# IP Intelligence Briefing: 185.247.137.186/32
Classification: Moderate Risk (Score: 50) | Status: Monitored | Data Collected: 2026-06-25
## Executive Summary
IP 185.247.137.186 is a single-service host associated with Driftnet Hostmaster (ASN 211298) in Manchester, England. The IP exhibits moderate risk characteristics driven by DNSBL listings and hosting infrastructure patterns, with no evidence of active malicious behavior. Recommended action: Monitor; no immediate blocking required.
## Technical Profile
| Attribute | Value |
|---|---|
| **Risk Score** | 50 (Moderate) |
| **ASN** | 211298 |
| **Organization** | Driftnet Hostmaster |
| **Location** | Manchester, England, GB |
| **Geolocation Accuracy** | ±500km |
| **DNSBL Listings** | 2 of 8 |
| **Open Ports** | 80/TCP (HTTP) |
| **HTTP Status** | 302 Redirect |
## Threat Assessment
Positive Indicators:
- No known attacker associations
- No Tor exit node activity
- No spam source classification
- No campaign matches detected
Risk Factors:
- DNSBL listed on 2 threat intelligence feeds
- Moderate operator score (0.2609)
- DNSBL listings indicate reputation concerns with email authentication systems
## Network Context
Subnet Analysis (185.247.137.0/24):
- Abuse Density: 0.3723 (mixed classification)
- Total Siblings: 188
- Active Siblings: 49
- Threat Siblings: 70
- Risk Distribution: 0 High, 38 Medium, 62 Low
Relationships:
- DNS associations to monitoring.internet-measurement.com infrastructure
- Network association: UK-DRIFTNET-20180301
## Historical Activity
- Observations: 24 total signals tracked
- Timeline: Most recent signal 2026-06-25
- Trend: Consistent monitoring pattern with no escalation
- Geolocation Validation: ICMP blocked; location validation incomplete
## Recommended Actions
Firewall Rules:
- No immediate blocking required
- Rate limiting recommended for port 80 traffic if exposure concerns exist
- Monitor for any new DNSBL additions
SOC Guidance:
- This IP functions as a hosting/monitoring infrastructure address
- DNSBL listings likely related to email reputation management
- No evidence of command-and-control, spam, or attack activity
- Continue routine monitoring; no threat intelligence indicators present
Priority: LOW | Confidence: HIGH | Last Updated: 2026-06-25
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Driftnet Hostmaster |
| ASN | AS211298 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | r4-186-ba.monitoring.internet-measurement.com |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | r4-186-ba.monitoring.internet-measurement.com |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| Closed Ports | 22, 25, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 24% | 2 | 3 |
| ownership | 20% | 2 | 3 |
| reputation | 19% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 21% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-08 11:10:10 UTC |
| Last Seen | 2026-06-25 05:32:06 UTC |
| Profile Built | 2026-06-25 05:49:35 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 24 |
Full dossier details are available via our API.