# IP Intelligence Briefing: 213.176.26.29/32
## Executive Summary
IP address 213.176.26.29 is classified as Moderate Risk with an overall risk score of 50. The address is part of ASN 209425 (IROST-MNT) within the 213.176.24.0/22 block, registered under RIPE RIR. Current analysis indicates no active threat indicators, no known malicious campaigns, and no operational services.
## Technical Profile
Network Classification: Firewalled / No Services
- No open ports detected
- No active TLS certificates
- No HTTP services responding
- No email authentication records (SPF, DMARC)
Ownership & Registration:
- ASN: 209425
- Organization: IROST-MNT
- Network Name: MM500-NET
- CIDR Block: 213.176.24.0/22
- Abuse Contact: Available via RDAP
- RIR: RIPE
Geolocation:
- Country: NL (Netherlands)
- Coordinates: 52.13°N, 5.29°E
- Timezone: Europe/Amsterdam
- Geolocation consensus: Active (1 source)
Control Plane Status:
- BGP Origin: 213.176.26.0/24
- Route stability: Unstable
- DNSSEC: Valid
- Operator Score: 0.1304 (Minimal)
## Threat Assessment
Current Threat Indicators:
- Known attacker: No
- Tor exit node: No
- Spam source: No
- Blacklist count: 0
- DNSBL listings: 2 of 8 total lists
- Known campaigns: None identified
Historical Observations (12 records):
Monitoring data from July 31, 2026 shows consistent geolocation and ownership attribution across all observations. No escalation in threat signals detected. Operator-level analysis classified this resource as "Minimal" operator score with 0.15 raw score.
## Neighborhood Analysis
Subnet: 213.176.26.0/24
- Total sibling IPs: 35
- Abuse density: 0%
- Risk distribution:
- High risk: 0
- Medium risk: 24
- Low risk: 11
The subnet exhibits elevated medium-to-high risk concentration (24 of 35 neighbors). Notable high-risk neighbors include:
- 213.176.26.44 (Risk: 65)
- Multiple IPs with Risk Score: 50 (213.176.26.19, .21, .22, .23, .34, .41, .42, .51, .52, .54, .58, .62, .69, .72, .87, .88, .94, .95, .109, .123, .133, .153, .165, .175, .182, .186, .191, .194)
## Relationship Graph
Identified Relationships:
- Same Network: MM500-NET
The relationship graph indicates this IP is associated with the MM500-NET network infrastructure.
## Recommended Actions
Based on current risk profile and threat indicators:
1. Monitoring: Continue passive monitoring given moderate risk classification
2. Traffic Analysis: No immediate blocking required; no active services detected
3. Network Context: Be aware of elevated medium-risk density in adjacent subnet (213.176.26.0/24)
4. DNSBL Awareness: IP appears on 2 of 8 known DNS blacklists
5. Route Stability: Note unstable BGP routing; monitor for prefix hijacking or misconfiguration
## Conclusion
IP 213.176.26.29 presents a moderate risk profile with no active threat indicators. The absence of open services and lack of historical malicious activity suggest this is likely a passive or dormant resource. However, the surrounding subnet shows concentrated medium-to-high risk activity, warranting awareness of potential lateral threat vectors. SOC analysts should monitor for any service activation or threat indicator emergence from this resource or its neighbors.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IROST-MNT |
| ASN | AS209425 |
| Network Name | MM500-NET |
| CIDR Block | 213.176.24.0/22 |
| RIR | RIPE |
| Country | NL |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_7.4 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 16% | 4 | 4 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-30 17:11:59 UTC |
| Last Seen | 2026-08-06 06:40:13 UTC |
| Profile Built | 2026-07-31 03:49:59 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 19 |
Full dossier details are available via our API.