# IP INTELLIGENCE BRIEFING
Target: 112.196.188.99/32
Classification: Moderate Risk (Score: 55/100)
Date: 2026-07-27
Prepared by: IPDebrief Intelligence Team
---
## EXECUTIVE SUMMARY
IP 112.196.188.99 presents a moderate risk profile with an overall risk score of 55/100. The IP is associated with Indian ISP infrastructure (ASN 45184, DEN-ISP-AS-IN-AP) and is listed on three DNSBL feeds. No active threat campaigns or malicious services were observed. Recommended mitigation includes increased monitoring and selective firewall blocking.
---
## NETWORK IDENTIFICATION
- IP Address: 112.196.188.99/32
- ASN: 45184 (DEN-ISP-AS-IN-AP - Den Digital Entertainment Pvt. Ltd.)
- Country: India (IN)
- BGP Prefix: 112.196.188.0/24
- Service Purpose: Firewalled / No Services Detected
- Control Plane: Route stable, RPKI state not verified
---
## THREAT ASSESSMENT
| Metric | Value |
|---|---|
| Risk Score | 55/100 (Moderate) |
| DNSBL Listings | 3 of 8 total lists |
| Blacklist Severity | High |
| Tor Exit Node | No |
| Known Attacker | No |
| Spam Source | No |
| Active Attacker | No |
Key Observations:
- IP shows elevated risk score but lacks confirmed malicious indicators
- Listed on multiple DNSBL feeds with high severity ratings
- No open ports or active services detected
- No correlation to known threat campaigns or certificates
---
## NETWORK BEHAVIOR
DNS Analysis:
- Reverse DNS: 99.188.196.112.in-addr.arpa (resolved)
- DNSSEC Valid: Yes
- Forward Resolution: No hostnames
- Email Authentication: No SPF/DMARC records
Services:
- Open Ports: None detected
- TLS Certificate: None
- HTTP Banner: None
- Response Time: Not measured (no active service)
---
## NEIGHBORHOOD ANALYSIS
Subnet: 112.196.188.0/24
Total Siblings: 5 IPs
Abuse Density: 0
Risk Distribution: 2 Medium, 3 Low
| IP Address | Risk Score | Classification |
|---|---|---|
| 112.196.188.32 | 55 | Medium |
| 112.196.188.44 | 55 | Medium |
| 112.196.188.112 | 15 | Low |
| 112.196.188.36 | 0 | Low |
| 112.196.188.110 | 0 | Low |
Assessment: Neighborhood shows moderate abuse concentration with 40% of sibling IPs (2 of 5) exhibiting elevated risk scores.
---
## OBSERVATION HISTORY
Six signal observations recorded. Recent activity includes:
- DNSSEC Validation: Confirmed valid signatures
- ASN Resolution: Confirmed DEN-ISP-AS-IN-AP allocation (2009-02-13)
- DNSBL Listings: 3 high-severity listings detected
- Operator Score: 0.1304 (Minimal)
---
## RELATIONSHIPS
No external relationships detected (subnets, hostnames, organizations, certificates). This suggests limited connectivity to known threat infrastructure.
---
## RECOMMENDED ACTIONS
Immediate Mitigation:
- Monitoring: Increase logging verbosity and review recent traffic activity
- Firewall Rules: Block inbound traffic at perimeter
Technical Implementation:
```
# iptables
iptables -A INPUT -s 112.196.188.99 -j DROP
# nftables
nft add rule inet filter input ip saddr 112.196.188.99 drop
# Cloudflare WAF
{"description":"Block 112.196.188.99 — IPDebrief risk score 55","action":"block","filter":{"expression":"ip.src eq 112.196.188.99"}}
```
Priority: High — Risk score 55 warrants monitoring and selective blocking.
---
## CONCLUSION
IP 112.196.188.99 demonstrates moderate risk characteristics with DNSBL listings but lacks confirmed malicious activity. The absence of open services and active attacks suggests the IP may be a dormant or misconfigured endpoint. SOC analysts should treat this IP as potentially suspicious and implement the recommended firewall rules while maintaining enhanced logging for forensic analysis.
Status: Monitor / Block Recommended
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | DEN Networks Limited |
| ASN | AS45184 |
| Network Name | DEN-IN |
| CIDR Block | 112.196.128.0/18 |
| RIR | APNIC |
| Country | IN |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS45184 |
| Network Prefix | 112.196.188.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 21% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 17% | 2 | 3 |
| reputation | 8% | 1 | 2 |
| geolocation | 17% | 2 | 3 |
| Overall | 14% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-14 09:42:35 UTC |
| Last Seen | 2026-09-02 22:09:04 UTC |
| Profile Built | 2026-09-02 22:11:14 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 23 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 112.196.188.99
Who owns the IP address 112.196.188.99?
112.196.188.99 is registered to DEN Networks Limited. The address falls within the 112.196.128.0/18 network block. Registration is held at APNIC.
Where is 112.196.188.99 located?
Geolocation data places 112.196.188.99 in Jodhpur, Rajasthan, India. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 112.196.188.99 malicious or safe?
112.196.188.99 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.