# IP Intelligence Briefing: 14.186.215.199/32
Classification: Moderate Risk (Risk Score: 40)
Report Date: 2026-07-24
Analysis Authority: IPDebrief Intelligence Platform
---
## Executive Summary
Intellectual analysis of IP address 14.186.215.199/32 revealed a moderate-risk endpoint with limited observable threat indicators. The IP resolved to Vietnamese infrastructure (vnpt.vn) and demonstrated DNSSEC validation. Control plane analysis identified the address within AS45899's BGP prefix (14.186.208.0/20), though routing stability metrics indicated instability. No persistent malicious activity or active attack campaigns were observed across the observation window.
---
## Technical Profile
Risk Assessment:
- Overall Risk Score: 40/100 (Moderate Risk)
- Reputation Classification: Moderate Risk
- Abuse Confidence Score: Not Determined
- Provider/Authority Scores: 0 (Insufficient Data)
Network Classification:
- Infrastructure Type: Firewalled / No Services
- Service Purpose: No Open Ports Detected
- Mobile/Cloud/Proxy Classification: Not Applicable
- Anycast Status: Not Identified
Control Plane Analysis:
- Origin ASN: 45899
- BGP Prefix: 14.186.208.0/20
- Route Stability: False (Unstable)
- RPKI State: Not Determined
- IRR Consistency: Not Determined
DNS Resolution:
- PTR Hostname: static.vnpt.vn
- Forward Resolution: static.vnpt.vn
- Forward Confirmation: False
- DNSSEC Validation: True
- Hosted Domain: vnpt.vn
- Email Authentication: SPF (Yes), DMARC (Yes)
---
## Threat Indicators
Blacklist Status:
- DNSBL Listed: 2 of 8 Total Lists
- Abuse Confidence Score: Not Determined
- Known Attacker Status: False
- Tor Exit Node: False
- Spam Source: False
Threat Feeds:
- Pulsedive Risk: Not Determined
- Known Campaigns: None Identified
- Blacklist Count: 0
---
## Geolocation Context
Country/Region: Vietnamese Infrastructure (vnpt.vn domain)
Geolocation Confidence: Low (GeoPlausible: False)
Accuracy Radius: Not Determined
---
## Observation History (Last 9 Signals)
Analysis of the observation window revealed the following signal timeline:
1. 2026-07-24T02:52:23Z (Confidence: 0.85)
- Multiple blacklist listings with varying severity levels
- Maximum severity: High
- Total lists checked: 8; Listed count: 2
2. 2026-07-24T02:52:21Z (Confidence: 0.50)
- DNS Resolution: vnpt.vn
- CAA Records: None
3. 2026-07-24T02:52:21Z (Confidence: 0.90)
- DNSSEC Validation: True
- Zone: 199.215.186.14.in-addr.arpa
- RRSIG: Not Present
4. 2026-07-24T02:52:19Z (Confidence: 0.30)
- Operator Score: 0 (Minimal)
- Signal Count: 1 of 8 Max Signals
5. 2026-07-24T02:52:19Z (Confidence: 0.08)
- Overall Confidence: 0.0833
- Data Sufficiency: 0.33
- Covered Dimensions: 2 of 6
Temporal Indicators:
- Ownership Changes: 0
- Threat Persistence Days: 0
- Threat Observation Count: 0
- Persistently Malicious: False
---
## Entity Relationships
DNS Associations:
- Hostname: static.vnpt.vn
- Relationship Type: DNS Association
Subnet Analysis (14.186.215.0/24):
- Neighboring IP: 14.186.215.52 (Risk Score: Not Determined)
- Total Siblings: 1
- Abuse Density: 0
- Threat Siblings: 0
- Inherited Risk: 0
---
## Behavioral Analysis
Attack Indicators:
- Active Attacker: False
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
- Total Incidents: 0
- Auto-Banned: False
Network Behavior:
- Is Hosting: False
- Is CDN: False
- Is VPN: False
- Is Proxy: False
- Is Mobile: False
---
## Recommended Security Actions
Based on the risk profile (Score: 40), the following firewall rules are recommended:
iptables:
```
iptables -A INPUT -s 14.186.215.199 -j DROP
```
nftables:
```
nft add rule inet filter input ip saddr 14.186.215.199 drop
```
nginx:
```
deny 14.186.215.199;
```
pfSense:
```
14.186.215.199/32
```
Cloudflare WAF:
```json
{
"description": "Block 14.186.215.199 — IPDebrief risk score 40",
"action": "block",
"filter": {
"expression": "ip.src eq 14.186.215.199"
}
}
```
AWS WAF:
```json
{
"Addresses": ["14.186.215.199/32"],
"Description": "IPDebrief risk 40"
}
```
---
## Intelligence Conclusions
IP 14.186.215.199/32 presents moderate risk primarily due to DNSBL listings (2 of 8) and routing instability. The IP resolved to Vietnamese infrastructure (vnpt.vn) with DNSSEC validation and proper email authentication (SPF/DMARC). No active attack patterns, malware indicators, or persistent malicious behavior were observed. The neighborhood subnet (14.186.215.0/24) showed no abuse density or correlated threat activity.
Risk Mitigation: Blocking is recommended based on current risk score and blacklist presence. However, the low threat persistence and absence of active attack indicators suggest this may be a benign or low-risk endpoint. Correlation with other security signals is advised before implementing blocking rules.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Pham Tien Huy |
| ASN | AS45899 |
| Network Name | VNPT-VN |
| CIDR Block | 14.160.0.0/11 |
| RIR | APNIC |
| Country | VN |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | static.vnpt.vn |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | static.vnpt.vn |
🔐 DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS45899 |
| Network Prefix | 14.186.208.0/20 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 8% | 2 | 2 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-06 12:08:21 UTC |
| Last Seen | 2026-08-26 20:32:20 UTC |
| Profile Built | 2026-08-29 07:33:31 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 20 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 14.186.215.199
Who owns the IP address 14.186.215.199?
14.186.215.199 is registered to Pham Tien Huy. The address falls within the 14.160.0.0/11 network block. Registration is held at APNIC.
Where is 14.186.215.199 located?
Geolocation data places 14.186.215.199 in Ho Chi Minh City, Ho Chi Minh, Vietnam. The local time zone is Asia/Ho_Chi_Minh. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 14.186.215.199 malicious or safe?
14.186.215.199 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 14.186.215.199?
The reverse DNS (PTR) record for 14.186.215.199 is static.vnpt.vn. This hostname is not forward-confirmed, so it should be treated as a weak signal.