An intelligence profile was generated for IP address 210.101.60.1. The address was assessed as Low Risk with a risk score of 25. Ownership records attributed the address to ASN 131098 under the organization IP Manager and network name KRNIC-NET-KR, registered within APNIC. Geolocation data indicated the host was located in South Korea, though geo sources disagreed on the country designation, citing the US in some instances.
Network analysis revealed the IP was firewalled with no active services or open ports. The endpoint was not identified as a Tor exit, proxy, or CDN. Behavioral metrics showed zero honeypot hits, enumeration strikes, or WAF violations. While the immediate neighborhood was classified as clean, the IP was listed on one DNS blacklist out of eight total checks.
Threat intelligence feeds did not correlate with known campaigns or active attacker signatures. The address was observed active between 2026-09-05 and 2026-09-27. Due to signal contradictions regarding geolocation and insufficient data for intent classification, the overall confidence level was rated Very Low. The recommended action was to Monitor the address with low severity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IP Manager |
| ASN | AS131098 |
| Network Name | KRNIC-NET-KR |
| CIDR Block | 210.101.60.0/22 |
| RIR | APNIC |
| Country | KR |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 0% (None) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 21% | 10 | 14 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-09-05 05:53:01 UTC |
| Last Seen | 2026-09-27 14:49:28 UTC |
| Profile Built | 2026-09-27 14:59:56 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 27 |
Full dossier details are available via our API.