# IP Intelligence Briefing: 154.127.36.139
Classification: Moderate Risk | Risk Score: 55/100 | Date: 2026-07-29
---
## Executive Summary
IP address 154.127.36.139 presents moderate threat risk with elevated neighborhood activity. The subnet exhibits 20% abuse density with 3 high-risk siblings. No active services detected on target IP, but DNSBL listings and geolocation inconsistencies warrant monitoring.
---
## Network Ownership & Geolocation
| Attribute | Value |
|---|---|
| ASN | 37292 (Christian N. MIGNAN) |
| CIDR Block | 154.127.36.0/24 |
| RIR | afrinic |
| Reported Locations | Boston, MA, US / Cotonou, Benin |
| Geolocation Confidence | 85% |
| Route Stability | **UNSTABLE** |
Note: Conflicting geolocation data detected. US and Benin locations observed in recent signals.
---
## Threat Indicators
- DNSBL Listings: 3 of 8 total blacklist entries (High severity confirmed)
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Open Ports/Services: None detected
- Blacklist Count: 3 (dnsblListedCount)
---
## Subnet Analysis (154.127.36.0/24)
| Metric | Value |
|---|---|
| Total Siblings | 15 active |
| Abuse Density | 20% (0.2) |
| High-Risk Neighbors | 3 IPs |
| Medium-Risk Neighbors | 11 IPs |
| Low-Risk Neighbors | 1 IP |
High-Risk Siblings: 154.127.36.209 (80), 154.127.36.232 (80), 154.127.36.237 (80)
---
## Historical Observations
Recent signal history (10 observations):
- DNSBL Listings: Confirmed (3 lists, high severity)
- Geolocation: Inconsistent (US Boston β Benin Cotonou)
- Ownership: Stable (0 changes recorded)
- Threat Persistence: 0 days
---
## Recommended Actions
Priority: Monitor / Block (based on risk score 55)
| System | Recommended Rule |
|---|---|
| iptables | `iptables -A INPUT -s 154.127.36.139 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 154.127.36.139 drop` |
| Nginx | `deny 154.127.36.139;` |
| pfSense | `154.127.36.139/32` |
| Cloudflare WAF | Block with expression: `ip.src eq 154.127.36.139` |
| AWS WAF | Addresses: `["154.127.36.139/32"]` |
---
## SOC Analyst Notes
1. Elevated Risk Score (55/100) triggers monitoring recommendation
2. Subnet Abuse Density (20%) suggests coordinated or shared infrastructure risk
3. Geolocation Inconsistencies between US and Benin may indicate routing anomalies or spoofing
4. No Active Services detected reduces immediate exploitation risk
5. Route Instability detected in BGP control plane data
Recommendation: Implement blocking rule with monitoring enabled. Investigate subnet-wide activity patterns and consider blocklisting entire /24 if business case supports it given 20% abuse density.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Christian N. MIGNAN |
| ASN | AS37292 |
| Network Name | 154.127.36.0 - 154.127.36.255 |
| CIDR Block | 154.127.36.0/24 |
| RIR | AFRINIC |
| Country | BJ |
| Abuse Contact | β |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | lighttpd/1.4.39 |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-24 14:25:56 UTC |
| Last Seen | 2026-08-09 23:07:36 UTC |
| Profile Built | 2026-08-04 11:51:12 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 17 |
Full dossier details are available via our API.