IPDebrief

43.250.173.68

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IPDebrief Intelligence Briefing

Target IP: 43.250.173.68/32

Date: 2026-07-30

Classification: Low Risk / Defensive Monitoring Recommended

## Executive Summary

IP address 43.250.173.68 presents a low-risk threat profile with no direct malicious activity detected. The IP is currently firewalled with no active services or open ports. While the target IP itself shows clean indicators, the /24 subnet contains one neighbor (43.250.173.130) with elevated risk metrics that warrants contextual awareness.

## Risk Assessment

MetricValueAssessment
Overall Risk Score0Low Risk
Provider Score0Neutral
Authority Score0Neutral
Stability Score0Insufficient Data
Abuse ConfidenceN/ANo Evidence
Blacklist Count0Clean

## Network Classification

## Services & Ports

No open ports detected. No TLS certificates, HTTP services, or server banners observed. The IP appears to be passively listening or completely blocked at the network layer.

## Geolocation & Ownership

Geolocation data unavailable. No ASN, organization, or registration information returned. No PTR hostnames or reverse DNS resolution. Forward DNS resolution failed.

## Threat Indicators

## Neighborhood Analysis

The IP resides in subnet 43.250.173.0/24 with the following characteristics:

MetricValue
Subnet Abuse Density0
Total Siblings2
Active Siblings1
Threat Siblings0
Risk Distribution2 Low, 0 Medium, 0 High

Notable Neighbor: 43.250.173.130 (riskScore: 25, authorityScore: 50)

## Historical Observations

Nine signal observations recorded. Key findings include:

No persistent malicious behavior observed. Threat observation count: 0.

## Relationships

No related entities identified (subnets, hostnames, organizations, or certificates).

## Recommended Actions

1. Monitoring: Add to passive monitoring for service activation or port opening

2. Block Status: No immediate blocking required based on current risk profile

3. Contextual Awareness: Monitor neighbor 43.250.173.130 for correlated activity

4. Review: Periodic re-scan recommended to detect service changes

## SOC Analyst Notes

This IP appears to be a passive or blocked endpoint with no active threat indicators. The elevated risk neighbor (43.250.173.130) suggests the /24 subnet may contain some compromised or abused infrastructure, but the target IP itself shows no malicious behavior. Continue baseline monitoring and watch for any service activation or outbound connection attempts.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ญ๐Ÿ‡ฐ Hong Kong
RegionHK
CityHong Kong
TimezoneAsia/Hong_Kong
Latitude22.40
Longitude114.11

๐Ÿข Ownership & Registration

OrganizationIRT-HKUNITED-HK
ASNAS62468
Network NameHKUNITED-HK
CIDR Block43.250.173.0/24
RIRAPNIC
CountryHK
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeMulti-Service Host
Network TierUnknown โ€” Insufficient routing data to classify
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
22sshtcp
Closed Ports25, 443, 3389, 8080, 8443 (2 open / 7 scanned)
Servernginx
HTTP Titleโ€”
SSH VersionSSH-2.0-OpenSSH_7.2p2 Ubuntu-4ubuntu2.10

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
35%
22
routing
25%
11
services
25%
11
ownership
0%
00
reputation
25%
11
geolocation
0%
00
Overall18%55
Coverage: 4/6 dimensions ยท Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-07-26 15:20:46 UTC
Last Seen2026-07-30 08:41:05 UTC
Profile Built2026-07-30 08:58:11 UTC
Data FreshnessLive
Signal Types19
Total Observations19
๐Ÿ” 19 signal types ยท 19 observations collected
This report is generated from 19+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.