Threat Intelligence Briefing: IP 212.33.235.243/32
Date: 2026-06-06
Overview:
- Risk Profile: Moderate Risk (Risk Score: 50). No active threats or malicious indicators detected.
- Ownership: Registered to JSC "ER-Telecom Holding" (AS12768) in Russia (Perm Krai).
- Geolocation: Perm, Russia (RU).
- Network Role: Firewalled host with no open services or TLS/HTTP activity.
Key Findings:
1. DNS Associations:
- Linked to mxr.fort.tel (PTR record).
- No email authentication records (SPF/DMARC) found.
2. Network Context:
- Part of the ERTH-PERM-CORP-5-NET network.
- Subnet 212.33.235.243/24 shows 0 abuse density, with no neighboring IPs flagged for risk.
3. Threat Indicators:
- No malicious campaigns, spam, or blacklist entries.
- BGP analysis shows stable routing with no recent changes.
4. Historical Activity:
- Last observed in DNSSEC validation (2026-06-06) and network classification (2026-05-29).
- No persistent threats or enumeration attempts detected.
Recommendations:
- Monitor DNS records (e.g., mxr.fort.tel) for anomalies or unauthorized changes.
- Verify network segmentation to ensure firewalled hosts (like this IP) are isolated from critical systems.
- Conduct periodic re-validation of ownership and geolocation, as the IP shows no recent activity in threat feeds.
Conclusion:
This IP appears to be a legitimate corporate asset with no immediate malicious activity. However, its moderate risk score and lack of visibility into internal network security practices warrant continued monitoring.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | JSC "ER-Telecom Holding" |
| ASN | AS12768 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | mxr.fort.tel |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | mxr.fort.tel |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Residential |
| Service Purpose | Residential Endpoint |
| Network Tier | End-User โ Residential ISP endpoint |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 27% | 2 | 3 |
| reputation | 16% | 1 | 2 |
| geolocation | 19% | 2 | 2 |
| Overall | 19% | 9 | 11 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-13 12:12:55 UTC |
| Last Seen | 2026-06-13 03:45:31 UTC |
| Profile Built | 2026-06-06 21:28:08 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 22 |
Full dossier details are available via our API.