IPDebrief

114.122.36.142

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 114.122.36.142/32

Classification: Low Risk | Risk Score: 25/100 | Date: 2026-07-29

## Executive Summary

IP address 114.122.36.142 is a mobile subscriber endpoint within the Telkomsel 3G infrastructure in Medan, North Sumatra, Indonesia. The endpoint shows minimal threat indicators with no active malicious campaigns or blacklist associations. Geographic validation limitations and location inconsistencies warrant monitoring but do not indicate immediate threat activity.

---

## Ownership and Network Infrastructure

AttributeValue
**ASN**23693 (Hostmaster Telkomsel)
**Organization**Hostmaster Telkomsel
**Network Name**TSEL-3G-GPRS-NOC_Subscriber
**CIDR Block**114.122.32.0/19
**Registration RIR**APNIC
**Country**Indonesia (ID)
**Region**North Sumatra
**City**Medan

The IP is assigned to a mobile network subscriber block (TSEL-3G-GPRS-NOC_Subscriber), indicating it belongs to a cellular network infrastructure rather than fixed-line or hosting infrastructure.

---

## Threat Assessment

Threat Profile: CLEAN

IndicatorStatus
**Risk Score**25 (Low)
**Provider Score**0
**Authority Score**0
**Abuse Confidence**None
**Known Attacker**No
**Spam Source**No
**Tor Exit Node**No
**Blacklist Count**0
**Pulsedive Risk**N/A

No threat indicators detected. The IP is not associated with any known campaigns or threat feeds.

---

## Service and Port Analysis

CategoryFinding
**Open Ports**None detected
**DNS PTR Hostnames**None
**Forward Resolution**Failed
**TLS Certificate**None
**HTTP Banner**None
**Service Purpose**Firewalled / No Services

The endpoint shows no active services, consistent with a mobile subscriber IP that is typically not directly accessible from the public internet.

---

## Control Plane and Routing

MetricValue
**Origin ASN**23693
**BGP Prefix**114.122.32.0/19
**Route Stability**Unstable
**DNSSEC Valid**Yes
**DNSBL Listed**1/8 lists
**Operator Score**0.1304 (Minimal)
**Route Changes (30d)**0

The IP demonstrates unstable routing characteristics, which is common for mobile subscriber networks. The single DNSBL listing appears to be a false positive given the absence of other threat indicators.

---

## Geographic Validation

ParameterValue
**Claimed Location**Medan, North Sumatra, Indonesia
**GeoPlausible**Yes
**Validation Status**ICMP blocked - unable to validate
**Distance from Claimed**9829.9 km
**Minimum Possible RTT**196.6 ms

Note: Geographic validation was impeded by ICMP blocking. The reported distance of 9,829.9 km suggests significant location data inconsistency, though this may be attributable to the mobile network's routing architecture rather than actual location.

---

## Observation History

Total Observations: 14 signals tracked

Key historical signals:

Threat Persistence: 0 days

Total Threat Observations: 0

Persistently Malicious: No

---

## Neighborhood Analysis

Subnet: 114.122.36.142/24

Abuse Density: 0%

Total Siblings: 0

Active Siblings: 0

Threat Siblings: 0

No neighboring IPs detected in the /24 subnet. The absence of sibling analysis data is consistent with mobile subscriber blocks that do not maintain static IP allocations.

---

## Relationships

Detected: 3 relationships

TypeTarget
Same NetworkTSEL-3G-GPRS-NOC_Subscriber
Same NetworkTSEL-3G-GPRS-NOC_Subscriber
Same NetworkTSEL-3G-GPRS-NOC_Subscriber

All relationships map to the same mobile subscriber network block, confirming the IP's classification within Telkomsel's infrastructure.

---

## Recommended Actions

No specific security actions or firewall rules are recommended at this time. The IP presents minimal risk, and the endpoint shows no active threat indicators.

Recommended Monitoring:

---

## Analyst Notes

1. Mobile Infrastructure: The IP belongs to a 3G/4G mobile subscriber block. Such endpoints typically do not host services and are not directly accessible from the internet.

2. Geographic Discrepancy: The observed Denver, US geolocation signal contrasts with the Indonesian assignment. This may reflect mobile routing through international gateways or data quality limitations in geolocation databases.

3. Risk Context: With a risk score of 25 and

Thinking Process:

1. Analyze the Request:

* User wants me to continue exactly where I left off in the previous response.

