## IP Intelligence Briefing: 195.46.183.181
Classification: Moderate Risk (Score: 50)
Date of Analysis: 2026-07-31
Report Type: Defensive Threat Intelligence
---
Executive Summary
IP address 195.46.183.181 is a firewalled infrastructure IP in Russia (RU) under ASN 3216 (SOVINTEL-MNT). The address shows moderate risk scoring (50/100) but exhibits no active threat indicators, no open services, and resides in a clean subnet with zero abuse density. The IP is associated with the RU-CITY-LINE-Interface-IP-pool-NET network and resolves to a dial-in hostname in Kemerovo.
---
Ownership and Network Context
- ASN: 3216 (SOVINTEL-MNT)
- Network: RU-CITY-LINE-Interface-IP-pool-NET (195.46.183.0/24)
- RIR: RIPE
- Geolocation: Russia (RU) โ Kemerovo region
- DNS PTR: ts1-a181.Kemerovo.dial.rol.ru
- Forward Resolution: Confirmed (1 hostname)
---
Risk Assessment
| Metric | Value |
|---|---|
| Risk Score | 50 (Moderate) |
| Provider Score | 0 |
| Authority Score | 0 |
| Stability Score | 0 |
| DNSBL Listed | 2 of 8 lists |
| Open Ports | None |
| Active Threats | None |
Key Observations:
- No known campaigns, attacker reputation, or spam source activity
- No Tor exit node or proxy behavior detected
- Infrastructure appears to be residential dial-in service (indicated by hostname structure)
- No HTTP/HTTPS services running (firewalled/no services)
---
Neighborhood Analysis
Subnet 195.46.183.0/24 shows:
- Abuse Density: 0% (clean)
- Active Siblings: 0
- Threat Siblings: 0
- Neighbor Count: 0
No neighboring IPs in the /24 show elevated risk signals, indicating this IP exists in isolation from broader subnet abuse activity.
---
Historical Signal Activity
Observation Count: 18 signals recorded (latest: 2026-07-31T02:09:04)
Recent Signal Types:
- Geolocation inference (Russia, 61.52N, 105.32E, 0.52 confidence)
- Network ownership confirmation (SOVINTEL-MNT, RU-CITY-LINE-Interface-IP-pool-NET)
- Port scanning activity detected
- ICMP validation blocked (unable to validate geolocation)
Temporal Analysis:
- No persistent malicious behavior detected
- Ownership stability: Stable
- Threat persistence: 0 days
- Is persistently malicious: No
---
Relationship Graph
Associated Entities:
- DNS Hostnames: ts1-a181.Kemerovo.dial.rol.ru (multiple associations)
- Network: RU-CITY-LINE-Interface-IP-pool-NET (multiple associations)
No additional certificate, organization, or external entity relationships identified.
---
Recommended Actions
Firewall Rules (Block Recommended):
```bash
# iptables
iptables -A INPUT -s 195.46.183.181 -j DROP
# nftables
nft add rule inet filter input ip saddr 195.46.183.181 drop
# nginx
deny 195.46.183.181;
# pfSense
195.46.183.181/32
# Cloudflare WAF
Expression: ip.src eq 195.46.183.181
Action: block
# AWS WAF
Addresses: ["195.46.183.181/32"]
```
Operational Notes:
- This IP shows moderate risk but lacks active threat indicators
- Consider blocking based on organizational policy rather than threat activity
- Monitor for changes in service banners or open ports
- No immediate threat action required beyond standard filtering
---
Conclusion
195.46.183.181 is a firewalled residential dial-in IP in Russia with moderate risk scoring. No active malicious activity, campaigns, or threat indicators are present. The IP exists in a clean subnet with no neighboring abuse activity. Standard blocking is recommended based on the moderate risk score, but no emergency threat response is warranted.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | SOVINTEL-MNT |
| ASN | AS3216 |
| Network Name | RU-CITY-LINE-Interface-IP-pool-NET |
| CIDR Block | 195.46.183.0/24 |
| RIR | RIPE |
| Country | RU |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | ts1-a181.Kemerovo.dial.rol.ru |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | ts1-a181.Kemerovo.dial.rol.ru |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-30 11:03:39 UTC |
| Last Seen | 2026-08-01 04:25:30 UTC |
| Profile Built | 2026-07-31 02:17:21 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 21 |
Full dossier details are available via our API.