# IP INTELLIGENCE BRIEFING: 195.130.35.148/32
Classification: Moderate Risk | Date: 2026-07-30 | Status: Active
## Executive Summary
IP 195.130.35.148 presents a moderate risk profile (score: 65/100) and is associated with residential/web hosting infrastructure in Sarajevo, Bosnia and Herzegovina. The IP operates a web server under the UTIC_UNSA network and is listed on three DNSBLs. While no active threat campaigns were detected, the elevated risk score warrants defensive monitoring and consideration for blocking.
## Ownership and Infrastructure
- ASN: 8670 (UTIC_UNSA_195_130_32)
- Registrant: Cemal Suljevic
- RIR: RIPE
- CIDR Block: 195.130.32.0/20
- Location: Sarajevo, Federation of Bosnia and Herzegovina (BA)
- Geolocation Confidence: High (geo-plausible verified)
## Technical Profile
- Role: Web Server
- DNS: linhost05.utic.net.ba (forward-confirmed)
- Server Software: nginx (HTTP/2 enabled)
- Open Ports: 80/tcp (HTTP), 443/tcp (HTTPS), 8443/tcp (HTTPS-alt)
- TLS Certificate: Let's Encrypt (CN=linhost05.utic.net.ba)
## Threat Indicators
- Risk Score: 65/100 (Moderate)
- DNSBL Listings: 3 of 8 total lists
- Known Malicious Activity: None detected
- Tor Exit Node: No
- Known Attacker/Spam Source: No
- Campaign Activity: None observed
## Neighborhood Analysis
The /24 subnet (195.130.35.0/24) shows:
- Abuse Density: 0%
- Classification: Clean
- Threat Siblings: 0
- Active Siblings: 1
## Historical Observations
19 observations recorded. Most recent activity observed on 2026-07-30. No evidence of persistent malicious activity or ownership changes. Threat observation count remains at zero.
## Recommended Actions
Priority: High โ Increase monitoring and consider blocking
1. Immediate: Increase logging verbosity for traffic from this IP
2. Firewall Rule Implementation:
- iptables: `iptables -A INPUT -s 195.130.35.148 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 195.130.35.148 drop`
- nginx: `deny 195.130.35.148;`
- pfSense: Add `195.130.35.148/32` to block list
- Cloudflare WAF: Block with expression `ip.src eq 195.130.35.148`
- AWS WAF: Add `195.130.35.148/32` to rule set
## Intelligence Notes
The IP is associated with a residential/web hosting provider in the Balkans region. The moderate risk score correlates with DNSBL listings, though no active exploit campaigns or threat feeds were identified. The single DNSBL listing count suggests potential reputation degradation rather than active malicious behavior. SOC teams should monitor for any behavioral changes and consider implementing the recommended firewall rules while maintaining the ability to investigate legitimate traffic patterns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Cemal Suljevic |
| ASN | AS8670 |
| Network Name | UTIC_UNSA_195_130_32 |
| CIDR Block | 195.130.32.0/20 |
| RIR | RIPE |
| Country | BA |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | linhost05.utic.net.ba |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | linhost05.utic.net.ba |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 8443 | https-alt | tcp | โ |
| Closed Ports | 22, 25, 3389, 8080 (3 open / 7 scanned) | ||
| Server | nginx |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | linhost05.utic.net.ba |
| Valid From | 2026-07-17T14:39:42+00:00 |
| Valid Until | 2026-10-15T14:39:41+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 89 days |
| Serial Number | 05CCCE1AA49D008E90F87D430498FA8259F6 |
| Thumbprint | 500A3248530BDDDEDE9A3C451036464CE2BA15A6 |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 35% | 2 | 2 |
| Overall | 18% | 5 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-28 22:22:13 UTC |
| Last Seen | 2026-08-12 00:07:28 UTC |
| Profile Built | 2026-08-10 05:20:55 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 20 |
Full dossier details are available via our API.