# IP Intelligence Briefing: 113.199.240.94/32
Classification: LOW RISK / MONITOR
Generated: 2026-07-30
## Executive Summary
IP 113.199.240.94 is classified as LOW RISK (Risk Score: 25/100). The address is assigned to Nepal Telecommunications Corporation (ASN 23752) but geolocates to New York, USAβa notable inconsistency requiring validation. The IP is currently firewalled with no active services and shows minimal threat indicators.
## Technical Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 25 (Low Risk) |
| **ASN** | 23752 (IRT-NPTELECOM-NP) |
| **Organization** | NTCINTERNET (Nepal Telecom) |
| **CIDR Block** | 113.199.224.0/19 |
| **RIR** | APNIC |
| **Registration Date** | 2008-12-02 |
| **Service Status** | Firewalled / No Services |
| **Open Ports** | None detected |
| **TLS Certificates** | None |
| **Hostname Resolution** | None |
## Threat Assessment
- Abuse Confidence Score: Not reported
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
- Blacklist Count: 1 of 8 DNSBLs checked
- Maximum Severity: High (observed in one listing)
- Known Campaigns: None identified
- Threat Persistence: 0 days observed
## Geolocation Discrepancy
CRITICAL: ASN 23752 belongs to Nepal Telecommunications Corporation (NP), yet geolocation services report the IP as located in New York, USA. This discrepancy requires investigation through manual verification or additional intelligence sources.
## Subnet Analysis
/24 Neighborhood (113.199.240.0/24):
- Total Neighbors: 4
- Abuse Density: 0%
- Risk Distribution: 0 High, 4 Medium, 0 Low
| Neighbor IP | Risk Score | Authority Score |
|---|---|---|
| 113.199.240.45 | 40 | 50 |
| 113.199.240.61 | 40 | 50 |
| 113.199.240.62 | 60 | 50 |
| 113.199.240.164 | 40 | 50 |
## Historical Observations
Total Observations: 14 signals recorded
Recent Activity:
- 2026-07-30 06:58: Port scan activity observed
- 2026-07-30 06:55: Blacklist listing detected (High severity)
- 2026-07-30 06:54: DNSSEC validation confirmed (Valid)
- 2026-07-30 06:54: ASN resolution confirmed (NPTELECOM-NP-AS)
Temporal Indicators:
- Threat Observation Count: 1
- Threat Persistence Days: 0
- Persistently Malicious: False
## Network Classification
| Classification | Status |
|---|---|
| Provider | No |
| CDN | No |
| VPN | No |
| Proxy | No |
| Hosting | No |
| Mobile | No |
| Residential | No |
| Cloud | No |
| Anycast | No |
## Recommended Actions
Current Risk: No immediate blocking required. Monitor for service activation or increased activity.
Suggested Firewall Rule:
- Default: Allow with logging (LOW RISK)
- If geolocation discrepancy confirmed: Investigate ownership and routing anomalies
- If neighbor activity increases: Consider subnet-level monitoring for 113.199.240.0/24
## Intelligence Notes
1. Geolocation Mismatch: The Nepal Telecom ASN with US geolocation warrants investigation. Potential causes include:
- Transit routing through US backbone
- Geo-database misattribution
- Malicious spoofing of origin
2. Limited Service Exposure: The IP is currently firewalled, reducing immediate attack surface. Monitor for service activation.
3. Neighborhood Context: Subnet shows moderate risk levels across neighbors. Correlated analysis with adjacent IPs (113.199.240.45, 113.199.240.61-62, 113.199.240.164) recommended if threat indicators emerge.
4. Blacklist Presence: Single DNSBL listing with high severity suggests potential reputation issues. Verify listing sources and reasons.
---
Analyst Notes: This IP presents low immediate threat but requires ongoing monitoring due to geolocation anomalies. Prioritize geolocation validation through multiple sources. Subnet neighbors show consistent medium-risk profiles; consider correlated threat analysis if activity increases.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | IRT-NPTELECOM-NP |
| ASN | AS23752 |
| Network Name | NTCINTERNET |
| CIDR Block | 113.199.224.0/19 |
| RIR | APNIC |
| Country | NP |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 8% | 2 | 2 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-26 09:11:40 UTC |
| Last Seen | 2026-07-30 06:53:32 UTC |
| Profile Built | 2026-07-30 07:04:50 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.