Threat Intelligence Briefing for IP 116.99.173.235/32
Observation History:
The IP address 116.99.173.235/32 has been observed in various online activities primarily associated with web traffic. Historical data indicates regular interaction with multiple domains, suggesting its use in standard internet browsing or hosting services. The traffic patterns show consistent outbound activity, which may indicate the hosting of content or services that are frequently accessed by users or automated systems.
Relationships:
The IP address has been linked to a range of domains, including both legitimate and potentially malicious sites. Some associated domains have been flagged in cybersecurity databases for hosting phishing attempts or distributing malware. These associations suggest that the IP address might be leveraged for malicious purposes, either as a hosting server or as part of a larger botnet infrastructure.
Neighborhood Data:
Analysis of neighboring IP addresses reveals a mixed environment. Several adjacent IPs are associated with known content delivery networks (CDNs), indicating possible legitimate use for content distribution. However, a number of neighboring IPs have also been identified in past cybersecurity incidents, including data breaches and distributed denial-of-service (DDoS) attacks. This mixed neighborhood suggests a potential risk of exploitation by malicious actors seeking to blend into a legitimate network environment.
Actionable Intelligence:
- Monitoring: Continuous monitoring of traffic patterns originating from and directed to 116.99.173.235/32 is recommended. Look for anomalies in traffic volume, frequency, or destination that could indicate malicious activity.
- Domain Analysis: Conduct further analysis of domains associated with this IP to identify any potential phishing or malware distribution activities. Implement DNS filtering to block access to known malicious domains.
- Network Segmentation: Consider network segmentation strategies to isolate traffic related to this IP, reducing potential exposure to malicious activities.
- Incident Response Preparedness: Ensure that incident response plans are updated to address potential threats originating from or targeting this IP address.
This intelligence briefing provides a comprehensive overview of the current understanding of IP 116.99.173.235/32, highlighting potential risks and recommended actions for SOC teams.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-VNNIC-AP |
| ASN | AS24086 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | APNIC |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | dynamic-ip-adsl.viettel.vn |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | dynamic-adsl.viettel.vn |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 24% | 2 | 3 |
| ownership | 30% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 24% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:33 UTC |
| Last Seen | 2026-06-22 10:21:49 UTC |
| Profile Built | 2026-06-22 10:43:01 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 32 |
Full dossier details are available via our API.