IPDebrief

120.51.38.52

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 120.51.38.52/32

Classification: LOW RISK

Report Date: Current

Analysis Period: Full profile assessment with historical signal review

## Executive Summary

IP 120.51.38.52 presents a low-risk threat profile with no active malicious indicators. The address resolves to a Japanese infrastructure endpoint with firewalled services and minimal historical threat observations. No immediate defensive actions recommended based on current signal analysis.

## Technical Profile

Geolocation: Japan (Tokyo, Chiba region)

ASN: 2519

BGP Prefix: 120.51.0.0/18

Timezone: Asia/Tokyo

Network Classification: Firewalled / No Services

DNS Resolution: s52.HtokyoFL34.vectant.ne.jp (ne.jp domain)

PTR Record: Forward confirmed with single hostname mapping

DNSSEC Status: Valid

Network Reachability:

## Threat Indicators

Risk Assessment:

Threat Classification:

Service Exposure: No open ports detected; services appear to be actively firewalled or not running.

## Historical Signal Analysis

Observation Count: 11 signals recorded

Recent Activity: Signals observed as of 2026-07-28

Signal Breakdown:

Temporal Analysis: No evidence of persistent malicious behavior. Ownership changes recorded at 0. Threat observation count: 0.

## Relationship Graph

Associated Entities: 1

No additional organizational, certificate, or subnet relationships detected.

## Subnet Analysis (120.51.38.0/24)

Subnet Characteristics:

Notable Neighbor: 120.51.38.55

The target IP shares the /24 subnet with one additional address showing elevated risk metrics. This warrants monitoring but does not indicate correlation with malicious activity.

## Recommended Security Actions

Current Status: No automated firewall rules or blocking recommendations generated.

Suggested Actions:

1. Monitor subnet 120.51.38.0/24 for any escalation in neighbor 120.51.38.55's activity

2. No immediate blocking required for 120.51.38.52

3. Continue standard network monitoring procedures

## Conclusion

IP 120.51.38.52 is classified as low-risk with no active threat indicators. The address appears to be a legitimate Japanese infrastructure endpoint with firewalled services. Historical signals show no escalation in malicious behavior. No immediate defensive actions required, but maintain awareness of elevated-risk neighbor within the same /24 subnet.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇯🇵 Japan
Region13
CityTokyo
TimezoneAsia/Tokyo
Latitude35.97
Longitude138.89

🏢 Ownership & Registration

OrganizationJapan Network Information Center
ASNAS2519
Network NameV-FLETS
CIDR Block120.51.38.0/24
RIRAPNIC
CountryJP
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRs52.HtokyoFL34.vectant.ne.jp
Forward ConfirmedYes — FCrDNS verified
Forward Hostnamess52.HtokyoFL34.vectant.ne.jp

🔐 DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierTier 3 — Basic operator with some routing infrastructure
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS2519
Network Prefix120.51.0.0/18
Route mappingFound
RPKI StatusValid

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
21%
24
routing
18%
22
services
12%
22
ownership
17%
23
reputation
8%
12
geolocation
35%
23
Overall19%1116
Coverage: 3/6 dimensions · Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionHigh (85%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

📅 Observation Timeline 🔄 Live

First Seen2026-07-17 17:11:49 UTC
Last Seen2026-09-03 07:37:49 UTC
Profile Built2026-09-01 09:11:40 UTC
Data FreshnessLive
Signal Types24
Total Observations31
🔍 24 signal types · 31 observations collected
This report is generated from 24+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 120.51.38.52

Who owns the IP address 120.51.38.52?

120.51.38.52 is registered to Japan Network Information Center. The address falls within the 120.51.38.0/24 network block. Registration is held at APNIC.

Where is 120.51.38.52 located?

Geolocation data places 120.51.38.52 in Tokyo, 13, Japan. The local time zone is Asia/Tokyo. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 120.51.38.52 malicious or safe?

120.51.38.52 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.

What is the hostname for 120.51.38.52?

The reverse DNS (PTR) record for 120.51.38.52 is s52.HtokyoFL34.vectant.ne.jp. This hostname is forward-confirmed, meaning it resolves back to the same address.

🏘️ Related IP Addresses

Nearby addresses in 120.51.38.0/24

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.