# IP Intelligence Briefing: 173.225.111.78/32
## Executive Summary
IP address 173.225.111.78 is a moderate-risk (55/100) infrastructure endpoint owned by Interserver, Inc (ASN 19318). The address hosts within the 173.225.96.0/20 block and presents elevated risk primarily through open RDP services and DNSBL listings. No active threat indicators were detected, but monitoring is recommended due to service exposure.
---
## Infrastructure Profile
Ownership: Interserver, Inc | ASN 19318 | Network: INTER-83
Registration: ARIN | CIDR Block: 173.225.96.0/20
Geolocation: United States (2500km accuracy radius)
Network Role: Single-Service Host | Not classified as CDN, Cloud, VPN, or Proxy
---
## Risk Assessment
Overall Risk Score: 55 (Moderate)
Abuse Confidence: Not applicable
DNSBL Listings: 3 of 8 total lists
Operator Score: 0.1304 (Minimal)
Risk Factors Identified:
- Elevated risk score (55/100)
- 3 DNSBL blacklist entries
- Non-stable BGP route (route changes detected)
- Open RDP port 3389 exposed to internet
Mitigating Factors:
- No known attacker or spam source flags
- Not a Tor exit node
- Clean subnet classification (abuse density: 0)
- No persistent malicious behavior observed
---
## Network Services
Open Ports:
- TCP/3389 (RDP) - Remote Desktop Protocol
DNS Analysis:
- No forward resolution
- No hosted domains
- No email authentication (SPF/DMARC)
- DNSSEC validated: Yes
---
## Threat Intelligence
Threat Indicators: None detected
Known Campaigns: None
Blacklist Sources: 3 listings (specific feeds not enumerated)
Campaign Likelihood: Not correlated
Observation History: 16 signals observed
- Recent activity: Port scanning detected (2026-07-30)
- No ownership changes recorded
- Threat persistence: 0 days
- Persistently malicious: No
---
## Neighborhood Analysis
Subnet: 173.225.111.78/24
Abuse Density: 0 (Clean)
Neighbor Count: 0
Threat Siblings: 0
Classification: Clean
---
## Recommended Actions
Immediate Recommendations
1. Monitoring: Increase logging verbosity and review recent activity from this IP
2. Firewall: Consider blocking or rate-limiting based on organizational policy
Platform-Specific Rules
iptables:
```
iptables -A INPUT -s 173.225.111.78 -j DROP
```
nftables:
```
nft add rule inet filter input ip saddr 173.225.111.78 drop
```
nginx:
```
deny 173.225.111.78;
```
pfSense:
```
173.225.111.78/32
```
Cloudflare WAF:
```json
{"description":"Block 173.225.111.78 β IPDebrief risk score 55","action":"block","filter":{"expression":"ip.src eq 173.225.111.78"}}
```
AWS WAF:
```json
{"Addresses":["173.225.111.78/32"],"Description":"IPDebrief risk 55"}
```
---
## Intelligence Narrative
The IP 173.225.111.78 is a commercial hosting endpoint that presents moderate risk due to exposed RDP services and DNSBL listings. While no active attack signatures were detected, the open RDP port represents a potential lateral movement vector if compromised. The subnet shows zero abuse density, indicating this is an isolated risk rather than part of a coordinated campaign. SOC analysts should monitor for port scanning activity and consider blocking based on RDP exposure policies. The IP's BGP route instability suggests potential hosting infrastructure changes that may affect long-term threat assessment.
Classification: Moderate Risk - Monitor
Last Updated: 2026-07-30
Data Source: IPDebrief Intelligence Platform
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Interserver, Inc |
| ASN | AS19318 |
| Network Name | INTER-83 |
| CIDR Block | 173.225.96.0/20 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 3389 | rdp | tcp | β |
| Closed Ports | 22, 25, 80, 443, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 20% | 5 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-26 09:12:03 UTC |
| Last Seen | 2026-08-13 06:44:06 UTC |
| Profile Built | 2026-07-30 07:24:51 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.