# IP Intelligence Briefing: 137.255.13.247/32
Classification: Moderate Risk | Date: 2026-07-29 | Status: Active
## Executive Summary
IP address 137.255.13.247 is registered to organization Vivien ASSANGBE under ASN 328228 and operates from the 137.255.12.0/22 block. The asset presents a moderate risk profile (score: 50) with a single-service SSH host configuration. The IP is listed on 8 DNSBLs with 2 high-severity listings and shows evidence of geographic signal inconsistency.
## Technical Profile
| Attribute | Value |
|---|---|
| **ASN** | 328228 |
| **Organization** | Vivien ASSANGBE |
| **Network Block** | 137.255.12.0/22 |
| **Geolocation** | GB (London) / BJ (Benin) |
| **DNS Hostname** | sbin.bj |
| **Open Ports** | 22/TCP (SSH-2.0-OpenSSH_9.6p1) |
| **Risk Score** | 50 (Moderate) |
| **DNSBL Listings** | 8 total (2 high severity) |
## Key Observations
Network Context
The IP belongs to a /24 subnet (137.255.13.0/24) with mixed classification and moderate abuse density (0.3333). Of 9 sibling IPs, 6 remain active with 3 flagged as threat-related. Risk distribution within the subnet shows 3 medium-risk and 5 low-risk neighbors, with no high-risk siblings identified.
Reputation Signals
- DNSBL Presence: Listed on 8 blacklists including high-severity entries
- Ownership Stability: No ownership changes recorded
- Service Classification: Single-service host (SSH)
- Campaign Correlation: No known campaign matches or certificate associations
Geographic Anomalies
Signal history reveals conflicting geolocation data: current profile indicates GB (London), while historical observations reference BJ (Benin). This inconsistency warrants monitoring for potential spoofing or multi-region operations.
Control Plane
- Route Stability: Flagged as unstable (isRouteStable: false)
- BGP Prefix: 137.255.13.0/24
- RPKI State: Not validated
- IRR Consistency: Not verified
## Recommended Actions
Based on the risk profile, the following defensive measures are recommended:
| Platform | Recommended Action |
|---|---|
| **iptables** | `iptables -A INPUT -s 137.255.13.247 -j DROP` |
| **nftables** | `nft add rule inet filter input ip saddr 137.255.13.247 drop` |
| **nginx** | `deny 137.255.13.247;` |
| **pfSense** | Block 137.255.13.247/32 |
| **Cloudflare WAF** | Configure expression: `ip.src eq 137.255.13.247` with action: block |
| **AWS WAF** | Add address: 137.255.13.247/32 |
## Intelligence Notes
- SSH Service: The single open port (22) indicates a dedicated SSH host, typical of hosting infrastructure or compromised systems.
- DNS Association: The reverse DNS record (sbin.bj) suggests potential geographic spoofing given the .bj TLD (Benin) versus GB geolocation.
- Historical Volatility: 17 observations recorded with multiple signal type changes, indicating active monitoring of this address.
- Threat Persistence: Current threat observation count is 1 with 0 threat persistence days; not classified as persistently malicious.
## Conclusion
IP 137.255.13.247 warrants defensive blocking due to DNSBL listings, geographic signal inconsistency, and unstable route characteristics. The moderate risk score (50) combined with the single-service SSH configuration and subnet-level threat activity suggests this asset should be treated as potentially suspicious. Continue monitoring for changes in geolocation, DNS records, or service exposure.
---
*Data sourced from IPDebrief Intelligence Platform. All findings based on observed signal data as of 2026-07-29.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Vivien ASSANGBE |
| ASN | AS328228 |
| Network Name | 137.255.12.0 - 137.255.15.255 |
| CIDR Block | 137.255.12.0/22 |
| RIR | ARIN |
| Country | BJ |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | sbin.bj |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | sbin.bj |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 8% | 2 | 2 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-23 20:04:56 UTC |
| Last Seen | 2026-08-01 01:41:30 UTC |
| Profile Built | 2026-07-29 19:45:08 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 19 |
Full dossier details are available via our API.