# IP Intelligence Briefing: 49.124.147.251/32
Classification: Low Risk / Routine
Date: 2026-07-23
Analyst: Automated Intelligence System
## Executive Summary
IP address 49.124.147.251 is a low-risk infrastructure endpoint belonging to DiGi IP Support (ASN 4818) in Malaysia. Current threat indicators show minimal malicious activity with a risk score of 15/100. No active campaigns, blacklisting, or known attack patterns detected. The IP operates without open services and is firewalled.
## Ownership and Infrastructure
| Attribute | Value |
|---|---|
| ASN | 4818 (DIGI-AS-AP) |
| Organization | DiGi IP Support |
| CIDR Block | 49.124.0.0/15 |
| RIR | APNIC |
| Abuse Contact | abuse@celcomdigi.com |
| Registration | Malaysia, Selangor |
## Geolocation Data
- Country: Malaysia (MY)
- City: 40000 Shah Alam
- State: Selangor
- Coordinates: 4.21°N, 101.98°E
- Timezone: Asia/Kuala_Lumpur
- Geo Consensus: True (1 source)
## Network Role Classification
The IP is classified with no active services:
- Open Ports: None detected
- TLS Certificates: None
- HTTP Services: None
- Network Types: Not cloud, CDN, VPN, proxy, Tor, or hosting infrastructure
- Service Purpose: Firewalled / No Services
## Threat Intelligence Profile
| Indicator | Status |
|---|---|
| Risk Score | 15 (Low Risk) |
| Abuse Confidence Score | Not applicable |
| Tor Exit Node | No |
| Known Attacker | No |
| Spam Source | No |
| Blacklist Count | 0 |
| Threat Feeds | None detected |
| Known Campaigns | None |
## DNS and Email Reputation
- PTR Hostnames: None resolved
- Forward Resolution: Confirmed false
- Hosted Domains: 0
- Email Auth: No SPF, DMARC records
- TXT Record Count: 0
## Control Plane Analysis
- Route Stability: False (flagged as unstable)
- DNSBL Listed: 1 of 8 total lists
- Operator Score: 0.1304 (Minimal)
- BGP Prefix: 49.124.0.0/15
- Route Changes (30d): 0
- RPKI State: Not determined
- DNSSEC: Valid
## Neighborhood Analysis (49.124.147.0/24)
The /24 subnet contains 15 total sibling IPs with 10 currently active:
Risk Distribution:
- High Risk: 1 IP
- Medium Risk: 12 IPs
- Low Risk: 1 IP
- Abuse Density: 0.071 (7.1%)
Notable Neighbors:
- 49.124.147.120: Risk 80 (highest in subnet)
- 49.124.147.101, 49.124.147.109, 49.124.147.248, 49.124.147.249, 49.124.147.253: Risk 70
- 49.124.147.96, 49.124.147.102, 49.124.147.105, 49.124.147.110, 49.124.147.111, 49.124.147.115, 49.124.147.118, 49.124.147.252: Risk 55
- 49.124.147.251 (subject): Risk 15
## Historical Observations
Fifteen signals observed on 2026-07-23 within minutes of each other:
- 11:25:03 - Ownership stability signal (confidence 0.85)
- 11:23:47 - Network type classification (confidence 0.30)
- 11:21:04 - Subnet abuse density analysis (confidence 0.75)
- 11:20:30 - ASN and organizational registration data (confidence 0.90-0.95)
No ownership changes or threat persistence patterns detected.
## Threat Campaign Correlation
- Campaign Likelihood: Not determined
- Certificate Matches: 0
- Banner Matches: 0
- Correlated IPs: 0
- Cert Subjects: None
## Recommended Actions
Based on the low-risk profile (score 15) and absence of threat indicators, no immediate firewall rules or blocking actions are recommended. The IP shows:
- No active malicious indicators
- No blacklist presence
- No campaign correlation
- Stable ownership history
Monitoring Recommendation: Standard monitoring appropriate. No blocking required unless new threat indicators emerge.
## Conclusion
IP 49.124.147.251 represents routine infrastructure activity from a Malaysian telecommunications provider. The absence of open services and threat indicators supports classification as low-risk. The subnet shows moderate abuse density (0.071), but this IP specifically demonstrates clean behavior. SOC teams may monitor for changes in network role or service exposure.
---
*Intelligence generated by IPDebrief Automated Analysis System*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | DiGi IP Support |
| ASN | AS4818 |
| Network Name | DIGI-AS-AP |
| CIDR Block | 49.124.0.0/15 |
| RIR | APNIC |
| Country | MY |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS4818 |
| Network Prefix | 49.124.0.0/15 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-04 11:16:40 UTC |
| Last Seen | 2026-08-27 06:38:51 UTC |
| Profile Built | 2026-08-29 05:30:17 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 18 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 49.124.147.251
Who owns the IP address 49.124.147.251?
49.124.147.251 is registered to DiGi IP Support. The address falls within the 49.124.0.0/15 network block. Registration is held at APNIC.
Where is 49.124.147.251 located?
Geolocation data places 49.124.147.251 in 40000 Shah Alam, Selangor, Malaysia. The local time zone is Asia/Kuala_Lumpur. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 49.124.147.251 malicious or safe?
49.124.147.251 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.