# IP INTELLIGENCE BRIEFING
Target IP: 39.34.135.22/32
Report Date: 2026-07-24
Classification: Moderate Risk
---
## EXECUTIVE SUMMARY
IP 39.34.135.22 presents a moderate risk profile (Score: 40) with conflicting geolocation data and evidence of blacklist listing activity. The IP is attributed to organization "Munir Ahmed" under ASN 132165 (PTCLBB-PK) within the APNIC RIR. No active services were detected during scanning.
---
## OWNERSHIP & REGISTRATION
- ASN: 132165
- Organization: Munir Ahmed
- Netname: PTCLBB-PK
- RIR: APNIC
- CIDR Block: 39.32.0.0/11
- Abuse Contact: csirt@ptcl.net (available via RDAP)
---
## GEOLOCATION ANALYSIS
Significant geolocation discrepancy detected between data sources:
- Profile Data: United States (New York)
- History Data: Pakistan (Islamabad)
- Geo Consensus: FALSE
- Geo Plausible: FALSE
This inconsistency warrants investigation into routing anomalies or potential spoofing.
---
## THREAT INDICATORS
- Risk Score: 40 (Moderate)
- Blacklist Status: Listed on 2 of 8 total DNSBL lists
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Threat Persistence Days: 0
- Max Severity from Lists: High
---
## NETWORK OBSERVATIONS
- Services Detected: None (Firewalled / No Services)
- Open Ports: None observed
- DNS Records: No PTR hostnames, no forward resolution
- Email Authentication: No SPF/DMARC records
- HTTP/HTTPS: No web services detected
---
## CONTROL PLANE DATA
- BGP Prefix: 39.34.135.0/24
- Route Stability: UNSTABLE
- Route Changes (30d): 0
- RPKI State: Not reported
- DNSSEC: Valid
- Honeypot Hits: 0
---
## NEIGHBORHOOD ANALYSIS
Subnet: 39.34.135.0/24
Total Siblings: 3
Abuse Density: 0%
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 39.34.135.4 | 0 | 50 |
| 39.34.135.53 | 15 | 50 |
| 39.34.135.233 | 0 | 50 |
*Note: 39.34.135.53 shows elevated risk (Score: 15) and should be monitored.*
---
## OBSERVATION HISTORY
14 total observations recorded. Recent activity includes:
- Ownership and geolocation data changes
- Blacklist listings with high severity
- Multiple signal type variations indicating dynamic reputation changes
---
## RECOMMENDED ACTIONS
Immediate Mitigation
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 39.34.135.22 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 39.34.135.22 drop` |
| nginx | `deny 39.34.135.22;` |
| pfSense | `39.34.135.22/32` |
| Cloudflare WAF | Block IP with expression: `ip.src eq 39.34.135.22` |
| AWS WAF | Add address 39.34.135.22/32 to rule |
Additional Recommendations
1. Monitor 39.34.135.53 — Shows elevated risk score (15) within same subnet
2. Investigate geolocation discrepancy — Validate actual location against routing data
3. Review DNSBL listings — Identify specific blacklist sources and removal procedures
---
## INTELLIGENCE SUMMARY
This IP exhibits moderate risk characteristics with no active service exposure. The geolocation conflict between US and Pakistan data, combined with blacklist listings, suggests potential misconfiguration or reputation issues. No evidence of active malicious campaigns or known attacker association was detected. Block recommendation provided for defensive hardening; continue monitoring subnet 39.34.135.0/24 for related activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Munir Ahmed |
| ASN | AS132165 |
| Network Name | PTCLBB-PK |
| CIDR Block | 39.32.0.0/11 |
| RIR | APNIC |
| Country | PK |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS132165 |
| Network Prefix | 39.34.135.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 4% | 1 | 1 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-06 12:09:11 UTC |
| Last Seen | 2026-08-30 08:02:11 UTC |
| Profile Built | 2026-08-29 05:47:50 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 18 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 39.34.135.22
Who owns the IP address 39.34.135.22?
39.34.135.22 is registered to Munir Ahmed. The address falls within the 39.32.0.0/11 network block. Registration is held at APNIC.
Where is 39.34.135.22 located?
Geolocation data places 39.34.135.22 in New York, US-NY, United States. The local time zone is America/New_York. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 39.34.135.22 malicious or safe?
39.34.135.22 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.