IPDebrief

130.185.101.86

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 130.185.101.86/32

Classification: High Risk

Report Date: 2026-07-28

Analyst: IPDebrief Intelligence Team

---

## Executive Summary

IP 130.185.101.86 is classified as High Risk (80/100) and should be treated as suspicious. The address belongs to Pelephone Communications Ltd. (AS16116) within Israel. Despite legitimate network ownership, the IP exhibits elevated risk characteristics including DNSBL listing and misconfigured TLS certificates. Immediate monitoring and blocking are recommended.

---

## Ownership & Infrastructure

AttributeValue
**Organization**Pelephone Communications Ltd.
**AS Number**16116
**Network**IL-PELEPHONE-20111024 / 130.185.96.0/21
**Location**Israel (31.05°N, 34.85°E)
**Registration**ARIN
**RIR**ARIN

The IP is assigned to Pelephone's telecommunications infrastructure and operates as a web server within the /21 CIDR block.

---

## Risk Assessment

Key Risk Indicators:

---

## Network Services & Fingerprinting

PortProtocolServiceDetails
443TCPHTTPS-
22TCPSSHdropbear_2018.76

TLS Configuration:

HTTP Banner:

HTTP Status: 200 OK

---

## Historical Observation Analysis

Total Observations: 19 signals recorded

Recent Activity (July 28, 2026):

Temporal Analysis:

---

## Network Neighborhood

Subnet: 130.185.101.86/24

MetricValue
Total Siblings2
Active Siblings1
Threat Siblings0
Abuse Density0
Subnet ClassificationClean

Neighbor Analysis:

The IP's immediate subnet shows minimal abuse activity with 0 threat siblings, suggesting the risk may be isolated to this specific address.

---

## Relationship Graph

Detected Relationships: 5

---

## Threat Intelligence Indicators

Indicator TypeStatusDetails
Tor Exit NodeNoFalse
Known AttackerNoFalse
Spam SourceNoFalse
Campaign LikelihoodNone0 cert matches, 0 banner matches
Correlated IPs0No correlated addresses

Blacklist Status: 4 DNSBL lists active

---

## Recommended Actions

Immediate Firewall Rules

iptables:

```bash

iptables -A INPUT -s 130.185.101.86 -j DROP

```

nftables:

```bash

nft add rule inet filter input ip saddr 130.185.101.86 drop

```

nginx:

```nginx

deny 130.185.101.86;

```

pfSense:

```

130.185.101.86/32

```

Cloudflare WAF:

```json

{

"description": "Block 130.185.101.86 — IPDebrief risk score 80",

"action": "block",

"filter": {

"expression": "ip.src eq 130.185.101.86"

}

}

```

AWS WAF:

```json

{

"Addresses": ["130.185.101.86/32"],

"Description": "IPDebrief risk 80"

}

```

Monitoring Recommendations

Critical:

---

## Intelligence Narrative

IP 130.185.101.86 presents a High Risk profile despite being assigned to legitimate telecommunications infrastructure (Pelephone Communications). The elevated risk score (80/100) is primarily driven by DNSBL listing activity and misconfigured security certificates. The IP operates as a web server with SSH access enabled, running outdated lighttpd software.

Historical analysis shows the IP is not persistently malicious with no observed threat persistence or campaign correlations. The immediate subnet (130.185.101.0/24) maintains a clean classification with minimal abuse density. However, the specific risk indicators—particularly the 4 DNSBL listings and self-signed TLS certificate—warrant immediate defensive action.

Assessment: The risk appears isolated to this single IP rather than representing broader infrastructure compromise. SOC teams should implement blocking rules while maintaining monitoring for potential activity escalation.

---

## Conclusion

This intelligence report provides a comprehensive threat profile for IP 130.185.101.86/32. The High Risk classification (80/100) is supported by DNSBL listing activity and misconfigured TLS certificates. While the subnet shows minimal abuse density, the specific indicators associated with this address warrant immediate defensive action.

Priority: Medium-High

Recommended Response Time: 24 hours

Classification: Active Threat Indicator

---

## Appendices

Data Sources:

Last Updated: 2026-07-28

Report ID: IPR-20260728-13018510186

---

*End of Intelligence Briefing*

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇮🇱 Israel
Region—
CityFrankfurt
TimezoneAsia/Jerusalem
Latitude31.05
Longitude34.85

🏢 Ownership & Registration

OrganizationPelephone Communications Ltd.
ASNAS16116
Network NameIL-PELEPHONE-20111024
CIDR Block130.185.96.0/21
RIRARIN
CountryIL
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)

🔐 DNS Hygiene

Hygiene Score0% (None)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECNot signed
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
80httptcp—
443httpstcp—
22sshtcpBanner detected
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
ServerWeb server detected
HTTP Title—

🔐 TLS Certificate

A self-signed certificate was detected. This is common for development servers, internal services, or IoT devices.
⚠️
CN=localhost
Issued by CN=localhost
Self-signed: Yes
SANsNone
Valid From2023-08-01T08:19:07+00:00
Valid Until2033-07-29T08:19:07+00:00
TLS ProtocolTls12
Cipher SuiteTLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period3650 days

🛡️ Public Network Snapshot

Origin ASNAS16116
Network Prefix130.185.96.0/21
Route mappingFound
HSTSNot detected
CSPNot detected
HTTP/2Not detected

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
23%
24
routing
8%
11
services
34%
25
ownership
23%
24
reputation
20%
13
geolocation
23%
24
Overall22%1021
Coverage: 6/6 dimensions · Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) — 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Geo sources disagree on country: DE, IL

📅 Observation Timeline 🔄 Live

First Seen2026-07-16 22:51:32 UTC
Last Seen2026-09-29 20:35:07 UTC
Profile Built2026-09-29 09:08:10 UTC
Data FreshnessLive
Signal Types21
Total Observations32
🔍 21 signal types · 32 observations collected
This report is generated from 21+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 130.185.101.86

Who owns the IP address 130.185.101.86?

130.185.101.86 is registered to Pelephone Communications Ltd.. The address falls within the 130.185.96.0/21 network block. Registration is held at ARIN.

Where is 130.185.101.86 located?

Geolocation data places 130.185.101.86 in Frankfurt. The local time zone is Asia/Jerusalem. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 130.185.101.86 malicious or safe?

130.185.101.86 currently carries a high risk assessment, meaning indicators associated with malicious or abusive activity have been observed. This assessment is generated from continuously collected signals and can change over time.

What ports are open on 130.185.101.86?

Responsive ports observed on 130.185.101.86 include 80, 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.

🏘️ Related IP Addresses

Nearby addresses in 130.185.96.0/21

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.