## IP Intelligence Briefing: 146.158.118.252
Classification: MODERATE RISK โ Monitoring Recommended
Date: Current Intelligence Cycle
Prepared For: SOC Analysts
---
Executive Summary
IP 146.158.118.252 presents a moderate risk profile (65/100) with no active threat indicators. The address is owned by SM Ltd. NOC (ASN 210616) within the SIBMEDVED-NET network block (146.158.96.0/19) located in Krasnodar Krai, Russia. While the IP is geolocated to Russia and listed on 3 of 8 DNSBLs, comprehensive threat scanning reveals no malicious activity, open services, or known campaigns.
---
Key Intelligence Indicators
Risk Profile:
- Risk Score: 65/100 (Moderate)
- Provider/Authority Scores: 0/0
- Primary Risk Driver: DNSBL listings (3/8 total)
- No Tor exit node, known attacker, or spam source indicators
Network Attributes:
- ASN: 210616 | Organization: SM Ltd. NOC
- Network Block: 146.158.96.0/19
- BGP Prefix: 146.158.118.0/23
- Route Stability: Unstable (isRouteStable: false)
- Control Plane Operator Score: 0.1304 (Minimal)
Geolocation:
- Country: RU (Russia)
- Region: Krasnodar Krai
- Geo Validation: Blocked (ICMP restrictions)
- Geo Plausibility: Confirmed via consensus
Service State:
- Open Ports: None detected
- DNS Resolution: Forward resolution not confirmed
- Network Role: Firewalled / No Services
- Infrastructure Type: Not CDN, proxy, cloud, hosting, or residential
---
Neighborhood Analysis
The /24 subnet (146.158.118.0/24) shows clean characteristics:
- Abuse Density: 0
- Threat Siblings: 0
- Active Siblings: 1
- Risk Distribution: No high/medium risk neighbors detected
- Classification: Clean
---
Observation History (16 Signals)
Recent monitoring indicates:
- Network Classification: Consistently classified as "clean" with 0 abuse density
- Port Scanning: No open ports detected; scan activity observed but no services running
- Traceroute: 30-hop path with target unreachable (timed out)
- Ownership: No ownership changes detected; not persistently malicious
- Temporal: 0 threat observation count; threat persistence days: 0
---
Related Entities
Relationship graph reveals only network-level associations:
- Same Network: SIBMEDVED-NET (5 relationship entries)
- No certificate, hostname, or organizational relationships beyond network block
---
Recommended Actions
Immediate:
- Increase logging verbosity for this IP
- Review recent activity patterns in SIEM
Firewall Rules (Recommended):
```bash
# iptables
iptables -A INPUT -s 146.158.118.252 -j DROP
# nftables
nft add rule inet filter input ip saddr 146.158.118.252 drop
```
WAF Integration:
- Cloudflare WAF: Block 146.158.118.252 (filter: ip.src eq 146.158.118.252)
- AWS WAF: Add 146.158.118.252/32 to block set
- pfSense: Add 146.158.118.252/32 to firewall rule
Note: These recommendations are probabilistic and should be combined with additional context before enforcement.
---
Analyst Assessment
This IP requires monitoring rather than immediate blocking. The moderate risk score stems from DNSBL listings without corroborating threat activity. The network shows no active services, and the neighborhood is clean. Monitor for changes in service state, ownership, or risk indicators. Consider reviewing if this IP appears in connection logs with your environment; if no legitimate traffic exists, blocking may be justified despite the lack of confirmed malicious activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | SM Ltd. NOC |
| ASN | AS210616 |
| Network Name | SIBMEDVED-NET |
| CIDR Block | 146.158.96.0/19 |
| RIR | ARIN |
| Country | RU |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 20% | 5 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-29 22:49:37 UTC |
| Last Seen | 2026-07-31 19:32:10 UTC |
| Profile Built | 2026-07-30 23:53:03 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.