# IP INTELLIGENCE BRIEFING
## Subject: 202.155.19.165/32
## Classification: LOW RISK / INFRASTRUCTURE
## Date: Current
EXECUTIVE SUMMARY
IP address 202.155.19.165 presents as a low-risk web server infrastructure endpoint with no observable malicious activity. The address belongs to IRT-CRI-ID (ASN 138115) and operates under the RWIPXO network registration. No active threat indicators, blacklist entries, or attack campaigns were observed.
NETWORK OWNERSHIP & REGISTRATION
- Organization: IRT-CRI-ID
- ASN: 138115
- Netname: RWIPXO
- CIDR Block: 202.155.16.0/21
- RIR: APNIC
- Abuse Contact: Available via RDAP
GEOLOCATION DATA
- Country: US
- Geolocation Source: Consensus validated
- Note: Geolocation signals show US assignment with multi-signal inference
SERVICE & APPLICATION PROFILE
- Primary Service: Web Server
- Open Ports: 80/TCP (HTTP), 443/TCP (HTTPS), 22/TCP (SSH)
- Web Server: nginx/1.24.0 (Ubuntu)
- TLS Certificate: Let's Encrypt (CN=rizkyhidayat.web.id)
- Fingerprinted Domains:
- 202-155-19-165.domainesia.io
- rizkyhidayat.web.id
- www.rizkyhidayat.web.id
THREAT ASSESSMENT
- Risk Score: 0 (Low Risk)
- Abuse Confidence Score: None detected
- Blacklist Count: 0
- Threat Indicators: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Persistent Malicious Activity: No
NEIGHBORHOOD ANALYSIS
- Subnet: 202.155.19.0/24
- Abuse Density: 0 (Clean)
- Total Siblings: 2
- Active Siblings: 1
- Threat Siblings: 0
- Notable Neighbor: 202.155.19.8 (Risk Score: 0, Authority Score: 60)
OBSERVATION HISTORY
- Total Observations: 22 signals
- Recent Activity: Observed 2026-07-29
- Threat Persistence: 0 days
- Ownership Changes: 0
- Route Stability: Unstable (isRouteStable: false)
- Campaign Likelihood: None
- Cert Matches: 0
- Banner Matches: 0
NETWORK CLASSIFICATION FLAGS
- Cloud Infrastructure: No
- CDN: No
- VPN/Proxy: No
- Hosting Provider: No
- Mobile Carrier: No
- Residential: No
- Bogon: No
- Anycast: No
RECOMMENDED ACTIONS
No action required. The IP address presents no immediate threat indicators. Standard monitoring practices are sufficient.
SOC ANALYST NOTES
The IP 202.155.19.165 operates as a public web server with standard HTTPS and SSH services. The infrastructure shows typical web hosting characteristics with Let's Encrypt certificates and nginx web server. The subnet demonstrates low abuse density with one active sibling IP that also maintains a low-risk profile. No malicious activity, threat campaigns, or suspicious behaviors were observed across the available data sources.
---
*This intelligence briefing was generated using IPDebrief threat intelligence platform. Data accuracy reflects real-time observations and historical analysis.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | IRT-CRI-ID |
| ASN | AS138115 |
| Network Name | RWIPXO |
| CIDR Block | 202.155.16.0/21 |
| RIR | APNIC |
| Country | US |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | 202-155-19-165.domainesia.io |
| Forward Confirmed | Yes — FCrDNS verified |
| Forward Hostnames | 202-155-19-165.domainesia.io202-155-19-165.domainesia.io |
🔐 DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | 0/5 domains |
| DMARC | 0/5 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 5 domains |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Tier 3 — Basic operator with some routing infrastructure |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 443 | https | tcp | — |
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | rizkyhidayat.web.idwww.rizkyhidayat.web.id |
| Valid From | 2026-07-26T03:32:28+00:00 |
| Valid Until | 2026-10-24T03:32:27+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
🛡️ Public Network Snapshot
| Origin ASN | AS138115 |
| Network Prefix | 202.155.19.0/24 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Not detected |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 5 |
| routing | 8% | 1 | 1 |
| services | 36% | 2 | 6 |
| ownership | 34% | 2 | 6 |
| reputation | 25% | 1 | 4 |
| geolocation | 31% | 2 | 5 |
| Overall | 27% | 10 | 27 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-20 12:28:18 UTC |
| Last Seen | 2026-09-05 22:45:42 UTC |
| Profile Built | 2026-09-06 16:17:07 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 47 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 202.155.19.165
Who owns the IP address 202.155.19.165?
202.155.19.165 is registered to IRT-CRI-ID. The address falls within the 202.155.16.0/21 network block. Registration is held at APNIC.
Where is 202.155.19.165 located?
Geolocation data places 202.155.19.165 in London. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 202.155.19.165 malicious or safe?
202.155.19.165 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 202.155.19.165?
The reverse DNS (PTR) record for 202.155.19.165 is 202-155-19-165.domainesia.io. This hostname is forward-confirmed, meaning it resolves back to the same address.
What ports are open on 202.155.19.165?
Responsive ports observed on 202.155.19.165 include 80, 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.