# IPDEBRIEF THREAT INTELLIGENCE BRIEFING
Target IP: 154.57.223.95/32
Date: 2026-07-28
Risk Classification: LOW RISK (Score: 25/100)
---
## EXECUTIVE SUMMARY
IP 154.57.223.95 is a low-risk address assigned to Cogent Communications, LLC within the 154.57.0.0/16 CIDR block registered under the afrinic RIR. No active threat indicators, known campaigns, or malicious reputation signals were identified. The IP appears to be firewalled with no open services detected.
---
## OWNERSHIP & NETWORK CLASSIFICATION
| Attribute | Value |
|---|---|
| **Organization** | Cogent Communications, LLC |
| **ASN** | 138655 |
| **Netname** | COGENT-154-57-16 |
| **RIR** | afrinic |
| **CIDR Block** | 154.57.0.0/16 |
| **Abuse Contact** | abuse@cogentco.com |
---
## GEOLOCATION DATA
| Attribute | Value |
|---|---|
| **Country** | Pakistan (PK) |
| **Region** | Punjab |
| **City** | Lahore |
| **Confidence** | 0.70 (MaxMind GeoLite2) |
| **Accuracy Radius** | 2500 km |
| **Geo Sources** | 1 |
*Note: Additional geolocation signals reported US coordinates (39.83, -98.58) with 0.35 confidence from Cymru Country method.*
---
## THREAT INTELLIGENCE
Threat Indicators: None Identified
- Blacklist Count: 0
- Known Campaigns: 0
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Abuse Confidence Score: N/A
Control Plane Analysis:
- Route Changes (30-day): 0
- BGP Prefix: 154.57.223.0/24
- Route Stability: Stable
- DNSSEC Valid: Yes
- DNSBL Listed: 1 of 8 total lists
---
## NETWORK SERVICES
| Service Type | Status |
|---|---|
| **Open Ports** | None detected |
| **DNS PTR** | Unresolved |
| **Forward Resolution** | 0 records |
| **HTTP/S** | No services responding |
| **SSL/TLS Certificate** | N/A |
Classification: Firewalled / No Services
---
## NEIGHBORHOOD ANALYSIS
Subnet: 154.57.223.0/24
Total Siblings: 8
Abuse Density: 0%
Risk Distribution:
- High Risk: 0
- Medium Risk: 1 (154.57.223.206 - Score: 40)
- Low Risk: 7 (including target IP - Score: 25)
Notable Neighbor: 154.57.223.206 shows elevated risk (40/100) but remains within normal operational parameters for the subnet.
---
## OBSERVATION HISTORY
Total Observations: 13 signals tracked
Ownership Changes: 0 (stable)
Threat Persistence Days: 0
Persistently Malicious: No
Recent signals indicate consistent network infrastructure with no escalation in threat profile. All observations from 2026-07-28 timeframe show stable ownership and geolocation consistency.
---
## RELATIONSHIP GRAPH
Connected Entities: 3 relationships identified
- Same Network: COGENT-154-57-16 (3 instances)
No external associations to hostnames, organizations, or certificates beyond network-level relationships.
---
## RECOMMENDED ACTIONS
Immediate Action: No specific firewall rules generated
Risk Level: Low - Standard monitoring appropriate
Classification Flags: None requiring escalation
Suggested Mitigations:
- Block or rate-limit if connection attempts observed (low-risk profile)
- Monitor for service changes (currently firewalled)
- No immediate block recommended based on current risk profile
---
INTELLIGENCE ANALYST NOTES:
This IP represents legitimate Cogent Communications infrastructure with no active threat indicators. The low-risk classification (25/100) combined with zero blacklist entries and no open services suggests this is either a reserved, administrative, or firewalled endpoint. Neighborhood analysis shows minimal abuse activity within the /24 subnet. Continue standard monitoring but no defensive action required at this time.
DATA SOURCES: IPDebrief Intelligence Platform
CLASSIFICATION: SOC Analyst - Defensive Security
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Cogent Communications, LLC |
| ASN | AS138655 |
| Network Name | COGENT-154-57-16 |
| CIDR Block | 154.57.0.0/16 |
| RIR | AFRINIC |
| Country | United States |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS138655 |
| Network Prefix | 154.57.223.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-17 17:12:07 UTC |
| Last Seen | 2026-08-31 23:10:35 UTC |
| Profile Built | 2026-08-31 23:13:17 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 20 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 154.57.223.95
Who owns the IP address 154.57.223.95?
154.57.223.95 is registered to Cogent Communications, LLC. The address falls within the 154.57.0.0/16 network block. Registration is held at AFRINIC.
Where is 154.57.223.95 located?
Geolocation data places 154.57.223.95 in Lahore, Punjab, Pakistan. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 154.57.223.95 malicious or safe?
154.57.223.95 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.