# IP Intelligence Briefing: 31.77.131.189/32
## Executive Summary
IP address 31.77.131.189 presents a low-risk profile (risk score: 25/100) associated with PLAY2GO hosting infrastructure. No active threat indicators or malicious activity detected. Recommended action: Monitor only.
---
## Network Profile
| Attribute | Value |
|---|---|
| **IP Address** | 31.77.131.189/32 |
| **Risk Score** | 25 (Low Risk) |
| **Country** | Netherlands (NL) |
| **City** | Amsterdam |
| **ASN** | 215439 |
| **Network Block** | 31.77.131.0/24 |
| **Organization** | PLAY2GO (Abuse contact role object) |
| **Abuse Contact** | abuse@play2go.cloud |
| **Service Status** | Firewalled / No Services |
---
## Threat Indicators
- Blacklist Count: 1/8 DNSBL lists flagged
- Known Campaigns: None detected
- Tor Exit Node: False
- Spam Source: False
- Known Attacker: False
- Abuse Confidence Score: Not applicable
- Threat Feeds: No matches
---
## Neighborhood Assessment
The /24 subnet (31.77.131.0/24) contains minimal risk activity:
- Total Siblings: 1 active neighbor identified
- Neighbor IP: 31.77.131.226 (risk score: 25)
- Subnet Abuse Density: 0
- High Risk Neighbors: 0
- Medium Risk Neighbors: 0
---
## Historical Observations
11 observations recorded. Key signals include:
- RIPE registration confirmed
- Network identified as PLAY2GO-CUSTOMERS-NETWORK
- Geolocation data shows Amsterdam, NL (US geolocation observed once, likely outlier)
- DNSSEC validation: Valid
- Ownership changes: 0
- Threat persistence: 0 days
---
## Relationships
No related entities detected (certificates, hostnames, organizations, subnets).
---
## Security Recommendations
Given the low-risk profile and lack of threat indicators:
1. Allow Traffic: No firewall blocks recommended
2. Monitoring: Standard monitoring sufficient
3. Investigation Priority: Low
4. Threat Hunting: Not required at this time
---
## Conclusion
The IP address 31.77.131.189 is a legitimate customer IP within PLAY2GO's hosting infrastructure. The subnet demonstrates minimal abuse activity and no correlation with known threat campaigns. No defensive actions beyond standard monitoring are warranted.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Abuse contact role object |
| ASN | AS215439 |
| Network Name | PLAY2GO-CUSTOMERS-NETWORK |
| CIDR Block | 31.77.131.0/24 |
| RIR | RIPE |
| Country | NL |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 0% (None) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS215439 |
| Network Prefix | 31.77.131.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 20% | 2 | 2 |
| routing | 8% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 23% | 2 | 4 |
| reputation | 26% | 1 | 3 |
| geolocation | 15% | 2 | 2 |
| Overall | 17% | 9 | 13 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-15 22:24:02 UTC |
| Last Seen | 2026-09-29 03:07:53 UTC |
| Profile Built | 2026-09-28 02:53:43 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 29 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 31.77.131.189
Who owns the IP address 31.77.131.189?
31.77.131.189 is registered to Abuse contact role object. The address falls within the 31.77.131.0/24 network block. Registration is held at RIPE.
Where is 31.77.131.189 located?
Geolocation data places 31.77.131.189 in Amsterdam, 07, Netherlands. The local time zone is Europe/Amsterdam. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 31.77.131.189 malicious or safe?
31.77.131.189 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 31.77.131.189?
Responsive ports observed on 31.77.131.189 include 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.