# IP Intelligence Briefing: 185.65.135.182/32
## Executive Summary
IP address 185.65.135.182 presents a moderate risk profile with an overall risk score of 40. The address is registered to ESAB-MNT (AS39351) within the 185.65.135.0/24 block, allocated through RIR RIPE. Geolocation data indicates Stockholm, Sweden (SE), with plausible validation metrics. No active services are detected, and the IP is not listed as a known attacker, spam source, or Tor exit node. Two DNS blacklist entries were identified across eight total lists.
## Technical Profile
Ownership & Network Classification:
- ASN: 39351 (ESAB-MNT)
- CIDR Block: 185.65.135.0/24
- RIR: RIPE
- Registration: Abuse contact available via RDAP
- Network Role: Firewalled / No Services
Geolocation:
- Country: Sweden (SE)
- Region: Stockholm County
- City: Stockholm
- Validation Distance: 1,038.4 km from probe origin
- Minimum RTT: 115 ms; Average RTT: 117.8 ms
- Geo Plausibility: Validated
Threat Indicators:
- Abuse Confidence Score: Not calculated
- Blacklist Count: 2 (of 8 total lists checked)
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Threat Feeds: None detected
DNS & Email:
- Forward Resolution: Confirmed false
- Hosted Domains: None
- Email Authentication: No SPF or DMARC records
- PTR Hostnames: None
Network Behavior:
- Open Ports: None detected
- TLS Certificate: None
- Service Banner: None
- HTTP Title: None
## Neighborhood Analysis
The /24 subnet (185.65.135.0/24) exhibits low abuse density with a classification of "clean." Analysis identified one neighbor IP (185.65.135.250) with a risk score of 25 and authority score of 50. No threat siblings were observed within the subnet. The subnet contains 2 total sibling IPs with 0 currently active.
## Historical Observations
Sixteen observation signals recorded between 2026-07-26. Traceroute analysis revealed a 15-hop path with transit through Comcast networks. Two hops timed out during probing. Geo validation confirmed the Stockholm location with distance metrics consistent with the claimed coordinates (59.3098°N, 17.9796°E). No ownership changes detected. Threat persistence metrics remain at zero days with zero threat observation count, indicating the IP is not persistently malicious.
## Control Plane Data
- BGP Prefix: 185.65.135.0/24
- Origin ASN: 39351
- Route Stability: False (not route stable)
- RPKI State: Not evaluated
- IRR Consistency: Not evaluated
- Route Changes (30d): 0
- DNSSEC Valid: True
- CAA Records: None
- DNSBL Listed Count: 2 of 8 total lists
- Operator Score: 0.1304 (Minimal)
## Recommended Actions
Based on the risk profile (score 40), the following defensive measures are recommended:
- Firewall Blocking: Apply DROP rules for inbound traffic from 185.65.135.182
- Cloudflare WAF: Configure block action with expression `ip.src eq 185.65.135.182`
- AWS WAF: Add IP address to block list with description "IPDebrief risk 40"
- pfSense: Apply block rule for 185.65.135.182/32
- nginx: Implement deny directive for the address
- nftables: Configure input rule with `ip saddr 185.65.135.182 drop`
## Intelligence Narrative
185.65.135.182 is a Swedish-based IP address within the ESAB-MNT network block. While the IP shows moderate risk (40), the absence of open ports, no known malicious indicators, and clean subnet classification suggest limited active threat activity. The two DNSBL listings warrant attention but do not indicate confirmed malicious behavior. The IP's lack of services and firewalled status may indicate it is reserved for administrative or internal use. Monitoring is recommended, and blocking may be considered based on organizational policy thresholds for moderate-risk IPs. The neighbor IP (185.65.135.250) also presents low risk and should be evaluated in context of any observed connection patterns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | ESAB-MNT |
| ASN | AS39351 |
| Network Name | NET-31173-185-65-135-0-24 |
| CIDR Block | 185.65.135.0/24 |
| RIR | RIPE |
| Country | SE |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS39351 |
| Network Prefix | 185.65.135.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 12% | 2 | 2 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 17% | 2 | 3 |
| reputation | 8% | 1 | 2 |
| geolocation | 17% | 2 | 3 |
| Overall | 12% | 10 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-11 08:22:19 UTC |
| Last Seen | 2026-09-03 23:26:41 UTC |
| Profile Built | 2026-09-03 23:31:16 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 24 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 185.65.135.182
Who owns the IP address 185.65.135.182?
185.65.135.182 is registered to ESAB-MNT. The address falls within the 185.65.135.0/24 network block. Registration is held at RIPE.
Where is 185.65.135.182 located?
Geolocation data places 185.65.135.182 in Stockholm, Stockholm County, Sweden. The local time zone is Europe/Stockholm. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 185.65.135.182 malicious or safe?
185.65.135.182 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.