# Intelligence Briefing: 195.36.31.62/32
## Executive Summary
IP address 195.36.31.62 is a low-to-moderate risk infrastructure endpoint belonging to HALSERVICE-ADMIN (AS44092). The address is currently firewalled with no active services, located in Serravalle Sesia, Italy, and shows minimal threat indicators. Monitoring recommended due to elevated risk score (55/100) and DNSBL listings.
---
## Ownership & Registration
- ASN: 44092 (HALSERVICE-ADMIN)
- Network: MYWIC-NET (195.36.31.0/24)
- RIR: RIPE
- Abuse Contact: Available via RDAP
## Geolocation
- Country: Italy (IT)
- Region: Piedmont
- City: Serravalle Sesia
- Geo Confidence: Consensus established across 1 source with plausible validation
## Network Classification
- Classification: Residential/Hosting endpoint
- Services: No open ports detected (Firewalled)
- Indicators: Not a proxy, Tor, VPN, CDN, or cloud endpoint
- Bogon: No
---
## Threat Assessment
- Risk Score: 55/100 (Moderate Risk)
- Abuse Confidence: Not quantified
- Blacklist Status: Listed on 3 of 8 DNSBLs
- Known Threats: No active campaigns or known attacker indicators
- Tor Exit: No
- Residential/Hosting: Likely residential IP
---
## DNS & Hostname Resolution
- PTR Record: host-195-36-31-62.mywic.eu
- Forward Resolution: Confirmed to host-195-36-31-62.mywic.eu
- Domain: mywic.eu
- Email Authentication: SPF enabled, DMARC not configured
---
## Neighborhood Analysis
- Subnet: 195.36.31.0/24
- Abuse Density: 0 (clean)
- Threat Siblings: 0 of 1 active siblings
- Risk Distribution: No high or medium risk neighbors detected
- Subnet Classification: Clean
---
## Control Plane & Routing
- Origin ASN: 44092
- BGP Prefix: 195.36.16.0/20
- Route Stability: False
- RPKI State: Unknown
- Operator Score: 0.1304 (Minimal)
---
## Historical Observation (19 observations)
- Threat Persistence: None observed
- Ownership Changes: None detected
- Geolocation: Consistent Italian location
- Classification: Clean subnet classification maintained throughout observation period
---
## Recommended Security Actions
Monitoring
- Increase logging verbosity and review recent activity from this IP
- Monitor for service enumeration attempts
Firewall Rules (Recommended)
```bash
# iptables
iptables -A INPUT -s 195.36.31.62 -j DROP
# nftables
nft add rule inet filter input ip saddr 195.36.31.62 drop
# nginx
deny 195.36.31.62;
# pfSense
195.36.31.62/32
# Cloudflare WAF
{
"description": "Block 195.36.31.62 โ IPDebrief risk score 55",
"action": "block",
"filter": {
"expression": "ip.src eq 195.36.31.62"
}
}
# AWS WAF
{
"Addresses": ["195.36.31.62/32"],
"Description": "IPDebrief risk 55"
}
```
---
## Analyst Notes
This IP presents a low-to-moderate risk profile with no active malicious indicators. The moderate risk score (55) appears to be driven by DNSBL listings rather than observed threat activity. The subnet shows clean classification with no threat neighbors. Given the firewalled state and lack of services, immediate blocking may be warranted based on organizational policy, but correlation with other threat intelligence sources is recommended before implementing defensive controls.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | HALSERVICE-ADMIN |
| ASN | AS44092 |
| Network Name | MYWIC-NET |
| CIDR Block | 195.36.31.0/24 |
| RIR | RIPE |
| Country | IT |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | host-195-36-31-62.mywic.eu |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | host-195-36-31-62.mywic.eu |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 35% | 2 | 2 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 22% | 6 | 7 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-27 09:39:17 UTC |
| Last Seen | 2026-07-30 11:38:40 UTC |
| Profile Built | 2026-07-30 11:51:12 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 20 |
Full dossier details are available via our API.