IP INTELLIGENCE BRIEFING: 14.39.111.87
Classification: HIGH RISK | Status: Active Threat Indicator
---
**Executive Summary**
IP address 14.39.111.87 is classified as HIGH RISK (risk score: 70/100). The IP is associated with KT Corporation (mobile carrier) in South Korea and operates as a web server with elevated risk characteristics. While no active malicious campaigns or known attacker signatures were identified, the IP exhibits suspicious behavioral patterns requiring immediate SOC attention.
---
**Network & Ownership Profile**
- IP: 14.39.111.87/32
- ASN: 4766 (IP Manager)
- Organization: KORNET-KR
- Geolocation: Jeju City, Jeju-do, South Korea (KR)
- Timezone: Asia/Seoul
- Network Classification: Mobile connection via KT Corporation (LTE/5G)
- Infrastructure Type: Web Server
---
**Technical Services & Indicators**
Open Ports:
- TCP/80 (HTTP)
- TCP/443 (HTTPS)
- TCP/22 (SSH)
TLS Certificate:
- Issuer: Ruckus Wireless Inc., Sunnyvale, CA
- Subject: SN-242543007980
- Certificate: Self-signed=false
HTTP Response: Status code 503 (Service Unavailable) observed during recent probing
DNSBL Status: Listed on 4 of 8 threat feeds
---
**Threat Assessment**
- Risk Score: 70/100 (High Risk)
- Abuse Confidence Score: Not calculated
- Known Campaigns: None detected
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Historical Observations: 19 signals recorded. Recent activity shows HTTP 503 responses and mobile carrier connection patterns. No persistent malicious behavior detected in observation window.
---
**Geographic & Network Context**
- Country Consensus: Not consistent (geoPlausible=false)
- Control Plane: BGP prefix 14.32.0.0/13, route stability flagged
- Neighborhood Analysis: Subnet 14.39.111.87/24 shows 0% abuse density, 0 threat siblings
- Related Network: KORNET-KR (multiple relationship entries)
---
**Recommended Actions**
Immediate:
1. Block IP at perimeter firewall using provided rules:
- iptables: `iptables -A INPUT -s 14.39.111.87 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 14.39.111.87 drop`
- Cloudflare/AWS WAF: Enable block rule for IP
2. Increase logging verbosity for this source to capture any subsequent activity patterns
3. Monitor for related IPs within the 14.39.111.0/24 subnet
Justification: Elevated risk score (70/100) combined with mobile carrier hosting pattern and DNSBL listings warrants defensive blocking. No active threat intelligence matches, but probabilistic risk assessment indicates potential for malicious activity.
---
Prepared for SOC Operations | Data Source: IPDebrief Intelligence Platform
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | IP Manager |
| ASN | AS4766 |
| Network Name | KORNET-KR |
| CIDR Block | 14.32.0.0/11 |
| RIR | APNIC |
| Country | KR |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 443 | https | tcp | — |
| 22 | ssh | tcp | — |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | 2025-05-24T17:44:53+00:00 |
| Valid Until | 2050-05-25T17:44:53+00:00 |
| TLS Protocol | Tls12 |
| Cipher Suite | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 9132 days |
🛡️ Public Network Snapshot
| Origin ASN | AS4766 |
| Network Prefix | 14.32.0.0/13 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Not detected |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 35% | 2 | 2 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 14% | 4 | 4 |
| Data Coherence | Mixed Signals (68%) — 2 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
⚠ TLS certificate claims US but primary geo says KR
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-15 04:05:33 UTC |
| Last Seen | 2026-09-29 20:35:13 UTC |
| Profile Built | 2026-08-31 17:33:46 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 25 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 14.39.111.87
Who owns the IP address 14.39.111.87?
14.39.111.87 is registered to IP Manager. The address falls within the 14.32.0.0/11 network block. Registration is held at APNIC.
Where is 14.39.111.87 located?
Geolocation data places 14.39.111.87 in Jeju City, Jeju-do, South Korea. The local time zone is Asia/Seoul. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 14.39.111.87 malicious or safe?
14.39.111.87 currently carries a high risk assessment, meaning indicators associated with malicious or abusive activity have been observed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 14.39.111.87?
Responsive ports observed on 14.39.111.87 include 80, 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.
Is 14.39.111.87 a VPN, proxy, or data center address?
14.39.111.87 is classified as a mobile network based on network ownership and behavioural analysis.