# IP Intelligence Briefing: 119.156.93.44/32
## Executive Summary
IP address 119.156.93.44 is classified as Moderate Risk (Score: 65/100). The address is geolocated to Burewala, Punjab, Pakistan (PK) and is associated with APNIC RIR under the PTCL network. Current profile indicates no active malicious indicators, but the elevated risk score warrants monitoring.
## Technical Profile
- Risk Score: 65 (Moderate Risk)
- Geolocation: Pakistan, Punjab, Burewala (30.16°N, 72.68°E)
- ASN: 17557
- BGP Prefix: 119.156.64.0/19
- Operator Score: 0.1304 (Minimal)
- DNSBL Listings: 3 of 8 total lists
- Network Role: Firewalled / No Services Detected
## Ownership & Attribution
- Organization: Munir Ahmed
- Abuse Contact: csirt@ptcl.net
- RIR: APNIC
- Registration: Data indicates ownership under PTCL network infrastructure
## Threat Indicators Assessment
- Malicious Indicators: None detected
- Blacklist Status: Listed on 3 DNSBL sources
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Active Campaign: No correlated campaign activity
## Network Behavior
- Open Services: None detected (ports closed or filtered)
- DNS Resolution: No reverse PTR records
- Forward Resolution: Inactive (0 forward hostnames)
- Email Reputation: No email authentication records (SPF/DMARC)
- Control Plane: Route stability flagged as unstable; 0 route changes in 30 days
## Historical Analysis (10 Observations)
Recent signal history shows:
- 2026-07-31: Multiple geolocation sources reporting Burewala, Punjab
- Organization: Consistent attribution to PTCL/Munir Ahmed
- Port Scanning: Activity detected (multiple ports probed)
- Operator Score: Maintained at 0.1304 (Minimal risk)
- Geographic Discrepancy: Some historical signals indicated Islamabad; current consensus shows Burewala
## Neighborhood Context
- Subnet: 119.156.93.0/24
- Abuse Density: 0%
- Threat Siblings: 0 detected
- High/Medium/Low Risk Neighbors: 0/0/0
## Recommended Actions
Immediate
1. Increase logging verbosity for traffic from 119.156.93.44
2. Review recent activity from this IP address
Firewall Rules (Recommended)
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 119.156.93.44 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 119.156.93.44 drop` |
| nginx | `deny 119.156.93.44;` |
| pfSense | `119.156.93.44/32` |
| Cloudflare WAF | Block IP 119.156.93.44 |
| AWS WAF | Add 119.156.93.44/32 to block list |
## Intelligence Assessment
This IP presents an elevated risk score despite lacking active malicious indicators. The combination of DNSBL listings, port scanning activity, and unstable routing classification suggests potential for future threat activity. However, no immediate malicious behavior has been observed. The IP is part of a low-abuse-density subnet with no related threat siblings.
Recommendation: Monitor activity patterns; implement blocking rules as a precautionary measure while maintaining logging for forensic analysis.
---
*Data sourced from IPDebrief intelligence platform. All analysis based on observed network signals and threat feeds.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Munir Ahmed |
| ASN | AS17557 |
| Network Name | PTCL |
| CIDR Block | 119.156.64.0/19 |
| RIR | APNIC |
| Country | PK |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-30 11:03:01 UTC |
| Last Seen | 2026-08-01 04:24:51 UTC |
| Profile Built | 2026-07-31 01:47:05 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.