# IPDEBRIEF INTELLIGENCE BRIEFING
Target: 185.15.171.83/32
Classification: Moderate Risk (55/100)
Date of Analysis: 2026-07-30
---
## EXECUTIVE SUMMARY
IP 185.15.171.83 is a web server endpoint associated with Italian hosting provider DONATO CONTE (ASN 57558). The IP presents moderate risk (55/100) with no active threat indicators currently observed. While the IP itself shows no known malicious activity, the surrounding /24 subnet demonstrates elevated abuse density, warranting monitoring and potential traffic filtering.
---
## OWNERSHIP & GEOLOCATION
Network: METIS-V4-NET-2 (185.15.170.0/23)
Organization: DONATO CONTE
ASN: 57558
Registry: RIPE
Location: Tito, Basilicate, Italy (41.87°N, 12.57°E)
Geolocation Confidence: Low (500km radius)
---
## NETWORK PROFILE
Role: Web Server
Service: lighttpd/1.4.39
Open Ports: 80/TCP (HTTP), 443/TCP (HTTPS), 22/TCP (SSH - dropbear)
DNS: host083-171-015-185.retemetis.net โ retemetis.net
Forward Resolution: Confirmed
Security Posture:
- DNSSEC: Valid
- SPF/DMARC: Not configured
- TLS Certificates: None detected
- HSTS/CSP: Not implemented
---
## THREAT ASSESSMENT
Risk Score: 55/100 (Moderate)
Abuse Confidence: N/A
Blacklist Status: 0 entries
DNSBL Listings: 3 of 8 lists
Known Campaigns: None
Tor Exit Node: No
Spam Source: No
Known Attacker: No
Control Plane:
- BGP Prefix: 185.15.168.0/22
- Route Stability: Unstable
- Route Changes (30d): 0
- RPKI State: Not assessed
---
## NEIGHBORHOOD ANALYSIS
Subnet: 185.15.171.83/24
Total Siblings: 96
Active Siblings: 66
Threat Siblings: 8
Abuse Density: 8.33%
Classification: Mostly Clean
Risk Distribution in /24:
- High Risk: 16 IPs
- Medium Risk: 76 IPs
- Low Risk: 3 IPs
*Note: Elevated high-risk neighbor count (16) within the subnet suggests coordinated or related infrastructure. Correlate traffic with other threat siblings.*
---
## OBSERVATION HISTORY
Total Observations: 21 signals
Threat Persistence Days: 0
Ownership Changes: 0
Persistent Malicious Behavior: No
Recent observations indicate consistent web server classification with no significant risk profile changes over the observation period.
---
## RELATED ENTITIES
DNS Associations:
- host083-171-015-185.retemetis.net (retemetis.net)
Network Associations:
- METIS-V4-NET-2 (185.15.170.0/23)
Correlated IPs: 0
---
## RECOMMENDED ACTIONS
Immediate:
- Increase logging verbosity for traffic from 185.15.171.83
- Review recent activity from this IP for anomalies
Mitigation Rules:
iptables:
```
iptables -A INPUT -s 185.15.171.83 -j DROP
```
nftables:
```
nft add rule inet filter input ip saddr 185.15.171.83 drop
```
nginx:
```
deny 185.15.171.83;
```
pfSense:
```
185.15.171.83/32
```
Cloudflare WAF:
```json
{
"description": "Block 185.15.171.83 โ IPDebrief risk score 55",
"action": "block",
"filter": {
"expression": "ip.src eq 185.15.171.83"
}
}
```
AWS WAF:
```json
{
"Addresses": ["185.15.171.83/32"],
"Description": "IPDebrief risk 55"
}
```
---
## ANALYST NOTES
The target IP shows no intrinsic malicious activity but operates in a moderately risky subnet. The 16 high-risk neighbors in the /24 subnet suggest potential for lateral movement or shared infrastructure abuse. Consider blocking at perimeter if legitimate traffic patterns are not verified. Monitor for DNS queries to retemetis.net and SSH connection attempts, which may indicate reconnaissance activity.
Classification: MONITOR โ BLOCK (if policy permits)
Severity: HIGH
Confidence: MODERATE
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | DONATO CONTE |
| ASN | AS57558 |
| Network Name | METIS-V4-NET-2 |
| CIDR Block | 185.15.170.0/23 |
| RIR | RIPE |
| Country | IT |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | host083-171-015-185.retemetis.net |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | host083-171-015-185.retemetis.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | lighttpd/1.4.39 |
| HTTP Title | โ |
| SSH Version | SSH-2.0-dropbear <??92)???}r1?r??curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-grou |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 35% | 2 | 2 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 14% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-28 16:14:03 UTC |
| Last Seen | 2026-08-03 11:22:10 UTC |
| Profile Built | 2026-08-02 23:23:06 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.