## IP Intelligence Briefing: 2.56.182.14
Executive Summary
Risk Assessment: HIGH RISK (Score: 80)
This IP address is classified as high-risk despite limited observable threat indicators. The IP belongs to Russian hosting provider Intal Alliulin with a reputation score of 80. While no active threat campaigns or open services were detected, the IP shows DNSBL presence and requires monitoring due to its risk classification.
---
Network Ownership & Geolocation
| Attribute | Value |
|---|---|
| **IP Address** | 2.56.182.14/32 |
| **Network** | RU-SKYNETWORK1-20190314 |
| **CIDR Block** | 2.56.180.0/22 |
| **ASN** | 31566 |
| **Organization** | Intal Alliulin |
| **Country** | Russia (RU) |
| **Region** | Tatarstan Republic |
| **City** | Kazan |
| **RIR** | RIPE |
| **Abuse Contact** | noc@skynet-kazan.com |
---
Threat Profile
- Risk Score: 80/100 (High Risk)
- DNSBL Listings: 6/8 total lists
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Blacklist Count: 0
- Operator Score: 0.1304 (Minimal)
- Services: Firewalled/No Services detected
- Open Ports: None
---
Observation History (16 Observations)
Recent activity observed on 2026-07-30:
- Geo Signals: Confirmed Russia, distance ~2,750km, geoPlausible: true
- Ownership Signals: Intal Alliulin, RIPE, 2.56.180.0/22
- ICMP Validation: Blocked (unable to validate via ICMP)
- Signal Confidence: Ranges 0.30โ0.95
- Threat Persistence: 0 days
- Is Persistently Malicious: No
---
Relationship Graph
- Total Relationships: 3
- Same Network References: 3 (RU-SKYNETWORK1-20190314)
- External Entities: None
- Associated Hostnames/Orgs: None detected
---
Subnet Analysis (2.56.182.0/24)
- Neighbor Count: 0
- Abuse Density: 0
- Threat Siblings: 0
- Active Siblings: 0
- Subnet Classification: None detected
- Inherited Risk: 0
---
Control Plane Data
- BGP Prefix: 2.56.180.0/22
- Route Stability: False
- Route Changes (30d): 0
- MOAS: No
- RPKI State: Not available
- DNSSEC: Valid
- IRR Consistency: Not available
---
Recommended Actions for SOC Analysts
Immediate:
1. Monitor inbound connections from 2.56.182.14 for potential scanning or connection attempts
2. Review firewall rules for existing blocks on this IP
3. Verify if any internal assets have communicated with this IP address
Short-term:
1. Add to watchlist for traffic pattern analysis
2. Monitor for changes in service availability or port exposure
3. Review DNSBL listings to understand reputation context
Long-term:
1. Track ownership changes and subnet activity
2. Correlate with other IPs in the 2.56.180.0/22 block
3. Maintain threat intelligence context for this provider segment
---
Intelligence Notes
The IP presents a risk classification mismatch: while the risk score is 80, no active threat indicators (open ports, blacklists, campaigns) are currently observed. The 6 DNSBL listings suggest historical reputation issues. This IP may have been temporarily inactive or may represent infrastructure with limited public exposure. Continued monitoring is advised due to the high-risk classification.
*Report generated from IPDebrief intelligence platform. Data accuracy subject to real-time validation.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Intal Alliulin |
| ASN | AS31566 |
| Network Name | RU-SKYNETWORK1-20190314 |
| CIDR Block | 2.56.180.0/22 |
| RIR | RIPE |
| Country | RU |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 35% | 2 | 2 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 20% | 6 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-28 16:14:15 UTC |
| Last Seen | 2026-08-01 04:25:32 UTC |
| Profile Built | 2026-07-30 18:05:59 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.