IPDebrief

147.189.169.69

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 147.189.169.69/32

## Executive Summary

IP address 147.189.169.69 is classified as High Risk (Score: 80/100) and is associated with ASN 206996, organization ZapHostingHolding. The IP shows no active services, no open ports, and no forward DNS resolution. Despite the high risk classification, the IP demonstrates no threat indicators, zero blacklist entries, and zero known campaign affiliations.

## Network Classification

The IP resides in the 147.189.168.0/21 CIDR block under Marvin Kluck's ownership. Network classification indicates "Firewalled / No Services" with no evidence of hosting, proxy, VPN, CDN, or cloud infrastructure. Control plane analysis shows the IP is not route stable and has an operator score of 0.1304 (labeled "Minimal").

## Geolocation and Infrastructure

Geolocation data places the IP in Germany (DE) with coordinates 51.17°N, 10.45°E, though ICMP validation was blocked during testing. The IP has no associated PTR hostnames, no forward-resolved hostnames, and zero hosted domains. No TLS certificates or HTTP titles were observed.

## Threat Indicators and Reputation

Threat analysis reveals no active indicators: zero known attackers, zero spam sources, zero Tor exit node activity. The IP has zero blacklist counts despite showing 4 DNSBL listings within the control plane. No threat feeds flagged the IP, and no known campaigns were correlated.

## Historical Observations

Seventeen historical observations recorded between 2026-07-31 show consistent subnet classification as "clean" with an abuse density of 0. Geolocation signals maintained consistency with multi-signal inference methods. No temporal changes in ownership or threat persistence were observed.

## Network Neighborhood Analysis

The /24 subnet 147.189.169.69/24 contains 3 total sibling IPs, with 2 currently active and 0 threat siblings. Two neighboring IPs were identified:

The subnet abuse density is 0, indicating no inherited risk from neighbors. The target IP remains isolated from known threat siblings.

## Recommended Actions

Based on the elevated risk score of 80/100, the following actions are recommended:

1. Monitoring: Increase logging verbosity and review recent activity from this IP

2. Firewall Rules: Implement blocking across infrastructure:

- iptables: `iptables -A INPUT -s 147.189.169.69 -j DROP`

- nftables: `nft add rule inet filter input ip saddr 147.189.169.69 drop`

- nginx: `deny 147.189.169.69;`

- pfSense: `147.189.169.69/32`

- Cloudflare WAF: Block with expression `ip.src eq 147.189.169.69`

- AWS WAF: Add 147.189.169.69/32 to rule set

## Intelligence Assessment

Despite the high risk classification, the IP demonstrates minimal malicious characteristics. The high risk score appears attributable to control plane instability and minimal operator score rather than active threat behavior. No correlation with known malicious campaigns or attack patterns was found. The IP maintains a clean neighborhood profile with no threat siblings in the /24 subnet.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฉ๐Ÿ‡ช Germany
Regionโ€”
Cityโ€”
TimezoneEurope/Berlin
Latitude51.17
Longitude10.45

๐Ÿข Ownership & Registration

OrganizationMarvin Kluck
ASNAS206996
Network NameZapHostingHolding
CIDR Block147.189.168.0/21
RIRARIN
CountryDE
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown โ€” Insufficient routing data to classify
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
25%
12
reputation
0%
00
geolocation
25%
11
Overall20%56
Coverage: 5/6 dimensions ยท Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-07-30 11:03:13 UTC
Last Seen2026-08-01 04:25:05 UTC
Profile Built2026-07-31 01:59:58 UTC
Data FreshnessLive
Signal Types18
Total Observations18
๐Ÿ” 18 signal types ยท 18 observations collected
This report is generated from 18+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.