IPDebrief

195.133.156.119

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING

Target: 195.133.156.119/32

Classification: HIGH RISK

Report Date: Current

---

## EXECUTIVE SUMMARY

IP 195.133.156.119 is assigned to Pelephone Communications Ltd. (ASN: 16116) in Jerusalem, Israel. The address carries a risk score of 70/100 (High Risk) with elevated DNSBL listings across 4 of 8 threat intelligence feeds. No active services or open ports are detected. The IP exhibits moderate threat persistence with single threat observation events.

---

## OWNERSHIP & GEOGRAPHY

AttributeValue
**Organization**Pelephone Communications Ltd.
**ASN**16116
**CIDR Block**195.133.152.0/21
**Country**Israel (IL)
**City**Jerusalem
**Registration**RIR: RIPE
**Abuse Contact**hostmaster@pelephone.co.il

---

## RISK PROFILE

Risk Score: 70/100 (High Risk)

Threat Indicators: None identified

Blacklist Status: Listed on 4 DNSBL feeds (4/8 total)

Tor Exit Node: No

Known Attacker: No

Spam Source: No

Control Plane:

---

## NETWORK NEIGHBORHOOD ANALYSIS

Subnet: 195.133.156.0/24

Abuse Density: 0.2 (20% of sibling IPs flagged)

IP AddressRisk ScoreAuthority Score
195.133.156.1154050
195.133.156.1165550
195.133.156.1338050
195.133.156.1445550
195.133.156.1587050

Observation: The /24 subnet contains 5 sibling IPs. One neighbor (195.133.156.133) carries an elevated risk score of 80/100, suggesting concentrated abuse activity within this subnet.

---

## OBSERVATION HISTORY

Total Observations: 15

Threat Observation Count: 1

Persistent Malicious Activity: No

Geolocation and ownership signals have remained consistent across recent observation windows. No significant temporal shifts in risk posture detected.

---

## NETWORK SERVICES

CategoryStatus
Open PortsNone detected
TLS CertificateNone
HTTP BannerNone
Hosted Domains0
Email Auth (SPF/DMARC)Not configured

Assessment: Address appears firewalled or dormant with no publicly accessible services.

---

## RECOMMENDED ACTIONS

Immediate Mitigation

Block traffic from 195.133.156.119/32 at perimeter security controls.

Firewall Implementation

```bash

# iptables

iptables -A INPUT -s 195.133.156.119 -j DROP

# nftables

nft add rule inet filter input ip saddr 195.133.156.119 drop

# pfSense

195.133.156.119/32

```

WAF Configuration

Cloudflare WAF:

```json

{

"description": "Block 195.133.156.119 — IPDebrief risk score 70",

"action": "block",

"filter": {

"expression": "ip.src eq 195.133.156.119"

}

}

```

AWS WAF:

```json

{

"Addresses": ["195.133.156.119/32"],

"Description": "IPDebrief risk 70"

}

```

Monitoring

Increase logging verbosity for all traffic to/from 195.133.156.0/24 subnet due to elevated abuse density (20%) and presence of high-risk neighbor (195.133.156.133).

---

## ANALYST NOTES

---

Classification: DEFENSIVE SECURITY INTELLIGENCE

Source: IPDebrief Threat Intelligence Platform

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇮🇱 Israel
RegionJM
CityJerusalem
TimezoneAsia/Jerusalem
Latitude31.05
Longitude34.85

🏢 Ownership & Registration

OrganizationPelephone Communications Ltd.
ASNAS16116
Network NameIL-PELEPHONE-19970415
CIDR Block195.133.152.0/21
RIRRIPE
CountryIL
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)

🔐 DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
443httpstcp—
22sshtcpBanner detected
Closed Ports25, 80, 3389, 8080, 8443 (2 open / 7 scanned)
ServerWeb server detected
HTTP Title—

🔐 TLS Certificate

A self-signed certificate was detected. This is common for development servers, internal services, or IoT devices.
⚠️
CN=localhost
Issued by CN=localhost
Self-signed: Yes
SANsNone
Valid From2021-01-12T08:37:28+00:00
Valid Until2031-01-10T08:37:28+00:00
TLS ProtocolTls12
Cipher SuiteTLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period3650 days

🛡️ Public Network Snapshot

Origin ASNAS16116
Network Prefix195.133.152.0/21
Route mappingFound
HSTSNot detected
CSPNot detected
HTTP/2Not detected

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
31%
25
routing
8%
11
services
31%
26
ownership
17%
23
reputation
14%
13
geolocation
20%
24
Overall20%1022
Coverage: 2/6 dimensions · Data sufficiency: partial
Data CoherenceMostly Consistent (80%) — 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Geo sources disagree on country: IL, DE

📅 Observation Timeline 🔄 Live

First Seen2026-07-15 22:23:47 UTC
Last Seen2026-09-15 08:32:46 UTC
Profile Built2026-09-15 08:38:14 UTC
Data FreshnessLive
Signal Types22
Total Observations33
🔍 22 signal types · 33 observations collected
This report is generated from 22+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 195.133.156.119

Who owns the IP address 195.133.156.119?

195.133.156.119 is registered to Pelephone Communications Ltd.. The address falls within the 195.133.152.0/21 network block. Registration is held at RIPE.

Where is 195.133.156.119 located?

Geolocation data places 195.133.156.119 in Jerusalem, JM, Israel. The local time zone is Asia/Jerusalem. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 195.133.156.119 malicious or safe?

195.133.156.119 currently carries a high risk assessment, meaning indicators associated with malicious or abusive activity have been observed. This assessment is generated from continuously collected signals and can change over time.

What ports are open on 195.133.156.119?

Responsive ports observed on 195.133.156.119 include 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.

🏘️ Related IP Addresses

Nearby addresses in 195.133.152.0/21

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.