# IPDEBRIEF INTELLIGENCE BRIEFING
Target: 193.165.237.202/32
Classification: Moderate Risk (Score: 40)
Date: Intelligence compiled from full profile analysis
---
## Executive Summary
IP address 193.165.237.202 is assigned to PODA-CZ, a Czech provider operating under ASN 30764. The endpoint is classified as firewalled with no active services. No known malicious activity or threat indicators were identified during analysis. The IP exhibits characteristics consistent with a residential or business endpoint rather than infrastructure hosting.
---
## Ownership & Geolocation
| Attribute | Value |
|---|---|
| **Organization** | PODA-CZ Contact Role |
| **Network Name** | PODA-DYNAMIC-ID3248876800-NET |
| **CIDR Block** | 193.165.237.0/24 |
| **Country** | Czech Republic (CZ) |
| **City/Region** | Havířov, Moravian-Silesian Region |
| **ASN** | 30764 |
| **RIR** | RIPE |
| **Registration** | Dynamic IP allocation |
Geolocation data shows consensus across multiple sources with validation at 875.4km from primary probe location. The IP is dynamically allocated within the provider's pool infrastructure.
---
## Threat Intelligence Assessment
Risk Profile: Moderate Risk (40/100)
Threat Indicators: None detected
Malicious Activity: Not observed
Key findings:
- Not classified as Tor exit node, known attacker, or spam source
- Zero blacklist entries across scanned feeds
- No known campaigns or attributed activity
- Abuse confidence score: Not available (no active threats)
- DNSBL listings: 2 out of 8 lists (minimal operator concern)
Temporal Analysis: No persistent malicious behavior detected. Historical observations show consistent classification as clean with zero threat persistence days.
---
## Network & Service Analysis
Service Status: Firewalled / No Services Detected
Open Ports: None identified
Infrastructure Type: Residential/Business Endpoint
DNS analysis reveals PTR hostname mapping to `cgnat44-pool1-237-202.poda.cz` with forward resolution confirmation. Domain `poda.cz` maintains SPF and DMARC authentication records. No reverse DNS discrepancies observed.
---
## Neighborhood Analysis (193.165.237.0/24)
Subnet Classification: Clean
Abuse Density: 0.00
Total Siblings: 1
Threat Siblings: 0
High/Medium Risk IPs: 0
The /24 subnet demonstrates minimal abuse activity with no correlated threat indicators among neighboring addresses.
---
## Control Plane Intelligence
| Parameter | Value |
|---|---|
| **BGP Prefix** | 193.165.236.0/23 |
| **Route Stability** | False (changes observed) |
| **RPKI State** | Not validated |
| **Operator Score** | 0.1304 (Minimal) |
| **Delegation Age** | Not available |
| **DNSSEC** | Valid |
---
## Historical Observations
Analysis captured 18 signal observations. Recent signal types include:
- Ownership and organizational data (95% confidence)
- Geolocation data (90% confidence)
- Network classification (85% confidence)
- Subnet risk classification (40% confidence)
No significant signal degradation or escalation patterns identified.
---
## Recommended Security Actions
Current Risk: 40/100 (Moderate)
Recommendation: Monitor with caution
Available firewall rules for implementation:
```bash
# iptables
iptables -A INPUT -s 193.165.237.202 -j DROP
# nftables
nft add rule inet filter input ip saddr 193.165.237.202 drop
# nginx
deny 193.165.237.202;
# pfSense
193.165.237.202/32
# Cloudflare WAF
{"description":"Block 193.165.237.202 — IPDebrief risk score 40","action":"block","filter":{"expression":"ip.src eq 193.165.237.202"}}
# AWS WAF
{"Addresses":["193.165.237.202/32"],"Description":"IPDebrief risk 40"}
```
Note: These recommendations are probabilistic and should be combined with additional telemetry before enforcement.
---
## Intelligence Narrative
The target IP 193.165.237.202 operates within Czech provider PODA-CZ infrastructure. Analysis confirms the endpoint is firewalled with no exposed services, consistent with a residential or small business connection. No malicious indicators, threat feeds, or blacklist associations were detected. The subnet environment (193.165.237.0/24) demonstrates clean abuse metrics with zero threat correlations among neighboring addresses. Historical signal analysis reveals stable classification patterns with no escalation trends. While the risk score registers at 40 (moderate), this reflects conservative scoring for dynamically allocated residential IPs rather than confirmed malicious activity. SOC teams may monitor the IP for future threat emergence but should not treat it as an active threat source at this time.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | PODA-CZ Contact Role |
| ASN | AS30764 |
| Network Name | PODA-DYNAMIC-ID3248876800-NET |
| CIDR Block | 193.165.237.0/24 |
| RIR | RIPE |
| Country | CZ |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | cgnat44-pool1-237-202.poda.cz |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | cgnat44-pool1-237-202.poda.cz |
🔐 DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS30764 |
| Network Prefix | 193.165.236.0/23 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 17% | 2 | 3 |
| reputation | 20% | 1 | 3 |
| geolocation | 17% | 2 | 3 |
| Overall | 16% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-13 21:32:16 UTC |
| Last Seen | 2026-09-03 01:09:56 UTC |
| Profile Built | 2026-09-03 01:16:46 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 29 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 193.165.237.202
Who owns the IP address 193.165.237.202?
193.165.237.202 is registered to PODA-CZ Contact Role. The address falls within the 193.165.237.0/24 network block. Registration is held at RIPE.
Where is 193.165.237.202 located?
Geolocation data places 193.165.237.202 in Havířov, Moravian-Silesian Region, Czechia. The local time zone is Europe/Prague. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 193.165.237.202 malicious or safe?
193.165.237.202 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 193.165.237.202?
The reverse DNS (PTR) record for 193.165.237.202 is cgnat44-pool1-237-202.poda.cz. This hostname is not forward-confirmed, so it should be treated as a weak signal.