# IP INTELLIGENCE BRIEFING
Target: 202.43.165.140/32
Date: July 30, 2026
Classification: Moderate Risk
---
## EXECUTIVE SUMMARY
IP address 202.43.165.140 presents a moderate risk profile (risk score: 40) associated with Indonesian hosting infrastructure. The IP is owned by Hostmaster DTP (ASN 18059) under network GRAMED-8A-MAJALAH. Current threat indicators show no active malicious activity, but the IP is listed on 2 of 8 DNSBLs and exhibits unstable routing behavior. Recommended action: Block with monitoring.
---
## OWNERSHIP AND GEOSOURCE
| Attribute | Value |
|---|---|
| Organization | Hostmaster DTP (GRAMED-8A-MAJALAH) |
| ASN | 18059 |
| Country | Indonesia (ID) |
| City | North Jakarta |
| CIDR Block | 202.43.165.128/26 |
| RIR | APNIC |
---
## THREAT PROFILE
- Risk Score: 40 (Moderate)
- Abuse Confidence Score: Not calculated
- Blacklist Count: 0
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Vulnerability Scans: 0 open ports detected
Control Plane Indicators:
- Route stability: Unstable
- DNSBL listings: 2 of 8
- Route changes (30d): 0
- RPKI state: Not assessed
---
## NETWORK BEHAVIOR
Current State:
- Service status: Firewalled / No Services
- DNS: Forward resolution confirmed (ip-165-140.dtp.net.id)
- PTR hostname: ip-165-140.dtp.net.id
- Open ports: None detected
- TLS certificates: None
Observation History (18 signals):
- Recent activity observed July 30, 2026
- Classification: Clean subnet (0 abuse density)
- No threat persistence detected
- No ownership changes recorded
---
## NEIGHBORHOOD ANALYSIS
- Subnet: 202.43.165.140/24
- Abuse Density: 0 (clean)
- High Risk Neighbors: 0
- Medium Risk Neighbors: 0
- Low Risk Neighbors: 0
- Threat Siblings: 0
No malicious neighboring IPs detected.
---
## RELATIONSHIP MAPPING
Seven relationships identified, all local to the network:
- DNS associations: ip-165-140.dtp.net.id
- Network affiliations: GRAMED-8A-MAJALAH
- No external organizational or infrastructure connections detected
---
## RECOMMENDED ACTIONS
Firewall/Blocking Rules:
```bash
# iptables
iptables -A INPUT -s 202.43.165.140 -j DROP
# nftables
nft add rule inet filter input ip saddr 202.43.165.140 drop
# nginx
deny 202.43.165.140;
# pfSense
202.43.165.140/32
# Cloudflare WAF
{
"description": "Block 202.43.165.140 โ IPDebrief risk score 40",
"action": "block",
"filter": {
"expression": "ip.src eq 202.43.165.140"
}
}
# AWS WAF
{
"Addresses": ["202.43.165.140/32"],
"Description": "IPDebrief risk 40"
}
```
Priority: Block with monitoring
Justification: Moderate risk score, DNSBL listings, unstable routing behavior
---
## ANALYST NOTES
The IP is classified as moderate risk primarily due to DNSBL listings and unstable routing. No active threat indicators detected. The subnet shows clean classification with no malicious neighbors. Recommended to block outbound connections while monitoring for behavioral changes. Re-assess after 30 days or upon detection of new threat indicators.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Hostmaster DTP |
| ASN | AS18059 |
| Network Name | GRAMED-8A-MAJALAH |
| CIDR Block | 202.43.165.128/26 |
| RIR | APNIC |
| Country | ID |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | ip-165-140.dtp.net.id |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | ip-165-140.dtp.net.id |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 1 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 20% | 5 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-25 21:00:46 UTC |
| Last Seen | 2026-07-30 05:29:36 UTC |
| Profile Built | 2026-07-30 05:41:49 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 20 |
Full dossier details are available via our API.