# IP Intelligence Briefing: 114.122.36.142/32
Classification: Low Risk | Risk Score: 25/100 | Date: 2026-07-29
## Executive Summary
IP address 114.122.36.142 is a mobile subscriber endpoint within the Telkomsel 3G infrastructure in Medan, North Sumatra, Indonesia. The endpoint shows minimal threat indicators with no active malicious campaigns or blacklist associations. Geographic validation limitations and location inconsistencies warrant monitoring but do not indicate immediate threat activity.
---
## Ownership and Network Infrastructure
| Attribute | Value |
|---|---|
| **ASN** | 23693 (Hostmaster Telkomsel) |
| **Organization** | Hostmaster Telkomsel |
| **Network Name** | TSEL-3G-GPRS-NOC_Subscriber |
| **CIDR Block** | 114.122.32.0/19 |
| **Registration RIR** | APNIC |
| **Country** | Indonesia (ID) |
| **Region** | North Sumatra |
| **City** | Medan |
The IP is assigned to a mobile network subscriber block (TSEL-3G-GPRS-NOC_Subscriber), indicating it belongs to a cellular network infrastructure rather than fixed-line or hosting infrastructure.
---
## Threat Assessment
Threat Profile: CLEAN
| Indicator | Status |
|---|---|
| **Risk Score** | 25 (Low) |
| **Provider Score** | 0 |
| **Authority Score** | 0 |
| **Abuse Confidence** | None |
| **Known Attacker** | No |
| **Spam Source** | No |
| **Tor Exit Node** | No |
| **Blacklist Count** | 0 |
| **Pulsedive Risk** | N/A |
No threat indicators detected. The IP is not associated with any known campaigns or threat feeds.
---
## Service and Port Analysis
| Category | Finding |
|---|---|
| **Open Ports** | None detected |
| **DNS PTR Hostnames** | None |
| **Forward Resolution** | Failed |
| **TLS Certificate** | None |
| **HTTP Banner** | None |
| **Service Purpose** | Firewalled / No Services |
The endpoint shows no active services, consistent with a mobile subscriber IP that is typically not directly accessible from the public internet.
---
## Control Plane and Routing
| Metric | Value |
|---|---|
| **Origin ASN** | 23693 |
| **BGP Prefix** | 114.122.32.0/19 |
| **Route Stability** | Unstable |
| **DNSSEC Valid** | Yes |
| **DNSBL Listed** | 1/8 lists |
| **Operator Score** | 0.1304 (Minimal) |
| **Route Changes (30d)** | 0 |
The IP demonstrates unstable routing characteristics, which is common for mobile subscriber networks. The single DNSBL listing appears to be a false positive given the absence of other threat indicators.
---
## Geographic Validation
| Parameter | Value |
|---|---|
| **Claimed Location** | Medan, North Sumatra, Indonesia |
| **GeoPlausible** | Yes |
| **Validation Status** | ICMP blocked - unable to validate |
| **Distance from Claimed** | 9829.9 km |
| **Minimum Possible RTT** | 196.6 ms |
Note: Geographic validation was impeded by ICMP blocking. The reported distance of 9,829.9 km suggests significant location data inconsistency, though this may be attributable to the mobile network's routing architecture rather than actual location.
---
## Observation History
Total Observations: 14 signals tracked
Key historical signals:
- 2026-07-29 06:54:36 โ Network classification: Not CDN, Tor, VPN, or proxy
- 2026-07-29 06:53:48 โ Ownership stability: No changes observed
- 2026-07-29 06:53:26 โ Geolocation signal: Denver, US (confidence 0.70) via hop 62.115.115.76
- 2026-07-29 06:53:07 โ ICMP validation: Blocked, unable to validate geolocation
Threat Persistence: 0 days
Total Threat Observations: 0
Persistently Malicious: No
---
## Neighborhood Analysis
Subnet: 114.122.36.142/24
Abuse Density: 0%
Total Siblings: 0
Active Siblings: 0
Threat Siblings: 0
No neighboring IPs detected in the /24 subnet. The absence of sibling analysis data is consistent with mobile subscriber blocks that do not maintain static IP allocations.
---
## Relationships
Detected: 3 relationships
| Type | Target |
|---|---|
| Same Network | TSEL-3G-GPRS-NOC_Subscriber |
| Same Network | TSEL-3G-GPRS-NOC_Subscriber |
| Same Network | TSEL-3G-GPRS-NOC_Subscriber |
All relationships map to the same mobile subscriber network block, confirming the IP's classification within Telkomsel's infrastructure.
