## IP Intelligence Briefing: 37.221.135.232/32
Classification: Moderate Risk (Score: 40/100)
Status: Firewalled / No Services Detected
---
Ownership & Network Profile
Organization: Radio Service Ltd.
ASN: 62384
Network: 37.221.128.0/20
Location: Lviv, Ukraine (UA)
RIR: RIPE
The IP belongs to Radio Service Ltd., a Ukrainian organization registered with RIPE. The address is part of a larger /20 block and is currently in a firewalled state with no active services detected on the endpoint.
---
Threat Assessment
Current Risk Indicators:
- DNSBL Listed: 2/8 lists (listed on Spamhaus and additional feeds)
- Abuse Confidence Score: Not calculated (no active services)
- Threat Campaigns: None detected
- Known Attacker: False
- Tor Exit Node: False
- Proxy/VPN: False
Observed Signals (Historical):
- Recent observation (2026-06-26): IP flagged with threats and blacklist listings in multiple sources
- Previous observation (2026-06-06): Subnet 37.221.135.232/24 classified as "mixed" with 40% abuse density
- Geolocation signals show associations with Ukrainian academic/research networks
---
Neighborhood Analysis (Subnet: 37.221.135.0/24)
Abuse Density: 0.4 (Moderate)
Classification: Mixed
Total Siblings: 10
Threat Siblings: 4
High-Risk Neighbors Identified:
- 37.221.135.96: Risk Score 80 (Highest threat in subnet)
- 37.221.135.109: Risk Score 70
- 37.221.135.48, 37.221.135.63: Risk Score 55
The /24 subnet demonstrates elevated malicious activity, with four IPs flagged as threats and one high-risk neighbor (37.221.135.96) showing score of 80.
---
Service & Network Role
Infrastructure Type: Firewalled / No Services
Open Ports: None detected
DNS Records: None hosted
Email Authentication: Not configured
The endpoint shows no active services, suggesting it may be:
- A dormant/reserved IP
- Heavily firewalled infrastructure
- Recently decommissioned
---
Recommended Actions
Immediate Mitigation: Block traffic from this IP at network perimeter
Firewall Rules:
- iptables: `iptables -A INPUT -s 37.221.135.232 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 37.221.135.232 drop`
- nginx: `deny 37.221.135.232;`
- Cloudflare WAF: Block expression `ip.src eq 37.221.135.232`
- AWS WAF: Add address `37.221.135.232/32` with description "IPDebrief risk 40"
---
Intelligence Summary
This Ukrainian IP address (37.221.135.232) presents a moderate risk profile with historical blacklist activity and operates within a subnet showing elevated abuse density. While the endpoint itself shows no active services, the surrounding neighborhood contains multiple high-risk neighbors, including 37.221.135.96 (risk score 80). The IP should be blocked at the network perimeter as a precautionary measure, particularly given its presence on multiple DNSBLs and association with Ukrainian research/academic network infrastructure that has been observed in threat contexts.
Priority: Medium
Action Required: Block at perimeter firewall
Monitor: Watch for service activation on this address or related subnet activity
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Radio Service Ltd. |
| ASN | AS62384 |
| Network Name | RADIOSERVICE-201712 |
| CIDR Block | 37.221.128.0/20 |
| RIR | RIPE |
| Country | UA |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 19% | 2 | 2 |
| Overall | 19% | 10 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-11 21:11:06 UTC |
| Last Seen | 2026-06-26 12:37:49 UTC |
| Profile Built | 2026-06-26 12:44:38 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 20 |
Full dossier details are available via our API.