# IP INTELLIGENCE BRIEFING
Target: 36.82.125.37/32
Date: 2026-07-30
Classification: MODERATE RISK โ DEFENSIVE MONITORING RECOMMENDED
---
## EXECUTIVE SUMMARY
IP 36.82.125.37 is a residential/corporate endpoint located in Surabaya, East Java, Indonesia (ASN 7713, Febrian Setiadi). The IP presents a moderate risk score of 50 with a clean subnet classification and no active threat indicators. However, the IP is listed on 2 of 8 DNSBLs and exhibits unstable routing characteristics. The address shows no open ports or active services, and the surrounding /24 subnet demonstrates zero abuse density. SOC analysts should monitor for behavioral anomalies while maintaining standard defensive posture.
---
## OWNERSHIP & INFRASTRUCTURE
| Attribute | Value |
|---|---|
| **ASN** | 7713 (Febrian Setiadi) |
| **Organization** | Febrian Setiadi |
| **Network** | TLKM_BB_SERVICE_36_82_DIVRE5-6 (36.82.112.0/20) |
| **Location** | Surabaya, East Java, Indonesia |
| **CIDR Block** | 36.82.112.0/20 |
| **RIR** | APNIC |
Control Plane: Routing status flagged as unstable (isRouteStable: false). The IP is listed on 2 DNSBLs out of 8 total lists checked. Operator score: 0.1304 (minimal threat).
---
## THREAT INDICATORS
Current Risk Assessment:
- Overall Risk Score: 50/100 (Moderate)
- Abuse Confidence Score: Not available
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
- Blacklist Count: 0 (active threat feeds)
- Known Campaigns: None detected
Threat Persistence:
- Threat observation count: 0
- Persistently malicious: False
- Campaign likelihood: Not detected
- Certificate matches: 0
---
## NETWORK BEHAVIOR & SERVICES
Service Exposure:
- Open Ports: None detected
- HTTP Services: No active HTTP endpoints
- TLS Certificates: None
- DNS Resolution: No PTR hostnames, no forward resolution
- Email Reputation: No email authentication records (SPF/DMARC)
Network Classification:
- Provider: Not identified
- Infrastructure Type: Not identified
- Cloud/CDN/VPN/Proxy: All negative
- Mobile Carrier: Not identified
- Residential: Not confirmed
---
## SUBNET ANALYSIS
Neighborhood Profile (36.82.125.37/24):
- Abuse Density: 0.0
- Classification: Clean
- Inherited Risk: 0
- Total Siblings: 1
- Active/Threat Siblings: 0
- Neighbor Risk Distribution: No high/medium/low risk neighbors identified
Assessment: The surrounding /24 subnet demonstrates no abuse activity, suggesting this IP is an isolated endpoint rather than part of a coordinated infrastructure.
---
## OBSERVATION HISTORY
Historical Signals (13 observations):
- Most recent activity: 2026-07-30
- Geolocation: Consistent Indonesia (ID) attribution with confidence 0.30โ0.85
- Network Classification: Clean classification with confidence 0.40
- Ownership: 0 ownership changes detected
- Threat Persistence: 0 threat observation days
Temporal Analysis: No evidence of escalating threat behavior. The IP has remained stable in classification with no persistent malicious activity detected over the observation window.
---
## RELATIONSHIP GRAPH
Identified Relationships (5 entries):
- All relationships map to the same network: TLKM_BB_SERVICE_36_82_DIVRE5-6
- No external hostname, certificate, or organizational relationships beyond the assigned network block
- No correlated IPs detected
---
## DEFENSIVE RECOMMENDATIONS
Risk-Based Actions:
Given the moderate risk score of 50 combined with DNSBL listings and routing instability, the following controls are recommended:
Firewall Rules:
- iptables: `iptables -A INPUT -s 36.82.125.37 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 36.82.125.37 drop`
- nginx: `deny 36.82.125.37;`
- pfSense: `36.82.125.37/32`
- Cloudflare WAF: Block with expression `ip.src eq 36.82.125.37`
- AWS WAF: `Addresses: ["36.82.125.37/32"]`
SOC Monitoring Priorities:
1. Monitor for DNSBL list updates (currently 2 of 8 lists)
2. Watch for emergence of open ports or service banners
3. Track routing stability changes
4. Correlate with any abuse reports from the Febrian Setiadi organization
5. Review for any changes in geolocation attribution
---
## FINAL ASSESSMENT
IP 36.82.125.37 is classified as MODERATE RISK (50/100) with no active threat indicators. The subnet shows clean classification with zero abuse density. While no immediate threat activity is present, the DNSBL listings and routing instability warrant continued monitoring. Standard defensive blocking is recommended pending further behavioral analysis.
Classification: MODERATE RISK โ DEFENSIVE MONITORING
Action Level: BLOCK (with review)
Confidence: HIGH
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Febrian Setiadi |
| ASN | AS7713 |
| Network Name | TLKM_BB_SERVICE_36_82_DIVRE5-6 |
| CIDR Block | 36.82.112.0/20 |
| RIR | APNIC |
| Country | ID |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-29 10:34:13 UTC |
| Last Seen | 2026-07-30 23:20:39 UTC |
| Profile Built | 2026-07-30 21:43:49 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 16 |
Full dossier details are available via our API.