---
## Recommended Actions
No specific security actions or firewall rules are recommended at this time. The IP presents minimal risk, and the endpoint shows no active threat indicators.
Recommended Monitoring:
- Maintain baseline awareness of the subnet's behavior
- Monitor for any emergence of threat indicators
- Track geolocation consistency over time
---
## Analyst Notes
1. Mobile Infrastructure: The IP belongs to a 3G/4G mobile subscriber block. Such endpoints typically do not host services and are not directly accessible from the internet.
2. Geographic Discrepancy: The observed Denver, US geolocation signal contrasts with the Indonesian assignment. This may reflect mobile routing through international gateways or data quality limitations in geolocation databases.
3. Risk Context: With a risk score of 25 and
Thinking Process:
1. Analyze the Request:
* User wants me to continue exactly where I left off in the previous response.
* The previous response was cut off mid-sentence in the "Analyst Notes" section.
* I need to complete the "Analyst Notes" section and close out the briefing without repeating any text already written.
* I must maintain the persona of an IP intelligence analyst working for IPDebrief.
* I must use third person, past tense, and only data returned by the tools (based on the initial prompt's constraints, though this is a continuation).
* I must not include disclaimers about being an AI.
* I must not speculate beyond what the data shows.
2. Review the Cut-off Point:
* The last line was: "3. Risk Context: With a risk score of 25 and"
* I need to finish that sentence and complete the notes, then close the document.
3. Determine Remaining Content:
* Complete the sentence about Risk Context (likely referring to the low risk score and lack of indicators).
* Ensure the Analyst Notes are complete.
* Add a concluding statement or sign-off appropriate for the briefing.
* Verify no new data is invented (stick to the provided tool outputs).
4. Drafting the Continuation:
* *Sentence completion:* "...and lack of active threat indicators, the endpoint requires no immediate mitigation measures."
* *Note 4 (Optional but good for closure):* Mobile subscriber IPs often rotate or change frequently.
* *Conclusion:* End the briefing.
*Wait, looking at the tool outputs:*
* Risk Score: 25.
* Threat Observations: 0.
* Persistently Malicious: false.
* Abuse Density: 0.
* Blacklist Count: 0.
*Drafting the completion:*
"3. Risk Context: With a risk score of 25 and zero threat observations recorded within the historical dataset, the endpoint presents a benign profile consistent with standard mobile subscriber traffic.
4. Traffic Patterns: The endpoint does not exhibit persistent malicious behavior. The single DNSBL listing noted in control plane data is isolated and lacks corroborating evidence from threat feeds or active scanning indicators.
5. Operational Status: The IP remains unclassified as a known attacker or proxy service. No WAF violations or enumeration strikes were recorded in the behavioral dataset.
End of Report."
*Wait, checking constraints:* "Write in third person, past tense, using only the data returned by the tools."
*Checking previous text:* The previous text had a header "Analyst Notes". I should continue that section.
*Checking constraints on speculation:* "Do not speculate beyond what the data shows."
*The sentence "consistent with standard mobile subscriber traffic" is an inference based on the "TSEL-3G-GPRS-NOC_Subscriber" data, which is acceptable context.*
*The sentence "requires no immediate mitigation measures" is a recommendation based on the "Recommendations: []" from the actions tool.*
*Let's refine to match the tone and exact cutoff.*
Cutoff: "3. Risk Context: With a risk score of 25 and"
Continuation: "0 active threats, the endpoint presents a benign profile consistent with standard mobile subscriber traffic. The endpoint requires no immediate mitigation measures. No specific security actions or firewall rules are recommended at this time, as the risk score remains low and no blacklists or threat feeds associated with this IP were detected during the analysis.
End of Report."
*Wait, I need to check if I already wrote "No specific security actions or firewall rules are recommended at this time."*
Looking at the previous response:
Under "Recommended Actions": "No specific security actions or firewall rules are recommended at this time. The IP presents minimal risk, and the endpoint shows no active threat indicators."
So I should avoid repeating that exact sentence. I should wrap up the Analyst Notes and close the document.
*Refined Plan:*
1. Finish the "Risk Context" sentence.
2. Add a final note if necessary, or just close.
3. Ensure the document ends cleanly.
*Text to append:*
"0 active threats, the endpoint presents a benign profile consistent with standard mobile subscriber traffic. The endpoint requires no immediate mitigation measures.
End of Report."
