# IP Intelligence Briefing: 176.103.2.180
Classification: Moderate Risk
Analysis Date: Current
Report Type: Single IP Intelligence
---
## Executive Summary
IP address 176.103.2.180 is associated with network operator DIALOGKOM-MNT (ASN 56812) and geolocated to Balakliya, Kharkivs'ka Oblast', Ukraine. The IP carries a moderate risk score of 40 and is currently classified as "Firewalled / No Services" with no active open ports or TLS certificates. While the IP itself shows no direct threat indicators, the surrounding /24 subnet demonstrates mixed traffic patterns with measurable abuse density.
---
## Technical Profile
Ownership & Registration:
- ASN: 56812 (DIALOGKOM-MNT)
- RIR: RIPE
- BGP Prefix: 176.103.0.0/20
- Route Stability: Unstable (false)
- Control Plane Origin: ASN 56812
Geolocation:
- Country: Ukraine (UA)
- Region: Kharkivs'ka Oblast'
- City: Balakliya
- Geographic Confidence: Consensus-based across multiple sources (500km accuracy radius)
Network Classification:
- Infrastructure Type: Non-provider, non-hosting
- Service Purpose: Firewalled / No Services
- DNS Resolution: No PTR records, no forward resolution
- Email Auth: No SPF or DMARC records
---
## Threat Assessment
Current Risk Score: 40 (Moderate)
Threat Indicators:
- Blacklist Status: Listed on 2 of 8 DNSBLs
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Known Campaigns: None correlated
Behavioral Signals:
- Service Enumeration: None detected
- WAF Violations: 0
- Honeypot Hits: 0
- Total Incidents: 0
Operator Assessment: 0.1304 (Minimal)
---
## Neighborhood Analysis
Subnet: 176.103.2.0/24
Total Siblings: 54 IPs analyzed
Abuse Density: 0.037 (low-moderate)
Risk Distribution:
- High Risk: 2 IPs
- Medium Risk: 33 IPs
- Low Risk: 19 IPs
Key Observations:
- Multiple sibling IPs with risk scores of 40-55
- Neighborhood classification: Mixed
- Inherited risk score: 14
- 14 threat-related siblings identified
---
## Historical Trajectory
Observation Count: 17 historical signals
Temporal Analysis:
- Ownership changes: 0
- Threat persistence: No persistent malicious activity detected
- Threat observation count: 1
- Is persistently malicious: No
Recent observations (June 2026) indicate stable routing and geolocation data with no significant degradation in signal quality or increased threat activity over the observation window.
---
## Relationship Graph
Primary Association: DIALOG-NET network (20 relationship entries)
- All detected relationships map to the same network entity
- No certificate associations detected
- No correlated IP addresses beyond subnet boundaries
---
## Recommended Actions
Firewall Blocking Rules:
*iptables:*
```
iptables -A INPUT -s 176.103.2.180 -j DROP
```
*nftables:*
```
nft add rule inet filter input ip saddr 176.103.2.180 drop
```
*nginx:*
```
deny 176.103.2.180;
```
*Cloudflare WAF:*
```json
{
"description": "Block 176.103.2.180 β IPDebrief risk score 40",
"action": "block",
"filter": {"expression": "ip.src eq 176.103.2.180"}
}
```
*AWS WAF:*
```json
{
"Addresses": ["176.103.2.180/32"],
"Description": "IPDebrief risk 40"
}
```
Recommendation: While the IP currently shows no active exploitation indicators, the moderate risk score (40) combined with subnet-level abuse density warrants blocking at the perimeter. Consider implementing rate-limiting for the broader /24 subnet if traffic patterns warrant additional scrutiny.
---
Disclaimer: This intelligence is derived from IPDebrief platform data and should be validated against additional threat indicators before operational implementation.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DIALOGKOM-MNT |
| ASN | AS56812 |
| Network Name | β |
| CIDR Block | β |
| RIR | RIPE |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 20% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 20% | 2 | 3 |
| reputation | 19% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 17% | 9 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-08 23:18:12 UTC |
| Last Seen | 2026-06-25 11:13:34 UTC |
| Profile Built | 2026-06-25 11:28:19 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 20 |
Full dossier details are available via our API.