# IP Intelligence Briefing: 185.247.137.130
## Executive Summary
IP 185.247.137.130 presents as a low-risk (score: 25) single-service host associated with UK hosting infrastructure. The address shows minimal threat activity and is classified as a monitoring/infrastructure endpoint. No immediate blocking action required, but neighborhood context suggests moderate baseline risk.
## Current Risk Profile
- Risk Score: 25 (Low Risk)
- Reputation: Low Risk
- Provider/Authority/Ownership: No definitive ownership data available
- Stability: No ownership changes observed
## Geolocation & Network Infrastructure
- Location: Manchester, England, GB (Europe/London timezone)
- ASN: 211298 (Driftnet Hostmaster)
- Geolocation Consensus: Single-source data with 500km accuracy radius
- Service Type: Single-Service Host with HTTP port 80 open
- Control Plane: 1 DNSBL listing out of 8 total lists; route changes observed within 30-day window
## Threat Intelligence
- Blacklist Status: Listed on 1 of 8 threat feeds
- Tor Exit: Not confirmed as Tor exit node
- Known Attacker: No indicators
- Spam Source: Not flagged
- Active Campaigns: None detected
- DNS Records: r4-130-82.monitoring.internet-measurement.com (forward confirmed)
## Neighborhood Analysis (185.247.137.0/24)
- Subnet Classification: Mostly Clean
- Abuse Density: 17.11% (39 threat siblings out of 228 total)
- Inherited Risk Score: 6
- Risk Distribution: 0 high-risk, 39 medium-risk, 61 low-risk neighbors
- Notable Neighbors: 185.247.137.2 (risk: 50), 185.247.137.3 (risk: 65), 185.247.137.5 (risk: 25)
## Historical Observation
- Total Observations: 23 signals recorded
- Recent Activity: Monitoring for subnet abuse density and DNS listings
- Threat Persistence: No persistent malicious activity detected
- Observation Confidence: Variable (0.25โ0.85) across different signal types
## Key Relationships
- DNS Association: r4-130-82.monitoring.internet-measurement.com
- Network Affiliation: UK-DRIFTNET-20180301
- Network Type: Not CDN, not VPN, not proxy infrastructure
## Recommended Actions
- No immediate blocking required based on current risk profile
- Monitor for DNSBL listing escalations (currently 1 of 8)
- Consider contextual blocking if source traffic correlates with medium-risk subnet neighbors (185.247.137.2, 185.247.137.3)
- Verify traffic patterns against expected monitoring infrastructure behavior
## Intelligence Notes
This IP appears to function as a legitimate monitoring endpoint based on hostname patterns and service profile. The subnet contains moderate abuse density (17%), suggesting some neighbors may require monitoring. No actionable threat indicators present at this time.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Driftnet Hostmaster |
| ASN | AS211298 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | r4-130-82.monitoring.internet-measurement.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | r4-130-82.monitoring.internet-measurement.com |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| Closed Ports | 22, 25, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 42% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 24% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 19% | 1 | 2 |
| geolocation | 27% | 2 | 2 |
| Overall | 24% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-09 11:33:45 UTC |
| Last Seen | 2026-06-25 15:37:28 UTC |
| Profile Built | 2026-06-25 15:44:17 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 21 |
Full dossier details are available via our API.