# IP Intelligence Briefing: 154.118.49.144
Date: 2026-08-03
Classification: Moderate Risk (55/100)
Analyst: IPDebrief Intelligence System
---
## Executive Summary
IP 154.118.49.144 presents a moderate-risk profile with conflicting geolocation data and multiple DNSBL listings. The address is associated with ASN 37340 (Technical Contact SN) within the 154.118.32.0/19 block registered under AFRINIC. Despite being located in New York, US according to primary geolocation, historical signals indicate activity from Lagos, Nigeria. The IP is currently firewalled with no active services and presents an elevated risk requiring enhanced monitoring.
---
## Risk Profile
| Metric | Value |
|---|---|
| **Risk Score** | 55/100 (Moderate) |
| **Operator Score** | 0.1304 (Minimal) |
| **Blacklist Count** | 3 of 8 total DNSBL listings |
| **Maximum Severity** | High |
| **Geolocation Consensus** | False |
| **Service Status** | Firewalled / No Services |
---
## Ownership & Network Infrastructure
- ASN: 37340 (AS37340 african network information center)
- Organization: Technical Contact SN
- CIDR Block: 154.118.32.0/19 (154.118.32.0 - 154.118.63.255)
- RIR: AFRINIC
- Network Classification: Provider / Infrastructure
- Subnet: 154.118.49.144/24 (no active sibling IPs detected)
---
## Geolocation Discrepancies
Primary Location: New York, US (America/New_York timezone)
Historical Signals: Lagos, NG (Africa)
Geolocation Consensus: Inconsistent across multiple sources
This inconsistency warrants investigation. The IP is appearing in different geographic contexts, which may indicate:
- Proxy or tunneling activity
- Misconfigured or spoofed geolocation data
- Multi-jurisdictional infrastructure
---
## Threat Indicators
- Abuse Confidence Score: Present
- DNSBL Listings: 3 confirmed (high severity)
- Known Campaigns: None identified
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Honeypot Hits: 0
- Enumeration Strikes: 0
---
## Historical Observation Analysis
Recent signal history (10 observations) reveals:
1. Geolocation Volatility: Signals show country code NG (Nigeria) and US with confidence levels ranging from 0.30 to 0.95
2. ASN Conflicts: Historical records reference AS37340 as "african network information center" versus current profile showing "Technical Contact SN"
3. Threat Persistence: 0 threat persistence days, 0 threat observation count
4. Blacklist Activity: Listed on multiple DNSBLs with high severity ratings
---
## Network Services & Fingerprinting
- Open Ports: None detected
- TLS Certificate: None
- HTTP Title: None
- Server Banner: None
- Reverse DNS (PTR): None
- Forward Resolution: None
- Hosted Domains: 0
Behavioral Indicators:
- No WAF violations
- No HTTP2, HSTS, or CSP headers
- No referrer policy or permissions policy
---
## Recommended Security Actions
Immediate Actions (Priority: High)
1. Block at Perimeter: Implement firewall rules to drop traffic from this source
2. Enhanced Logging: Increase logging verbosity for all traffic from this IP range
3. Review Recent Activity: Analyze logs for the past 30 days for anomalous patterns
Firewall Implementation Rules
```bash
# iptables
iptables -A INPUT -s 154.118.49.144 -j DROP
# nftables
nft add rule inet filter input ip saddr 154.118.49.144 drop
# nginx
deny 154.118.49.144;
# pfSense
154.118.49.144/32
```
Cloud Platform Rules
Cloudflare WAF:
```json
{"description":"Block 154.118.49.144 β IPDebrief risk score 55","action":"block","filter":{"expression":"ip.src eq 154.118.49.144"}}
```
AWS WAF:
```json
{"Addresses":["154.118.49.144/32"],"Description":"IPDebrief risk 55"}
```
---
## Intelligence Assessment
Threat Level: Moderate
Confidence: Medium
Action Required: Immediate blocking recommended pending further investigation
The IP presents moderate risk primarily due to:
1. Multiple DNSBL listings with high severity
2. Conflicting geolocation data suggesting potential proxy usage
3. Risk score of 55/100 exceeding typical thresholds for blocking
Recommendation: Block at perimeter immediately and monitor for lateral activity within the 154.118.32.0/19 network block. No immediate evidence of active exploitation or malicious activity, but the geolocation inconsistency and blacklist presence warrant continued monitoring.
---
Disclaimer: This intelligence is generated from automated data collection and should be validated against internal security logs and threat intelligence feeds before taking action.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Technical Contact SN |
| ASN | AS37340 |
| Network Name | 154.118.32.0 - 154.118.63.255 |
| CIDR Block | 154.118.32.0/19 |
| RIR | AFRINIC |
| Country | NG |
| Abuse Contact | β |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-26 03:08:34 UTC |
| Last Seen | 2026-07-30 06:05:03 UTC |
| Profile Built | 2026-07-30 06:14:19 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 16 |
Full dossier details are available via our API.