# IPDEBRIEF INTELLIGENCE BRIEFING
Target: 72.61.171.227/32
Date: July 2026
Classification: Low Risk with Monitoring Indicators
## Executive Summary
IP address 72.61.171.227 presents a low-risk profile (Risk Score: 25) but warrants monitoring due to inconsistent geolocation data and DNSBL listings. The IP resolves to mail.thumbeja.com with no open services detected.
## Network Profile
Ownership & Control Plane:
- Origin ASN: 47583
- BGP Prefix: 72.61.168.0/21
- Route Stability: False
- DNSSEC: Valid
- Operator Score: 0.2609 (Basic)
Geolocation Consensus:
- Primary: US, Georgia, Atlanta, America/New_York
- Secondary Signals: India (Mumbai) and Lithuania (Vilnius) observed in historical data
- Geo-Consensus: True
- Geo-Plausible: False
## Threat Indicators
Risk Assessment:
- Risk Score: 25 (Low Risk)
- Abuse Confidence Score: Null
- Blacklist Count: 0
- DNSBL Listed: 1 of 8 lists
- Is Tor Exit: False
- Is Known Attacker: False
- Is Spam Source: False
Network Classification:
- Service Purpose: Firewalled / No Services
- Open Ports: None detected
- Not classified as CDN, VPN, Proxy, Hosting, or Mobile infrastructure
## Historical Observation Analysis
Fifteen observations recorded. Notable findings include:
- Recent geolocation signals show inconsistent reporting between US (Atlanta), India (Mumbai), and Lithuania (Vilnius)
- ASN 1239 (Sprint) association detected with threat indicators in one observation
- Hostinger NOC referenced in multiple historical signals
- Average ownership days: Null
- Threat persistence: 0 days (not persistently malicious)
## DNS Intelligence
Resolved Hostnames:
- mail.thumbeja.com (forward confirmed)
- Forward Resolution Count: 1
Email Authentication:
- SPF: Configured
- DMARC: Configured
- TXT Record Count: 0
## Relationship Graph
Two DNS associations identified:
- mail.thumbeja.com (hostname)
## Neighborhood Analysis
Subnet 72.61.171.227/24:
- Neighbor Count: 0
- Abuse Density: 0
- Risk Distribution: No high/medium/low risk siblings detected
## Recommended Actions
1. Monitor Geolocation Discrepancies: The inconsistent reporting between Atlanta, US; Mumbai, India; and Vilnius, Lithuania suggests potential IP reuse, reassignment, or geolocation database errors. Continue monitoring for stability.
2. DNSBL Review: Verify the single DNSBL listing to determine if removal is appropriate or if the listing is justified.
3. Email Reputation: Confirm thumbeja.com email reputation through sender score testing given SPF/DMARC configuration.
4. Service Verification: Confirm the "Firewalled / No Services" status through active port scanning if legitimate services are expected.
## Intelligence Narrative
72.61.171.227 is a low-risk IP address associated with the thumbeja.com domain. The IP exhibits no active services and maintains firewalled status. However, geolocation inconsistencies across multiple signal sources and a single DNSBL listing warrant continued observation. The absence of open ports and threat indicators suggests benign operational use, but the geographic confusion requires validation to prevent potential IP misattribution in threat correlation workflows. No immediate blocking required; maintain passive monitoring.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Hostinger NOC |
| ASN | AS47583 |
| Network Name | HOSTINGER-HOSTING |
| CIDR Block | 72.61.168.0/21 |
| RIR | ARIN |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | mail.thumbeja.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | mail.thumbeja.com |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-21 12:55:47 UTC |
| Last Seen | 2026-07-29 09:36:35 UTC |
| Profile Built | 2026-07-29 09:48:32 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 23 |
Full dossier details are available via our API.