IPDEBRIEF INTELLIGENCE BRIEFING
Target: 202.218.50.50/32
Classification: Low Risk
Date: Current
Analyst: IPDebrief Intelligence
---
**Executive Summary**
IP 202.218.50.50 presents a low-risk profile (Risk Score: 30/100) with no active threat indicators. The address is part of the NEOTECH-GEAR network operated by Japan Network Information Center (ASN: 4694, APNIC). No malicious activity, open services, or known attacker associations were detected during analysis.
**Network Ownership & Infrastructure**
- Organization: Japan Network Information Center
- Netname: NEOTECH-GEAR
- ASN: 4694
- CIDR Block: 202.218.50.32/27
- RIR: APNIC
- Abuse Contact: Available via RDAP
**Geolocation Analysis**
Geolocation data presents inconsistencies across sources:
- Primary profile indicates: Los Angeles, CA, US
- Historical signals indicate: Tokyo, Japan (Chiyoda-ku/Meguro City)
- Multiple geo sources reported with consensus disagreement
This inconsistency warrants monitoring but does not currently indicate malicious activity.
**Threat Intelligence**
- Risk Score: 30 (Low Risk)
- Blacklist Count: 0
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Threat Feeds: No matches
**Network Behavior**
- Open Ports: None detected
- Services: None active (Firewalled / No Services)
- TLS Certificates: None
- DNS: PTR record present (50.32/27.50.218.202.in-addr.arpa); forward resolution limited
- Route Stability: Unstable (isRouteStable: false)
- DNSBL Listings: 2 of 8 total lists
**Subnet Context**
- Subnet: 202.218.50.50/24
- Abuse Density: 0%
- Neighbor Count: 0 (single IP in range)
- Threat Siblings: 0
**Historical Observations**
Fourteen historical observations recorded. No persistent malicious behavior detected. Threat observation count: 0. Ownership changes: 0. The IP has not exhibited persistent malicious activity.
**Recommended Actions**
No immediate blocking or remediation actions recommended. The IP presents low-risk characteristics with no actionable threat indicators. Standard monitoring protocols should apply.
**Intelligence Assessment**
202.218.50.50 is a legitimate network address with no evidence of compromise or abuse. The geolocation inconsistencies require periodic re-evaluation but do not currently warrant defensive action. The subnet shows zero abuse density and no related malicious infrastructure.
SOC Action: Continue standard monitoring. No escalation required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Japan Network Information Center |
| ASN | AS4694 |
| Network Name | NEOTECH-GEAR |
| CIDR Block | 202.218.50.32/27 |
| RIR | APNIC |
| Country | JP |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | 50.32/27.50.218.202.in-addr.arpa |
| Forward Confirmed | Yes — FCrDNS verified |
| Forward Hostnames | mxout-c2.vg-mail.com50.32/27.50.218.202.in-addr.arpa |
🔐 DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | 1/3 domains |
| DMARC | 1/3 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
| Domains Checked | 3 domains |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 443 | https | tcp | — |
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
CN=epr-system.jp was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.| SANs | *.epr-system.jpepr-system.jp |
| Valid From | 2026-03-19T07:26:50+00:00 |
| Valid Until | 2026-06-17T07:26:49+00:00 (expired) |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 89 days |
🛡️ Public Network Snapshot
| Origin ASN | AS4694 |
| Network Prefix | 202.218.48.0/22 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Not detected |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 17% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 21% | 2 | 4 |
| ownership | 17% | 2 | 3 |
| reputation | 8% | 1 | 2 |
| geolocation | 23% | 2 | 4 |
| Overall | 16% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-13 03:14:27 UTC |
| Last Seen | 2026-09-02 11:03:20 UTC |
| Profile Built | 2026-09-02 11:14:15 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 34 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 202.218.50.50
Who owns the IP address 202.218.50.50?
202.218.50.50 is registered to Japan Network Information Center. The address falls within the 202.218.50.32/27 network block. Registration is held at APNIC.
Where is 202.218.50.50 located?
Geolocation data places 202.218.50.50 in Meguro City, Tokyo, Japan. The local time zone is Asia/Tokyo. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 202.218.50.50 malicious or safe?
202.218.50.50 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 202.218.50.50?
The reverse DNS (PTR) record for 202.218.50.50 is 50.32/27.50.218.202.in-addr.arpa. This hostname is forward-confirmed, meaning it resolves back to the same address.
What ports are open on 202.218.50.50?
Responsive ports observed on 202.218.50.50 include 80, 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.