# IP Intelligence Briefing: 39.35.228.145
Classification: Moderate Risk | Risk Score: 40
Date of Assessment: July 30, 2026
Report Type: Single-IP Threat Intelligence
---
## Executive Summary
IP 39.35.228.145 is classified as Moderate Risk with a risk score of 40. The address is firewalled with no active services detected and no direct threat indicators. However, the IP appears on 2 of 8 DNSBL feeds and exhibits geographic inconsistencies in attribution data.
---
## Network Attribution
- ASN: 17557
- BGP Prefix: 39.35.224.0/20
- RIR: APNIC
- Organization: Munir Ahmed
- Abuse Contact: csirt@ptcl.net
- Geolocation: Pakistan (PK)
- City: Karachi (MaxMind), Islamabad (RIR) โ *inconsistent*
---
## Risk Profile
| Metric | Value | Assessment |
|---|---|---|
| Risk Score | 40 | Moderate Risk |
| Provider Score | 0 | None |
| Authority Score | 0 | None |
| DNSBL Listings | 2/8 | Present |
| Open Ports | None | Firewalled |
| Known Threats | None | Clean |
| Campaigns | None | Not Associated |
---
## Observations
Nine signal observations were recorded. Most recent data (July 30, 2026) confirms:
- Ownership consistently attributed to "Munir Ahmed"
- APNIC RIR registration confirmed
- Operator score: 0.1304 (Minimal)
- GeoPlausible flag: false (geolocation inconsistencies detected)
The IP shows no threat persistence patterns and is not flagged as persistently malicious.
---
## Neighborhood Analysis
The /24 subnet (39.35.228.0/24) contains 3 neighbor IPs:
- 39.35.228.10 โ Risk: 0, Authority: 50
- 39.35.228.50 โ Risk: 0, Authority: 50
- 39.35.228.251 โ Risk: 40, Authority: 50 (same risk level as target)
Subnet abuse density: 0. Only one neighbor (39.35.228.251) exhibits comparable risk characteristics.
---
## Relationships
No relationships detected to related subnets, hostnames, organizations, or certificates.
---
## Recommended Actions
Despite the moderate risk classification, no specific threat-based recommendations were generated. Standard defensive measures include:
```bash
# iptables
iptables -A INPUT -s 39.35.228.145 -j DROP
# nftables
nft add rule inet filter input ip saddr 39.35.228.145 drop
# pfSense
block 39.35.228.145/32
```
The IP should be blocked on perimeter devices due to DNSBL presence and moderate risk score.
---
## Intelligence Assessment
The IP address is not actively malicious. The moderate risk score appears to be driven by DNSBL listings and geographic data inconsistencies rather than active threat activity. The address is firewalled with no open services, reducing immediate exploitability. Monitor for changes in threat indicators or neighborhood activity, particularly regarding neighbor 39.35.228.251 which shares similar risk characteristics.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Munir Ahmed |
| ASN | AS17557 |
| Network Name | PTCLBB-PK |
| CIDR Block | 39.32.0.0/11 |
| RIR | APNIC |
| Country | PK |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-27 21:54:34 UTC |
| Last Seen | 2026-07-30 14:36:52 UTC |
| Profile Built | 2026-07-30 14:50:42 UTC |
| Data Freshness | Live |
| Signal Types | 15 |
| Total Observations | 15 |
Full dossier details are available via our API.