IP INTELLIGENCE BRIEFING: 151.240.100.190/32
Classification: LOW RISK
Date: 2026-07-30
---
EXECUTIVE SUMMARY
IP address 151.240.100.190 presents a low-risk profile (Risk Score: 25/100) with no active threat indicators. The address is associated with a London-based network block and exhibits minimal threat persistence. No actionable intelligence requires immediate defensive response.
---
NETWORK OWNERSHIP & GEOLOCATION
- ASN: 215114 (netutils-mnt)
- Network Block: 151.240.100.0/24 (NET-151-240-100-0-24)
- Geolocation: London, United Kingdom (GB)
- RIR: RIPE
- Registration: Abusive contact available via RDAP
INFRASTRUCTURE CLASSIFICATION
- Primary Role: Provider/Tor Exit Node
- Infrastructure Type: Unknown
- Cloud/CDN/VPN: Not applicable
- Mobile/Residential: Not identified
---
THREAT ASSESSMENT
- Overall Risk Score: 25 (Low Risk)
- Abuse Confidence: Not elevated
- Blacklist Status: Listed on 1 of 8 DNSBL feeds
- Campaign Indicators: None detected
- Known Attacks: No known attacker or spam source designation
- Tor Exit Node: Classification indicates potential Tor exit node activity
---
SERVICES & EXPOSURE
- Open Ports:
- Port 22/TCP: SSH (OpenSSH_9.2p1 Debian-2+deb12u10)
- Port 80/TCP: HTTP
- HTTP Fingerprint: HTTP/1.0, Response time 287ms
- Security Headers: HSTS, CSP, Permissions Policy: Not present
- Content: robots.txt with "Disallow: /" directive
---
TEMPORAL ANALYSIS
- Observations: 17 signals captured
- Ownership Stability: No ownership changes detected
- Threat Persistence: 0 days (No persistent malicious behavior observed)
- Threat Observation Count: 0
---
NETWORK NEIGHBORHOOD
- Subnet Abuse Density: 0 (Clean classification)
- Active Neighbors: 0
- Threat Siblings: 0
- Overall Subnet Risk: Minimal
---
RELATIONSHIP GRAPH
- Related Entities: Only network-level associations detected
- Organizations: None identified
- Hostnames/Certificates: None discovered
---
HISTORICAL SIGNALS
Recent observations (2026-07-30) show:
- Stable geolocation signals from LHR (London)
- HTTP 200 responses with standard content
- No escalation in threat signals
- No new correlations or campaign activity
---
RECOMMENDED ACTIONS
Based on the low-risk profile and current threat landscape:
1. Monitoring: Continue standard passive monitoring
2. Blocking: No immediate blocking required
3. Rule Generation: No firewall rules recommended at this time
4. Classification: Maintain "Low Risk" designation
---
INTELLIGENCE CONCLUSION
IP 151.240.100.190 demonstrates benign network behavior with no active malicious indicators. The address appears to be part of a stable, low-abuse-density network block in London. No threat correlation exists with known campaigns or attack infrastructure. SOC teams may continue routine monitoring without additional defensive measures.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | netutils-mnt |
| ASN | AS215114 |
| Network Name | NET-151-240-100-0-24 |
| CIDR Block | 151.240.100.0/24 |
| RIR | RIPE |
| Country | FR |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.2p1 Debian-2+deb12u10 |
๐ TLS Certificate
| SANs | None |
| Valid From | 2026-06-30T00:00:00+00:00 |
| Valid Until | 2027-04-20T23:59:59+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 294 days |
| Serial Number | 00E0CF2E77DC69885F |
| Thumbprint | 27C5FBC93FEEF2ED32AED7F178A42B6A0E98FE61 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 60% | 2 | 27 |
| routing | 27% | 2 | 3 |
| services | 33% | 2 | 3 |
| ownership | 37% | 3 | 5 |
| reputation | 26% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 36% | 12 | 44 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-29 22:48:49 UTC |
| Last Seen | 2026-08-13 09:39:35 UTC |
| Profile Built | 2026-08-13 09:52:04 UTC |
| Data Freshness | Live |
| Signal Types | 27 |
| Total Observations | 79 |
Full dossier details are available via our API.