IPDebrief

185.121.25.25

IP Intelligence Dossier
Your IP: 216.73.217.34
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

Intelligence Briefing: 185.121.25.25

Risk Assessment: The IP address was classified as Low Risk with a risk score of 25. No known attacker indicators, spam sources, or active malicious campaigns were detected. The target is not identified as a Tor exit node, proxy, or known attacker.

Ownership and Location: The address was registered to ParadoxNetworks Limited (ASN 52025) under RIPE and is geolocated to Portland, Oregon, United States. The surrounding subnet (185.121.25.0/24) was classified as clean with zero observed threat siblings and low inherited risk.

Network Behavior: The host was identified as a web server responding on TCP ports 80 and 443. TLS inspection revealed a self-signed certificate. One DNSBL listing was recorded in control plane data, though the overall threat indicator list remained empty. No honeypot hits or WAF violations were observed.

Recommendation: Monitor. The target presents a low severity profile with insufficient data to classify intent. No immediate firewall rules are required.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡Έ United States
RegionOR
CityPortland
TimezoneAmerica/Los_Angeles
Latitude45.59
Longitude-122.60

🏒 Ownership & Registration

OrganizationParadoxNetworks Limited
ASNAS52025
Network NamePARADOXNETWORKS
CIDR Block185.121.25.0/24
RIRRIPE
CountryGB
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRlo0.rt0-nik.ams01.nl.pdx.net.uk
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnameslo0.rt0-nik.ams01.nl.pdx.net.uk

πŸ” DNS Hygiene

Hygiene Score0% (None)
SPF0/2 domains
DMARC0/2 domains
FCrDNSNot verified
DNSSECNot signed
CAANot configured
Domains Checked2 domains

☁️ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierTier 3 β€” Basic operator with some routing infrastructure
No specific classification

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpβ€”
443httpstcpβ€”
Closed Ports22, 25, 3389, 8080, 8443 (2 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

A self-signed certificate was detected. This is common for development servers, internal services, or IoT devices.
⚠️
CN=self.signed
Issued by CN=self.signed
Self-signed: Yes
SANsNone
Valid From2017-02-01T15:56:55+00:00
Valid Until2099-03-23T15:56:55+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period30000 days
Serial Number00B8E48E5DAA6DCB5D
Thumbprint64664D37BEDCE3B9308F2D96FCB2C9F1375A86D2

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
36%
28
routing
38%
45
services
27%
24
ownership
35%
35
reputation
27%
15
geolocation
33%
27
Overall33%1434
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionHigh (80%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-08-29 18:29:54 UTC
Last Seen2026-09-24 13:30:58 UTC
Profile Built2026-09-24 13:43:51 UTC
Data FreshnessLive
Signal Types32
Total Observations56
πŸ” 32 signal types Β· 56 observations collected
This report is generated from 32+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.