# IP INTELLIGENCE BRIEFING
IP Address: 173.181.131.247/32
Classification: Mobile Network Static IP
Report Date: Current
Reputation: HIGH RISK (80/100)
## EXECUTIVE SUMMARY
IP 173.181.131.247 is a Telus Mobility static IP assigned to a mobile carrier (TELUS Communications) in Calgary, Alberta. The address carries an elevated risk score of 80/100 with no active services detected. Historical observations indicate fluctuating operator scores (0.13โ0.26) with no evidence of persistent malicious activity. The subnet (173.181.131.0/24) shows low abuse density with no active sibling threats.
## TECHNICAL PROFILE
- ASN: 852 (TELUS Mobility HSPA Static)
- Organization: TELUS Communications Inc.
- Location: Calgary, AB, CA (GeoSource Consensus: True)
- Network Type: Mobile Carrier (LTE/5G)
- DNS Resolution: 173-181-131-247-ent-barlow-staticipwest.wireless.telus.com
- Email Authentication: SPF and DMARC configured (DMARC policy: reject)
- Services: None detected (Firewalled / No Services)
- Open Ports: 0
## THREAT INDICATORS
- Risk Score: 80/100 (Critical)
- Blacklist Count: 0
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Threat Feeds: None
- Control Plane Risk: Operator Score 0.2609 (Basic)
- Route Stability: Unstable
## OBSERVATION HISTORY
Recent signal history (20 observations) shows:
- Consistent geolocation attribution to CA
- DNS records stable with proper SPF/DMARC configuration
- Operator score variance: 0.13 (June 17) to 0.26 (current)
- No observed threat persistence (0 days)
- Single threat observation recorded
## NETWORK CONTEXT
- Subnet: 173.181.131.0/24
- Abuse Density: 0 (Mostly Clean)
- Active Siblings: 0
- Threat Siblings: 1
- Total Relationships: 56
## RECOMMENDED ACTIONS
Priority: Monitor (Increase logging verbosity)
Firewall Rules
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 173.181.131.247 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 173.181.131.247 drop` |
| nginx | `deny 173.181.131.247;` |
| pfSense | `173.181.131.247/32` |
| Cloudflare WAF | Block with expression: `ip.src eq 173.181.131.247` |
| AWS WAF | Address: 173.181.131.247/32 |
## ANALYST NOTES
- False Positive Consideration: Mobile carrier static IPs may be legitimately used by employees or contractors. Review before blocking if internal business need exists.
- Risk Mitigation: No open services detected reduces exploitation risk. Primary concern is reputation-based classification.
- Monitoring: Track for service activity emergence. Current state shows firewalled configuration.
Status: Awaiting SOC validation for firewall enforcement.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | TELUS Mobility HSPA Static |
| ASN | AS852 |
| Network Name | TELUS-MOBILITY-HSPA-STATIC |
| CIDR Block | 173.181.128.0/20 |
| RIR | ARIN |
| Country | Canada |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | 173-181-131-247-ent-barlow-staticipwest.wireless.telus.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | 173-181-131-247-ent-barlow-staticipwest.wireless.telus.com |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 11% | 1 | 2 |
| ownership | 15% | 2 | 2 |
| reputation | 21% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 17% | 9 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:54 UTC |
| Last Seen | 2026-06-26 18:10:47 UTC |
| Profile Built | 2026-06-22 21:30:55 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 20 |
Full dossier details are available via our API.