# IP Intelligence Briefing: 130.185.101.86/32
Classification: High Risk
Report Date: 2026-07-28
Analyst: IPDebrief Intelligence Team
---
## Executive Summary
IP 130.185.101.86 is classified as High Risk (80/100) and should be treated as suspicious. The address belongs to Pelephone Communications Ltd. (AS16116) within Israel. Despite legitimate network ownership, the IP exhibits elevated risk characteristics including DNSBL listing and misconfigured TLS certificates. Immediate monitoring and blocking are recommended.
---
## Ownership & Infrastructure
| Attribute | Value |
|---|---|
| **Organization** | Pelephone Communications Ltd. |
| **AS Number** | 16116 |
| **Network** | IL-PELEPHONE-20111024 / 130.185.96.0/21 |
| **Location** | Israel (31.05°N, 34.85°E) |
| **Registration** | ARIN |
| **RIR** | ARIN |
The IP is assigned to Pelephone's telecommunications infrastructure and operates as a web server within the /21 CIDR block.
---
## Risk Assessment
- Risk Score: 80/100 (High Risk)
- Provider Score: 0
- Authority Score: 0
- Stability Score: 0
- DNSBL Listed: 4/8 total lists
- Abuse Confidence Score: Not available
Key Risk Indicators:
- DNSBL listing on 4 blacklist feeds
- Self-signed TLS certificate (CN=localhost)
- Outdated web server software (lighttpd/1.4.53)
- Elevated risk score despite clean neighborhood classification
---
## Network Services & Fingerprinting
| Port | Protocol | Service | Details |
|---|---|---|---|
| 443 | TCP | HTTPS | - |
| 22 | TCP | SSH | dropbear_2018.76 |
TLS Configuration:
- Certificate Issuer: CN=localhost
- Certificate Subject: CN=localhost
- Certificate Status: Self-signed/misconfigured
HTTP Banner:
- Server: lighttpd/1.4.53
HTTP Status: 200 OK
---
## Historical Observation Analysis
Total Observations: 19 signals recorded
Recent Activity (July 28, 2026):
- Geolocation signals confirmed Israel region with 52% confidence
- Subnet classification: Clean
- Network role: Web Server (confirmed)
- Ownership stability: No changes detected (0 changes)
- Threat persistence: None observed
- Persistent malicious activity: False
Temporal Analysis:
- Ownership Changes: 0
- Threat Observation Count: 0
- Threat Persistence Days: 0
- Classification: Not persistently malicious
---
## Network Neighborhood
Subnet: 130.185.101.86/24
| Metric | Value |
|---|---|
| Total Siblings | 2 |
| Active Siblings | 1 |
| Threat Siblings | 0 |
| Abuse Density | 0 |
| Subnet Classification | Clean |
Neighbor Analysis:
- 130.185.101.32: Risk Score 0, Authority Score 50 (low risk)
The IP's immediate subnet shows minimal abuse activity with 0 threat siblings, suggesting the risk may be isolated to this specific address.
---
## Relationship Graph
Detected Relationships: 5
- All relationships link to "IL-PELEPHONE-20111024" (same network)
- No connections to external organizations, hostnames, or certificates detected
- Relationships confirm network ownership within Pelephone infrastructure
---
## Threat Intelligence Indicators
| Indicator Type | Status | Details |
|---|---|---|
| Tor Exit Node | No | False |
| Known Attacker | No | False |
| Spam Source | No | False |
| Campaign Likelihood | None | 0 cert matches, 0 banner matches |
| Correlated IPs | 0 | No correlated addresses |
Blacklist Status: 4 DNSBL lists active
---
## Recommended Actions
Immediate Firewall Rules
iptables:
```bash
iptables -A INPUT -s 130.185.101.86 -j DROP
```
nftables:
```bash
nft add rule inet filter input ip saddr 130.185.101.86 drop
```
nginx:
```nginx
deny 130.185.101.86;
```
pfSense:
```
130.185.101.86/32
```
Cloudflare WAF:
```json
{
"description": "Block 130.185.101.86 — IPDebrief risk score 80",
"action": "block",
"filter": {
"expression": "ip.src eq 130.185.101.86"
}
}
```
AWS WAF:
```json
{
"Addresses": ["130.185.101.86/32"],
"Description": "IPDebrief risk 80"
}
```
Monitoring Recommendations
Critical:
- Increase logging verbosity for all traffic from this IP
- Review recent activity patterns and connection logs
- Monitor for any changes in threat indicators over next 24-48 hours
---
## Intelligence Narrative
IP 130.185.101.86 presents a High Risk profile despite being assigned to legitimate telecommunications infrastructure (Pelephone Communications). The elevated risk score (80/100) is primarily driven by DNSBL listing activity and misconfigured security certificates. The IP operates as a web server with SSH access enabled, running outdated lighttpd software.
Historical analysis shows the IP is not persistently malicious with no observed threat persistence or campaign correlations. The immediate subnet (130.185.101.0/24) maintains a clean classification with minimal abuse density. However, the specific risk indicators—particularly the 4 DNSBL listings and self-signed TLS certificate—warrant immediate defensive action.
Assessment: The risk appears isolated to this single IP rather than representing broader infrastructure compromise. SOC teams should implement blocking rules while maintaining monitoring for potential activity escalation.
---
## Conclusion
This intelligence report provides a comprehensive threat profile for IP 130.185.101.86/32. The High Risk classification (80/100) is supported by DNSBL listing activity and misconfigured TLS certificates. While the subnet shows minimal abuse density, the specific indicators associated with this address warrant immediate defensive action.
Priority: Medium-High
Recommended Response Time: 24 hours
Classification: Active Threat Indicator
---
## Appendices
Data Sources:
- IPDebrief Profile Analysis
- IPDebrief Historical Observations (19 signals)
- IPDebrief Relationship Mapping
- IPDebrief Neighborhood Analysis
- IPDebrief Actionable Recommendations
Last Updated: 2026-07-28
Report ID: IPR-20260728-13018510186
---
*End of Intelligence Briefing*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Pelephone Communications Ltd. |
| ASN | AS16116 |
| Network Name | IL-PELEPHONE-20111024 |
| CIDR Block | 130.185.96.0/21 |
| RIR | ARIN |
| Country | IL |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 0% (None) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 443 | https | tcp | — |
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | 2023-08-01T08:19:07+00:00 |
| Valid Until | 2033-07-29T08:19:07+00:00 |
| TLS Protocol | Tls12 |
| Cipher Suite | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 3650 days |
🛡️ Public Network Snapshot
| Origin ASN | AS16116 |
| Network Prefix | 130.185.96.0/21 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Not detected |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 23% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 34% | 2 | 5 |
| ownership | 23% | 2 | 4 |
| reputation | 20% | 1 | 3 |
| geolocation | 23% | 2 | 4 |
| Overall | 22% | 10 | 21 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-16 22:51:32 UTC |
| Last Seen | 2026-09-29 20:35:07 UTC |
| Profile Built | 2026-09-29 09:08:10 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 32 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 130.185.101.86
Who owns the IP address 130.185.101.86?
130.185.101.86 is registered to Pelephone Communications Ltd.. The address falls within the 130.185.96.0/21 network block. Registration is held at ARIN.
Where is 130.185.101.86 located?
Geolocation data places 130.185.101.86 in Frankfurt. The local time zone is Asia/Jerusalem. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 130.185.101.86 malicious or safe?
130.185.101.86 currently carries a high risk assessment, meaning indicators associated with malicious or abusive activity have been observed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 130.185.101.86?
Responsive ports observed on 130.185.101.86 include 80, 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.