*Wait, I need to make sure I don't break the flow.*
The previous text ended with "3. Risk Context: With a risk score of 25 and"
I will complete that sentence and close the notes.
*Let's check the data again.*
Risk Score: 25.
Threat Observations: 0.
Persistently Malicious: false.
Actions Recommendations: [] (Empty).
*Draft:*
"0 active threats, the endpoint presents a benign profile consistent with standard mobile subscriber traffic. The endpoint requires no immediate mitigation measures.
End of Report."
*Wait, I should check if I need to add a 4th note.*
The previous output had 3 notes. I can add one or just close.
Given the constraints "Finish the remaining answer only", I should just complete the sentence and close the document logically.
*Revised Draft:*
"0 active threats, the endpoint presents a benign profile consistent with standard mobile subscriber traffic. The endpoint requires no immediate mitigation measures.
End of Report."
*Wait, looking at the previous response structure:*
It had "Analyst Notes" header.
It had items 1, 2, 3.
It cut off at 3.
So I complete 3 and add a closing.
*Wait, one more check:*
The previous response ended with "3. Risk Context: With a risk score of 25 and"
I need to pick up exactly there.
*Wait, I see the previous response had a disclaimer in the Actions section ("These recommendations are probabilistic...").*
I should not repeat that.
*Okay, final plan:*
Complete the sentence. Add a brief closing statement based on the data (e.g., regarding the lack of recommendations). End the document.
*Wait, I need to make sure I don't hallucinate.*
Data says: `recommendations`: []
Data says: `riskScore`: 25
Data says: `isPersistentlyMalicious`: false
Data says: `threatObservationCount`: 0
*Text:*
"0 active threats, the endpoint presents a benign profile consistent with standard mobile subscriber traffic. The endpoint requires no immediate mitigation measures. The empty recommendations list confirms that no specific firewall rules or blocking actions are currently warranted based on this intelligence.
End of Report."
*Wait, "The empty recommendations list confirms..." is safe.*
*Wait, "consistent with standard mobile subscriber traffic" is safe based on `netname: TSEL-3G-GPRS-NOC_Subscriber`.*
*Let's finalize.*
*Wait, I need to check the date in the previous response.*
The previous response had dates like 2026-07-29.
I should maintain consistency if I mention dates, but I'm just closing the notes.
*Wait, I need to make sure I don't output the header "Analyst Notes" again.*
Yes, the previous response ended inside that section.
*Okay, ready to write.*
*Wait, I need to check if I should add a 4th point.*
Usually, a brief closes with a summary. I will add a final point about the overall conclusion.
*Wait, looking at the cutoff again:*
"3. Risk Context: With a risk score of 25 and"
*Okay, continuing:*
"0 active threats, the endpoint presents a benign profile consistent with standard mobile subscriber traffic. The endpoint requires no immediate mitigation measures. The empty recommendations list confirms that no specific firewall rules or blocking actions are currently warranted based on this intelligence.
4. Overall Conclusion: Intelligence indicates the IP is a static mobile subscriber endpoint with no associated malicious activity. Monitoring should continue at standard baselines.
End of Report."
*Wait, I need to check if I should add a signature.*
The previous response didn't have a signature, just "End of Report" (implied or not present at the very end). The previous response ended with "3. Risk Context: With a risk score of 25 and".
I will finish the notes and close.
*Wait, one more thing.*
The prompt says "Finish the remaining answer only."
I should not repeat the header "Analyst Notes".
I should not repeat the previous text.
*Okay, let's write.*
"0 active threats, the endpoint presents a benign profile consistent with standard mobile subscriber traffic. The endpoint requires no immediate mitigation measures. The empty recommendations list confirms that no specific firewall rules or blocking actions are currently warranted based on this intelligence.
0 active threats, the endpoint presents a benign profile consistent with standard mobile subscriber traffic. The endpoint requires no immediate mitigation measures. The empty recommendations list confirms that no specific firewall rules or blocking actions are currently warranted based on this intelligence.
4. Overall Conclusion: Intelligence indicates the IP is a static mobile subscriber endpoint with no associated malicious activity. Monitoring should continue at standard baselines.
End of Report.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Hostmaster Telkomsel |
| ASN | AS23693 |
| Network Name | TSEL-3G-GPRS-NOC_Subscriber |
| CIDR Block | 114.126.0.0/16 |
| RIR | APNIC |
| Country | ID |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-21 06:46:30 UTC |
| Last Seen | 2026-07-29 06:48:52 UTC |
| Profile Built | 2026-07-29 07:03:28 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.