# IPDEBRIEF INTELLIGENCE BRIEFING
Target: 212.95.138.76/32
Date: 2026-07-25
Classification: Moderate Risk
---
## EXECUTIVE SUMMARY
IP 212.95.138.76 presents a moderate-risk threat profile (risk score: 40) with conflicting geolocation data and DNSBL listings. The IP is assigned to ASIACELL communications infrastructure but geolocates to the US, creating a potential spoofing or misconfiguration indicator. Recommended action is monitoring/blocking pending correlation with other threat indicators.
---
## OWNERSHIP & NETWORK CLASSIFICATION
| Attribute | Value |
|---|---|
| **ASN** | 51684 (ASIACELL - ASIACELL COMMUNICATIONS PJSC, IQ) |
| **Organization** | IQ-ASIACELL-20090427 |
| **CIDR Block** | 212.95.128.0/19 |
| **RIR** | RIPE |
| **Registration** | 2009-04-27 |
| **Country** | IQ (Iraq) per ASN registry |
| **Geolocation** | US, New York (flagged implausible) |
Note: ASN registry confirms Iraqi assignment, but geolocation tools report US coordinates with low confidence (geoPlausible: false, geoConsensus: false). This discrepancy warrants investigation.
---
## THREAT ASSESSMENT
Risk Indicators
- Overall Risk Score: 40 (Moderate)
- DNSBL Listings: 2 of 8 total lists
- Maximum Severity: High
- Known Campaigns: None detected
- Tor Exit/Proxy: No
- Open Ports: None detected (Firewalled / No Services)
Behavioral Observations
- Route Stability: Unstable (3 route changes in 30 days)
- DNSSEC: Valid
- Honeypot Hits: 0
- Enumeration Strikes: 0
- Threat Persistence: 0 days observed
---
## NETWORK NEIGHBORHOOD ANALYSIS
Subnet: 212.95.138.0/24
- Abuse Density: 0 (Clean)
- Total Siblings: 4
- Active Siblings: 1
- Threat Siblings: 0
| Neighbor IP | Risk Score | Authority Score |
|---|---|---|
| 212.95.138.55 | 0 | 50 |
| 212.95.138.58 | 0 | 50 |
| 212.95.138.156 | 25 | 50 |
*One sibling IP (212.95.138.156) shows elevated risk (25) but remains below action threshold.*
---
## OBSERVATION HISTORY
Total observations: 16
- Recent DNSSEC Validation: Confirmed (2026-07-25)
- ASN Confirmation: ASN 51684 confirmed via Cymru DNS
- Ownership Changes: 0 (stable)
- Threat Observation Count: 0
---
## RECOMMENDED SECURITY ACTIONS
| Platform | Recommendation |
|---|---|
| **iptables** | `iptables -A INPUT -s 212.95.138.76 -j DROP` |
| **nftables** | `nft add rule inet filter input ip saddr 212.95.138.76 drop` |
| **nginx** | `deny 212.95.138.76;` |
| **pfSense** | `212.95.138.76/32` |
| **Cloudflare WAF** | Block with expression: `ip.src eq 212.95.138.76` |
| **AWS WAF** | Add 212.95.138.76/32 to blacklist |
---
## INTELLIGENCE ANALYSIS
Key Finding: The geolocation discrepancy (ASN shows Iraq, geolocation shows US) is the primary anomaly. This could indicate:
1. Geolocation database error
2. IP address spoofing
3. Legitimate infrastructure with misreported location
Risk Assessment: The IP has no active open services, no known threat indicators, and resides in a clean subnet. However, the DNSBL listings (2 of 8, high severity) suggest prior abuse activity. The route instability further indicates potential infrastructure changes or misconfiguration.
SOC Action: Monitor for correlation with other malicious activity. The moderate risk score (40) with high-severity DNSBL listings warrants blocking in perimeter controls, particularly if observed in connection with suspicious traffic patterns.
---
*This briefing generated by IPDebrief threat intelligence system. All data sourced from real-time IP reputation analysis.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Admin Person |
| ASN | AS51684 |
| Network Name | IQ-ASIACELL-20090427 |
| CIDR Block | 212.95.128.0/19 |
| RIR | RIPE |
| Country | IQ |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS51684 |
| Network Prefix | 212.95.138.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 25% | 1 | 2 |
| services | 0% | 0 | 0 |
| ownership | 25% | 1 | 1 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 12% | 3 | 4 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-09 01:19:32 UTC |
| Last Seen | 2026-08-27 08:31:19 UTC |
| Profile Built | 2026-08-29 05:01:32 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 20 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 212.95.138.76
Who owns the IP address 212.95.138.76?
212.95.138.76 is registered to Admin Person. The address falls within the 212.95.128.0/19 network block. Registration is held at RIPE.
Where is 212.95.138.76 located?
Geolocation data places 212.95.138.76 in New York, US-NY, United States. The local time zone is America/New_York. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 212.95.138.76 malicious or safe?
212.95.138.76 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.