# INTELLIGENCE BRIEFING: 185.223.152.112
Classification: Moderate Risk | Report Date: 2026-07-30 | Analyst: IPDebrief SOC
---
## EXECUTIVE SUMMARY
IP address 185.223.152.112 presents a moderate risk profile (score: 50/100) with no active threat indicators. The IP is associated with RIPE-registrant IPXO (ASN: 396356, netutils-mnt) and shows geolocation inconsistencies. No open services, Tor exit, or known malicious activity detected. Recommended action: Block at perimeter firewall.
---
## NETWORK OWNERSHIP & INFRASTRUCTURE
| Attribute | Value |
|---|---|
| **ASN** | 396356 |
| **Organization** | netutils-mnt |
| **Netname** | IPXO |
| **CIDR Block** | 185.223.152.0/23 |
| **RIR** | RIPE |
| **Control Plane** | 185.223.152.0/24 |
| **Route Stability** | Unstable |
Network Classification: Infrastructure (firewalled/no services)
---
## GEOLOCATION ANALYSIS β οΈ
Flagged: Data Inconsistencies Detected
| Parameter | Reported Value | Status |
|---|---|---|
| Country | GB | β οΈ |
| City/Region | Boston, US-MA | β οΈ |
| Distance from Source | 9,014 km | β οΈ |
| RTT Measurement | 78 ms | β οΈ |
| **RTT Violation** | 78ms < 180.3ms minimum | **INVALID** |
| Geo Confidence | 0.28 / 0.30 | Low |
| GeoPlausible | **false** | β |
Assessment: Geolocation data is unreliable due to RTT distance violations. IP may be spoofed, misconfigured, or using proxy/relay infrastructure.
---
## THREAT ASSESSMENT
| Indicator | Status |
|---|---|
| **Overall Risk Score** | 50 (Moderate) |
| Threat Indicators | None |
| Blacklist Count | 0 |
| DNSBL Listings | 2/8 |
| Is Tor Exit | false |
| Is Known Attacker | false |
| Is Spam Source | false |
| Open Ports/Services | None |
| Active Certificates | None |
| Known Campaigns | None |
Neighborhood Context (185.223.152.0/24):
- Total Siblings: 198
- Active Siblings: 116
- Threat Siblings: 8
- Abuse Density: 4.04%
- Risk Distribution: 0 high, 17 medium, 83 low
---
## OBSERVATION HISTORY
16 signals observed across 2026-07-30:
- Network classification: Stable (inherited_risk: 1)
- Ownership changes: 0
- Threat observation count: 0
- Persistently malicious: false
- No campaigns correlated
Temporal Analysis: No persistent malicious behavior detected. IP appears dormant with no historical threat activity.
---
## RECOMMENDED SECURITY ACTIONS
Action Level: BLOCK (Risk Score: 50)
Firewall Rules
- iptables: `iptables -A INPUT -s 185.223.152.112 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 185.223.152.112 drop`
- nginx: `deny 185.223.152.112;`
- pfSense: `185.223.152.112/32`
- Cloudflare WAF: Block IP (risk score 50)
- AWS WAF: 185.223.152.112/32
Note: These recommendations are probabilistic and should be combined with other signals before enforcement.
---
## INTELLIGENCE NARRATIVE
This IP address belongs to the IPXO network (185.223.152.0/23) under RIPE registration. The moderate risk score reflects baseline caution rather than active malicious behavior. Critical geolocation anomaliesβspecifically the impossible RTT measurement of 78ms for a 9,014km distanceβindicate potential IP spoofing, proxy usage, or data quality issues. No threat indicators, blacklists, or open services were detected. The /24 subnet shows low abuse density (4.04%) with 8 identified threat siblings out of 198 total addresses.
Recommendation: Apply blocking rules at perimeter defense layers. Monitor for any service openings or reputation changes. The IP's dormant status and lack of persistent malicious activity suggest low immediate threat, but geolocation inconsistencies warrant continued monitoring.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | netutils-mnt |
| ASN | AS396356 |
| Network Name | IPXO |
| CIDR Block | 185.223.152.0/23 |
| RIR | RIPE |
| Country | GB |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 35% | 2 | 2 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 14% | 4 | 4 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-29 04:30:09 UTC |
| Last Seen | 2026-08-11 17:58:24 UTC |
| Profile Built | 2026-08-11 05:42:09 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 18 |
Full dossier details are available via our API.