# IP Intelligence Briefing: 39.63.186.185/32
## Executive Summary
The IP address 39.63.186.185 is classified as Low Risk with an overall risk score of 25. This address belongs to Pakistan Telecommunication Company Limited (PTCL) business network infrastructure. The IP shows no active threat indicators, no open services, and no associated malicious activity in available threat feeds.
---
## Network Profile
| Attribute | Value |
|---|---|
| **IP Address** | 39.63.186.185/32 |
| **ASN** | 17557 |
| **Organization** | Munir Ahmed |
| **Netname** | PTCLBB-PK |
| **Country** | Pakistan (PK) |
| **Region** | Khyber Pakhtunkhwa |
| **City** | Mardan |
| **RIR** | APNIC |
| **CIDR Block** | 39.32.0.0/11 |
---
## Risk Assessment
- Overall Risk Score: 25/100 (Low)
- Reputation: Low Risk
- Abuse Confidence Score: Not available
- Blacklist Count: 0
- Threat Feeds: None
- Known Campaigns: None
- Persistently Malicious: No
Classification Flags
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- CDN/Cloud/Proxy/VPN: No
- Hosting/Residential: No
- Bogon Address: No
---
## Service & Port Analysis
- Open Ports: None detected
- Network Role: Firewalled / No Services
- HTTP/HTTPS: No active services
- TLS Certificates: None
- DNS Resolution: No PTR records, no forward resolution
---
## Control Plane Data
- BGP Prefix: 39.63.160.0/19
- Route Stability: Unstable (0 changes in 30 days)
- RPKI State: Not available
- IR Consistency: Not available
- DNSBL Listed: 1 of 8 total DNSBLs
- Operator Score: 0.1304 (Minimal)
---
## Neighborhood Analysis (39.63.186.0/24)
| Metric | Value |
|---|---|
| **Subnet Abuse Density** | 0 |
| **Total Siblings** | 1 |
| **Active Siblings** | 0 |
| **Threat Siblings** | 0 |
| **Neighbor IP** | 39.63.186.204 (Risk Score: 0) |
The /24 subnet shows minimal abuse activity with one low-risk sibling IP (39.63.186.204).
---
## Relationship Graph
- Associated Network: PTCLBB-PK
- Relationship Count: 1
---
## Signal History
The IP has generated 12 observations with the most recent activity recorded on 2026-07-30. Historical analysis indicates:
- Ownership Changes: 0
- Threat Persistence Days: 0
- Threat Observation Count: 0
- Signal Persistence: Not persistently malicious
Recent signals include ownership verification, geographic resolution to Pakistan (Mardan/Islabad), and network classification as business infrastructure.
---
## Security Recommendations
No immediate blocking or firewall rules recommended. The IP presents low-risk characteristics with no active threat indicators. However, standard operational guidance applies:
- Monitor for new open ports or service changes
- Verify inbound connection requests against known business requirements
- Review DNSBL listings periodically
---
## SOC Analyst Notes
This IP address represents legitimate telecommunications infrastructure with no observed malicious behavior. The low risk score (25) combined with zero open ports, zero blacklist hits, and zero threat indicators suggests routine business network traffic. No correlation with known attack campaigns or malicious IP clusters was detected.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Munir Ahmed |
| ASN | AS17557 |
| Network Name | PTCLBB-PK |
| CIDR Block | 39.32.0.0/11 |
| RIR | APNIC |
| Country | PK |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-27 09:39:32 UTC |
| Last Seen | 2026-07-30 11:55:33 UTC |
| Profile Built | 2026-07-30 12:04:34 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 16 |
Full dossier details are available via our API.