IP Intelligence Briefing: 121.200.48.114
Date: 2026-06-17
---
**1. Core Profile**
- Risk Score: 80 (High Risk)
- Ownership: Registered to IRT-WLSNET-IN (AS45284) in India.
- Geolocation: Coimbatore, Tamil Nadu, India (latitude 11.0142, longitude 76.9941).
- Network Role: Firewalled / No Services (no open ports, TLS, or HTTP detected).
- Threat Indicators: Minimal direct evidence of malicious activity, but inferred threats (e.g., 13 pulse alerts) linked to the network.
---
**2. Observation History**
- Recent Activity (2026-06-17):
- Detected as "Minimal Risk" with low operator score (0.13).
- Inferred geolocation with 1500km accuracy radius.
- Threat pulses linked to WLSNET-IN network, including potential enumeration and enumeration strikes.
- Long-Term Trends:
- No persistent malicious behavior; threat observations are sporadic.
- No DNSBL listings or known campaigns associated.
---
**3. Relationships**
- Network Affiliation: Part of WLSNET-IN (IRT-WLSNET-IN, AS45284).
- Linked Entities: No direct hostname or certificate relationships.
- Subnet: 121.200.48.0/24, classified as "clean" with zero abuse density.
---
**4. Neighborhood Analysis**
- Subnet: 121.200.48.0/24 (no active or threat-laden sibling IPs).
- Abuse Density: 0% (clean subnet).
- Isolation: No neighboring IPs reported, suggesting a single-host configuration.
---
**5. Recommendations**
- Monitoring: Track for unexpected DNS activity or port openings, as the IP is currently firewalled.
- Network Segmentation: Ensure isolation from internal systems, given the inferred threat pulses.
- Geolocation Verification: Cross-check coordinates with other sources due to discrepancies in observations.
Conclusion: While the IP is registered to a local Indian ISP, its high risk score stems from inferred threats within its network. SOC teams should monitor for anomalies without overreacting to the current clean subnet status.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-WLSNET-IN |
| ASN | AS45284 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | APNIC |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 19% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 24% | 2 | 3 |
| reputation | 15% | 1 | 2 |
| geolocation | 21% | 2 | 2 |
| Overall | 17% | 9 | 11 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:35 UTC |
| Last Seen | 2026-06-26 08:23:05 UTC |
| Profile Built | 2026-06-22 11:54:35 UTC |
| Data Freshness | Live |
| Signal Types | 15 |
| Total Observations | 16 |
Full dossier details are available via our API.