IP Intelligence Briefing: 85.203.23.162
Date: 2026-06-03
---
**1. Risk Profile**
- Overall Risk Score: 25 (Low Risk)
- Provider Score: 0 (No known malicious ISP ties)
- Authority Score: 0 (No authoritative malicious indicators)
- Threat Indicators: No detected malware, phishing, or spam sources.
- Geolocation: Singapore (SG), with inferred coordinates matching Singaporeβs capital.
---
**2. Ownership & Network Context**
- Registered ASN: AS137409 (VPN Consumer Singapore, Republic of Singapore)
- Network Role: Firewalled / No Services (no open ports, no TLS/HTTP services detected).
- Subnet: 85.203.23.0/24
- Subnet Abuse Density: 48.41% (mixed risk, with 76/157 sibling IPs flagged as threats).
---
**3. Observation History**
- Latest Activity: 2026-06-03
- Geolocation: Confirmed Singapore (1.35°N, 103.82°E) with 45km accuracy.
- Network Classification: Mixed-risk subnet (some neighbors linked to abuse).
- BGP Analysis: Stable route with no recent changes.
---
**4. Relationships & Neighbors**
- Linked Entities:
- Same subnet (85.203.23.0/24) with 157 sibling IPs.
- No direct ties to known malicious organizations or campaigns.
- Neighbor Risk Distribution:
- 53 IPs flagged as medium risk (score β₯40), 47 low risk.
- Notable neighbors:
- 85.203.23.50, 54β57 (risk score 40, authority score 50).
---
**5. Threat & Malware Indicators**
- Threat Feeds: No matches in known malicious databases (DNSBL, honeypots, etc.).
- Behavioral Analysis: No enumeration strikes, WAF violations, or honeypot hits.
---
**6. Recommendations**
- Monitor Subnet: Given the 48% abuse density, increase monitoring of 85.203.23.0/24 for lateral movement or command-and-control activity.
- Check Neighbors: Investigate medium-risk neighbors (e.g., 85.203.23.50β57) for potentialε ³θ.
- Firewall Rules: Consider blocking high-risk neighbors using IPDebriefβs generated rules for iptables/nftables.
---
Conclusion: 85.203.23.162 is a low-risk IP with no direct malicious indicators, but its subnet contains a significant number of medium-risk neighbors. SOC teams should prioritize subnet-level monitoring and investigate higher-risk siblings for potential indirect threats.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | VPN Consumer Singapore, Republic of Singapore |
| ASN | AS137409 |
| Network Name | β |
| CIDR Block | β |
| RIR | RIPE |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 32% | 2 | 3 |
| Overall | 22% | 9 | 14 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:38 UTC |
| Last Seen | 2026-06-23 23:23:07 UTC |
| Profile Built | 2026-06-23 23:25:37 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 18 |
Full dossier details are available via our API.