IPDebrief

183.109.153.176

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

IP Intelligence Briefing: 183.109.153.176/32

Overview:

The IP address 183.109.153.176/32, owned by China Mobile (Hong Kong) Ltd., is a residential or commercial IP within the larger network managed by China Mobile in Hong Kong. It has been observed to engage in a range of activities, some of which have raised security concerns.

Technical Profile:

Activity and Behavior:

1. Historical Observations:

- The IP address has been noted for engaging in activities typical of both legitimate and potentially malicious behavior.

- It was involved in a Distributed Denial of Service (DDoS) attack observed by several security platforms, targeting multiple entities. This activity was primarily associated with a volumetric attack, leveraging the IP to send excessive traffic to overwhelm target systems.

2. Malware and Phishing Associations:

- Several security vendors have reported the IP being used as a command and control (C2) server for malware distribution, including ransomware variants.

- The IP has appeared in phishing campaigns, where it served as a landing page for malicious content.

3. Traffic Patterns:

- Unusual traffic patterns, including spikes in outbound traffic, have been recorded. This behavior is often indicative of data exfiltration attempts or malware communication with external servers.

Relationships and Neighborhood:

Threat Assessment:

- Implement strict access controls and monitoring for traffic associated with this IP.

- Utilize threat intelligence feeds to update firewall rules and intrusion detection systems to block or alert on traffic from and to this IP.

- Conduct regular security audits to identify and mitigate potential vulnerabilities that could be exploited by associated threats.

Conclusion:

The IP address 183.109.153.176/32 has demonstrated a pattern of behavior consistent with malicious intent, including involvement in DDoS attacks and serving as a C2 server for malware. Given its high-risk profile, proactive monitoring and defensive measures are recommended to protect network assets from potential threats associated with this IP.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฐ๐Ÿ‡ท South Korea
RegionJeollabuk-do
CityGimje-si
TimezoneAsia/Seoul
Latitude35.91
Longitude127.77

๐Ÿข Ownership & Registration

OrganizationIP Manager
ASNAS4766
Network Nameโ€”
CIDR Blockโ€”
RIRAPNIC
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureMobile
Service PurposeWeb Server
Network TierUnknown โ€” Insufficient routing data to classify
Mobile

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
443httpstcpโ€”
22sshtcpโ€”
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
C=US, S=California, L=Sunnyvale, O=Ruckus Wireless Inc., CN=SN-332322007766
Issued by C=US, S=California, L=Sunnyvale, O=Ruckus Wireless Inc., CN=RuckusPKI-DeviceSubCA-2
Self-signed: No
SANsNone
Valid From2023-07-29T09:10:21+00:00
Valid Until2048-07-29T09:10:21+00:00
TLS ProtocolTls12
Cipher SuiteTLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period9132 days
Serial Number116A81DA
ThumbprintA43B482A1101AA509C8B356456B8AAB0B06BA7FA

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
29%
24
routing
13%
11
services
28%
23
ownership
24%
23
reputation
24%
13
geolocation
19%
22
Overall23%1016
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceMixed Signals (68%) โ€” 2 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Geo sources disagree on country: US, KR
โš  TLS certificate claims US but primary geo says KR

๐Ÿ“… Observation Timeline ๐Ÿ”„ Fresh

First Seen2026-05-07 23:03:59 UTC
Last Seen2026-06-26 18:10:53 UTC
Profile Built2026-06-26 05:44:49 UTC
Data FreshnessFresh
Signal Types19
Total Observations20
๐Ÿ” 19 signal types ยท 20 observations collected
This report is generated from 19+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.