# IP Intelligence Briefing: 176.115.251.18/32
Date: 2026-07-23
Classification: High Risk
Risk Score: 70/100
---
## Executive Summary
IP address 176.115.251.18 is classified as High Risk with a risk score of 70/100. The IP belongs to the NETSYSTEM-NET network (AS198766) under ART-COM-MNT and is associated with 4 DNS blacklist entries. The IP shows no open services, indicating firewall protection or non-service role. No malicious campaigns or known attacker indicators were detected.
---
## Network Ownership & Geolocation
- ASN: 198766 (NETSYSTEM-NET)
- Organization: ART-COM-MNT
- CIDR Block: 176.115.240.0/20
- Primary Geolocation: Germany (DE), Berlin
- RIR: RIPE
- PTR Hostname: 176.115.251.18.ip.netsystem.net.pl
- Abuse Contact: biuro@netsystem.net.pl
Geolocation consensus shows inconsistency between Germany (DE) and Poland (PL) in historical observations, with geo-plausibility validation flagged as false. This geographic discrepancy warrants additional verification during incident investigation.
---
## Threat Indicators
- DNSBL Listed: 4 of 8 total lists
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Open Ports: None detected (Firewalled / No Services)
- Campaign Matches: 0
- Correlated IPs: 0
---
## Neighborhood Analysis
The /24 subnet (176.115.251.18/24) shows:
- Abuse Density: 0%
- Classification: Clean
- Active Siblings: 0
- Threat Siblings: 0
- Total Siblings: 1
The neighborhood exhibits minimal abuse activity, suggesting this IP may be flagged based on specific historical signals rather than broader subnet compromise.
---
## Temporal Analysis
- Total Observations: 17
- Ownership Changes: 0
- Threat Persistence Days: 0
- Persistently Malicious: No
- Route Stability: Unstable (isRouteStable: false)
- Route Changes (30d): 0
Recent activity indicates this IP has not demonstrated persistent malicious behavior over extended observation periods.
---
## Recommended Actions
Firewall Rules
| Platform | Rule |
|---|---|
| **iptables** | `iptables -A INPUT -s 176.115.251.18 -j DROP` |
| **nftables** | `nft add rule inet filter input ip saddr 176.115.251.18 drop` |
| **nginx** | `deny 176.115.251.18;` |
| **pfSense** | `176.115.251.18/32` |
WAF/Cloud Rules
- Cloudflare WAF: Block IP 176.115.251.18 (Expression: `ip.src eq 176.115.251.18`)
- AWS WAF: Add 176.115.251.18/32 to rule set
Monitoring Recommendations
- Increase logging verbosity and review recent activity from this IP (High severity)
- Monitor for any connection attempts, even if no services are actively listening
- Verify geo-location discrepancies during investigation
---
## Intelligence Assessment
This IP presents a moderate-to-high risk profile primarily due to DNSBL listings and elevated risk scoring. While no active malicious services or campaigns were detected, the high risk score warrants defensive posture. The IP's network role appears to be firewalled with no accessible services, which may indicate it is a reserved or internal address being scanned/probed.
Recommended Response: Implement blocking rules while maintaining logging for forensic analysis. Monitor for any behavioral changes or emergence of services on this address.
---
*Report generated by IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | ART-COM-MNT |
| ASN | AS198766 |
| Network Name | NETSYSTEM-NET |
| CIDR Block | 176.115.240.0/20 |
| RIR | RIPE |
| Country | PL |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | 176.115.251.18.ip.netsystem.net.pl |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 176.115.251.18.ip.netsystem.net.pl |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | — |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS198766 |
| Network Prefix | 176.115.240.0/20 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 4% | 1 | 1 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-03 23:05:14 UTC |
| Last Seen | 2026-08-22 15:15:08 UTC |
| Profile Built | 2026-08-29 10:34:17 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 176.115.251.18
Who owns the IP address 176.115.251.18?
176.115.251.18 is registered to ART-COM-MNT. The address falls within the 176.115.240.0/20 network block. Registration is held at RIPE.
Where is 176.115.251.18 located?
Geolocation data places 176.115.251.18 in Brzesko, Lesser Poland, Poland. The local time zone is Europe/Warsaw. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 176.115.251.18 malicious or safe?
176.115.251.18 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 176.115.251.18?
The reverse DNS (PTR) record for 176.115.251.18 is 176.115.251.18.ip.netsystem.net.pl. This hostname is not forward-confirmed, so it should be treated as a weak signal.
What ports are open on 176.115.251.18?
Responsive ports observed on 176.115.251.18 include 443. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.