# Threat Intelligence Briefing: 185.198.56.217/32
## Executive Summary
IP address 185.198.56.217 is classified as a Tor exit node with a moderate risk score of 59/100. The IP is registered under ASN 60117 to organization "Ali Al-Attiyah" (Netname: AE-SAILORHOST-20170406) within the RIPE region, located in the Netherlands (NL). No active services were detected on this IP, and it was determined to be firewalled with no open ports.
## Key Indicators
- Classification: Tor Exit Node
- Risk Score: 59/100 (Moderate Risk)
- Blacklist Status: Listed on 1 DNS blacklist (out of 8 total lists)
- Network Role: Anonymous proxy/exit node infrastructure
- Geolocation: Netherlands (NL), coordinates 52.13°N, 5.29°E
## Threat Observations
Tor exit node indicators were observed during passive collection. The IP is associated with the subnet 185.198.56.0/24, which maintains a subnet classification of "mostly_clean" with low inherited risk. No active services were detected on this IP address, and reverse DNS resolution returned only a reverse pointer record with no forward confirmation.
## Historical Analysis
Signal observation history shows 44 recorded observations. Recent signal quality assessments indicate "Minimal" signal quality across routing, ownership, and reputation dimensions. Traceroute analysis completed successfully with 30 hops, though ICMP validation was blocked. Route stability analysis indicated one route change within the past 30 days, suggesting network-level configuration modifications.
## Network Relationships
The IP maintains multiple relationships to network AE-SAILORHOST-20170406. No related hostnames, organizations, or certificates were identified in the relationship graph. The subnet neighborhood analysis showed one active sibling IP with threat indicators present.
## Recommended Actions
Based on the risk profile, the following actions are recommended:
1. Access Control: Implement enhanced verification for anonymous traffic originating from this IP address
2. Monitoring: Increase logging verbosity and review recent activity from this IP for potential abuse patterns
3. Blocking: Consider firewall rules to block traffic from this IP:
- `iptables -A INPUT -s 185.198.56.217 -j DROP`
- `nft add rule inet filter input ip saddr 185.198.56.217 drop`
- Equivalent rules available for pfSense, Cloudflare WAF, and AWS WAF
## Intelligence Assessment
This IP represents typical Tor exit node infrastructure with moderate risk characteristics. While not classified as a known attacker or spam source, the Tor exit node classification warrants defensive measures including enhanced logging and access control verification. No evidence of persistent malicious activity or campaign association was identified.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Ali Al-Attiyah |
| ASN | AS60117 |
| Network Name | AE-SAILORHOST-20170406 |
| CIDR Block | 185.198.56.0/24 |
| RIR | RIPE |
| Country | NL |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | 217.128-255.56.198.185.in-addr.arpa |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | server103356.hostsailor.com217.128-255.56.198.185.in-addr.arpa |
🔐 DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | 1/2 domains |
| DMARC | 1/2 domains |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
| Domains Checked | 2 domains |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS60117 |
| Network Prefix | 185.198.56.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 30% | 2 | 3 |
| services | 19% | 2 | 2 |
| ownership | 37% | 3 | 5 |
| reputation | 26% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 28% | 12 | 20 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-17 17:46:57 UTC |
| Last Seen | 2026-09-01 00:47:53 UTC |
| Profile Built | 2026-08-29 13:07:00 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 32 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 185.198.56.217
Who owns the IP address 185.198.56.217?
185.198.56.217 is registered to Ali Al-Attiyah. The address falls within the 185.198.56.0/24 network block. Registration is held at RIPE.
Where is 185.198.56.217 located?
Geolocation data places 185.198.56.217 in Bucharest, Bucharest, Netherlands. The local time zone is Europe/Amsterdam. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 185.198.56.217 malicious or safe?
185.198.56.217 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 185.198.56.217?
The reverse DNS (PTR) record for 185.198.56.217 is 217.128-255.56.198.185.in-addr.arpa. This hostname is not forward-confirmed, so it should be treated as a weak signal.