## IP Intelligence Briefing: 180.246.206.137/32
Date: 2026-07-29
Analyst: Automated Threat Intelligence System
Classification: Moderate Risk
---
Executive Summary
IP address 180.246.206.137 is classified as Moderate Risk (Risk Score: 50). The address is assigned to PT Telkom Indonesia (ASN 7713) but displays inconsistent geolocation data. No active malicious services detected, but DNSBL listings warrant monitoring.
---
Ownership and Network Classification
- ASN: 7713 (PT Telkom Indonesia APNIC Resources Management)
- CIDR Block: 180.246.192.0/19
- Network Name: TLKM_BB_INF_180_246
- RIR: APNIC
- Classification: Infrastructure/Telecom
- Service Status: Firewalled / No Services (No open ports detected)
---
Geolocation Analysis
Data Inconsistency Detected:
- Primary geolocation: US (Chicago, IL)
- Historical geolocation: Indonesia (Jakarta)
- Status: GEO_INCONSISTENT β Multiple geo sources reporting conflicting locations. This discrepancy may indicate routing anomalies or data pollution.
---
Threat Indicators
- Risk Score: 50 (Moderate)
- Blacklist Count: 0
- DNSBL Listed: 2 of 8 total lists
- DNSBL Max Severity: High
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
---
Neighborhood Assessment (180.246.206.0/24)
- Abuse Density: 0.0
- Subnet Classification: Clean
- Active Siblings: 0
- Threat Siblings: 0
- Risk Distribution: High: 0, Medium: 0, Low: 0
The /24 subnet shows no elevated abuse activity. This IP exists in isolation within its subnet.
---
Observation History
Total Observations: 13 signals over monitoring period
Key Historical Signals:
- Ownership consistency: No changes detected
- Threat persistence: 0 days (not persistently malicious)
- Geo inconsistencies: Confirmed between US and ID sources
- DNSBL activity: High-severity listings detected in recent observations
---
Relationship Graph
Detected Relationships: 3 (all internal)
- Network relationships: TLKM_BB_INF_180_246 (repeated entries)
- No external relationships to hostnames, organizations, or certificates detected
---
Recommended Actions
Immediate (Automated):
```bash
# Firewall/Blocking Rules
iptables -A INPUT -s 180.246.206.137 -j DROP
nft add rule inet filter input ip saddr 180.246.206.137 drop
```
Application-Level:
- NGINX: `deny 180.246.206.137;`
- pfSense: Block 180.246.206.137/32
- Cloudflare WAF: Block rule with expression `ip.src eq 180.246.206.137`
- AWS WAF: Add address 180.246.206.137/32 to block list
Recommended by Risk Score: 50 (Moderate)
---
Intelligence Assessment
The IP presents a Moderate Risk profile with several key observations:
1. Geolocation Discrepancy: The conflict between Indonesian ASN ownership and US geolocation requires validation. This may indicate transit routing through US networks or data quality issues.
2. DNSBL Presence: Despite zero traditional blacklists, 2 of 8 DNSBL listings with high severity suggest some reputation concerns.
3. Clean Neighborhood: The /24 subnet shows no abuse activity, suggesting this IP may be flagged in isolation rather than as part of a coordinated campaign.
4. No Active Services: No open ports or services detected, reducing immediate exploitation risk.
Recommendation: Monitor for emerging threat indicators. The moderate risk score combined with DNSBL activity and geolocation inconsistency suggests this IP should be monitored but does not require immediate blocking unless additional contextual threat data emerges.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | PT Telkom Indonesia APNIC Resources Management |
| ASN | AS7713 |
| Network Name | TLKM_BB_INF_180_246 |
| CIDR Block | 180.246.192.0/19 |
| RIR | APNIC |
| Country | ID |
| Abuse Contact | β |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 4% | 1 | 1 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-22 07:15:40 UTC |
| Last Seen | 2026-07-30 11:03:29 UTC |
| Profile Built | 2026-07-29 12:43:36 UTC |
| Data Freshness | Live |
| Signal Types | 14 |
| Total Observations | 14 |
Full dossier details are available via our API.