closing statement based on the data.
* Data Review:
* Risk Score: 55 (Moderate).
* Reputation: Moderate.
* Threat Indicators: None active.
* Route Stability: Unstable (2 changes in 30d).
* DNSBL: 3/8 lists.
* Ownership: Long-standing (2003).
* Location: Panadura, LK.
* Missing Content: The previous output ended with a narrative paragraph. I should complete the narrative and then finalize the document. I need to make sure I don't regenerate the sections that were already written (Executive Summary, Technical Profile, etc.). I must pick up from the narrative conclusion.
* Refinement: The previous output ended with: "The DNS associations point to SLT's internal DNS infrastructure (v4.dns.slt.lk)."
* Next Step: Conclude the narrative based on the remaining data (risk score, recommendations context) and sign off the report.
*Wait, looking at the previous output:* It ended with the narrative. There isn't much more data to add. I should wrap up the narrative logically and close the report.
*Correction:* I need to check if the previous output was actually *truncated* or if it ended naturally. The prompt says "Continue exactly where you left off." The previous output ended with `The DNS associations point to SLT's internal DNS infrastructure (v4.dns.slt.lk).`. This looks like a complete sentence, but the section is titled "Intelligence Narrative". I should add a concluding sentence to that section or a new section like "Assessment" to wrap it up. Given the instruction "Finish the remaining answer only", I should avoid regenerating headers that might look like repeats if I'm not careful. But since the previous text was the end of the "Intelligence Narrative" section, I can continue writing that section or start a "Conclusion" section.
*Actually, the safest approach for "Continue exactly where you left off" is to append the next logical paragraph or closing statement to the existing flow, ensuring no repetition.*
*Let's draft the continuation:*
* The narrative currently ends with DNS info.
* Next logical point: Summarize the overall threat posture based on the risk score and lack of active indicators.
* Then close the document.
* I must not repeat the Executive Summary or Technical Profile.
* I must not repeat the recommendations already listed in the "Recommended Actions" section (though referencing them in the narrative is okay if phrased differently).
* I will focus on the synthesis of the Moderate Risk status.
*Drafting:*
... The DNS associations point to SLT's internal DNS infrastructure (v4.dns.slt.lk). Despite the presence of three DNSBL listings, no active exploit attempts or malicious payloads were observed in the historical record. The route instability suggests potential infrastructure adjustments or BGP hijacking attempts within the upstream transit path, which warrants monitoring but does not indicate direct compromise. The combination of long-term ownership stability and current moderate risk classification indicates this address functions as a legitimate endpoint or infrastructure component rather than an active threat actor. SOC analysts should maintain elevated logging for this IP while adhering to the recommended firewall rules to mitigate potential abuse vectors associated with the DNSBL listings.
*Wait, I need to check the previous output's ending again.*
It ended with: "The DNS associations point to SLT's internal DNS infrastructure (v4.dns.slt.lk)."
So I will continue from there.
*Wait, one more check:* The previous output included a "Recommended Actions" section with code blocks. The narrative section follows that. I should ensure I don't duplicate the "Recommended Actions" content in the narrative, but rather reference it as context for the assessment.
*Plan:*
1. Continue the narrative paragraph (or start a new concluding paragraph).
2. Provide a final closing statement.
3. Ensure no markdown headers are repeated unless necessary (usually better to avoid repeating "Intelligence Narrative" if I continue the text).
4. Keep it concise and professional.
*Wait, looking at the instruction:* "Finish the remaining answer only."
This implies I should output the text that follows the previous output.
Previous output last line: `The DNS associations point to SLT's internal DNS infrastructure (v4.dns.slt.lk).`
I will continue the paragraph and then close the document.
*Wait, I need to be careful about the "Continue exactly where you left off" instruction.*
If I add a newline, it might look like a new section.
I'll continue the paragraph logically.
Then I'll add a final "Conclusion" or "End of Briefing" line to signal completion.
Actually, since the previous output already had "Intelligence Narrative" as a header, I should probably not add another header unless I'm starting a new section. I'll just continue the text or close it.
Let's add a concluding paragraph to the narrative and then a brief footer.
