INTELLIGENCE BRIEFING: 202.47.34.52
---
**SUMMARY**
The IP address 202.47.34.52 is associated with ASN 9541 (CYBERNET-PK) under organization Amjad Qasmi. The address is geolocated to Karachi, Sindh, Pakistan. The IP carries a moderate risk score of 50 and is currently classified as firewalled with no active services or open ports.
**OWNERSHIP & INFRASTRUCTURE**
- ASN: 9541 (cyber internet services (pvt) ltd.)
- Organization: Amjad Qasmi
- Network Block: 202.47.32.0/23 (CYBERNET-PK)
- RIR: APNIC
- Registration: Data unavailable
**GEOLOCATION**
- Country: Pakistan (PK)
- Region: Sindh
- City: Karachi
- Coordinates: 24.86°N, 67.00°E
- Geo Sources: 2 (consensus confirmed)
**THREAT INDICATORS**
- Risk Score: 50 (Moderate)
- Blacklist Status: Listed on 2 DNSBL entries out of 8 total lists
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaign Associations: None identified
- Control Plane: Route stability flag set to false; operator score 0.1304 (Minimal)
**NETWORK SERVICES**
- Open Ports: None detected
- DNS Resolution: No PTR records; forward resolution failed
- TLS/Certificates: None
- HTTP: No active web services
- Classification: Firewalled / No Services
**NEIGHBORHOOD ANALYSIS**
- Subnet: 202.47.34.52/24
- Abuse Density: 0 (clean)
- Active Siblings: 0
- Threat Siblings: 0
- Risk Distribution: No high, medium, or risk flags in subnet
**OBSERVATION HISTORY**
Fourteen signal observations were recorded. The most recent activity (2026-07-31) included port scanning, ownership verification, subnet classification, and geolocation checks with threat flags. One signal indicated "has_threats": true with 2 associated threat pulses. No persistent malicious behavior was detected over the observation period.
**RELATIONSHIPS**
Three relationship records exist, all pointing to the CYBERNET-PK network. No additional organizational, hostname, or certificate relationships were identified.
**RECOMMENDED ACTIONS**
Based on the risk profile, the following defensive measures are recommended:
| Platform | Action |
|---|---|
| iptables | `iptables -A INPUT -s 202.47.34.52 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 202.47.34.52 drop` |
| nginx | `deny 202.47.34.52;` |
| pfSense | `202.47.34.52/32` |
| Cloudflare WAF | Block IP with expression `ip.src eq 202.47.34.52` |
| AWS WAF | Add 202.47.34.52/32 to rule group |
**ASSESSMENT**
The IP address presents moderate risk with no active services and a clean neighborhood profile. The 2 DNSBL listings suggest potential reputation issues requiring monitoring. The lack of persistent malicious activity and zero threat siblings indicates this IP may be a dormant or misconfigured endpoint rather than an active threat actor. SOC teams should consider blocking based on organizational policy, particularly given the DNSBL listings and moderate risk classification.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Amjad Qasmi |
| ASN | AS9541 |
| Network Name | CYBERNET-PK |
| CIDR Block | 202.47.32.0/23 |
| RIR | APNIC |
| Country | PK |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-30 23:20:25 UTC |
| Last Seen | 2026-08-01 16:33:29 UTC |
| Profile Built | 2026-07-31 05:01:51 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.