# IPDEBRIEF INTELLIGENCE BRIEFING
Target: 192.24.37.157/32
Classification: High Risk
Risk Score: 80/100
Report Date: 2026-06-23
---
## Executive Summary
IP 192.24.37.157 is classified as a High Risk (80/100) single-service host located in Dutton, Ontario, Canada. The IP is registered to The North Frontenac Telephone Corporation Limited (ASN 393632) and is associated with a DNSBL presence on 4 of 8 total lists. While the IP lacks explicit malicious indicators (no Tor exit, spam source, or known attacker flags), the elevated risk score and multiple DNSBL listings warrant defensive monitoring and potential blocking.
---
## Technical Profile
Ownership & Registration:
- Organization: The North Frontenac Telephone Corporation Limited
- ASN: 393632
- RIR: ARIN
- Service Type: Single-Service Host
Geolocation:
- Country: Canada (CA)
- Region: Ontario (ON)
- City: Dutton
- Geolocation Accuracy: 3000km radius (consensus-based)
Network Classification:
- Control Plane Status: Route instability detected (0 route changes in 30 days, route stability: false)
- BGP Prefix: 192.24.32.0/21
- DNSBL Listed: Yes (4 of 8 total lists)
- Operator Score: 0.1304 (Minimal)
DNS Analysis:
- PTR Hostname: 192-24-37-157.nftctelecom.com
- Forward Resolution Confirmed: No
- SPF Record: Present
- DMARC Record: Absent
- Forward Hostnames: 1 (192-24-37-157.nftctelecom.com)
Active Services:
- Port 8080/TCP: http-alt (micro_httpd banner)
---
## Threat Indicators & Reputation
Risk Assessment:
- Overall Risk Score: 80/100 (High Risk)
- Is Tor Exit: No
- Is Known Attacker: No
- Is Spam Source: No
- Blacklist Count: 0
- Threat Feeds: None detected
Campaign Analysis:
- Campaign Likelihood: None
- CERT Matches: 0
- Correlated IPs: 0
- Threat Persistence Days: 0
Neighborhood Analysis:
- Subnet: 192.24.37.157/24
- Abuse Density: Low (0)
- Classification: Mostly Clean
- Threat Siblings: 1
- Total Siblings: 1
- Active Siblings: 1
---
## Historical Signal Observations
Observation history indicates multiple signal types observed since 2026-06-17:
- 2026-06-23T02:42:30Z: Operator score recorded as Minimal (0), FCRDNS signal observed
- 2026-06-17T22:49:01Z: Geolocation signal detected (CA, 56.13, -106.35)
- 2026-06-17T22:46:03Z: AlienVault OTX signal with threat flags (pulse_count: 27, has_threats: true)
Signal history shows 22 total observations with varying confidence levels (0.22โ0.95), indicating periodic network scanning and threat correlation activity.
---
## Relationship Graph
18 relationships identified:
- Same Network (NFTCL): 16 entries
- DNS Association: 2 entries (192-24-37-157.nftctelecom.com)
---
## Recommended Actions
Immediate: Block traffic at network perimeter
Firewall Rules:
- iptables: `iptables -A INPUT -s 192.24.37.157 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 192.24.37.157 drop`
- nginx: `deny 192.24.37.157;`
- pfSense: `192.24.37.157/32`
- Cloudflare WAF: Block with expression `ip.src eq 192.24.37.157`
- AWS WAF: Add `192.24.37.157/32` to rule
Monitoring: Increase logging verbosity and review recent activity from this IP (risk severity: Critical)
---
## Analyst Notes
The elevated risk score (80/100) combined with DNSBL listings and historical threat correlation signals suggest this IP should be treated as potentially malicious despite the absence of explicit attacker indicators. The route instability and minimal operator score warrant continued monitoring. Consider blocking at edge infrastructure and investigating any traffic connections from this IP.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | The North Frontenac Telephone Corporation Limited |
| ASN | AS393632 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 192-24-37-157.nftctelecom.com |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 192-24-37-157.nftctelecom.com |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 8080 | http-alt | tcp | โ |
| Closed Ports | 22, 25, 80, 443, 3389, 8443 (1 open / 7 scanned) | ||
| Server | micro_httpd |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 26% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 24% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 22% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:03 UTC |
| Last Seen | 2026-06-26 18:10:59 UTC |
| Profile Built | 2026-06-23 02:50:16 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.