# IP Intelligence Briefing: 185.17.124.123/32
Classification: Moderate Risk Web Server
Date: Current Analysis
Risk Score: 55/100
---
## Executive Summary
IP address 185.17.124.123 is a web server located in Ukraine (UA) with a moderate risk profile (55/100). The IP operates a lighttpd-based web service on ports 80/443 within the UA-EKSINTECH-20130130 network block (185.17.124.0/22, ASN 3255). While not currently flagged as a known malicious actor, the IP demonstrates elevated risk characteristics and should be monitored or blocked depending on organizational threat tolerance.
---
## Network Ownership & Geolocation
- ASN: 3255 (admin)
- Organization: admin
- Network Block: 185.17.124.0/22
- Geolocation: Ukraine (UA), Pavliv region
- RIR: RIPE
- Registration Date: 2013-01-30
- Abuse Contact: abuse@eksintech.net
---
## Threat Assessment
Current Risk Indicators
- Risk Score: 55/100 (Moderate)
- Abuse Confidence: Not classified as known attacker, spam source, or Tor exit node
- Blacklist Status: 0 blacklists (0% of threat feeds)
- Known Campaigns: None identified
Control Plane Analysis
- Route Stability: Unstable (isRouteStable: false)
- DNSSEC: Valid
- DNSBL Listings: 3 of 8 total lists
- Operator Score: 0.1304 (Minimal)
---
## Service Profile
- Service Purpose: Web Server
- Open Ports: 80/tcp (HTTP), 443/tcp (HTTPS)
- Web Server: lighttpd/1.4.39
- Email Authentication: No SPF, DMARC, or TXT records configured
- Forward Resolution: Unconfirmed
---
## Neighborhood Analysis (185.17.124.0/24)
- Total Subnet IPs: 92
- Abuse Density: 0.022 (Low-Moderate)
- Risk Distribution:
- High Risk: 2 IPs
- Medium Risk: 67 IPs
- Low Risk: 23 IPs
- Notable High-Risk Neighbors:
- 185.17.124.16 (Risk: 70/100)
- 185.17.124.22 (Risk: 55/100)
---
## Historical Observation Summary
- Total Observations: 12
- Recent Signals Include:
- Geolocation: Ukraine (48.38°N, 31.17°E) with 500km accuracy
- ASN Registration: RIPE
- Connection Status: Occasional connection failures observed on HTTPS
- Operator Score: Maintained at 0.1304 (Minimal)
---
## Recommended Security Actions
Immediate Actions
| Platform | Action |
|---|---|
| **iptables** | `iptables -A INPUT -s 185.17.124.123 -j DROP` |
| **nftables** | `nft add rule inet filter input ip saddr 185.17.124.123 drop` |
| **nginx** | `deny 185.17.124.123;` |
| **pfSense** | `185.17.124.123/32` (Block rule) |
| **Cloudflare WAF** | Block IP with expression: `ip.src eq 185.17.124.123` |
| **AWS WAF** | Add 185.17.124.123/32 to block list |
Monitoring Recommendations
- Increase logging verbosity for this IP
- Review recent activity patterns
- Monitor for changes in threat indicators
- Consider blocking subnet-level if threat tolerance is low
---
## Analyst Notes
The IP presents moderate risk primarily due to route instability and DNSBL listings. The subnet contains 2 high-risk neighbors, suggesting potential for correlated malicious activity. Given the Ukraine-based location and web server classification, this IP should be evaluated against organizational threat tolerances for APT or state-sponsored actor attribution.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | admin |
| ASN | AS3255 |
| Network Name | UA-EKSINTECH-20130130 |
| CIDR Block | 185.17.124.0/22 |
| RIR | RIPE |
| Country | UA |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | lighttpd/1.4.39 |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 35% | 2 | 2 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 18% | 5 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-28 16:14:03 UTC |
| Last Seen | 2026-08-13 06:44:15 UTC |
| Profile Built | 2026-08-12 12:22:38 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.