IPDebrief

146.70.205.118

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Threat Intelligence Briefing: 146.70.205.118/32

Classification: LOW RISK / MONITOR

Date Generated: 2026-06-17

Analyst: IPDebrief Intelligence Team

## Executive Summary

IP 146.70.205.118 is a low-risk address hosted on M247 Global Tokyo infrastructure with a risk score of 25. The IP operates as a single-service host on port 8443. While the primary risk profile is low, the neighborhood shows elevated abuse density (0.75) with three threat-identified siblings in the /24 subnet. One DNSBL listing was detected across eight monitored lists.

## Ownership and Infrastructure

## Threat Indicators

## Neighborhood Analysis (146.70.205.0/24)

- 146.70.205.94: Risk 0 (clean)

- 146.70.205.124: Risk 25 (low/medium)

- 146.70.205.180: Risk 50 (moderate)

## Historical Signal Analysis

## Technical Fingerprint

## Recommended Actions

Based on the risk profile and neighborhood context, the following actions are recommended:

1. Monitor Closely: The IP's low individual risk score (25) contrasts with elevated neighborhood abuse density. Implement behavioral monitoring for unusual outbound traffic patterns.

2. Block DNSBL Listings: One DNSBL listing detected. Review and block if applicable to your threat intelligence policy.

3. Network-Level Controls: Consider blocking at the perimeter firewall if the IP is not a known legitimate source for your organization.

4. Monitor Related IPs: The /24 subnet shows three threat siblings. Monitor 146.70.205.124 and 146.70.205.180 for additional malicious activity.

5. Log and Correlate: Enable logging for 8443 port activity. Correlate with other threat intelligence feeds to verify if this IP appears in emerging campaigns.

## Conclusion

146.70.205.118 presents a low-risk profile but warrants monitoring due to neighborhood context and conflicting geolocation signals. The IP is part of Tokyo-based hosting infrastructure and should be treated with standard defensive scrutiny. No immediate blocking is required, but continued observation is recommended.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฏ๐Ÿ‡ต Japan
RegionTokyo
CityTokyo
TimezoneAsia/Tokyo
Latitude35.62
Longitude139.74

๐Ÿข Ownership & Registration

OrganizationM247 Global TOKYO NOC
ASNAS9009
Network Nameโ€”
CIDR Blockโ€”
RIRARIN
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeSingle-Service Host
Network TierUnknown โ€” Insufficient routing data to classify
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
8443https-alttcpโ€”
Closed Ports22, 25, 80, 443, 3389, 8080 (1 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
26%
24
routing
13%
11
services
15%
22
ownership
24%
23
reputation
23%
13
geolocation
21%
22
Overall20%1015
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-07 23:03:44 UTC
Last Seen2026-06-22 16:26:43 UTC
Profile Built2026-06-22 16:32:54 UTC
Data FreshnessLive
Signal Types21
Total Observations22
๐Ÿ” 21 signal types ยท 22 observations collected
This report is generated from 21+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.