# INTELLIGENCE BRIEFING: 180.230.46.67/32
Classification: LOW RISK / DEFENSIVE MONITORING
Report Date: 2026-07-23
Intel Confidence: MEDIUM (geo validation discrepancy noted)
---
## EXECUTIVE SUMMARY
Target IP 180.230.46.67 is classified as LOW RISK (score: 25). The address exhibits minimal threat indicators with no active services, no blacklist entries, and zero observed malicious activity. However, geographic validation discrepancies require monitoring.
---
## NETWORK ATTRIBUTES
IP Address: 180.230.46.67/32
Control Plane:
- Origin ASN: 17858
- BGP Prefix: 180.228.0.0/14
- Route Stability: UNSTABLE (isRouteStable: false)
- RPKI State: Not Validated
- DNSSEC: VALID
- DNSBL Listings: 1 of 8 total lists
Geolocation Data:
- Primary Classification: US (New York, NY)
- Alternative Sources: South Korea (Cheonan, Chungcheongnam-do)
- RIR Registry: APNIC
- Network Name: Xpeed-KR / IP Manager
- Abuse Contact: hostmaster@nic.or.kr
- *Note: Geographic consensus is false with conflicting sources*
Network Role: Firewalled / No Services (no open ports detected)
---
## THREAT ASSESSMENT
Risk Indicators:
- Risk Score: 25 (Low Risk)
- Provider Score: 0
- Authority Score: 0
- Blacklist Count: 0
- Known Campaigns: None
- Threat Feeds: Empty
Malicious Activity:
- Is Tor Exit: False
- Is Known Attacker: False
- Is Spam Source: False
- Is Proxy/Vpn/Cdn: False
- Is Hosting: False
- Honeypot Hits: 0
- WAF Violations: 0
- Enumeration Strikes: 0
---
## OBSERVATION HISTORY
Total Observations: 14 signals recorded
Recent Timeline (July 23, 2026):
- 12:35:24 UTC: Geolocation signal (South Korea, confidence 0.35)
- 12:35:00 UTC: Geolocation signal (Cheonan, KR, confidence 0.70)
- 12:35:32 UTC: Ownership/registration data (IP Manager, APNIC)
- 12:36:16 UTC: Ownership status signal (no changes detected)
Temporal Analysis:
- Ownership Changes: 0
- Threat Persistence Days: 0
- Threat Observation Count: 0
- Persistently Malicious: False
---
## RELATIONSHIP GRAPH
No relationships detected. The IP has no links to:
- Related subnets
- Associated hostnames
- Linked organizations
- Correlated certificates
---
## SUBNET NEIGHBORHOOD ANALYSIS
Subnet: 180.230.46.67/24
Neighbor Count: 0
Abuse Density: 0
Risk Distribution:
- High Risk: 0
- Medium Risk: 0
- Low Risk: 0
Threat Siblings: 0 active threat IPs in adjacent address space
---
## OPERATIONAL PROFILE
Services: None detected (no open ports)
DNS: No PTR records, no forward resolution
Email: No SPF/DMARC records, no hosted domains
HTTP: No web services, no TLS certificates
Traceroute: 20 hops, Comcast transit network detected
---
## RECOMMENDED ACTIONS
Firewall Rules:
No blocking required at this time. IP maintains low-risk profile.
Monitoring Recommendations:
1. Monitor geographic validation discrepancy (US vs KR sources)
2. Track route stability changes (current status: unstable)
3. Watch for DNSBL listing changes (currently listed on 1 of 8 feeds)
4. Consider periodic re-scanning due to route instability
Classification: Defensive monitoring only. No immediate blocking or threat response actions warranted.
---
END OF BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | IP Manager |
| ASN | AS17858 |
| Network Name | Xpeed-KR |
| CIDR Block | 180.224.0.0/13 |
| RIR | APNIC |
| Country | KR |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS17858 |
| Network Prefix | 180.228.0.0/14 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-04 17:23:55 UTC |
| Last Seen | 2026-07-23 12:34:11 UTC |
| Profile Built | 2026-07-23 12:41:43 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 16 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 180.230.46.67
Who owns the IP address 180.230.46.67?
180.230.46.67 is registered to IP Manager. The address falls within the 180.224.0.0/13 network block. Registration is held at APNIC.
Where is 180.230.46.67 located?
Geolocation data places 180.230.46.67 in Cheonan, Chungcheongnam-do, South Korea. The local time zone is Asia/Seoul. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 180.230.46.67 malicious or safe?
180.230.46.67 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
Is 180.230.46.67 a VPN, proxy, or data center address?
180.230.46.67 is classified as a mobile network based on network ownership and behavioural analysis.