Your IP: 216.73.216.123
π€ Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.
Threat Intelligence Briefing for IP 37.220.132.93/32
Overview
- Risk Score: 25 (Low Risk)
- Ownership: Assigned to ACE Telecom NOC (AS50261) under the Metrolink_static_ip_pool subnet.
- Geolocation: Budapest, Hungary (47.16°N, 19.5°E).
- Network Role: Residential endpoint.
- Threat Indicators: No malicious activity detected (no indicators, campaigns, or blacklist entries).
Historical Observations
- Stability: No significant changes in geolocation or network behavior over the past 30 days.
- DNSSEC Validity: Confirmed.
- DNSBL Listings: 1 out of 8 DNSBL lists (minimal risk).
- Subnet Abuse Density: 1 (low risk, mostly clean).
Relationships
- Linked to Metrolink_static_ip_pool (same network).
- No connections to known malicious entities, organizations, or certificates.
Neighborhood Analysis
- Subnet: 37.220.132.0/24
- Active Neighbors: 0
- Threat Siblings: 1 (potential risk, but no confirmed malicious activity).
Actionable Insights
- No Immediate Threat: The IP is residential, owned by a Hungarian ISP, and shows no direct malicious indicators.
- Monitor DNSBL Flags: The single DNSBL listing may indicate spam or abuse activity; investigate further if the IP exhibits unusual traffic patterns.
- Subnet Health: The subnet has low abuse density, but the single threat sibling warrants periodic rechecks.
Recommendation
- No immediate firewall rules or blocking actions required.
- Maintain monitoring for unexpected behavior or changes in the subnetβs abuse density.
Source: IPDebrief intelligence.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | ACE Telecom NOC |
| ASN | AS50261 |
| Network Name | β |
| CIDR Block | 37.220.128.0/20 |
| RIR | RIPE |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Residential |
| Service Purpose | Web Server |
| Network Tier | End-User β Residential ISP endpoint |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
β Unusual for residential β open services on a home connection may indicate self-hosting, compromise, or misconfigured networking equipment.
π TLS Certificate
An expired certificate for
CN=blkflpr.ddns.net was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.CN=blkflpr.ddns.net
Issued by CN=R12, O=Let's Encrypt, C=US
Self-signed: No
| SANs | blkflpr.ddns.net |
| Valid From | 2026-03-27T05:36:35+00:00 |
| Valid Until | 2026-06-25T05:36:34+00:00 (expired) |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 89 days |
| Serial Number | 0687747CBE7C7A29169C08CF66422E837808 |
| Thumbprint | F3A22203D238B58AA201762B759FDC7DFC80176E |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 27% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 27% | 2 | 2 |
| Overall | 21% | 9 | 13 |
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-14 01:09:53 UTC |
| Last Seen | 2026-06-07 02:04:15 UTC |
| Profile Built | 2026-06-07 02:33:15 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 21 |
π 20 signal types Β· 21 observations collected
This report is generated from 20+ independent intelligence signals including
ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds,
behavioral fingerprinting, and more.
Full dossier details are available via our API.
Full dossier details are available via our API.
βΉοΈ About This Report
All data shown is publicly available network metadata β IP addresses do not reliably identify individuals.
Assessments are probabilistic and should not be used as sole basis for access control decisions.
To report an issue or request data review, contact admin@ipdebrief.com.