# IP Intelligence Briefing: 98.159.43.111/32
Classification: LOW RISK
Date: 2026-06-03
Intel Level: Definitive
---
## Executive Summary
IP address 98.159.43.111 is associated with TH-LOGICWEB (ASN 206092) in the 98.159.43.0/24 block. Overall risk score is 25 (Low Risk). The IP exhibits minimal threat indicators but shows route instability and minimal DNSBL presence. Neighborhood analysis indicates moderate abuse density within the subnet.
---
## Technical Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 25 (Low) |
| **Organization** | TH-LOGICWEB |
| **ASN** | 206092 |
| **CIDR Block** | 98.159.43.0/24 |
| **Country** | US |
| **Services** | None detected (Firewalled) |
| **Open Ports** | 0 |
| **DNS PTR** | None resolved |
| **Forward Resolution** | Not confirmed |
---
## Threat Indicators
- Blacklist Count: 0
- DNSBL Listings: 1 out of 8 checked lists
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Threat Feeds: Empty
---
## Network Context
Subnet Analysis (98.159.43.0/24):
- Total Siblings: 156
- Active Siblings: 0
- Threat Siblings: 19
- Abuse Density: 12.18%
- Classification: Mostly Clean
Neighbor Risk Distribution:
- High Risk: 0
- Medium Risk: 68
- Low Risk: 32
Control Plane:
- Route Stability: Not stable
- BGP Prefix: 98.159.43.0/24
- RPKI State: Not assessed
- DNSSEC: Valid
---
## Historical Observations
Total Observations: 14
- Threat Persistence: 0 days
- Threat Observation Count: 1
- Persistently Malicious: No
- Ownership Changes: 0
Key signal timeline (June 2026):
- 20:16:29 β Attacker/Threat list check: Negative
- 20:16:26 β Network role classification: No proxy/VPN/Tor/Cloud
- 20:14:56 β Geolocation: US (confidence 0.35)
- 20:21:24 β Ownership persistence: 0 changes
---
## Relationships
- Network Association: TH-LOGICWEB (15 relationships recorded)
- Hostnames: None
- Organizations: TH-LOGICWEB
- Certificates: None
- Correlated IPs: 0
---
## Recommended Actions
Current Status: No automated recommendations generated.
Manual Review Considerations:
- Monitor for route stability changes (route currently unstable)
- Verify geolocation accuracy (US/Bangkok discrepancy noted in data)
- Review subnet-level abuse patterns (19 threat siblings in /24)
- Consider blocking if traffic exhibits malicious behavior despite low IP risk
---
## SOC Analyst Notes
This IP presents low individual risk but warrants contextual monitoring. The 98.159.43.0/24 subnet shows moderate abuse density with 19 threat-identified siblings. Route instability suggests potential infrastructure changes that may indicate active network operations. No services or open ports detected on this specific IP, reducing immediate exploitation surface. Monitor for behavioral anomalies rather than relying on reputation scores alone.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | TH-LOGICWEB |
| ASN | AS206092 |
| Network Name | TH-LOGICWEB |
| CIDR Block | 98.159.43.0/24 |
| RIR | ARIN |
| Country | Thailand |
| Abuse Contact | β |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 19% | 2 | 2 |
| reputation | 22% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 17% | 9 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:44 UTC |
| Last Seen | 2026-06-24 02:19:45 UTC |
| Profile Built | 2026-06-24 02:28:38 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.