# IP Intelligence Briefing: 201.3.225.24
## Executive Summary
Target IP 201.3.225.24 is a low-risk server (risk score: 25/100) operating within the IPbnb-LLC network block (201.3.225.0/24). The IP is classified as a web server with minimal operator risk (0.1304) and is currently not flagged as a known attacker or spam source. However, the subnet exhibits moderate abuse density (0.3), with 3 threat-identified siblings requiring monitoring.
## Infrastructure Profile
Ownership & Registration
- ASN: 48031 (IPBNB Abuse Contact)
- Organization: IPbnb-LLC
- CIDR Block: 201.3.225.0/24
- RIR: LACNIC (Latin America and Caribbean)
- Network Classification: Provider / Tor Exit Nodes
Geolocation
- Country: Poland (PL)
- City: Stockholm (data discrepancy noted)
- Accuracy Radius: 400km
- Geo-Consensus: Validated across multiple sources
DNS Configuration
- PTR Hostname: vm23364.bit.hosting
- Domain: bit.hosting
- Forward Resolution: Confirmed (1 hostname)
- Email Auth: SPF and DMARC records present
## Network Services & Fingerprinting
Open Ports & Services
| Port | Protocol | Service | Notes |
|---|---|---|---|
| 443 | TCP | HTTPS | Primary web service |
| 22 | TCP | SSH | OpenSSH_10.2p1 Ubuntu-2ubuntu3.5 |
TLS Certificate Analysis
- Issuer: CN=www.ld22dpp4.com
- Subject: CN=www.l3qaalepn.net
- Certificate Type: Self-signed (false positive flag)
- SANs: None detected
- HTTP Title: Not detected
## Threat Intelligence Assessment
Current Threat Status
- Risk Score: 25 (Low Risk)
- Abuse Confidence Score: Not detected
- Blacklist Count: 0
- Known Campaigns: None
- Threat Feeds: No matches
- Tor Exit Node: False (though classified in network role)
Control Plane Indicators
- Route Stability: False (not route stable)
- DNSBL Listed: 1 of 8 lists
- BGP Prefix: 201.3.225.0/24
- RPKI State: Not verified
- IRR Consistency: Not verified
- Operator Score: 0.1304 (Minimal)
## Neighborhood Analysis
Subnet Overview: 201.3.225.0/24
- Total Siblings: 10
- Active Siblings: 7
- Threat-Identified Siblings: 3
- Abuse Density: 0.3 (Moderate)
- Classification: Mixed
High-Risk Neighbors Identified
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 201.3.225.26 | 70 | 50 |
| 201.3.225.20 | 66 | 50 |
| 201.3.225.25 | 66 | 50 |
| 201.3.225.28 | 40 | 50 |
| 201.3.225.29 | 40 | 50 |
## Historical Observations
Observation Count: 24 signals tracked
- Most Recent: 2026-07-30 20:29:54 UTC
- Signal Types: Geolocation, DNS, Operator, and threat observations
- Consistency: Operator score stable at 0.1304 across all observations
- Threat Persistence: 0 days (no persistent malicious activity detected)
- Ownership Changes: 0 (stable ownership)
## Relationship Graph
Primary Associations:
- Network: IPbnb-LLC (multiple same-network relationships)
- Hostname: vm23364.bit.hosting (DNS association)
## Recommended Security Actions
Based on the current risk profile and neighborhood context:
1. Monitor Subnet Activity: The 201.3.225.0/24 subnet contains 3 threat-identified IPs. Monitor for lateral movement or coordinated activity.
2. Traffic Filtering: No immediate blocking recommended for this IP. However, consider rate-limiting SSH access (port 22) due to the open service.
3. TLS Certificate Verification: The self-signed certificate with mismatched issuer/subject warrants investigation. Verify if this is a legitimate hosting configuration or potential misconfiguration.
4. DNSBL Monitoring: The IP is listed on 1 of 8 DNSBLs. Monitor for additional listings and investigate the specific blacklist.
5. Geolocation Verification: Discrepancy between Poland country code and Stockholm city location requires validation.
## Intelligence Assessment
IP 201.3.225.24 presents a low-risk profile with no active malicious indicators. The infrastructure is operational as a web server with standard HTTPS/SSH services. While the subnet shows moderate abuse density, the target IP itself does not exhibit threat characteristics. Continued monitoring of the subnet is recommended due to the presence of high-risk neighbors (201.3.225.20, 201.3.225.25, 201.3.225.26). No immediate defensive action required beyond standard network hygiene.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IPBNB Abuse Contact |
| ASN | AS48031 |
| Network Name | IPbnb-LLC |
| CIDR Block | 201.3.225.0/24 |
| RIR | LACNIC |
| Country | PL |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vm23364.bit.hosting |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | vm23364.bit.hosting |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 4 |
| routing | 24% | 2 | 2 |
| services | 43% | 2 | 3 |
| ownership | 35% | 2 | 4 |
| reputation | 30% | 1 | 3 |
| geolocation | 17% | 1 | 1 |
| Overall | 31% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (65%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-25 19:18:27 UTC |
| Last Seen | 2026-08-05 04:49:36 UTC |
| Profile Built | 2026-08-05 02:51:29 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 50 |
Full dossier details are available via our API.