Your IP: 216.73.216.123
π€ Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.
IP Intelligence Briefing: 195.178.110.104
Date: June 2026
---
**1. Profile Summary**
- Risk Score: 50 (Moderate Risk)
- Ownership: ASN 48090 (ABUSE DEP), Bulgaria (BG).
- Geolocation: Duivendrecht, North Holland, Bulgaria (latitude 42.73, longitude 25.49).
- Threat Indicators: No malicious indicators, spam, or known attacker activity.
- Network Role: Firewalled / No Services (no open ports, no TLS/HTTP services).
- Control Plane: DNSSEC validated, CAA records present. DNSBL listed on 2/8 lists (low-severity).
---
**2. Observation History**
- Recent Activity (June 2026):
- Risk score fluctuated between 0β80, with no persistent malicious trends.
- DNS resolution errors observed (e.g., timeouts to 192.168.2.108#53).
- Subnet abuse density: 0.22 (mixed risk, 6/28 neighbors flagged as high/medium risk).
---
**3. Network Relationships**
- Same Subnet: 28 IPs in 195.178.110.0/24.
- High-Risk Neighbors:
- 195.178.110.105 (80), 195.178.110.199 (80), 195.178.110.223 (80).
- 195.178.110.15 (65), 195.178.110.26 (65), 195.178.110.31 (65).
- Abuse Density: 14.3% of subnet IPs show risk (4 high, 18 medium, 6 low).
---
**4. Key Findings**
- No Direct Threat: The IP itself shows no malicious activity, but its subnet has a moderate abuse density.
- DNS Issues: DNS resolution errors and partial DNSBL listings suggest potential misconfiguration or network instability.
- Neighbor Risk: Three high-risk neighbors (80/100) may indicate compromised hosts or malicious infrastructure in the same subnet.
---
**5. Recommendations**
- Monitor Subnet: Track activity around high-risk neighbors (195.178.110.105, 195.178.110.199, 195.178.110.223).
- Investigate DNS Errors: Verify if DNS resolution issues are due to misconfigurations or upstream provider problems.
- Block High-Risk Neighbors: Consider firewall rules to restrict traffic from high-risk IPs if they are not part of your infrastructure.
- Check DNSBL Listings: Confirm if the IPβs DNSBL presence is a false positive or part of a larger network issue.
Note: The IP appears to be a legitimate, firewalled server, but its subnetβs abuse density warrants closer scrutiny.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | ABUSE DEP |
| ASN | AS48090 |
| Network Name | β |
| CIDR Block | 195.178.110.0/24 |
| RIR | RIPE |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
No certificate
Issued by β
N/A
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 32% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 11% | 1 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 21% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 20% | 9 | 15 |
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:05 UTC |
| Last Seen | 2026-06-26 18:11:00 UTC |
| Profile Built | 2026-06-23 03:40:02 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 25 |
π 22 signal types Β· 25 observations collected
This report is generated from 22+ independent intelligence signals including
ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds,
behavioral fingerprinting, and more.
Full dossier details are available via our API.
Full dossier details are available via our API.
βΉοΈ About This Report
All data shown is publicly available network metadata β IP addresses do not reliably identify individuals.
Assessments are probabilistic and should not be used as sole basis for access control decisions.
To report an issue or request data review, contact admin@ipdebrief.com.