# IP INTELLIGENCE BRIEFING: 212.36.194.131
Classification: Moderate Risk (Score: 55/100)
Report Date: Current
Analyst: SOC Operations
---
## EXECUTIVE SUMMARY
IP 212.36.194.131 is a multi-service host operating from Lebanon (Beirut) under ASN 9051 (INCoNet Data Management). The IP presents a moderate risk profile with elevated threat indicators including DNSBL listings (3/8 lists) and SSH service exposure. Recommended action: implement monitoring controls and consider blocking pending correlation with additional threat intelligence.
---
## NETWORK IDENTIFICATION
| Field | Value |
|---|---|
| **IP Address** | 212.36.194.131/32 |
| **Subnet** | 212.36.194.0/24 |
| **ASN** | 9051 |
| **Organization** | Dima Saleh / INCoNet Data Management sal |
| **Country** | Lebanon (LB) |
| **City** | Beirut |
| **RIR** | RIPE |
| **Allocation Date** | 1998-08-12 |
---
## THREAT ASSESSMENT
Overall Risk Score: 55/100 (Moderate)
Risk Indicators
- DNSBL Listings: 3 of 8 known lists (control plane data)
- Operator Score: 0.3478 (Basic classification)
- Abuse Confidence: No direct threat indicators detected
- Campaign Association: None identified
- Known Attacker: No
- Spam Source: No
Network Characteristics
- Service Purpose: Multi-Service Host
- Is Cloud/CDN/VPN: No
- Is Proxy/Tor: No
- Is Hosting: No
- Route Stability: Stable (true)
- DNSSEC Valid: Yes
---
## OBSERVED SERVICES
| Port | Protocol | Service | Status |
|---|---|---|---|
| 80 | TCP | HTTP | Open |
| 22 | TCP | SSH | Open (SSH-2.0-ROSSSH banner) |
---
## NETWORK CONTEXT
Neighborhood Analysis (212.36.194.0/24)
- Abuse Density: 1 (Subnet classified as "mostly_clean")
- Inherited Risk: 2
- Total Siblings: 1
- Active Siblings: 1
- Threat Siblings: 1
BGP Path Analysis
- Origin ASN: 9051
- AS Path: 57866 โ 5511 โ 42020 โ 24634 โ 24634 โ 24634 โ 24634 โ 9051
- Route Changes (30d): 0
---
## OBSERVATION HISTORY
Recent signal observations (20 total) indicate:
- DNSSEC validation confirmed on in-addr.arpa PTR records
- ASN/prefix resolution consistently identifies 212.36.194.0/24
- Routing signals show stable BGP propagation
- Operator scoring fluctuates (latest: 0.3478)
- Threat observation count: 1
---
## RELATIONSHIP ANALYSIS
The IP maintains 15 relationship entries, all classified as "Same Network" relationships to network entity "IDM-CORPORATE-DIALUP." No hostname, organization, or certificate associations detected.
---
## RECOMMENDED ACTIONS
Immediate
1. Block Traffic - Implement firewall rules to deny traffic from this IP:
- `iptables -A INPUT -s 212.36.194.131 -j DROP`
- `nft add rule inet filter input ip saddr 212.36.194.131 drop`
- `nginx: deny 212.36.194.131;`
Enhanced Monitoring
- Increase logging verbosity for all traffic from this subnet
- Review recent activity logs for potential correlation with other threats
- Monitor SSH port (22) for unauthorized access attempts
Additional Controls
- Cloudflare WAF: Block IP with expression `ip.src eq 212.36.194.131`
- AWS WAF: Add 212.36.194.131/32 to block list
---
## INTELLIGENCE GAPS
- Limited PTR hostname resolution
- No email authentication records (SPF/DMARC)
- No TLS certificate data available
- No forward DNS resolution confirmed
---
## CONCLUSION
IP 212.36.194.131 represents a moderate-risk multi-service host from Lebanon with established infrastructure but elevated threat indicators. The subnet maintains relatively clean abuse density but contains one threat-identified sibling. Recommend blocking at perimeter and implementing enhanced logging for correlation purposes.
---
Sources: IPDebrief Intelligence Platform
Classification: Defensible Intelligence
Last Updated: Current
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dima Saleh |
| ASN | AS9051 |
| Network Name | โ |
| CIDR Block | 212.36.194.0/24 |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Multi-Service Host |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 443, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-ROSSSH |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 36% | 2 | 5 |
| routing | 33% | 2 | 4 |
| services | 24% | 2 | 3 |
| ownership | 30% | 3 | 4 |
| reputation | 22% | 1 | 3 |
| geolocation | 13% | 1 | 1 |
| Overall | 26% | 11 | 20 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-10 22:17:33 UTC |
| Last Seen | 2026-06-26 05:09:30 UTC |
| Profile Built | 2026-06-26 05:16:27 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 21 |
Full dossier details are available via our API.