IPDebrief

14.191.4.171

IP Intelligence Dossier
Your IP: 216.73.216.157
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# INTELLIGENCE BRIEFING: 14.191.4.171/32

Classification: Moderate Risk

Date: 2026-07-25

IP Address: 14.191.4.171/32

---

## EXECUTIVE SUMMARY

IP 14.191.4.171 is a Vietnamese infrastructure address operated by VNPT-VN (IRT-VNNIC-AP), assigned to the 14.160.0.0/11 CIDR block. The IP carries a moderate risk score of 40 and is listed on 2 of 8 DNSBLs. No active services, open ports, or known threat indicators were observed. The IP is associated with the hostname static.vnpt.vn and shows no evidence of active malicious campaigns or persistent threat activity.

---

## TECHNICAL PROFILE

Network Ownership & Geolocation

Network Classification

DNS Analysis

---

## THREAT ASSESSMENT

Current Risk Indicators

Control Plane Analysis

---

## OBSERVATION HISTORY

Total Observations: 15

Recent observations (July 25, 2026) indicate:

No evidence of escalating threat behavior or changing ownership patterns observed during the observation window.

---

## RELATIONSHIP GRAPH

Total Relationships: 10

No relationships detected to known malicious infrastructure or threat actors.

---

## SUBNET ANALYSIS

Subnet: 14.191.4.171/24

No neighboring IPs with known malicious activity detected in the immediate subnet.

---

## RECOMMENDED ACTIONS

Firewall Blocking Rules

iptables:

```bash

iptables -A INPUT -s 14.191.4.171 -j DROP

```

nftables:

```bash

nft add rule inet filter input ip saddr 14.191.4.171 drop

```

nginx:

```nginx

deny 14.191.4.171;

```

pfSense:

```

14.191.4.171/32

```

Cloudflare WAF:

```json

{

"description": "Block 14.191.4.171 — IPDebrief risk score 40",

"action": "block",

"filter": {

"expression": "ip.src eq 14.191.4.171"

}

}

```

AWS WAF:

```json

{

"Addresses": ["14.191.4.171/32"],

"Description": "IPDebrief risk 40"

}

```

---

## ANALYST NOTES

The IP address 14.191.4.171 represents standard Vietnamese telecommunications infrastructure from VNPT. The moderate risk score (40) is primarily driven by DNSBL listings rather than active threat indicators. No open services or port scans were detected. The route stability flag being false indicates potential BGP routing changes, but no actual route changes were observed in the last 30 days.

SOC Recommendations:

1. Monitor traffic patterns for this IP as part of routine Vietnamese ISP traffic analysis

2. Current risk level does not warrant immediate blocking unless additional threat indicators emerge

3. Consider implementing rate limiting rather than hard blocking if traffic is observed

4. No immediate threat action required based on current data

---

*Intelligence generated using IPDebrief tools. Data is current as of observation timestamp.*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇻🇳 Vietnam
RegionHanoi
CityHanoi
TimezoneAsia/Ho_Chi_Minh
Latitude21.02
Longitude105.85

🏢 Ownership & Registration

OrganizationPham Tien Huy
ASNAS45899
Network NameVNPT-VN
CIDR Block14.160.0.0/11
RIRAPNIC
CountryVN
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRstatic.vnpt.vn
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesstatic.vnpt.vn

🔐 DNS Hygiene

Hygiene Score60% (Good)
SPFPresent
DMARCPresent
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS45899
Network Prefix14.191.0.0/21
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
25%
12
reputation
0%
00
geolocation
25%
11
Overall20%56
Coverage: 5/6 dimensions · Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

📅 Observation Timeline 🔄 Live

First Seen2026-07-09 01:18:37 UTC
Last Seen2026-08-27 04:14:06 UTC
Profile Built2026-08-29 06:03:23 UTC
Data FreshnessLive
Signal Types19
Total Observations21
🔍 19 signal types · 21 observations collected
This report is generated from 19+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 14.191.4.171

Who owns the IP address 14.191.4.171?

14.191.4.171 is registered to Pham Tien Huy. The address falls within the 14.160.0.0/11 network block. Registration is held at APNIC.

Where is 14.191.4.171 located?

Geolocation data places 14.191.4.171 in Hanoi, Hanoi, Vietnam. The local time zone is Asia/Ho_Chi_Minh. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 14.191.4.171 malicious or safe?

14.191.4.171 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.

What is the hostname for 14.191.4.171?

The reverse DNS (PTR) record for 14.191.4.171 is static.vnpt.vn. This hostname is not forward-confirmed, so it should be treated as a weak signal.

🏘️ Related IP Addresses

Nearby addresses in 14.160.0.0/11

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.