Intelligence Briefing: 185.93.1.250
Executive Summary
The IP address 185.93.1.250 was observed with a High Risk reputation score of 70. The system was identified as Web Server infrastructure operating within the DATACAMP-MNT network (ASN 60068, netname: BUNNYCDN_CHI).
Technical Observations
Network scanning indicated the presence of HTTP and HTTPS services on ports 80 and 443. DNS resolution pointed to 185-93-1-250.bunnyinfra.net with a forward resolution count of 1. TLS certificates were issued by Sectigo Public Server Authentication CA DV R36 for the subject *.b-cdn.net.
Threat Analysis
Campaign correlation analysis assigned a high likelihood to coordinated attack infrastructure, noting 26 certificate matches and 40 correlated IPs. The threat actor classification was identified as Campaign Infrastructure. Physical validation revealed a contradiction where the claimed geolocation contradicted RTT physics measurements, flagging a violation in distance calculation.
Risk Assessment
While the neighborhood subnet (185.93.1.250/24) was classified as clean with zero inherited risk, the specific IP maintained a critical severity rating. Overall classification confidence was recorded as Very Low (0.1667), but the recommendation for blocking remained Critical due to high risk scores and strong threat evidence.
Recommendation
Actionable guidance was to Block the address immediately. Implementation rules were generated for iptables, nginx, and pf.
Observation History
Signals were first recorded on 2026-09-15 and the last observation occurred on 2026-09-25.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | DATACAMP-MNT |
| ASN | AS60068 |
| Network Name | BUNNYCDN_CHI |
| CIDR Block | 185.93.1.240/28 |
| RIR | RIPE |
| Country | US |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 185-93-1-250.bunnyinfra.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 185-93-1-250.bunnyinfra.net |
๐ DNS Hygiene
| Hygiene Score | 0% (None) |
| SPF | 0/3 domains |
| DMARC | 0/3 domains |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
| Domains Checked | 3 domains |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | BunnyCDN-IL1-941 |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | *.b-cdn.netb-cdn.net |
| Valid From | 2025-11-06T00:00:00+00:00 |
| Valid Until | 2026-11-11T23:59:59+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 370 days |
| Serial Number | 2482BCCD8F8C1F7E7FC86E921D7049EA |
| Thumbprint | 929B3729B42DABEB68077B03B2802E5B53CEADE7 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 27% | 2 | 3 |
| ownership | 27% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 19% | 2 | 2 |
| Overall | 22% | 10 | 14 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-09-15 05:53:49 UTC |
| Last Seen | 2026-09-25 04:04:04 UTC |
| Profile Built | 2026-09-25 04:19:18 UTC |
| Data Freshness | Live |
| Signal Types | 31 |
| Total Observations | 39 |
Full dossier details are available via our API.