# IP INTELLIGENCE BRIEFING
Target: 155.133.201.174/32
Classification: DEFENSIVE INTELLIGENCE
Date: Current
Status: LOW RISK
---
## EXECUTIVE SUMMARY
Target IP 155.133.201.174 presents a LOW RISK threat profile with a risk score of 0. No active threat indicators, blacklist entries, or malicious campaign associations detected. The IP operates without open services and is currently firewalled.
---
## OWNERSHIP & INFRASTRUCTURE
- Control Plane Origin: ASN 62365, BGP Prefix 155.133.200.0/21
- Route Stability: False (route changes detected in 30-day window)
- Geolocation: Germany (DE), Saxony region
- Geographic Consensus: Confirmed across 2 sources
- Network Classification: Firewalled / No Services
- Service Status: No open ports detected
- Mobile/Carrier: No mobile carrier association
---
## THREAT INDICATORS
- Risk Score: 0 (Low Risk)
- Abuse Confidence: Not applicable
- Blacklist Status: Not listed (0 entries)
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Threat Feeds: None active
- Known Campaigns: None associated
---
## BEHAVIORAL ANALYSIS
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
- Total Incidents: 0
- Active Attacker: No
- Auto-Banned: No
- Persistence: No persistent malicious activity observed (0 threat persistence days)
---
## NETWORK NEIGHBORHOOD (155.133.201.0/24)
- Subnet Abuse Density: 0 (Minimal)
- Neighbor Count: 2 total IPs analyzed
- Risk Distribution: 1 Low, 0 Medium, 0 High
- Elevated Neighbor: 155.133.201.186 (Risk Score: 25, Authority Score: 50)
- Threat Siblings: 0
---
## OBSERVATION HISTORY (9 Observations)
Most recent activity recorded: 2026-07-27
- Geolocation Signals: Consistent Germany/DE classification, with regional variations between Berlin and Dresden (confidence: 0.70)
- Operator Score: 0.1304 (Label: "Minimal")
- DNSSEC: Valid on reverse zone 174.201.133.155.in-addr.arpa (confidence: 0.90)
- Threat Persistence: None detected
- Ownership Changes: 0 events
---
## RELATIONSHIP GRAPH
- Associated Entities: 0 relationships identified
- Linked Hostnames: None
- Related Organizations: None
- Certificate Associations: None
---
## RECOMMENDED ACTIONS
Based on current risk assessment:
1. MONITORING: Continue standard passive monitoring. No immediate blocking required.
2. FIREWALL RULES: No specific blocking rules recommended. Standard allow/deny policies apply.
3. THREAT INTELLIGENCE:
- No active threat indicators require escalation
- Monitor elevated neighbor 155.133.201.186 for potential cross-contamination
- Route instability (false stable flag) warrants periodic re-verification
4. INCIDENT RESPONSE: No incident response actions required. IP maintains low-risk classification.
---
## CONCLUSION
IP 155.133.201.174 is a low-risk, non-malicious address with no active threat indicators. The subnet shows minimal abuse density with one neighbor exhibiting elevated risk. SOC analysts should continue standard monitoring without requiring immediate defensive actions.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | DESANET-MNT |
| ASN | AS62365 |
| Network Name | ENSO-03 |
| CIDR Block | 155.133.201.0/24 |
| RIR | ARIN |
| Country | DE |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256RSA |
| Validity Period | 24852 days |
🛡️ Public Network Snapshot
| Origin ASN | AS62365 |
| Network Prefix | 155.133.200.0/21 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Enabled |
| HTTP/2 | Not detected |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-12 21:06:18 UTC |
| Last Seen | 2026-09-02 23:51:19 UTC |
| Profile Built | 2026-09-02 23:56:03 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 26 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 155.133.201.174
Who owns the IP address 155.133.201.174?
155.133.201.174 is registered to DESANET-MNT. The address falls within the 155.133.201.0/24 network block. Registration is held at ARIN.
Where is 155.133.201.174 located?
Geolocation data places 155.133.201.174 in Dresden, Saxony, Germany. The local time zone is Europe/Berlin. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 155.133.201.174 malicious or safe?
155.133.201.174 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.