# IP Intelligence Briefing: 37.245.227.18
## Executive Summary
IP address 37.245.227.18 is classified as a low-risk network asset with a risk score of 0. The address belongs to ETISALAT-MNT's GPRS-EMIRNET infrastructure in Ajman, UAE. Current analysis indicates no active threat indicators, no open services, and a clean reputation profile.
## Ownership & Network Classification
- ASN: 5384 (ETISALAT-MNT)
- Organization: GPRS-EMIRNET
- CIDR Block: 37.245.192.0/18
- RIR: RIPE
- Network Role: Firewall / No Services
- Classification: Not a CDN, VPN, proxy, hosting, cloud, mobile, or residential IP
## Geolocation
- Country: United Arab Emirates (AE)
- Region: Ajman
- Coordinates: 23.42°N, 53.85°E
- Timezone: Asia/Dubai
- Geo Confidence: Consensus validated (geoPlausible flag inconsistent)
## Threat Assessment
- Risk Score: 0 (Low Risk)
- Abuse Confidence: Not applicable
- Blacklist Status: 0 entries
- Known Campaigns: None detected
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
## Network Services & DNS
- Open Ports: None detected
- TLS Certificates: None
- Forward Resolution: 0 hostnames
- PTR Records: None
- Email Authentication: SPF, DMARC, and TXT records absent
- DNSSEC: Validated
- Service Purpose: Firewalled / No Services
## Control Plane Analysis
- Route Stability: Unstable
- RPKI State: Not verified
- IRR Consistency: Not verified
- DNSBL Listing: 0 lists (8 total DNSBL references)
- Operator Score: 0.1304 (Minimal)
- Delegation Age: Not available
## Neighborhood Analysis (37.245.227.0/24)
- Abuse Density: 0.5
- Subnet Classification: Mostly clean
- Total Siblings: 2
- Active Siblings: 1
- Threat Siblings: 1
- Risk Distribution: 1 low-risk, 0 medium, 0 high
- Notable Neighbor: 37.245.227.24 (Risk Score: 25, Authority Score: 50)
## Observation History
14 observations recorded (most recent: 2026-07-29). Historical signals indicate:
- Consistent ownership classification with 0 ownership changes
- No persistent malicious activity detected
- Stable geographic attribution to UAE
- Neighborhood risk assessment shows minimal inherited threat
- Operator classification remains minimal
## Relationships
- Same Network: GPRS-EMIRNET (2 relationships detected)
- No additional external entity relationships
## Recommended Actions
- Action: Monitor
- Firewall Rules: None required
- Rationale: No actionable threats detected. IP is properly classified as firewalled with no open services or threat indicators.
## Intelligence Narrative
IP 37.245.227.18 is an infrastructure address within the GPRS-EMIRNET network block (37.245.192.0/18) operated by ETISALAT-MNT in Ajman, UAE. The address shows no evidence of malicious activity, with a risk score of 0 and zero blacklist entries. Network reconnaissance reveals no open ports, TLS certificates, or HTTP servicesβthe IP is configured as a firewall with no active services.
The subnet 37.245.227.0/24 demonstrates low abuse density (0.5) with one neighbor (37.245.227.24) showing elevated but not critical risk scores (25). Historical analysis confirms consistent, non-malicious behavior with no ownership changes or threat persistence.
Threat Level: LOW
SOC Recommendation: Monitor. No immediate blocking or alerting required. No firewall rules necessary at this time.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | ETISALAT-MNT |
| ASN | AS5384 |
| Network Name | GPRS-EMIRNET |
| CIDR Block | 37.245.192.0/18 |
| RIR | RIPE |
| Country | AE |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-23 01:41:34 UTC |
| Last Seen | 2026-07-29 16:26:21 UTC |
| Profile Built | 2026-07-29 16:40:22 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 16 |
Full dossier details are available via our API.