# INTELLIGENCE BRIEFING: 191.101.59.59/32
## EXECUTIVE SUMMARY
On 2026-06-04, IP address 191.101.59.59/32 was analyzed and classified as MODERATE RISK (risk score: 40). The IP operates within the IPXO network infrastructure in the City of London, GB, with no active services exposed and a moderate abuse density of 41.67% within its /24 subnet.
## OWNERSHIP & INFRASTRUCTURE
- ASN: 42831 (netutils-mnt)
- Organization: IPXO (inferred from network relationships)
- Network: 191.101.59.0/24 (LACNIC RIR)
- Geolocation: City of London, England, GB (750km accuracy radius)
- Service Status: Firewalled / No Services detected
## THREAT ASSESSMENT
- Overall Risk Score: 40/100 (Moderate)
- Abuse Confidence: Not explicitly scored
- Known Threats: No active threat indicators
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- DNSBL Listings: 2 of 8 total lists (mixed severity)
## NEIGHBORHOOD ANALYSIS
The /24 subnet (191.101.59.0/24) shows elevated activity:
- Total Siblings: 12 IPs
- Active Siblings: 5
- Threat Siblings: 5
- Abuse Density: 0.4167 (41.67% - moderate to high)
- Risk Distribution: 9 medium-risk, 2 low-risk, 0 high-risk
High-Risk Neighbors in Subnet:
- 191.101.59.252 (risk score: 65)
- 191.101.59.86, 191.101.59.100, 191.101.59.89 (risk score: 50)
## RELATIONSHIP GRAPH
- DNS Association: atrfe.space (primary PTR hostname)
- Network Affiliation: IPXO (multiple relationship entries)
- Total Relationships: 30 associations detected
## OBSERVATION HISTORY
- Total Observations: 21 signals recorded
- Recent Activity: Signals observed as recently as 2026-06-04T20:45:30
- Threat Persistence: No persistent malicious activity detected
- Key Signals:
- Subnet abuse density classification
- Geographic inference (GB, England)
- DNSBL listings with high severity categories
## INFRASTRUCTURE CHARACTERISTICS
- Connection Type: Firewalled (no open ports)
- Cloud/CDN/VPN: Not detected
- Mobile/Residential: No
- Bogon/Anycast: No
- DNSSEC: Valid
- CAA Records: Present
- Operator Score: 0.3478 (Basic)
## ACTIONABLE INTELLIGENCE
1. Risk Context: Moderate risk IP within a high-abuse-density subnet (41.67%). Monitor associated IPs for coordinated activity.
2. Infrastructure: No active services detected; IP is firewalled. Traffic patterns may indicate server-to-server communication.
3. DNS Activity: Associated with domain atrfe.space. Monitor for DNS-based reconnaissance or C2 traffic.
4. Subnet Monitoring: Recommend monitoring 191.101.59.0/24, particularly 191.101.59.252 (risk 65) and IPs with risk score 50+.
5. Firewall Considerations: Low immediate threat, but maintain awareness of subnet abuse patterns. No immediate blocking recommended.
## RECOMMENDATIONS
- Monitor DNS queries to/from atrfe.space
- Track subnet-wide activity patterns for 191.101.59.0/24
- Alert on any service exposure on previously firewalled IPs
- Correlate with any observed traffic to/from this IP for behavioral analysis
---
*Intelligence generated via IPDebrief platform. All data sourced from automated network telemetry and threat feeds.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | netutils-mnt |
| ASN | AS42831 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | LACNIC |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | atrfe.space |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | atrfe.space |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 20% | 2 | 3 |
| ownership | 24% | 2 | 3 |
| reputation | 19% | 1 | 3 |
| geolocation | 27% | 2 | 2 |
| Overall | 21% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-08 05:01:59 UTC |
| Last Seen | 2026-06-25 02:43:04 UTC |
| Profile Built | 2026-06-25 02:48:37 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.