# IP Intelligence Briefing: 203.198.150.36/32
Classification: Low Risk / Commercial Infrastructure
Date: 2026-07-29
Status: Active
---
## Executive Summary
IP address 203.198.150.36 is identified as a legitimate commercial infrastructure address associated with Netvigator (AS4760), a Hong Kong-based Internet service provider. The IP exhibits no malicious indicators, maintains a zero risk score, and presents as a standard single-service host with no evidence of abuse or threat activity.
---
## Network Ownership & Geolocation
| Attribute | Value |
|---|---|
| **Organization** | IRT-HKTIMS-HK (Netvigator) |
| **ASN** | 4760 |
| **Country** | Hong Kong (HK) |
| **City** | Kowloon City |
| **CIDR Block** | 203.198.128.0/17 |
| **RIR** | APNIC |
| **BGP Prefix** | 203.198.144.0/21 |
The address belongs to the NETVIGATOR network infrastructure. Geo-validation indicates Hong Kong placement with 30km accuracy radius. Multiple geo-sources confirm this location (geoConsensus: true).
---
## DNS & Hostname Resolution
- PTR Record: 036.150.198.203.static.netvigator.com
- Forward Resolution: Confirmed to netvigator.com domain
- Email Authentication: SPF and DMARC records present
- HTTP Host: netvigator.com
DNS configuration demonstrates proper email authentication setup with valid SPF and DMARC records.
---
## Service Profile
- Open Ports: TCP/80 (HTTP)
- HTTP Status Code: 500 (Internal Server Error)
- HTTP Version: 1.1
- Server Response Time: 497ms
The IP responds on port 80 with an error status code, suggesting the service may be misconfigured or under maintenance. No TLS certificate detected.
---
## Threat Intelligence Assessment
| Indicator | Status |
|---|---|
| **Risk Score** | 0 |
| **Abuse Confidence** | None |
| **Blacklist Count** | 0 |
| **Tor Exit Node** | No |
| **Known Attacker** | No |
| **Spam Source** | No |
| **Threat Campaigns** | None |
| **DNSBL Lists** | 0 of 8 |
No threat indicators detected. The IP does not appear on any threat feeds, blacklists, or known campaign databases.
---
## Network Neighborhood Analysis
- Subnet: 203.198.150.0/24
- Abuse Density: 0%
- Total Siblings: 0
- Threat Siblings: 0
- High Risk Neighbors: 0
- Medium Risk Neighbors: 0
The subnet shows zero abuse density with no sibling IPs flagged as threats, indicating this is an isolated infrastructure address without neighborhood-level malicious activity.
---
## Historical Observations
Analysis of 19 signal observations reveals:
- Threat Persistence: None
- Ownership Changes: 0
- Last Observed: 2026-07-29
- Classification Stability: Consistent
The IP maintains stable ownership characteristics with no observed malicious behavior over the observation period. No threat persistence patterns detected.
---
## Control Plane Analysis
- Route Stability: Unstable (isRouteStable: false)
- DNSSEC: Valid
- RPKI State: Not available
- IRR Consistency: Not available
- Route Changes (30d): 0
- MOAS Status: No
- Delegation Age: Not available
BGP routing shows route instability. DNSSEC validation is enabled.
---
## Recommended Security Actions
No immediate action required. The IP presents as legitimate commercial infrastructure with no threat indicators. However, the 500 HTTP error status may warrant monitoring if this IP is expected to serve user-facing services.
Firewall Rules: None recommended
---
## Relationships
- Same Network: NETVIGATOR (multiple associations)
- DNS Associations: 036.150.198.203.static.netvigator.com
No external relationships detected beyond organizational network associations.
---
## Analyst Notes
This IP represents standard ISP infrastructure with no malicious attributes. The 500 error response on port 80 may indicate service degradation or misconfiguration rather than security concerns. SOC teams may monitor if this address appears in connection logs, but no blocking or mitigation actions are indicated.
Confidence Level: High – Comprehensive threat intelligence signals support benign classification.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | IRT-HKTIMS-HK |
| ASN | AS4760 |
| Network Name | NETVIGATOR |
| CIDR Block | 203.198.128.0/17 |
| RIR | APNIC |
| Country | HK |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | 036.150.198.203.static.netvigator.com |
| Forward Confirmed | Yes — FCrDNS verified |
| Forward Hostnames | 036.150.198.203.static.netvigator.com |
🔐 DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | 2/2 domains |
| DMARC | 2/2 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 2 domains |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 — Basic operator with some routing infrastructure |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| Closed Ports | 22, 25, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS4760 |
| Network Prefix | 203.198.144.0/21 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Not detected |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 23% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 17% | 2 | 3 |
| ownership | 17% | 2 | 3 |
| reputation | 8% | 1 | 2 |
| geolocation | 17% | 2 | 3 |
| Overall | 15% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-20 12:28:18 UTC |
| Last Seen | 2026-09-02 13:48:55 UTC |
| Profile Built | 2026-09-02 13:55:31 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 35 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 203.198.150.36
Who owns the IP address 203.198.150.36?
203.198.150.36 is registered to IRT-HKTIMS-HK. The address falls within the 203.198.128.0/17 network block. Registration is held at APNIC.
Where is 203.198.150.36 located?
Geolocation data places 203.198.150.36 in Kowloon City, Kowloon City, Hong Kong. The local time zone is Asia/Hong_Kong. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 203.198.150.36 malicious or safe?
203.198.150.36 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 203.198.150.36?
The reverse DNS (PTR) record for 203.198.150.36 is 036.150.198.203.static.netvigator.com. This hostname is forward-confirmed, meaning it resolves back to the same address.
What ports are open on 203.198.150.36?
Responsive ports observed on 203.198.150.36 include 80. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.