# IP Intelligence Briefing: 49.124.155.177
Date: 2026-07-30
Analyst: IPDebrief Intelligence Team
Classification: Defensive Threat Intelligence
---
## Executive Summary
IP address 49.124.155.177 is classified as Moderate Risk (risk score: 55/100). The address belongs to DiGi IP Support (ASN 4818) and is geolocated to Shah Alam, Malaysia (MY). The IP presents a moderate risk profile with no open services detected, but exhibits concerning neighborhood-level abuse patterns.
---
## Network Ownership & Classification
| Attribute | Value |
|---|---|
| **ASN** | 4818 (DIGI-AS-AP) |
| **Organization** | DiGi IP Support |
| **CIDR Block** | 49.124.0.0/15 |
| **RIR** | APNIC |
| **Country** | Malaysia (MY) |
| **Region** | Selangor |
| **City** | Shah Alam |
| **Classification** | Provider Infrastructure |
---
## Threat Assessment
Current Risk Indicators
- Risk Score: 55/100 (Moderate Risk)
- Threat Indicators: None detected
- Known Campaigns: None
- Blacklist Count: 0
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Network Behavior
- Open Ports: None detected
- DNS Records: No PTR hostnames; no forward resolution
- Services: No open services (Firewalled / No Services)
- TLS Certificates: None
Control Plane Analysis
- BGP Prefix: 49.124.0.0/15
- Route Stability: Unstable (isRouteStable: false)
- DNSBL Listed: 3 of 8 total lists
- RPKI State: Not evaluated
- Operator Score: 0.1304 (Minimal)
---
## Neighborhood Analysis
The /24 subnet (49.124.155.0/24) shows elevated abuse activity:
| Metric | Value |
|---|---|
| **Total Siblings** | 8 |
| **Abuse Density** | 0.375 (High) |
| **High Risk Neighbors** | 3 |
| **Medium Risk Neighbors** | 4 |
| **Low Risk Neighbors** | 0 |
Notable High-Risk Neighbors:
- 49.124.155.149 (Risk: 80, Authority: 50)
- 49.124.155.162 (Risk: 70, Authority: 50)
- 49.124.155.174 (Risk: 55, Authority: 50)
- 49.124.155.175 (Risk: 55, Authority: 50)
- 49.124.155.179 (Risk: 70, Authority: 50)
- 49.124.155.182 (Risk: 80, Authority: 50)
- 49.124.155.189 (Risk: 80, Authority: 50)
---
## Temporal History
- Observation Count: 16 signals
- Latest Observation: 2026-07-30T10:01:54 UTC
- Threat Persistence Days: 0
- Threat Observation Count: 0
- Is Persistently Malicious: No
- Ownership Changes: 0
Recent observations indicate sporadic port scanning activity and geolocation inference, but no persistent malicious behavior has been observed.
---
## Recommended Actions
Monitoring (Priority: High)
Action: Increase logging verbosity and review recent activity from this IP
Rationale: Elevated risk score (55/100) combined with high-density abuse neighborhood requires enhanced monitoring.
Firewall Rules
iptables:
```bash
iptables -A INPUT -s 49.124.155.177 -j DROP
```
nftables:
```bash
nft add rule inet filter input ip saddr 49.124.155.177 drop
```
nginx:
```nginx
deny 49.124.155.177;
```
pfSense:
```
49.124.155.177/32
```
Cloudflare WAF:
```json
{
"description": "Block 49.124.155.177 โ IPDebrief risk score 55",
"action": "block",
"filter": {
"expression": "ip.src eq 49.124.155.177"
}
}
```
AWS WAF:
```json
{
"Addresses": ["49.124.155.177/32"],
"Description": "IPDebrief risk 55"
}
```
---
## Intelligence Assessment
This IP address represents a moderate-risk threat requiring enhanced monitoring. The absence of open services suggests the address may be used for residential purposes, hosting services, or as part of a broader network infrastructure. However, the 0.375 abuse density in the local /24 subnet indicates systemic issues within this network segment, with 7 of 8 neighbors scoring moderate to high risk.
Recommended SOC Actions:
1. Implement enhanced logging for all traffic from 49.124.155.0/24 subnet
2. Review historical connection logs for this IP
3. Monitor for any service emergence on previously closed ports
4. Consider subnet-level blocking if organizational policy permits
5. Correlate with threat intelligence feeds for associated malicious activity
---
Disclaimer: This intelligence briefing is based on IPDebrief analysis data and should be combined with additional threat intelligence sources before taking operational action.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | DiGi IP Support |
| ASN | AS4818 |
| Network Name | DIGI-AS-AP |
| CIDR Block | 49.124.0.0/15 |
| RIR | APNIC |
| Country | MY |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 20% | 5 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-26 21:28:28 UTC |
| Last Seen | 2026-08-09 23:08:17 UTC |
| Profile Built | 2026-08-08 10:23:51 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.