# IP Intelligence Briefing: 160.191.89.47/32
Classification: LOW RISK | Status: MONITOR | Date: 2026-07-22
---
## Executive Summary
IP 160.191.89.47 presents a low-risk profile with no active threat indicators. The address shows no open ports, no DNS resolution, and no known associations with malicious campaigns or threat feeds. No recommended firewall actions are currently warranted.
---
## Profile Assessment
- Risk Score: 0 (Low Risk)
- Provider/Authority Scores: 0/0
- Geolocation: US (Denver, CO) / VN (Historical) - Geographic consensus pending validation
- ASN: 151858 | BGP Prefix: 160.191.88.0/23
- Network Classification: Firewalled / No Services
- ISP Attribution: IRT-VNNIC-AP (Vietnam)
---
## Threat Indicators
- Blacklist Count: 0
- Known Campaigns: None detected
- Tor/Proxy/VPN: Not identified
- Abuse Confidence Score: Not applicable
- Threat Feeds: Empty
---
## Network Activity
- Open Ports: None
- DNS Resolution: Inactive
- HTTP/TLS Services: Not detected
- Certificate Data: None
- Behavioral Analysis: No honeypot hits, enumeration strikes, or WAF violations
---
## Temporal Analysis
- Ownership Changes: 0
- Threat Persistence: 0 days
- Observation Count: 11 total signals
- Persistent Malicious Behavior: False
- Route Stability: Inconsistent (isRouteStable: false)
---
## Neighborhood Analysis
Subnet: 160.191.89.0/24
- Abuse Density: 0 (Low)
- Total Siblings: 4
- Risk Distribution: 0 High, 0 Medium, 4 Low
Neighbor IPs:
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 160.191.89.7 | 25 | 50 |
| 160.191.89.95 | 0 | 50 |
| 160.191.89.223 | 25 | 50 |
| 160.191.89.246 | 25 | 50 |
---
## Relationships
- Linked Entities: None detected
- Associated Hostnames: None
- Related Organizations: None
---
## Recommended Actions
No immediate security actions required. The IP demonstrates benign characteristics with no active threat indicators. Standard monitoring protocols apply.
For Reference - No Firewall Rules Generated:
- No blocking/allowing rules recommended at this time
- No WAF rules generated
- No iptables/nftables rules needed
---
## Intelligence Notes
- The IP is geographically inconsistent (US vs VN) requiring geo-validation
- Control plane data shows route instability (isRouteStable: false)
- Low confidence scores in historical observations (0.12-0.85 range)
- No email authentication records (SPF/DMARC) detected
- Traceroute shows 23 hops with Comcast as transit network
- Geo validation marked as implausible (geoPlausible: false)
---
Analyst Assessment: This IP represents a benign endpoint with no current threat activity. Continue standard monitoring and periodic re-evaluation.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Tran Binh Trong |
| ASN | AS151858 |
| Network Name | GOLDEN-VN |
| CIDR Block | 160.191.88.0/23 |
| RIR | ARIN |
| Country | VN |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 443 | https | tcp | — |
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
CN=nongnghiepgreencity.com was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.| SANs | nongnghiepgreencity.com |
| Valid From | 2026-04-02T05:23:20+00:00 |
| Valid Until | 2026-07-01T05:23:19+00:00 (expired) |
| TLS Protocol | Tls12 |
| Cipher Suite | TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
🛡️ Public Network Snapshot
| Origin ASN | AS151858 |
| Network Prefix | 160.191.88.0/23 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Not detected |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-02 04:21:06 UTC |
| Last Seen | 2026-08-28 07:39:34 UTC |
| Profile Built | 2026-08-29 03:02:51 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 160.191.89.47
Who owns the IP address 160.191.89.47?
160.191.89.47 is registered to Tran Binh Trong. The address falls within the 160.191.88.0/23 network block. Registration is held at ARIN.
Where is 160.191.89.47 located?
Geolocation data places 160.191.89.47 in Denver. The local time zone is Asia/Ho_Chi_Minh. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 160.191.89.47 malicious or safe?
160.191.89.47 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 160.191.89.47?
Responsive ports observed on 160.191.89.47 include 80, 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.