# IP INTELLIGENCE BRIEFING
Target: 109.172.55.64/32
Classification: Moderate Risk / Known Attacker
Date: 2026-06-17
## Executive Summary
IP address 109.172.55.64 is classified as a moderate-risk address (risk score: 49) with confirmed malicious indicators. The IP is registered to Global Connectivity Solutions (ASN 215540) in Lille, France. While the /24 subnet shows clean abuse density, this specific endpoint has been flagged as a known attacker with blacklist listings. SSH service is active, and control plane data indicates route instability.
## Risk Assessment
- Overall Risk Score: 49/100 (Moderate Risk)
- Reputation Status: Known Attacker (isKnownAttacker: true)
- Blacklist Exposure: 1 of 8 DNSBL lists
- Operator Score: 0.1304 (Minimal)
- Threat Indicators: Emerging Threats classification present
## Technical Profile
Network & Ownership
| Attribute | Value |
|---|---|
| ASN | 215540 |
| Organization | Global Connectivity Solutions |
| Country | France (Hauts-de-France, Lille) |
| CIDR Block | 109.172.55.0/24 |
| RIR | ARIN |
Services & Ports
| Port | Protocol | Service | Banner |
|---|---|---|---|
| 22/tcp | TCP | SSH | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
DNS Analysis
| Field | Value |
|---|---|
| PTR Record | 142942.ip-ptr.tech |
| Forward Resolution | Not confirmed |
| Email Authentication | None (no SPF/DMARC) |
Control Plane Data
- BGP Prefix: 109.172.55.0/24
- Route Stability: Unstable (isRouteStable: false)
- DNSSEC: Valid
- DNSBL Listings: 1 active listing
- MOAS Status: Not observed
- Origin ASN: 215540
## Neighborhood Analysis
Subnet: 109.172.55.0/24
- Abuse Density: 0 (Clean)
- Subnet Classification: Clean
- Sibling IPs: 1 total
- 109.172.55.136: Risk score 0, Authority score 50 (clean)
- Threat Siblings: 0
## Observation History
Total observations: 24
- Recent Activity: Blacklist listings detected (confidence: 0.60)
- Geolocation Inference: France (confidence: 0.28)
- Operator Score Trend: 0.15 โ 0.1304 (stable minimal operator risk)
- Threat Persistence: 0 days (not persistently malicious)
## Relationship Graph
66 relationships identified, predominantly "Same Network" connections to GCS_SER-NET network identifiers. No certificate or organization-level relationships detected.
## Recommended Actions
Immediate Mitigation
Severity: HIGH
| System | Configuration |
|---|---|
| iptables | `iptables -A INPUT -s 109.172.55.64 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 109.172.55.64 drop` |
| nginx | `deny 109.172.55.64;` |
| pfSense | `109.172.55.64/32` |
| Cloudflare WAF | Block IP (risk score 49) |
| AWS WAF | Block 109.172.55.64/32 |
Intelligence Notes
1. Despite clean neighborhood metrics, this specific endpoint shows malicious behavior patterns
2. SSH service availability indicates potential for lateral movement or unauthorized access
3. Route instability suggests possible infrastructure changes or misconfiguration
4. Single DNSBL listing provides confirmation of prior malicious activity
## Conclusion
This IP warrants defensive blocking at network boundaries. The combination of known attacker classification, blacklist presence, and active SSH service presents a credible threat vector. Recommend monitoring for any related IPs within the 109.172.55.0/24 subnet, though current sibling analysis indicates no additional threats.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Global Connectivity Solutions |
| ASN | AS215540 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 142942.ip-ptr.tech |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 142942.ip-ptr.tech |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 39% | 2 | 5 |
| routing | 13% | 1 | 1 |
| services | 26% | 2 | 3 |
| ownership | 24% | 2 | 3 |
| reputation | 27% | 1 | 4 |
| geolocation | 30% | 2 | 3 |
| Overall | 26% | 10 | 19 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:29 UTC |
| Last Seen | 2026-06-22 08:34:53 UTC |
| Profile Built | 2026-06-22 08:41:00 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 25 |
Full dossier details are available via our API.