# IP Intelligence Briefing: 147.161.3.25/32
Classification: Low Risk with Elevated Neighborhood Context
Date: 2026-07-25
Risk Score: 25/100
---
## Executive Summary
IP 147.161.3.25 presents as a low-risk endpoint (risk score 25) operating as a web server within the 147.161.3.0/24 subnet. However, neighborhood analysis reveals 4 sibling IPs with consistent medium-high risk scores (66), indicating elevated threat activity in the /24 block. The target IP lacks registered ASN/organization data and is listed on 1 of 8 DNS blacklists.
---
## Technical Profile
Geolocation: Czech Republic (CZ), Prague timezone
Control Plane: BGP Prefix 147.161.3.0/24, Origin ASN 399486
Route Stability: Unstable (isRouteStable: false)
DNSBL Status: Listed on 1 of 8 reputation lists
Network Classification: Web Server / Provider Infrastructure
Open Services:
- Port 443/TCP: HTTPS
- Port 22/TCP: SSH (OpenSSH 8.9p1 Ubuntu-3ubuntu0.16)
TLS Certificate Analysis:
- Subject: CN=www.k4ynzrbwdxjigup6yi.net
- Issuer: CN=www.bhdgj2llikcqd5.com
- Self-signed certificate detected
- Certificate validity period: Pending validation
---
## Neighborhood Assessment (147.161.3.0/24)
Abuse Density: 0.8 (Elevated)
Active Siblings: 4 of 5 total
Threat Siblings: 4
High-Risk Neighbors:
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 147.161.3.20 | 66 | 50 |
| 147.161.3.31 | 66 | 50 |
| 147.161.3.32 | 66 | 50 |
| 147.161.3.33 | 66 | 50 |
All four active siblings in the subnet share identical risk profiles, suggesting coordinated infrastructure or shared hosting environment.
---
## Historical Observations
Total Observations: 18
Latest Signal Date: 2026-07-25
Observed Signals:
- DNSSEC validation signals (operator score: 0.1304)
- Connection failures on HTTPS endpoints
- SSH banner enumeration (OpenSSH 8.9p1 Ubuntu)
- TLS 1.3 cipher suite: TLS_AES_256_GCM_SHA384
No persistent threat activity detected over observation window.
---
## Relationship Graph
No direct relationships identified (subnets, hostnames, organizations, certificates).
---
## Recommended Actions
1. Monitor Subnet Activity: Elevated risk scores (66) across all neighbor IPs suggest potential compromised infrastructure in 147.161.3.0/24. Correlate traffic patterns with sibling IPs.
2. TLS Certificate Review: Self-signed certificate with non-standard domain names warrants investigation. Certificate does not align with established domain reputation.
3. SSH Exposure: Port 22 is open. Consider implementing fail2ban or SSH key-only authentication if not already configured.
4. DNSBL Verification: Confirm current blacklist status. Single listing suggests minor reputation issues but does not indicate active malware distribution.
5. Route Monitoring: Unstable BGP routing may indicate hosting environment changes or infrastructure migration.
---
## Threat Indicators
Current Status: No active threat indicators
Campaign Correlation: None detected
Tor Exit Node: No
Known Attacker: No
Spam Source: No
---
Analyst Notes: The IP presents a low-risk profile but operates within a high-density risk subnet. Recommend ongoing monitoring of sibling IPs and subnet-wide activity correlation. The self-signed TLS certificate and unstable routing warrant periodic reassessment.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | netutils-mnt |
| ASN | AS399486 |
| Network Name | Srvnet_LTD |
| CIDR Block | 147.161.3.0/24 |
| RIR | ARIN |
| Country | EU |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS399486 |
| Network Prefix | 147.161.3.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 5 |
| routing | 8% | 1 | 1 |
| services | 17% | 2 | 3 |
| ownership | 17% | 2 | 3 |
| reputation | 14% | 1 | 3 |
| geolocation | 17% | 2 | 3 |
| Overall | 16% | 10 | 18 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-16 15:02:03 UTC |
| Last Seen | 2026-09-03 17:55:40 UTC |
| Profile Built | 2026-09-03 18:03:02 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 29 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 147.161.3.25
Who owns the IP address 147.161.3.25?
147.161.3.25 is registered to netutils-mnt. The address falls within the 147.161.3.0/24 network block. Registration is held at ARIN.
Where is 147.161.3.25 located?
Geolocation data places 147.161.3.25 in Amsterdam, NH, Czechia. The local time zone is Europe/Prague. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 147.161.3.25 malicious or safe?
147.161.3.25 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
Is 147.161.3.25 a VPN, proxy, or data center address?
147.161.3.25 is classified as the Tor network based on network ownership and behavioural analysis.