IPDebrief

213.221.63.119

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 213.221.63.119/32

## Executive Summary

Risk Assessment: Low Risk (Score: 25/100)

Classification: Legitimate ISP Infrastructure

Geolocation: Russia (RU)

Status: Monitored but no active threat indicators detected

---

## Network Ownership & Infrastructure

Control Plane Data:

Network Classification:

---

## Geolocation Analysis

Primary Location: Russia (RU)

---

## DNS & Hostname Analysis

PTR Records: 119.spb.sovintel.ru

Forward Resolution: Confirmed (1 hostname)

Domain: sovintel.ru

Email Authentication:

DNSBL Status: Listed on 1 of 8 tested blacklists

---

## Threat Intelligence Indicators

Threat Profile:

Behavioral Signals:

---

## Historical Observation Analysis

Observation Count: 18 signals recorded

Most Recent Signal: 2026-07-26 20:57:01 UTC

Signal Timeline:

Temporal Indicators:

---

## Relationship Graph Analysis

Total Relationships: 7

Relationship Types:

External Link Analysis: No relationships to external organizations, subnets, or certificates detected

---

## Neighborhood Analysis (213.221.63.0/24)

Subnet Classification:

---

## Recommended Actions

Security Recommendations: None currently required

Firewall Rules: No specific rules generated

Provider Score: 0

Authority Score: 0

Stability Score: 0

Action Rationale: The IP presents low-risk characteristics with no active threat indicators. However, the presence of 1 DNSBL listing warrants continued monitoring. No immediate blocking recommended.

---

## SOC Analyst Notes

Key Observations:

1. This IP belongs to a Russian ISP infrastructure (SOVINTEL-Interface-Network, ASN 3216)

2. No active threat indicators or malicious behavior detected

3. Subnet shows 0% abuse density with no threat siblings

4. DNS infrastructure includes SPF/DMARC configuration

5. One DNSBL listing detected—requires contextual analysis

6. Route stability flagged as false, indicating potential BGP changes

Recommendation: Continue monitoring. No immediate action required. If this IP appears in incident logs, investigate in context of broader attack patterns rather than as standalone threat.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇷🇺 Russia
Region—
City—
Timezone—
Latitude—
Longitude—

🏢 Ownership & Registration

OrganizationSt.Peterburg internet helpdesk group
ASNAS3216
Network NameSOVINTEL-Interface-Network
CIDR Block213.221.63.0/24
RIRRIPE
CountryRU
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTR119.spb.sovintel.ru
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnames119.spb.sovintel.ru

🔐 DNS Hygiene

Hygiene Score40% (Fair)
SPF2/2 domains
DMARC2/2 domains
FCrDNSNot verified
DNSSECNot signed
CAANot configured
Domains Checked2 domains

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS3216
Network Prefix213.221.48.0/20
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
25%
12
reputation
0%
00
geolocation
0%
00
Overall16%45
Coverage: 4/6 dimensions · Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

📅 Observation Timeline 🔄 Live

First Seen2026-07-11 14:30:55 UTC
Last Seen2026-09-22 07:39:18 UTC
Profile Built2026-09-21 07:30:31 UTC
Data FreshnessLive
Signal Types21
Total Observations28
🔍 21 signal types · 28 observations collected
This report is generated from 21+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 213.221.63.119

Who owns the IP address 213.221.63.119?

213.221.63.119 is registered to St.Peterburg internet helpdesk group. The address falls within the 213.221.63.0/24 network block. Registration is held at RIPE.

Where is 213.221.63.119 located?

Geolocation data places 213.221.63.119 in Russia. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 213.221.63.119 malicious or safe?

213.221.63.119 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.

What is the hostname for 213.221.63.119?

The reverse DNS (PTR) record for 213.221.63.119 is 119.spb.sovintel.ru. This hostname is not forward-confirmed, so it should be treated as a weak signal.

🏘️ Related IP Addresses

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.