# IP Intelligence Briefing: 154.208.59.3/32
## Executive Summary
IP 154.208.59.3 presents as a low-risk, non-malicious address with no active threat indicators. The IP is classified as "Firewalled / No Services" with zero open ports detected. Current risk score is 0 with no known abuse activity or blacklisting.
## Ownership & Registration
- ASN: 150750 (Cloud Innovation Support)
- CIDR Block: 154.208.59.0/24
- RIR: AFRINIC
- Organization: Cloud Innovation Support
## Network Classification
The address is classified as infrastructure with no active services:
- Not cloud, CDN, VPN, proxy, Tor, hosting, or residential
- No open ports detected
- Service purpose: Firewalled / No Services
- No TLS certificates or HTTP services active
## Geolocation Analysis
Geolocation data shows significant inconsistencies requiring validation:
- Profile Data: GB (London), Punjab region
- Historical Observations: PK (Pakistan - Lahore) and Seychelles
- GeoPlausible: false
- GeoConsensus: false
Multiple geolocation sources are reporting conflicting locations, suggesting potential routing anomalies or data collection issues. This requires manual verification if physical location verification is critical for the investigation.
## Threat Intelligence
- Risk Score: 0 (Low Risk)
- Abuse Confidence Score: null
- Blacklist Count: 0
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
No threat indicators, malicious campaigns, or known attacker associations detected.
## Subnet/Neighborhood Analysis
- Subnet: 154.208.59.0/24
- Abuse Density: 0 (clean)
- Threat Siblings: 0
- Neighbor Count: 0
- Classification: clean
The /24 subnet shows no abuse activity or related threats. No neighboring IPs flagged for risk.
## Control Plane Observations
- Operator Score: 0.1304 (Minimal)
- Route Stability: false (route changes detected)
- DNSBL Listed: 0
- DNSSEC: Valid
- BGP Prefix: 154.208.59.0/24
## Historical Activity
Observation history shows 12 data points with varying confidence levels. Signals include:
- Ownership change tracking: 0 changes observed
- Threat persistence: 0 days
- Route stability signals present
- Geolocation observations with conflicting location data
No persistent malicious behavior or threat persistence detected.
## Recommended Actions
No specific security actions required at this time. The IP presents as benign infrastructure with no active services. Recommendations:
- Monitor for service activation if previously inactive
- Verify physical location if geolocation accuracy is critical
- Continue routine observation for any behavior changes
## SOC Analyst Notes
This IP should be treated as low-risk but warrants geolocation verification due to conflicting location data across different sources. No immediate blocking or mitigation actions recommended.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Cloud Innovation Support |
| ASN | AS150750 |
| Network Name | 154.208.59.0 - 154.208.59.255 |
| CIDR Block | 154.208.59.0/24 |
| RIR | AFRINIC |
| Country | PK |
| Abuse Contact | — |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS150750 |
| Network Prefix | 154.208.59.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 25% | 1 | 1 |
| Overall | 22% | 6 | 6 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-10 01:48:17 UTC |
| Last Seen | 2026-09-17 06:32:55 UTC |
| Profile Built | 2026-08-29 06:38:51 UTC |
| Data Freshness | Live |
| Signal Types | 15 |
| Total Observations | 16 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 154.208.59.3
Who owns the IP address 154.208.59.3?
154.208.59.3 is registered to Cloud Innovation Support. The address falls within the 154.208.59.0/24 network block. Registration is held at AFRINIC.
Where is 154.208.59.3 located?
Geolocation data places 154.208.59.3 in London, Punjab, United Kingdom. The local time zone is Europe/London. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 154.208.59.3 malicious or safe?
154.208.59.3 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.