# IP Intelligence Briefing: 223.25.110.37/32
Classification: Moderate Risk
Date of Analysis: Current
Source: IPDebrief Intelligence Platform
## Executive Summary
IP address 223.25.110.37 is classified as Moderate Risk (Risk Score: 40). The address belongs to IRT-SINERGINET-ID (ASN: 136873) and operates as a web server within the Indonesian telecommunications infrastructure. No direct evidence of malicious activity was observed, though the IP appears on two DNSBL listings.
## Infrastructure Profile
Ownership & Registration:
- Organization: IRT-SINERGINET-ID
- Netname: Pelanggan_Malang_MEGADATAISP-ID
- ASN: 136873
- RIR: APNIC
- CIDR Block: 223.25.110.0/24
- Abuse Contact: Available via RDAP
Geolocation:
- Country: Indonesia (ID)
- Region: Surabaya
- City: Jl. A. Yani 88
- Postal Code: 60234
- Accuracy Radius: 1500km
Network Services:
- Open Ports: TCP 80 (HTTP), TCP 443 (HTTPS)
- Service Purpose: Web Server
- TLS Certificate: Not detected
- DNS Resolution: Forward resolution unconfirmed
Threat Indicators:
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- DNSBL Listings: 2 of 8 total lists
- Pulsedive Risk: Not scored
- Threat Feeds: Empty
## Temporal Analysis
The IP address recorded 14 signal observations across the observation period. Key historical signals include:
- Port scan activities detected on 2026-07-29
- Connection failures observed during HTTPS probes
- Organizational ownership data consistently resolved
- AlienVault OTX reputation signals indicating threat presence with three associated pulse names
- Geolocation data pointing to Surabaya, Indonesia with coordinates at -6.1728° latitude, 106.8272° longitude
No persistent malicious activity was observed. The IP is not classified as persistently malicious, with zero threat persistence days recorded.
## Neighborhood Assessment
Subnet Analysis: 223.25.110.0/24
- Total Siblings: 1
- Active Siblings: 0
- Threat Siblings: 0
- Abuse Density: 0
- Subnet Classification: Low risk (1 sibling with risk score 0)
The only neighboring IP observed (223.25.110.106) returned a risk score of 0 with authority score of 50, indicating minimal threat activity within the subnet.
## Relationships
Two relationships were identified, both linking to the network identifier "Pelanggan_Malang_MEGADATAISP-ID," confirming the IP's placement within the Megadata ISP customer network infrastructure.
## Recommended Security Actions
Risk Score: 40 (Moderate)
Firewall Rule Recommendations:
- iptables: `iptables -A INPUT -s 223.25.110.37 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 223.25.110.37 drop`
- nginx: `deny 223.25.110.37;`
- pfSense: `223.25.110.37/32`
- Cloudflare WAF: Block with expression `ip.src eq 223.25.110.37`
- AWS WAF: Block address `223.25.110.37/32`
Note: These recommendations are probabilistic and should be combined with other signals before taking action.
## Intelligence Assessment
The IP address operates as a legitimate web server within Indonesian ISP infrastructure. While the moderate risk score (40) and presence on two DNSBL lists warrant monitoring, no definitive malicious indicators were identified. The IP is not associated with Tor networks, known attack campaigns, or spam operations. The neighborhood shows no elevated abuse density, suggesting localized rather than systemic threat activity.
Recommended Action: Monitor for increased activity. No immediate blocking required unless additional threat indicators emerge.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-SINERGINET-ID |
| ASN | AS136873 |
| Network Name | Pelanggan_Malang_MEGADATAISP-ID |
| CIDR Block | 223.25.110.0/24 |
| RIR | APNIC |
| Country | ID |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 46% | 2 | 3 |
| routing | 22% | 1 | 1 |
| services | 46% | 2 | 3 |
| ownership | 47% | 2 | 3 |
| reputation | 23% | 1 | 2 |
| geolocation | 22% | 1 | 1 |
| Overall | 34% | 9 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-21 19:03:23 UTC |
| Last Seen | 2026-08-07 07:32:49 UTC |
| Profile Built | 2026-08-05 12:30:37 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 19 |
Full dossier details are available via our API.