IPDebrief

185.191.171.6

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

IPDEBRIEF INTELLIGENCE BRIEFING

Target IP: 185.191.171.6/32

Analysis Date: 2026-07-22

---

EXECUTIVE SUMMARY

The IP address 185.191.171.6 presents as a low-risk infrastructure endpoint with no active threat indicators. The address operates under AS209366 (Jaroslav Jacjuk) within the RIPE RIR, allocated to netname SCL66-rented1. Geolocation data indicates United Kingdom (GB) origin with Cyprus region attribution. The IP is currently firewalled with no open services detected.

---

RISK ASSESSMENT

Overall Risk Score: 25/100 (Low Risk)

Reputation Classification: Low Risk

Threat indicators assessment reveals no known attacker status, no Tor exit node activity, and no spam source designation. The IP maintains zero blacklisted entries and shows no evidence of persistent malicious behavior.

Control Plane Data:

---

NETWORK CLASSIFICATION

Infrastructure Type: None identified

Network Role: Firewalled / No Services

Service Purpose: Firewall or blocked traffic

No active services detected on open ports. TLS certificates, HTTP titles, and server banners remain absent. The IP operates as a static endpoint without hosting, proxy, or CDN functionality.

---

DNS ANALYSIS

PTR Hostnames: 6.bl.bot.semrush.com

Forward Resolution: Confirmed to semrush.com domain

Forward Resolution Count: 1

Email Authentication: SPF record present; DMARC record absent

TXT Record Count: 0

The DNS association points to Semrush botnet infrastructure (semrush.com), suggesting this endpoint may be part of a legitimate security or analytics infrastructure.

---

NEIGHBORHOOD ANALYSIS

Subnet: 185.191.171.0/24

Total Siblings: 19

Active Siblings: 10

Threat Siblings: 1

Abuse Density: 0.0526 (mostly clean)

Inherited Risk: 2

All 18 neighboring IPs in the /24 subnet maintain identical risk scores (25) and authority scores (60). The subnet shows minimal abuse density with no high-risk neighbors detected.

---

OBSERVATION HISTORY

Total Observations: 19

Most Recent: 2026-07-22T02:43:31 UTC

Historical data shows consistent low-risk classification across multiple observation windows. The subnet classification evolved from "clean" to "mostly_clean" with minimal inherited risk propagation. No significant threat persistence observed.

---

RELATIONSHIP GRAPH

Total Relationships: 21

Primary Associations:

The relationship graph indicates strong DNS association with Semrush bot infrastructure and consistent network-level relationships within the allocated CIDR block.

---

THREAT INTELLIGENCE RECOMMENDATIONS

Action Required: None

Blocking Recommendation: Not recommended

The IP address demonstrates no active threat behavior and maintains clean reputation across threat feeds. No firewall rules or blocking actions are warranted at this time. The IP's association with Semrush infrastructure and low-risk classification supports continued monitoring without restrictive measures.

SOC Analyst Notes: Monitor for any changes in service availability or DNS resolution patterns. The subnet shows uniform risk characteristics across all siblings, indicating coordinated infrastructure deployment rather than opportunistic threat actor activity.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇬🇧 United Kingdom
RegionLimassol
CityCYPRUS
TimezoneEurope/London
Latitude—
Longitude—

🏢 Ownership & Registration

OrganizationJaroslav Jacjuk
ASNAS209366
Network NameSCL66-rented1
CIDR Block185.191.171.0/24
RIRRIPE
CountryCY
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR6.bl.bot.semrush.com
Forward ConfirmedYes — FCrDNS verified
Forward Hostnames6.bl.bot.semrush.com

🔐 DNS Hygiene

Hygiene Score100% (Excellent)
SPF2/2 domains
DMARC2/2 domains
FCrDNSVerified
DNSSECValid
CAAPresent
Domains Checked2 domains

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierTier 3 — Basic operator with some routing infrastructure
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS209366
Network Prefix185.191.171.0/24
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
35%
23
routing
13%
11
services
19%
22
ownership
27%
23
reputation
13%
12
geolocation
19%
22
Overall21%1013
Coverage: 6/6 dimensions · Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

📅 Observation Timeline 🔄 Live

First Seen2026-06-30 13:39:56 UTC
Last Seen2026-08-22 10:40:22 UTC
Profile Built2026-08-29 11:05:07 UTC
Data FreshnessLive
Signal Types20
Total Observations23
🔍 20 signal types · 23 observations collected
This report is generated from 20+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 185.191.171.6

Who owns the IP address 185.191.171.6?

185.191.171.6 is registered to Jaroslav Jacjuk. The address falls within the 185.191.171.0/24 network block. Registration is held at RIPE.

Where is 185.191.171.6 located?

Geolocation data places 185.191.171.6 in CYPRUS, Limassol, United Kingdom. The local time zone is Europe/London. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 185.191.171.6 malicious or safe?

185.191.171.6 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.

What is the hostname for 185.191.171.6?

The reverse DNS (PTR) record for 185.191.171.6 is 6.bl.bot.semrush.com. This hostname is forward-confirmed, meaning it resolves back to the same address.

🏘️ Related IP Addresses

Nearby addresses in 185.191.171.0/24

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.