# IP Intelligence Briefing: 37.231.41.222
## Executive Summary
IP 37.231.41.222 presents a moderate risk profile (score: 55) with no active threat indicators. The address belongs to the VIVA-Mobile-Users network (ASN 47589) and shows limited service exposure. While DNSBL listings indicate some reputation impact, the subnet remains clean with zero abuse density. No actionable threat indicators were identified.
## Network Ownership and Classification
- Organization: VIVA-Mobile-Users (MNT-AS2306)
- ASN: 47589
- Network Block: 37.231.0.0/17
- RIR: RIPE
- IP Classification: Firewalled / No Services
- Geolocation: London, GB (geo consensus: false; conflicting signals indicate potential misattribution)
## Threat Intelligence Assessment
The IP shows no active malicious indicators:
- Threat Indicators: None detected
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0 active blocks
- DNSBL Status: Listed on 3 of 8 total DNSBL lists (minimal impact)
- Campaign Correlation: No matches to known campaigns
- CertMatches: 0
## Service and Network Exposure
- Open Ports: None detected
- Active Services: None
- HTTP/HTTPS: No web services exposed
- Certificate Data: None
- Reverse DNS: Not configured
- Forward DNS Resolution: Failed
## Neighborhood Analysis
The /24 subnet (37.231.41.222/24) demonstrates clean network characteristics:
- Abuse Density: 0%
- Threat Siblings: 0
- Active Siblings: 0
- Total Siblings: 1
- Inherited Risk: 0
- Classification: Clean
No neighboring IPs were identified as threats.
## Control Plane and Routing
- Route Stability: Unstable (isRouteStable: false)
- Origin ASN: 47589
- BGP Prefix: 37.231.40.0/23
- RPKI State: Not validated
- IRR Consistency: Not assessed
- Route Changes (30 days): 0
## Historical Signal Observations
Analysis of 13 historical observations reveals:
- Ownership Changes: 0
- Threat Persistence Days: 0
- Persistent Malicious Activity: No
- Geo Inconsistencies: Observed signals show conflicting geolocation data (GB vs KW)
- Recent Signals: Ownership, ASN, traceroute, and subnet classification signals observed on 2026-07-26
## Relationship Graph
Limited connectivity graph identified:
- Same Network Relationships: 2 entries (VIVA-Mobile-Users)
- Related Domains/Certificates: None
- Associated Organizations: None beyond network ownership
## Recommended Actions
No immediate blocking recommended. The IP shows moderate risk primarily due to DNSBL listings and route instability, but lacks active threat indicators, malicious behavior, or service exposure.
Monitoring Considerations:
- Track geolocation consistency (GB/KW discrepancy)
- Monitor for service emergence on previously closed ports
- Continue DNSBL reputation tracking
Classification: Low Priority - Monitor
---
*Report generated from IPDebrief intelligence platform data.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | MNT-AS2306 |
| ASN | AS47589 |
| Network Name | VIVA-Mobile-Users |
| CIDR Block | 37.231.0.0/17 |
| RIR | RIPE |
| Country | KW |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS47589 |
| Network Prefix | 37.231.40.0/23 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 23% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 23% | 2 | 4 |
| reputation | 20% | 1 | 3 |
| geolocation | 12% | 2 | 2 |
| Overall | 16% | 10 | 16 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-11 02:18:53 UTC |
| Last Seen | 2026-09-02 11:29:06 UTC |
| Profile Built | 2026-09-02 11:30:19 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 23 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 37.231.41.222
Who owns the IP address 37.231.41.222?
37.231.41.222 is registered to MNT-AS2306. The address falls within the 37.231.0.0/17 network block. Registration is held at RIPE.
Where is 37.231.41.222 located?
Geolocation data places 37.231.41.222 in London, Al Asimah, United Kingdom. The local time zone is Europe/London. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 37.231.41.222 malicious or safe?
37.231.41.222 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.