Skip to content

IPv4 address

49.0.2.184

Last fetched

49.0.2.184 is announced in 49.0.2.0/24 by ASNET-AS-ID - PT. Usaha Adisanggoro and geolocates to ID. 49.0.2.184 is listed by 1 threat feed; reconciled level LOW.

Threat posture

0.8threat score (procedure-native scale)

LOW

Listed by 1 threat feed.

Threat feeds listing this
1
Verdict coverage
malicious-evidenced
First seen on a feed
Wed, 26 Aug 2026 14:50:03 GMT
Last seen on a feed
Tue, 29 Sep 2026 21:52:03 GMT

Nutrition Label

WHISPER CANON · 49.0.2.184Routing diversity7.6/10Peering density4.3/10MOAS conflict✓ noneThreat-feed listings8.0/10WHOIS transparency—Resolver footprint—canon.whisper.security/ip/49.0.2.184

Attribution

Announced prefix
49.0.2.0/24
RIR-registered prefix
49.0.0.0/22
RPKI
valid

Abuse contact

Report abuse from 49.0.2.184 to the address block's holder first and copy the announcing network. These are the abuse contacts WhisperGraph holds for the block and the network.

Address block
abuse@as.net.id

Network context is temporarily unavailable.

The graph did not answer within the page budget. Refresh in a moment to retry — fresh data is fetched on the next visit.

Anycast detection

Anycast detection is temporarily unavailable.

Canon could not read this address's reverse DNS, and will not guess without all three signals. Refresh in a moment to retry — fresh data is fetched on the next visit.

Reverse DNS

Reverse DNS is temporarily unavailable.

The graph did not answer within the page budget. Refresh in a moment to retry — fresh data is fetched on the next visit.

Geographic detail

City
Bogor, ID
Country
ID

Threat-feed listings is temporarily unavailable.

The graph did not answer within the page budget. Refresh in a moment to retry — fresh data is fetched on the next visit.

Threat-feed evidence

History

Related pages

Pivot from 49.0.2.184 into the prefix, network and country that carry it.

Queries

This address's full card — routing attribution, reverse DNS and listed feeds.


MATCH (ip:IPV4 {name: $ip})
OPTIONAL MATCH (ip)-[:BELONGS_TO]->(rp:REGISTERED_PREFIX)
OPTIONAL MATCH (ip)-[:ANNOUNCED_BY]->(ap:ANNOUNCED_PREFIX)
OPTIONAL MATCH (a:ASN)-[:ROUTES]->(ap)
OPTIONAL MATCH (a)-[:HAS_NAME]->(an:ASN_NAME)
OPTIONAL MATCH (ip)-[:LOCATED_IN]->(city:CITY)
OPTIONAL MATCH (ip)-[:HAS_COUNTRY]->(ipc:COUNTRY)
WITH ip, rp, ap, a, an, city, ipc
LIMIT 10
WITH ip,
     collect(rp.name) AS registeredPrefixes,
     collect(rp.abuseEmail) AS registeredAbuseEmails,
     collect({prefix: ap.name, asn: a.name, network: an.name, isMoas: ap.isMoas, rpkiStatus: ap.rpkiStatus, isAnycast: ap.isAnycast, dominantCity: ap.dominantCity, abuseEmail: ap.abuseEmail, networkAbuseEmail: a.abuseEmail}) AS announcements,
     collect(city.name) AS cities,
     collect(ipc.name) AS countries,
     collect(a.name) AS announcerNames,
     head(collect(a)) AS primaryAsn,
     head(collect(ap)) AS primaryPrefix
OPTIONAL MATCH (primaryPrefix)-[:CONFLICTS_WITH]->(conflict:ASN)
WITH ip, registeredPrefixes, registeredAbuseEmails, announcements, cities, countries, announcerNames, primaryAsn,
     collect(conflict.name) AS conflictAsns
CALL { WITH primaryAsn MATCH (primaryAsn)-[:ROUTES]->(p:ANNOUNCED_PREFIX) RETURN count(p) AS asnPrefixCount }
CALL { WITH primaryAsn MATCH (primaryAsn)-[:BGP_NEIGHBOR]-(peer:ASN) RETURN count(peer) AS asnPeerCount }
RETURN ip.name AS name,
       ip.verdictLevel AS verdictLevel,
       ip.verdictScore AS verdictScore,
       ip.verdictBlocking AS verdictBlocking,
       ip.verdictCoverage AS verdictCoverage,
       ip.verdictAdvisory AS verdictAdvisory,
       ip.threatSources AS threatSources,
       ip.threatFirstSeen AS threatFirstSeen,
       ip.threatLastSeen AS threatLastSeen,
       ip.isTor AS isTor,
       ip.isVpn AS isVpn,
       ip.isProxy AS isProxy,
       ip.isC2 AS isC2,
       ip.isPhishing AS isPhishing,
       registeredPrefixes, registeredAbuseEmails, announcements, cities, countries, announcerNames, conflictAsns,
       asnPrefixCount, asnPeerCount
Run yourself →

Network context — Tor exit relays, attributed actors, and the covering blocks' signals, cloud region and vendor.


MATCH (ip:IPV4 {name: $ip})
OPTIONAL MATCH (ip)-[:OPERATES_EXIT_NODE]->(tor:TOR_RELAY)
WITH ip, count(tor) AS torRelays
OPTIONAL MATCH (ip)-[:ATTRIBUTED_TO]->(actor:ACTOR)
WITH ip, torRelays, collect(actor.name)[0..5] AS actors
OPTIONAL MATCH (ip)-[:BELONGS_TO]->(p:PREFIX)
WITH torRelays, actors, collect(p.name) AS coveringPrefixes
UNWIND (CASE WHEN size(coveringPrefixes) = 0 THEN [null] ELSE coveringPrefixes END) AS pn
OPTIONAL MATCH (cp:PREFIX {name: pn})
OPTIONAL MATCH (cp)-[:HAS_SIGNAL]->(sig:THREAT_SIGNAL_TYPE)
OPTIONAL MATCH (cp)-[:PREFIX_IN_REGION]->(reg:CLOUD_REGION)
OPTIONAL MATCH (cp)-[:DELEGATED_TO]->(v:VENDOR)
RETURN torRelays, actors,
       collect(sig.name) AS signals,
       collect(reg.name) AS regions,
       collect(v.name) AS vendors
Run yourself →

Or query Whisper from your own LLM workflow via the Whisper MCP server.