IPDebrief

183.99.71.185

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 183.99.71.185

Classification: Low Risk โ€“ Mobile Endpoint

Date of Analysis: 2026-06-23

Prepared For: SOC Operations Team

---

## Executive Summary

IP address 183.99.71.185 is a low-risk mobile endpoint assigned to South Korea's APNIC region. The IP operates within the KT Corporation (KT) mobile network infrastructure and is classified as firewalled with no active services. Historical monitoring indicates minimal threat persistence, and no known malicious campaigns correlate with this address.

---

## Technical Profile

AttributeValue
**Risk Score**25 (Low Risk)
**ASN**4766 (IP Manager)
**Organization**IP Manager
**Country**South Korea (KR)
**Region**Gyeonggi-do, Seongnam-si
**Mobile Carrier**KT Corporation (MCC: 450, MNC: 08)
**Connection Type**LTE/5G Mobile
**Geolocation Accuracy**250 km radius
**Service Purpose**Firewalled / No Services

---

## Threat Assessment

Current Threat Status

Control Plane Analysis

---

## Network Neighborhood Analysis

Subnet: 183.99.71.185/24

Classification: Mostly Clean

Abuse Density: 1 (Low)

Total Siblings: 1

Active Siblings: 0

Threat Siblings: 1

The immediate /24 subnet demonstrates minimal abuse activity with a single threat sibling observed historically. No neighboring IPs currently show active threat indicators.

---

## Relationship Graph

The IP exhibits 14 relationship entries, all classified as "Same Network" pointing to KORNET-KR. This indicates the IP is part of a larger network infrastructure managed under the same organizational entity, with no cross-network relationships detected.

---

## Observation History

Total Observations: 15

Time Range: 2026-06-17 to 2026-06-23

Signal Types Monitored:

Temporal Analysis:

The IP has demonstrated stable characteristics with no significant ownership changes or persistent malicious behavior patterns over the monitoring period.

---

## Service & DNS Analysis

The absence of open ports and forward DNS resolution confirms the IP is not actively hosting services or resolving to public domains.

---

## Recommended Security Actions

Current Action Level: Monitor

Firewall Rules: None required at this time

Recommendations: None

Suggested Monitoring Parameters

1. Traffic Baselines: Monitor for unusual outbound connection patterns

2. Geolocation Validation: Verify traffic originates from South Korea as expected

3. Mobile Network Classification: Confirm continued mobile carrier association

4. DNSBL Watch: Monitor the 1 DNSBL listing for potential changes

---

## Intelligence Narrative

This IP address represents a mobile endpoint within South Korea's telecommunications infrastructure. The low risk score (25) and absence of threat indicators suggest benign operational characteristics. The single DNSBL listing may warrant periodic review but does not indicate active malicious activity.

The mobile classification (KT Corporation LTE/5G) combined with firewalled status and no open services indicates this endpoint is likely a consumer or enterprise mobile device. The absence of persistent malicious behavior across 15 observation cycles supports classification as low-risk infrastructure.

Actionable Intelligence: No immediate blocking or mitigation required. Standard monitoring protocols apply.

---

Data Sources: IPDebrief Intelligence Platform

Analysis Confidence: High (multiple validation signals)

Next Review: 30 days or upon threat indicator emergence

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฐ๐Ÿ‡ท South Korea
RegionGyeonggi-do
CitySeongnam-si
TimezoneAsia/Seoul
Latitude35.91
Longitude127.77

๐Ÿข Ownership & Registration

OrganizationIP Manager
ASNAS4766
Network Nameโ€”
CIDR Blockโ€”
RIRAPNIC
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureMobile
Service PurposeFirewalled / No Services
Network TierUnknown โ€” Insufficient routing data to classify
Mobile

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
29%
23
routing
13%
11
services
8%
11
ownership
30%
23
reputation
28%
13
geolocation
21%
22
Overall21%913
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-07 23:04:00 UTC
Last Seen2026-06-23 00:24:47 UTC
Profile Built2026-06-23 00:31:27 UTC
Data FreshnessLive
Signal Types15
Total Observations16
๐Ÿ” 15 signal types ยท 16 observations collected
This report is generated from 15+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.