IP Intelligence Briefing: 175.207.208.221
*Generated via IPDebrief Analysis*
---
**Risk Assessment**
- Overall Risk Score: Low Risk (0/100)
- Threat Indicators: No malicious activity detected (no malware, phishing, or C2 indicators).
- Network Classification: Firewalled / No Services (no open ports or active domains).
- Provider: Korea Telecom (KORNET-KR, ASN 4766), South Korea.
---
**Geolocation & Ownership**
- Location: Jeju City, Jeju-do, South Korea (33.49°N, 126.48°E).
- ASN: 4766 (KIXS-AS-KR-KR) | ISP: Korea Telecom.
- Subnet: 175.207.208.0/24 (abuse density: 1/100, classified as "mostly clean").
---
**Threat Observations**
- Historical Activity:
- 18 observations over 30 days, including DNS queries and subnet analysis.
- No persistent threats or malicious campaigns detected.
- DNSSEC and CAA records validated (no misconfigurations).
- DNS: No PTR records or associated domains.
---
**Network Relationships**
- Linked Entities:
- Same network: KORNET-KR (175.207.208.0/24).
- No other subnets, organizations, or certificates tied to the IP.
- Neighbors: 0 active IPs in the subnet (no siblings or threat siblings).
---
**Actionable Insights**
- No Immediate Mitigation Needed: The IP shows no signs of exploitation or malicious intent.
- Monitor for Anomalies: Track DNS activity or unexpected subnet changes, as the IPโs history includes sparse DNS queries.
- SOC Recommendations:
- Maintain current firewall rules (no blocking required).
- Validate DNSSEC configurations for associated subnets.
---
*End of Briefing*
*Generated by IPDebrief | © 2026 Jason Alberino*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IP Manager |
| ASN | AS4766 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | APNIC |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Web Server |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | โ |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | 2022-02-12T08:21:04+00:00 |
| Valid Until | 2047-02-13T08:21:04+00:00 |
| TLS Protocol | Tls12 |
| Cipher Suite | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 9132 days |
| Serial Number | 48CAF4D5 |
| Thumbprint | 032D58C9EF803C1ADA72AC063451791C65EE790F |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 42% | 2 | 3 |
| routing | 25% | 1 | 1 |
| services | 19% | 1 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 28% | 1 | 3 |
| geolocation | 13% | 1 | 1 |
| Overall | 26% | 8 | 13 |
| Data Coherence | Mixed Signals (68%) โ 2 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
โ TLS certificate claims US but primary geo says KR
๐ Observation Timeline ๐ Fresh
| First Seen | 2026-05-16 02:54:38 UTC |
| Last Seen | 2026-06-26 18:10:47 UTC |
| Profile Built | 2026-06-25 17:21:51 UTC |
| Data Freshness | Fresh |
| Signal Types | 23 |
| Total Observations | 24 |
Full dossier details are available via our API.