# IP Intelligence Briefing: 116.110.10.20/32
Classification: Moderate Risk | Jurisdiction: Vietnam (VN) | Organization: VIETTEL-VN (ASN 24086)
## Executive Summary
IP address 116.110.10.20 is registered to Vietnam's Viettel network infrastructure and presents a moderate risk profile (risk score: 40). The IP has no active services exposed, no open ports detected, and no evidence of malicious activity. However, the IP shows DNSBL listings on two of eight monitored threat feeds. The surrounding /24 subnet demonstrates clean characteristics with zero abuse density and no threat-classified sibling IPs.
## Infrastructure Profile
Ownership & Registration:
- Organization: IRT-VNNIC-AP
- Netname: VIETTEL-VN
- ASN: 24086
- CIDR Block: 116.96.0.0/12
- RIR: APNIC
- BGP Prefix: 116.110.8.0/21
Geolocation:
- Country: Vietnam (VN)
- Region/City: Da Nang
- Accuracy Radius: 600 km
- Timezone: Asia/Ho_Chi_Minh
Network Classification:
- Service Purpose: Firewalled / No Services
- Cloud/CDN/Proxy/VPN/Hosting: Negative indicators
- IP Type: None identified
- Bogon Status: Not applicable
## Threat Assessment
Current Indicators:
- Risk Score: 40 (Moderate Risk)
- Abuse Confidence Score: Not applicable
- Blacklist Status: 0 explicit blacklists
- DNSBL Listings: 2 of 8 total lists
- Threat Indicators: None detected
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Behavioral Analysis:
- Open Ports: None detected
- TLS Certificates: None
- HTTP Services: None
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
- Total Incidents: 0
## Subnet Neighborhood Analysis (116.110.10.0/24)
Subnet Health:
- Abuse Density: 0.0 (Clean)
- Classification: Clean
- Total Siblings: 10
- Active Siblings: 4
- Threat Siblings: 0
Neighbor Risk Distribution:
- High Risk: 0 IPs
- Medium Risk: 2 IPs (116.110.10.22, 116.110.10.255)
- Low Risk: 7 IPs
- Average Neighbor Risk Score: 27.1
Notable neighbors include 116.110.10.22 (risk: 40) and 116.110.10.255 (risk: 40), both sharing the same risk profile as the subject IP.
## Historical Observations
Signal History:
- Total Observations: 14
- Most Recent: 2026-07-29T16:00:07 UTC
- Threat Persistence Days: 0
- Ownership Changes: 0
- Average Ownership Duration: Not applicable
Temporal Indicators:
- The IP shows no persistent malicious behavior
- Threat observation count: 0
- The IP is not flagged as persistently malicious
- Control plane shows route instability (isRouteStable: false) with 0 route changes in 30 days
## Relationships
Identified Associations:
- 3 relationships detected, all pointing to VIETTEL-VN network
- All relationships categorized as "Same Network"
- No external entity associations (hostnames, certificates, organizations beyond network)
## Recommended Actions
Firewall/Blocking Rules:
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 116.110.10.20 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 116.110.10.20 drop` |
| nginx | `deny 116.110.10.20;` |
| pfSense | `116.110.10.20/32` |
| Cloudflare WAF | Block IP with risk score 40 |
| AWS WAF | Add 116.110.10.20/32 to blacklist |
Analyst Notes:
- Risk score 40 indicates moderate risk requiring verification before blocking
- DNSBL listings present on 2 of 8 feeds warrant review
- No active services detected reduces immediate threat likelihood
- Subnet environment is clean with no threat-sibling correlation
- Recommended to monitor rather than block unless additional threat signals emerge
Risk Mitigation Recommendation: Monitor traffic patterns and threat intelligence feeds for escalation. Current data suggests defensive posture is appropriate but immediate blocking may not be warranted without additional corroborating evidence.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-VNNIC-AP |
| ASN | AS24086 |
| Network Name | VIETTEL-VN |
| CIDR Block | 116.96.0.0/12 |
| RIR | APNIC |
| Country | VN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 50% | 2 | 3 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 25% | 6 | 7 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-23 01:40:33 UTC |
| Last Seen | 2026-07-29 15:54:05 UTC |
| Profile Built | 2026-07-29 16:08:28 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.