# IP Intelligence Briefing: 37.203.49.132/32
## Executive Summary
IP 37.203.49.132 registered as a moderate-risk address (55/100) located in Piltown, Leinster, Ireland, associated with ASN 51173 (MNT-NIALL). The address exhibits firewalled characteristics with no active services observed. Neighboring subnet analysis indicates elevated abuse density (33.3%), with three high-risk sibling addresses (risk score 80) within the same /24 block.
## Technical Profile
- Geolocation: Ireland (IE), Piltown, Leinster. Coordinates: 53.14°N, -7.69°W. Geographic validation confirmed plausible (945.9 km from probe origin; average RTT: 107.2 ms).
- Network Infrastructure: ASN 51173, RIR RIPE. Control plane prefix: 37.203.49.0/24. Route stability flagged as unstable.
- DNS/Email: No PTR records, no forward resolution, no hosted domains. No SPF/DMARC records present. Listed on 3 of 8 DNSBL checks.
- Services: None observed. Classification: "Firewalled / No Services." No TLS certificates, open ports, or HTTP activity detected.
- Network Role: Not identified as cloud, CDN, proxy, VPN, Tor, or hosting infrastructure.
## Threat Indicators
- Risk Score: 55/100 (Moderate Risk)
- Abuse Confidence: Not explicitly scored
- Known Campaigns: None identified
- Blacklist Status: Listed on 3 DNSBL feeds
- Tor/Proxy/VPN: Negative indicators
- Known Attacker: No matches in threat feeds
## Neighborhood Context (37.203.49.0/24)
The /24 subnet demonstrates mixed classification with abuse density of 0.333. Nine sibling addresses analyzed:
- High Risk (80/100): 37.203.49.113, 37.203.49.122, 37.203.49.127
- Medium Risk (55/100): 37.203.49.64, 37.203.49.102, 37.203.49.121, 37.203.49.126
- Low Risk: 37.203.49.25 (0), 37.203.49.129 (30)
## Historical Observations
Sixteen total observations recorded. Most recent signals from June 2026 show consistent geolocation validation and subnet-level abuse density patterns. One threat observation event logged with 1 day of threat persistence. Ownership stability maintained with zero ownership changes.
## Network Relationships
All 11 relationship records indicate association with "IE-PBB-ALPHAWAVE-COMMUNICATIONS," indicating the IP and associated network infrastructure share common routing infrastructure.
## Recommended Actions
1. Immediate: Increase logging verbosity and review recent activity from this IP source.
2. Firewall Rules:
- `iptables`: `iptables -A INPUT -s 37.203.49.132 -j DROP`
- `nftables`: `nft add rule inet filter input ip saddr 37.203.49.132 drop`
- `nginx`: `deny 37.203.49.132;`
- `pfsense`: `37.203.49.132/32`
- `Cloudflare WAF`: Block with filter expression `ip.src eq 37.203.49.132`
- `AWS WAF`: Add to whitelist block list with CIDR `37.203.49.132/32`
## Assessment
The IP presents moderate risk primarily driven by subnet-level abuse density and DNSBL listings. No direct attack indicators or malicious campaign associations detected. However, the presence of three high-risk sibling addresses within the same /24 block suggests potential infrastructure compromise or shared hosting abuse. Monitor for lateral activity patterns from neighboring addresses (37.203.49.113, 37.203.49.122, 37.203.49.127).
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | MNT-NIALL |
| ASN | AS51173 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 24% | 2 | 3 |
| reputation | 19% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 20% | 9 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-08 17:18:02 UTC |
| Last Seen | 2026-06-26 18:11:16 UTC |
| Profile Built | 2026-06-25 09:47:21 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.