# IP Intelligence Briefing: 185.242.3.49/32
Classification: Moderate Risk β Requires Monitoring
Report Date: Current
IP Address: 185.242.3.49/32
---
## Executive Summary
IP address 185.242.3.49 is assigned to ASN 401626 (FELCLOUDNET-MNT) within the Felcloud-24 CIDR block (185.242.3.0/24). The IP presents a moderate risk score of 55/100 with no open services detected. While the subnet exhibits low abuse density (2.9%), the target IP is recommended for blocking due to elevated risk classification.
---
## Technical Profile
| Attribute | Value |
|---|---|
| **ASN** | 401626 (FELCLOUDNET-MNT) |
| **Country** | United States (US-MA) |
| **City** | Boston |
| **Service Type** | Firewalled / No Services |
| **DNSBL Listings** | 3 of 8 lists |
| **Route Stability** | Unstable |
| **DNSSEC Valid** | Yes |
---
## Threat Indicators
The IP shows no active threat indicators: not a Tor exit node, not classified as a known attacker or spam source. No campaigns or correlated IPs detected. However, three DNSBL listings indicate prior reputation issues.
---
## Neighborhood Analysis
The /24 subnet contains 35 total sibling IPs with 24 currently active. Risk distribution shows:
- High Risk: 1 IP
- Medium Risk: 9 IPs
- Low Risk: 24 IPs
The subnet is classified as "clean" with an abuse density of 0.029. One threat sibling (185.242.3.195) shows elevated risk score of 80.
---
## Observation History
Sixteen signals observed with the most recent activity on 2026-07-29. Signals include mixed geolocation data (US with 28% confidence, Poland with 30% confidence) and multiple service scan attempts. No persistent malicious behavior detected.
---
## Recommended Actions
Immediate:
- Block IP at network perimeter (recommended for iptables, nftables, pfSense, Cloudflare WAF, AWS WAF)
- Increase logging verbosity to monitor any activity
Rationale: Elevated risk score (55/100) combined with DNSBL presence warrants defensive blocking despite lack of active threat indicators.
---
## Intelligence Confidence
Moderate β IP shows no open services and limited historical threat activity, but DNSBL listings and moderate risk classification warrant continued monitoring and blocking.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | FELCLOUDNET-MNT |
| ASN | AS401626 |
| Network Name | Felcloud-24 |
| CIDR Block | 185.242.3.0/24 |
| RIR | RIPE |
| Country | US |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 25% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 22% | 6 | 7 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-23 07:48:38 UTC |
| Last Seen | 2026-07-29 17:17:51 UTC |
| Profile Built | 2026-07-29 17:25:58 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.