# THREAT INTELLIGENCE BRIEFING
IP Address: 139.228.161.54/32
Date: July 27, 2026
Classification: LOW RISK
---
## EXECUTIVE SUMMARY
IP 139.228.161.54 is classified as a low-risk address (Risk Score: 25/100) associated with Indonesian infrastructure operator IRT-BM-ID. The IP shows no active threat indicators, no open services, and operates within a clean neighborhood profile. No immediate action required.
---
## OWNERSHIP & GEOLOCATION
- Organization: IRT-BM-ID (ASN 23700)
- Network: BM-ID (139.228.0.0/16)
- Location: Surabaya, East Java, Indonesia (ID)
- RIR: ARIN
- Registration Date: Not available in profile
---
## THREAT ASSESSMENT
| Indicator | Status |
|---|---|
| Risk Score | 25 (Low) |
| Known Attacker | No |
| Tor Exit Node | No |
| Spam Source | No |
| Blacklist Count | 0 |
| Abuse Confidence Score | N/A |
| Known Campaigns | None |
Assessment: No malicious indicators detected. IP does not appear in threat feeds or campaign correlations.
---
## NETWORK CHARACTERISTICS
- Service Purpose: Firewalled / No Services
- Open Ports: None detected
- TLS Certificates: None
- HTTP Services: None
- Network Classification: Infrastructure (non-public)
Note: The IP is not classified as a provider, CDN, VPN, proxy, Tor, hosting, mobile, or residential endpoint.
---
## DNS ANALYSIS
- PTR Hostname: fm-dyn-139-228-161-54.fast.net.id
- Forward Resolution: 1 hostname (net.id)
- Email Authentication: SPF: No | DMARC: No
- Forward Confirmed: No
---
## NEIGHBORHOOD ANALYSIS
- Subnet: 139.228.161.54/24
- Abuse Density: 0%
- Classification: Clean
- Threat Siblings: 0
- Active Siblings: 0
Assessment: No related high-risk IPs detected in the /24 subnet.
---
## OBSERVATION HISTORY (20 observations)
- Ownership Changes: 0
- Threat Persistence Days: 0
- Persistently Malicious: No
- Recent Signals:
- Geo validation: ICMP blocked, unable to validate
- Neighborhood classification: Clean
- No threat observations recorded
---
## CONTROL PLANE
- Origin ASN: 23700
- BGP Prefix: 139.228.160.0/19
- RPKI State: Not available
- DNSSEC Valid: Yes
- DNSBL Listed: 1 of 8 lists (minor listing)
- Route Stability: Unstable (route changes in 30d: 0)
---
## RECOMMENDED ACTIONS
No firewall rules or blocking recommended. The IP presents minimal risk based on current profile.
Monitoring Notes:
- Maintain baseline observation for infrastructure IPs
- Monitor for service activation (current state: no open ports)
- The minor DNSBL listing warrants periodic review if traffic patterns change
---
## SOC ANALYST NOTES
This IP is part of Indonesian network infrastructure (IRT-BM-ID). The absence of open services and clean neighborhood profile indicates legitimate network usage rather than malicious activity. The single DNSBL listing is inconclusive and requires correlation with other threat indicators before escalation.
Confidence Level: High
Priority: Low
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | IRT-BM-ID |
| ASN | AS23700 |
| Network Name | BM-ID |
| CIDR Block | 139.228.0.0/16 |
| RIR | ARIN |
| Country | ID |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | fm-dyn-139-228-161-54.fast.net.id |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | fm-dyn-139-228-161-54.fast.net.id |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS23700 |
| Network Prefix | 139.228.160.0/19 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 20% | 5 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-12 08:50:55 UTC |
| Last Seen | 2026-09-01 00:11:51 UTC |
| Profile Built | 2026-09-01 00:12:56 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 25 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 139.228.161.54
Who owns the IP address 139.228.161.54?
139.228.161.54 is registered to IRT-BM-ID. The address falls within the 139.228.0.0/16 network block. Registration is held at ARIN.
Where is 139.228.161.54 located?
Geolocation data places 139.228.161.54 in Surabaya, JI, Indonesia. The local time zone is Asia/Jakarta. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 139.228.161.54 malicious or safe?
139.228.161.54 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 139.228.161.54?
The reverse DNS (PTR) record for 139.228.161.54 is fm-dyn-139-228-161-54.fast.net.id. This hostname is not forward-confirmed, so it should be treated as a weak signal.