IPDebrief

175.207.239.76

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 175.207.239.76/32

## Executive Summary

IP address 175.207.239.76 is classified as high risk with a risk score of 70/100. The IP is registered to ASN 4766 (IP Manager) under APNIC and is located in Jeju City, South Korea (KR). The address is associated with mobile carrier KT Corporation and operates as a web server with HTTP, HTTPS, and SSH services enabled.

## Risk Profile

The IP received a risk score of 70, indicating elevated threat activity. The address appears on four out of eight DNS blacklist lists. Control plane analysis shows BGP origin through ASN 4766 with prefix 175.200.0.0/13. RPKI validation and IRR consistency were not definitively resolved in available data. The operator score registered as "Basic" (0.3478), suggesting limited routing infrastructure.

## Geolocation and Ownership

Geolocation data indicates South Korea (KR) with coordinates 35.91°N, 127.77°E in Jeju City. The IP is associated with mobile carrier KT Corporation (KT), utilizing LTE/5G connection technology. Ruckus Wireless Inc. issued an SSL certificate (SN-382202006472) associated with this address.

## Network Services

Open ports identified:

HTTP probing returned 503 Service Unavailable responses with HTTP/1.1 protocol. The server did not present identifiable application banners or technology fingerprints.

## Threat Indicators

Current threat indicators include blacklist presence across multiple feeds. The IP is not identified as a Tor exit node or known attacker. No active campaigns were correlated. The temporal data shows one threat observation with zero persistent malicious activity detected.

## Neighborhood Analysis

Subnet 175.207.239.76/24 shows mostly_clean classification with abuse density of 0. Two sibling IPs exist in the /24 range, with one active threat sibling identified at 175.207.239.222 (risk score 70, authority score 50).

## Observation History

28 signals were recorded over the observation period. Recent listings show blacklisting activity across 8 total lists with maximum severity rated high. Geolocation inference consistently points to South Korea. Operator assessments remain at Basic level.

## Recommended Actions

Based on the risk profile, the following defensive measures are recommended:

Firewall Rules:

Monitoring:

Increase logging verbosity and review recent activity from this IP due to the elevated risk score of 70/100.

## Intelligence Conclusion

IP 175.207.239.76 represents a high-risk endpoint requiring defensive attention. The combination of blacklist presence, operator classification, and neighborhood threat density suggests potential abuse activity. Recommended firewall blocking is supported by the risk score assessment, though correlation with additional threat intelligence feeds is advised before implementing permanent blocking policies.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฐ๐Ÿ‡ท South Korea
Region49
CityJeju City
TimezoneAsia/Seoul
Latitude35.91
Longitude127.77

๐Ÿข Ownership & Registration

OrganizationIP Manager
ASNAS4766
Network Nameโ€”
CIDR Block175.200.0.0/13
RIRAPNIC
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAAPresent

โ˜๏ธ Network Classification

InfrastructureMobile
Service PurposeWeb Server
Network TierUnknown โ€” Insufficient routing data to classify
Mobile

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
443httpstcpโ€”
22sshtcpโ€”
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
C=US, S=California, L=Sunnyvale, O=Ruckus Wireless Inc., CN=SN-382202006472
Issued by C=US, S=California, L=Sunnyvale, O=Ruckus Wireless Inc., CN=RuckusPKI-DeviceSubCA-1
Self-signed: No
SANsNone
Valid From2022-09-03T08:45:15+00:00
Valid Until2047-09-04T08:45:15+00:00
TLS ProtocolTls12
Cipher SuiteTLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period9132 days
Serial Number6610CE5D
Thumbprint0131EAC99EFDF1712381849FEB02CABDC35D2AB6

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
30%
24
routing
27%
23
services
29%
24
ownership
24%
34
reputation
21%
13
geolocation
21%
22
Overall25%1220
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceMixed Signals (68%) โ€” 2 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Geo sources disagree on country: KR, US
โš  TLS certificate claims US but primary geo says KR

๐Ÿ“… Observation Timeline ๐Ÿ”„ Fresh

First Seen2026-05-07 23:03:55 UTC
Last Seen2026-06-26 18:10:47 UTC
Profile Built2026-06-25 05:23:40 UTC
Data FreshnessFresh
Signal Types27
Total Observations28
๐Ÿ” 27 signal types ยท 28 observations collected
This report is generated from 27+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.