# IPDebrief Intelligence Briefing
Target IP: 185.189.160.105/32
Classification: Low Risk / Clean
Analysis Date: Current Observation Cycle
Risk Score: 0/100
---
## Executive Summary
IP address 185.189.160.105 is classified as Low Risk with no active threat indicators. The address belongs to Gigabit TW (ASN 55720) and operates within the 185.189.160.0/24 block. Current observations show no malicious activity, open services, or threat associations.
---
## Network Ownership & Registration
| Attribute | Value |
|---|---|
| **ASN** | 55720 |
| **Organization** | GIGABIT-MY - Gigabit Hosting Sdn Bhd, MY |
| **Netname** | DCNL-HK |
| **Registry** | APNIC |
| **Allocation Date** | 2017-02-10 |
| **CIDR Block** | 185.189.160.0/24 |
| **Abuse Contact** | Available via RDAP |
Geolocation Discrepancy Note: ASN registration indicates Malaysia (MY) under APNIC, while current geolocation reports Chicago, US. Distance from claimed location: 9,348.8 km. This discrepancy warrants monitoring but does not indicate malicious activity.
---
## Threat Assessment
Current Status
- Risk Score: 0 (Low Risk)
- Abuse Confidence Score: None
- Blacklist Count: 0 (historically 8 DNSBL listings)
- Known Campaigns: None
- Is Known Attacker: No
- Is Spam Source: No
- Is Tor Exit Node: No
- Is Proxy: No
Threat Indicators
- Active Threat Feeds: None
- Campaign Likelihood: None
- Correlated IPs: 0
- Certificate Matches: 0
- Banner Matches: 0
---
## Network Neighborhood Analysis
| Metric | Value |
|---|---|
| **Subnet** | 185.189.160.0/24 |
| **Abuse Density** | 0 (Clean) |
| **Total Siblings** | 1 |
| **Active Siblings** | 0 |
| **Threat Siblings** | 0 |
| **Risk Distribution** | High: 0, Medium: 0, Low: 0 |
Assessment: The /24 subnet shows no threat siblings and zero abuse density. This indicates a clean network segment with no observed malicious activity from adjacent addresses.
---
## Service & Network Role
- Open Ports: None detected
- TLS Certificate: None
- HTTP Title: None
- Server Banner: None
- Service Purpose: Firewalled / No Services
- Infrastructure Type: Not classified as CDN, Cloud, VPN, or Hosting
- Connection Type: Not classified
Assessment: The IP is currently firewalled with no open services, reducing attack surface and limiting exploitation opportunities.
---
## DNS Analysis
- PTR Hostnames: None
- Forward Resolution: 0 records
- DNSSEC Valid: Yes
- Hosted Domains: 0
- SPF/DMARC: Not configured
- Email Auth: Not applicable
---
## Observation History (13 Total Observations)
Recent Signals (2026-07-23)
- Geo Probe: Confidence 90%, 5 probes, avg RTT 210ms
- Subnet Classification: Confidence 40%, Clean
- DNSSEC Validation: Confidence 90%, Valid
- ASN Resolution: Confidence 85%, ASN 55720 from team-cymru-dns
Temporal Analysis
- Ownership Changes: 0
- Threat Persistence Days: 0
- Threat Observation Count: 0
- Is Persistently Malicious: No
---
## Recommended Security Actions
Based on the low-risk profile and clean classification:
1. Monitoring: Continue passive monitoring; no blocking required
2. Firewall Rules: No specific rules recommended; standard allow policy applies
3. Threat Intelligence: No alerting or correlation actions needed
4. Geolocation Verification: Monitor for further discrepancies between ASN registry (MY) and reported geolocation (US)
---
## Relationship Graph
- Same Network: DCNL-HK (2 relationships)
---
## Conclusion
IP 185.189.160.105 presents a Low Risk profile with no active threat indicators. The subnet is classified as clean with zero abuse density. Recommended action is Continue Monitoring with no immediate blocking or alerting required. The geolocation discrepancy between ASN registry and reported location should be noted but does not currently indicate malicious activity.
Threat Level: LOW
Action Required: MONITORING ONLY
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Gigabit TW |
| ASN | AS55720 |
| Network Name | DCNL-HK |
| CIDR Block | 185.189.160.0/24 |
| RIR | RIPE |
| Country | TW |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | — |
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 80, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | — |
| HTTP Title | SoftEther VPN Server |
🔐 TLS Certificate
CN=e001.panda003.net was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.| SANs | e001.panda003.net |
| Valid From | 2026-02-15T22:24:08+00:00 |
| Valid Until | 2026-05-16T22:24:07+00:00 (expired) |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 89 days |
🛡️ Public Network Snapshot
| Origin ASN | AS55720 |
| Network Prefix | 185.189.160.0/24 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Not detected |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 25% | 2 | 3 |
| ownership | 17% | 2 | 3 |
| reputation | 14% | 1 | 2 |
| geolocation | 17% | 2 | 3 |
| Overall | 18% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-03 16:57:56 UTC |
| Last Seen | 2026-08-24 13:22:26 UTC |
| Profile Built | 2026-08-29 09:47:22 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 185.189.160.105
Who owns the IP address 185.189.160.105?
185.189.160.105 is registered to Gigabit TW. The address falls within the 185.189.160.0/24 network block. Registration is held at RIPE.
Where is 185.189.160.105 located?
Geolocation data places 185.189.160.105 in Taipei, Taipei City, Taiwan. The local time zone is Asia/Taipei. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 185.189.160.105 malicious or safe?
185.189.160.105 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 185.189.160.105?
Responsive ports observed on 185.189.160.105 include 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.