## IP Intelligence Briefing: 113.212.70.33/32
Executive Summary
IP address 113.212.70.33 is associated with Indonesian hosting provider IRT-DATAUTAMA-ID (DATAUTAMA-NET) and presents moderate risk (score: 49). The IP is flagged as a known attacker and listed on one blacklist (blocklist.de). No active services or open ports were detected.
Ownership & Attribution
- Organization: IRT-DATAUTAMA-ID
- Network: DATAUTAMA-NET
- CIDR Block: 113.212.68.0/22
- RIR: APNIC
- Abuse Contact: Available via RDAP
Geolocation
- Country: Indonesia (ID)
- Region/City: Jakarta, Meruya Utara - Kembangan
- Accuracy: ~1500km radius
- Validation: Geo data plausible; ICMP validation attempted (blocked)
Threat Indicators
- Reputation: Moderate Risk
- Risk Score: 49
- Known Attacker: Yes
- Blacklist Count: 1
- Threat Feeds: blocklist.de
- DNSBL Listings: 1 of 8 total lists
- Tor Exit Node: No
- Hosting/Proxy/VPN: No
Network Classification
- Services: Firewalled / No Services Detected
- DNS Resolution: No PTR records or forward resolution
- Email Auth: No SPF, DMARC, or TXT records
- Operator Score: 0.1304 (Minimal)
- Route Stability: Not stable; 7 hop traceroute via Comcast
Neighborhood Analysis (Subnet: 113.212.70.33/24)
- Total Siblings: 256
- Active Siblings: 94
- Abuse Density: High (classification: high_abuse)
- Risk Distribution: Medium (86), Low (14), High (0)
- Inherited Risk: 40
- Threat Siblings: 256 detected in neighborhood
Historical Observations
- Total Signals: 42 observations
- Observation Period: Recent activity detected (June 24, 2026)
- Threat Persistence: 0 days (not persistently malicious)
- Ownership Changes: 0
- Signal Confidence: Low to moderate (0.20-0.40)
Relationships
- Network Relationships: 125 relationships identified, primarily same network (DATAUTAMA-NET)
- Campaign Correlation: No known campaigns or certificate matches
Recommended Actions
1. Block this IP at perimeter firewalls and WAFs
2. Monitor associated subnet 113.212.70.0/24 for elevated activity (high abuse density)
3. Investigate inbound connections from this IP if any were logged
4. Update blocklists with this IP address
Intelligence Confidence
Moderate confidence based on multiple corroborating threat indicators. The IP demonstrates attacker behavior patterns but lacks persistent malicious activity. Neighborhood analysis indicates elevated risk environment requiring continued monitoring.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-DATAUTAMA-ID |
| ASN | โ |
| Network Name | DATAUTAMA-NET |
| CIDR Block | 113.212.68.0/22 |
| RIR | APNIC |
| Country | ID |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 3 | 3 |
| routing | 0% | 0 | 0 |
| services | 8% | 1 | 1 |
| ownership | 24% | 2 | 3 |
| reputation | 34% | 2 | 3 |
| geolocation | 28% | 2 | 3 |
| Overall | 21% | 10 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:05:06 UTC |
| Last Seen | 2026-06-26 18:12:04 UTC |
| Profile Built | 2026-06-27 02:17:23 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 44 |
Full dossier details are available via our API.