# Intelligence Briefing: IP 144.31.81.21/32
Date: 2026-06-25
Classification: Moderate Risk
Status: Active Threat Indicator
---
## Executive Summary
IP 144.31.81.21 is a German-hosted colocation server (ASN 210546, Cloud Hosting Solutions NOC) flagged as a known attacker with moderate risk scoring (59/100). The address is associated with colocation infrastructure, currently firewalled with no open services, but maintains a threat observation history and blacklist presence.
---
## Threat Profile
- Risk Score: 59 (Moderate Risk)
- Operator Score: 0.1304 (Minimal)
- Known Attacker: Yes
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 1 active listing
- DNSBL Listed: 2 of 8 total lists
- Infrastructure Type: Colocation Hosting
- Network Role: Firewalled / No Services
## Geolocation
- Country: Germany (DE)
- Region: Europe/Berlin timezone
- ASN: 210546
- Organization: Cloud Hosting Solutions NOC
- CIDR Block: 144.31.81.0/24
---
## Observation History
The IP has generated 17 observations over the monitoring period. Key temporal indicators:
- 2026-06-04: High-severity blacklist listings detected across 8 total lists (2 active at time of observation)
- 2026-06-25: Recent operator score reduced to 0 (Minimal), indicating stabilized or mitigated threat activity
- Threat Persistence: 0 days (non-persistent threat actor)
- Threat Observation Count: 1 persistent observation
---
## Network Relationships
- Control Plane: BGP prefix 144.31.81.0/24 (AS210546)
- Route Stability: Not stable (route changes observed in 30-day window)
- Related Networks: All 16 relationship entries point to AS199785-DE-iPv4 (same network classification)
- Network Classification: Same network associations with no anomalous infrastructure links
---
## Subnet Neighborhood Analysis
- Subnet: 144.31.81.0/24
- Abuse Density: 1 (low-to-moderate)
- Classification: Mostly clean
- Threat Siblings: 1 identified
- Active Siblings: 0
- Inherited Risk: 2
---
## Technical Services
- Open Ports: None detected
- TLS Certificate: None
- HTTP Title: None
- DNS PTR Records: None
- Forward Resolution: 0 hostnames
- Email Authentication: No SPF/DMARC records
---
## Recommended Actions
Based on the risk profile, the following defensive measures are recommended:
1. Firewall Rules: Block outbound connections from 144.31.81.0/24 to known malicious destinations
2. Monitoring: Add IP to threat intelligence watchlist for correlation with other observed indicators
3. DNSBL Check: Implement DNSBL filtering for the 2 active blacklist sources
4. Traffic Analysis: Monitor for any new service openings on this previously firewalled infrastructure
5. Reputation Scoring: Continue monitoring operator score trends (recent reduction to 0.1304)
---
## Intelligence Assessment
This IP represents a low-to-moderate risk threat actor operating from German colocation infrastructure. The historical blacklist presence suggests prior malicious activity, though recent operator scoring indicates reduced threat activity. The subnet shows minimal abuse density, suggesting the threat is isolated rather than systemic. SOC teams should treat this as a known bad actor but with reduced immediate threat level.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Cloud Hosting Solutions NOC |
| ASN | AS210546 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 24% | 2 | 3 |
| reputation | 19% | 1 | 3 |
| geolocation | 24% | 2 | 3 |
| Overall | 19% | 9 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:05:37 UTC |
| Last Seen | 2026-06-25 00:52:24 UTC |
| Profile Built | 2026-06-25 00:57:37 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 18 |
Full dossier details are available via our API.