# Intelligence Briefing: 113.212.69.126/32
Classification: Moderate Risk (Score: 40/100)
Jurisdiction: Indonesia (Jakarta)
Organization: IRT-DATAUTAMA-ID / DATAUTAMA-NET
Network Block: 113.212.68.0/22
---
## Executive Summary
IP 113.212.69.126 is an Indonesian infrastructure address associated with IRT-DATAUTAMA-ID within the DATAUTAMA-NET network. The IP presents moderate risk (40) but is currently firewalled with no active services. The immediate /24 neighborhood exhibits high abuse density (0.8398) with 215 threat siblings identified, suggesting coordinated abuse activity within the subnet.
---
## Risk Assessment
| Metric | Value |
|---|---|
| Overall Risk Score | 40 (Moderate) |
| Abuse Confidence | Not Available |
| Threat Indicators | None |
| Blacklist Count | 0 |
| DNSBL Listings | 1 of 8 total lists |
| Is Tor Exit | No |
| Is Known Attacker | No |
| Is Spam Source | No |
---
## Network Characteristics
- Geolocation: Jakarta, Indonesia (Meruya Utara - Kembangan)
- Classification: Firewalled / No Services
- Open Ports: None detected
- DNS Resolution: No forward resolution; PTR record missing
- Email Authentication: No SPF/DMARC records
- Service Banner: None observed
---
## Neighborhood Analysis (113.212.69.0/24)
- Abuse Density: 0.8398 (High Abuse Classification)
- Inherited Risk: 33
- Active Siblings: 147 of 256 total IPs
- Threat Siblings: 215
- Risk Distribution: 0 High, 100 Medium, 0 Low (sampled)
The elevated neighborhood abuse density indicates this IP belongs to a subnet with significant abuse activity, warranting heightened monitoring of related addresses.
---
## Observation History
Total Observations: 42 signals recorded
Recent Risk Trend: Minimal (last 5 observations)
Stability Score: 0
Ownership Changes: 0
Threat Persistence: 0 days
Campaign Correlation: No matching campaigns identified
The IP has been observed primarily with minimal risk signals in recent activity, though the neighborhood context suggests elevated risk.
---
## Control Plane
- DNSSEC: Valid
- Route Stability: False
- MoAS Status: False
- Operator Score: 0.1304 (Minimal)
- RPKI State: Not Available
- IRR Consistency: Not Available
---
## Recommended Actions
Based on the moderate risk profile and high-abuse neighborhood context:
1. Monitor Closely: Despite current firewalled status, the high-abuse subnet warrants continued observation for service activation or behavior changes.
2. Neighborhood Correlation: Cross-reference with other 113.212.69.0/24 addresses (215 threat siblings identified).
3. DNSBL Verification: Confirm current blacklist status; 1 of 8 DNSBL listings detected.
4. Historical Baseline: Track for changes in open ports, DNS resolution, or service banners.
---
## Intelligence Conclusions
IP 113.212.69.126 is a low-service, firewalled address in Indonesia with a moderate risk score. While not currently presenting active threats, the high-abuse neighborhood environment and 215 threat siblings in the /24 subnet indicate this IP should be monitored as part of a broader subnet analysis. No immediate blocking is warranted, but the address warrants inclusion in watchlists for the 113.212.69.0/24 block.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-DATAUTAMA-ID |
| ASN | โ |
| Network Name | DATAUTAMA-NET |
| CIDR Block | 113.212.68.0/22 |
| RIR | APNIC |
| Country | ID |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 4 |
| routing | 0% | 0 | 0 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 27% | 1 | 3 |
| geolocation | 28% | 2 | 3 |
| Overall | 20% | 9 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:05:05 UTC |
| Last Seen | 2026-06-26 18:12:03 UTC |
| Profile Built | 2026-06-27 02:33:25 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 46 |
Full dossier details are available via our API.