IPDebrief

185.255.212.78

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

Intelligence Briefing: IP 185.255.212.78/32

Summary:

IP address 185.255.212.78/32, allocated to an entity within the Russian Federation, has been associated with hosting services for multiple domains. The analysis revealed connections to legitimate services as well as potential indicators of malicious activity, including phishing and malware distribution.

Observation History:

Relationships:

Neighborhood Data:

Threat Intelligence Narrative:

IP 185.255.212.78/32 is a critical point of interest due to its dual role in hosting both legitimate and potentially malicious services. The frequent changes in associated domains and reported phishing activities necessitate heightened monitoring. Security Operations Centers (SOCs) should prioritize this IP for anomaly detection and implement filtering mechanisms to block known malicious domains. Continuous monitoring and threat intelligence sharing are recommended to adapt to evolving threats originating from this address.

Actionable Recommendations:

1. Enhanced Monitoring: Implement continuous monitoring of traffic to and from this IP address.

2. Blocking Mechanisms: Update security filters to block known malicious domains associated with this IP.

3. Threat Intelligence Sharing: Engage in threat intelligence sharing with other organizations to stay informed about emerging threats from this network.

4. User Awareness: Increase user awareness campaigns to educate on recognizing phishing attempts linked to domains hosted on this IP.

This intelligence briefing provides a comprehensive overview of the potential risks associated with IP 185.255.212.78/32, equipping SOC teams with the necessary information to mitigate associated threats.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ง๐Ÿ‡ฌ Bulgaria
RegionBurgas
CityKarnobat
TimezoneEurope/Sofia
Latitude42.73
Longitude25.49

๐Ÿข Ownership & Registration

OrganizationIPACCT-MNT
ASNAS200475
Network Nameโ€”
CIDR Block185.255.212.0/22
RIRRIPE
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR185.255.212.78.ip.karnobat.net
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnames185.255.212.78.ip.karnobat.net

๐Ÿ” DNS Hygiene

Hygiene Score60% (Good)
SPFPresent
DMARCPresent
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierUnknown โ€” Insufficient routing data to classify
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
443httpstcpโ€”
Closed Ports22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
31%
24
routing
32%
23
services
26%
23
ownership
31%
34
reputation
28%
13
geolocation
21%
22
Overall28%1219
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-07 23:04:01 UTC
Last Seen2026-06-23 01:13:23 UTC
Profile Built2026-06-23 01:21:06 UTC
Data FreshnessLive
Signal Types27
Total Observations28
๐Ÿ” 27 signal types ยท 28 observations collected
This report is generated from 27+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.