IPDebrief

49.124.155.177

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 49.124.155.177

Date: 2026-07-30

Analyst: IPDebrief Intelligence Team

Classification: Defensive Threat Intelligence

---

## Executive Summary

IP address 49.124.155.177 is classified as Moderate Risk (risk score: 55/100). The address belongs to DiGi IP Support (ASN 4818) and is geolocated to Shah Alam, Malaysia (MY). The IP presents a moderate risk profile with no open services detected, but exhibits concerning neighborhood-level abuse patterns.

---

## Network Ownership & Classification

AttributeValue
**ASN**4818 (DIGI-AS-AP)
**Organization**DiGi IP Support
**CIDR Block**49.124.0.0/15
**RIR**APNIC
**Country**Malaysia (MY)
**Region**Selangor
**City**Shah Alam
**Classification**Provider Infrastructure

---

## Threat Assessment

Current Risk Indicators

Network Behavior

Control Plane Analysis

---

## Neighborhood Analysis

The /24 subnet (49.124.155.0/24) shows elevated abuse activity:

MetricValue
**Total Siblings**8
**Abuse Density**0.375 (High)
**High Risk Neighbors**3
**Medium Risk Neighbors**4
**Low Risk Neighbors**0

Notable High-Risk Neighbors:

---

## Temporal History

Recent observations indicate sporadic port scanning activity and geolocation inference, but no persistent malicious behavior has been observed.

---

## Recommended Actions

Monitoring (Priority: High)

Action: Increase logging verbosity and review recent activity from this IP

Rationale: Elevated risk score (55/100) combined with high-density abuse neighborhood requires enhanced monitoring.

Firewall Rules

iptables:

```bash

iptables -A INPUT -s 49.124.155.177 -j DROP

```

nftables:

```bash

nft add rule inet filter input ip saddr 49.124.155.177 drop

```

nginx:

```nginx

deny 49.124.155.177;

```

pfSense:

```

49.124.155.177/32

```

Cloudflare WAF:

```json

{

"description": "Block 49.124.155.177 โ€” IPDebrief risk score 55",

"action": "block",

"filter": {

"expression": "ip.src eq 49.124.155.177"

}

}

```

AWS WAF:

```json

{

"Addresses": ["49.124.155.177/32"],

"Description": "IPDebrief risk 55"

}

```

---

## Intelligence Assessment

This IP address represents a moderate-risk threat requiring enhanced monitoring. The absence of open services suggests the address may be used for residential purposes, hosting services, or as part of a broader network infrastructure. However, the 0.375 abuse density in the local /24 subnet indicates systemic issues within this network segment, with 7 of 8 neighbors scoring moderate to high risk.

Recommended SOC Actions:

1. Implement enhanced logging for all traffic from 49.124.155.0/24 subnet

2. Review historical connection logs for this IP

3. Monitor for any service emergence on previously closed ports

4. Consider subnet-level blocking if organizational policy permits

5. Correlate with threat intelligence feeds for associated malicious activity

---

Disclaimer: This intelligence briefing is based on IPDebrief analysis data and should be combined with additional threat intelligence sources before taking operational action.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฒ๐Ÿ‡พ Malaysia
RegionSelangor
City40000 Shah Alam
TimezoneAsia/Kuala_Lumpur
Latitude4.21
Longitude101.98

๐Ÿข Ownership & Registration

OrganizationDiGi IP Support
ASNAS4818
Network NameDIGI-AS-AP
CIDR Block49.124.0.0/15
RIRAPNIC
CountryMY
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown โ€” Insufficient routing data to classify
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
25%
12
reputation
0%
00
geolocation
25%
11
Overall20%56
Coverage: 5/6 dimensions ยท Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-07-26 21:28:28 UTC
Last Seen2026-08-09 23:08:17 UTC
Profile Built2026-08-08 10:23:51 UTC
Data FreshnessLive
Signal Types18
Total Observations18
๐Ÿ” 18 signal types ยท 18 observations collected
This report is generated from 18+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.