IPDebrief

201.3.225.24

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 201.3.225.24

## Executive Summary

Target IP 201.3.225.24 is a low-risk server (risk score: 25/100) operating within the IPbnb-LLC network block (201.3.225.0/24). The IP is classified as a web server with minimal operator risk (0.1304) and is currently not flagged as a known attacker or spam source. However, the subnet exhibits moderate abuse density (0.3), with 3 threat-identified siblings requiring monitoring.

## Infrastructure Profile

Ownership & Registration

Geolocation

DNS Configuration

## Network Services & Fingerprinting

Open Ports & Services

PortProtocolServiceNotes
443TCPHTTPSPrimary web service
22TCPSSHOpenSSH_10.2p1 Ubuntu-2ubuntu3.5

TLS Certificate Analysis

## Threat Intelligence Assessment

Current Threat Status

Control Plane Indicators

## Neighborhood Analysis

Subnet Overview: 201.3.225.0/24

High-Risk Neighbors Identified

IP AddressRisk ScoreAuthority Score
201.3.225.267050
201.3.225.206650
201.3.225.256650
201.3.225.284050
201.3.225.294050

## Historical Observations

Observation Count: 24 signals tracked

## Relationship Graph

Primary Associations:

## Recommended Security Actions

Based on the current risk profile and neighborhood context:

1. Monitor Subnet Activity: The 201.3.225.0/24 subnet contains 3 threat-identified IPs. Monitor for lateral movement or coordinated activity.

2. Traffic Filtering: No immediate blocking recommended for this IP. However, consider rate-limiting SSH access (port 22) due to the open service.

3. TLS Certificate Verification: The self-signed certificate with mismatched issuer/subject warrants investigation. Verify if this is a legitimate hosting configuration or potential misconfiguration.

4. DNSBL Monitoring: The IP is listed on 1 of 8 DNSBLs. Monitor for additional listings and investigate the specific blacklist.

5. Geolocation Verification: Discrepancy between Poland country code and Stockholm city location requires validation.

## Intelligence Assessment

IP 201.3.225.24 presents a low-risk profile with no active malicious indicators. The infrastructure is operational as a web server with standard HTTPS/SSH services. While the subnet shows moderate abuse density, the target IP itself does not exhibit threat characteristics. Continued monitoring of the subnet is recommended due to the presence of high-risk neighbors (201.3.225.20, 201.3.225.25, 201.3.225.26). No immediate defensive action required beyond standard network hygiene.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ต๐Ÿ‡ฑ Poland
Regionโ€”
CityStockholm
TimezoneEurope/Warsaw
Latitude51.92
Longitude19.15

๐Ÿข Ownership & Registration

OrganizationIPBNB Abuse Contact
ASNAS48031
Network NameIPbnb-LLC
CIDR Block201.3.225.0/24
RIRLACNIC
CountryPL
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRvm23364.bit.hosting
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesvm23364.bit.hosting

๐Ÿ” DNS Hygiene

Hygiene Score60% (Good)
SPFPresent
DMARCPresent
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierTier 3 โ€” Basic operator with some routing infrastructure
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
35%
24
routing
24%
22
services
43%
23
ownership
35%
24
reputation
30%
13
geolocation
17%
11
Overall31%1017
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (65%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-07-25 19:18:27 UTC
Last Seen2026-08-05 04:49:36 UTC
Profile Built2026-08-05 02:51:29 UTC
Data FreshnessLive
Signal Types24
Total Observations50
๐Ÿ” 24 signal types ยท 50 observations collected
This report is generated from 24+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.