# IP Intelligence Briefing: 61.72.140.163/32
Date: 2026-07-29
Classification: Low Risk
Reporting Agency: IPDebrief Intelligence Platform
---
## Executive Summary
IP 61.72.140.163 is a South Korean mobile network address assigned to KT Corporation (ASN 4766, KORNET-KR). Current risk assessment indicates low threat posture with a risk score of 25. The address operates on a residential/mobile network infrastructure with no active services exposed. Historical data reveals minimal blacklist presence with one high-severity listing among eight monitored feeds.
---
## Network Attribution
| Attribute | Value |
|---|---|
| **IP Address** | 61.72.140.163/32 |
| **Country** | KR (South Korea) |
| **City/Region** | Seoul, Dongdaemun |
| **ASN** | 4766 (IP Manager) |
| **Organization** | KORNET-KR (KT Corporation) |
| **Network Block** | 61.72.0.0/14 |
| **Mobile Carrier** | KT Corporation (MCC: 450, MNC: 08) |
| **Connection Type** | LTE/5G Mobile |
---
## Risk Assessment
Current Risk Score: 25/100 (Low Risk)
Risk Indicators:
- Abuse Confidence: Not quantified
- Threat Indicators: None detected
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Network Classification:
- Provider Status: Not identified
- Infrastructure Type: Not applicable
- Service Purpose: Firewalled / No Services
- Open Ports: None detected
- TLS Certificates: None
---
## Control Plane Analysis
| Metric | Value |
|---|---|
| **BGP Prefix** | 61.72.0.0/13 |
| **Origin ASN** | 4766 |
| **Route Stability** | Unstable (isRouteStable: false) |
| **RPKI State** | Not available |
| **DNSSEC Valid** | Yes |
| **DNSBL Listed** | 1 of 8 feeds |
| **Operator Score** | 0.1304 (Minimal) |
| **Delegation Age** | Not available |
---
## Observation History
Total Signals Observed: 13
Recent Activity (2026-07-29):
- Geolocation: Confirmed KR (Seoul, Dongdaemun) at 35.91°N, 127.77°E with 250km accuracy radius
- Ownership Changes: 0 (stable)
- Threat Persistence: 0 days
- Persistent Malicious Activity: No
- DNSBL Status: 1 listing detected with maximum severity "high"
Temporal Analysis:
- Ownership Changes: 0
- Threat Observation Count: 0
- Persistently Malicious: False
---
## Relationship Graph
Connected Entities: 3
- All relationships classified as "Same Network" (KORNET-KR)
- No hostname, organization, or certificate relationships identified
- No cross-referenced entities detected
---
## Subnet Neighborhood Analysis
Subnet: 61.72.140.0/24
- Neighbor Count: 0
- Abuse Density: 0
- High Risk Neighbors: 0
- Medium Risk Neighbors: 0
- Low Risk Neighbors: 0
- Threat Siblings: 0
---
## Recommended Security Actions
Based on current risk profile:
1. Allow with Monitoring: This IP presents low risk and is a legitimate mobile carrier address. No blocking required.
2. DNSBL Monitoring: Monitor the one active blacklist listing for changes in severity or additional feeds.
3. Traffic Classification: Treat as mobile/residential traffic; apply appropriate mobile carrier filtering policies if required.
4. No Firewall Rules Required: No actionable firewall rules recommended; IP does not exhibit malicious behavior.
---
## Intelligence Conclusion
61.72.140.163 is a legitimate South Korean mobile network address from KT Corporation with minimal threat indicators. The single high-severity DNSBL listing appears to be historical or related to content rather than the IP itself. No blocking or mitigation actions are recommended. Standard mobile carrier traffic handling procedures apply.
---
Report Generated: 2026-07-29
Data Source: IPDebrief Intelligence Platform
Classification: Internal Use - SOC Operations
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IP Manager |
| ASN | AS4766 |
| Network Name | KORNET-KR |
| CIDR Block | 61.72.0.0/14 |
| RIR | APNIC |
| Country | KR |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| Closed Ports | 22, 25, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | Microsoft-IIS/10.0 |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-22 07:16:30 UTC |
| Last Seen | 2026-07-29 12:57:19 UTC |
| Profile Built | 2026-07-29 13:13:23 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.