# IP INTELLIGENCE BRIEFING: 185.147.81.52/32
## EXECUTIVE SUMMARY
Target 185.147.81.52 is a moderate-risk IP address (score: 55/100) originating from Russia. The address resolves to a firewalled endpoint with no active services, but is listed on three DNSBLs. Intelligence indicates basic operator classification with limited routing stability.
## GEOLOCATION & NETWORK ATTRIBUTES
- Location: St Petersburg, Russia (RU)
- Origin ASN: 41722
- BGP Prefix: 185.147.81.0/24
- Route Stability: False (route changes observed in last 30 days)
- DNSBL Status: Listed on 3 of 8 threat feeds
## OWNERSHIP & INFRASTRUCTURE
- PTR Record: node2.ttcsoft.ru
- Reverse DNS: node2.ttcsoft.ru
- Forward Resolution: node2.ttcsoft.ru
- Infrastructure Type: Firewalled / No Services (no open ports detected)
- Cloud/CDN/Proxy Status: Not identified as cloud infrastructure, CDN, VPN, proxy, or hosting service
## THREAT INTELLIGENCE
- Risk Score: 55/100 (Moderate Risk)
- Abuse Confidence: Not quantified
- Tor Exit Node: No
- Known Attacker: Not flagged
- Spam Source: Not flagged
- Campaign Correlation: No matches in known campaigns
- Threat Persistence: 0 days (no persistent malicious activity observed)
## OBSERVATION HISTORY
Thirteen observation records collected as of July 29, 2026. Signals include:
- Port scanning activity detected
- Geolocation validation from MaxMind GeoLite2 (Russia, St. Petersburg)
- Operator scoring: Basic classification (0.2609)
- DNSBL listings: 3 lists active
## NEIGHBORHOOD ANALYSIS
Subnet: 185.147.81.0/24
- Total Siblings: 0 discovered
- Abuse Density: 0
- Threat Siblings: 0
No adjacent IPs flagged as malicious in the /24 neighborhood.
## RELATIONSHIPS
Single relationship identified:
- DNS Association: node2.ttcsoft.ru
No organization, certificate, or hostname associations beyond DNS PTR record.
## RECOMMENDED ACTIONS
Priority: Monitor/Review
- Increase logging verbosity for traffic from this IP
- Review recent activity patterns
Blocklist Recommendations:
- iptables: `iptables -A INPUT -s 185.147.81.52 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 185.147.81.52 drop`
- nginx: `deny 185.147.81.52;`
- pfSense: Add 185.147.81.52/32 to blocklist
- Cloudflare WAF: Block IP (risk score 55)
- AWS WAF: Add to blocked addresses with description "IPDebrief risk 55"
## ANALYST NOTES
The IP exhibits moderate risk characteristics with multiple DNSBL listings but lacks confirmed malicious indicators. The absence of open services suggests either a defensive posture or inactive endpoint. Route instability and DNSBL presence warrant continued monitoring. No immediate threat indicators require emergency response.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Miran Contacts |
| ASN | AS41722 |
| Network Name | MIRAN-VS-Net |
| CIDR Block | 185.147.81.0/24 |
| RIR | RIPE |
| Country | RU |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | node2.ttcsoft.ru |
| Forward Confirmed | Yes — FCrDNS verified |
| Forward Hostnames | node2.ttcsoft.ru |
🔐 DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | 2/2 domains |
| DMARC | 0/2 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 2 domains |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 — Basic operator with some routing infrastructure |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS41722 |
| Network Prefix | 185.147.81.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 5 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 23% | 2 | 4 |
| reputation | 20% | 1 | 3 |
| geolocation | 17% | 2 | 3 |
| Overall | 18% | 10 | 18 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-20 18:35:45 UTC |
| Last Seen | 2026-09-04 23:57:22 UTC |
| Profile Built | 2026-09-05 00:04:50 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 30 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 185.147.81.52
Who owns the IP address 185.147.81.52?
185.147.81.52 is registered to Miran Contacts. The address falls within the 185.147.81.0/24 network block. Registration is held at RIPE.
Where is 185.147.81.52 located?
Geolocation data places 185.147.81.52 in St Petersburg, St.-Petersburg, Russia. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 185.147.81.52 malicious or safe?
185.147.81.52 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 185.147.81.52?
The reverse DNS (PTR) record for 185.147.81.52 is node2.ttcsoft.ru. This hostname is forward-confirmed, meaning it resolves back to the same address.