# IP Intelligence Briefing: 119.156.95.140/32
Date: 2026-07-29
Classification: Low Risk / Dormant Infrastructure
## Executive Summary
IP address 119.156.95.140 is classified as Low Risk with a risk score of 0. The address belongs to PTCL (Pakistan Telecommunication Company Limited) under ASN 17557 (PKTELECOM-AS-PK), allocated within the 119.156.64.0/19 CIDR block. The IP has no active services, no open ports, and no detected threat indicators. No neighbors are present in the /24 subnet, and abuse density is 0.
## Infrastructure Profile
Ownership:
- Organization: PTCL (Munir Ahmed)
- ASN: 17557 (PKTELECOM-AS-PK)
- RIR: APNIC
- CIDR Block: 119.156.64.0/19
- Registration: 2008-02-19
Geolocation:
- Country: FR (France) with Pakistan regional designation
- Note: Geographic data shows inconsistency between country code and regional attribution
- Timezone: Europe/Paris
Network Role:
- Classification: Firewalled / No Services
- Not identified as CDN, VPN, proxy, Tor, hosting, or mobile infrastructure
- No reverse DNS (PTR) records present
- No forward resolution to hostnames
## Threat Assessment
Current Risk Status:
- Risk Score: 0 (Low Risk)
- Abuse Confidence Score: Not applicable
- Blacklist Count: 0
- Is Known Attacker: False
- Is Tor Exit: False
- Is Spam Source: False
Threat Indicators:
- No active threat feeds matched
- No known campaign associations
- No malicious IP correlations
- No honeypot hits recorded
- No enumeration strikes detected
- No WAF violations
## Historical Observations
Observation Count: 10 signals recorded
Recent Activity Timeline:
- 2026-07-29 18:10:28: Multiple DNS listings observed with 8 total lists, 1 listed entry, medium severity classification
- 2026-07-29 18:10:27: DNSSEC validation confirmed for reverse zone 140.95.156.119.in-addr.arpa
- 2026-07-29 18:10:27: ASN 17557 confirmed via team-cymru-dns source
- 2026-07-29 18:09:43: Operator score calculated as 0 (Minimal risk classification)
Temporal Trends:
- Ownership changes: 0
- Threat persistence days: 0
- Threat observation count: 0
- Status: Not persistently malicious
## Network Relationships
Detected Relationships:
- 1 relationship identified: Same Network โ PTCL
- No organizational, hostname, or certificate relationships detected
Subnet Analysis (119.156.95.0/24):
- Neighbor count: 0
- Risk distribution: 0 high, 0 medium, 0 low
- Abuse density: 0
- No sibling IPs with threat indicators
## Behavioral Indicators
Network Behavior:
- Traceroute: 30 hops, transit through Comcast
- First hop RTT: 0.2ms
- Last hop RTT: 320.5ms
- Timeouts: 20 hops
Security Posture:
- Honeypot hits: 0
- Enumeration strikes: 0
- Auto-banned: False
- Active attacker status: False
## Recommended Actions
Firewall/Network Rules:
- No blocking actions required based on current risk profile
- IP classified as low risk with no active threat indicators
- Standard monitoring sufficient
Monitoring Recommendations:
- Continue standard traffic monitoring
- No immediate threat mitigation actions warranted
- Profile indicates dormant or legitimately firewalled infrastructure
## Conclusion
IP 119.156.95.140 represents low-risk infrastructure with no active threat indicators. The address is associated with PTCL Pakistan Telecommunications and shows no evidence of malicious activity. Historical data indicates stable ownership with no threat persistence. The IP's firewalled state and lack of open services suggest legitimate infrastructure or decommissioned resources. No immediate action required by SOC analysts.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Munir Ahmed |
| ASN | AS17557 |
| Network Name | PTCL |
| CIDR Block | 119.156.64.0/19 |
| RIR | APNIC |
| Country | PK |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 4% | 1 | 2 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-23 13:56:02 UTC |
| Last Seen | 2026-07-29 18:09:11 UTC |
| Profile Built | 2026-07-29 18:22:04 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 16 |
Full dossier details are available via our API.