# IPDEBRIEF THREAT INTELLIGENCE BRIEFING
IP Address: 182.9.2.216/32
Classification: Moderate Risk (Score: 65/100)
Date: 2026-07-30
---
## EXECUTIVE SUMMARY
IP 182.9.2.216 is a moderate-risk Indonesian infrastructure address associated with IRT-IDNIC-ID (ASN 23693). Despite an elevated risk score, the IP shows no active malicious indicators, no known threat campaigns, and no running services. The risk score is primarily driven by DNSBL listings (3/8) and geolocation validation anomalies.
---
## OWNERSHIP & GEOLOCATION
- Organization: IRT-IDNIC-ID (TELKOMSEL-ID)
- ASN: 23693 (APNIC RIR)
- Country: Indonesia (ID)
- Region: Bengkulu
- CIDR Block: 182.0.0.0/12
- Registration: Network registration details available via RDAP
---
## THREAT INDICATORS
- Risk Score: 65/100 (Moderate)
- Blacklist Status: 0 blacklists (blacklistCount: 0)
- DNSBL Listings: 3/8 total lists
- Tor Exit: No
- Known Attacker: No
- Spam Source: No
- Abuse Confidence Score: Not calculated
- Campaign Association: None detected
---
## NETWORK PROFILE
- Service Status: Firewalled / No Services Detected
- Open Ports: None
- DNS Status: No PTR records, forward resolution failed
- TLS/HTTPS: Not detected
- Network Classification: Provider infrastructure
- Mobile: No
- Residential: No
- CDN/Proxy/VPN: No
---
## OBSERVATION HISTORY
- Total Observations: 13 signals
- Recent Activity: All observations from 2026-07-30
- Threat Persistence: 0 days
- Ownership Changes: 0
- Threat Observation Count: 0
- Is Persistently Malicious: No
Key Findings: No temporal escalation in risk. The IP has remained static with no evidence of becoming more or less dangerous over the observation period.
---
## NEIGHBORHOOD ANALYSIS (182.9.2.0/24)
- Abuse Density: 0 (Low)
- Total Siblings: 3
- Risk Distribution: High: 0, Medium: 0, Low: 3
- Neighbor IPs:
- 182.9.2.50 (Risk: 25)
- 182.9.2.115 (Risk: 0)
- 182.9.2.144 (Risk: 25)
The /24 subnet exhibits low abuse density with no high-risk neighbors.
---
## RELATIONSHIP GRAPH
- Same Network Links: 2 relationships to TELKOMSEL-ID network
- Related Hostnames: None
- Associated Organizations: None beyond network owner
- Certificates: None detected
---
## RECOMMENDED ACTIONS
Immediate
1. Increase Logging Verbosity โ Review recent activity from this IP due to elevated risk score (65/100)
Firewall Implementation
- iptables: `iptables -A INPUT -s 182.9.2.216 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 182.9.2.216 drop`
- nginx: `deny 182.9.2.216;`
- pfSense: Add 182.9.2.216/32 to block list
- Cloudflare WAF: Block IP with expression `ip.src eq 182.9.2.216`
- AWS WAF: Add 182.9.2.216/32 to IP set
---
## ANALYST NOTES
While the risk score of 65 suggests caution, the absence of active threat indicators, known campaigns, and malicious behavior suggests this may be a false positive or dormant infrastructure. The moderate risk classification is driven by DNSBL listings rather than confirmed malicious activity. Monitor for service discovery or behavioral changes. No immediate threat to SOC operations detected, but logging and monitoring recommended.
---
*Intelligence generated by IPDebrief. Recommendations are probabilistic and should be combined with additional signals before taking action.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-IDNIC-ID |
| ASN | AS23693 |
| Network Name | TELKOMSEL-ID |
| CIDR Block | 182.0.0.0/12 |
| RIR | APNIC |
| Country | ID |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-29 10:33:44 UTC |
| Last Seen | 2026-07-31 05:28:03 UTC |
| Profile Built | 2026-07-30 21:19:43 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 19 |
Full dossier details are available via our API.