IP Intelligence Briefing: 185.15.170.24
Date: 2026-06-08
---
**1. Risk Profile**
- Risk Score: 55/100 (Moderate Risk)
- Ownership: Registered to DONATO CONTE (Italy) under ASN 57558 (METIS-AS).
- Geolocation:
- City: Tito, Basilicate, Italy
- Coordinates: 40.58°N, 15.67°E
- Timezone: Europe/Rome
- Network Role: Firewalled / No Services (no open ports or TLS certificates detected).
- DNS:
- PTR hostname: `host024-170-015-185.retemetis.net`
- No email authentication records (SPF/DKIM).
---
**2. Threat Indicators**
- No direct malicious activity detected (no indicators, blacklists, or campaigns).
- DNS Abuse: 3/8 DNSBL lists flagged the subnet (185.15.168.0/22).
- BGP:
- Origin ASN: 57558 (METIS-AS)
- Route stability: Unstable (recent route changes).
- RPKI invalidation: Not reported.
---
**3. Network Relationships**
- Subnet: 185.15.170.0/23 (METIS-V4-NET-2)
- Neighbors (24-bit subnet):
- 44 total IPs, with 13 high-risk (80/100) and 25 medium-risk (55/100).
- Notable high-risk neighbors: 185.15.170.8, 185.15.170.11, 185.15.170.22.
- Shared DNS: Linked to `retemetis.net` (host024-170-015-185.retemetis.net).
---
**4. Behavioral Observations**
- Historical Activity:
- 16 observations (2026-05-29 to 2026-06-08).
- Mixed signal confidence (0.18โ0.95).
- No persistent malicious behavior.
- Traffic Patterns:
- No HTTP/HTTPS services or TLS certificates detected.
- No honeypot or enumeration activity.
---
**5. Recommended Actions**
- Firewall Blocking:
- iptables: `iptables -A INPUT -s 185.15.170.24 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 185.15.170.24 drop`
- Cloudflare WAF: Block IP with rule `ip.src eq 185.15.170.24`.
- Monitoring:
- Increase logging verbosity for traffic from this IP.
- Review neighboring IPs (e.g., 185.15.170.8, 185.15.170.11) for correlation.
- Investigation:
- Validate DNS ownership of `retemetis.net` and check for subdomain sprawl.
- Monitor BGP route stability for the 185.15.168.0/22 subnet.
---
Conclusion: This IP is part of a moderately risky subnet with no direct malicious activity. The owner is a private entity in Italy, and the IP is firewalled. While not immediately hostile, the subnet contains high-risk neighbors, warranting closer monitoring and network segmentation.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | DONATO CONTE |
| ASN | AS57558 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | host024-170-015-185.retemetis.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | host024-170-015-185.retemetis.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | lighttpd/1.4.39 |
| HTTP Title | โ |
| SSH Version | SSH-2.0-dropbear <?)^N?3x??'l????T?curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-gr |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 13% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 27% | 2 | 3 |
| reputation | 13% | 1 | 1 |
| geolocation | 13% | 1 | 1 |
| Overall | 17% | 7 | 8 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Fresh
| First Seen | 2026-05-17 21:14:44 UTC |
| Last Seen | 2026-06-25 07:54:47 UTC |
| Profile Built | 2026-06-23 15:42:59 UTC |
| Data Freshness | Fresh |
| Signal Types | 21 |
| Total Observations | 21 |
Full dossier details are available via our API.