# IP INTELLIGENCE BRIEFING
Target: 181.214.140.22/32
Date: Current
Classification: MODERATE RISK
---
## EXECUTIVE SUMMARY
IP address 181.214.140.22 presents a moderate risk profile (Score: 40) with no active open services detected. The address is firewalled with no HTTP/HTTPS services exposed. Geographic indicators show consensus location in United Arab Emirates (AE), though historical signals contain conflicting geolocation data from US and UK sources. The IP appears associated with ASN 20860 within the 181.214.140.0/24 BGP prefix.
---
## RISK PROFILE
- Overall Risk Score: 40 (Moderate)
- Provider Score: 0
- Authority Score: 0
- Operator Score: 0.1304 (Minimal)
- Risk Classification: Moderate Risk
- Route Stability: False
- DNSBL Listings: 2 of 8 total lists
---
## GEOLOCATION ANALYSIS
Consensus Location: UAE (United Arab Emirates)
- Coordinates: 23.42°N, 53.85°E
- Timezone: Asia/Dubai
- Accuracy Radius: 200km
Historical Geolocation Discrepancies:
- Recent signals indicate US (Ashburn, VA) and UK (London) origins
- Multiple geo sources flagged (geoPlausible: false)
- Geographic validation failures suggest potential spoofing or multi-region deployment
---
## NETWORK CLASSIFICATION
- ASN: 20860 (digital energy technologies ltd.)
- BGP Prefix: 181.214.140.0/24
- Network Role: Firewalled / No Services
- Infrastructure Type: Non-provider
- Cloud/CDN/VPN/Proxy: Not detected
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
---
## THREAT INDICATORS
- Abuse Confidence Score: Not calculated
- Known Campaigns: None detected
- Threat Feeds: No matches
- Blacklist Count: 0
- Pulsedive Risk: Not available
- Cert Matches: 0
---
## SERVICES & DNS ANALYSIS
- Open Ports: None detected
- TLS Certificate: None
- HTTP Title: None
- Forward DNS Resolution: Failed
- PTR Hostnames: None
- Email Auth: SPF/DMARC not configured
- Hosted Domains: 0
---
## NEIGHBORHOOD ANALYSIS
Subnet: 181.214.140.0/24
- Abuse Density: 0 (Low)
- Total Siblings: 1 detected
- Active Threat Siblings: 0
Notable Neighbor:
- 181.214.140.97
- Risk Score: 40
- Authority Score: 50
- Classification: Medium risk
---
## OBSERVATION HISTORY
Total Observations: 10 signals tracked
Recent Signals:
- 2026-07-30 10:29:06 โ ASN AS61317 (digital energy technologies ltd.) detected with threat flags
- 2026-07-30 10:28:58 โ LACNIC RIR registration with netutils-mnt organization
- 2026-07-30 10:27:39 โ Operator score 0.1304 (Minimal)
Temporal Indicators:
- Ownership changes: 0
- Threat persistence days: 0
- Persistently malicious: No
- Is active attacker: No
---
## RELATIONSHIP GRAPH
- Related Entities: None detected
- Correlated IPs: 0
- Certificate Matches: 0
---
## RECOMMENDED ACTIONS
1. Monitor โ IP shows moderate risk with geographic inconsistencies
2. Block at WAF if traffic originates from this IP and presents suspicious payloads
3. Investigate any connections to this IP for potential spoofing indicators
4. Correlate with ASN 20860 and neighbor 181.214.140.97 for coordinated activity
5. No immediate block recommended โ firewalled with no active services
---
## ANALYST NOTES
This IP address exhibits moderate risk characteristics with firewalled status. The geographic inconsistencies across multiple signals warrant continued monitoring. No active attack patterns or threat indicators detected. The single neighbor in the /24 subnet shows similar risk scoring, suggesting potential shared infrastructure or related deployment.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | netutils-mnt |
| ASN | AS20860 |
| Network Name | IPXO |
| CIDR Block | 181.214.0.0/16 |
| RIR | LACNIC |
| Country | US |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_8.9p1 Ubuntu-3 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 40% | 2 | 3 |
| routing | 20% | 1 | 1 |
| services | 40% | 2 | 3 |
| ownership | 40% | 2 | 3 |
| reputation | 20% | 1 | 2 |
| geolocation | 20% | 1 | 1 |
| Overall | 30% | 9 | 13 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-27 03:35:50 UTC |
| Last Seen | 2026-08-04 05:42:32 UTC |
| Profile Built | 2026-08-02 23:28:47 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 19 |
Full dossier details are available via our API.