## IP Intelligence Briefing: 185.168.28.213
Classification: Low Risk / Defensive Operations
Target: 185.168.28.213/32
Date of Analysis: 2026-07-30
Executive Summary
IP 185.168.28.213 is classified as Low Risk with a risk score of 25. The address is assigned to Apex Data Solutions LLC (ASN 213954), operating under the ISP-NETLABS-NET network block (185.168.28.0/23) in Germany (DE). No active threat indicators, blacklist entries, or malicious campaign associations were identified. The IP shows no open services and is currently firewalled.
Network Ownership & Infrastructure
- Organization: Apex Data Solutions LLC
- ASN: 213954
- Network: ISP-NETLABS-NET
- CIDR Block: 185.168.28.0/23
- RIR: RIPE
- Abuse Contact: admin@netlabs.com.ua (per registration data)
- Geolocation: Germany (DE) โ Berlin timezone, 600km accuracy radius
- Geographic Consensus: 1 source (geoPlausible flag: false)
Threat Indicators
- Blacklist Count: 0
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Active Campaigns: None detected
- Threat Feeds: None
Abuse Confidence: Null (insufficient evidence for classification)
Service & Port Analysis
- Open Ports: None (service purpose: Firewalled / No Services)
- TLS Certificate: None detected
- HTTP Banner: None detected
- DNS PTR Records: None
- Forward Resolution: Not confirmed
Control Plane & Routing
- BGP Origin ASN: 213954
- BGP Prefix: 185.168.28.0/23
- Route Stability: False (routing instability detected)
- MoAS Status: No
- Route Changes (30d): 0
- DNSSEC Valid: True
- DNSBL Listed Count: 1 (out of 8 total lists checked)
Subnet Neighborhood Analysis
The /24 subnet containing this IP was examined. Of 4 sibling IPs:
- 185.168.28.46 โ Risk Score: 25
- 185.168.28.51 โ Risk Score: 0
- 185.168.28.65 โ Risk Score: 25
- 185.168.28.152 โ Risk Score: 0
- Subnet Abuse Density: 0
- High Risk Neighbors: 0
- Overall Classification: Low Risk
Historical Signal Observation
Thirteen observations recorded, with the most recent on 2026-07-30. Historical signals indicate:
- No ownership changes
- No persistent malicious activity
- Consistent geolocation inferences (DE)
- Stable ASN attribution (213954)
- Threat Observation Count: 0
Entity Relationships
Relationship graph shows three "Same Network" entries pointing to ISP-NETLABS-NET. No associations with external hostnames, organizations, or certificates beyond the immediate network block.
Traceroute Analysis
- Hop Count: 29
- Transit Networks: Comcast, Cogent
- Timed Out Hops: 14
- First Hop RTT: 0.2ms
- Last Hop RTT: 116.3ms
Recommended Security Actions
No specific firewall rules or blocking recommendations were generated based on the current risk profile. The low risk score (25) and absence of active threat indicators suggest the IP does not warrant immediate blocking. However, the following conditions should be monitored:
1. Route Stability Flag: False โ monitor for routing anomalies
2. DNSBL Listing: 1 listing detected โ verify source and relevance
3. Geographic Inconsistency: geoPlausible flag false โ validate geolocation claims
Intelligence Assessment
IP 185.168.28.213 presents as a benign infrastructure address within a German ISP network. No evidence of malicious activity, command-and-control behavior, or abuse indicators. The network shows stable ownership attribution and no recent threat persistence. Recommended monitoring approach: passive observation with standard logging. No immediate action required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Apex Data Solutions LLC |
| ASN | AS213954 |
| Network Name | ISP-NETLABS-NET |
| CIDR Block | 185.168.28.0/23 |
| RIR | RIPE |
| Country | DE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 35% | 2 | 2 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 14% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-28 16:14:03 UTC |
| Last Seen | 2026-08-02 17:02:09 UTC |
| Profile Built | 2026-07-30 17:56:34 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.