# IP Intelligence Briefing: 105.235.132.175/32
## Executive Summary
IP address 105.235.132.175 presents a moderate risk profile (score: 40) with limited active threat indicators. The address belongs to ASN 33779 (Wataniya Eldjazair) and is classified as a firewalled host with no open services. While not actively malicious, the IP warrants monitoring and consideration for blocking in controlled environments.
## Network Attribution & Infrastructure
- Organization: Wataniya Eldjazair (Algerian ISP)
- ASN: 33779
- CIDR Block: 105.235.132.0/24
- Geolocation: London, GB (Note: Geolocation discrepancy exists; ASN indicates Algerian origin)
- Network Classification: Firewalled / No Services detected
- DNS: No PTR records, no forward resolution, no hosted domains
## Threat Assessment
- Risk Score: 40 (Moderate Risk)
- Known Threats: None detected
- Blacklist Status: 0 blacklist hits
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Control Plane Indicators:
- Route stability: Not stable
- DNSBL listings: 2 of 8 total lists
- RPKI state: Unverified
- Operator Score: 0.1304 (Minimal)
## Neighborhood Analysis (105.235.132.0/24)
- Abuse Density: 0.0 (Clean)
- Subnet Classification: Clean
- Active Siblings: 2
- Threat Siblings: 0
- High Risk Neighbors: 0
- Medium Risk Neighbors: 2
Notable Neighbors:
- 105.235.132.1 (Risk Score: 40, Authority Score: 50)
- 105.235.132.170 (Risk Score: 40, Authority Score: 50)
## Historical Observations
- Total Observations: 14
- Threat Persistence: None detected
- Ownership Changes: 0
- Recent Activity: Scans detected on multiple ports (no services confirmed)
- Campaign Correlation: None
## Recommended Actions
Based on the risk profile, the following security controls are recommended:
Firewall Rules
- iptables: `iptables -A INPUT -s 105.235.132.175 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 105.235.132.175 drop`
- nginx: `deny 105.235.132.175;`
WAF/Cloud Services
- Cloudflare WAF: Block with expression `ip.src eq 105.235.132.175`
- AWS WAF: Add 105.235.132.175/32 to IP set for blocking
## Analyst Notes
The IP exhibits moderate risk characteristics primarily due to DNSBL listings and unstable routing. However, the subnet demonstrates clean abuse density with no active malicious siblings. The firewalled status suggests the IP is not currently serving open services, reducing immediate exploitation risk. SOC teams should monitor for any changes in network behavior or emergence of threat indicators in the associated neighborhood.
*Report generated: 2026-07-29*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Wataniya Eldjazair |
| ASN | AS33779 |
| Network Name | 105.235.132.0 - 105.235.132.255 |
| CIDR Block | 105.235.132.0/24 |
| RIR | AFRINIC |
| Country | DZ |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 1 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-23 20:04:38 UTC |
| Last Seen | 2026-07-29 19:22:55 UTC |
| Profile Built | 2026-07-29 19:38:12 UTC |
| Data Freshness | Live |
| Signal Types | 15 |
| Total Observations | 15 |
Full dossier details are available via our API.