# IP Intelligence Briefing: 61.9.8.157
## Executive Summary
IP address 61.9.8.157 is a low-risk infrastructure asset belonging to Converge ICT Network in the Philippines. The address demonstrates stable ownership, no active services, and minimal threat indicators. No immediate defensive action required.
## Network Ownership and Registration
- Organization: ABUSE CONVERGEPH (Converge ICT Network)
- ASN: 17639
- Network Block: 61.9.8.0/22
- RIR: APNIC
- Abuse Contact: abuse@convergeict.com
- Registration: PH (Philippines) — Bicol Region, Pili
## Risk Assessment
- Overall Risk Score: 25 (Low Risk)
- Reputation: Low Risk
- Threat Indicators: None detected
- Blacklist Status: Listed on 1 of 8 DNSBL feeds
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
## Network Configuration
- Service Status: Firewalled / No Services
- Open Ports: None detected
- DNS Resolution: No PTR records, no forward resolution
- Email Auth: No SPF or DMARC records
- HTTP/HTTPS: No services responding
## Historical Observations
17 signal observations recorded. Most recent activity dated 2026-07-27. Historical signals indicate:
- Stable ownership (no changes detected)
- Consistent classification as "clean"
- No persistent malicious behavior
- Subnet abuse density: 0%
## Neighborhood Analysis
The /24 subnet (61.9.8.0/24) contains 51 sibling IPs with the following risk distribution:
- High Risk: 0
- Medium Risk: 1 (61.9.8.116 — score 40)
- Low Risk: 50
Multiple sibling IPs show risk score of 25, including 61.9.8.54, 61.9.8.77, 61.9.8.80, 61.9.8.88, 61.9.8.102, 61.9.8.113, 61.9.8.119, 61.9.8.150, 61.9.8.166, 61.9.8.233, 61.9.8.246.
## Relationship Graph
Single relationship detected: Same Network (Converge_ICT_Network). No additional hostnames, organizations, or certificate associations.
## Recommended Actions
No specific firewall rules or mitigation actions recommended due to low risk profile. The IP should be allowed through standard security controls with monitoring enabled.
## Intelligence Notes
- The IP has been passively monitored with minimal threat persistence
- Geographic location validates as plausible (RTT: 240ms average)
- Control plane shows route stability issues (isRouteStable: false)
- Operator score: 0.1304 (Minimal)
- No honeypot hits, enumeration strikes, or WAF violations observed
Classification: LOW THREAT — Routine monitoring advised. No blocking or alerting required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | ABUSE CONVERGEPH |
| ASN | AS17639 |
| Network Name | Converge_ICT_Network |
| CIDR Block | 61.9.8.0/22 |
| RIR | APNIC |
| Country | PH |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS17639 |
| Network Prefix | 61.9.8.0/22 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 23% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 36% | 2 | 7 |
| reputation | 23% | 1 | 4 |
| geolocation | 31% | 2 | 5 |
| Overall | 22% | 10 | 23 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-13 03:14:51 UTC |
| Last Seen | 2026-09-05 11:06:10 UTC |
| Profile Built | 2026-09-05 11:06:55 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 33 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 61.9.8.157
Who owns the IP address 61.9.8.157?
61.9.8.157 is registered to ABUSE CONVERGEPH. The address falls within the 61.9.8.0/22 network block. Registration is held at APNIC.
Where is 61.9.8.157 located?
Geolocation data places 61.9.8.157 in Pili, Bicol Region, Philippines. The local time zone is Asia/Manila. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 61.9.8.157 malicious or safe?
61.9.8.157 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.