# IPDEBRIEF INTELLIGENCE BRIEFING
Target: 113.212.70.186/32
Classification: Moderate Risk | Date: June 2026
## EXECUTIVE SUMMARY
IP 113.212.70.186 is assigned to IRT-DATAUTAMA-ID (DATAUTAMA-NET) within the APNIC registry. The IP carries a risk score of 40 (Moderate Risk) and is geolocated to Jakarta, Indonesia. No direct threat indicators or open services were detected on this endpoint, though the IP resides within a high-abuse subnet showing significant contextual risk.
## NETWORK OWNERSHIP & GEOLOCATION
- Organization: IRT-DATAUTAMA-ID (DATAUTAMA-NET)
- CIDR Block: 113.212.68.0/22
- ASN: Not assigned (Provider score: 0)
- Location: Jakarta, Indonesia (ID)
- RIR: APNIC
- Registration: Network data available via RDAP
## THREAT PROFILE
- Risk Score: 40/100
- Reputation: Moderate Risk
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0
- Threat Feeds: None detected
- DNSBL Status: Listed on 1 of 8 checked lists
- Services: No open ports; firewall/no services detected
## NEIGHBORHOOD ANALYSIS
The IP is embedded in a high-abuse environment:
- Subnet: 113.212.70.0/24
- Abuse Density: 0.5547 (High)
- Classification: high_abuse
- Inherited Risk: 22
- Total Siblings: 256
- Active Siblings: 149
- Threat Siblings: 142
The /24 subnet shows concentrated risk with 142 of 256 IPs flagged as threats. All neighbor IPs in the sample display medium-level risk scores (40), indicating systemic issues within this network segment.
## OBSERVATION HISTORY
41 historical observations recorded through June 2026. Key signals include:
- Multiple threat pulse detections with 50+ pulse counts
- Consistent high-abuse subnet classification
- Recent threat activity observed within 24-hour windows
- No persistent malicious behavior pattern (threatPersistenceDays: 0)
## RELATIONSHIP GRAPH
132 relationships identified, primarily network-level associations to DATAUTAMA-NET. No external organization, hostname, or certificate relationships detected beyond the parent network block.
## RECOMMENDED ACTIONS
Based on risk score 40 and high-abuse neighborhood context, the following controls are recommended:
```bash
# iptables
iptables -A INPUT -s 113.212.70.186 -j DROP
# nftables
nft add rule inet filter input ip saddr 113.212.70.186 drop
# Cloudflare WAF
Filter: ip.src eq 113.212.70.186
Action: Block
Description: IPDebrief risk score 40
# AWS WAF
Addresses: 113.212.70.186/32
Description: IPDebrief risk 40
```
## INTELLIGENCE ASSESSMENT
The target IP represents a contextual risk rather than a confirmed threat actor. While no direct malicious activity was observed on this specific endpoint, the high-abuse density of the /24 subnet (0.5547) and the presence of 142 threat-sibling IPs suggest the network segment warrants defensive posture. The moderate risk score (40) combined with DNSBL listings indicates the IP has been flagged by reputation systems, likely due to neighborhood association.
SOC Guidance: Monitor for traffic patterns from this IP while implementing blocking controls. Consider broader subnet-level filtering (113.212.70.0/24) if operational tolerance allows, given the high-abuse classification. Maintain observation for any escalation in threat indicators.
---
*Report generated from IPDebrief intelligence platform. Data accuracy: High. Last updated: June 2026.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-DATAUTAMA-ID |
| ASN | โ |
| Network Name | DATAUTAMA-NET |
| CIDR Block | 113.212.68.0/22 |
| RIR | APNIC |
| Country | ID |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 4 |
| routing | 0% | 0 | 0 |
| services | 20% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 27% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 23% | 9 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:05:07 UTC |
| Last Seen | 2026-06-26 18:12:05 UTC |
| Profile Built | 2026-06-27 02:04:53 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 45 |
Full dossier details are available via our API.