# IP Intelligence Briefing: 213.233.104.181/32
Briefing Date: 2026-07-28
Classification: Low Risk
Analyst: IPDebrief Intelligence
## Executive Summary
The target IP address 213.233.104.181/32 presents a low-risk security posture with a risk score of 25/100. The IP is classified as "clean" with no active threat indicators, no open services, and no known malicious associations. The subnet demonstrates minimal abuse density with zero threat-identified siblings.
## Network Classification
The IP is associated with control plane data linking it to ASN 12302 and BGP prefix 213.233.104.0/24. Network role assessment indicates the IP is "Firewalled / No Services" with no detected open ports, TLS certificates, or HTTP services. The route stability assessment shows the BGP route is not stable, and the IP is not a MoAS (Multi-Origin Autonomous System).
## Geolocation Data
Geolocation intelligence places the IP in Bucharest, Romania (Country Code: RO, Continent: EU). However, geo-validation validation returned false with zero probe count, indicating insufficient data points to confirm location accuracy. The consensus geo-data is not considered plausible by the system.
## Threat Assessment
Threat indicators returned no malicious indicators. The IP is not classified as a Tor exit node, known attacker, spam source, or proxy service. Blacklist analysis shows one DNSBL listing out of eight total lists checked. Abuse confidence score remained null across the assessment cycle. No known malware campaigns were correlated with this IP.
## Reputation Metrics
- Risk Score: 25 (Low Risk)
- Provider Score: 0
- Authority Score: 0
- Stability Score: 0
- Operator Score: 0.1304 (Label: Minimal)
- DNSBL Listed Count: 1
## Historical Observations
Nine signal observations were recorded across the observation period. Key observations include:
- Geolocation signals consistently mapped to Bucharest, Romania with 70% confidence
- Subnet classification remained "clean" with 0 abuse density and 0 inherited risk
- One DNSBL listing event was recorded with "high" severity classification
- Risk persistence assessment returned 0 days, indicating no persistent malicious behavior
## Neighborhood Analysis
Subnet analysis for 213.233.104.181/24 returned:
- Abuse Density: 0
- Classification: Clean
- Total Siblings: 1
- Active Siblings: 0
- Threat Siblings: 0
No neighboring IPs were identified within the subnet. Risk distribution across the neighborhood shows no high or medium risk classifications.
## Relationship Graph
The relationship analysis returned zero relationships, indicating no detected associations with related entities such as subnets, hostnames, organizations, or certificates.
## Recommended Actions
Based on the risk profile assessment, no specific firewall rules or blocking actions are recommended at this time. The IP presents no actionable threat indicators requiring immediate defensive measures.
Status: Monitor - No Action Required
Confidence Level: Low (0.125 overall confidence score)
Last Updated: 2026-07-28
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | AS12302-MNT |
| ASN | AS12302 |
| Network Name | MOBIFON |
| CIDR Block | 213.233.104.0/24 |
| RIR | RIPE |
| Country | RO |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS12302 |
| Network Prefix | 213.233.104.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-16 22:52:15 UTC |
| Last Seen | 2026-09-01 00:00:47 UTC |
| Profile Built | 2026-08-30 19:05:06 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 17 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 213.233.104.181
Who owns the IP address 213.233.104.181?
213.233.104.181 is registered to AS12302-MNT. The address falls within the 213.233.104.0/24 network block. Registration is held at RIPE.
Where is 213.233.104.181 located?
Geolocation data places 213.233.104.181 in Bucharest, Bucharest, Romania. The local time zone is Europe/Bucharest. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 213.233.104.181 malicious or safe?
213.233.104.181 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.