IP INTELLIGENCE BRIEFING
Target: 140.213.5.182/32
Classification: Moderate Risk (Score: 40)
Report Date: Current
EXECUTIVE SUMMARY
IP address 140.213.5.182 is associated with ASN 24203 (Beny Dwi Setyawan, XLNET-ID) and geolocated to Jakarta, Indonesia. The address maintains a moderate risk profile with no active services detected. The IP appears to be firewalled with no open ports or services. While the subnet demonstrates low abuse density, the address is listed on 2 out of 8 DNS blacklists.
OWNERSHIP AND GEOGRAPHY
- Organization: Beny Dwi Setyawan (XLNET-ID)
- ASN: 24203
- Country: Indonesia (ID)
- Region/City: Jakarta / North Jakarta
- CIDR Block: 140.213.0.0/16
- Geolocation Confidence: 52% accuracy radius of 1500km
THREAT INDICATORS
- Risk Score: 40/100 (Moderate)
- Abuse Confidence Score: Not available
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- DNSBL Listings: 2 of 8 total lists
- Campaign Activity: No known campaign associations
- Threat Persistence: 0 days observed
NETWORK BEHAVIOR
- Service Status: Firewalled / No Services Detected
- DNS Records: No PTR records, no forward resolution
- TLS/Certificates: None observed
- Open Ports: None
- Neighborhood Analysis: Subnet 140.213.5.0/24 shows zero abuse density with no active sibling threats detected
OBSERVATION HISTORY
Fourteen signal observations recorded. Recent observations (2026-07-22) indicate:
- Network classification: Clean
- Inherited risk: 0
- Geo validation: Distance 11,243km from probe origin with plausible coordinates
- No ownership changes detected
- No threat persistence observed
RELATIONSHIP GRAPH
- Four relationships identified, all classified as "Same Network" (XLNET-ID)
- No external entity associations (hostnames, organizations, certificates)
- No certificate matches or correlated IPs
RECOMMENDED ACTIONS
Based on the risk profile, the following defensive measures are recommended:
Firewall Rules:
- iptables: `iptables -A INPUT -s 140.213.5.182 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 140.213.5.182 drop`
- nginx: `deny 140.213.5.182;`
WAF Recommendations:
- Cloudflare WAF: Block with expression `ip.src eq 140.213.5.182`
- AWS WAF: Block address `140.213.5.182/32`
ANALYST NOTES
The IP presents a moderate risk profile primarily due to DNS blacklist listings. While no active exploitation or malicious service detection is present, the firewall configuration suggests defensive posture rather than active threat activity. The low neighborhood abuse density (0.0) indicates this is not part of a larger compromised subnet. SOC teams should monitor for changes in service status or blacklist status, but immediate blocking is not strongly mandated without corroborating threat intelligence.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Beny Dwi Setyawan |
| ASN | AS24203 |
| Network Name | XLNET-ID |
| CIDR Block | 140.213.0.0/16 |
| RIR | ARIN |
| Country | ID |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS24203 |
| Network Prefix | 140.213.5.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-02 04:20:58 UTC |
| Last Seen | 2026-08-22 11:07:53 UTC |
| Profile Built | 2026-08-29 11:01:30 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 17 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 140.213.5.182
Who owns the IP address 140.213.5.182?
140.213.5.182 is registered to Beny Dwi Setyawan. The address falls within the 140.213.0.0/16 network block. Registration is held at ARIN.
Where is 140.213.5.182 located?
Geolocation data places 140.213.5.182 in North Jakarta, Jakarta, Indonesia. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 140.213.5.182 malicious or safe?
140.213.5.182 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.