# Intelligence Briefing: 113.199.245.41/32
## Executive Summary
IP address 113.199.245.41 presents a low-risk profile with no active threat indicators. The IP is associated with Nepal Telecommunications Corporation (IRT-NPTELECOM-NP) but exhibits geographic inconsistencies. No immediate defensive actions are recommended based on current data.
## Profile Overview
- Risk Score: 0 (Low Risk)
- Provider Score: 0
- Authority Score: 0
- Organization: IRT-NPTELECOM-NP (Nepal Telecommunications Corporation, Internet Services)
- ASN: 23752
- Network: NTCINTERNET (113.199.224.0/19)
- Geolocation: New York, US (discrepancy noted with Nepal-based ASN)
- Registration: APNIC RIR, allocated 2008-12-02
## Threat Indicators
No malicious threat indicators were identified:
- Blacklist Count: 0
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
- Known Campaigns: None
- Threat Feeds: Empty
- Abuse Confidence Score: Not available
## Network Behavior
The IP exhibits minimal network activity:
- Open Ports: None detected (Firewalled / No Services)
- DNS Resolution: No PTR hostnames; no forward resolution
- Service Banner: No HTTP/SSH/TLS services detected
- TLS Certificate: None
- Email Authentication: No SPF or DMARC records
## Control Plane Data
- BGP Prefix: 113.199.244.0/23
- Origin ASN: 23752
- RPKI State: Not verified
- Route Stability: Unstable (isRouteStable: false)
- Route Changes (30d): 0
- DNSBL Listings: 0 of 8 total checks
## Observation History
Fourteen observations were recorded, with the most recent from 2026-07-30. Historical signals include:
- Port scan activity detected
- DNSSEC validation confirmed as valid
- ASN attribution to NPTELECOM-NP-AS (Nepal)
- No persistent malicious behavior flagged
- Single threat observation recorded
- Ownership changes: 0
## Neighborhood Analysis
The /24 subnet (113.199.245.41/24) contains:
- Total Neighbors: 1
- Abuse Density: 0
- Neighbor: 113.199.245.72 (Risk Score: 40, Authority Score: 50)
- Risk Distribution: 0 high, 1 medium, 0 low
- Threat Siblings: 0
## Relationships
Two network relationships identified:
- Same Network: NTCINTERNET (2 entries)
## Recommended Actions
No specific firewall rules or security actions are recommended at this time due to the low-risk classification. The IP does not trigger automated action thresholds.
## Analyst Notes
- Geographic Discrepancy: ASN 23752 is Nepal-based but geolocation data indicates New York, US. This warrants monitoring for potential hijacking or misattribution.
- Neighbor Risk: Adjacent IP 113.199.245.72 shows medium risk (score 40). Consider monitoring this sibling for correlated activity.
- Service Status: The target IP is firewalled with no active services, reducing its utility for common attack vectors.
Classification: LOW RISK
Priority: Routine monitoring recommended; no immediate escalation required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | IRT-NPTELECOM-NP |
| ASN | AS23752 |
| Network Name | NTCINTERNET |
| CIDR Block | 113.199.224.0/19 |
| RIR | APNIC |
| Country | NP |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 8% | 2 | 2 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-26 09:11:40 UTC |
| Last Seen | 2026-07-30 06:53:42 UTC |
| Profile Built | 2026-07-30 07:04:50 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.