IPDebrief

185.17.124.235

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING

Target: 185.17.124.235/32

Date: Current Analysis

Classification: High Risk

---

## EXECUTIVE SUMMARY

The IP address 185.17.124.235 is classified as HIGH RISK with a risk score of 70/100. The address is located in Ukraine under ASN 3255 (UARNET-AS - LLC EKSINTECH) and is currently DNSBL-listed on 4 of 8 threat intelligence feeds. The IP shows minimal active services and appears firewalled, with no open ports or TLS certificates detected.

---

## RISK ASSESSMENT

Overall Risk Score: 70 (High)

Provider Risk: 0

Authority Risk: 0

Stability: Not assessed (Score: 0)

Key Risk Indicators

---

## GEOGRAPHIC & NETWORK CONTEXT

AttributeValue
CountryUkraine (UA)
ASN3255
OrganizationLLC EKSINTECH
RIRRIPE
Allocation Date2013-01-30
CityUstiyanovycha St.
TimezoneEurope/Kyiv

---

## SUBNET ANALYSIS (185.17.124.0/24)

Abuse Density: 31.11% (Elevated)

Total Siblings: 45

Active Siblings: 12

Threat Siblings: 14

Notable High-Risk Neighbors

IP AddressRisk ScoreStatus
185.17.124.2570High Risk
185.17.124.2665Medium-High
185.17.124.2255Medium
185.17.124.2755Medium
185.17.124.1915Low

Risk Distribution: 3 High (7.4%), 38 Medium (60.3%), 20 Low (31.7%)

---

## OBSERVATION HISTORY

Recent observations indicate:

---

## NETWORK BEHAVIOR

IndicatorStatus
Tor Exit NodeNo
Known AttackerNo
Spam SourceNo
Cloud InfrastructureNo
CDNNo
VPNNo
ProxyNo
HostingNo
MobileNo
ResidentialNo
BogonNo

Services: None detected

Open Ports: None

TLS Certificate: None

---

## RELATIONSHIP GRAPH

Total Relationships: 14

Connection Type: Same Network (UA-EKSINTECH-20130130)

All relationships indicate network-level association with the UARNET-AS infrastructure.

---

## RECOMMENDED ACTIONS

Based on risk profile and threat indicators:

1. Monitor for DNSBL Updates: IP is listed on 4 of 8 feeds. Monitor for additional listings.

2. Subnet-Level Correlation: Investigate 185.17.124.0/24 for coordinated activity given 31% abuse density.

3. Firewall Rules: Consider blocking inbound traffic to 185.17.124.235 if not required for business operations.

4. Neighbor Watch: Monitor high-risk neighbors (185.17.124.25, 185.17.124.26) for similar activity patterns.

---

## ANALYST NOTES

This IP represents a high-risk asset within a moderately abused Ukrainian subnet. The absence of active services suggests either defensive hardening or a dormant infrastructure. The elevated DNSBL listing count warrants continued monitoring, particularly for potential spam or abuse campaign participation. The subnet's abuse density of 31% indicates this is not an isolated threat but part of a broader operational pattern.

Priority: Medium-High

Recommended Action: Monitor and document for future correlation analysis.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡ΊπŸ‡¦ Ukraine
Regionβ€”
CityUstiyanovycha St.
TimezoneEurope/Kyiv
Latitude50.45
Longitude30.53

🏒 Ownership & Registration

Organizationadmin
ASNAS3255
Network Nameβ€”
CIDR Blockβ€”
RIRRIPE
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo β€” PTR hostname does not resolve back to this IP (weak signal)

πŸ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown β€” Insufficient routing data to classify
No specific classification

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
38%
25
routing
19%
12
services
15%
22
ownership
24%
23
reputation
22%
13
geolocation
19%
22
Overall23%1017
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-12 09:40:42 UTC
Last Seen2026-06-26 16:33:10 UTC
Profile Built2026-06-26 16:53:21 UTC
Data FreshnessLive
Signal Types17
Total Observations24
πŸ” 17 signal types Β· 24 observations collected
This report is generated from 17+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.