# Threat Intelligence Briefing: 155.254.24.156/32
Classification: High Risk | Risk Score: 70/100
---
## Executive Summary
IP address 155.254.24.156/32 presents an elevated security concern with a risk score of 70/100. The address is associated with a private customer account under ASN 397373, located in Charlotte, North Carolina, US. No active services were detected, and the IP appears firewalled. Multiple DNSBL listings (4 of 8) suggest prior reputation issues.
---
## Technical Profile
Ownership & Network:
- ASN: 397373 (Private Customer)
- Network Block: 155.254.24.2/31
- RIR Registration: ARIN
- Geolocation: United States, North Carolina, Charlotte (6,825 km from probe origin)
Network Services:
- Open Ports: None detected
- HTTP/TLS: No services responding
- Classification: Firewalled / No Services
Control Plane Indicators:
- BGP Prefix: 155.254.24.0/22
- Route Stability: Unstable
- DNSBL Listings: 4 of 8 total lists
- RPKI Status: Not validated
---
## Threat Observations
Current Threat Indicators:
- No active threat campaigns detected
- Not identified as Tor exit node, known attacker, or spam source
- No email authentication records (SPF/DMARC)
DNSBL Status:
- Listed on 4 out of 8 DNSBL feeds
- Indicates prior reputation issues or blacklisted activity
Historical Activity:
- Single threat observation recorded
- Not classified as persistently malicious
- No evidence of sustained malicious campaigns
---
## Neighborhood Analysis
Subnet: 155.254.24.156/24
- Abuse Density: 1
- Classification: Mostly clean
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 1
The surrounding /24 subnet shows minimal threat presence with one active threat sibling. No significant correlated abuse patterns detected in the immediate neighborhood.
---
## Recommended Actions
Immediate:
```bash
# iptables
iptables -A INPUT -s 155.254.24.156 -j DROP
# nftables
nft add rule inet filter input ip saddr 155.254.24.156 drop
# pfSense
155.254.24.156/32
```
Monitoring:
- Increase logging verbosity and review recent activity from this IP
- Monitor for any changes in network behavior or service emergence
---
## Intelligence Assessment
The elevated risk score (70/100) is primarily driven by DNSBL listings and historical reputation issues. The absence of open services and no active threat indicators suggests this IP may be dormant or previously associated with malicious activity. The single threat sibling in the /24 subnet indicates minimal network-wide correlation.
Recommendation: Block at perimeter firewall with monitoring enabled. Re-evaluate in 30 days if no further activity is observed.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Private Customer |
| ASN | AS397373 |
| Network Name | 155254241 |
| CIDR Block | 155.254.24.2/31 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | β |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 25% | 1 | 1 |
| reputation | 25% | 1 | 1 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-28 04:02:36 UTC |
| Last Seen | 2026-07-30 15:08:47 UTC |
| Profile Built | 2026-07-30 15:18:31 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.