## THREAT INTELLIGENCE BRIEFING
Target: 144.79.187.29/32
Classification: MODERATE RISK (Score: 40)
Date: Analysis completed based on available data
---
OWNERSHIP & GEOLOCATION
The IP address 144.79.187.29 is registered to ASN 138000 (IRT-IDNIC-ID) within the Indonesia region (ID). Geolocation data indicates Jakarta Selatan with a 1500km accuracy radius. The subnet 144.79.187.0/24 is classified under IANA-BLOCK ownership.
---
NETWORK CLASSIFICATION
Service Status: Firewalled / No Services
Open Ports: None detected
DNS Resolution: No forward resolution, no PTR records
Email Authentication: No SPF or DMARC records configured
Network Role: No CDN, Cloud, VPN, Proxy, or Hosting services identified
---
THREAT INDICATORS
Risk Assessment: Moderate Risk (Score: 40)
Blacklist Status: Listed on 1 of 8 DNSBLs
Threat Indicators: None explicitly identified in current profile
Campaign Correlation: No known campaigns or certificate matches
---
NEIGHBORHOOD ANALYSIS
Subnet: 144.79.187.0/24
Abuse Density: 0.5625 (HIGH ABUSE CLASSIFICATION)
Total Siblings: 16 IPs
Active Siblings: 3
Threat Siblings: 9
Risk Distribution: All neighbor IPs show risk score of 40 with authority score of 50
The /24 subnet exhibits high abuse density with 9 out of 16 sibling IPs flagged as threats. This contextual factor elevates the threat posture for the target IP.
---
OBSERVATION HISTORY
Total Observations: 18 signals tracked
Latest Signal: 2026-06-22T16:12:51
Temporal Persistence: 0 threat observation days
Status: Not persistently malicious
Historical data shows operator scores labeled "Minimal" with stable risk characteristics over the observation period.
---
RECOMMENDED ACTIONS
Firewall Blocking: Recommended for deployment
Platform-Specific Rules:
- iptables: `iptables -A INPUT -s 144.79.187.29 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 144.79.187.29 drop`
- nginx: `deny 144.79.187.29;`
- pfSense: `144.79.187.29/32`
- Cloudflare WAF: Block with filter expression `ip.src eq 144.79.187.29`
- AWS WAF: Add `144.79.187.29/32` to block list
Note: Recommendations should be validated against local security policies and combined with additional threat intelligence before implementation.
---
ANALYST SUMMARY
This IP presents moderate risk within a high-abuse-density subnet. While no active threat indicators are currently associated with the specific address, the contextual abuse density of the 144.79.187.0/24 subnet (0.5625) suggests elevated threat potential. The subnet contains 9 threat-siblings and is classified as "high_abuse." Recommended blocking actions are available across major firewall platforms. Continuous monitoring is advised given the neighborhood threat landscape.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-IDNIC-ID |
| ASN | AS138000 |
| Network Name | IANA-BLOCK |
| CIDR Block | 0.0.0.0/0 |
| RIR | ARIN |
| Country | ID |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 27% | 2 | 3 |
| reputation | 24% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 20% | 9 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:44 UTC |
| Last Seen | 2026-06-22 16:13:17 UTC |
| Profile Built | 2026-06-22 16:19:30 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 18 |
Full dossier details are available via our API.