IPDebrief

139.180.163.29

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 139.180.163.29/32

Classification: Moderate Risk Cloud Infrastructure Asset

Date: [Current Date]

Risk Score: 65/100

---

## Executive Summary

IP address 139.180.163.29 is a Vultr cloud computing VPS hosted in Sydney, Australia, operating as a web server with moderate risk profile (65/100). The system is associated with the domain icare-catalogue.com and vps1708.tmdvps.com. While the /24 subnet demonstrates clean abuse characteristics, the IP is listed on three DNS blacklist entries with high severity ratings, warranting monitoring for potential spam or abuse activity.

---

## Infrastructure Profile

Ownership & Provider:

Geolocation:

DNS Infrastructure:

---

## Service Exposure

Open Ports:

PortProtocolServiceStatus
80TCPHTTPOpen
443TCPHTTPSOpen
22TCPSSHOpen (OpenSSH 7.4)

TLS/SSL Certificate:

HTTP Fingerprint:

---

## Threat Indicators

Observed Threat Activity:

Blacklist Status:

Campaign Correlation:

---

## Historical Observations

Signal History: 27 observations recorded

---

## Network Neighborhood Analysis

Subnet: 139.180.163.0/24

Relationship Graph:

---

## Recommended Actions

Immediate Actions:

1. Monitor DNSBL Listings: Investigate the 3 DNSBL entries with high severity ratings

2. Verify Legitimate Use: Confirm icare-catalogue.com is a legitimate service

3. SSH Access Review: Evaluate necessity of port 22 access from external networks

4. DMARC Implementation: Deploy DMARC record for icare-catalogue.com to enhance email authentication

Firewall/Filtering Rules:

Long-term Mitigation:

---

## Risk Assessment

Overall Risk: MODERATE

Key Risk Factors:

Mitigating Factors:

Recommendation: Monitor closely for DNSBL status changes and verify legitimate business use of the icare-catalogue.com domain. Consider temporary filtering if DNSBL listings confirm malicious activity.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฆ๐Ÿ‡บ Australia
RegionNSW
CitySydney
Timezoneโ€”
Latitude-33.90
Longitude151.19

๐Ÿข Ownership & Registration

OrganizationIRT-CHOOPALLC-AP
ASNAS20473
Network Nameโ€”
CIDR Block139.180.160.0/20
RIRARIN
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRvps1708.tmdvps.com
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamesvps1708.tmdvps.com

๐Ÿ” DNS Hygiene

Hygiene Score60% (Good)
SPF1/2 domains
DMARC0/2 domains
FCrDNSVerified
DNSSECValid
CAANot configured
Domains Checked2 domains

โ˜๏ธ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeWeb Server
Network TierTier 3 โ€” Basic operator with some routing infrastructure
CloudHosting

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
443httpstcpโ€”
22sshtcp
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
ServerApache
HTTP Titleโ€”
SSH VersionSSH-2.0-OpenSSH_7.4

๐Ÿ” TLS Certificate

๐Ÿ”’
CN=*.icare-catalogue.com
Issued by CN=R12, O=Let's Encrypt, C=US
Self-signed: No
SANs*.icare-catalogue.comicare-catalogue.com
Valid From2026-05-23T20:37:48+00:00
Valid Until2026-08-21T20:37:47+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period89 days
Serial Number05CD5CCD17BB40187A09AA622873D9212711
ThumbprintA71A97CD730A03844303A4F388AD0A8FEFF24F7A

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
30%
24
routing
17%
23
services
26%
23
ownership
22%
34
reputation
28%
13
geolocation
23%
22
Overall24%1219
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-08 23:18:04 UTC
Last Seen2026-06-27 14:13:49 UTC
Profile Built2026-06-28 08:19:39 UTC
Data FreshnessLive
Signal Types25
Total Observations31
๐Ÿ” 25 signal types ยท 31 observations collected
This report is generated from 25+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.