IPDebrief

49.244.110.154

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 49.244.110.154/32

Classification: LOW RISK | Status: Monitored | Last Updated: 2026-07-30

---

## Executive Summary

IP 49.244.110.154 is a residential Fiber To The Home (FTTH) address located in Bhojpur, Koshi region, Nepal. The IP presents a low risk profile (risk score: 25) with no active threat indicators detected. This address is assigned to Nepal Telecom (NTC), a legitimate ISP operator.

---

## Technical Profile

Geolocation:

Network Attribution:

DNS Resolution:

---

## Threat Assessment

Current Risk Score: 25/100 (Low)

Threat Indicators:

Network Classification:

---

## Behavioral History

Observation Count: 13 signals (most recent: 2026-07-30)

Temporal Analysis:

Risk Trend: Stable. No significant changes in geolocation, ownership, or threat indicators observed over the observation period.

---

## Neighborhood Analysis

Subnet: 49.244.110.154/24

Abuse Density: 0 (No abuse activity detected in neighborhood)

Sibling Analysis:

The IP exists in a low-density subnet with no adjacent addresses flagged for abuse.

---

## Relationships

DNS Associations:

No additional relationships to organizations, certificates, or related subnets identified.

---

## Recommended Actions

SOC Analyst Guidance:

1. No immediate blocking required. The IP presents low risk and appears to be legitimate residential infrastructure.

2. Monitor for service exposure. Currently no ports are open, but standard monitoring should continue.

3. Verify blacklist status. The IP is listed on 1 of 8 DNSBLsβ€”investigate the specific listing if traffic from this IP triggers reputation-based filtering.

4. Allow legitimate traffic. This is a Nepal Telecom FTTH address; block only if specific malicious activity is observed.

5. Update firewall rules: No specific iptables/nftables rules recommended at this time.

---

## Conclusion

IP 49.244.110.154 is a benign residential address assigned to Nepal Telecom. No threat indicators support blocking or enhanced monitoring beyond standard baseline operations. The IP's stable history, low-risk profile, and lack of active services indicate normal residential usage.

Recommendation: Monitor as normal traffic; no action required.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡³πŸ‡΅ NP
RegionKoshi
CityBhojpur
Timezoneβ€”
Latitude27.16
Longitude87.05

🏒 Ownership & Registration

OrganizationIRT-NPTELECOM-NP
ASNAS23752
Network NameNTCINTERNET
CIDR Block49.244.0.16/28
RIRAPNIC
CountryNP
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR154-ftth.ntc.net.np
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnames154-ftth.ntc.net.np

πŸ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureResidential
Service PurposeResidential Endpoint
Network TierEnd-User β€” Residential ISP endpoint
Residential

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
0%
00
reputation
0%
00
geolocation
25%
11
Overall16%44
Coverage: 4/6 dimensions Β· Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-07-26 21:28:28 UTC
Last Seen2026-07-30 09:53:31 UTC
Profile Built2026-07-30 10:09:45 UTC
Data FreshnessLive
Signal Types19
Total Observations19
πŸ” 19 signal types Β· 19 observations collected
This report is generated from 19+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.