IP Intelligence Briefing: 27.79.5.212
*Generated via IPDebrief Threat Intelligence Platform*
---
**1. Core Profile**
- Risk Score: 15 (Low Risk)
- Owner: IRT-VNNIC-AP (Viettel, Vietnam)
- Geolocation: Da Nang, Vietnam (APNIC registry)
- Network Role: Firewalled / No Services (no open ports, TLS, or HTTP detected)
- Threat Indicators: No malicious activity, no blacklists, no known campaigns, and no DNS anomalies.
---
**2. Network Context**
- Subnet: 27.79.5.212/24
- Subnet Abuse Density: 46.67% (moderate risk)
- Neighbors:
- 7 high-risk neighbors (avg. score 55)
- 7 medium-risk neighbors (avg. score 40)
- 6 low-risk neighbors (avg. score 25)
- Subnet Classification: Mixed (some IPs flagged for abuse).
---
**3. Historical Observations**
- Observation Count: 59 entries (last 30 days)
- Risk Trend: Stable low risk (Moderate signal score: 0.8).
- Key Metrics:
- No spikes in threat signals.
- BGP route stability confirmed (RPKI valid, no route changes).
- DNSSEC valid, no DNSBL listings.
---
**4. Relationships**
- Network Affiliation: Part of VIETTEL-VN (APNIC CIDR: 27.64.0.0/12).
- Connected Entities:
- Shared subnet with 14 sibling IPs.
- No direct links to hostnames, organizations, or certificates.
---
**5. Actionable Insights**
- SOC Analyst Recommendations:
1. Monitor Subnet: The 27.79.5.0/24 subnet contains mixed-risk IPs; investigate high-risk neighbors (e.g., 27.79.5.73, 27.79.5.181).
2. Verify Network Segmentation: Ensure 27.79.5.212 is isolated from critical assets, given its firewalled state.
3. Check for Anomalies: Monitor for unexpected DNS or BGP changes in the subnet.
4. No Immediate Mitigation Needed: The IP itself shows no malicious activity, but its subnet has moderate abuse density.
---
Conclusion: 27.79.5.212 is a low-risk IP owned by Viettel in Vietnam. While the subnet contains some risky neighbors, the IP itself has no direct threat indicators. Focus monitoring on the subnet for potential lateral movement or shared vulnerabilities.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IRT-VNNIC-AP |
| ASN | AS7552 |
| Network Name | VIETTEL-VN |
| CIDR Block | 27.64.0.0/12 |
| RIR | APNIC |
| Country | VN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | localhost |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | localhost |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 20% | 2 | 4 |
| routing | 24% | 4 | 5 |
| services | 12% | 2 | 2 |
| ownership | 27% | 3 | 4 |
| reputation | 19% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 20% | 14 | 20 |
| Data Coherence | Consistent (100%) |
| Attribution | High (80%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-10 22:17:36 UTC |
| Last Seen | 2026-06-26 05:12:31 UTC |
| Profile Built | 2026-06-26 05:23:14 UTC |
| Data Freshness | Live |
| Signal Types | 29 |
| Total Observations | 29 |
Full dossier details are available via our API.