# IP Intelligence Briefing: 183.106.59.245
Classification: Moderate Risk โ Mobile Originated
Date: Current Intelligence
Prepared For: SOC Operations
---
## Executive Summary
IP 183.106.59.245 is a moderate-risk (score 40) mobile-originated address associated with KT Corporation's LTE/5G network in South Korea. While exhibiting no confirmed malicious indicators, the address presents a medium-risk profile due to its mobile carrier classification and open SSH service.
---
## Technical Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 40 (Moderate) |
| **Geolocation** | South Korea โ Gyeongsangbuk-do, Yeongju |
| **ASN** | 4766 (IP Manager) |
| **Organization** | IP Manager |
| **Network Role** | Single-Service Host |
| **Connection Type** | Mobile (KT Corporation LTE/5G) |
| **Abuse Confidence** | Not applicable |
Network Characteristics
- Subnet: 183.106.59.245/24
- Abuse Density: 0 (Clean classification)
- Neighboring IPs: None detected in /24 block
- Route Stability: False (BGP prefix changes observed)
Open Services
- Port 22/TCP: SSH service detected
- TLS Certificates: None
- HTTP Services: None
- DNS: No PTR records or forward resolution
---
## Threat Indicators
| Indicator | Status |
|---|---|
| Known Attacker | Negative |
| Spam Source | Negative |
| Tor Exit Node | Negative |
| Blacklist Count | 0 |
| DNSBL Listed | 2 of 8 lists |
| Campaign Correlation | None |
| Threat Persistence | 0 days |
Threat Assessment: No active threat indicators detected. Historical analysis shows 19 observations with no persistent malicious activity.
---
## Observed Behavior
Historical Analysis
- Observation Count: 19 signals collected
- Last Observation: 2026-06-23
- Threat Persistence: None
- Ownership Changes: 0
The IP has demonstrated stable characteristics with minimal operator score (0.1304) and no significant threat persistence patterns.
---
## Relationship Mapping
- Primary Network: KORNET-KR (Korea Network)
- Relationship Count: 20 entries
- Network Classification: National infrastructure network
All relationships indicate association with Korea's national network infrastructure.
---
## Recommended Actions
Based on risk profile and service exposure:
Firewall Recommendations
```bash
# iptables
iptables -A INPUT -s 183.106.59.245 -j DROP
# nftables
nft add rule inet filter input ip saddr 183.106.59.245 drop
# Nginx
deny 183.106.59.245;
```
WAF/Cloud Recommendations
- Cloudflare WAF: Block with expression `ip.src eq 183.106.59.245`
- AWS WAF: Add address 183.106.59.245/32 to block list
---
## Analyst Notes
Risk Mitigation Priority: MEDIUM
1. Mobile Origin: Connection via KT mobile network suggests potential residential or mobile user traffic. Monitor for unusual data patterns.
2. SSH Exposure: Open port 22 presents exploitation risk. Consider SSH rate limiting or geo-blocking if not required.
3. DNSBL Presence: Listed on 2 of 8 DNSBLs warrants monitoring but does not indicate confirmed malicious activity.
4. No Sibling Threats: Clean subnet classification with no neighboring IP threats detected.
---
## Conclusion
IP 183.106.59.245 presents moderate risk primarily due to mobile carrier classification and SSH service exposure. While no active threats have been identified, the combination of mobile origin and open SSH service warrants defensive positioning. Recommended blocking action is probabilistic and should be evaluated in context of overall threat posture and asset criticality.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IP Manager |
| ASN | AS4766 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | APNIC |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | โ |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 30% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 22% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:59 UTC |
| Last Seen | 2026-06-23 00:05:02 UTC |
| Profile Built | 2026-06-23 00:13:04 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 19 |
Full dossier details are available via our API.