IP Intelligence Briefing: 195.19.49.129
Date: 2026-06-10
---
**1. Core Profile**
- Risk Score: 65 (Moderate Risk)
- Ownership:
- ASN: AS57529 (ZAO GTNT, Russia)
- Geolocation: Moscow, Russia (55.74°N, 37.61°E)
- Network: 195.19.48.0/20
- Threat Indicators:
- No active malware, phishing, or exploit activity detected.
- Flagged as a compromised server (proxy check).
- Listed in 3 DNSBLs (high-severity threat feeds).
---
**2. Observation History**
- Recent Activity (Last 30 Days):
- DNSBL Listings: 1 high-severity listing (confidence: 0.85).
- Network Changes: No ownership shifts or persistent malicious behavior.
- Proxy Flags: Marked as a "compromised server" (proxy type).
- Subnet Abuse: 0 abuse density in 195.19.49.0/24.
---
**3. Network Relationships**
- Linked Entities:
- Same network: GTNT (ZAO GTNT, Russia).
- No direct connections to known C2 servers, CDN nodes, or Tor relays.
- Subnet Neighbors:
- 1 active neighbor (195.19.49.128) with a low risk score (25).
- Subnet abuse density: 0% (clean).
---
**4. Technical Characteristics**
- Services: No open ports or TLS services detected.
- DNS:
- No PTR records or domain associations.
- DNSSEC validated.
- Network Role: Firewalled infrastructure with no public services.
---
**5. Recommendations**
- Monitoring: Continuously monitor for DNSBL reappearances or subnet changes.
- Firewall: Block traffic to this IP unless explicitly required.
- Investigation: Verify the compromised server flag with internal logs.
Final Assessment: Moderate risk due to DNSBL associations, but no direct malicious activity observed. Subnet appears clean.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | JSC GTNT |
| ASN | AS57529 |
| Network Name | GTNT |
| CIDR Block | 195.19.48.0/20 |
| RIR | RIPE |
| Country | RU |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 13% | 1 | 1 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 30% | 2 | 3 |
| reputation | 0% | 0 | 0 |
| geolocation | 13% | 1 | 1 |
| Overall | 14% | 6 | 7 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-24 12:34:31 UTC |
| Last Seen | 2026-06-10 15:18:11 UTC |
| Profile Built | 2026-06-10 15:24:42 UTC |
| Data Freshness | Live |
| Signal Types | 15 |
| Total Observations | 15 |
Full dossier details are available via our API.