# IP Intelligence Briefing: 120.51.38.52/32
Classification: LOW RISK
Report Date: Current
Analysis Period: Full profile assessment with historical signal review
## Executive Summary
IP 120.51.38.52 presents a low-risk threat profile with no active malicious indicators. The address resolves to a Japanese infrastructure endpoint with firewalled services and minimal historical threat observations. No immediate defensive actions recommended based on current signal analysis.
## Technical Profile
Geolocation: Japan (Tokyo, Chiba region)
ASN: 2519
BGP Prefix: 120.51.0.0/18
Timezone: Asia/Tokyo
Network Classification: Firewalled / No Services
DNS Resolution: s52.HtokyoFL34.vectant.ne.jp (ne.jp domain)
PTR Record: Forward confirmed with single hostname mapping
DNSSEC Status: Valid
Network Reachability:
- Traceroute: 14 hops
- Transit networks: Comcast, Lumen
- Minimum possible RTT: Not measured
## Threat Indicators
Risk Assessment:
- Overall Risk Score: 0 (Low Risk)
- Provider Score: 0
- Authority Score: 0
- Stability Score: 0
Threat Classification:
- Not a Tor exit node
- Not a known attacker
- Not a spam source
- Blacklist count: 0
- Abuse confidence score: Not applicable
Service Exposure: No open ports detected; services appear to be actively firewalled or not running.
## Historical Signal Analysis
Observation Count: 11 signals recorded
Recent Activity: Signals observed as of 2026-07-28
Signal Breakdown:
- DNSSEC validation: Passed
- Reverse DNS resolution: Confirmed
- Blacklist checks: No listings detected (0/8 lists checked)
- Operator score: 0.2609 (low threat activity)
Temporal Analysis: No evidence of persistent malicious behavior. Ownership changes recorded at 0. Threat observation count: 0.
## Relationship Graph
Associated Entities: 1
- DNS Association: s52.HtokyoFL34.vectant.ne.jp
No additional organizational, certificate, or subnet relationships detected.
## Subnet Analysis (120.51.38.0/24)
Subnet Characteristics:
- Abuse Density: 0%
- Total Siblings: 1 detected
- Threat Siblings: 0
Notable Neighbor: 120.51.38.55
- Risk Score: 25
- Authority Score: 60
- Classification: Elevated risk relative to 120.51.38.52
The target IP shares the /24 subnet with one additional address showing elevated risk metrics. This warrants monitoring but does not indicate correlation with malicious activity.
## Recommended Security Actions
Current Status: No automated firewall rules or blocking recommendations generated.
Suggested Actions:
1. Monitor subnet 120.51.38.0/24 for any escalation in neighbor 120.51.38.55's activity
2. No immediate blocking required for 120.51.38.52
3. Continue standard network monitoring procedures
## Conclusion
IP 120.51.38.52 is classified as low-risk with no active threat indicators. The address appears to be a legitimate Japanese infrastructure endpoint with firewalled services. Historical signals show no escalation in malicious behavior. No immediate defensive actions required, but maintain awareness of elevated-risk neighbor within the same /24 subnet.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Japan Network Information Center |
| ASN | AS2519 |
| Network Name | V-FLETS |
| CIDR Block | 120.51.38.0/24 |
| RIR | APNIC |
| Country | JP |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | s52.HtokyoFL34.vectant.ne.jp |
| Forward Confirmed | Yes — FCrDNS verified |
| Forward Hostnames | s52.HtokyoFL34.vectant.ne.jp |
🔐 DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 — Basic operator with some routing infrastructure |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS2519 |
| Network Prefix | 120.51.0.0/18 |
| Route mapping | Found |
| RPKI Status | Valid |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 21% | 2 | 4 |
| routing | 18% | 2 | 2 |
| services | 12% | 2 | 2 |
| ownership | 17% | 2 | 3 |
| reputation | 8% | 1 | 2 |
| geolocation | 35% | 2 | 3 |
| Overall | 19% | 11 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | High (85%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-17 17:11:49 UTC |
| Last Seen | 2026-09-03 07:37:49 UTC |
| Profile Built | 2026-09-01 09:11:40 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 31 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 120.51.38.52
Who owns the IP address 120.51.38.52?
120.51.38.52 is registered to Japan Network Information Center. The address falls within the 120.51.38.0/24 network block. Registration is held at APNIC.
Where is 120.51.38.52 located?
Geolocation data places 120.51.38.52 in Tokyo, 13, Japan. The local time zone is Asia/Tokyo. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 120.51.38.52 malicious or safe?
120.51.38.52 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 120.51.38.52?
The reverse DNS (PTR) record for 120.51.38.52 is s52.HtokyoFL34.vectant.ne.jp. This hostname is forward-confirmed, meaning it resolves back to the same address.