IP INTELLIGENCE BRIEFING: 5.155.37.78/32
Classification: Low Risk / Monitor
Risk Score: 25/100
Report Date: Current
---
Executive Summary
IP 5.155.37.78 presents a low-risk profile with a risk score of 25. The address is currently classified as "Firewalled / No Services" with no active open ports detected. While the IP shows historical DNSBL listings (1 of 8 lists, including one high-severity entry), current behavioral indicators show no active malicious activity. The address belongs to BGP prefix 5.155.32.0/19 (origin ASN 29256) with a route stability classification of "not stable." The /24 subnet (5.155.37.0/24) is classified as "clean" with zero abuse density and no threat siblings.
---
Technical Profile
Network Classification:
- ASN: 29256
- BGP Prefix: 5.155.32.0/19
- Network Role: Firewalled / No Services
- Infrastructure Type: None detected
- Cloud/CDN/Proxy/Tor: Not identified
Geolocation:
- Country: Syria (SY) — recent observation from 2026-07-22
- Coordinates: 35.0, 38.0
- Geo Consensus: Inconsistent across sources
- Note: Geographic data shows limited consensus; multiple probe attempts yielded null values.
DNS and Email:
- PTR Hostnames: None
- Forward Resolution: Failed
- Email Authentication: No SPF, DMARC, or TXT records
- DNSBL Status: Listed on 1 of 8 DNSBLs
Services and Ports:
- Open Ports: None detected
- TLS Certificate: Not present
- HTTP Banner: None
---
Observation History (8 Recorded Signals)
Recent signals from 2026-07-22 include:
- Geolocation: Syria (SY) — confidence 0.70
- DNSSEC: Minimal scoring (operator score 0.13) — confidence 0.30
- Routing/Ownership/Services: Multi-dimensional assessment — confidence 0.18
- Blacklist Status: 1 of 8 lists flagged with "high" severity — confidence 0.85
- Subnet Analysis: 5.155.37.0/24 classified as "clean" with 0 abuse density
Temporal Indicators:
- Threat Persistence: 0 days observed
- Ownership Changes: 0 recorded
- Persistently Malicious: False
- Active Attacker: False
---
Relationship Analysis
- Related Entities: None detected
- Subnet Siblings: 1 total sibling; 0 active; 0 threats
- Certificate Links: 0
- Correlated IPs: 0
- Campaign Matches: 0
---
Neighborhood Assessment (5.155.37.0/24)
- Subnet Classification: Clean
- Abuse Density: 0
- Inherited Risk: 0
- Total Siblings: 1
- Active Siblings: 0
- Threat Siblings: 0
- Risk Distribution: High: 0, Medium: 0, Low: 0
---
Behavioral Indicators
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
- Total Incidents: 0
- Auto-Banned: False
- Route Stability: Not stable (route changes 30d: 0)
---
Recommended Actions
Current Status: No immediate blocking required. Risk score 25 with no active behavioral indicators.
Monitoring Recommendations:
1. DNSBL Monitoring: Continue tracking the 1 DNSBL listing. Investigate which list and reasons for inclusion.
2. Route Stability: Monitor ASN 29256 for route changes; current prefix shows no stability.
3. Geographic Consistency: Verify Syria geolocation attribution against actual traffic patterns.
4. Subnet Context: Despite single IP concerns, 5.155.37.0/24 shows clean classification with no neighbor threats.
Firewall Rules: None required at this time. Default allow policy acceptable if traffic is legitimate.
---
Threat Assessment
This IP address presents minimal immediate threat. Historical DNSBL listings warrant periodic review, but current behavioral metrics show no active exploitation attempts. The subnet environment remains benign with zero threat siblings. Recommended monitoring approach: passive observation with periodic DNSBL verification.
Confidence Level: Moderate — data sufficiency varies across dimensions; some profile fields remain null.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Firas Ahmad |
| ASN | AS29256 |
| Network Name | SY-ISP-TARASSUL |
| CIDR Block | 5.155.0.0/17 |
| RIR | RIPE |
| Country | SY |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS29256 |
| Network Prefix | 5.155.32.0/19 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 18% | 5 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-02 04:22:03 UTC |
| Last Seen | 2026-08-24 17:11:19 UTC |
| Profile Built | 2026-08-29 09:34:01 UTC |
| Data Freshness | Live |
| Signal Types | 15 |
| Total Observations | 17 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 5.155.37.78
Who owns the IP address 5.155.37.78?
5.155.37.78 is registered to Firas Ahmad. The address falls within the 5.155.0.0/17 network block. Registration is held at RIPE.
Where is 5.155.37.78 located?
Geolocation data places 5.155.37.78 in SY. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 5.155.37.78 malicious or safe?
5.155.37.78 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.