# IP Intelligence Briefing: 202.29.51.12
## Executive Summary
Risk Assessment: HIGH RISK (Score: 80/100)
Status: Active Threat Indicator
Origin: Thailand (TH) / ASN 4621 (UNINET-TH)
Classification: Education Network Infrastructure with Compromised Reputation
---
## Key Findings
Network Attribution
- Organization: Office of Info.Tech. Admin. for Educational Development
- Network Name: UNINET-TH
- ASN: 4621 (APNIC RIR)
- CIDR Block: 202.28.0.0/15
- Registration: 1993-10-14
Geographic Location
- Country: Thailand (TH)
- Coordinates: 15.87°N, 100.99°E
- Geo Confidence: 52% (multi-signal inference)
- Geo Plausibility: Invalid
Risk Profile
- Risk Score: 80/100 (High Risk)
- DNSBL Listings: 5 of 8 total lists
- Max Listing Severity: High
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Network State
- Open Ports: None detected
- Active Services: None (Firewalled / No Services)
- DNS Records: No PTR record, no forward resolution
- TLS/HTTP: No certificates or web services
---
## Threat Intelligence Indicators
Malicious Activity Signals
- DNSBL Presence: IP listed on 5 blacklist feeds with high severity ratings
- Observation Count: 13 historical observations recorded
- Recent Activity: Observations as recent as 27 July 2026
- Threat Persistence: No persistent malicious behavior detected
- Campaign Correlation: No known campaign matches
Behavioral Analysis
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
- Control Plane: Route unstable, 0 route changes in 30 days
---
## Related Entities & Infrastructure
Network Relationships
- Primary Association: UNINET-TH (multiple same-network relationships)
- Neighborhood Analysis: No sibling IPs detected in /24 subnet
- Abuse Density: 0 (subnet-level metric unavailable)
Control Plane Data
- BGP Prefix: 202.29.51.0/24
- RPKI State: Not validated
- Route Stability: Unstable
- MoAS Status: No
---
## Recommended Security Actions
Immediate Mitigation
Priority: CRITICAL
1. Block at Perimeter: Implement firewall rules to drop traffic from 202.29.51.12/32
2. Enhanced Logging: Increase logging verbosity for all traffic from this IP range
3. Threat Feed Integration: Monitor against current blacklist feeds
Platform-Specific Rules
iptables:
```
iptables -A INPUT -s 202.29.51.12 -j DROP
```
nftables:
```
nft add rule inet filter input ip saddr 202.29.51.12 drop
```
nginx:
```
deny 202.29.51.12;
```
pfSense:
```
202.29.51.12/32
```
Cloudflare WAF:
```json
{
"description": "Block 202.29.51.12 — IPDebrief risk score 80",
"action": "block",
"filter": {"expression": "ip.src eq 202.29.51.12"}
}
```
AWS WAF:
```json
{
"Addresses": ["202.29.51.12/32"],
"Description": "IPDebrief risk 80"
}
```
---
## Intelligence Assessment
This IP address belongs to Thailand's national education network (UNINET-TH) but exhibits high-risk characteristics despite lacking active service indicators. The presence on 5 DNSBLs with high severity ratings suggests prior malicious activity, potentially from compromised infrastructure within the education network or misconfigured systems.
Threat Level: HIGH — Block at perimeter but monitor for legitimate educational traffic that may require whitelisting.
Recommendation: Implement block rules with monitoring for false positives from legitimate institutional users. Review threat feed listings to determine if activity is from the IP itself or associated infrastructure.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | IRT-UNINET-TH |
| ASN | AS4621 |
| Network Name | UNINET-TH |
| CIDR Block | 202.28.0.0/15 |
| RIR | APNIC |
| Country | TH |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 0% (None) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | — |
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 80, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | 2022-03-14T11:32:37+00:00 |
| Valid Until | 2049-07-29T11:32:37+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 9999 days |
🛡️ Public Network Snapshot
| Origin ASN | AS4621 |
| Network Prefix | 202.29.51.0/24 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Not detected |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 39% | 2 | 5 |
| routing | 8% | 1 | 1 |
| services | 20% | 2 | 3 |
| ownership | 34% | 2 | 6 |
| reputation | 25% | 1 | 4 |
| geolocation | 28% | 2 | 4 |
| Overall | 26% | 10 | 23 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-14 03:40:07 UTC |
| Last Seen | 2026-09-29 20:36:14 UTC |
| Profile Built | 2026-09-22 01:54:33 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 34 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 202.29.51.12
Who owns the IP address 202.29.51.12?
202.29.51.12 is registered to IRT-UNINET-TH. The address falls within the 202.28.0.0/15 network block. Registration is held at APNIC.
Where is 202.29.51.12 located?
Geolocation data places 202.29.51.12 in London. The local time zone is Asia/Bangkok. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 202.29.51.12 malicious or safe?
202.29.51.12 currently carries a high risk assessment, meaning indicators associated with malicious or abusive activity have been observed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 202.29.51.12?
Responsive ports observed on 202.29.51.12 include 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.