IP INTELLIGENCE BRIEFING
Target: 118.194.249.186/32
Date: 2026-06-22
Classification: Low Risk Infrastructure Host
---
EXECUTIVE SUMMARY
IP 118.194.249.186 is classified as a low-risk infrastructure host located in Seoul, South Korea, associated with UCLOUD INFORMATION TECHNOLOGY HK LIMITED (ASN 135377). The address exhibits minimal threat indicators with a risk score of 25/100 and no active malicious campaign correlations.
OWNERSHIP & GEOLOCATION
- Organization: UCLOUD INFORMATION TECHNOLOGY HK LIMITED
- ASN: 135377
- Country: South Korea (KR)
- City: Seoul
- Geolocation Confidence: 0.28 (inferred)
- Coordinates: 35.91°N, 127.77°E
NETWORK ROLE & CLASSIFICATION
- Primary Role: Single-Service Host
- Not Classified As: Cloud service, CDN, VPN, proxy, Tor, hosting, mobile, or residential infrastructure
- Service Purpose: Single-Service Host
- Network Stability: Route stability flagged as false, suggesting potential BGP routing changes
THREAT ASSESSMENT
Threat Score: 25/100 (Low Risk)
- Abuse Confidence: Not elevated
- Blacklist Status: 0 blacklists active
- DNSBL Listed: 1 of 8 total lists
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
Threat Indicators: None detected across all monitored threat feeds.
NETWORK SERVICES
- Port 22/TCP: Open (SSH-2.0-OpenSSH_8.0)
- HTTP/HTTPS: No active web services detected
- TLS Certificate: None
- Reverse DNS: spqwt.site (forward resolution unconfirmed)
SUBNET NEIGHBORHOOD ANALYSIS
- Subnet: 118.194.249.0/24
- Abuse Density: 1 (low)
- Classification: Mostly clean
- Sibling IPs: 1 active neighbor (118.194.249.72, risk score: 0)
- Threat Siblings: 1
OBSERVATION HISTORY
Temporal Signals: 25 historical observations
- Latest Observation: 2026-06-22T10:54:12 UTC
- Threat Persistence: 0 days
- Ownership Changes: 0
- Signal Confidence Range: 0.21โ0.60
- Operator Score: 0.1304 (Minimal)
Recent signals indicate consistent geolocation attribution to South Korea with no significant changes in threat profile over the observed period.
RELATIONSHIP GRAPH
64 relationships identified, primarily:
- Same Network: UCLOUD-KR (59+ instances)
- Network associations indicate infrastructure clustering within UCLOUD-KR network
SECURITY RECOMMENDATIONS
Current Risk Profile: Low
- No immediate blocking recommended based on current risk score and threat indicators
- Monitoring: Standard monitoring appropriate given the single-service host classification
- Firewall Rules: None generated (risk score below threshold for automated action)
- Email Reputation: No score available (no email infrastructure detected)
ACTIONABLE INTELLIGENCE
1. Traffic Analysis: SSH service on port 22 indicates potential administrative access; monitor for unusual access patterns
2. DNS Validation: Reverse DNS points to spqwt.site with unconfirmed forward resolution; monitor for DNS-based attacks
3. Network Context: Part of UCLOUD-KR infrastructure cluster; consider cluster-wide threat correlation
4. Threat Level: Current assessment indicates low probability of malicious activity; maintain baseline monitoring
---
ASSESSMENT: This IP represents a low-risk infrastructure host with no active threat indicators. Routine monitoring is sufficient. No immediate defensive actions required beyond standard network hygiene practices.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | UCLOUD INFORMATION TECHNOLOGY HK LIMITED |
| ASN | AS135377 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | APNIC |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | spqwt.site |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | spqwt.site |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_8.0 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 24% | 2 | 3 |
| ownership | 24% | 2 | 3 |
| reputation | 21% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 21% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:34 UTC |
| Last Seen | 2026-06-22 10:52:54 UTC |
| Profile Built | 2026-06-22 11:00:28 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 25 |
Full dossier details are available via our API.