# IP Intelligence Briefing: 185.91.69.110/32
Classification: Low Risk | Risk Score: 25 | Generated: 2026-07-30
---
## Executive Summary
IP address 185.91.69.110 is a single-service host located in Redditch, England (GB) under ASN 201579 (Damien Cutler / UK-HOSTGNOME-20150311). The IP presents a low overall risk profile (25) with no active threat indicators. The subnet 185.91.69.0/24 is classified as clean with zero abuse density.
---
## Technical Profile
Ownership & Registration:
- ASN: 201579
- Organization: Damien Cutler
- Netname: UK-HOSTGNOME-20150311
- RIR: RIPE
- CIDR Block: 185.91.69.0/24
- Registration Date: Not available
Geolocation:
- Country: United Kingdom (GB)
- Region: England
- City: Redditch
- Coordinates: 55.38°N, 3.44°W (accuracy radius: 500km)
Network Services:
- Open Ports: TCP/22 (SSH - OpenSSH_8.2p1 Ubuntu-4ubuntu0.13)
- No HTTP/TLS services detected
- No hostnames, no email authentication records (no SPF/DMARC)
- Single-service host classification
---
## Threat Assessment
Current Risk Indicators:
- Risk Score: 25 (Low)
- Reputation: Low Risk
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- CDN/Cloud/VPN/Proxy: No
DNSBL Status:
- Listed on 1 of 8 total DNSBLs
- Maximum severity: High (per historical observation)
- Route stability: False (route changes detected in 30-day period)
Historical Observations (15 signals recorded):
- Most recent: 2026-07-30T05:26:23
- Ownership changes: 0
- Threat observation count: 0
- Is persistently malicious: No
- DNSSEC: Valid
- Geo validation: Inconsistent (geoPlausible: false)
---
## Neighborhood Analysis
Subnet: 185.91.69.0/24
| Metric | Value |
|---|---|
| Total Siblings | 9 |
| Active Siblings | 3 |
| Threat Siblings | 0 |
| Abuse Density | 0 |
| Classification | Clean |
Neighbor Risk Distribution:
- High Risk: 0
- Medium Risk: 1 (185.91.69.5, risk score 40)
- Low Risk: 7
Notable neighbor: 185.91.69.5 (risk score 40, authority score 50)
---
## Relationships
- 3 relationships identified
- All relationships: Same Network (UK-HOSTGNOME-20150311)
- No external entity links (subnets, hostnames, organizations, certificates)
---
## Recommended Actions
Monitoring:
- No immediate firewall blocking required
- Monitor for route stability changes (currently flagged as unstable)
- Watch for additional DNSBL listings
Mitigation:
- SSH port access should be validated if inbound connections received
- No WAF rules recommended (no HTTP services)
Investigation Priority: Low
- No active campaigns or correlated IPs
- No certificate matches
- No banner matches
---
## SOC Analyst Notes
This IP represents a legitimate low-risk single-service host. The single DNSBL listing and route instability are historical artifacts rather than active threats. The subnet environment is clean with minimal abuse. No immediate defensive action required. Continue standard passive monitoring.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Damien Cutler |
| ASN | AS201579 |
| Network Name | UK-HOSTGNOME-20150311 |
| CIDR Block | 185.91.69.0/24 |
| RIR | RIPE |
| Country | GB |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_8.2p1 Ubuntu-4ubuntu0.13 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 0% | 0 | 0 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 25% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-25 21:00:36 UTC |
| Last Seen | 2026-07-30 05:21:15 UTC |
| Profile Built | 2026-07-30 05:31:58 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.