## IP Intelligence Briefing: 185.141.119.59/32
Classification: Low Risk / Single-Service Host
Date: Current analysis based on multi-signal observation
---
Executive Summary
IP address 185.141.119.59 is registered to ASN 207990 under network name IN-HOSTROYALE-20160302. The asset carries a risk score of 25 (Low Risk) and is classified as a single-service host with limited operational indicators. No active threat campaigns or known attacker associations were identified. The subnet demonstrates minimal abuse density with no threat-implicated neighbors.
---
Network Ownership & Registration
- ASN: 207990
- Organization: in-hostroyale-1-mnt
- Network Name: IN-HOSTROYALE-20160302
- CIDR Block: 185.141.119.0/24
- RIR: RIPE
- Abuse Contact: Available via RDAP
---
Geolocation Analysis
- Claimed Location: United States, Michigan, Detroit
- Geolocation Consensus: True (based on 1 source)
- Geo Validation Status: Implausible
- Distance Violation: 6,399.5 km claimed with RTT of 50.0ms, below minimum possible 128.0ms for claimed distance
- Average RTT: 51.6ms (5 probes)
The geolocation data shows significant validation inconsistencies, suggesting the IP may be misconfigured or the location data is unreliable.
---
Threat Indicators
- Blacklist Count: 0
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Abuse Confidence Score: Not available
- DNSBL Listings: 1 of 8 lists
- Active Threat Campaigns: None detected
---
Network Classification
- Infrastructure Type: Single-Service Host
- Cloud: No
- CDN: No
- VPN: No
- Proxy: No
- Tor: No
- Hosting: No
- Mobile: No
- Residential: No
- Bogon: No
- Anycast: No
---
Service Exposure
- Open Ports: 8443/TCP (HTTPS-alt)
- TLS Certificate: Not detected
- HTTP Title: Not detected
- Server Banner: Not detected
- DNS Hosted Domains: 0
- PTR Hostnames: None
- Email Auth: No SPF, No DMARC records
---
Subnet Neighborhood Analysis
The /24 subnet 185.141.119.0/24 shows:
- Abuse Density: 0 (Clean)
- Total Siblings: 4
- Active Siblings: 4
- Threat Siblings: 0
- Inherited Risk: 0
Neighbor Risk Distribution:
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 185.141.119.53 | 25 | 50 |
| 185.141.119.109 | 25 | 50 |
| 185.141.119.146 | 20 | 50 |
All neighbors maintain low risk profiles with no abuse indicators.
---
Historical Signal Analysis
Analysis of 17 historical observations reveals:
- Subnet Classification: Consistently "clean" with 0 abuse density
- Threat Persistence: 0 days (not persistently malicious)
- Observation Pattern: Recent activity includes port scanning, traceroute validation, and subnet classification checks
- Ownership Changes: 0 (stable ownership)
- Route Stability: False (network routing may have changes)
---
Control Plane Data
- Origin ASN: 207990
- BGP Prefix: 185.141.119.0/24
- AS Path: Not available
- RPKI State: Not available
- IRR Consistency: Not available
- Route Changes (30d): 0
- DNSSEC Valid: True
- Operator Score: 0.1304 (Minimal)
---
Recommended Actions
Current Risk Score: 25 (Low)
No specific firewall rules or security actions are currently recommended at this risk level. The IP presents minimal threat indicators and maintains a clean neighborhood profile.
SOC Analyst Guidance:
- Monitor port 8443 for suspicious HTTPS traffic patterns
- Geovalidation discrepancies warrant periodic re-validation
- Subnet maintains clean status—no escalation required
- Standard logging and monitoring practices recommended
---
Intelligence Confidence: Moderate
Data Sources: Multi-signal inference, port scanning, traceroute, DNS validation, BGP routing data
Last Updated: Current analysis cycle
*This briefing is based on IPDebrief intelligence platform data and should be combined with other threat intelligence sources before operational decision-making.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | in-hostroyale-1-mnt |
| ASN | AS207990 |
| Network Name | IN-HOSTROYALE-20160302 |
| CIDR Block | 185.141.119.0/24 |
| RIR | RIPE |
| Country | US |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 8443 | https-alt | tcp | — |
| Closed Ports | 22, 25, 80, 443, 3389, 8080 (1 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS207990 |
| Network Prefix | 185.141.119.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 5 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 17% | 2 | 3 |
| reputation | 23% | 1 | 4 |
| geolocation | 17% | 2 | 3 |
| Overall | 18% | 10 | 18 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-14 21:58:28 UTC |
| Last Seen | 2026-09-03 01:09:18 UTC |
| Profile Built | 2026-09-03 01:10:41 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 26 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 185.141.119.59
Who owns the IP address 185.141.119.59?
185.141.119.59 is registered to in-hostroyale-1-mnt. The address falls within the 185.141.119.0/24 network block. Registration is held at RIPE.
Where is 185.141.119.59 located?
Geolocation data places 185.141.119.59 in Detroit, Michigan, United States. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 185.141.119.59 malicious or safe?
185.141.119.59 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 185.141.119.59?
Responsive ports observed on 185.141.119.59 include 8443. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.