# IP Intelligence Briefing: 213.137.138.209/32
Date: 2026-07-30
Classification: Moderate Risk
Risk Score: 50/100
## Executive Summary
IP 213.137.138.209 is a firewalled infrastructure address belonging to Belgacom ICS Engineering and Operations (ASN 6774). The IP shows moderate risk (score 50) with no active malicious indicators. No services are exposed, and the subnet exhibits minimal abuse density.
## Ownership and Geolocation
- Organization: Belgacom ICS Engineering and Operations
- Network: BICS-SIM (213.137.138.0/24)
- ASN: 6774 (Belgacom)
- Location: Brussels, Belgium (50.5°N, 4.47°E)
- RIR: RIPE
- Registration Date: Not available in current data
## Network Role and Service Status
- Infrastructure Type: Firewalled / No Services
- Open Ports: None detected
- TLS Certificates: None
- Hosted Domains: 0
- Email Reputation: No SPF/DMARC records detected
- Network Classification: Provider network segment
## Threat Indicators
- Blacklist Status: Listed on 2 of 8 DNSBLs
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaign Association: None detected
- Abuse Confidence Score: Not available
## Neighborhood Analysis
Subnet 213.137.138.0/24 analysis reveals:
- Total Siblings: 4
- Abuse Density: 0 (low)
- Risk Distribution: 0 high, 0 medium, 3 low risk IPs
- Notable Neighbors:
- 213.137.138.82 (Risk: 25)
- 213.137.138.157 (No score)
- 213.137.138.213 (Risk: 0)
- 213.137.138.225 (Risk: 25)
The subnet exhibits minimal threat activity with no high-risk siblings.
## Observation History
11 observations recorded over the monitoring period:
- Most Recent: 2026-07-30 22:42:50 UTC
- Geolocation Consistency: Belgium (BE) consistently reported across multiple signal sources
- Operator Score: Minimal (0.1304)
- Threat Persistence: 0 days (no persistent malicious behavior detected)
- Ownership Changes: 0
- Threat Observation Count: 0
## Relationships
Four relationship records identified, all mapping to:
- Type: Same Network
- Target: BICS-SIM (213.137.138.0/24)
No organizational, hostname, or certificate relationships detected.
## Recommended Security Actions
Based on risk profile (score 50), consider the following firewall rules:
iptables:
```
iptables -A INPUT -s 213.137.138.209 -j DROP
```
nftables:
```
nft add rule inet filter input ip saddr 213.137.138.209 drop
```
Cloudflare WAF:
```json
{
"description": "Block 213.137.138.209 โ IPDebrief risk score 50",
"action": "block",
"filter": {
"expression": "ip.src eq 213.137.138.209"
}
}
```
AWS WAF:
```json
{
"Addresses": ["213.137.138.209/32"],
"Description": "IPDebrief risk 50"
}
```
## Analyst Notes
- Action Priority: LOW to MEDIUM
- Risk Context: IP is firewalled with no exposed services. Risk score 50 reflects DNSBL listings rather than active threat indicators.
- Recommended Approach: Review against organizational threat context before implementing blocking. Consider subnet-level analysis (213.137.138.0/24) before taking action on individual hosts.
- Monitoring: Continue passive observation. No immediate threat indicators warrant aggressive blocking without additional context.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Belgacom ICS Engineering and Operations |
| ASN | AS6774 |
| Network Name | BICS-SIM |
| CIDR Block | 213.137.138.0/24 |
| RIR | RIPE |
| Country | BE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 5 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-29 16:41:56 UTC |
| Last Seen | 2026-07-31 07:31:33 UTC |
| Profile Built | 2026-07-30 22:51:44 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.