# IP INTELLIGENCE BRIEFING: 180.93.228.187
Classification: Moderate Risk | Risk Score: 55/100 | Date: 2026-07-30
---
## Executive Summary
IP address 180.93.228.187 originates from Vietnam via ASN 7602 (IRT-VNNIC-AP, SPT-VN). The IP demonstrates moderate risk with a score of 55/100. No active threat indicators detected, but three DNSBL listings and elevated risk classification warrant monitoring. The /24 subnet is classified as clean with zero abuse density and no threat siblings.
---
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **ASN** | 7602 (IRT-VNNIC-AP) |
| **Network** | SPT-VN (180.93.0.0/16) |
| **Country** | Vietnam (VN) |
| **RIR** | APNIC |
| **Status** | Active |
| **Service Purpose** | Firewalled / No Services |
Network Classification: No open ports detected. No TLS certificates, HTTP services, or email authentication (SPF/DMARC) configured.
---
## Threat Assessment
Threat Indicators:
- No known campaigns or threat feeds associated
- Not identified as Tor exit node, known attacker, or spam source
- Blacklist count: 0
- DNSBL listings: 3 of 8 total lists
Risk Factors:
- Elevated risk score (55/100) triggers monitoring recommendation
- DNSBL presence indicates historical or current reputation concerns
- No persistent malicious behavior observed
---
## Geolocation & Network Signals
| Metric | Value |
|---|---|
| **Country** | Vietnam (VN) |
| **RTT (avg)** | 264.8ms |
| **Distance** | 9,325 km |
| **GeoConsensus** | Validated (600km accuracy) |
| **Probe Count** | 5 |
Geolocation data from multiple sources confirms Vietnam origin. RTT metrics are plausible for Vietnamese infrastructure.
---
## Neighborhood Analysis
Subnet: 180.93.228.187/24
- Abuse Density: 0.0 (clean)
- Threat Siblings: 0
- Active Siblings: 0
- Classification: Clean
No neighboring IPs detected in immediate vicinity. Subnet shows no inherited risk from adjacent addresses.
---
## Relationship Graph
All detected relationships map to "Same Network" (SPT-VN). No external associations with organizations, hostnames, or certificates identified.
---
## Temporal Analysis
- Observation Count: 13 historical signals
- Ownership Changes: 0 (stable)
- Threat Persistence: 0 days
- Persistently Malicious: No
Recent observations (2026-07-30) show clean classification and consistent geolocation signals.
---
## Recommended Actions
Priority: Monitor / Consider Blocking
Firewall Rules:
- iptables: `iptables -A INPUT -s 180.93.228.187 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 180.93.228.187 drop`
- nginx: `deny 180.93.228.187;`
- Cloudflare WAF: Block expression: `ip.src eq 180.93.228.187`
- AWS WAF: `Addresses: ["180.93.228.187/32"]`
Rationale: Elevated risk score (55/100) with DNSBL presence warrants proactive blocking or enhanced logging and monitoring.
---
## Intelligence Conclusion
This IP represents Vietnamese infrastructure from a legitimate provider (IRT-VNNIC-AP) but carries moderate risk due to DNSBL listings and elevated risk classification. The clean neighborhood and stable ownership suggest this may be an isolated incident rather than coordinated malicious activity. Recommend blocking or monitoring based on operational tolerance thresholds.
Status: Actionable intelligence for defensive security operations.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-VNNIC-AP |
| ASN | AS7602 |
| Network Name | SPT-VN |
| CIDR Block | 180.93.0.0/16 |
| RIR | APNIC |
| Country | VN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 5 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-27 15:46:26 UTC |
| Last Seen | 2026-08-04 17:59:18 UTC |
| Profile Built | 2026-07-30 13:15:10 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 19 |
Full dossier details are available via our API.