*Wait, checking the tool outputs again.*
Are there any other insights?
- GeoValidation: geoPlausible: false (interesting).
- Traceroute: timedOutHops: 0.
- Fingerprint: statusCode: null, httpVersion: null.
- Behavioral: honeypotHits: 0.
- Campaign: likelihood: null.
I can incorporate the GeoValidation result (geoPlausible: false) into the narrative if I haven't mentioned it yet. I did mention location, but not the validation status.
I can mention the route instability more clearly.
*Revised Plan:*
1. Continue the narrative paragraph starting from the DNS sentence.
2. Mention GeoValidation status.
3. Mention Route Stability implications.
4. Conclude the narrative.
5. Close the report.
*Wait, I must not repeat the "Intelligence Narrative" header if it was already there.*
The previous output had:
`## Intelligence Narrative`
`The IP address...`
`...`
`The DNS associations point to SLT's internal DNS infrastructure (v4.dns.slt.lk).`
So I should just continue the text.
*Wait, looking at the previous output again.*
It ends with `The DNS associations point to SLT's internal DNS infrastructure (v4.dns.slt.lk).`
There is a trailing space or newline.
I will start with a newline to continue the paragraph or start a new one. Since it's a paragraph, a space or newline is fine. I'll use a newline to make it distinct visually if it's a new thought.
Actually, to "continue exactly where you left off", I should probably not add a double newline if the previous one didn't have one. But the previous one ended with a period. I'll add a newline and continue
While the geolocation data shows the IP is plausible for Sri Lanka, automated validation flags it as geoPlausible: false, which may indicate temporary infrastructure changes or measurement discrepancies rather than malicious behavior. The route instability (2 BGP changes in 30 days) suggests potential upstream routing adjustments, warranting monitoring for any anomalies during traffic flows.
Given the moderate risk score of 55/100 and the absence of active threat indicators, this IP should be monitored rather than immediately blocked, unless specific traffic patterns align with the recommended firewall rules. The combination of long-term ownership stability and current moderate risk classification indicates this address functions as a legitimate endpoint or infrastructure component rather than an active threat actor. SOC analysts should maintain elevated logging for this IP while adhering to the recommended firewall rules to mitigate potential abuse vectors associated with the DNSBL listings.
End of Briefing
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | IRT-LKTELECOM-LK |
| ASN | AS9329 |
| Network Name | SLTADSL-SLT-LK |
| CIDR Block | 112.134.145.0/24 |
| RIR | APNIC |
| Country | LK |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | v4.dns.slt.lk |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | v4.dns.slt.lk |
🔐 DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | 2/2 domains |
| DMARC | 2/2 domains |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 2 domains |
☁️ Network Classification
| Infrastructure | Residential |
| Service Purpose | Residential Endpoint |
| Network Tier | End-User — Residential ISP endpoint |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS9329 |
| Network Prefix | 112.134.144.0/22 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 8% | 1 | 1 |
| routing | 17% | 2 | 3 |
| services | 8% | 1 | 1 |
| ownership | 19% | 3 | 4 |
| reputation | 8% | 1 | 1 |
| geolocation | 12% | 2 | 2 |
| Overall | 12% | 10 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-08 19:10:20 UTC |
| Last Seen | 2026-08-27 04:47:09 UTC |
| Profile Built | 2026-08-29 05:55:07 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 21 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 112.134.145.230
Who owns the IP address 112.134.145.230?
112.134.145.230 is registered to IRT-LKTELECOM-LK. The address falls within the 112.134.145.0/24 network block. Registration is held at APNIC.
Where is 112.134.145.230 located?
Geolocation data places 112.134.145.230 in Panadura, Western Province, LK. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 112.134.145.230 malicious or safe?
112.134.145.230 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 112.134.145.230?
The reverse DNS (PTR) record for 112.134.145.230 is v4.dns.slt.lk. This hostname is not forward-confirmed, so it should be treated as a weak signal.
Is 112.134.145.230 a VPN, proxy, or data center address?
112.134.145.230 is classified as a residential network based on network ownership and behavioural analysis.