## IP Intelligence Briefing: 195.66.79.15
Classification: LOW RISK
Date: 2026-07-30
Analyst: IPDebrief Intelligence Team
Executive Summary
IP address 195.66.79.15 presents a low-risk threat profile with no active threat indicators. The address belongs to the RINET-UA-NET network (ASN 39084) under RIPE NCC registration. No malicious activity, abuse reports, or known campaign associations were detected during analysis.
Network Ownership and Registration
- Organization: RINET-UA-NET (RINET)
- ASN: 39084
- CIDR Block: 195.66.79.0/24
- RIR: RIPE NCC
- Registration: RIR-registered network
- Abuse Contact: Available via RDAP
Geolocation Assessment
- Primary Location: Warsaw, Poland (PL)
- Historical Signals: Mixed geolocation data with one signal indicating Ukraine (UA) at 52% confidence
- Consensus: Multiple geo-signal sources present
- Note: Geographic discrepancies observed in historical signals; further correlation recommended if location is critical to investigation
Threat Indicators
- Overall Risk Score: 25 (Low Risk)
- Blacklist Status: Not listed on major threat feeds
- DNSBL Presence: Listed on 1 of 8 monitored DNSBL lists
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Campaign Association: None detected
Network Services and Open Ports
| Port | Protocol | Service |
|---|---|---|
| 22 | TCP | SSH (OpenSSH 9.2) |
| 8080 | TCP | HTTP-alt |
- Forward DNS Resolution: None confirmed
- PTR Records: None detected
- TLS Certificates: Not observed
Neighborhood Analysis
- Subnet: 195.66.79.0/24
- Abuse Density: 0 (Clean)
- Threat Siblings: 0
- Active Siblings: 0
- Total Siblings: 1
- Classification: Clean
Historical Signal Timeline
Analysis of 16 historical observations reveals:
- Recent Activity: Observations from 2026-07-30 indicate stable network characteristics
- Threat Persistence: 0 days of persistent malicious activity
- Ownership Changes: 0 changes observed
- Route Stability: Route status flagged as unstable in control plane data
- Traceroute: 30 hops recorded with 20+ timed out hops, suggesting path variability
Risk Assessment
- Provider Score: 0
- Authority Score: 0
- Stability Label: Not applicable
- Operator Score: 0.1304 (Minimal)
- Campaign Likelihood: None
Recommended Actions
- Firewall Rules: No blocking recommended based on current risk profile
- Monitoring: Continue standard monitoring practices
- Investigation Priority: Low
- Escalation Criteria: Only if new threat indicators emerge
Conclusion
IP 195.66.79.15 represents a low-risk network endpoint with no current threat indicators. The IP shows normal service banners (SSH, HTTP) and is part of a clean subnet with no abuse density. While route stability is flagged as unstable, this does not indicate malicious activity. SOC teams may classify this IP as benign for operational purposes, though continued monitoring is recommended to detect any future behavior changes.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | MNT-RINET |
| ASN | AS39084 |
| Network Name | RINET-UA-NET |
| CIDR Block | 195.66.79.0/24 |
| RIR | RIPE |
| Country | UA |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Multi-Service Host |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| 8080 | http-alt | tcp | β |
| Closed Ports | 25, 80, 443, 3389, 8443 (2 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
| SSH Version | SSH-2.0-OpenSSH_9.2 |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 25% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 22% | 6 | 7 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-26 03:08:52 UTC |
| Last Seen | 2026-07-30 06:21:16 UTC |
| Profile Built | 2026-07-30 06:27:58 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
Full dossier details are available via our API.