# THREAT INTELLIGENCE BRIEFING: 193.37.32.192/32
## EXECUTIVE SUMMARY
IP address 193.37.32.192 is classified as Low Risk (Risk Score: 25) with minimal threat indicators. The address is geolocated to Singapore and belongs to ASN 206092 (VPN Consumer Singapore, Republic of Singapore). No active threat campaigns or persistent malicious activity detected.
## PROFILE ASSESSMENT
Risk Classification: Low Risk (Score: 25)
Reputation: Low Risk
Ownership: ASN 206092 - VPN Consumer Singapore, Republic of Singapore
Geolocation: Singapore (1.35°N, 103.82°E) - Asia/Singapore timezone
Network Role: Firewalled / No Services Detected
Network Classification: Non-cloud, non-CDN, non-VPN, non-proxy
Threat Indicators:
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Blacklist Count: 0
- Abuse Confidence Score: Not applicable
DNS Analysis:
- No PTR records resolved
- No forward DNS resolution
- No hosted domains or email authentication records (SPF/DMARC)
## OBSERVATION HISTORY
Total Observations: 16 signals recorded
Most Recent Activity: 2026-06-17 23:19:13 UTC
Temporal Analysis:
- Ownership Changes: 0
- Threat Persistence Days: 0
- Is Persistently Malicious: False
- Threat Observation Count: 1
Signal Timeline Highlights:
- Geolocation signals consistently indicate Singapore (confidence: 0.28-0.30)
- Operator score: Minimal (0.1304)
- Comprehensive multi-dimension analysis with 0.24 confidence level
- Subnet analysis shows mixed classification with moderate abuse density (0.4857)
## NETWORK ENVIRONMENT ANALYSIS
/24 Subnet Context (193.37.32.0/24):
- Total Siblings: 210
- Active Siblings: 103
- Threat Siblings: 102
- Abuse Density: 0.4857 (Moderate)
- Classification: Mixed
Risk Distribution in Subnet:
- High Risk: 0 addresses
- Medium Risk: 30 addresses
- Low Risk: 70 addresses
Control Plane Indicators:
- BGP Prefix: 193.37.32.0/24
- Route Stable: False
- DNSBL Listed: 1 of 8 total lists
- RPKI State: Not evaluated
## RELATIONSHIP GRAPH
Linked Entities: 15 relationships identified
- All relationships point to same network: SINGAPORE-193-37-32-0
- No external organizational, hostname, or certificate associations detected
- No inter-IP relationships beyond subnet scope
## SECURITY RECOMMENDATIONS
Immediate Actions:
1. Allow Traffic - IP shows low risk profile with no active threat indicators
2. Monitor Subnet - 102 threat siblings in /24 suggest elevated regional activity; monitor for lateral movement
3. DNSBL Monitoring - 1 DNSBL listing detected; verify source and context
Firewall Rules:
```bash
# Allow standard traffic (low risk IP)
iptables -A INPUT -s 193.37.32.192 -j ACCEPT
# Monitor subnet-wide activity
iptables -A INPUT -s 193.37.32.0/24 -m limit --limit 10/min -j LOG
# Block malicious neighbors if needed
# Review specific IPs with risk score 40+ before action
```
SOC Monitoring Priorities:
- Track subnet abuse density changes over 30-day period
- Monitor for new threat siblings emerging in 193.37.32.0/24
- Watch for DNSBL listing changes
- Correlate with known campaigns (currently: none identified)
## CONCLUSION
The target IP 193.37.32.192 presents a low threat profile with no evidence of malicious activity. The primary concern is the elevated threat sibling count (102) within its /24 subnet, indicating Singapore-based infrastructure may host mixed-use networks with varying threat levels. No immediate blocking required; maintain standard monitoring protocols.
Classification: LOW RISK - No action required beyond routine monitoring
Confidence Level: Moderate (based on 16 historical observations)
Last Updated: 2026-06-17
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | VPN Consumer Singapore, Republic of Singapore |
| ASN | AS206092 |
| Network Name | β |
| CIDR Block | β |
| RIR | RIPE |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 21% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:04 UTC |
| Last Seen | 2026-06-23 03:12:55 UTC |
| Profile Built | 2026-06-23 03:19:55 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 20 |
Full dossier details are available via our API.