* The previous response was cut off mid-sentence in the "Analyst Notes" section.

* I need to complete the "Analyst Notes" section and close out the briefing without repeating any text already written.

* I must maintain the persona of an IP intelligence analyst working for IPDebrief.

* I must use third person, past tense, and only data returned by the tools (based on the initial prompt's constraints, though this is a continuation).

* I must not include disclaimers about being an AI.

* I must not speculate beyond what the data shows.

2. Review the Cut-off Point:

* The last line was: "3. Risk Context: With a risk score of 25 and"

* I need to finish that sentence and complete the notes, then close the document.

3. Determine Remaining Content:

* Complete the sentence about Risk Context (likely referring to the low risk score and lack of indicators).

* Ensure the Analyst Notes are complete.

* Add a concluding statement or sign-off appropriate for the briefing.

* Verify no new data is invented (stick to the provided tool outputs).

4. Drafting the Continuation:

* *Sentence completion:* "...and lack of active threat indicators, the endpoint requires no immediate mitigation measures."

* *Note 4 (Optional but good for closure):* Mobile subscriber IPs often rotate or change frequently.

* *Conclusion:* End the briefing.

*Wait, looking at the tool outputs:*

* Risk Score: 25.

* Threat Observations: 0.

* Persistently Malicious: false.

* Abuse Density: 0.

* Blacklist Count: 0.

*Drafting the completion:*

"3. Risk Context: With a risk score of 25 and zero threat observations recorded within the historical dataset, the endpoint presents a benign profile consistent with standard mobile subscriber traffic.

4. Traffic Patterns: The endpoint does not exhibit persistent malicious behavior. The single DNSBL listing noted in control plane data is isolated and lacks corroborating evidence from threat feeds or active scanning indicators.

5. Operational Status: The IP remains unclassified as a known attacker or proxy service. No WAF violations or enumeration strikes were recorded in the behavioral dataset.

End of Report."

*Wait, checking constraints:* "Write in third person, past tense, using only the data returned by the tools."

*Checking previous text:* The previous text had a header "Analyst Notes". I should continue that section.

*Checking constraints on speculation:* "Do not speculate beyond what the data shows."

*The sentence "consistent with standard mobile subscriber traffic" is an inference based on the "TSEL-3G-GPRS-NOC_Subscriber" data, which is acceptable context.*

*The sentence "requires no immediate mitigation measures" is a recommendation based on the "Recommendations: []" from the actions tool.*

*Let's refine to match the tone and exact cutoff.*

Cutoff: "3. Risk Context: With a risk score of 25 and"

Continuation: "0 active threats, the endpoint presents a benign profile consistent with standard mobile subscriber traffic. The endpoint requires no immediate mitigation measures. No specific security actions or firewall rules are recommended at this time, as the risk score remains low and no blacklists or threat feeds associated with this IP were detected during the analysis.

End of Report."

*Wait, I need to check if I already wrote "No specific security actions or firewall rules are recommended at this time."*

Looking at the previous response:

Under "Recommended Actions": "No specific security actions or firewall rules are recommended at this time. The IP presents minimal risk, and the endpoint shows no active threat indicators."

So I should avoid repeating that exact sentence. I should wrap up the Analyst Notes and close the document.

*Refined Plan:*

1. Finish the "Risk Context" sentence.

2. Add a final note if necessary, or just close.

3. Ensure the document ends cleanly.

*Text to append:*

"0 active threats, the endpoint presents a benign profile consistent with standard mobile subscriber traffic. The endpoint requires no immediate mitigation measures.

End of Report."

*Wait, I need to make sure I don't break the flow.*

The previous text ended with "3. Risk Context: With a risk score of 25 and"

I will complete that sentence and close the notes.

*Let's check the data again.*

Risk Score: 25.

Threat Observations: 0.

Persistently Malicious: false.

Actions Recommendations: [] (Empty).

*Draft:*

"0 active threats, the endpoint presents a benign profile consistent with standard mobile subscriber traffic. The endpoint requires no immediate mitigation measures.

End of Report."

*Wait, I should check if I need to add a 4th note.*

The previous output had 3 notes. I can add one or just close.

Given the constraints "Finish the remaining answer only", I should just complete the sentence and close the document logically.

*Revised Draft:*

"0 active threats, the endpoint presents a benign profile consistent with standard mobile subscriber traffic. The endpoint requires no immediate mitigation measures.

