## IP Intelligence Briefing: 37.231.34.249/32
Classification: Moderate Risk Infrastructure IP
---
Executive Summary
IP address 37.231.34.249 is a moderate-risk infrastructure endpoint associated with Kuwaiti mobile network provider VIVA-Mobile-Users (ASN 47589). The IP shows no active threat indicators, no known malware campaigns, and no open services. The subnet exhibits clean abuse density with one neighboring IP showing elevated risk. No defensive blocking is recommended without additional corroborating signals.
---
Technical Profile
Ownership & Attribution:
- ASN: 47589 (VIVA-Mobile-Users)
- Organization: MNT-AS2306
- Country/Region: Kuwait (KW) โ Al Asimah, Kuwait City
- CIDR Block: 37.231.0.0/17 (RIPE NCC)
- Registration: RIR-registered under Kuwaiti telecom infrastructure
Network Classification:
- Risk Score: 40/100 (Moderate Risk)
- Infrastructure Type: Mobile Network Infrastructure
- Services: Firewalled / No Services Detected
- Open Ports: None
- DNS Resolution: None (no PTR hostnames)
- Blacklist Status: 0 blacklist hits
Geolocation Validation:
- Coordinates: 29.3706°N, 47.9697°E
- Distance: 4,230.2 km from validation origin
- ICMP Validation: Blocked (unable to validate)
- Minimum Possible RTT: 84.6 ms
---
Threat Indicators
Current Threat Status:
- No known attacker indicators
- No spam source activity
- No Tor exit node association
- No proxy/VPN/proxy service characteristics
- No hosting services detected
- No mobile carrier services (despite VIVA association)
Control Plane:
- BGP Prefix: 37.231.34.0/23
- Route Stability: False
- DNSSEC Valid: Yes
- DNSBL Listed: 2 of 8 total lists
- Operator Score: 0.1304 (Minimal)
---
Historical Analysis
Observation Timeline: 13 total observations
- Ownership Stability: No ownership changes detected
- Threat Persistence: 0 days observed
- Classification Trend: Consistent "clean" classification
- Inherited Risk: 0 (no subnet-level risk inheritance)
Temporal Signals:
- Recent subnet classification: Clean (abuse density: 0)
- No persistent malicious activity patterns
- No threat persistence indicators
---
Network Relationships
Associations:
- 3 relationship entries identified
- All mapped to network: VIVA-Mobile-Users
- No external organization, hostname, or certificate associations detected
---
Neighborhood Analysis
Subnet: 37.231.34.249/24
- Total Siblings: 2
- Active Siblings: 1
- Threat Siblings: 0
- Abuse Density: 0 (clean)
- Classification: Clean
Notable Neighbor:
- IP 37.231.34.31: Risk score 55 (Medium Risk), Authority Score 50
---
Recommended Actions
Current Recommendation: Monitor / Low-Priority Block
The IP presents a moderate risk profile typical of mobile network infrastructure. Blocking is not recommended without additional threat correlation. If defensive measures are required, apply the following rules:
Firewall Rules:
- iptables: `iptables -A INPUT -s 37.231.34.249 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 37.231.34.249 drop`
- Cloudflare WAF: Block with expression `ip.src eq 37.231.34.249`
- AWS WAF: Block CIDR `37.231.34.249/32`
---
Intel Summary
This IP is part of Kuwaiti telecom infrastructure (VIVA-Mobile-Users). While classified as moderate risk (40), the absence of active threat indicators, open services, and malicious campaigns suggests this is legitimate network infrastructure. The elevated risk score likely reflects the inherent risk of mobile network ranges rather than malicious activity. Monitor for changes in service patterns or threat indicators that may warrant defensive blocking.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | MNT-AS2306 |
| ASN | AS47589 |
| Network Name | VIVA-Mobile-Users |
| CIDR Block | 37.231.0.0/17 |
| RIR | RIPE |
| Country | KW |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-22 07:16:12 UTC |
| Last Seen | 2026-07-29 12:51:29 UTC |
| Profile Built | 2026-07-29 13:03:55 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.