IPDebrief

112.199.192.139

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 112.199.192.139

## Executive Summary

IP address 112.199.192.139 is classified as High Risk with a risk score of 80/100. The IP belongs to ASN 4773 (M1 Hostmaster) under the Mobile-Broadband network, located in Singapore (SG). Despite the elevated risk rating, the IP shows no active open ports, no known threat indicators, and zero blacklist matches. Recommended action: Block or monitor closely.

## Technical Profile

AttributeValue
**IP Address**112.199.192.139/32
**Risk Score**80 (High Risk)
**ASN**4773
**Organization**M1 Hostmaster
**Network Block**112.199.192.0/18
**Location**Singapore, SG
**Service Purpose**Firewalled / No Services
**Open Ports**None detected
**DNS PTR**139.192.199.112.unknown.m1.com.sg

## Threat Indicators

## Network Context

Subnet Analysis: The IP resides in subnet 112.199.192.139/24 with:

Neighboring IPs: No additional sibling IPs identified in the immediate /24 range.

## Relationship Graph

The IP maintains associations with:

No organizational or certificate relationships detected.

## Historical Activity

The IP has demonstrated consistent network classification with no significant temporal shifts in threat posture.

## Recommended Actions

Immediate Recommendations

1. Block Traffic: Implement firewall rules to drop all traffic from this IP

2. Increase Logging: Enable verbose logging for any observed traffic from this subnet

Firewall Rules

PlatformRule
**iptables**`iptables -A INPUT -s 112.199.192.139 -j DROP`
**nftables**`nft add rule inet filter input ip saddr 112.199.192.139 drop`
**nginx**`deny 112.199.192.139;`
**pfSense**`112.199.192.139/32`
**Cloudflare WAF**Block IP with description "IPDebrief risk score 80"
**AWS WAF**`Addresses: ["112.199.192.139/32"]`

## Assessment Notes

Despite the elevated risk score of 80, the IP shows minimal malicious characteristics:

The high risk rating appears to be based on network classification flags rather than active malicious behavior. Recommend blocking as a precautionary measure while monitoring for any activity.

---

*Intelligence generated by IPDebrief. Recommendations should be validated with additional signals before enforcement.*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇸🇬 Singapore
Region—
CitySingapore
TimezoneAsia/Singapore
Latitude1.35
Longitude103.82

🏢 Ownership & Registration

OrganizationM1 Hostmaster
ASNAS4773
Network NameMobile-Broadband
CIDR Block112.199.192.0/18
RIRAPNIC
CountrySG
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR139.192.199.112.unknown.m1.com.sg
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnames139.192.199.112.unknown.m1.com.sg

🔐 DNS Hygiene

Hygiene Score60% (Good)
SPF1/2 domains
DMARC1/2 domains
FCrDNSNot verified
DNSSECValid
CAANot configured
Domains Checked2 domains

☁️ Network Classification

InfrastructureUnknown
Service PurposeMulti-Service Host
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
22sshtcpBanner detected
8443https-alttcp—
Closed Ports25, 80, 443, 3389, 8080 (2 open / 7 scanned)
ServerWeb server detected
HTTP Title—

🔐 TLS Certificate

A self-signed certificate was detected. This is common for development servers, internal services, or IoT devices.
⚠️
CN=router.asus.com, C=US
Issued by CN=router.asus.com, C=US
Self-signed: Yes
SANsrouter.asus.com
Valid From2025-12-23T07:29:06+00:00
Valid Until2035-12-24T07:29:06+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period3653 days

🛡️ Public Network Snapshot

Origin ASNAS4773
Network Prefix112.199.128.0/17
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
24%
24
routing
13%
12
services
12%
22
ownership
40%
26
reputation
8%
12
geolocation
23%
22
Overall20%1018
Coverage: 4/6 dimensions · Data sufficiency: partial
Data CoherenceMixed Signals (68%) — 2 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Geo sources disagree on country: SG, US
⚠ TLS certificate claims US but primary geo says SG

📅 Observation Timeline 🔄 Live

First Seen2026-07-18 11:33:37 UTC
Last Seen2026-09-02 08:27:04 UTC
Profile Built2026-09-02 08:29:04 UTC
Data FreshnessLive
Signal Types22
Total Observations32
🔍 22 signal types · 32 observations collected
This report is generated from 22+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 112.199.192.139

Who owns the IP address 112.199.192.139?

112.199.192.139 is registered to M1 Hostmaster. The address falls within the 112.199.192.0/18 network block. Registration is held at APNIC.

Where is 112.199.192.139 located?

Geolocation data places 112.199.192.139 in Singapore. The local time zone is Asia/Singapore. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 112.199.192.139 malicious or safe?

112.199.192.139 currently carries a high risk assessment, meaning indicators associated with malicious or abusive activity have been observed. This assessment is generated from continuously collected signals and can change over time.

What is the hostname for 112.199.192.139?

The reverse DNS (PTR) record for 112.199.192.139 is 139.192.199.112.unknown.m1.com.sg. This hostname is not forward-confirmed, so it should be treated as a weak signal.

What ports are open on 112.199.192.139?

Responsive ports observed on 112.199.192.139 include 22, 8443. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.

🏘️ Related IP Addresses

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.