# IP Intelligence Briefing: 115.131.27.24/32
Classification: LOW RISK
Date: July 2026
Status: Monitored – No Immediate Action Required
---
## Executive Summary
IP 115.131.27.24 presents a low-risk profile with no active threat indicators. The endpoint is classified as firewalled with no open services. Historical data indicates limited blacklist activity, but current observations show no malicious behavior, campaigns, or peer activity in the subnet.
---
## Risk Assessment
| Metric | Value |
|---|---|
| Overall Risk Score | 0 |
| Reputation | Low Risk |
| Provider Score | 0 |
| Authority Score | 0 |
| Blacklist Count | 0 (current) |
| Active Threat Indicators | None |
---
## Network Characteristics
Geolocation: Chicago, IL, US (US-IL region)
Network Type: Firewalled / No Services
Services: None detected (no open ports)
DNS Resolution: No reverse/forward DNS records
ASN: Not resolved in current profile
Historical ASN Data: Some observations link to TPG-INTERNET-AP (ASN 7545, Australia), suggesting possible routing or data inconsistency.
---
## Threat Indicators
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaign Affiliation: None detected
- Abuse Confidence Score: Not elevated
---
## Observation History
- Total Observations: 12 signals recorded
- Recent Activity: July 27, 2026
- Historical Listings: 8 total listings detected (4 with high severity in historical data)
- DNSSEC Status: Valid on reverse lookup
- Persistence: No persistent malicious activity observed
---
## Subnet Analysis (115.131.27.0/24)
- Neighbor Count: 0 active neighbors
- Abuse Density: 0
- Threat Siblings: 0
- Risk Distribution: No high/medium/low risk peers detected
---
## Recommendations
Current Posture: No defensive actions required. The IP presents a benign profile with no actionable threat indicators.
Monitoring Guidelines:
- Continue passive observation; no immediate blocking or filtering necessary
- No firewall rules recommended at this time
- Monitor for changes in service status or threat indicators
---
## Intelligence Notes
The IP appears to be a residential or firewalled endpoint with minimal network activity. Historical listing data suggests potential past attention from threat intelligence sources, but current signals show no active malicious behavior. The conflicting geolocation data (US vs. AU ASN) warrants periodic review but does not currently impact risk posture.
Analyst Action: No immediate action required. Continue standard monitoring procedures.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | TPG Hostmaster |
| ASN | AS7545 |
| Network Name | TPG-AU |
| CIDR Block | 115.128.0.0/14 |
| RIR | APNIC |
| Country | AU |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | 115-131-27-24.tpgi.com.au |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 115-131-27-24.tpgi.com.au |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS7545 |
| Network Prefix | 115.131.24.0/21 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 0% | 0 | 0 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-13 15:24:01 UTC |
| Last Seen | 2026-09-03 21:38:46 UTC |
| Profile Built | 2026-09-03 21:44:46 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 27 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 115.131.27.24
Who owns the IP address 115.131.27.24?
115.131.27.24 is registered to TPG Hostmaster. The address falls within the 115.128.0.0/14 network block. Registration is held at APNIC.
Where is 115.131.27.24 located?
Geolocation data places 115.131.27.24 in Adelaide, SA, Australia. The local time zone is Australia/Adelaide. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 115.131.27.24 malicious or safe?
115.131.27.24 currently carries a high risk assessment, meaning indicators associated with malicious or abusive activity have been observed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 115.131.27.24?
The reverse DNS (PTR) record for 115.131.27.24 is 115-131-27-24.tpgi.com.au. This hostname is not forward-confirmed, so it should be treated as a weak signal.