# IP INTELLIGENCE BRIEFING: 213.176.26.44/32
Classification: Moderate Risk (Score: 65) | Status: Active Monitoring | Date: 2026-07-30
---
## EXECUTIVE SUMMARY
IP address 213.176.26.44 is registered to the MM500-NET network under ASN 209425 (IROST-MNT), allocated through RIPE NCC. The address presents moderate risk (65/100) with no confirmed malicious activity, though it appears on 3 DNS blacklists. Geolocation data shows inconsistency between registration (Netherlands) and alternative probe data (Iran), requiring verification.
---
## OWNERSHIP AND REGISTRATION
- ASN: 209425
- Organization: IROST-MNT
- Network Name: MM500-NET
- CIDR Block: 213.176.24.0/22
- RIR: RIPE
- Abuse Contact: Available via RDAP
---
## GEOLOCATION ANALYSIS
Primary Classification: Netherlands (NL)
- Coordinates: 52.13°N, 5.29°E
- Accuracy Radius: 150km
- Timezone: Europe/Amsterdam
Geolocation Discrepancy Detected:
- Signal 1: Netherlands (confidence: 0.40)
- Signal 2: Iran (confidence: 0.70)
- Source: maxmind-geolite2-city
This inconsistency warrants monitoring for potential spoofing or misconfiguration.
---
## THREAT INDICATORS
- Abuse Confidence Score: Not available
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Blacklist Count: 0 (active threats)
- DNSBL Listed: 3 of 8 total lists
- Known Campaigns: None identified
Risk Assessment: Moderate risk score (65) with no active threat indicators. The DNSBL listings suggest some reputation issues but no confirmed malicious activity.
---
## NETWORK INFRASTRUCTURE
- Services: Firewalled / No Services
- Open Ports: None detected
- TLS Certificate: None
- DNS Resolution: Forward resolution not confirmed
- PTR Hostnames: None
Control Plane Data:
- BGP Prefix: 213.176.26.0/24
- Origin ASN: 209425
- Route Stability: False
- RPKI State: Not validated
---
## SUBNET ANALYSIS (213.176.26.0/24)
- Total Neighbors: 35 sibling IPs
- Abuse Density: 0
- Risk Distribution: High: 0, Medium: 0, Low: 0
- Active Threat Siblings: 0
The /24 subnet shows minimal abuse activity, with no sibling IPs flagged as high or medium risk.
---
## OBSERVATION HISTORY
Total Signals: 11 observations
Key Temporal Indicators:
- Ownership changes: 0
- Threat persistence days: 0
- Threat observation count: 0
- Persistently Malicious: False
Recent Signal Activity (2026-07-30):
- 22:42: Ownership stability confirmed
- 22:41: Geolocation signal (Netherlands, confidence 0.40)
- 22:41: Geolocation signal (Iran, confidence 0.70)
- 22:40: Operator score: "Minimal" (0.1304)
---
## RELATIONSHIP GRAPH
- Same Network: MM500-NET (3 references)
- Subnet Links: None
- Hostname Associations: None
- Certificate Matches: None
Limited relationship footprint indicates isolated network presence.
---
## RECOMMENDED ACTIONS
1. Monitor Geolocation Inconsistencies: The NL/IR discrepancy requires ongoing validation
2. DNSBL Review: Investigate the 3 blacklist entries for potential policy violations
3. Passive Monitoring: Continue observation for service emergence (currently firewalled)
4. Subnet Correlation: Monitor 35 sibling IPs for coordinated activity patterns
---
## SOC DECISION POINTS
- Block Recommendation: Not required (no active threats)
- Monitor Priority: Medium (geolocation inconsistency)
- Escalation Threshold: Service emergence or threat indicator activation
Final Assessment: This IP presents moderate risk primarily due to DNSBL listings and geolocation ambiguity. No immediate blocking required; maintain monitoring posture and watch for service activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | IROST-MNT |
| ASN | AS209425 |
| Network Name | MM500-NET |
| CIDR Block | 213.176.24.0/22 |
| RIR | RIPE |
| Country | NL |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_7.4 |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 5 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-29 16:41:57 UTC |
| Last Seen | 2026-08-13 06:44:37 UTC |
| Profile Built | 2026-08-10 17:30:14 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 18 |
Full dossier details are available via our API.