# IP Intelligence Briefing: 39.35.202.82/32
## Executive Summary
IP address 39.35.202.82 presents a low risk profile with a risk score of 15 out of 100. The IP is classified as firewalled with no open services detected. No active threat indicators were identified during the assessment period.
## Ownership and Registration
| Attribute | Value |
|---|---|
| ASN | 17557 |
| Organization | Munir Ahmed |
| Netname | PTCLBB-PK |
| RIR | APNIC |
| CIDR Block | 39.32.0.0/11 |
| Abuse Contact | csirt@ptcl.net |
## Network Classification
- Service Purpose: Firewalled / No Services
- Open Ports: None detected
- Infrastructure Type: Residential/Hosting classification not confirmed
- Cloud/CDN/VPN: Not applicable
- Tor/Proxy: Not detected
## Geographic Data
- Primary Location: Marseille, France (FR)
- Registered ASN Origin: Pakistan (PK)
- Geographic Consensus: False (multiple geo sources with conflicting data)
- Timezone: Europe/Paris
Note: Geographic data shows inconsistency between ASN registration (Pakistan) and geolocation probes (France). This may indicate route manipulation or misconfigured routing tables.
## Threat Indicators
- Abuse Confidence Score: Not applicable
- Blacklist Count: 0 (DNSBL lists: 1 out of 8)
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Known Campaigns: None detected
- Campaign Likelihood: Not assessed
## Observation History (13 signals)
Recent signals indicate:
- Ownership data consistent across observations
- Subnet classified as "clean" with 0 abuse density
- One DNSBL listing observed (medium severity)
- No persistent malicious activity detected
- No ownership changes recorded
## Neighborhood Analysis (/24 Subnet)
| Metric | Value |
|---|---|
| Subnet | 39.35.202.82/24 |
| Abuse Density | 0 |
| Classification | Clean |
| Total Siblings | 2 |
| Threat Siblings | 0 |
Neighbor IP: 39.35.202.153 (Risk Score: 0, Authority Score: 50)
The immediate subnet demonstrates minimal risk with one neighbor showing low-risk characteristics. No threat-sibling IPs were identified.
## Control Plane Data
- BGP Prefix: 39.35.192.0/19
- Route Stability: False
- RPKI State: Not assessed
- Route Changes (30d): 0
- DNSSEC: Valid
- Hop Count: 12 (2 timed out)
## Recommended Actions
Based on the low-risk profile and lack of active threats:
1. Allow traffic with standard monitoring
2. No immediate blocking recommended
3. Monitor geographic anomalies - investigate routing discrepancy between Pakistan registration and France geolocation
4. Track DNSBL listing - review the single DNSBL listing for context
## SOC Analyst Notes
The IP address 39.35.202.82 demonstrates characteristics of a legitimate, non-malicious endpoint with firewalled services. The geographic inconsistency warrants periodic review but does not indicate active threat behavior. No immediate defensive actions are required. Standard network monitoring procedures apply.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Munir Ahmed |
| ASN | AS17557 |
| Network Name | PTCLBB-PK |
| CIDR Block | 39.32.0.0/11 |
| RIR | APNIC |
| Country | PK |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS17557 |
| Network Prefix | 39.35.192.0/19 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 4% | 1 | 1 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-15 04:06:17 UTC |
| Last Seen | 2026-08-31 16:28:33 UTC |
| Profile Built | 2026-08-31 16:35:36 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 22 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 39.35.202.82
Who owns the IP address 39.35.202.82?
39.35.202.82 is registered to Munir Ahmed. The address falls within the 39.32.0.0/11 network block. Registration is held at APNIC.
Where is 39.35.202.82 located?
Geolocation data places 39.35.202.82 in Marseille, Sindh, France. The local time zone is Europe/Paris. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 39.35.202.82 malicious or safe?
39.35.202.82 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.