# IP Intelligence Briefing: 213.221.63.119/32
## Executive Summary
Risk Assessment: Low Risk (Score: 25/100)
Classification: Legitimate ISP Infrastructure
Geolocation: Russia (RU)
Status: Monitored but no active threat indicators detected
---
## Network Ownership & Infrastructure
Control Plane Data:
- ASN: 3216
- Organization: St.Peterburg internet helpdesk group
- Netname: SOVINTEL-Interface-Network
- CIDR Block: 213.221.63.0/24
- RIR Registry: RIPE
- Route Stability: False (route changes detected in 30-day window)
- RPKI State: Not validated
- IRRS Consistency: Not available
Network Classification:
- Infrastructure Type: No specific classification
- Service Purpose: Firewalled / No Services
- Cloud/CDN/VPN/Proxy/Tor: Negative indicators across all categories
- Mobile/Residential: Not applicable
---
## Geolocation Analysis
Primary Location: Russia (RU)
- Confidence: Multiple signal sources confirm Russian origin
- Coordinates: 55.7386, 37.6068 (Moscow region per MaxMind Geolite2)
- Alternative Signal: 61.52, 105.32 (52% confidence, 5000km accuracy)
- Distance from Probe: 2035.6km
- Minimum Possible RTT: 40.7ms
- Geo Validation: ICMP blocked - unable to validate via probe
---
## DNS & Hostname Analysis
PTR Records: 119.spb.sovintel.ru
Forward Resolution: Confirmed (1 hostname)
Domain: sovintel.ru
Email Authentication:
- SPF: Configured
- DMARC: Configured
- TXT Records: 0
DNSBL Status: Listed on 1 of 8 tested blacklists
---
## Threat Intelligence Indicators
Threat Profile:
- Reputation: Low Risk
- Abuse Confidence Score: Not assigned
- Blacklist Count: 0 (primary feed)
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Known Campaigns: None detected
- Threat Feeds: Empty
Behavioral Signals:
- Honeypot Hits: 0
- Threat Persistence Days: 0
- Persistently Malicious: No
- Threat Observation Count: 0
---
## Historical Observation Analysis
Observation Count: 18 signals recorded
Most Recent Signal: 2026-07-26 20:57:01 UTC
Signal Timeline:
- Network Type: Not CDN, Tor, VPN, proxy, or hosting infrastructure
- Geolocation Signals: Multiple sources confirm Russian origin with varying confidence levels (30-85%)
- Ownership Tracking: 0 ownership changes detected
- Threat Persistence: No persistent malicious activity observed
Temporal Indicators:
- Ownership Changes: 0
- Threat Persistence Days: 0
- Is Persistently Malicious: False
---
## Relationship Graph Analysis
Total Relationships: 7
Relationship Types:
- Same Network: 4 relationships to SOVINTEL-Interface-Network
- DNS Association: 3 relationships to hostname 119.spb.sovintel.ru
External Link Analysis: No relationships to external organizations, subnets, or certificates detected
---
## Neighborhood Analysis (213.221.63.0/24)
Subnet Classification:
- Abuse Density: 0%
- Total Siblings: 0
- Active Siblings: 0
- Threat Siblings: 0
- Risk Distribution: No IPs with high/medium/low risk detected
- Inherited Risk: 0
---
## Recommended Actions
Security Recommendations: None currently required
Firewall Rules: No specific rules generated
Provider Score: 0
Authority Score: 0
Stability Score: 0
Action Rationale: The IP presents low-risk characteristics with no active threat indicators. However, the presence of 1 DNSBL listing warrants continued monitoring. No immediate blocking recommended.
---
## SOC Analyst Notes
Key Observations:
1. This IP belongs to a Russian ISP infrastructure (SOVINTEL-Interface-Network, ASN 3216)
2. No active threat indicators or malicious behavior detected
3. Subnet shows 0% abuse density with no threat siblings
4. DNS infrastructure includes SPF/DMARC configuration
5. One DNSBL listing detected—requires contextual analysis
6. Route stability flagged as false, indicating potential BGP changes
Recommendation: Continue monitoring. No immediate action required. If this IP appears in incident logs, investigate in context of broader attack patterns rather than as standalone threat.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | St.Peterburg internet helpdesk group |
| ASN | AS3216 |
| Network Name | SOVINTEL-Interface-Network |
| CIDR Block | 213.221.63.0/24 |
| RIR | RIPE |
| Country | RU |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | 119.spb.sovintel.ru |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 119.spb.sovintel.ru |
🔐 DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | 2/2 domains |
| DMARC | 2/2 domains |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
| Domains Checked | 2 domains |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS3216 |
| Network Prefix | 213.221.48.0/20 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-11 14:30:55 UTC |
| Last Seen | 2026-09-22 07:39:18 UTC |
| Profile Built | 2026-09-21 07:30:31 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 28 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 213.221.63.119
Who owns the IP address 213.221.63.119?
213.221.63.119 is registered to St.Peterburg internet helpdesk group. The address falls within the 213.221.63.0/24 network block. Registration is held at RIPE.
Where is 213.221.63.119 located?
Geolocation data places 213.221.63.119 in Russia. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 213.221.63.119 malicious or safe?
213.221.63.119 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 213.221.63.119?
The reverse DNS (PTR) record for 213.221.63.119 is 119.spb.sovintel.ru. This hostname is not forward-confirmed, so it should be treated as a weak signal.