# IP INTELLIGENCE BRIEFING: 185.17.124.64
Classification: HIGH RISK | Date: 2026-07-30
## EXECUTIVE SUMMARY
IP 185.17.124.64 presents a HIGH RISK profile (score: 70/100). The address is associated with netname UA-EKSINTECH-20130130, registered under ASN 3255 (admin) within the RIPE RIR. Multiple DNSBL listings (4 of 8 total lists) indicate prior malicious activity. The IP operates as a web server (ports 80/443) running lighttpd/1.4.39.
## RISK ASSESSMENT
| Metric | Value |
|---|---|
| Risk Score | 70 (High) |
| DNSBL Listings | 4 of 8 |
| Operator Score | 0.1304 (Minimal) |
| Route Stability | Unstable |
| DNSSEC Valid | Yes |
| Abuse Confidence | Not reported |
Primary Risk Factors:
- Elevation to High Risk status (70/100)
- Multiple DNSBL blacklist entries
- Geolocation inconsistencies (Poland/Warsaw vs Ukraine observations in signal history)
## NETWORK CONTEXT
Ownership:
- ASN: 3255 (admin)
- Org: admin
- Netname: UA-EKSINTECH-20130130
- CIDR: 185.17.124.0/22
- RIR: RIPE
Geolocation:
- Country: Poland (PL) / Ukraine (UA) - conflicting signals
- City: Warsaw
- Geo Consensus: Mixed signals across observations
Services:
- HTTP (port 80)
- HTTPS (port 443)
- Server: lighttpd/1.4.39
## NEIGHBORHOOD ANALYSIS
Subnet: 185.17.124.0/24
- Abuse Density: 2.2%
- Total Neighbors: 92
- High-Risk Neighbors: 2
- Medium-Risk Neighbors: 64
- Low-Risk Neighbors: 24
Notable High-Risk Neighbor:
- 185.17.124.16 (Risk: 70, Authority: 50)
## OBSERVATION HISTORY
Total Observations: 12 signals (most recent: 2026-07-30T03:07:48)
Key Observations:
- Port scanning activity detected
- Multiple geolocation signal variations (PL/UA)
- DNS resolution inconsistencies
- Provider/organization data variations
- Low-confidence network role classification (30% confidence)
## RELATIONSHIP MAPPING
Connected Entities:
- Network: UA-EKSINTECH-20130130 (Same Network relationship)
## RECOMMENDED ACTIONS
SOC Analyst Actions:
1. Block at perimeter: Implement firewall rules to deny traffic from 185.17.124.0/24
2. Monitor adjacent IPs: Pay particular attention to 185.17.124.16 (risk score 70)
3. Threat correlation: Review inbound/outbound logs for any connections to this subnet
4. DNSBL verification: Confirm current blacklist status across multiple feeds
Firewall Rule Example (iptables):
```
iptables -A INPUT -s 185.17.124.0/24 -j DROP
iptables -A OUTPUT -d 185.17.124.0/24 -j DROP
```
Cloudflare/AWS WAF:
```
ip: 185.17.124.64
action: block
reason: High-risk IP with DNSBL listings
```
## THREAT INTELLIGENCE NOTES
The IP's risk profile suggests potential abuse. The subnet shows moderate abuse density (2.2%) with a concentration of medium-risk addresses. Geolocation inconsistencies warrant monitoring for potential infrastructure misrepresentation. The unstable routing status indicates potential infrastructure changes that could impact traffic patterns.
Recommendation: Treat as malicious until proven otherwise. Implement blocking controls and monitor for any outbound connections from your environment to this subnet.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | admin |
| ASN | AS3255 |
| Network Name | UA-EKSINTECH-20130130 |
| CIDR Block | 185.17.124.0/22 |
| RIR | RIPE |
| Country | UA |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | lighttpd/1.4.39 |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-25 08:45:05 UTC |
| Last Seen | 2026-08-11 05:40:53 UTC |
| Profile Built | 2026-07-30 03:17:35 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 19 |
Full dossier details are available via our API.