IPDebrief

154.118.49.144

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 154.118.49.144

Date: 2026-08-03

Classification: Moderate Risk (55/100)

Analyst: IPDebrief Intelligence System

---

## Executive Summary

IP 154.118.49.144 presents a moderate-risk profile with conflicting geolocation data and multiple DNSBL listings. The address is associated with ASN 37340 (Technical Contact SN) within the 154.118.32.0/19 block registered under AFRINIC. Despite being located in New York, US according to primary geolocation, historical signals indicate activity from Lagos, Nigeria. The IP is currently firewalled with no active services and presents an elevated risk requiring enhanced monitoring.

---

## Risk Profile

MetricValue
**Risk Score**55/100 (Moderate)
**Operator Score**0.1304 (Minimal)
**Blacklist Count**3 of 8 total DNSBL listings
**Maximum Severity**High
**Geolocation Consensus**False
**Service Status**Firewalled / No Services

---

## Ownership & Network Infrastructure

---

## Geolocation Discrepancies

Primary Location: New York, US (America/New_York timezone)

Historical Signals: Lagos, NG (Africa)

Geolocation Consensus: Inconsistent across multiple sources

This inconsistency warrants investigation. The IP is appearing in different geographic contexts, which may indicate:

---

## Threat Indicators

---

## Historical Observation Analysis

Recent signal history (10 observations) reveals:

1. Geolocation Volatility: Signals show country code NG (Nigeria) and US with confidence levels ranging from 0.30 to 0.95

2. ASN Conflicts: Historical records reference AS37340 as "african network information center" versus current profile showing "Technical Contact SN"

3. Threat Persistence: 0 threat persistence days, 0 threat observation count

4. Blacklist Activity: Listed on multiple DNSBLs with high severity ratings

---

## Network Services & Fingerprinting

Behavioral Indicators:

---

## Recommended Security Actions

Immediate Actions (Priority: High)

1. Block at Perimeter: Implement firewall rules to drop traffic from this source

2. Enhanced Logging: Increase logging verbosity for all traffic from this IP range

3. Review Recent Activity: Analyze logs for the past 30 days for anomalous patterns

Firewall Implementation Rules

```bash

# iptables

iptables -A INPUT -s 154.118.49.144 -j DROP

# nftables

nft add rule inet filter input ip saddr 154.118.49.144 drop

# nginx

deny 154.118.49.144;

# pfSense

154.118.49.144/32

```

Cloud Platform Rules

Cloudflare WAF:

```json

{"description":"Block 154.118.49.144 β€” IPDebrief risk score 55","action":"block","filter":{"expression":"ip.src eq 154.118.49.144"}}

```

AWS WAF:

```json

{"Addresses":["154.118.49.144/32"],"Description":"IPDebrief risk 55"}

```

---

## Intelligence Assessment

Threat Level: Moderate

Confidence: Medium

Action Required: Immediate blocking recommended pending further investigation

The IP presents moderate risk primarily due to:

1. Multiple DNSBL listings with high severity

2. Conflicting geolocation data suggesting potential proxy usage

3. Risk score of 55/100 exceeding typical thresholds for blocking

Recommendation: Block at perimeter immediately and monitor for lateral activity within the 154.118.32.0/19 network block. No immediate evidence of active exploitation or malicious activity, but the geolocation inconsistency and blacklist presence warrant continued monitoring.

---

Disclaimer: This intelligence is generated from automated data collection and should be validated against internal security logs and threat intelligence feeds before taking action.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionUS-NY
CityNew York
TimezoneAmerica/New_York
Latitudeβ€”
Longitudeβ€”

🏒 Ownership & Registration

OrganizationTechnical Contact SN
ASNAS37340
Network Name154.118.32.0 - 154.118.63.255
CIDR Block154.118.32.0/19
RIRAFRINIC
CountryNG
Abuse Contactβ€”

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)

πŸ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown β€” Insufficient routing data to classify
No specific classification

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
0%
00
reputation
0%
00
geolocation
0%
00
Overall12%33
Coverage: 3/6 dimensions Β· Data sufficiency: partial
Data CoherenceMostly Consistent (80%) β€” 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Geo sources disagree on country: NG, US

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-07-26 03:08:34 UTC
Last Seen2026-07-30 06:05:03 UTC
Profile Built2026-07-30 06:14:19 UTC
Data FreshnessLive
Signal Types16
Total Observations16
πŸ” 16 signal types Β· 16 observations collected
This report is generated from 16+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.