# IP Threat Intelligence Briefing: 146.70.205.118/32
Classification: LOW RISK / MONITOR
Date Generated: 2026-06-17
Analyst: IPDebrief Intelligence Team
## Executive Summary
IP 146.70.205.118 is a low-risk address hosted on M247 Global Tokyo infrastructure with a risk score of 25. The IP operates as a single-service host on port 8443. While the primary risk profile is low, the neighborhood shows elevated abuse density (0.75) with three threat-identified siblings in the /24 subnet. One DNSBL listing was detected across eight monitored lists.
## Ownership and Infrastructure
- ASN: AS9009 (M247 Global TOKYO NOC)
- Organization: M247-LTD-TOKYO
- Geolocation: Japan (Tokyo) โ consensus from multiple sources
- Service Type: Single-Service Host
- Active Port: 8443/TCP (https-alt)
- Route Stability: Flagged as unstable (isRouteStable: false)
## Threat Indicators
- Overall Risk Score: 25 (Low Risk)
- Abuse Confidence: Null
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- DNSBL Listed: 1 of 8 lists
- Threat Feeds: 0 active campaigns
- Blacklist Count: 0
## Neighborhood Analysis (146.70.205.0/24)
- Subnet Abuse Density: 0.75 (elevated)
- Total Siblings: 4
- Active Siblings: 3
- Threat Siblings: 3
- Risk Distribution: 0 high, 1 medium, 2 low
- Key Neighbors:
- 146.70.205.94: Risk 0 (clean)
- 146.70.205.124: Risk 25 (low/medium)
- 146.70.205.180: Risk 50 (moderate)
## Historical Signal Analysis
- Total Observations: 19 signals recorded
- Threat Persistence: 0 days (transient activity)
- Recent Signals: Conflicting geolocation data observed โ Japan (JP) and Romania (RO) signals detected with varying confidence levels (0.22โ0.75)
- Abuse Density Trend: Consistent at 0.75 across recent observations
- Classification: "mostly_clean" despite elevated neighborhood risk
## Technical Fingerprint
- Server Fingerprint: Insufficient data
- TLS Certificate: None detected
- HTTP Headers: Missing HSTS, CSP, and Referrer-Policy headers
- DNSSEC: Valid
- Traceroute: 23 hops via Comcast and Cogent transit networks
## Recommended Actions
Based on the risk profile and neighborhood context, the following actions are recommended:
1. Monitor Closely: The IP's low individual risk score (25) contrasts with elevated neighborhood abuse density. Implement behavioral monitoring for unusual outbound traffic patterns.
2. Block DNSBL Listings: One DNSBL listing detected. Review and block if applicable to your threat intelligence policy.
3. Network-Level Controls: Consider blocking at the perimeter firewall if the IP is not a known legitimate source for your organization.
4. Monitor Related IPs: The /24 subnet shows three threat siblings. Monitor 146.70.205.124 and 146.70.205.180 for additional malicious activity.
5. Log and Correlate: Enable logging for 8443 port activity. Correlate with other threat intelligence feeds to verify if this IP appears in emerging campaigns.
## Conclusion
146.70.205.118 presents a low-risk profile but warrants monitoring due to neighborhood context and conflicting geolocation signals. The IP is part of Tokyo-based hosting infrastructure and should be treated with standard defensive scrutiny. No immediate blocking is required, but continued observation is recommended.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | M247 Global TOKYO NOC |
| ASN | AS9009 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 8443 | https-alt | tcp | โ |
| Closed Ports | 22, 25, 80, 443, 3389, 8080 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 23% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 20% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:44 UTC |
| Last Seen | 2026-06-22 16:26:43 UTC |
| Profile Built | 2026-06-22 16:32:54 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.