# IP Intelligence Briefing: 202.67.47.27
## Executive Summary
IP address 202.67.47.27 presents a moderate risk profile (55/100) with no active threat indicators. The IP belongs to ASN 4761 (John Sihar Simanjuntak/THREE) and is geolocated to Batam, Indonesia. While currently showing no malicious activity, the elevated risk score warrants increased monitoring.
---
## Ownership & Network Details
| Attribute | Value |
|---|---|
| **IP Address** | 202.67.47.27/32 |
| **ASN** | 4761 |
| **Organization** | John Sihar Simanjuntak |
| **Network Name** | THREE |
| **CIDR Block** | 202.67.47.0/24 |
| **RIR** | APNIC |
| **Geolocation** | Batam, Riau Islands, Indonesia (ID) |
| **Abuse Contact** | abuse@ipnet.net.id |
---
## Risk Assessment
Current Risk Profile
- Overall Risk Score: 55/100 (Moderate Risk)
- Abuse Confidence: Not applicable
- Blacklist Count: 0
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Threat Indicators
No active threat indicators detected. The IP does not appear in any known threat feeds, campaigns, or blacklists.
---
## Network Characteristics
Infrastructure Classification
- Service Purpose: Firewalled / No Services
- Open Ports: None detected
- DNS Records: No forward resolution
- Email Authentication: No SPF/DMARC records
Control Plane Data
- Route Stability: Unstable
- DNSBL Status: Listed on 3 of 8 total lists
- Operator Score: 0.1304 (Minimal)
- RPKI State: Not validated
- IRR Consistency: Not validated
---
## Neighborhood Analysis
Subnet: 202.67.47.0/24
- Abuse Density: 0%
- Classification: Clean
- Active Siblings: 0
- Threat Siblings: 0
- Total Neighbors: 0
The /24 subnet shows no neighboring threat activity, suggesting this IP is isolated in its threat profile.
---
## Historical Observations
Total Observations: 16 signals over monitoring period
Recent Activity (2026-07-29):
- Geolocation signals confirming Indonesian origin
- Ownership registration data updated
- No ownership changes detected
- No persistent malicious activity observed
---
## Security Recommendations
Immediate Actions Required
1. Increase logging verbosity and review recent activity from this IP (Risk Severity: High)
Firewall Rule Recommendations
iptables:
```bash
iptables -A INPUT -s 202.67.47.27 -j DROP
```
nftables:
```bash
nft add rule inet filter input ip saddr 202.67.47.27 drop
```
nginx:
```nginx
deny 202.67.47.27;
```
pfSense:
```
202.67.47.27/32
```
Cloudflare WAF:
```json
{
"description": "Block 202.67.47.27 โ IPDebrief risk score 55",
"action": "block",
"filter": {
"expression": "ip.src eq 202.67.47.27"
}
}
```
AWS WAF:
```json
{
"Addresses": ["202.67.47.27/32"],
"Description": "IPDebrief risk 55"
}
```
---
## Threat Intelligence Narrative
IP 202.67.47.27 is a residential or infrastructure IP assigned to Indonesian network operator THREE (ASN 4761). Despite showing a moderate risk score of 55, the IP has no open services, no email authentication records, and no active threat indicators. The subnet demonstrates clean characteristics with zero abuse density among neighboring addresses. The elevated risk score appears to stem from DNSBL listings (3 of 8 lists) rather than confirmed malicious activity.
Recommended SOC Action: Implement monitoring with the provided firewall rules. The risk profile suggests blocking or rate-limiting traffic from this IP while maintaining logging for correlation with other events.
---
*Intel Briefing Generated: IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | John Sihar Simanjuntak |
| ASN | AS4761 |
| Network Name | THREE |
| CIDR Block | 202.67.47.0/24 |
| RIR | APNIC |
| Country | ID |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 18% | 5 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-23 20:05:39 UTC |
| Last Seen | 2026-07-29 20:08:03 UTC |
| Profile Built | 2026-07-29 20:18:38 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.