# IPDEBRIEF INTELLIGENCE BRIEFING
## Target: 185.255.100.243/32
Classification: Low Risk | SOC Action: Monitor
---
EXECUTIVE SUMMARY
The target IP 185.255.100.243 is classified as Low Risk with a risk score of 25. The address is associated with IP_HostMaster (AS9009) and is geolocated to New York, United States. While the IP shows minimal threat indicators, it is listed on one DNS blacklist and resides in a subnet with mixed-classification peers. No active malicious campaigns or known attacker indicators were observed.
---
OWNERSHIP & INFRASTRUCTURE
- Organization: IP_HostMaster (m247 ltd)
- ASN: AS9009
- Registry: RIPE (allocated 2005-06-06; age: 7,681 days)
- IP Block: 185.255.100.0/24 (BGPPrefix: 185.255.100.0/24)
- Route Stability: Stable (no changes in last 30 days)
- Service Purpose: Single-Service Host
- Open Ports: TCP/22 (SSH)
---
GEOLOCATION
- Country: United States (US)
- Region: New York (NY)
- Coordinates: 40.80°N, -73.9763°W
- GeoSources: 2 sources; consensus achieved
- Validation: Geo-plausibility status: False
---
THREAT INDICATORS
- Overall Risk Score: 25 (Low Risk)
- Reputation: Low Risk
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 1 (of 8 total DNSBL checks)
- Threat Feeds: Empty
- Known Campaigns: None detected
- Campaign Likelihood: None
---
NETWORK BEHAVIOR & SERVICES
- DNS Resolution: No forward resolution; no PTR records
- Email Auth: No SPF/DMARC records
- TLS Certificate: None observed
- HTTP Service: No web services detected
- Control Plane: RPKI state: Not available; IRR consistency: Not available
---
OBSERVATION HISTORY
- Total Signals: 21 observations
- Latest Observation: 2026-06-23T01:13:14 UTC
- Threat Persistence: Not persistently malicious
- Recent Activity: Threat signals observed in recent observations (AlienVault OTX pulse count: 15)
- Routing Profile: Minimal operator score (0.1304)
---
NEIGHBORHOOD ANALYSIS (185.255.100.0/24)
- Total Siblings: 20 IPs
- Active Siblings: 14
- Risk Distribution:
- High Risk: 0
- Medium Risk: 9
- Low Risk: 10
- Abuse Density: 0.45 (inherited risk: 18)
- Notable Peers: Multiple IPs with risk scores of 25-50, including 185.255.100.10, 185.255.100.12, 185.255.100.14, 185.255.100.90, 185.255.100.194, 185.255.100.196, 185.255.100.197, 185.255.100.198, 185.255.100.202, 185.255.100.203, 185.255.100.230, 185.255.100.234, 185.255.100.236, 185.255.100.242, 185.255.100.245, 185.255.100.248, 185.255.100.249, 185.255.100.250, 185.255.100.251
---
RELATIONSHIP GRAPH
- Total Relationships: 18
- Primary Association: ServersFactory_ny (network)
- Network Classification: Same Network associations to multiple instances of ServersFactory_ny
---
RECOMMENDED ACTIONS
- SOC Classification: Monitor
- Firewall Rule: No immediate blocking required; monitor for behavioral changes
- Threat Intel: Continue monitoring DNSBL listings and reputation feeds
- Network Defense: Standard monitoring recommended; no aggressive blocking advised
---
ANALYST NOTES
This IP represents a low-risk single-service host with SSH access. While the subnet shows mixed risk characteristics, the target IP itself lacks direct threat indicators. The presence of DNSBL listings warrants monitoring but does not justify immediate blocking. Correlation with ServersFactory_ny network suggests infrastructure association with a known hosting entity.
*Report generated: 2026-06-23*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | IP_HostMaster |
| ASN | AS9009 |
| Network Name | β |
| CIDR Block | 185.255.100.0/24 |
| RIR | RIPE |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_7.4 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 4 |
| routing | 32% | 2 | 3 |
| services | 15% | 2 | 2 |
| ownership | 34% | 3 | 4 |
| reputation | 28% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 26% | 12 | 18 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:01 UTC |
| Last Seen | 2026-06-23 01:12:53 UTC |
| Profile Built | 2026-06-23 01:20:02 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.