# IP Intelligence Briefing: 109.136.87.39
Classification: Low Risk / Residential Mobile
Generated: 2026-07-29
Status: Active Monitoring
## Executive Summary
IP address 109.136.87.39 is a low-risk residential mobile endpoint associated with Belgian carrier Proximus. No malicious activity, open services, or threat indicators detected. The IP demonstrates stable network infrastructure characteristics with clean neighborhood classification.
## Network Infrastructure Profile
| Attribute | Value |
|---|---|
| **IP Address** | 109.136.87.39/32 |
| **Risk Score** | 25 (Low) |
| **ASN** | 5432 |
| **Organization** | Belgacom Internet Expertise Center |
| **Network Name** | BE-BELGACOM-20090727 |
| **Country** | Belgium (BE) |
| **City** | Brussels |
| **Provider Score** | 0 |
| **Authority Score** | 0 |
## Network Role Classification
- Primary Type: Mobile Carrier Endpoint
- Mobile Carrier: Proximus (MCC: 206, MNC: 01)
- Connection Technology: LTE/5G
- Infrastructure: Firewalled / No Active Services
- Open Ports: None detected
- DNS Type: Dynamic (39.87-136-109.fia-dyn.isp.proximus.be)
## Threat Assessment
Threat Indicators: None
- Blacklist Count: 0
- Abuse Confidence Score: N/A
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Reputation Sources: None
Security Services:
- Email Authentication: SPF and DMARC configured
- TLS Certificates: None (no web services)
- HTTP Banner: None
## Geographic Validation
- Location: Brussels, Belgium
- Coordinates: 50.5°N, 4.47°E
- Geo Confidence: Moderate (0.52)
- Validation Method: Multi-signal inference
- RTT Analysis: Avg 105.6ms from probe locations
- Plausibility: Valid (236.8km from minimum RTT location)
## Network Stability Analysis
- BGP Prefix: 109.136.0.0/16
- AS Path: 3303 โ 5432
- Route Stability: Unstable (2 changes in 30 days)
- MOAS Status: No
- RPKI State: Not verified
- IRR Consistency: Not checked
- Route Origin ASN: 5432
## Relationship Graph
Connected Entities (8 total):
- Network Associations: BE-BELGACOM-20090727 (multiple entries)
- DNS Associations: 39.87-136-109.fia-dyn.isp.proximus.be (4 entries)
## Neighborhood Analysis (109.136.87.0/24)
- Total Siblings: 1
- Active Siblings: 0
- Threat Siblings: 0
- Abuse Density: 0 (Clean)
- Classification: Clean
- Inherited Risk: 0
## Historical Signal Analysis
Observations: 21 signals tracked
- ASN Consistency: Stable (allocated since 1995-10-23)
- Ownership Changes: 0
- Threat Persistence: 0 days
- Threat Observation Count: 0
- Persistent Malicious Activity: False
Recent Observations (2026-07-29):
- ASN allocation status: Allocated (11,237 days)
- BGP route changes: 2 in 30-day window
- Geographic location: Belgium (confirmed)
- Network role: Not mobile in this specific observation (inconsistency noted)
## Recommended Actions
Based on risk profile and threat assessment:
1. Firewall Rules: No blocking required. Monitor as legitimate endpoint.
2. IDS/IPS: Standard residential/mobile signature rules apply.
3. Threat Intelligence: No enrichment needed. No correlation to known campaigns.
4. Geographic Filtering: Belgium endpoint โ verify against business requirements.
## Conclusion
IP 109.136.87.39 represents a legitimate mobile subscriber address from Belgian carrier Proximus. The endpoint demonstrates clean security posture with no malicious indicators, no open services, and no neighborhood abuse. The BGP route instability is a network infrastructure characteristic rather than a security concern. No defensive action required beyond standard monitoring.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Belgacom Internet Expertise Center |
| ASN | AS5432 |
| Network Name | BE-BELGACOM-20090727 |
| CIDR Block | 109.128.0.0/12 |
| RIR | ARIN |
| Country | BE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 39.87-136-109.fia-dyn.isp.proximus.be |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 39.87-136-109.fia-dyn.isp.proximus.be |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 50% | 2 | 3 |
| reputation | 25% | 1 | 1 |
| geolocation | 25% | 1 | 1 |
| Overall | 30% | 8 | 9 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-21 12:54:28 UTC |
| Last Seen | 2026-07-29 08:14:39 UTC |
| Profile Built | 2026-07-29 08:26:02 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 23 |
Full dossier details are available via our API.