# IPDebrief Intelligence Briefing
Target: 201.3.225.21/32
Date: 2026-07-30
Classification: Low Risk
---
## Executive Summary
The target IP 201.3.225.21 presents a low-risk profile with no active threat indicators. However, contextual analysis of the parent subnet reveals elevated abuse activity requiring monitoring. The IP is operational as a web server with standard HTTP/HTTPS services and is registered under IPBNB-LLC (ASN 48031).
---
## Risk Assessment
| Metric | Value | Assessment |
|---|---|---|
| Risk Score | 0 | Low Risk |
| Provider Score | 0 | Minimal |
| Authority Score | 0 | Minimal |
| Operator Score | 0.1304 | Minimal |
| Blacklist Count | 0 | Clean |
| DNSBL Listed | 0/8 | Not Listed |
---
## Network Classification & Ownership
- Organization: IPBNB Abuse Contact (IPbnb-LLC)
- ASN: 48031
- CIDR Block: 201.3.225.0/24
- RIR: LACNIC
- Network Role: Provider - Tor Exit Nodes
- Infrastructure Type: Unknown
- Geolocation: Poland (PL) / Stockholm (reported)
- PTR Hostname: vm23382.bit.hosting
---
## Service Exposure
| Port | Protocol | Service | Status |
|---|---|---|---|
| 443 | TCP | HTTPS | Open |
| 22 | TCP | SSH | Open |
TLS Certificate: CN=www.emz5x5yxneizqs.com / CN=www.yru75u4uqiqrns3fofy.net
Email Authentication: SPF enabled, DMARC configured
---
## Neighborhood Analysis (201.3.225.0/24)
- Abuse Density: 30% (0.3)
- Subnet Classification: Mixed
- Inherited Risk: 7
- Active Siblings: 8 / 10 total IPs
High-Risk Neighbors:
- 201.3.225.20: Risk Score 66 (High)
- 201.3.225.25: Risk Score 66 (High)
- 201.3.225.26: Risk Score 70 (High)
Medium-Risk Neighbors:
- 201.3.225.22, .23, .24: Risk Score 25 (Medium)
- 201.3.225.28, .29: Risk Score 40 (Medium)
Low-Risk Neighbors:
- 201.3.225.27: Risk Score 0 (Low)
---
## Threat Indicators & Campaigns
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Active Campaigns: None detected
- Cert Matches: 0
- Banner Matches: 0
- Correlated IPs: 0
---
## Observation History
Total Observations: 23
Recent Activity: 2026-07-30 (5 observations in single day)
Threat Persistence: 0 days
Ownership Changes: 0
Persistent Malicious Activity: No
Operator scores consistently indicate minimal risk (0.1304) across multiple observation windows. No degradation in signal quality or emergence of threat indicators detected.
---
## Relationships & Infrastructure
Primary Associations:
- Network: IPBNB-LLC (multiple same-network relationships)
- DNS: vm23382.bit.hosting (multiple DNS associations)
No certificate-based relationships or additional organizational links identified.
---
## SOC Recommendations
Immediate Actions
1. Monitor, Do Not Block: Current risk profile supports allow-listing with monitoring
2. Traffic Analysis: Monitor HTTPS/SSH traffic patterns for anomalies
3. Subnet Awareness: Be aware of 3 high-risk siblings in parent subnet (201.3.225.20, .25, .26)
Firewall Rules (Recommended)
```bash
# Allow HTTPS (primary service)
iptables -A INPUT -p tcp -d 201.3.225.21 --dport 443 -j ACCEPT
# Allow SSH (monitor closely)
iptables -A INPUT -p tcp -d 201.3.225.21 --dport 22 -j LOG --log-prefix "SSH-201.3.225.21:"
```
Threat Hunting Triggers
- Subnet abuse density at 30% warrants periodic review
- Monitor for any emergence of threat indicators on target IP
- Watch for certificate changes or service pivoting
---
Conclusion: IP 201.3.225.21 is a low-risk web server with no active malicious indicators. The subnet context requires awareness but does not mandate defensive restrictions. Continue monitoring for changes in risk profile or subnet activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IPBNB Abuse Contact |
| ASN | AS48031 |
| Network Name | IPbnb-LLC |
| CIDR Block | 201.3.225.0/24 |
| RIR | LACNIC |
| Country | PL |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vm23382.bit.hosting |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | vm23382.bit.hosting |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_10.2p1 Ubuntu-2ubuntu3.5 |
๐ TLS Certificate
| SANs | None |
| Valid From | 2026-08-09T00:00:00+00:00 |
| Valid Until | 2026-08-26T00:00:00+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 17 days |
| Serial Number | 00BD19646C975E4B4D |
| Thumbprint | A112846FA3B33049698D1A78A10951B1C8FBFA5F |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 59% | 2 | 19 |
| routing | 34% | 3 | 4 |
| services | 38% | 2 | 3 |
| ownership | 32% | 3 | 4 |
| reputation | 26% | 1 | 3 |
| geolocation | 34% | 2 | 3 |
| Overall | 37% | 13 | 36 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-25 18:17:54 UTC |
| Last Seen | 2026-08-13 11:40:53 UTC |
| Profile Built | 2026-08-13 11:29:32 UTC |
| Data Freshness | Live |
| Signal Types | 29 |
| Total Observations | 75 |
Full dossier details are available via our API.