# IP Intelligence Briefing
IP Address: 185.255.215.145/32
Classification: High Risk
Date: 2026-06-26
---
## Executive Summary
IP address 185.255.215.145 is classified as High Risk (risk score: 80/100) with reputation flagged as "High Risk." The address is geolocated to Karnobat, Burgas, Bulgaria (BG) within AS200475 (IPACCT-MNT). Current service scanning indicates no active ports and no open services (Firewalled / No Services).
---
## Threat Profile
Risk Assessment: High Risk (80/100)
Provider Score: 0/100
Authority Score: 0/100
Stability: Null
Threat Indicators:
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0
- DNSBL Listed: 3 of 8 total lists
Network Role: Infrastructure host with no detected services
Network Classification: Firewalled / No Services
---
## Geolocation & Ownership
Country: Bulgaria (BG)
Region: Burgas
City: Karnobat
Coordinates: 42.73°N, 25.49°E
ASN: 200475
Organization: IPACCT-MNT
RIR: RIPE
BGP Prefix: 185.255.212.0/22
---
## Neighborhood Analysis (185.255.215.0/24)
Subnet Classification: Mixed
Abuse Density: 0.50 (50%)
Total Siblings: 30
Active Siblings: 8
Threat Siblings: 15
Risk Distribution:
- High Risk: 10 IPs
- Medium Risk: 19 IPs
- Low Risk: 0 IPs
Key High-Risk Neighbors: 185.255.215.7, 185.255.215.16, 185.255.215.57, 185.255.215.59, 185.255.215.78, 185.255.215.79, 185.255.215.103, 185.255.215.139, 185.255.215.165, 185.255.215.175 (all risk score: 80)
Inherited Risk Score: 20/100
---
## Historical Observations
Total Observations: 16
Recent Activity: 2026-06-26
Timeline:
- 2026-06-26 14:56: 8 blacklist listings detected (max severity: High)
- 2026-06-26 14:54: Operator score: 0 (Minimal)
- 2026-06-06 09:04: Subnet classification updated (abuse density: 0.5, mixed classification)
Threat Persistence: 0 days
Is Persistently Malicious: No
---
## Network Relationships
Primary Network Association: BG-KARNOBATNET (16 relationship entries)
Route Stability: Unstable (false)
MOAS Status: No
RPKI State: Not Available
IRRC Consistency: Not Available
Route Changes (30d): 0
---
## Control Plane Data
DNSSEC Valid: Yes
Has CAA: No
Operator Score: 0
Delegation Age: Not Available
---
## Recommended Actions
Current Firewall Recommendations: None generated (IP classified as Firewalled / No Services)
Threat Mitigation: Monitor subnet for lateral movement; 50% abuse density indicates coordinated threat activity in neighborhood.
---
## Intelligence Narrative
The IP address 185.255.215.145 resides within a high-abuse subnet (185.255.215.0/24) in Bulgaria with 50% abuse density and 15 threat-sibling addresses. While the target IP itself shows no active threat indicators and no open services, the subnet-level threat posture warrants defensive monitoring. The neighborhood contains 10 high-risk IPs with matching risk scores (80), suggesting potential infrastructure sharing or coordinated abuse activity. Historical data indicates recent blacklist activity on 2026-06-26 with 8 listings at high severity.
SOC Analyst Guidance: Implement monitoring on the /24 subnet for potential lateral movement. Consider blocking the subnet at perimeter if business justification exists. The IP is not currently active as a service host but remains classified as high risk due to neighborhood contamination.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IPACCT-MNT |
| ASN | AS200475 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-dropbear <?zt???A3??(?B???curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-gro |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 24% | 2 | 3 |
| reputation | 25% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 19% | 9 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-12 03:43:12 UTC |
| Last Seen | 2026-06-26 18:10:55 UTC |
| Profile Built | 2026-06-26 15:10:34 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 19 |
Full dossier details are available via our API.