IPDebrief

154.227.131.29

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 154.227.131.29/32

Classification: Low Risk – No Immediate Threat Indicators

Report Date: 2026-07-27

Analysis Period: Current observations

---

## Executive Summary

IP 154.227.131.29 presents a low-risk profile with a risk score of 25. The address is classified as "clean" with no threat indicators, no open services, and no known malicious activity. However, a geolocation mismatch (FR vs. DNS domain airtel.ug) warrants monitoring.

---

## Ownership & Infrastructure

AttributeValue
**ASN**37075
**Organization**Network Admin
**Netname**154.224.0.0 - 154.227.255.255
**CIDR Block**154.224.0.0/14
**RIR**afrinic
**Status**Firewalled / No Services

---

## Geolocation & Network Context

AttributeValue
**Country**France (FR)
**City**Marseille
**Region**Central Region
**DNS Domain**airtel.ug (Uganda)
**PTR Record**29-131-227-154.r.airtel.ug
**Distance (Geo Validation)**6,278.7 km

Note: Geographic discrepancy between network registration (France) and DNS domain (Uganda) indicates potential misconfiguration or multi-jurisdictional deployment.

---

## Threat Assessment

---

## Neighborhood Analysis (154.227.131.0/24)

MetricValue
**Abuse Density**0 (Clean)
**Subnet Classification**Clean
**Total Siblings**2
**Active Siblings**0
**Threat Siblings**0
**Neighbor IP**154.227.131.90 (Risk: 0, Authority: 50)

---

## Observation History (18 Observations)

Most recent activity recorded: 2026-07-27

Threat Persistence: 0 days

Ownership Changes: 0

Classification Trend: Stable (no degradation observed)

---

## Relationships Graph (5 Total)

1. Same Network: 154.224.0.0 - 154.227.255.255 (×2)

2. DNS Association: 29-131-227-154.r.airtel.ug (×3)

---

## Control Plane Data

MetricValue
**BGP Prefix**154.227.130.0/23
**Route Stability**False
**Route Changes (30d)**0
**IS Route Stable**No
**DNSSEC Valid**Yes
**CAA Records**Yes
**ICMP Validation**Blocked (unable to validate)

---

## Recommended Actions

Current Risk Level: No immediate action required.

Monitoring Recommendations:

1. Monitor for DNS geolocation mismatch resolution

2. Track any emergence of open services/ports

3. Watch for additional DNSBL listings

4. Maintain awareness of subnet-level activity

Firewall Rules: No restrictive rules recommended at this time.

---

Analyst Notes: This IP appears to be a legitimate infrastructure address with no active malicious behavior. The primary intelligence gap is the France/Uganda geolocation discrepancy, which should be verified with network operations teams. The subnet remains clean with no abuse activity.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇫🇷 France
RegionCentral Region
CityMarseille
TimezoneEurope/Paris
Latitude0.32
Longitude32.57

🏢 Ownership & Registration

OrganizationNetwork Admin
ASNAS37075
Network Name154.224.0.0 - 154.227.255.255
CIDR Block154.224.0.0/14
RIRAFRINIC
CountryUG
Abuse Contact—

🌐 DNS Intelligence

PTR29-131-227-154.r.airtel.ug
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnames29-131-227-154.r.airtel.ug

🔐 DNS Hygiene

Hygiene Score80% (Excellent)
SPF2/2 domains
DMARC1/2 domains
FCrDNSNot verified
DNSSECValid
CAAPresent
Domains Checked2 domains

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS37075
Network Prefix154.227.130.0/23
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
0%
00
routing
0%
00
services
0%
00
ownership
0%
00
reputation
0%
00
geolocation
25%
11
Overall4%11
Coverage: 1/6 dimensions · Data sufficiency: partial
Data CoherenceMostly Consistent (80%) — 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Geo sources disagree on country: UG, FR

📅 Observation Timeline 🔄 Live

First Seen2026-07-15 16:16:04 UTC
Last Seen2026-07-27 22:41:22 UTC
Profile Built2026-08-30 17:03:11 UTC
Data FreshnessLive
Signal Types20
Total Observations23
🔍 20 signal types · 23 observations collected
This report is generated from 20+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 154.227.131.29

Who owns the IP address 154.227.131.29?

154.227.131.29 is registered to Network Admin. The address falls within the 154.224.0.0/14 network block. Registration is held at AFRINIC.

Where is 154.227.131.29 located?

Geolocation data places 154.227.131.29 in Marseille, Central Region, France. The local time zone is Europe/Paris. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 154.227.131.29 malicious or safe?

154.227.131.29 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.

What is the hostname for 154.227.131.29?

The reverse DNS (PTR) record for 154.227.131.29 is 29-131-227-154.r.airtel.ug. This hostname is not forward-confirmed, so it should be treated as a weak signal.

🏘️ Related IP Addresses

Nearby addresses in 154.224.0.0/14

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.