IPDebrief

98.159.43.154

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING

Target: 98.159.43.154/32

Date: 2026-06-24

Classification: Mixed Risk Profile

---

## EXECUTIVE SUMMARY

IP 98.159.43.154 is assigned to organization TH-LOGICWEB (ASN 206092) within CIDR block 98.159.43.0/24. The IP presents a low-risk profile (score: 25) with no active threat indicators. However, the /24 subnet exhibits elevated abuse density (0.4359) with 68 threat-sibling IPs among 156 total siblings, warranting contextual monitoring despite the target IP's clean status.

---

## OWNERSHIP & INFRASTRUCTURE

AttributeValue
**Organization**TH-LOGICWEB
**ASN**206092
**CIDR Block**98.159.43.0/24
**Registration**ARIN
**Country**US
**Geolocation**Bangkok, US (consensus: true)
**Network Role**Firewalled / No Services

The IP shows no active services, open ports, or TLS certificates. DNS resolution is unconfirmed with zero forward hostnames or PTR records.

---

## THREAT ASSESSMENT

Current Risk Score: 25 (Low Risk)

Abuse Confidence: Not applicable

Blacklist Status: 0 listings

Campaign Affiliation: None identified

Threat Indicators:

Control Plane:

---

## NEIGHBORHOOD ANALYSIS

Subnet: 98.159.43.0/24

Total Siblings: 156

Active Siblings: 19

Threat Siblings: 68

Abuse Density: 0.4359 (High)

Classification: Mixed

Risk Distribution in /24:

The subnet demonstrates elevated abuse activity. Sample neighbors show consistent risk scores of 40 with authority scores of 50, suggesting coordinated infrastructure usage.

---

## OBSERVATION HISTORY

Total Observations: 15 signals tracked

Recent Signal Activity (2026-06-24):

Temporal Trends:

---

## RELATIONSHIP MAPPING

Connected Entities: 19 relationships identified

The IP maintains only network-level relationships with no hostname, organization, or certificate associations beyond the parent network.

---

## RECOMMENDED ACTIONS

Based on risk profile and neighborhood context:

1. Allow Traffic: Current risk score (25) supports permitting inbound/outbound traffic

2. Monitor Subnet: Track /24 abuse density (0.4359) for emerging threats

3. Block if Compromised: Should threat indicators emerge on this IP, apply immediate blocking

4. Log All Activity: Enable logging for forensic correlation within the TH-LOGICWEB network

5. No Specific WAF Rules: No actionable firewall rules generated for this IP

---

## ANALYST NOTES

The IP itself shows no malicious indicators, but the parent /24 subnet carries elevated risk. SOC teams should monitor the TH-LOGICWEB network broadly while maintaining per-IP threat intelligence. The Bangkok geolocation assignment for a US IP warrants validation through additional geolocation sources.

Clearance: Approved for operational use

Next Review: Monitor for threshold changes in subnet abuse density

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionBangkok
CityBangkok
Timezoneβ€”
Latitude13.76
Longitude100.51

🏒 Ownership & Registration

OrganizationTH-LOGICWEB
ASNAS206092
Network NameTH-LOGICWEB
CIDR Block98.159.43.0/24
RIRARIN
CountryThailand
Abuse Contactβ€”

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)

πŸ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown β€” Insufficient routing data to classify
No specific classification

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
31%
23
routing
13%
11
services
8%
11
ownership
19%
22
reputation
28%
13
geolocation
27%
22
Overall21%912
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-07 23:04:45 UTC
Last Seen2026-06-24 02:25:46 UTC
Profile Built2026-06-24 02:50:53 UTC
Data FreshnessLive
Signal Types14
Total Observations16
πŸ” 14 signal types Β· 16 observations collected
This report is generated from 14+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.