IPDebrief

195.130.35.148

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING: 195.130.35.148/32

Classification: Moderate Risk | Date: 2026-07-30 | Status: Active

## Executive Summary

IP 195.130.35.148 presents a moderate risk profile (score: 65/100) and is associated with residential/web hosting infrastructure in Sarajevo, Bosnia and Herzegovina. The IP operates a web server under the UTIC_UNSA network and is listed on three DNSBLs. While no active threat campaigns were detected, the elevated risk score warrants defensive monitoring and consideration for blocking.

## Ownership and Infrastructure

## Technical Profile

## Threat Indicators

## Neighborhood Analysis

The /24 subnet (195.130.35.0/24) shows:

## Historical Observations

19 observations recorded. Most recent activity observed on 2026-07-30. No evidence of persistent malicious activity or ownership changes. Threat observation count remains at zero.

## Recommended Actions

Priority: High โ€“ Increase monitoring and consider blocking

1. Immediate: Increase logging verbosity for traffic from this IP

2. Firewall Rule Implementation:

- iptables: `iptables -A INPUT -s 195.130.35.148 -j DROP`

- nftables: `nft add rule inet filter input ip saddr 195.130.35.148 drop`

- nginx: `deny 195.130.35.148;`

- pfSense: Add `195.130.35.148/32` to block list

- Cloudflare WAF: Block with expression `ip.src eq 195.130.35.148`

- AWS WAF: Add `195.130.35.148/32` to rule set

## Intelligence Notes

The IP is associated with a residential/web hosting provider in the Balkans region. The moderate risk score correlates with DNSBL listings, though no active exploit campaigns or threat feeds were identified. The single DNSBL listing count suggests potential reputation degradation rather than active malicious behavior. SOC teams should monitor for any behavioral changes and consider implementing the recommended firewall rules while maintaining the ability to investigate legitimate traffic patterns.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ง๐Ÿ‡ฆ BA
RegionFederation of Bosnia and Herzegovina
CitySarajevo
Timezoneโ€”
Latitude43.85
Longitude18.36

๐Ÿข Ownership & Registration

OrganizationCemal Suljevic
ASNAS8670
Network NameUTIC_UNSA_195_130_32
CIDR Block195.130.32.0/20
RIRRIPE
CountryBA
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRlinhost05.utic.net.ba
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnameslinhost05.utic.net.ba

๐Ÿ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierTier 3 โ€” Basic operator with some routing infrastructure
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
443httpstcpโ€”
8443https-alttcpโ€”
Closed Ports22, 25, 3389, 8080 (3 open / 7 scanned)
Servernginx
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
CN=linhost05.utic.net.ba
Issued by CN=YR2, O=Let's Encrypt, C=US
Self-signed: No
SANslinhost05.utic.net.ba
Valid From2026-07-17T14:39:42+00:00
Valid Until2026-10-15T14:39:41+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period89 days
Serial Number05CCCE1AA49D008E90F87D430498FA8259F6
Thumbprint500A3248530BDDDEDE9A3C451036464CE2BA15A6

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
0%
00
reputation
0%
00
geolocation
35%
22
Overall18%55
Coverage: 4/6 dimensions ยท Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-07-28 22:22:13 UTC
Last Seen2026-08-12 00:07:28 UTC
Profile Built2026-08-10 05:20:55 UTC
Data FreshnessLive
Signal Types20
Total Observations20
๐Ÿ” 20 signal types ยท 20 observations collected
This report is generated from 20+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.