# IP Intelligence Briefing: 176.65.148.93/32
Classification: Moderate Risk
Date: Intelligence compiled from IPDebrief platform data
Primary Indicator: Single IP address with elevated DNSBL listings
---
## Executive Summary
IP address 176.65.148.93/32 is registered to PF-CLOUD-NET-1 (ASN 51396) with a moderate risk profile (score: 40). The address resolves to the pfcloud.network domain in Eygelshoven, Limburg, Netherlands. Current network scans show no open ports or active services. The IP appears on 2 of 8 DNS blacklists, indicating prior reputation issues.
---
## Ownership and Network Details
| Attribute | Value |
|---|---|
| **ASN** | 51396 |
| **Organization** | Admin |
| **Network Name** | PF-CLOUD-NET-1 |
| **CIDR Block** | 176.65.148.0/24 |
| **RIR** | RIPE |
| **Location** | Netherlands (NL), Limburg, Eygelshoven |
| **Coordinates** | 51.68°N, 7.70°E |
| **Timezone** | Europe/Amsterdam |
| **DNS PTR** | 176.65.148.93.ptr.pfcloud.network |
---
## Threat Assessment
Risk Score: 40/100 (Moderate Risk)
Abuse Confidence: Not explicitly scored
Blacklist Status: Listed on 2 of 8 DNSBL feeds
Known Attacker: False
Spam Source: False
Tor Exit Node: False
Threat Indicators:
- No active threat campaign correlations
- Zero open ports detected during service enumeration
- No TLS certificates or HTTP services observed
- Recent DNSBL listings indicate prior reputation degradation
---
## Network Context
Subnet Analysis (176.65.148.0/24):
- Total siblings: 16
- Abuse density: 0
- Risk distribution: 0 high-risk, 3 medium-risk, 13 low-risk
- Inherited risk from subnet: None detected
Notable Neighboring IPs:
- 176.65.148.3 (Risk: 49)
- 176.65.148.133 (Risk: 49)
- 176.65.148.201 (Risk: 40)
---
## Control Plane Observations
| Metric | Value |
|---|---|
| **Origin ASN** | 51396 |
| **BGP Prefix** | 176.65.148.0/24 |
| **Route Stability** | False |
| **DNSSEC Valid** | True |
| **Route Changes (30d)** | 0 |
| **MOAS Status** | False |
| **IRR Consistency** | Not assessed |
---
## Historical Signal Analysis
Observation Count: 17 total signals recorded
Most Recent Activity: 2026-07-29
Signal Timeline Highlights:
- Geographic inference confirmed for Netherlands (confidence: 0.40)
- Ownership stability: No changes recorded
- Threat persistence: No persistent malicious activity detected
- DNS associations: Consistent resolution to pfcloud.network
---
## Recommended Security Actions
Classification: Consider blocking based on moderate risk profile and DNSBL presence.
Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 176.65.148.93 -j DROP
# nftables
nft add rule inet filter input ip saddr 176.65.148.93 drop
# nginx
deny 176.65.148.93;
# pfSense
176.65.148.93/32
# Cloudflare WAF
ip.src eq 176.65.148.93 โ Block
# AWS WAF
Addresses: 176.65.148.93/32
```
---
## Intelligence Notes
- The IP lacks open ports and active services, suggesting it may be dormant, misconfigured, or used for passive scanning
- DNSBL presence indicates prior abuse activity; investigate associated domains if traffic observed
- Subnet abuse density is low (0), suggesting isolated incident rather than coordinated campaign
- Route stability issues (false) may indicate transient routing anomalies or BGP hijack attempts
---
Recommendation: Monitor for outbound connections to this IP. Apply blocking rules with appropriate logging. Investigate any traffic from this address in context of broader threat intelligence.
*Data sourced from IPDebrief platform. Actions should be validated against operational context before implementation.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Admin |
| ASN | AS51396 |
| Network Name | PF-CLOUD-NET-1 |
| CIDR Block | 176.65.148.0/24 |
| RIR | RIPE |
| Country | NL |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 176.65.148.93.ptr.pfcloud.network |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | 176.65.148.93.ptr.pfcloud.network |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 4% | 1 | 2 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-24 02:13:22 UTC |
| Last Seen | 2026-07-29 21:13:37 UTC |
| Profile Built | 2026-07-29 21:29:23 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 25 |
Full dossier details are available via our API.