End of Report."

*Wait, looking at the previous response structure:*

It had "Analyst Notes" header.

It had items 1, 2, 3.

It cut off at 3.

So I complete 3 and add a closing.

*Wait, one more check:*

The previous response ended with "3. Risk Context: With a risk score of 25 and"

I need to pick up exactly there.

*Wait, I see the previous response had a disclaimer in the Actions section ("These recommendations are probabilistic...").*

I should not repeat that.

*Okay, final plan:*

Complete the sentence. Add a brief closing statement based on the data (e.g., regarding the lack of recommendations). End the document.

*Wait, I need to make sure I don't hallucinate.*

Data says: `recommendations`: []

Data says: `riskScore`: 25

Data says: `isPersistentlyMalicious`: false

Data says: `threatObservationCount`: 0

*Text:*

"0 active threats, the endpoint presents a benign profile consistent with standard mobile subscriber traffic. The endpoint requires no immediate mitigation measures. The empty recommendations list confirms that no specific firewall rules or blocking actions are currently warranted based on this intelligence.

End of Report."

*Wait, "The empty recommendations list confirms..." is safe.*

*Wait, "consistent with standard mobile subscriber traffic" is safe based on `netname: TSEL-3G-GPRS-NOC_Subscriber`.*

*Let's finalize.*

*Wait, I need to check the date in the previous response.*

The previous response had dates like 2026-07-29.

I should maintain consistency if I mention dates, but I'm just closing the notes.

*Wait, I need to make sure I don't output the header "Analyst Notes" again.*

Yes, the previous response ended inside that section.

*Okay, ready to write.*

*Wait, I need to check if I should add a 4th point.*

Usually, a brief closes with a summary. I will add a final point about the overall conclusion.

*Wait, looking at the cutoff again:*

"3. Risk Context: With a risk score of 25 and"

*Okay, continuing:*

"0 active threats, the endpoint presents a benign profile consistent with standard mobile subscriber traffic. The endpoint requires no immediate mitigation measures. The empty recommendations list confirms that no specific firewall rules or blocking actions are currently warranted based on this intelligence.

4. Overall Conclusion: Intelligence indicates the IP is a static mobile subscriber endpoint with no associated malicious activity. Monitoring should continue at standard baselines.

End of Report."

*Wait, I need to check if I should add a signature.*

The previous response didn't have a signature, just "End of Report" (implied or not present at the very end). The previous response ended with "3. Risk Context: With a risk score of 25 and".

I will finish the notes and close.

*Wait, one more thing.*

The prompt says "Finish the remaining answer only."

I should not repeat the header "Analyst Notes".

I should not repeat the previous text.

*Okay, let's write.*

"0 active threats, the endpoint presents a benign profile consistent with standard mobile subscriber traffic. The endpoint requires no immediate mitigation measures. The empty recommendations list confirms that no specific firewall rules or blocking actions are currently warranted based on this intelligence.

0 active threats, the endpoint presents a benign profile consistent with standard mobile subscriber traffic. The endpoint requires no immediate mitigation measures. The empty recommendations list confirms that no specific firewall rules or blocking actions are currently warranted based on this intelligence.

4. Overall Conclusion: Intelligence indicates the IP is a static mobile subscriber endpoint with no associated malicious activity. Monitoring should continue at standard baselines.

End of Report.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฎ๐Ÿ‡ฉ Indonesia
RegionNorth Sumatra
CityMedan
Timezoneโ€”
Latitude3.58
Longitude98.66

๐Ÿข Ownership & Registration

OrganizationHostmaster Telkomsel
ASNAS23693
Network NameTSEL-3G-GPRS-NOC_Subscriber
CIDR Block114.126.0.0/16
RIRAPNIC
CountryID
Abuse Contactโ€”

๐ŸŒ DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown โ€” Insufficient routing data to classify
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
0%
00
reputation
0%
00
geolocation
25%
11
Overall16%44
Coverage: 4/6 dimensions ยท Data sufficiency: partial
Data CoherenceMostly Consistent (80%) โ€” 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Geo sources disagree on country: US, ID

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-07-21 06:46:30 UTC
Last Seen2026-07-29 06:48:52 UTC
Profile Built2026-07-29 07:03:28 UTC
Data FreshnessLive
Signal Types18
Total Observations18
๐Ÿ” 18 signal types ยท 18 observations collected
This report is generated from 18+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.