# IP INTELLIGENCE BRIEFING
Subject: 200.121.203.152/32
Date: Current
Classification: Moderate Risk
## EXECUTIVE SUMMARY
IP 200.121.203.152 presents a moderate risk profile (55/100) with evidence of blacklist listings and rate-limit activity. The IP is associated with Peruvian ISP Integratel Peru S.A.A. (AS6147) but exhibits geographic discrepancies with US-based geolocation. No active services detected; network appears firewalled.
## RISK PROFILE
| Metric | Value |
|---|---|
| Risk Score | 55/100 (Moderate) |
| Reputation | Moderate Risk |
| Blacklist Count | 3 of 8 DNSBLs |
| DNSBL Total Lists | 8 |
| Tor Exit Node | No |
| Known Attacker | No |
| Spam Source | No |
## OWNERSHIP & GEOGRAPHY
ASN: 6147 (INTEGRATEL PERU S.A.A.)
Country: US (Peruvian ISP registry)
CIDR Block: 200.121.203.0/24
Geolocation: New York, US (US-NY)
Registration: 2004-05-07 (LACNIC)
*Note: Geographic discrepancy between Peruvian ISP assignment and US-based geolocation warrants monitoring for potential misconfiguration or dual-use infrastructure.*
## NETWORK STATUS
Services: None detected (Firewalled / No Services)
Open Ports: 0
DNS Resolution: client-200.121.203.152.speedy.net.pe
PTR Record: client-200.121.203.152.speedy.net.pe
Forward Resolution: 1 hostname (net.pe domain)
## OBSERVATION HISTORY (13 Signals)
Recent observations include:
- HTTP 429 rate limit response (2026-07-25T06:44:47)
- Multiple blacklist listings with HIGH severity (2026-07-25T06:42:28)
- DNSSEC validation confirmed (true)
- ASN attribution via team-cymru-dns source
## NEIGHBORHOOD ANALYSIS
Subnet: 200.121.203.0/24
Abuse Density: 0
Active Siblings: 0
Threat Siblings: 0
No correlated threat activity detected in adjacent /24 subnet.
## RELATIONSHIP GRAPH
| Type | Target |
|---|---|
| DNS Association | client-200.121.203.152.speedy.net.pe |
Single DNS hostname association; no organizational or certificate relationships identified.
## RECOMMENDED ACTIONS
IMMEDIATE
1. Block Traffic: Implement firewall rules to drop all traffic from 200.121.203.152
2. Increase Logging: Monitor recent activity patterns with enhanced verbosity
FIREWALL RULES
```bash
# iptables
iptables -A INPUT -s 200.121.203.152 -j DROP
# nftables
nft add rule inet filter input ip saddr 200.121.203.152 drop
# Cloudflare WAF
{"description":"Block 200.121.203.152 — IPDebrief risk score 55","action":"block"}
# AWS WAF
{"Addresses":["200.121.203.152/32"],"Description":"IPDebrief risk 55"}
```
MONITORING
- Track blacklist status changes
- Monitor for new service openings
- Watch for subnet-wide activity patterns
## INTELLIGENCE NOTES
- IP exhibits rate-limit behavior (HTTP 429) suggesting automated probing or abuse attempts
- Geographic mismatch between ISP registry (Peru) and geolocation (US) may indicate proxy usage or misconfiguration
- Low neighborhood abuse density suggests isolated threat actor or compromised endpoint
- No persistent malicious behavior detected; risk driven by blacklist listings and rate-limit signals
---
*Report generated via IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Unknown |
| ASN | AS6147 |
| Network Name | — |
| CIDR Block | 200.121.203.0/24 |
| RIR | LACNIC |
| Country | — |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR | client-200.121.203.152.speedy.net.pe |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | client-200.121.203.152.speedy.net.pe |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS6147 |
| Network Prefix | 200.121.203.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 4% | 1 | 1 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Very Low (15%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-09 01:19:26 UTC |
| Last Seen | 2026-08-27 03:22:50 UTC |
| Profile Built | 2026-08-29 06:16:01 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 22 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 200.121.203.152
Where is 200.121.203.152 located?
Geolocation data places 200.121.203.152 in New York, US-NY, United States. The local time zone is America/New_York. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 200.121.203.152 malicious or safe?
200.121.203.152 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 200.121.203.152?
The reverse DNS (PTR) record for 200.121.203.152 is client-200.121.203.152.speedy.net.pe. This hostname is not forward-confirmed, so it should be treated as a weak signal.