# IPDebrief Intelligence Briefing
Target: 211.253.9.49/32
Report Date: June 23, 2026
Classification: Moderate Risk
## Executive Summary
IP 211.253.9.49, registered to IP Manager (ASN 4766), is a mobile-originated IP address from Seoul, South Korea. The address carries a risk score of 65/100 and was listed on 3 DNSBLs with a maximum severity rating of high. The IP operates as a single-service host with HTTP services only.
## Network Profile
- Organization: IP Manager
- ASN: 4766
- Location: Seoul, South Korea (35.91°N, 127.77°E)
- BGP Prefix: 211.252.0.0/15
- Mobile Carrier: KT Corporation (LTE/5G)
- Connection Type: Mobile (non-residential)
## Technical Observations
- Open Ports: 80/tcp (HTTP)
- Server Fingerprint: Apache/2.4.7 (Ubuntu)
- HTTP Status: 200 OK
- DNSSEC: Valid
- DNSBL Status: Listed on 3 of 8 threat lists
- Route Stability: Unstable (false)
## Threat Indicators
- Abuse Confidence: Not explicitly scored
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaign Correlation: None detected
- Threat Persistence: 0 days observed
## Neighborhood Analysis
The /24 subnet (211.253.9.0/24) shows:
- Abuse Density: 1
- Classification: Mostly clean
- Inherited Risk: 5
- Total Siblings: 2
- Active Siblings: 0
- Threat Siblings: 2
Neighbor 211.253.9.160 carries a risk score of 25 with an authority score of 50.
## Relationship Graph
The IP maintains 33 relationships, predominantly classified as "Same Network" associations to KORNET-KR. Two DNS association errors were recorded targeting 192.168.2.108#53.
## Historical Timeline
23 signal observations were recorded, with the most recent activity on June 23, 2026. Signals included:
- High-severity blacklist listings (8 total, 2 active)
- Minimal operator score (0)
- HTTP fingerprinting with Apache server headers
- Consistent risk posture with no ownership changes
## Recommended Actions
Immediate: Increase logging verbosity and review recent activity from this IP address.
Firewall Rules:
- iptables: `iptables -A INPUT -s 211.253.9.49 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 211.253.9.49 drop`
- nginx: `deny 211.253.9.49;`
- pfSense: `211.253.9.49/32`
- Cloudflare WAF: Block with expression `ip.src eq 211.253.9.49`
- AWS WAF: Add address `211.253.9.49/32` with description "IPDebrief risk 65"
## Assessment
The IP operates from a mobile network environment with elevated risk due to DNSBL listings. While not classified as a known attacker, the moderate risk score warrants monitoring and consideration for blocking in inbound security policies. No persistent malicious behavior has been observed over the investigation period.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IP Manager |
| ASN | AS4766 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | APNIC |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| Closed Ports | 22, 25, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | Apache/2.4.7 (Ubuntu) |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 30% | 2 | 4 |
| ownership | 20% | 2 | 3 |
| reputation | 29% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 25% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:11 UTC |
| Last Seen | 2026-06-26 18:11:06 UTC |
| Profile Built | 2026-06-24 06:41:05 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 25 |
Full dossier details are available via our API.