IPDebrief

185.15.171.83

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IPDEBRIEF INTELLIGENCE BRIEFING

Target: 185.15.171.83/32

Classification: Moderate Risk (55/100)

Date of Analysis: 2026-07-30

---

## EXECUTIVE SUMMARY

IP 185.15.171.83 is a web server endpoint associated with Italian hosting provider DONATO CONTE (ASN 57558). The IP presents moderate risk (55/100) with no active threat indicators currently observed. While the IP itself shows no known malicious activity, the surrounding /24 subnet demonstrates elevated abuse density, warranting monitoring and potential traffic filtering.

---

## OWNERSHIP & GEOLOCATION

Network: METIS-V4-NET-2 (185.15.170.0/23)

Organization: DONATO CONTE

ASN: 57558

Registry: RIPE

Location: Tito, Basilicate, Italy (41.87°N, 12.57°E)

Geolocation Confidence: Low (500km radius)

---

## NETWORK PROFILE

Role: Web Server

Service: lighttpd/1.4.39

Open Ports: 80/TCP (HTTP), 443/TCP (HTTPS), 22/TCP (SSH - dropbear)

DNS: host083-171-015-185.retemetis.net โ†’ retemetis.net

Forward Resolution: Confirmed

Security Posture:

---

## THREAT ASSESSMENT

Risk Score: 55/100 (Moderate)

Abuse Confidence: N/A

Blacklist Status: 0 entries

DNSBL Listings: 3 of 8 lists

Known Campaigns: None

Tor Exit Node: No

Spam Source: No

Known Attacker: No

Control Plane:

---

## NEIGHBORHOOD ANALYSIS

Subnet: 185.15.171.83/24

Total Siblings: 96

Active Siblings: 66

Threat Siblings: 8

Abuse Density: 8.33%

Classification: Mostly Clean

Risk Distribution in /24:

*Note: Elevated high-risk neighbor count (16) within the subnet suggests coordinated or related infrastructure. Correlate traffic with other threat siblings.*

---

## OBSERVATION HISTORY

Total Observations: 21 signals

Threat Persistence Days: 0

Ownership Changes: 0

Persistent Malicious Behavior: No

Recent observations indicate consistent web server classification with no significant risk profile changes over the observation period.

---

## RELATED ENTITIES

DNS Associations:

Network Associations:

Correlated IPs: 0

---

## RECOMMENDED ACTIONS

Immediate:

Mitigation Rules:

iptables:

```

iptables -A INPUT -s 185.15.171.83 -j DROP

```

nftables:

```

nft add rule inet filter input ip saddr 185.15.171.83 drop

```

nginx:

```

deny 185.15.171.83;

```

pfSense:

```

185.15.171.83/32

```

Cloudflare WAF:

```json

{

"description": "Block 185.15.171.83 โ€” IPDebrief risk score 55",

"action": "block",

"filter": {

"expression": "ip.src eq 185.15.171.83"

}

}

```

AWS WAF:

```json

{

"Addresses": ["185.15.171.83/32"],

"Description": "IPDebrief risk 55"

}

```

---

## ANALYST NOTES

The target IP shows no intrinsic malicious activity but operates in a moderately risky subnet. The 16 high-risk neighbors in the /24 subnet suggest potential for lateral movement or shared infrastructure abuse. Consider blocking at perimeter if legitimate traffic patterns are not verified. Monitor for DNS queries to retemetis.net and SSH connection attempts, which may indicate reconnaissance activity.

Classification: MONITOR โ†’ BLOCK (if policy permits)

Severity: HIGH

Confidence: MODERATE

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฎ๐Ÿ‡น Italy
RegionBasilicate
CityTito
TimezoneEurope/Rome
Latitudeโ€”
Longitudeโ€”

๐Ÿข Ownership & Registration

OrganizationDONATO CONTE
ASNAS57558
Network NameMETIS-V4-NET-2
CIDR Block185.15.170.0/23
RIRRIPE
CountryIT
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRhost083-171-015-185.retemetis.net
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnameshost083-171-015-185.retemetis.net

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierTier 3 โ€” Basic operator with some routing infrastructure
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
443httpstcpโ€”
22sshtcp
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
Serverlighttpd/1.4.39
HTTP Titleโ€”
SSH VersionSSH-2.0-dropbear <??92)???}r1?r??curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-grou

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
35%
22
ownership
0%
00
reputation
0%
00
geolocation
0%
00
Overall14%44
Coverage: 3/6 dimensions ยท Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-07-28 16:14:03 UTC
Last Seen2026-08-03 11:22:10 UTC
Profile Built2026-08-02 23:23:06 UTC
Data FreshnessLive
Signal Types21
Total Observations22
๐Ÿ” 21 signal types ยท 22 observations collected
This report is generated from 21+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.