# IP Intelligence Briefing: 182.160.114.72/32
## Executive Summary
IP address 182.160.114.72 presents a High Risk profile with a risk score of 80/100. The endpoint is geolocated to Dhaka, Bangladesh (AS24323) and operates as a firewalled address with no active services. Multiple security signals indicate active threat observation despite minimal service exposure.
## Ownership & Network Context
- Organization: Syed Faruque Ahmed
- Network: DHANMONDIPOP-1 (182.160.114.0/24)
- ASN: 24323 (aamra networks limited)
- RIR: APNIC
- Registration: ASN registered under APNIC; network CIDR 182.160.114.0/24
## Geolocation
- Country: Bangladesh (BD)
- Region: Dhaka Division
- City: Dhaka
- Coordinates: 23.76°N, 90.4°E
- Network Validation: Distance 7,517.4 km; average RTT 275.2 ms
## Threat Profile
- Risk Score: 80/100 (High Risk)
- Abuse Confidence: Elevated risk indicators detected
- Blacklist Status: Listed on 5 of 8 DNSBL lists
- Threat Indicators: Active threat observations detected in recent signals
- Campaign Activity: No known campaign correlations at present
## Network Behavior
- Services: Firewalled / No services running
- Open Ports: None detected
- DNS: Forward resolution disabled; no PTR records; CAA record present
- Email Authentication: SPF, DMARC, and TXT records absent
- Infrastructure Classification: Not cloud, CDN, VPN, proxy, Tor, hosting, mobile, residential, bogon, or anycast
## Observed Threat Activity
- Signal Count: 22 total observations recorded
- Recent Activity: Multiple signals observed on 2026-06-22 and 2026-06-17
- Threat Persistence: Single threat observation detected (not persistently malicious)
- DNSBL Listings: 5 confirmed listings with maximum severity of high
- Pulse Count: 50 threat pulses detected in recent signals
## Neighborhood Assessment
- Subnet: 182.160.114.0/24
- Abuse Density: 1 (elevated)
- Classification: Mostly clean with inherited risk score of 2
- Sibling Count: 1 total sibling; 1 threat sibling identified
## Control Plane Metrics
- BGP Prefix: 182.160.114.0/24
- Route Stability: False (route changes detected)
- RPKI State: Not validated
- IRR Consistency: Not validated
- DNSSEC: Valid
- Operator Score: 0.2174 (Minimal)
## Recommended Security Actions
Immediate Mitigation
Recommendation: Increase logging verbosity and review recent activity from this IP (Severity: Critical)
Firewall Rules
```bash
# iptables
iptables -A INPUT -s 182.160.114.72 -j DROP
# nftables
nft add rule inet filter input ip saddr 182.160.114.72 drop
# nginx
deny 182.160.114.72;
# pfSense
182.160.114.72/32
# Cloudflare WAF
{
"description": "Block 182.160.114.72 โ IPDebrief risk score 80",
"action": "block",
"filter": {
"expression": "ip.src eq 182.160.114.72"
}
}
# AWS WAF
{
"Addresses": ["182.160.114.72/32"],
"Description": "IPDebrief risk 80"
}
```
## Intelligence Notes
This IP address demonstrates elevated threat characteristics with firewalled status and no active services. The presence of multiple DNSBL listings and recent threat observations warrants defensive blocking. Despite the firewalled state, the high risk score and DNSBL presence suggest prior malicious activity or association with compromised infrastructure. Monitor for any service activation or lateral movement within the 182.160.114.0/24 subnet.
---
*Report generated using IPDebrief threat intelligence platform. Recommendations are probabilistic and should be combined with other security signals before implementation.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Syed Faruque Ahmed |
| ASN | AS24323 |
| Network Name | DHANMONDIPOP-1 |
| CIDR Block | 182.160.114.0/24 |
| RIR | APNIC |
| Country | BD |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 11% | 1 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 21% | 1 | 3 |
| geolocation | 15% | 2 | 2 |
| Overall | 18% | 9 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:58 UTC |
| Last Seen | 2026-06-26 18:10:52 UTC |
| Profile Built | 2026-06-22 23:35:39 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 21 |
Full dossier details are available via our API.