# IPDEBRIEF INTELLIGENCE BRIEFING
Target: 61.9.8.166/32
Classification: LOW RISK
Date: 2026-07-27
---
## EXECUTIVE SUMMARY
IP 61.9.8.166 presents a LOW RISK profile with a risk score of 25. The address is assigned to Converge ICT (APNIC) in the Philippines and shows minimal threat indicators. No active malicious activity or established relationships were detected. The subnet demonstrates low abuse density.
---
## OWNERSHIP & GEOLOCATION
- Organization: ABUSE CONVERGEPH
- Abuse Contact: abuse@convergeict.com
- ASN: 17639 (Converge ICT)
- BGP Prefix: 61.9.8.0/22
- Country: Philippines (PH)
- Region: Bicol Region
- City: Pili
- RIR: APNIC
Note: Route stability is flagged as false with zero route changes in the last 30 days.
---
## THREAT ASSESSMENT
- Risk Score: 25 (Low Risk)
- Blacklist Count: 0
- Abuse Confidence: Not applicable
- Tor Exit: No
- Known Attacker: No
- Spam Source: No
- Threat Indicators: None detected
DNSBL Status: Listed on 1 of 8 total DNSBL lists.
---
## NETWORK CLASSIFICATION
- Service Purpose: Firewalled / No Services
- Open Ports: None detected
- TLS Certificates: None
- Cloud Infrastructure: No
- CDN/VPN/Proxy: No
- Hosting/Residential: No
---
## DNS & EMAIL REPUTATION
- PTR Hostnames: None
- Forward Resolution: Not confirmed
- SPF Record: Absent
- DMARC Record: Absent
- TXT Records: 0
- Email Reputation: Not scored
---
## NEIGHBORHOOD ANALYSIS (61.9.8.0/24)
- Total Siblings: 51
- Abuse Density: 0
- Risk Distribution:
- High: 0
- Medium: 1
- Low: 50
- Notable Neighbors:
- 61.9.8.116: Risk Score 40
- 61.9.8.102, 61.9.8.113, 61.9.8.119, 61.9.8.150, 61.9.8.157: Risk Score 25
---
## OBSERVATION HISTORY
Twelve observations recorded. Recent signals confirm ownership by ABUSE CONVERGEPH (confidence 0.90). Some routing and classification signals show lower confidence levels (0.17–0.30), indicating limited data sufficiency in certain dimensions. No persistent threat patterns observed.
---
## NETWORK BEHAVIOR
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
- Active Attacker Status: No
- Auto-Banned: No
---
## RECOMMENDED ACTIONS
No specific firewall rules or blocking recommendations generated due to low risk profile. Standard monitoring and logging is advised.
---
## ANALYST NOTES
This IP is classified as low risk with no active threat indicators. The subnet (61.9.8.0/24) shows minimal abuse density, though a few sibling addresses demonstrate elevated risk scores. The target IP itself is firewalled with no open services, suggesting it may be part of a managed infrastructure block. No actionable threat intelligence suggests immediate blocking; maintain standard monitoring protocols.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | ABUSE CONVERGEPH |
| ASN | AS17639 |
| Network Name | Converge_ICT_Network |
| CIDR Block | 61.9.8.0/22 |
| RIR | APNIC |
| Country | PH |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS17639 |
| Network Prefix | 61.9.8.0/22 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-13 03:14:51 UTC |
| Last Seen | 2026-08-31 22:02:03 UTC |
| Profile Built | 2026-08-31 22:12:48 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 21 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 61.9.8.166
Who owns the IP address 61.9.8.166?
61.9.8.166 is registered to ABUSE CONVERGEPH. The address falls within the 61.9.8.0/22 network block. Registration is held at APNIC.
Where is 61.9.8.166 located?
Geolocation data places 61.9.8.166 in Pili, Bicol Region, Philippines. The local time zone is Asia/Manila. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 61.9.8.166 malicious or safe?
61.9.8.166 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.