Intelligence Briefing: 175.157.27.116/32
The IP address was classified as Moderate Risk with a risk score of 40. Registration records assigned the address to ASN 18001 (ip noc, DIALOG-LK) within the APNIC RIR, with geolocation data placing the endpoint in London, GB.
Threat analysis detected no active indicators. The address was not flagged as a Tor exit node, known attacker, or spam source, and reported zero blacklist listings. Network scanning returned no open ports or active services, indicating a firewalled state. DNSSEC validation was confirmed valid, though route stability was reported as unstable.
No immediate containment actions are required based on available data. SOC teams should maintain monitoring due to the moderate risk classification and inconsistent route stability.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | ip noc |
| ASN | AS18001 |
| Network Name | DIALOG-LK |
| CIDR Block | 175.157.0.0/16 |
| RIR | APNIC |
| Country | LK |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS18001 |
| Network Prefix | 175.157.24.0/21 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 25% | 1 | 1 |
| geolocation | 25% | 1 | 1 |
| Overall | 26% | 7 | 8 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-10 14:01:07 UTC |
| Last Seen | 2026-08-26 15:21:44 UTC |
| Profile Built | 2026-08-29 08:01:12 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 21 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 175.157.27.116
Who owns the IP address 175.157.27.116?
175.157.27.116 is registered to ip noc. The address falls within the 175.157.0.0/16 network block. Registration is held at APNIC.
Where is 175.157.27.116 located?
Geolocation data places 175.157.27.116 in London, Western Province, United Kingdom. The local time zone is Europe/London. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 175.157.27.116 malicious or safe?
175.157.27.116 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.