IPDebrief

185.153.231.45

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 185.153.231.45/32

Date: 2026-06-23

Classification: Moderate Risk

Analyst: IPDebrief Intelligence Team

## Executive Summary

IP address 185.153.231.45 is classified as a Moderate Risk (risk score: 50) originating from Turkey (TR). The address belongs to ASN 60721 (Furkan Sahin) and operates as a single-service host with SSH exposure. The IP has been observed with DNSBL listings totaling 8 lists, with 2 active listings. Neighborhood analysis indicates a low-abuse-density subnet (0.5 abuse density) with one lower-risk sibling IP (185.153.231.44, risk score 25).

## Technical Profile

AttributeValue
**Risk Score**50 (Moderate Risk)
**ASN**60721
**Organization**Furkan Sahin
**Country**Turkey (TR)
**Geolocation**41.02°N, 28.99°E (Europe/Istanbul)
**Network Role**Single-Service Host
**Open Ports**TCP/22 (SSH)
**PTR Hostname**45231.rdns.sahinnet.name.tr
**DNSBL Listed**2 of 8 lists

## Threat Indicators

## Network Context

Subnet Analysis (185.153.231.0/24)

Neighbor IP Assessment

## Observed Network Relationships

The IP has 37 relationship entries, predominantly "Same Network" associations linked to:

## Historical Signal Timeline

Observations: 21 total signals recorded

Recent Activity (2026-06-23):

Subnet Signals (2026-06-17):

## Recommended Security Actions

Immediate Mitigation (Block Recommendation)

Based on the risk profile, the following firewall rules are recommended:

```bash

# iptables

iptables -A INPUT -s 185.153.231.45 -j DROP

# nftables

nft add rule inet filter input ip saddr 185.153.231.45 drop

# nginx

deny 185.153.231.45;

# pfSense

185.153.231.45/32

# Cloudflare WAF

{"description":"Block 185.153.231.45 โ€” IPDebrief risk score 50","action":"block","filter":{"expression":"ip.src eq 185.153.231.45"}}

# AWS WAF

{"Addresses":["185.153.231.45/32"],"Description":"IPDebrief risk 50"}

```

## Risk Assessment Summary

The IP 185.153.231.45 presents a moderate risk profile suitable for defensive blocking. While the subnet shows low abuse density and the IP is not associated with known campaigns or persistent malicious activity, the presence of DNSBL listings and SSH exposure warrants restrictive firewall treatment. The neighborhood analysis supports a conservative approach, with the only sibling IP showing minimal risk (score 25).

Recommendation: Implement blocking rules at perimeter firewalls and WAF appliances. Monitor for any escalation in threat indicators or neighborhood activity patterns.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡น๐Ÿ‡ท Turkey
RegionBursa Province
CityBursa
TimezoneEurope/Istanbul
Latitude41.02
Longitude28.99

๐Ÿข Ownership & Registration

OrganizationFurkan Sahin
ASNAS60721
Network Nameโ€”
CIDR Blockโ€”
RIRRIPE
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR45231.rdns.sahinnet.name.tr
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnames45231.rdns.sahinnet.name.tr

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeSingle-Service Host
Network TierUnknown โ€” Insufficient routing data to classify
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
22sshtcp
Closed Ports25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”
SSH VersionSSH-2.0-OpenSSH_8.2p1 Ubuntu-4ubuntu0.13

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
32%
23
routing
13%
11
services
15%
22
ownership
27%
23
reputation
17%
12
geolocation
13%
11
Overall20%912
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-07 23:04:00 UTC
Last Seen2026-06-26 18:10:54 UTC
Profile Built2026-06-23 00:44:36 UTC
Data FreshnessLive
Signal Types19
Total Observations21
๐Ÿ” 19 signal types ยท 21 observations collected
This report is generated from 19+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.