IP Intelligence Briefing: 85.203.23.67/32
*Generated via IPDebrief Threat Intelligence Platform*
---
**1. Core Profile**
- Risk Rating: Moderate (Risk Score: 50/100)
- Ownership: Owned by VPN Consumer Singapore (AS137409)
- Geolocation:
- Primary: Singapore (SG), Bukit Merah Estate (latitude 1.35, longitude 103.82)
- Secondary: Conflicting data suggests Dallas, TX (US), but geoplausibility is flagged as false
- Network Role: Firewalled / No Services (no open ports, no TLS/HTTP signatures)
- Threat Indicators: No malicious activity detected (no blacklists, campaigns, or honeypot hits)
---
**2. Temporal Observations**
- Latest Activity: June 6, 2026 (multi-signal inferred geolocation, 45km accuracy)
- Historical Trends:
- Conflicting geolocation data (Singapore vs. Dallas, TX) observed on May 29, 2026
- No persistent malicious behavior (threat persistence days: 0)
- Stability score: 0 (no recent network changes)
---
**3. Network Relationships**
- Subnet: 85.203.23.0/24 (abuse density: 18.47%)
- Key Links:
- Same network: SINGAPORE-SG-85-203-23-0
- 29 threat siblings in subnet (medium/low risk)
- 30 active neighbors (157 total siblings)
---
**4. Neighborhood Analysis**
- Subnet Risk: Mostly clean (abuse density: 0.18), but 29 neighbors flagged as threat siblings
- High-Risk Neighbors:
- 22 IPs with medium risk (score: 25β40)
- 78 IPs with low risk (score: 0β25)
- Notable: No direct IP-level abuse detected, but subnet-wide risk suggests monitoring
---
**5. Technical & Security Context**
- DNS: No PTR records, no email auth (SPF/DKIM/DMArC absent)
- BGP: Valid DNSSEC, CAA records; 2 DNSBL listings (low impact)
- Routing: Stable BGP prefix (AS137409), no route changes in 30 days
- Services: No open ports, no TLS certs, no HTTP server banners
---
**6. SOC Actionable Insights**
- Monitor: Subnet 85.203.23.0/24 for lateral movement or C2 activity
- Verify: Investigate conflicting geolocation data (Singapore vs. Dallas, TX)
- Block: Consider firewall rules for subnet if threat siblings escalate
- Context: No direct malicious indicators, but subnet risk warrants cautious scrutiny
---
*Generated from IPDebrief intelligence tools (profile, history, relationships, neighbors). Data as of June 6, 2026.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | VPN Consumer Singapore, Republic of Singapore |
| ASN | AS137409 |
| Network Name | β |
| CIDR Block | 85.203.23.0/24 |
| RIR | RIPE |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 27% | 2 | 3 |
| services | 27% | 2 | 3 |
| ownership | 30% | 3 | 4 |
| reputation | 22% | 1 | 3 |
| geolocation | 38% | 2 | 4 |
| Overall | 28% | 12 | 21 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-12 21:55:56 UTC |
| Last Seen | 2026-06-06 16:15:02 UTC |
| Profile Built | 2026-06-06 16:17:45 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 25 |
Full dossier details are available via our API.