# IP Intelligence Briefing: 156.225.1.112/32
Date: 2026-07-25
Classification: Moderate Risk
Analyst: IPDebrief Intelligence Team
---
## Executive Summary
IP address 156.225.1.112 presents a moderate risk profile (score: 50/100) with no active threat indicators. The address belongs to the 156.225.1.0/24 block owned by Cloud Innovation Support under ASN 9465. Geolocation data indicates registration in Hong Kong with reported coordinates in Seychelles. The subnet demonstrates minimal abuse density with 35 neighboring addresses, of which only three exhibit medium-risk scores.
---
## Technical Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 50 (Moderate Risk) |
| **ASN** | 9465 |
| **Organization** | Cloud Innovation Support |
| **Network Block** | 156.225.1.0 - 156.225.1.255 |
| **Country** | HK (Hong Kong) |
| **Geolocation Discrepancy** | Reported: Seychelles (22.4°N, 114.11°E) |
| **DNSBL Listed** | 2 of 8 total lists |
| **Open Services** | None detected |
| **Network Role** | Firewalled / No Services |
---
## Threat Indicators
- Blacklist Status: Listed on 2 DNSBL feeds
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaign Association: None identified
- Threat Persistence: 0 days
- Persistent Malicious Activity: False
---
## Neighborhood Analysis (156.225.1.0/24)
The /24 subnet contains 36 total sibling addresses with the following risk distribution:
- High Risk: 0 addresses
- Medium Risk: 3 addresses (scores 25-65)
- Low Risk: 29 addresses (score 0)
- Abuse Density: 0%
Notable medium-risk neighbors include 156.225.1.17, 156.225.1.30, 156.225.1.37, 156.225.1.40, 156.225.1.42, and 156.225.1.96.
---
## Historical Observations
Fourteen signal observations recorded since last update (2026-07-25). Key temporal indicators:
- Ownership Changes: 0
- Threat Observation Count: 0
- Threat Persistence Days: 0
- Geolocation Consistency: Maintained HK/Seychelles reporting
- Network Stability: Route changes over 30 days: 0
---
## Network Infrastructure
- BGP Prefix: 156.225.1.0/24
- Origin ASN: 9465
- Route Stability: False
- RPKI State: Not evaluated
- DNSSEC Valid: Yes
- HOP Count (Traceroute): 30
- Transit Networks: Comcast, NTT
---
## Recommended Actions
Based on the moderate risk profile and DNSBL listings, the following actions are recommended for defensive posture:
1. Monitor – Add IP to SIEM watchlist for traffic correlation
2. Block – Consider blocking if internal policy requires action on DNSBL-listed IPs
3. Investigate – Review inbound connection logs for this subnet
4. Rate Limit – Implement connection rate limiting if traffic patterns indicate abuse
Firewall Rule Example (iptables):
```bash
iptables -A INPUT -s 156.225.1.0/24 -j DROP
# Or implement rate limiting instead of full block
```
---
## Intelligence Conclusion
IP 156.225.1.112 presents a moderate risk profile characterized by DNSBL listings without active threat indicators. The subnet maintains low abuse density with minimal correlated malicious activity. While no immediate threat is detected, the moderate risk score warrants ongoing monitoring and consideration of defensive blocking based on organizational risk tolerance.
Confidence Level: Moderate
Next Review: Recommended within 30 days
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Cloud Innovation Support |
| ASN | AS9465 |
| Network Name | 156.225.1.0 - 156.225.1.255 |
| CIDR Block | 156.225.1.0/24 |
| RIR | ARIN |
| Country | HK |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS9465 |
| Network Prefix | 156.225.1.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 20% | 2 | 2 |
| routing | 8% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 12% | 2 | 2 |
| reputation | 8% | 1 | 2 |
| geolocation | 20% | 2 | 2 |
| Overall | 13% | 9 | 10 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-09 13:31:29 UTC |
| Last Seen | 2026-09-16 12:10:05 UTC |
| Profile Built | 2026-08-28 22:04:35 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 20 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 156.225.1.112
Who owns the IP address 156.225.1.112?
156.225.1.112 is registered to Cloud Innovation Support. The address falls within the 156.225.1.0/24 network block. Registration is held at ARIN.
Where is 156.225.1.112 located?
Geolocation data places 156.225.1.112 in Seychelles. The local time zone is Asia/Hong_Kong. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 156.225.1.112 malicious or safe?
156.225.1.112 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.