# INTELLIGENCE BRIEFING: IP 144.79.133.40
## Executive Summary
IP 144.79.133.40 was assessed as HIGH RISK with an overall risk score of 80. The address is registered to Hoststallcom administrator under ASN 153528 (HOSTSTALLCOM-BD). While the immediate /24 neighborhood shows low abuse density, the IP demonstrates concerning geolocation inconsistencies and DNSBL listings.
## Technical Profile
- Risk Score: 80 (High)
- ASN: 153528 (Hoststallcom administrator)
- Classification: Web Server
- Geolocation: Primary assignment to Hong Kong (HK); historical observations indicate Bangladesh (BD)
- DNS PTR: mail.ieducationbd.com
- TLS Certificate: boiferi.com (Let's Encrypt issuer)
- Open Ports: TCP/80 (HTTP), TCP/443 (HTTPS), TCP/22 (SSH)
- Server Banner: nginx/1.24.0 (Ubuntu)
- HTTP Version: 2.0 enabled
## Threat Indicators
- DNSBL Status: Listed on 4 of 8 total DNSBL feeds
- Geolocation Consensus: Inconsistent (geoConsensus: false; geoPlausible: false)
- Route Stability: False (isRouteStable: false)
- Campaign Matches: None identified
- Known Attacker/SpamSource/Tor Exit: Not flagged
## Historical Observations (21 total)
- Multiple geolocation signals recorded between Hong Kong and Bangladesh
- Recent TLS scanning activity observed (July 27–31)
- HTTP response times recorded at 1500ms
- Server fingerprinting indicates Next.js application stack
- No persistent malicious behavior detected over observation period
## Network Relationships
- Primary DNS association: mail.ieducationbd.com
- Network block: 144.79.132.0/23 (HOSTSTALLCOM-BD)
- Control plane origin: 144.79.133.0/24
- Operator score: 0.2609 (Basic)
## /24 Neighborhood Analysis
Subnet 144.79.133.0/24 shows:
- Abuse Density: 0 (clean classification)
- Active Siblings: 2
- Neighbor Risk Distribution: 0 High, 1 Medium, 1 Low
- Notable Neighbor IPs:
- 144.79.133.50 (Risk: 25)
- 144.79.133.252 (Risk: 50)
## Recommended Actions
- Monitor for increased DNSBL listings
- Correlate geolocation inconsistencies with operational context
- Evaluate necessity of blocking based on organizational threat tolerance
- Consider monitoring the /24 subnet for lateral movement indicators
## Conclusion
This IP presents a moderate-to-high risk profile driven primarily by DNSBL presence and geolocation inconsistencies rather than confirmed malicious activity. The address operates within a relatively clean neighborhood but exhibits behavioral anomalies warranting continued surveillance.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Hoststallcom administrator |
| ASN | AS153528 |
| Network Name | HOSTSTALLCOM-BD |
| CIDR Block | 144.79.132.0/23 |
| RIR | ARIN |
| Country | BD |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | mail.ieducationbd.com |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | mail.ieducationbd.com |
🔐 DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | 1/3 domains |
| DMARC | 1/3 domains |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 3 domains |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Tier 3 — Basic operator with some routing infrastructure |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 443 | https | tcp | — |
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | boiferi.comwww.boiferi.com |
| Valid From | 2026-07-21T10:36:02+00:00 |
| Valid Until | 2026-10-19T10:36:01+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
🛡️ Public Network Snapshot
| Origin ASN | AS153528 |
| Network Prefix | 144.79.133.0/24 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Enabled |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 20% | 2 | 3 |
| ownership | 17% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 15% | 2 | 2 |
| Overall | 17% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-14 15:50:26 UTC |
| Last Seen | 2026-09-02 19:26:46 UTC |
| Profile Built | 2026-09-02 11:29:17 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 33 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 144.79.133.40
Who owns the IP address 144.79.133.40?
144.79.133.40 is registered to Hoststallcom administrator. The address falls within the 144.79.132.0/23 network block. Registration is held at ARIN.
Where is 144.79.133.40 located?
Geolocation data places 144.79.133.40 in Hong Kong. The local time zone is Asia/Hong_Kong. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 144.79.133.40 malicious or safe?
144.79.133.40 currently carries a high risk assessment, meaning indicators associated with malicious or abusive activity have been observed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 144.79.133.40?
The reverse DNS (PTR) record for 144.79.133.40 is mail.ieducationbd.com. This hostname is not forward-confirmed, so it should be treated as a weak signal.
What ports are open on 144.79.133.40?
Responsive ports observed on 144.79.133.40 include 80, 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.