# IPDebrief Intelligence Briefing
## Subject: 201.3.225.27/32
Classification: LOW RISK / MONITOR
Date: 2026-07-30
Prepared For: SOC Analyst Team
---
EXECUTIVE SUMMARY
Target IP 201.3.225.27 presents a low-risk profile with no active threat indicators. The address is registered to IPBNB LLC under ASN 48031, operating from the LACNIC region. While the IP shows minimal operator risk scoring (0.1304), the subnet exhibits mixed classification with 30% abuse density. No immediate defensive action required; maintain monitoring posture.
---
OWNERSHIP & REGISTRAR
- Organization: IPBNB LLC
- Network Name: IPbnb-LLC
- ASN: 48031
- CIDR Block: 201.3.225.0/24
- RIR: LACNIC
- Abuse Contact: Available via RDAP
- Geolocation: Poland (PL) / Stockholm region
---
NETWORK CLASSIFICATION
- Reputation Score: 0 (Low Risk)
- Provider Score: 0
- Authority Score: 0
- Stability Score: 0
- Network Role: Web Server (with Tor Exit Node classification noted)
- Infrastructure Type: Unknown
- Cloud/CDN/VPN: Negative across all categories
- Bogon Status: False
---
THREAT ASSESSMENT
- Abuse Confidence Score: Not applicable (null)
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False (contradicts network role classification)
- Blacklist Count: 0
- Threat Feeds: None detected
- Campaign Likelihood: None
---
SERVICE PORTS & EXPOSURE
| Port | Protocol | Service | Status |
|---|---|---|---|
| 443 | TCP | HTTPS | Open |
| 22 | TCP | SSH | Open |
SSH Banner: SSH-2.0-OpenSSH_10.2p1 Ubuntu-2ubuntu3.5
TLS Configuration:
- Protocol: TLS 1.3
- Cipher Suite: TLS_AES_256_GCM_SHA384
- Certificate: Self-signed (CN=www.fmfilq6shyja5roh6rf.net)
- Issuer: CN=www.mebblm7fvcw2o.com
DNS Resolution: vm23373.bit.hosting (forward confirmed: False)
---
SUBNET ANALYSIS (201.3.225.0/24)
- Abuse Density: 0.3 (30%)
- Classification: Mixed
- Total Siblings: 10
- Active Siblings: 10
- Threat Siblings: 3
- Inherited Risk: 7
High-Risk Neighbors Identified:
- 201.3.225.26 (Risk: 70)
- 201.3.225.20 (Risk: 66)
- 201.3.225.25 (Risk: 66)
---
OBSERVATION HISTORY
- Total Observations: 25
- Latest Activity: 2026-07-30
- Threat Persistence Days: 0
- Ownership Changes: 0
- Is Persistently Malicious: False
Temporal Analysis:
- No persistent malicious behavior detected
- Ownership stable with zero changes
- Recent subnet classification consistently shows "mixed" status
---
RELATIONSHIP GRAPH
- Total Relationships: 31
- Same Network Entries: 15 (all pointing to IPBNB-LLC)
- DNS Associations: 15 (all pointing to vm23373.bit.hosting)
- External Organizations: None detected
---
CONTROL PLANE DATA
- Operator Score: 0.1304 (Minimal)
- DNSSEC Valid: True
- RRP Consistency: Not evaluated
- Route Stability: False
- BGP Prefix: 201.3.225.0/24
- Route Changes (30d): 0
---
RECOMMENDATIONS & ACTIONS
Current Action Status: No recommendations generated
Risk-Based Assessment:
- Risk Score: 0
- Provider Risk: 0
- Authority Risk: 0
- Firewall Rules: Not required at this time
SOC Analyst Guidance:
1. Continue standard monitoring for this IP
2. Monitor subnet 201.3.225.0/24 for correlation with high-risk neighbors
3. No immediate blocking required; maintain allow-list or standard filtering
4. Investigate SSL certificate discrepancy if traffic originates from this IP
---
INTELLIGENCE NOTES
The IP shows a discrepancy between its "Tor Exit Node" network role classification and actual threat indicators. The self-signed TLS certificate with non-standard domain names warrants attention if this IP is used as a response target. Three sibling IPs in the /24 subnet show elevated risk scores (66-70), suggesting potential coordinated activity or shared infrastructure. The subnet's 30% abuse density indicates this should be monitored as part of broader subnet hygiene assessments.
Status: Monitor - No Immediate Action Required
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IPBNB Abuse Contact |
| ASN | AS48031 |
| Network Name | IPbnb-LLC |
| CIDR Block | 201.3.225.0/24 |
| RIR | LACNIC |
| Country | PL |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vm23373.bit.hosting |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | vm23373.bit.hosting |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_10.2p1 Ubuntu-2ubuntu3.5 |
๐ TLS Certificate
| SANs | None |
| Valid From | 2026-06-20T00:00:00+00:00 |
| Valid Until | 2026-11-24T23:59:59+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 157 days |
| Serial Number | 5375A300046BE7F5 |
| Thumbprint | 5C4DE0A1DADD93591F6398339E4E7CAE5DB707DB |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 29% | 2 | 4 |
| routing | 34% | 3 | 4 |
| services | 37% | 2 | 3 |
| ownership | 32% | 3 | 4 |
| reputation | 26% | 1 | 3 |
| geolocation | 34% | 2 | 3 |
| Overall | 32% | 13 | 21 |
| Data Coherence | Mixed Signals (60%) โ 2 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
โ Geo sources disagree on country: US, PL
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-25 19:18:27 UTC |
| Last Seen | 2026-08-13 10:40:13 UTC |
| Profile Built | 2026-08-13 09:30:58 UTC |
| Data Freshness | Live |
| Signal Types | 30 |
| Total Observations | 59 |
Full dossier details are available via our API.