# IP Intelligence Briefing: 39.35.233.203/32
Classification: Low Risk / Clean
Date: Current analysis cycle
Target: 39.35.233.203
---
## Executive Summary
IP 39.35.233.203 presents a low-risk profile with no active threat indicators. The address belongs to PTCLBB-PK (Pakistan Telecommunications Company Limited backbone) under ASN 17557, registered to Munir Ahmed. The IP is currently firewalled with no open services or active threat campaigns. No blacklist listings or abuse reports detected.
---
## Technical Profile
Ownership & Registration:
- ASN: 17557 (PTCLBB-PK)
- Organization: Munir Ahmed
- CIDR Block: 39.32.0.0/11
- RIR: APNIC
- Abuse Contact: csirt@ptcl.net (available via RDAP)
Geolocation:
- Country: Pakistan (PK)
- Region: Sindh
- City: Karachi
- Coordinates: 24.86°N, 67.0°E
Network Services:
- Status: Firewalled / No Services
- Open Ports: None detected
- TLS/Certificate: None
- DNS: No PTR records, no forward resolution
- HTTP: Not accessible
---
## Threat Intelligence Indicators
Current Risk Score: 0.0 (Low Risk)
- Provider Score: 0
- Authority Score: 0
- Stability Score: 0
- Abuse Confidence: N/A
Threat Indicators:
- Blacklist Count: 0
- Is Tor Exit Node: No
- Is Known Attacker: No
- Is Spam Source: No
- Active Threat Campaigns: None
- Threat Feeds: None
---
## Network Neighborhood Analysis
Subnet: 39.35.233.203/24
- Abuse Density: 0.0 (Clean)
- Classification: Clean
- Total Siblings: 2
- Active Siblings: 1
- Threat Siblings: 0
Neighbor Observation:
- 39.35.233.180: Risk Score 25, Authority Score 50
- *Note: Single sibling IP shows elevated metrics, but subnet overall classified as clean*
---
## Observation History
Total Observations: 11
Most Recent Signal: 2026-07-30T10:48:02 UTC
Historical Trends:
- Ownership Changes: 0 (Stable)
- Threat Persistence Days: 0
- Threat Observation Count: 0
- Persistently Malicious: No
Signal Consistency:
- Ownership information (Munir Ahmed, PTCLBB-PK) remains consistent across observations
- Geolocation signals show consistent Pakistan assignment
- Routing and control plane data stable
---
## Relationship Graph
Direct Relationships: 2
- PTCLBB-PK (Same Network) โ Appears twice in relationship graph, indicating network-level association
No external relationships to hostnames, organizations, or certificates detected beyond network-level associations.
---
## Recommended Security Actions
Action Status: No Recommended Actions
- Risk Score: 0.0
- Firewall Rules: Not required
- WAF Rules: Not required
Note: This IP presents no immediate threat and no blocking or rate-limiting actions are recommended based on current risk profile.
---
## SOC Analyst Notes
Key Observations:
1. Clean Profile: No threat indicators, blacklists, or abuse reports
2. Infrastructure Role: Appears to be a standard telecommunication backbone IP with no public-facing services
3. Stability: Consistent ownership and geolocation data over observation period
4. Neighborhood Context: Single neighbor IP (39.35.233.180) shows elevated risk; subnet otherwise clean
Monitoring Recommendations:
- No immediate action required
- Include in routine network traffic monitoring if observed
- Monitor 39.35.233.180 separately if traffic patterns suggest concern
Risk Assessment: LOW โ Standard telecommunication infrastructure address with no malicious indicators.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Munir Ahmed |
| ASN | AS17557 |
| Network Name | PTCLBB-PK |
| CIDR Block | 39.32.0.0/11 |
| RIR | APNIC |
| Country | PK |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 25% | 1 | 1 |
| Overall | 22% | 6 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-27 03:36:13 UTC |
| Last Seen | 2026-07-30 10:42:40 UTC |
| Profile Built | 2026-07-30 10:52:58 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 16 |
Full dossier details are available via our API.