# IP Intelligence Briefing: 195.128.99.54/32
## Executive Summary
The target IP address 195.128.99.54 operates within a high-risk profile (risk score: 80/100) attributed to Intal Alliulin's RU-SKYNETWORK1-20180807 network infrastructure in Kazan', Tatarstan Republic, Russia. Despite showing no active service exposure, the IP maintains elevated threat indicators including DNSBL listings and route instability.
## Ownership and Network Classification
- Organization: Intal Alliulin
- ASN: 31566
- Network Block: 195.128.96.0/22
- CIDR Assignment: 195.128.99.54/24
- Geolocation: Kazan', Tatarstan Republic, Russia (RU)
- RIR: RIPE
- Registration: 2018-08-07
## Risk Assessment
- Overall Risk Score: 80/100 (High Risk)
- Network Reputation: High Risk
- DNSBL Status: Listed on 6 of 8 total DNSBL feeds
- Service Exposure: None detected (firewalled/no services)
- Open Ports: Empty
- Infrastructure Type: Non-residential, non-cloud infrastructure
## Behavioral Indicators
- Route Stability: False (route changes detected)
- Operator Score: 0.1304 (Minimal)
- Tor/Proxy/VPS: Not classified as any of these
- Email Authentication: No SPF, DMARC, or TXT records detected
- DNS Resolution: No forward resolution confirmed
## Observation History
Analysis of 16 historical observations reveals the following patterns:
- Geolocation: Consistent RU classification with geo-plausible validation
- Connectivity: ICMP probes blocked (unable to validate)
- Last Observed: 2026-07-31T02:12:12+00:00
- Threat Persistence: 0 days (not persistently malicious)
- Ownership Changes: 0 (stable ownership)
## Relationship Graph
Three relationship entries identified, all pointing to the same network identifier: RU-SKYNETWORK1-20180807. No connections to external subnets, hostnames, or organizations detected beyond the primary network assignment.
## Neighborhood Analysis
Subnet 195.128.99.0/24 shows:
- Total Siblings: 1
- Active Siblings: 0
- Abuse Density: 0%
- Threat Siblings: 0
- Classification: Clean
- Inherited Risk: 0
No neighboring IPs with elevated risk profiles detected within the /24 subnet.
## Recommended Security Actions
Immediate Mitigation
| Platform | Rule/Configuration |
|---|---|
| **iptables** | `iptables -A INPUT -s 195.128.99.54 -j DROP` |
| **nftables** | `nft add rule inet filter input ip saddr 195.128.99.54 drop` |
| **nginx** | `deny 195.128.99.54;` |
| **pfSense** | Add 195.128.99.54/32 to block list |
| **Cloudflare WAF** | Block rule: `ip.src eq 195.128.99.54` |
| **AWS WAF** | Address: `195.128.99.54/32` |
Monitoring Recommendations
- Increase logging verbosity for traffic from this IP
- Review recent activity logs for any interaction attempts
- Monitor for emergence of open services on this address
- Track for changes in network behavior or route announcements
## Intelligence Narrative
This IP address represents a dormant but classified high-risk asset. The elevated risk score (80/100) combined with DNSBL listings suggests historical abuse activity, though no active malicious services are currently exposed. The network classification as "firewalled/no services" indicates the IP may be reserved, administrative, or intentionally obscured. Route instability flags warrant ongoing monitoring for infrastructure changes. The absence of neighboring threats within the /24 subnet suggests isolated risk rather than a coordinated infrastructure. SOC analysts should maintain blocking posture while monitoring for service emergence or behavioral changes.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Intal Alliulin |
| ASN | AS31566 |
| Network Name | RU-SKYNETWORK1-20180807 |
| CIDR Block | 195.128.96.0/22 |
| RIR | RIPE |
| Country | RU |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-30 11:03:39 UTC |
| Last Seen | 2026-08-01 04:25:30 UTC |
| Profile Built | 2026-07-31 02:17:21 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.