# THREAT INTELLIGENCE BRIEFING
Target IP: 178.219.98.173/32
Report Date: 2026-06-17
Classification: Moderate Risk
---
## EXECUTIVE SUMMARY
IP 178.219.98.173 presents a MODERATE RISK profile (Risk Score: 55) with no active threat indicators. The IP belongs to ASN 51079 (MOKADI, Kamil Kazmierczak) and is geolocated to Poland (PL). While the IP itself shows no malicious activity, it resides within a subnet (178.219.98.0/24) exhibiting elevated abuse density (46.43%), suggesting potential infrastructure sharing or contamination risks.
---
## PROFILE ANALYSIS
Ownership & Network Classification
- ASN: AS51079 (MOKADI)
- Organization: Kamil Kazmierczak
- RIR: RIPE (Europe)
- Service Status: Firewalled / No Services Detected
- Network Role: Infrastructure Type Unidentified
- Cloud/CDN/Proxy: No indicators detected
Geolocation Data
- Country: Poland (PL)
- Region: 10
- Coordinates: 51.92°N, 19.15°E
- Data Quality: GEOLOCATION PLAUSIBILITY FALSE (multiple sources)
- Consensus: 2 sources, but confidence limited
Threat Indicators
- Blacklist Count: 0
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Campaign Matches: 0
---
## SUBNET ENVIRONMENT (178.219.98.0/24)
Risk Assessment
- Abuse Density: 0.4643 (HIGH)
- Classification: Mixed
- Total Siblings: 28
- Active Siblings: 14
- Threat Siblings: 13
High-Risk Neighbors
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 178.219.98.100 | 80 | 50 |
| 178.219.98.140 | 80 | 50 |
| 178.219.98.162 | 80 | 50 |
| 178.219.98.214 | 80 | 50 |
| 178.219.98.234 | 80 | 50 |
| 178.219.98.93 | 70 | 50 |
| 178.219.98.127 | 70 | 50 |
| 178.219.98.139 | 70 | 50 |
| 178.219.98.211 | 70 | 50 |
---
## OBSERVATION HISTORY
Temporal Analysis
- Observation Count: 1 threat-related observations
- Ownership Changes: 0
- Threat Persistence: 0 days
- Is Persistently Malicious: No
Recent Signals (Last 24 Hours)
1. Subnet Abuse Density: 0.4643 (Mixed classification, 13 threat siblings)
2. Operator Score: 0.2174 (Minimal)
3. Geolocation: Poland (PL) via multiple-signal inference
4. Network Association: MOKADI ASN consistently observed
---
## CONTROL PLANE STATUS
- Route Stability: False
- RPKI State: Unknown
- DNSSEC Valid: True
- DNSBL Listed: 3 of 8 total lists
- IRR Consistency: Unknown
- Route Changes (30d): 0
---
## RECOMMENDED ACTIONS
Immediate Actions
1. Monitor Subnet Activity: Given the high abuse density (46.43%) and 13 threat siblings, monitor all 178.219.98.0/24 addresses for correlated activity
2. Review High-Risk Neighbors: Investigate IPs with risk scores โฅ70 within the subnet for potential abuse campaigns
3. DNSBL Verification: Confirm why IP is listed on 3 of 8 DNSBLs despite 0 blacklist count in profile
Firewall Rules (If Blocking Recommended)
- Policy: Block or rate-limit traffic from 178.219.98.0/24 subnet
- Justification: Elevated subnet abuse density with 13 confirmed threat siblings
- Alternative: Allow-list specific ports if business relationship exists
SOC Analyst Notes
- IP shows no active threat indicators but resides in a high-risk subnet
- Geolocation data quality is poor (geoPlausible: false)
- No open ports or services detected; IP appears firewalled
- Relationship graph shows 46 connections, primarily to MOKADI network
- Consider correlating with other IPs from ASN 51079 for broader threat context
---
END OF BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Kamil Kazmierczak |
| ASN | AS51079 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 24% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 23% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 21% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:03:57 UTC |
| Last Seen | 2026-06-22 22:46:07 UTC |
| Profile Built | 2026-06-22 22:55:48 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 24 |
Full dossier details are available via our API.