IP Intelligence Briefing: 185.39.207.83
Date: 2026-06-16
---
**1. Risk Profile**
- Overall Risk: Moderate (Risk Score: 59)
- Threat Indicators:
- Tor exit node activity detected.
- Listed in 1 DNSBL (domain-based blocklist).
- Ownership:
- Registered to Global Connectivity Solutions (ASN 215540).
- Geolocation claims Greece (GR) but resolves to Khanty-Mansiysk, Russia (potential spoofing).
- Network Role:
- Classified as a Tor exit node (single-service host).
- No CDN, cloud, or residential indicators.
---
**2. Observations & Activity**
- SSH Service:
- Open port 22 (SSH) with banner: `SSH-2.0-OpenSSH_10.0p2 Debian-7+deb13u4`.
- DNS Associations:
- Linked to vanzetti.osservatorionessuno.org (potential malicious domain).
- Historical Signals:
- Consistent moderate risk profile; no significant changes in threat activity.
---
**3. Relationships & Context**
- Connected Entities:
- DNS: vanzetti.osservatorionessuno.org (requires further analysis).
- Network: Subnet 185.39.207.0/24 (abuse density: 0%βno risky neighbors).
- Geolocation Discrepancy:
- Reports Greece (GR) but resolves to Russia (Khanty-Mansiysk). May indicate misconfigured DNS or spoofing.
---
**4. Recommendations**
- Monitor Traffic:
- Investigate SSH traffic for unauthorized access attempts.
- Track Tor exit node activity for potential command-and-control (C2) communications.
- Domain Analysis:
- Validate the legitimacy of vanzetti.osservatorionessuno.org and its associated domains.
- Network Segmentation:
- Isolate or restrict access to this IP if itβs not required for legitimate operations.
---
Next Steps:
- Cross-reference the domain vanzetti.osservatorionessuno.org with threat intelligence feeds.
- Verify geolocation accuracy and check for DNS misconfigurations.
- Consider blocking Tor exit node traffic if not required for operational purposes.
Threat Level: Moderate. No immediate action required, but continuous monitoring is advised.
---
*Generated by IPDebrief. All data sourced from public and proprietary intelligence feeds.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Global Connectivity Solutions |
| ASN | AS215540 |
| Network Name | β |
| CIDR Block | 185.39.207.0/24 |
| RIR | RIPE |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | vanzetti.osservatorionessuno.org |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | vanzetti.osservatorionessuno.org |
π DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_10.0p2 Debian-7+deb13u4 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 33% | 2 | 3 |
| services | 18% | 2 | 2 |
| ownership | 37% | 3 | 9 |
| reputation | 26% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 28% | 12 | 24 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-22 13:35:43 UTC |
| Last Seen | 2026-06-26 21:06:52 UTC |
| Profile Built | 2026-06-27 18:02:50 UTC |
| Data Freshness | Live |
| Signal Types | 30 |
| Total Observations | 63 |
Full dossier details are available via our API.