# INTELLIGENCE BRIEFING: 109.72.12.37/32
## Executive Summary
IP 109.72.12.37 presents a MODERATE RISK profile (score: 55/100) with mixed threat indicators. The IP operates as a web server in Pลíbram, Czech Republic (ASN 49767, Lukas Holzel) and exhibits dynamic network characteristics with elevated DNSBL presence. Neighborhood analysis shows clustered medium-risk activity within the /24 subnet.
## Technical Profile
| Attribute | Value |
|---|---|
| **IP Address** | 109.72.12.37/32 |
| **Risk Score** | 55/100 (Moderate Risk) |
| **Geolocation** | Czech Republic, Central Bohemia, Pลíbram (49.82°N, 15.47°E) |
| **ASN/Org** | 49767 / Lukas Holzel |
| **Service Purpose** | Web Server (lighttpd/1.4.39) |
| **Open Ports** | 80/TCP (HTTP), 443/TCP (HTTPS), 22/TCP (SSH) |
| **PTR Hostname** | ip-109-72-12-37.pb.cz |
| **Forward Resolution** | Verified (1 host) |
## Threat Indicators
- DNSBL Listings: 3 of 8 total lists (high-severity listings present)
- Control Plane: Route stability compromised, DNSSEC valid
- Operator Score: 0.1304 (Minimal)
- Known Campaigns: None identified
- Tor/Proxy/CDN: Not classified
- Threat Feeds: No direct threat indicators
## Network Neighborhood Analysis
Subnet 109.72.12.37/24 shows clean classification with 0% abuse density, though clustered activity detected:
- Active Siblings: 2 IPs (109.72.12.68, 109.72.12.204)
- Neighbor Risk Scores: 55/100 (both medium-risk)
- Total Siblings: 3 (2 active, 1 inactive)
- Abuse Density: 0%
## Observation History (21 signals tracked)
Temporal analysis reveals intermittent activity patterns:
- June 17, 2026: Connection failures recorded (HTTPS)
- June 17, 2026: DNSBL listings detected (3 high-severity)
- June 22, 2026: Recent operator score assessment (Minimal risk)
- Threat Persistence: 0 days observed
- Ownership Changes: 0 events
## Relationship Graph
43 relationships identified, predominantly same-network associations (IPB_DYNAMIC_NAT). No direct organizational or certificate-based links to known malicious entities.
## Recommended Actions
Risk Level: High (score 55/100)
Primary Recommendation: Increase logging verbosity and review recent activity
Firewall Rules
- iptables: `iptables -A INPUT -s 109.72.12.37 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 109.72.12.37 drop`
- nginx: `deny 109.72.12.37;`
- pfSense: `109.72.12.37/32`
- Cloudflare WAF: Block (expression: `ip.src eq 109.72.12.37`)
- AWS WAF: Block (Addresses: `109.72.12.37/32`)
## Intelligence Assessment
The IP exhibits characteristics of a legitimate but potentially compromised or misconfigured web hosting resource. The presence of SSH access (port 22), multiple DNSBL listings, and route instability suggest either security hardening issues or prior abuse. The neighborhood clustering with identical risk scores indicates a pattern of behavior within the subnet. While not classified as persistently malicious, the moderate-to-elevated risk profile warrants monitoring and consideration of blocking if the IP appears in threat traffic logs.
Classification: Moderate Risk โ Monitor/Block Based on Context
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Lukas Holzel |
| ASN | AS49767 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | ip-109-72-12-37.pb.cz |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | ip-109-72-12-37.pb.cz |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | lighttpd/1.4.39 |
| HTTP Title | โ |
| SSH Version | SSH-2.0-dropbear <?"??d~NsY??x??curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 32% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 26% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 17% | 1 | 2 |
| geolocation | 21% | 2 | 2 |
| Overall | 23% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:29 UTC |
| Last Seen | 2026-06-25 20:08:44 UTC |
| Profile Built | 2026-06-22 08:47:26 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 23 |
Full dossier details are available via our API.