## IP Intelligence Briefing: 151.115.167.146
Executive Summary
IP address 151.115.167.146 is a low-risk (Score: 25) cloud infrastructure endpoint hosted on Scaleway's French network infrastructure. The IP demonstrates minimal threat activity with no known malicious indicators, though it warrants monitoring due to unusual DNS resolution patterns and elevated neighborhood abuse density.
Infrastructure Profile
- Network: Scaleway (ASN 12876)
- Infrastructure Type: CloudCompute / Hosting
- Geolocation: Italy (IT) / Paris region (IDF)
- BGP Prefix: 151.115.160.0/19
- Service Status: No open ports; service classification: "Firewalled / No Services"
Threat Assessment
- Overall Risk Score: 25 (Low Risk)
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Blacklist Count: 0
- DNSBL Listed: 1 of 8 lists
- Operator Score: 0.1304 (Minimal)
Network Neighborhood Analysis
The /24 subnet (151.115.167.0/24) shows moderate abuse density (0.6) with 5 total siblings and 3 active siblings. Neighbor IP risk distribution is predominantly low-risk (4/4 neighbors with Risk Score 25). This suggests the subnet hosts legitimate cloud infrastructure with occasional abuse activity from sibling IPs.
DNS Intelligence
- PTR Record: 146-167-115-151.instance.scw.eu (Scaleway instance)
- Forward Resolution: moramirathrel.clisporanten.pro (suspicious domain pattern)
- Forward Resolution Confirmed: No
- Hosted Domains: 0
Temporal Analysis
- Observation History: 25 signals observed
- Recent Trends:
- June 2026: Abuse density increased from 0.6 to 1.0
- Inherited risk increased from 7 to 12
- Classification remained "mostly_clean"
- Threat Persistence: 0 days (not persistently malicious)
Relationship Graph
45 relationships identified, primarily network-level associations (SCALEWAY-MIL). No significant hostname, organization, or certificate relationships detected.
Recommended Actions
- Monitoring: No immediate blocking required; low-risk profile
- Firewall Rules: Not required based on current risk assessment
- Investigation Priority: Monitor forward DNS resolution to moramirathrel.clisporanten.pro
SOC Analyst Notes
This IP represents Scaleway cloud infrastructure with a low-risk profile. The forward DNS resolution to a suspicious-sounding domain (moramirathrel.clisporanten.pro) warrants periodic review, though no active threat indicators are present. The subnet's elevated abuse density suggests neighboring IPs may require attention during incident response. Maintain baseline monitoring; no immediate defensive action required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | ONLINE-NET-MNT |
| ASN | AS12876 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 146-167-115-151.instance.scw.eu |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | 146-167-115-151.rev.scw.cloud |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 29% | 2 | 4 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 25% | 2 | 2 |
| Overall | 26% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-14 13:23:41 UTC |
| Last Seen | 2026-06-28 00:44:20 UTC |
| Profile Built | 2026-06-28 18:49:42 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 29 |
Full dossier details are available via our API.