# IP Intelligence Briefing: 180.180.232.242
Classification: HIGH RISK (Score: 80)
Date: Current Analysis
Origin: Thailand (Bangkok) / TOT Public Company Limited
---
## Executive Summary
IP 180.180.232.242 is a high-risk endpoint (Score: 80) assigned to TOT Public Company Limited's 180.180.0.0/16 network. The IP exhibits characteristics of a residential/ISP-managed endpoint with no active services, yet maintains elevated risk designation. Evidence includes DNSBL listings (6 of 8 lists), route instability, and geographic inconsistencies in observation data.
---
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **ASN** | 23969 (TOT-AS-AP) |
| **Network** | 180.180.0.0/16 |
| **Geolocation** | Bangkok, Thailand (TH) |
| **IP Type** | Dynamic Residential/ISP |
| **PTR Hostname** | node-1a0i.pool-180-180.dynamic.nt-isp.net |
| **Services** | None (Firewalled) |
| **Open Ports** | 0 |
---
## Threat Indicators
- Risk Score: 80 (High)
- DNSBL Listings: 6 of 8 lists
- Abuse Confidence: Elevated due to blacklist presence
- Threat Indicators: None detected directly
- Known Attacker: No
- Tor Exit: No
- Spam Source: No
Note: Despite lack of direct threat indicators, the IP carries high risk due to DNSBL listings and network-level reputation.
---
## Network Context
Subnet Analysis (180.180.232.0/24):
- Abuse Density: 1
- Classification: Mostly Clean
- Threat Siblings: 1
- Active Siblings: 0
Control Plane:
- BGP Prefix: 180.180.232.0/24
- Route Stability: Unstable (route changes in 30 days)
- DNSSEC Valid: Yes
- Operator Score: 0.2609 (Basic)
---
## Observation History
Recent observations (July 2026) reveal:
- Geolocation Signals: Mixed signals indicating Thailand (TH, Bangkok) and Los Angeles (US-CA)
- RTT Measurements: Average 270.6ms (minimum plausible: 181.3ms)
- Distance: 9064.4 km from probe origin
- Geo Validation: Plausible (5 probes)
- Abuse Density Signals: Classified as "mostly_clean" with inherited risk of 2
---
## Relationships
- Network Associations: TOT-AS-AP (multiple entries)
- DNS Associations: node-1a0i.pool-180-180.dynamic.nt-isp.net
- No Certificate Associations: None detected
---
## Recommended Actions
Firewall Rule (iptables/nftables):
```bash
# Block high-risk IP
iptables -A INPUT -s 180.180.232.242 -j DROP
# OR allow-list if business-critical:
iptables -A INPUT -s 180.180.232.242 -j ACCEPT
```
WAF Rules (Cloudflare/AWS):
- Block IP at edge or create IP allow-list exception
- Monitor for connection attempts from this subnet
Monitoring Priority:
- Monitor 180.180.232.0/24 for correlated activity
- Watch for new DNSBL additions
- Track route changes affecting 180.180.232.0/24
---
## Intelligence Notes
The IP is a dynamic residential/ISP endpoint with no active services. The high-risk score appears to be derived from DNSBL listings rather than active exploitation. The geographic signal inconsistency (TH vs US) may indicate routing anomalies or probe path issues. The subnet shows low abuse density but one threat sibling warrants monitoring.
Assessment: Monitor rather than block immediately. No evidence of active malicious activity, but maintain visibility due to DNSBL presence and network reputation.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | TOT Public Company Limited |
| ASN | AS23969 |
| Network Name | TOT-AS-AP |
| CIDR Block | 180.180.0.0/16 |
| RIR | APNIC |
| Country | TH |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | node-1a0i.pool-180-180.dynamic.nt-isp.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | node-1a0i.pool-180-180.dynamic.nt-isp.net |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_8.8 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 25% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 22% | 6 | 7 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-27 15:46:25 UTC |
| Last Seen | 2026-08-05 00:08:01 UTC |
| Profile Built | 2026-07-30 13:15:10 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 23 |
Full dossier details are available via our API.