# IP INTELLIGENCE BRIEFING
Target IP: 156.230.182.130/32
Date: 2026-07-28
Classification: Low Risk
---
## EXECUTIVE SUMMARY
IP 156.230.182.130 presents a low-risk profile with a risk score of 25. The address is part of a /24 block owned by Cloud Innovation Support (ASN 63859) under ARIN. Geographic consensus indicates Hong Kong, though geolocation validation experienced ICMP blocking. No active malicious indicators, open services, or threat campaign associations were detected. The subnet exhibits minimal abuse density with 11 of 12 neighboring IPs showing low risk scores.
---
## NETWORK ATTRIBUTION & OWNERSHIP
- ASN: 63859
- Organization: Cloud Innovation Support
- Network Range: 156.230.182.0/24 (156.230.182.0 - 156.230.182.255)
- RIR: ARIN
- Geographic Location: Hong Kong (HK)
- Registration Authority: ARIN
The IP resides in a network block with controlled ownership. No provider or hosting infrastructure flags were set, and the network classification indicates firewalling with no exposed services.
---
## THREAT INDICATORS ASSESSMENT
- Risk Score: 25 (Low Risk)
- Abuse Confidence Score: Not reported
- Blacklist Count: 0
- DNSBL Listed: 1 of 8 lists
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaign Likelihood: Not detected
- Threat Persistence: 0 days
- Persistent Malicious Status: False
No threat indicators were identified. The IP shows no association with known malicious campaigns, threat feeds, or abuse sources.
---
## NETWORK SERVICES & INFRASTRUCTURE
- Open Ports: None detected
- DNS Resolution: No PTR records; forward resolution failed
- Hosted Domains: 0
- Email Authentication: No SPF or DMARC records detected
- TLS Certificate: None
- HTTP Service: None
- Service Purpose: Firewalled / No Services
- Infrastructure Type: Not cloud, CDN, VPN, proxy, or hosting
The target IP exhibits no active service exposure, consistent with a firewalled infrastructure endpoint or passive network node.
---
## GEOLOCATION VALIDATION
- Consensus Location: Hong Kong, China
- Validation Status: Geo plausible (true)
- ICMP Validation: Blocked – unable to validate
- Reported Coordinates: -0.79, 113.92 (ID) in one observation
- Distance to Consensus: 11,242.8 km
- Minimum Possible RTT: 224.86 ms
Geographic data shows minor inconsistency with one observation reporting Indonesia coordinates. The consensus location (Hong Kong) remains the authoritative determination.
---
## OBSERVATION HISTORY
A total of 14 observations were recorded. Key temporal patterns:
- Ownership Stability: 0 ownership changes recorded
- Threat Observation Count: 0
- Recent Signals: Multiple observations captured on 2026-07-28
- Persistence: No persistent malicious behavior detected
- Average Ownership Days: Not calculated (insufficient data)
The IP demonstrates stable ownership with no escalation in threat signals over the observation period.
---
## SUBNET ANALYSIS
- Subnet: 156.230.182.0/24
- Total Neighbors: 12
- Abuse Density: 0
- Risk Distribution:
- High Risk: 0
- Medium Risk: 0
- Low Risk: 11
- Inherited Risk: 0
- Active Siblings: 0
- Threat Siblings: 0
The /24 subnet exhibits minimal abuse activity. Of the 12 neighboring IPs, 11 carry low-risk scores (25), while 2 have null risk scores. No high or medium-risk neighbors were identified.
---
## NETWORK RELATIONSHIPS
Three relationships were identified:
- Same Network: 156.230.182.0 - 156.230.182.255 (×3 entries)
- No organizational, hostname, or certificate relationships detected
The IP's relationship graph is limited to network-level associations, indicating isolation from broader malicious infrastructure.
---
## CONTROL PLANE ANALYSIS
- Origin ASN: 63859
- BGP Prefix: 156.230.182.0/24
- Route Stability: False
- MOAS Status: No
- RPKI State: Not reported
- IRR Consistency: Not reported
- Route Changes (30d): 0
- Operator Score: 0.1304 (Minimal)
- Delegation Age: Not reported
- DNSSEC: Valid
- CAA Records: None
BGP routing shows no recent changes within the 30-day window. The operator score reflects minimal influence in the control plane.
---
## RECOMMENDED ACTIONS
No specific firewall rules or security actions were generated based on the current risk profile. Given the low risk score and absence of active threat indicators, routine monitoring is appropriate.
---
## ANALYST NOTES
1. Low Priority: The IP presents minimal threat characteristics and does not warrant immediate defensive action.
2. Subnet Context: The /24 block shows uniform low-risk distribution; any single IP concern would be anomalous.
3. Service Exposure: The absence of open services suggests this is not a direct attack vector but may serve as a relay or supporting infrastructure.
4. Geographic Inconsistency: Monitor for changes in geolocation reporting, which may indicate configuration drift or spoofing attempts.
5. Action Threshold: No current threat justifies firewall blocking; maintain allow-through posture with logging enabled.
---
Report Status: Complete
Data Sources: IPDebrief Intelligence Platform
Classification: Defensive Intelligence
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Cloud Innovation Support |
| ASN | AS63859 |
| Network Name | 156.230.182.0 - 156.230.182.255 |
| CIDR Block | 156.230.182.0/24 |
| RIR | ARIN |
| Country | ID |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS63859 |
| Network Prefix | 156.230.182.0/24 |
| Route mapping | Found |
| Certificates in transparency logs | 0 certificates |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 5 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 28% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 17% | 2 | 3 |
| Overall | 20% | 10 | 17 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-20 00:17:00 UTC |
| Last Seen | 2026-09-03 18:39:07 UTC |
| Profile Built | 2026-09-03 18:48:45 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 29 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 156.230.182.130
Who owns the IP address 156.230.182.130?
156.230.182.130 is registered to Cloud Innovation Support. The address falls within the 156.230.182.0/24 network block. Registration is held at ARIN.
Where is 156.230.182.130 located?
Geolocation data places 156.230.182.130 in Hong Kong. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 156.230.182.130 malicious or safe?
156.230.182.130 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.