# IP Intelligence Briefing: 185.206.225.59/32
Date: 2026-07-29
Classification: Moderate Risk (Score: 40/100)
Status: Clean Network Infrastructure
## Executive Summary
IP address 185.206.225.59 is a residential/infrastructure IP assigned to GLOBALAXS OSLO NOC (M247-LTD-OSLO) under RIPE NCC. The IP presents a moderate risk profile (40) with no active threat indicators, no blacklist entries, and clean neighborhood classification. No open services detected; IP is currently firewalled with no active services.
## Network Ownership & Infrastructure
- ASN: 9009
- Organization: GLOBALAXS OSLO NOC (M247-LTD-OSLO)
- CIDR Block: 185.206.225.0/24
- Geolocation: United Kingdom (GB) โ London Sector
- RIR: RIPE
- BGP Prefix: 185.206.225.0/24 (Origin ASN: 9009)
- Route Stability: False (0 route changes in 30 days)
## Threat Profile
- Risk Score: 40 (Moderate)
- Abuse Confidence Score: Not calculated
- Blacklist Status: Listed on 2 of 8 DNSBLs
- Known Threat Indicators: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaign Correlation: None identified
## Network Services & DNS
- Open Ports: None detected (firewalled/no services)
- TLS Certificate: None
- HTTP Title: None
- Reverse DNS: 59.225.206.185.in-addr.arpa
- Forward DNS Resolution: Unconfirmed (1 hostname)
- Email Auth: No SPF or DMARC records
## Neighborhood Analysis (185.206.225.0/24)
- Subnet Classification: Clean
- Abuse Density: 0
- Total Siblings: 2
- Active Siblings: 0
- Threat Siblings: 0
- Neighbor Risk: 185.206.225.51 (Risk: 15, Authority: 50)
## Historical Observations
- Total Signals: 17 observations
- Last Observed: 2026-07-29 13:48 UTC
- Ownership Changes: 0
- Threat Persistence Days: 0
- Persistently Malicious: No
- Recent Activity: Provider identification confirmed (GLOBALAXS OSLO NOC); network classified as clean; no service scans indicating exploitation attempts
## Network Behavior
- Traceroute Hops: 18
- First Hop RTT: 0.2ms
- Last Hop RTT: 126.4ms
- Timed Out Hops: 3
- Transit Networks: Comcast, Cogent
- DNSSEC Valid: Yes
- RPKI State: Not verified
## Recommended Actions
Based on risk score 40, the following blocking rules are recommended:
Firewall Rules:
- iptables: `iptables -A INPUT -s 185.206.225.59 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 185.206.225.59 drop`
- nginx: `deny 185.206.225.59;`
- pfSense: `185.206.225.59/32`
- Cloudflare WAF: Block IP with description "IPDebrief risk score 40"
- AWS WAF: Add address 185.206.225.59/32 with description "IPDebrief risk 40"
Note: These recommendations are probabilistic and should be combined with other signals before taking action.
## Assessment
This IP belongs to M247 infrastructure network with no evidence of malicious activity. The moderate risk score (40) reflects DNSBL listings but not active threat behavior. The subnet shows minimal abuse density with one low-risk sibling IP. No immediate threat indicators warrant escalation. SOC analysts may consider blocking at perimeter firewalls if traffic correlation with incidents exists, but no active campaign or attack pattern identified.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | GLOBALAXS OSLO NOC |
| ASN | AS9009 |
| Network Name | M247-LTD-OSLO |
| CIDR Block | 185.206.225.0/24 |
| RIR | RIPE |
| Country | NO |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 59.225.206.185.in-addr.arpa |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 59.225.206.185.in-addr.arpa |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-22 13:24:00 UTC |
| Last Seen | 2026-08-01 22:41:34 UTC |
| Profile Built | 2026-07-29 13:55:03 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 19 |
Full dossier details are available via our API.