IPDebrief

185.198.56.217

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# Threat Intelligence Briefing: 185.198.56.217/32

## Executive Summary

IP address 185.198.56.217 is classified as a Tor exit node with a moderate risk score of 59/100. The IP is registered under ASN 60117 to organization "Ali Al-Attiyah" (Netname: AE-SAILORHOST-20170406) within the RIPE region, located in the Netherlands (NL). No active services were detected on this IP, and it was determined to be firewalled with no open ports.

## Key Indicators

## Threat Observations

Tor exit node indicators were observed during passive collection. The IP is associated with the subnet 185.198.56.0/24, which maintains a subnet classification of "mostly_clean" with low inherited risk. No active services were detected on this IP address, and reverse DNS resolution returned only a reverse pointer record with no forward confirmation.

## Historical Analysis

Signal observation history shows 44 recorded observations. Recent signal quality assessments indicate "Minimal" signal quality across routing, ownership, and reputation dimensions. Traceroute analysis completed successfully with 30 hops, though ICMP validation was blocked. Route stability analysis indicated one route change within the past 30 days, suggesting network-level configuration modifications.

## Network Relationships

The IP maintains multiple relationships to network AE-SAILORHOST-20170406. No related hostnames, organizations, or certificates were identified in the relationship graph. The subnet neighborhood analysis showed one active sibling IP with threat indicators present.

## Recommended Actions

Based on the risk profile, the following actions are recommended:

1. Access Control: Implement enhanced verification for anonymous traffic originating from this IP address

2. Monitoring: Increase logging verbosity and review recent activity from this IP for potential abuse patterns

3. Blocking: Consider firewall rules to block traffic from this IP:

- `iptables -A INPUT -s 185.198.56.217 -j DROP`

- `nft add rule inet filter input ip saddr 185.198.56.217 drop`

- Equivalent rules available for pfSense, Cloudflare WAF, and AWS WAF

## Intelligence Assessment

This IP represents typical Tor exit node infrastructure with moderate risk characteristics. While not classified as a known attacker or spam source, the Tor exit node classification warrants defensive measures including enhanced logging and access control verification. No evidence of persistent malicious activity or campaign association was identified.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇳🇱 Netherlands
RegionBucharest
CityBucharest
TimezoneEurope/Amsterdam
Latitude52.13
Longitude5.29

🏢 Ownership & Registration

OrganizationAli Al-Attiyah
ASNAS60117
Network NameAE-SAILORHOST-20170406
CIDR Block185.198.56.0/24
RIRRIPE
CountryNL
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR217.128-255.56.198.185.in-addr.arpa
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesserver103356.hostsailor.com
217.128-255.56.198.185.in-addr.arpa

🔐 DNS Hygiene

Hygiene Score80% (Excellent)
SPF1/2 domains
DMARC1/2 domains
FCrDNSNot verified
DNSSECValid
CAAPresent
Domains Checked2 domains

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS60117
Network Prefix185.198.56.0/24
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
29%
24
routing
30%
23
services
19%
22
ownership
37%
35
reputation
26%
13
geolocation
30%
23
Overall28%1220
Coverage: 6/6 dimensions · Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

📅 Observation Timeline 🔄 Live

First Seen2026-07-17 17:46:57 UTC
Last Seen2026-09-01 00:47:53 UTC
Profile Built2026-08-29 13:07:00 UTC
Data FreshnessLive
Signal Types26
Total Observations32
🔍 26 signal types · 32 observations collected
This report is generated from 26+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 185.198.56.217

Who owns the IP address 185.198.56.217?

185.198.56.217 is registered to Ali Al-Attiyah. The address falls within the 185.198.56.0/24 network block. Registration is held at RIPE.

Where is 185.198.56.217 located?

Geolocation data places 185.198.56.217 in Bucharest, Bucharest, Netherlands. The local time zone is Europe/Amsterdam. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 185.198.56.217 malicious or safe?

185.198.56.217 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.

What is the hostname for 185.198.56.217?

The reverse DNS (PTR) record for 185.198.56.217 is 217.128-255.56.198.185.in-addr.arpa. This hostname is not forward-confirmed, so it should be treated as a weak signal.

🏘️ Related IP Addresses

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.