# IP INTELLIGENCE BRIEFING
Target: 213.160.180.247/32
Date: 2026-06-23
Classification: High Risk Residential DSL
---
## EXECUTIVE SUMMARY
The IP address 213.160.180.247 is classified as High Risk (Risk Score: 70) with no active services detected. The address is associated with Telecom.sk residential DSL infrastructure in Pezinok, Slovakia, and appears on 4 of 8 DNSBLs with "high" severity ratings. While the /24 subnet shows zero abuse density, this isolated IP has been flagged for malicious activity.
---
## OWNERSHIP & GEOLOCATION
- ASN: 6855 (Jan Katuska)
- Network Provider: SK-TELECOM-2004
- Country: Slovakia (SK)
- Region/City: Bratislava Region, Pezinok
- Geolocation Accuracy: Moderate (2 sources, consensus: false)
- Registration: ASN allocated 1996-12-03 (10,789+ days old)
---
## THREAT INDICATORS
- Risk Score: 70/100 (High Risk)
- DNSBL Listings: 4/8 lists (High Severity)
- Known Attacker: No direct attribution
- Tor Exit Node: No
- Spam Source: No
- Campaign Association: None detected
- Operator Score: 0.1304 (Minimal)
---
## NETWORK ANALYSIS
- Service State: Firewalled / No Services
- Open Ports: None
- DNS: static-dsl-247.213-160-180.telecom.sk (forward confirmed)
- BGP Prefix: 213.160.160.0/19
- AS Path: 6939 โ 6855
- Route Stability: Stable (0 changes in 30 days)
---
## OBSERVATION HISTORY
- Total Observations: 26 signals
- Recent Activity:
- 2026-06-23: Blacklist listing detected (8 lists, 3 active, max severity: high)
- 2026-06-18: ASN allocation confirmed, routing stable
- Threat Persistence: 1 observation day
- Persistent Malicious Activity: No
---
## NEIGHBORHOOD ANALYSIS
- Subnet: 213.160.180.247/24
- Abuse Density: 0% (Clean)
- Total Siblings: 1
- Threat Siblings: 0
- Inherited Risk: 0
---
## RELATIONSHIP MAPPING
- Same Network: SK-TELECOM-2004 (24 relationships)
- DNS Associations: static-dsl-247.213-160-180.telecom.sk (24 relationships)
- No External Threat Correlations: 0
---
## RECOMMENDED ACTIONS
| Priority | Action | Justification |
|---|---|---|
| **HIGH** | Monitor inbound/outbound traffic | High-risk classification with blacklist presence |
| **MEDIUM** | Add to monitoring blocklist | 4 DNSBL listings with high severity |
| **LOW** | Consider temporary block | Subnet shows clean abuse density, suggesting isolated incident |
| **MEDIUM** | Investigate source of traffic | Residential DSL with no legitimate services |
---
## ANALYST NOTES
This IP represents a residential DSL connection that has been flagged for malicious activity despite being on a otherwise clean subnet. The lack of open services suggests either a compromised residential device or a connection used for outbound attacks. Given the subnet's clean abuse density, this may warrant monitoring rather than aggressive blocking. The DNSBL presence indicates prior abuse history, but the absence of persistent malicious activity patterns suggests the threat may be contained or intermittent.
SOC Team: Monitor for patterns; do not assume sustained threat.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Jan Katuska |
| ASN | AS6855 |
| Network Name | โ |
| CIDR Block | 213.160.160.0/19 |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | static-dsl-247.213-160-180.telecom.sk |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | static-dsl-247.213-160-180.telecom.sk |
๐ DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 39% | 2 | 5 |
| routing | 32% | 2 | 3 |
| services | 15% | 2 | 2 |
| ownership | 26% | 3 | 4 |
| reputation | 23% | 1 | 3 |
| geolocation | 13% | 1 | 1 |
| Overall | 25% | 11 | 18 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:11 UTC |
| Last Seen | 2026-06-23 07:22:59 UTC |
| Profile Built | 2026-06-23 07:31:09 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 27 |
Full dossier details are available via our API.