# IPDEBRIEF INTELLIGENCE BRIEFING
Target: 49.244.158.201/32
Date: 2026-07-28
Classification: MODERATE RISK (Score: 40)
---
## EXECUTIVE SUMMARY
IP 49.244.158.201 is a residential endpoint classified as moderate risk (score 40). The address resolves to a residential fiber connection in Denver, CO under NTCINTERNET (ASN 23752). No active malicious campaigns detected, but the IP appears on 2 of 8 DNS blacklists with high severity ratings. Neighborhood analysis shows clean subnet classification with zero abuse density.
---
## OWNERSHIP & GEOPOLITICAL ATTRIBUTES
- ASN: 23752 (IRT-NPTELECOM-NP / NTCINTERNET)
- CIDR: 49.244.0.16/28
- RIR: APNIC
- Geolocation: Denver, CO, US (America/Denver timezone)
- Infrastructure: Residential fiber endpoint
- Ownership Stability: Stable (0 ownership changes detected)
---
## THREAT INTELLIGENCE
- Risk Score: 40 (Moderate)
- Known Attack Indicators: None
- Tor Exit Node: No
- Proxy/VPN: No
- Cloud/Hosting: No
- DNSBL Status: Listed on 2 of 8 blacklists (max severity: HIGH)
- Campaign Correlation: 0 correlated IPs; 0 certificate matches
---
## NETWORK CLASSIFICATION
- Infrastructure Type: Residential Endpoint
- Connection Type: Fiber
- Network Role: Residential (not CDN, proxy, or hosting)
- BGP Prefix: 49.244.152.0/21
- Route Stability: Stable (0 route changes in 30 days)
- RPKI State: Valid
- DNSSEC: Valid
---
## DNS & SERVICES
- PTR Hostname: 201-ftth.ntc.net.np
- Forward Resolution: 201-ftth.ntc.net.np
- Domain: net.np (Nepal)
- Open Ports: None detected
- TLS/HTTP Services: None detected
- Email Authentication: SPF/DMARC not configured
---
## NEIGHBORHOOD ANALYSIS (49.244.158.201/24)
- Abuse Density: 0%
- Classification: Clean
- Sibling IPs: 1 total
- Active Threat Siblings: 0
- Inherited Risk: 0
---
## OBSERVATION HISTORY
17 historical observations recorded. Recent activity includes:
- July 28, 2026: Clean subnet classification and residential infrastructure confirmed
- DNSBL listing confirmed with high severity rating on 2 lists
- Ownership and threat persistence metrics stable
- No persistently malicious behavior observed
---
## RELATIONSHIP GRAPH
- Network Associations: NTCINTERNET (same network)
- DNS Associations: 201-ftth.ntc.net.np (forward/reverse resolved)
---
## RECOMMENDED ACTIONS
Firewall Rules
```bash
iptables -A INPUT -s 49.244.158.201 -j DROP
nft add rule inet filter input ip saddr 49.244.158.201 drop
nginx: deny 49.244.158.201;
```
WAF Rules
- Cloudflare WAF: Block IP (risk score 40)
- AWS WAF: Block 49.244.158.201/32
SOC Analysis Notes
Monitor for increased DNSBL listings or reputation degradation. The residential nature of this endpoint suggests it may be misconfigured rather than malicious. Consider whitelist evaluation if legitimate traffic patterns are observed from this address.
---
Report Generated: IPDebrief Intelligence Platform
Analyst: Automated Intelligence System
Classification: Internal Use - Defensive Security Operations
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | IRT-NPTELECOM-NP |
| ASN | AS23752 |
| Network Name | NTCINTERNET |
| CIDR Block | 49.244.0.16/28 |
| RIR | APNIC |
| Country | NP |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | 201-ftth.ntc.net.np |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 201-ftth.ntc.net.np |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Residential |
| Service Purpose | Residential Endpoint |
| Network Tier | End-User — Residential ISP endpoint |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS23752 |
| Network Prefix | 49.244.152.0/21 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 4% | 1 | 1 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-16 04:32:01 UTC |
| Last Seen | 2026-09-02 17:19:29 UTC |
| Profile Built | 2026-09-02 17:27:44 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 27 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 49.244.158.201
Who owns the IP address 49.244.158.201?
49.244.158.201 is registered to IRT-NPTELECOM-NP. The address falls within the 49.244.0.16/28 network block. Registration is held at APNIC.
Where is 49.244.158.201 located?
Geolocation data places 49.244.158.201 in Los Angeles, US-CA, United States. The local time zone is America/Los_Angeles. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 49.244.158.201 malicious or safe?
49.244.158.201 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 49.244.158.201?
The reverse DNS (PTR) record for 49.244.158.201 is 201-ftth.ntc.net.np. This hostname is not forward-confirmed, so it should be treated as a weak signal.
Is 49.244.158.201 a VPN, proxy, or data center address?
49.244.158.201 is classified as a residential network based on network ownership and behavioural analysis.