# IP INTELLIGENCE BRIEFING
Target: 98.159.43.154/32
Date: 2026-06-24
Classification: Mixed Risk Profile
---
## EXECUTIVE SUMMARY
IP 98.159.43.154 is assigned to organization TH-LOGICWEB (ASN 206092) within CIDR block 98.159.43.0/24. The IP presents a low-risk profile (score: 25) with no active threat indicators. However, the /24 subnet exhibits elevated abuse density (0.4359) with 68 threat-sibling IPs among 156 total siblings, warranting contextual monitoring despite the target IP's clean status.
---
## OWNERSHIP & INFRASTRUCTURE
| Attribute | Value |
|---|---|
| **Organization** | TH-LOGICWEB |
| **ASN** | 206092 |
| **CIDR Block** | 98.159.43.0/24 |
| **Registration** | ARIN |
| **Country** | US |
| **Geolocation** | Bangkok, US (consensus: true) |
| **Network Role** | Firewalled / No Services |
The IP shows no active services, open ports, or TLS certificates. DNS resolution is unconfirmed with zero forward hostnames or PTR records.
---
## THREAT ASSESSMENT
Current Risk Score: 25 (Low Risk)
Abuse Confidence: Not applicable
Blacklist Status: 0 listings
Campaign Affiliation: None identified
Threat Indicators:
- Not a Tor exit node
- Not a known attacker
- Not a spam source
- No active threat feeds matched
Control Plane:
- Route stability: False
- Operator score: 0.1304 (Minimal)
- DNSBL listed: 1 of 8 total lists
---
## NEIGHBORHOOD ANALYSIS
Subnet: 98.159.43.0/24
Total Siblings: 156
Active Siblings: 19
Threat Siblings: 68
Abuse Density: 0.4359 (High)
Classification: Mixed
Risk Distribution in /24:
- High Risk: 0
- Medium Risk: 68
- Low Risk: 32
The subnet demonstrates elevated abuse activity. Sample neighbors show consistent risk scores of 40 with authority scores of 50, suggesting coordinated infrastructure usage.
---
## OBSERVATION HISTORY
Total Observations: 15 signals tracked
Recent Signal Activity (2026-06-24):
- Subnet classification: High abuse density (0.5128)
- Inherited risk: 20
- Geographic signals: US coordinates (39.83, -98.58) with 2,500km accuracy radius
- Operator label: Minimal (score: 0.1304)
Temporal Trends:
- Threat persistence: 0 days
- Ownership changes: 0
- Not persistently malicious
- Single threat observation recorded
---
## RELATIONSHIP MAPPING
Connected Entities: 19 relationships identified
- Type: Same Network (TH-LOGICWEB)
- Pattern: All relationships point to TH-LOGICWEB network ownership
The IP maintains only network-level relationships with no hostname, organization, or certificate associations beyond the parent network.
---
## RECOMMENDED ACTIONS
Based on risk profile and neighborhood context:
1. Allow Traffic: Current risk score (25) supports permitting inbound/outbound traffic
2. Monitor Subnet: Track /24 abuse density (0.4359) for emerging threats
3. Block if Compromised: Should threat indicators emerge on this IP, apply immediate blocking
4. Log All Activity: Enable logging for forensic correlation within the TH-LOGICWEB network
5. No Specific WAF Rules: No actionable firewall rules generated for this IP
---
## ANALYST NOTES
The IP itself shows no malicious indicators, but the parent /24 subnet carries elevated risk. SOC teams should monitor the TH-LOGICWEB network broadly while maintaining per-IP threat intelligence. The Bangkok geolocation assignment for a US IP warrants validation through additional geolocation sources.
Clearance: Approved for operational use
Next Review: Monitor for threshold changes in subnet abuse density
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | TH-LOGICWEB |
| ASN | AS206092 |
| Network Name | TH-LOGICWEB |
| CIDR Block | 98.159.43.0/24 |
| RIR | ARIN |
| Country | Thailand |
| Abuse Contact | β |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 19% | 2 | 2 |
| reputation | 28% | 1 | 3 |
| geolocation | 27% | 2 | 2 |
| Overall | 21% | 9 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:45 UTC |
| Last Seen | 2026-06-24 02:25:46 UTC |
| Profile Built | 2026-06-24 02:50:53 UTC |
| Data Freshness | Live |
| Signal Types | 14 |
| Total Observations | 16 |
Full dossier details are available via our API.