# INTELLIGENCE BRIEFING: 165.154.105.128/32
## Executive Summary
IP address 165.154.105.128 is associated with UCLOUD INFORMATION TECHNOLOGY HK LIMITED (ASN 135377), operating from Ho Chi Minh City, Vietnam. Current risk assessment indicates MODERATE RISK (score: 65/100). The IP is part of UCLOUD's Vietnam infrastructure (UCLOUD-VN) and is classified as a single-service host with SSH service enabled.
## Ownership and Infrastructure
- Organization: UCLOUD INFORMATION TECHNOLOGY HK LIMITED
- ASN: 135377 (APNIC RIR registry)
- Network: 165.154.105.0/24
- Location: Ho Chi Minh City, Vietnam (900km accuracy radius)
- Network Classification: Cloud infrastructure host
## Threat Indicators
- DNSBL Listings: Listed on 3 of 8 blacklists with high-severity ratings
- Risk Score: 65/100 (Moderate Risk)
- Abuse Density: Subnet classified as "mostly_clean" (abuse density: 1)
- Threat Persistence: No persistent malicious activity detected
- Known Campaigns: None identified
## Network Activity
- Open Services: TCP/22 (SSH) โ OpenSSH 8.0
- DNS Resolution: No PTR records; no forward resolution
- Email Security: SPF/DMARC records not configured
- TLS Certificates: No TLS certificates detected
## Observed Behavior
Observation history contains 24 signals across multiple dates. Recent activity (2026-06-22) shows:
- High-severity blacklist listings (3 sources)
- SSH service banner confirmed
- No certificate matches or campaign correlations
- Route stability maintained
## Neighborhood Context
The /24 subnet (165.154.105.0/24) contains 1 threat sibling among 24 total sibling IPs. Current abuse density is low (0.0), suggesting isolated rather than coordinated activity.
## Recommended Actions
Based on risk profile, the following actions are recommended:
1. Immediate: Increase logging verbosity for all traffic from this IP
2. Firewall Rules: Consider blocking based on risk score
3. Monitoring: Track for escalation in threat indicators
Firewall Implementations:
- iptables: `iptables -A INPUT -s 165.154.105.128 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 165.154.105.128 drop`
- nginx: `deny 165.154.105.128;`
- Cloudflare WAF: Block with expression `ip.src eq 165.154.105.128`
## Assessment
This IP represents cloud infrastructure from a legitimate Vietnamese cloud provider (UCLOUD) but is currently listed on multiple blacklists with high-severity ratings. The moderate risk score warrants monitoring and consideration for blocking, particularly if the IP is observed initiating suspicious outbound connections or receiving targeted attacks.
---
*Intelligence generated using IPDebrief platform tools. All data sourced from active network reconnaissance and threat feeds.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | UCLOUD INFORMATION TECHNOLOGY HK LIMITED |
| ASN | AS135377 |
| Network Name | โ |
| CIDR Block | 165.154.105.0/24 |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_8.0 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 27% | 2 | 3 |
| services | 18% | 2 | 2 |
| ownership | 29% | 3 | 4 |
| reputation | 28% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 27% | 12 | 18 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:51 UTC |
| Last Seen | 2026-06-26 18:10:44 UTC |
| Profile Built | 2026-06-22 19:39:54 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 23 |
Full dossier details are available via our API.