# IPDEBRIEF INTELLIGENCE BRIEFING
Target: 154.241.21.228/32
Date: 2026-06-22
Classification: Defensive Intelligence
---
## EXECUTIVE SUMMARY
IP 154.241.21.228 is a low-risk infrastructure address hosted in Algiers, Algeria, with no active threat indicators. The IP has no open services and is currently firewalled. While the immediate risk is minimal, historical data shows the IP was previously listed on multiple blacklists, and the /24 neighborhood exhibits elevated abuse density.
---
## IP PROFILE
| Attribute | Value |
|---|---|
| **Risk Score** | 25 (Low) |
| **ASN** | 36947 |
| **Organization** | Security Departement |
| **Network Block** | 154.241.0.0/16 |
| **Registry** | AFRINIC |
| **Geolocation** | Algiers, Algeria (DZ) |
| **Coordinates** | 36.76°N, 3.15°E |
---
## THREAT ASSESSMENT
Current Threat Status: No active threat indicators detected.
- Blacklist Status: Currently unlisted
- Campaign Activity: None identified
- Malware Attribution: Not classified as known attacker
- Spam Source: Not flagged
- Tor Exit Node: False
Historical Context: On 2026-06-17, the IP was observed on 8 blacklist listings with high severity classification. This suggests a transient malicious period that has since been cleaned.
---
## NETWORK CHARACTERISTICS
- Service Status: Firewalled / No Services
- Open Ports: None detected
- DNS Resolution: No reverse DNS, no forward resolution
- Email Reputation: Not configured (no SPF/DMARC)
- Hosted Domains: 0
- Certificate Authority: None observed
Control Plane Indicators:
- BGP Origin: 154.241.0.0/19
- Route Stability: False
- DNSSEC: Valid
- Operator Score: 0.1304 (Minimal)
---
## NEIGHBORHOOD ANALYSIS
Subnet: 154.241.21.228/24
| Metric | Value |
|---|---|
| **Abuse Density** | 66.67% |
| **Classification** | Mostly Clean |
| **Total Siblings** | 3 |
| **Active Siblings** | 3 |
| **Threat Siblings** | 2 |
Neighbor Risk Distribution:
- High Risk: 0
- Medium Risk: 1 (154.241.21.64, Risk Score: 40)
- Low Risk: 1 (154.241.21.22, Risk Score: 25)
---
## OBSERVATION HISTORY
Total Observations: 18
Key Timeline:
- 2026-06-22: Minimal operator score (0), clean threat profile
- 2026-06-17: Listed on 8 blacklists, high severity rating
- 2026-06-17: Geolocation validation confirmed (1768.2km from probe)
---
## RECOMMENDATIONS
Current Actions: No immediate remediation required.
Monitoring Triggers:
- Watch for re-emergence on blacklists
- Monitor neighborhood subnet 154.241.21.0/24 for abuse density changes
- Track 154.241.21.64 (medium-risk neighbor) for potential lateral correlation
Firewall Policy: Current profile supports standard allow-listing with no special blocking rules required.
---
END OF BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Security Departement |
| ASN | AS36947 |
| Network Name | 154.241.0.0 - 154.241.255.255 |
| CIDR Block | 154.241.0.0/16 |
| RIR | AFRINIC |
| Country | DZ |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 23% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 19% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:47 UTC |
| Last Seen | 2026-06-22 18:09:12 UTC |
| Profile Built | 2026-06-22 18:18:22 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 18 |
Full dossier details are available via our API.