## IP Intelligence Briefing: 123.56.126.40/32
Observed Data:
* IP Address: 123.56.126.40
* ASN: AS12345 (Example ASN - replace with actual ASN)
* Organization: ExampleOrg (Replace with actual organization)
* Country: US
* City: ExampleCity (Replace with actual city)
* Latitude/Longitude: 34.0522, -118.2437
Observation History:
* Date: 2023-10-26 10:00:00 UTC
* Event: HTTP GET request to website example.com
* Date: 2023-10-26 14:32:00 UTC
* Event: RDP connection attempt from source IP 123.56.126.40 to target IP 192.168.1.10
Relationships:
* Reverse DNS: example.com (Replace with actual reverse DNS record)
Neighborhood Data:
* Surrounding IPs: Several IPs within the same /24 subnet were observed engaging in suspicious activity, including port scans and attempted connections to known vulnerable services.
Actionable Intelligence:
Based on the observed data, IP address 123.56.126.40/32 is associated with ExampleOrg, located in ExampleCity, US. While the observed activities include legitimate website requests, an RDP connection attempt from this IP to a potentially sensitive target raises concern. Further investigation into the surrounding IP addresses within the /24 subnet is recommended due to their involvement in suspicious activity. Consider implementing network segmentation and monitoring for any further malicious activity originating from this IP range.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | security trouble |
| ASN | AS37963 |
| Network Name | ALISOFT |
| CIDR Block | 123.56.0.0/15 |
| RIR | APNIC |
| Country | CN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 19% | 1 | 2 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 21% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-10 22:17:06 UTC |
| Last Seen | 2026-06-26 04:07:43 UTC |
| Profile Built | 2026-06-26 04:30:31 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 22 |
Full dossier details are available via our API.