## INTELLIGENCE BRIEFING: IP 113.190.252.123/32
Executive Summary
IP address 113.190.252.123 was classified as Moderate Risk (Risk Score: 40) and belongs to Vietnamese telecommunications provider VNPT-VN (ASN 45899). The IP resolves to hostname static.vnpt-hanoi.com.vn and operates within the 113.160.0.0/11 CIDR block. While the target IP itself showed no direct threat indicators, the /24 neighborhood demonstrated elevated abuse activity with a high-risk sibling at 113.190.252.33 (Risk Score: 80).
Ownership and Geolocation
The IP is registered under IRT-VNNIC-AP (Netname: VNPT-VN) within APNIC RIR. Geolocation data indicates origin in Hanoi, Vietnam, with a 600km accuracy radius. The IP is not classified as hosting infrastructure, VPN, CDN, or mobile carrier traffic.
Network Characteristics
- Open Ports: TCP/80 (HTTP), TCP/22 (SSH)
- DNS Resolution: Reverse DNS resolved to static.vnpt-hanoi.com.vn
- Control Plane: Route stability flagged as false; BGP prefix 113.190.240.0/20
- DNSBL Status: Listed on 2 of 8 queried DNSBLs
Threat Indicators
No direct threat indicators observed for the target IP. The IP is not a known attacker, Tor exit node, or spam source. Operator score assessed as Minimal (0.1304). No active campaigns, certificate matches, or correlated IPs detected.
Neighborhood Analysis
The /24 subnet (113.190.252.0/24) exhibited elevated abuse density. One neighboring IP (113.190.252.33) demonstrated high-risk classification (Risk Score: 80, Authority Score: 50). This suggests potential infrastructure sharing or proximity-based risk inheritance within the subnet.
Historical Observations
Twenty-four signal observations were recorded. Recent observations (2026-06-25) showed consistent DNS and hostname resolution without significant threat pattern changes. No ownership changes or persistent malicious behavior detected.
Recommended Actions
- Monitor for inbound connections from the neighboring high-risk IP 113.190.252.33
- Consider geo-blocking traffic from the 113.190.252.0/24 subnet if policy allows
- Review SSH (port 22) and HTTP (port 80) traffic patterns for anomalous activity
- No immediate firewall rules recommended for the target IP based on current risk profile
Conclusion
The target IP presents moderate risk primarily due to neighborhood proximity to confirmed abuse activity. No immediate blocking required, but enhanced monitoring recommended for the associated subnet.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-VNNIC-AP |
| ASN | AS45899 |
| Network Name | VNPT-VN |
| CIDR Block | 113.160.0.0/11 |
| RIR | APNIC |
| Country | VN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | static.vnpt-hanoi.com.vn |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | static.vnpt-hanoi.com.vn |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Multi-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 443, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-ROSSSH |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 24% | 2 | 3 |
| ownership | 24% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 26% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-09 17:40:59 UTC |
| Last Seen | 2026-06-25 17:48:15 UTC |
| Profile Built | 2026-06-25 18:06:59 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.