# IP INTELLIGENCE BRIEFING
Target: 195.133.156.119/32
Classification: HIGH RISK
Report Date: Current
---
## EXECUTIVE SUMMARY
IP 195.133.156.119 is assigned to Pelephone Communications Ltd. (ASN: 16116) in Jerusalem, Israel. The address carries a risk score of 70/100 (High Risk) with elevated DNSBL listings across 4 of 8 threat intelligence feeds. No active services or open ports are detected. The IP exhibits moderate threat persistence with single threat observation events.
---
## OWNERSHIP & GEOGRAPHY
| Attribute | Value |
|---|---|
| **Organization** | Pelephone Communications Ltd. |
| **ASN** | 16116 |
| **CIDR Block** | 195.133.152.0/21 |
| **Country** | Israel (IL) |
| **City** | Jerusalem |
| **Registration** | RIR: RIPE |
| **Abuse Contact** | hostmaster@pelephone.co.il |
---
## RISK PROFILE
Risk Score: 70/100 (High Risk)
Threat Indicators: None identified
Blacklist Status: Listed on 4 DNSBL feeds (4/8 total)
Tor Exit Node: No
Known Attacker: No
Spam Source: No
Control Plane:
- Route Status: Unstable (isRouteStable: false)
- Route Changes (30d): 0
- BGP Prefix: 195.133.152.0/21
- RPKI State: Not evaluated
---
## NETWORK NEIGHBORHOOD ANALYSIS
Subnet: 195.133.156.0/24
Abuse Density: 0.2 (20% of sibling IPs flagged)
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 195.133.156.115 | 40 | 50 |
| 195.133.156.116 | 55 | 50 |
| 195.133.156.133 | 80 | 50 |
| 195.133.156.144 | 55 | 50 |
| 195.133.156.158 | 70 | 50 |
Observation: The /24 subnet contains 5 sibling IPs. One neighbor (195.133.156.133) carries an elevated risk score of 80/100, suggesting concentrated abuse activity within this subnet.
---
## OBSERVATION HISTORY
Total Observations: 15
Threat Observation Count: 1
Persistent Malicious Activity: No
Geolocation and ownership signals have remained consistent across recent observation windows. No significant temporal shifts in risk posture detected.
---
## NETWORK SERVICES
| Category | Status |
|---|---|
| Open Ports | None detected |
| TLS Certificate | None |
| HTTP Banner | None |
| Hosted Domains | 0 |
| Email Auth (SPF/DMARC) | Not configured |
Assessment: Address appears firewalled or dormant with no publicly accessible services.
---
## RECOMMENDED ACTIONS
Immediate Mitigation
Block traffic from 195.133.156.119/32 at perimeter security controls.
Firewall Implementation
```bash
# iptables
iptables -A INPUT -s 195.133.156.119 -j DROP
# nftables
nft add rule inet filter input ip saddr 195.133.156.119 drop
# pfSense
195.133.156.119/32
```
WAF Configuration
Cloudflare WAF:
```json
{
"description": "Block 195.133.156.119 — IPDebrief risk score 70",
"action": "block",
"filter": {
"expression": "ip.src eq 195.133.156.119"
}
}
```
AWS WAF:
```json
{
"Addresses": ["195.133.156.119/32"],
"Description": "IPDebrief risk 70"
}
```
Monitoring
Increase logging verbosity for all traffic to/from 195.133.156.0/24 subnet due to elevated abuse density (20%) and presence of high-risk neighbor (195.133.156.133).
---
## ANALYST NOTES
- The 20% abuse density in the /24 subnet warrants expanded monitoring.
- Neighbor 195.133.156.133 (Risk: 80) may require separate intelligence collection.
- No correlation to known attack campaigns or certificate-based threats detected.
- Consider blocking entire /24 subnet if operational constraints permit, given concentrated risk indicators.
---
Classification: DEFENSIVE SECURITY INTELLIGENCE
Source: IPDebrief Threat Intelligence Platform
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Pelephone Communications Ltd. |
| ASN | AS16116 |
| Network Name | IL-PELEPHONE-19970415 |
| CIDR Block | 195.133.152.0/21 |
| RIR | RIPE |
| Country | IL |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | — |
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 80, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | 2021-01-12T08:37:28+00:00 |
| Valid Until | 2031-01-10T08:37:28+00:00 |
| TLS Protocol | Tls12 |
| Cipher Suite | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 3650 days |
🛡️ Public Network Snapshot
| Origin ASN | AS16116 |
| Network Prefix | 195.133.152.0/21 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Not detected |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 5 |
| routing | 8% | 1 | 1 |
| services | 31% | 2 | 6 |
| ownership | 17% | 2 | 3 |
| reputation | 14% | 1 | 3 |
| geolocation | 20% | 2 | 4 |
| Overall | 20% | 10 | 22 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-15 22:23:47 UTC |
| Last Seen | 2026-09-15 08:32:46 UTC |
| Profile Built | 2026-09-15 08:38:14 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 33 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 195.133.156.119
Who owns the IP address 195.133.156.119?
195.133.156.119 is registered to Pelephone Communications Ltd.. The address falls within the 195.133.152.0/21 network block. Registration is held at RIPE.
Where is 195.133.156.119 located?
Geolocation data places 195.133.156.119 in Jerusalem, JM, Israel. The local time zone is Asia/Jerusalem. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 195.133.156.119 malicious or safe?
195.133.156.119 currently carries a high risk assessment, meaning indicators associated with malicious or abusive activity have been observed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 195.133.156.119?
Responsive ports observed on 195.133.156.119 include 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.