# THREAT INTELLIGENCE BRIEFING
IP Address: 109.107.224.151/32
Classification: Low Risk / Firewalled Infrastructure
Date: Intelligence Analysis Report
---
## EXECUTIVE SUMMARY
IP address 109.107.224.151/32 is a Jordanian infrastructure address classified as Low Risk (Risk Score: 25). The IP is associated with ASN 9038 (BAT-AS9038 - Al Bahrainia al Urdunia Liltaknia Wa Alitisalat Plc. Co) and is located in Amman, Jordan. No active services are currently detected; the address is firewalled with no open ports. Historical threat signals exist but current risk indicators remain minimal.
---
## TECHNICAL PROFILE
Geolocation:
- Country: Jordan (JO)
- City: Amman
- Region: AM
- Coordinates: 31.95°N, 35.94°E
Network Classification:
- ASN: 9038
- BGP Prefix: 109.107.224.0/24
- Infrastructure Type: Firewalled / No Services
- Network Role: No active services detected
Risk Assessment:
- Overall Risk Score: 25 (Low Risk)
- Reputation: Low Risk
- Abuse Confidence Score: Minimal
- Blacklist Count: 0
- DNSBL Listed: 1 of 8 total lists
---
## THREAT INDICATORS
Current Status:
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Active Attacker: No
- Known Campaigns: None identified
Historical Signals:
- Threat observations recorded on 2026-06-05 (has_threats: true, pulse_count: 1)
- 15 total observations tracked over monitoring period
- Most recent data from 2026-06-25
---
## NEIGHBORHOOD ANALYSIS
Subnet Assessment (109.107.224.0/24):
- Abuse Density: 0-1 (minimal)
- Classification: Mostly Clean
- Inherited Risk: 2
- Total Siblings: 1
- Active Siblings: 0
- Threat Siblings: 1
Network Context:
- IP is part of WIMAX network infrastructure (17 network relationships detected)
- No peer abuse activity in immediate subnet
---
## OBSERVATION HISTORY
Temporal Analysis:
- Ownership Changes: 0
- Threat Persistence Days: 0
- Not Persistently Malicious
- Route Stability: False (route changes observed in 30-day window)
Recent Signal Activity:
- ASN routing data confirmed via Cymru and Alienvault OTX
- Multiple geo-location sources confirm Jordanian origin
- Historical threat pulses detected but no sustained malicious activity
---
## RECOMMENDATIONS
Security Actions:
- Firewall Rules: No immediate blocking required; low risk profile
- Monitoring: Continue baseline monitoring; historical threat signals suggest warranting attention
- Threat Intelligence: No actionable threat indicators; treat as benign infrastructure
SOC Analyst Notes:
- IP is firewalled with no services exposed
- Minimal risk to organizational networks
- Historical threat data indicates potential for activity but current state is low risk
- No correlation to known attack campaigns
- No need for aggressive blocking; standard logging recommended
---
## CONCLUSION
IP 109.107.224.151/32 represents low-risk infrastructure located in Jordan with firewalled status and no active services. Historical threat signals exist but current indicators suggest benign operation. Standard monitoring procedures are appropriate; no immediate threat response actions are warranted.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | MNT-UMNIAH-JO |
| ASN | AS9038 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 27% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 13% | 1 | 1 |
| Overall | 18% | 8 | 12 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-09 11:33:26 UTC |
| Last Seen | 2026-06-25 14:41:39 UTC |
| Profile Built | 2026-06-25 15:02:41 UTC |
| Data Freshness | Live |
| Signal Types | 15 |
| Total Observations | 24 |
Full dossier details are available via our API.