# IP INTELLIGENCE BRIEFING
Target: 178.137.16.109
Classification: Provider Network / High-Risk Subnet
Risk Score: 65/100 (Moderate Risk)
Last Updated: 2026-06-24
---
## EXECUTIVE SUMMARY
IP address 178.137.16.109 is a residential broadband endpoint operated by Kyivstar PJSC (ASN 15895) in Kyiv, Ukraine. The IP is assigned to a high-abuse-density subnet (178.137.16.0/24) with 65.6% abuse classification. While the individual IP shows no active threat indicators, its neighborhood exhibits elevated malicious activity, warranting defensive monitoring and filtering.
---
## OWNERSHIP & GEOGRAPHIC CONTEXT
| Attribute | Value |
|---|---|
| ASN | 15895 (kyivstar pjsc) |
| Organization | Kyivstar PJSC |
| Country | Ukraine (UA) |
| City | Kyiv |
| CIDR Block | 178.137.0.0/18 |
| Service Type | Residential Broadband |
| DNS PTR | 178-137-16-109.broadband.kyivstar.net |
---
## THREAT ASSESSMENT
Current Risk Profile:
- Risk Score: 65/100
- Abuse Confidence: Not scored (null)
- Blacklist Status: 0 active blacklists
- DNSBL Listings: 3 of 8 total lists
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Control Plane Observations:
- Route Stability: Unstable (route changes detected in 30d window)
- RPKI State: Not verified
- DNSSEC Valid: Yes
- Operator Score: 0.1304 (Minimal)
---
## NEIGHBORHOOD ANALYSIS
Subnet: 178.137.16.0/24
- Total Siblings: 256
- Active Siblings: 186
- Threat Siblings: 168
- Abuse Density: 65.62%
- Classification: High Abuse
Risk Distribution in /24:
- High Risk: 7 IPs
- Medium Risk: 93 IPs
- Low Risk: 0 IPs
Notable Neighbors:
- 178.137.16.0: Risk 50
- 178.137.16.1: Risk 65
- 178.137.16.2: Risk 65
- 178.137.16.3: Risk 65
- 178.137.16.4: Risk 65
---
## OBSERVATION HISTORY
Signal Observations: 23 total records
- Most recent: 2026-06-24T04:58:46
- Signal Types: Geolocation, Routing, Threat Indicators, Ownership
- Threat Persistence Days: 0
- Is Persistently Malicious: No
Key Historical Signals:
- 2026-06-24: Operator score 0, minimal threat signals
- 2026-06-04: Threat indicators detected with 50+ pulse matches from AlienVault OTX
---
## NETWORK RELATIONSHIPS
Connected Entities: 52 relationship entries
- Primary Network: KYIVSTAR-NET-7 (multiple associations)
- Network Type: Same Network associations
---
## RECOMMENDED DEFENSIVE ACTIONS
Priority: HIGH
1. Firewall Blocking
```bash
# iptables
iptables -A INPUT -s 178.137.16.109 -j DROP
# nftables
nft add rule inet filter input ip saddr 178.137.16.109 drop
```
2. WAF Integration
- Cloudflare WAF: Block 178.137.16.109 (expression: ip.src eq 178.137.16.109)
- AWS WAF: Block 178.137.16.109/32
- Nginx: `deny 178.137.16.109;`
- pfSense: Block rule for 178.137.16.109/32
3. Monitoring Enhancements
- Increase logging verbosity for this IP
- Review recent activity patterns
- Consider blocking entire /24 subnet if threat context warrants
---
## ANALYST NOTES
This IP resides in a high-risk residential broadband subnet commonly associated with compromised endpoints. The 65.62% abuse density of 178.137.16.0/24 indicates systematic abuse patterns. While this specific endpoint shows no active malicious indicators, its neighborhood profile suggests potential for future compromise. Recommend blocking at perimeter and maintaining enhanced logging for forensic analysis capability.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Kyivstar PJSC |
| ASN | AS15895 |
| Network Name | β |
| CIDR Block | β |
| RIR | RIPE |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 178-137-16-109.broadband.kyivstar.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 178-137-16-109.broadband.kyivstar.net |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 24% | 2 | 3 |
| Overall | 21% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:49 UTC |
| Last Seen | 2026-06-26 18:11:49 UTC |
| Profile Built | 2026-06-24 05:07:04 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 22 |
Full dossier details are available via our API.