# IP Intelligence Briefing: 2.57.131.177/32
## Executive Summary
IP 2.57.131.177 is classified as Low Risk with a risk score of 25. The address is a static residential IP assigned to Joan Gaudes within the ES-GOUFONE-20190319 network block (2.57.128.0/22), operated under RIPE registry. No active threat indicators or malicious activity were detected during analysis.
## Ownership & Registration
- ASN: 208909
- Organization: Joan Gaudes
- Netname: ES-GOUFONE-20190319
- CIDR Block: 2.57.128.0/22
- RIR: RIPE
- Abuse Contact: abuse@somvera.cat
## Geolocation
- Country: Spain (ES)
- Region: Catalonia
- City: Vic
- Coordinates: 40.46°N, -3.75°W (500km accuracy)
- Timezone: Europe/Madrid
- GeoValidation: GeoPlausible confirmed; ICMP validation blocked
## Threat Assessment
- Risk Score: 25 (Low Risk)
- Abuse Confidence Score: Not applicable
- Blacklist Status: 0 blacklists
- Pulsedive Risk: Not assessed
- Known Campaigns: None
- Threat Feeds: No detections
Threat Indicators
- Not a Tor exit node
- Not a known attacker
- Not a spam source
- Not classified as CDN, VPN, proxy, hosting, or mobile infrastructure
- No open ports detected (service purpose: Firewalled / No Services)
## DNS Configuration
- PTR Hostname: 177.131.57.2-ip.somvera.cat
- Associated Domain: somvera.cat
- Forward Resolution Count: 1
- DNSSEC Validation: Valid
- Email Authentication: SPF record present; DMARC status unknown
## Network Traffic Analysis
- BGP Prefix: 2.57.131.0/24
- Route Stability: Unstable (routeChanges30d: 0)
- DNSBL Listings: 1 out of 8 total lists
- Operator Score: 0.1304 (Minimal)
- RPKI State: Not validated
Traceroute Profile
- Hop Count: 30
- Timed Out Hops: 18
- Transit Networks: Comcast, GTT
- First Hop RTT: 0.2ms
- Last Hop RTT: 110.5ms
## Subnet Analysis (2.57.131.0/24)
- Abuse Density: 0 (Clean)
- Total Siblings: 1
- Active Siblings: 0
- Threat Siblings: 0
- Classification: Clean
- Inherited Risk: 0
## Relationship Graph
- Same Network Relationships: 3 (ES-GOUFONE-20190319)
- DNS Associations: 5 (177.131.57.2-ip.somvera.cat)
- Total Relationships: 8
## Historical Observation Summary
- Total Signals Observed: 19
- Recent Activity: July 26, 2026 (ownership signals, geolocation signals, network type signals)
- Ownership Changes: 0
- Threat Persistence Days: 0
- Threat Observation Count: 0
- Is Persistently Malicious: No
## SOC Recommendations
1. No Immediate Action Required: Risk score of 25 with clean subnet classification indicates low threat posture.
2. Monitor DNS Activity: IP resolves to somvera.cat domain; monitor for DNS-based anomalies.
3. Verify Email Authentication: SPF present but DMARC record status requires verification for complete email reputation assessment.
4. Review DNSBL Listing: One DNSBL listing detected; investigate specific list and reason for inclusion.
5. Baseline Network Behavior: Establish baseline for 2.57.131.0/24 subnet given clean classification and zero active threat siblings.
## Risk Conclusion
IP 2.57.131.177 represents a low-risk residential connection with no malicious indicators. The subnet demonstrates clean abuse density and no correlated threat activity. Standard monitoring practices are sufficient; no blocking or mitigation actions are warranted at this time.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Joan Gaudes |
| ASN | AS208909 |
| Network Name | ES-GOUFONE-20190319 |
| CIDR Block | 2.57.128.0/22 |
| RIR | RIPE |
| Country | ES |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | 177.131.57.2-ip.somvera.cat |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 177.131.57.2-ip.somvera.cat |
🔐 DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | 2/2 domains |
| DMARC | 2/2 domains |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 2 domains |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS208909 |
| Network Prefix | 2.57.131.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-12 02:47:11 UTC |
| Last Seen | 2026-07-26 23:38:26 UTC |
| Profile Built | 2026-08-31 01:57:09 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 24 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 2.57.131.177
Who owns the IP address 2.57.131.177?
2.57.131.177 is registered to Joan Gaudes. The address falls within the 2.57.128.0/22 network block. Registration is held at RIPE.
Where is 2.57.131.177 located?
Geolocation data places 2.57.131.177 in Vic, Catalonia, Spain. The local time zone is Europe/Madrid. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 2.57.131.177 malicious or safe?
2.57.131.177 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 2.57.131.177?
The reverse DNS (PTR) record for 2.57.131.177 is 177.131.57.2-ip.somvera.cat. This hostname is not forward-confirmed, so it should be treated as a weak signal.