# IP Intelligence Briefing: 217.78.189.180/32
Classification: Low Risk | Date: 2026-07-26
---
## Executive Summary
IP address 217.78.189.180 presents a low-risk profile with a risk score of 25. The address is geolocated to Russia and is associated with the koptevo.net domain infrastructure. While a single DNSBL listing was observed, no active threat campaigns or malicious services were detected. The IP appears to be a residential or static endpoint with firewall protection enabled.
---
## Technical Profile
Network Attribution:
- ASN: 30833
- BGP Prefix: 217.78.176.0/20
- Route Stability: Unstable (route changes detected)
- Origin ASN: 30833
Geolocation:
- Country: Russia (RU)
- Region: Moscow
- Coordinates: 55.7487° N, 37.6187° E
- Geo Confidence: Medium to Low (multiple geolocation sources with varying confidence)
DNS Intelligence:
- PTR Record: 217-78-189-180.pool.koptevo.net
- Forward Resolution: 217-78-189-180.pool.koptevo.net
- Domain Authority: koptevo.net
- DNSSEC Valid: Yes
- Forward Resolution Confirmed: No
Service Profile:
- Open Ports: None detected
- Service Purpose: Firewalled / No Services
- HTTP/HTTPS: No active web services
- TLS Certificate: Not configured
---
## Threat Indicators
Risk Assessment:
- Overall Risk Score: 25 (Low Risk)
- Abuse Confidence Score: Not available
- Threat Feeds: No active threat indicators
- Known Campaigns: None detected
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Blacklist Status:
- DNSBL Listings: 1 of 8 total lists
- Max Severity: High
- Listing Categories: Not specified
---
## Observation History
Recent Activity (12 Observations):
- Last Observed: 2026-07-26T20:55:49 UTC
- Geolocation Signals: Multiple Russia-based geolocation probes (Moscow, RU)
- Operator Score: 0.1304 (Minimal operator risk)
- Threat Persistence: 0 days (not persistently malicious)
- Threat Observation Count: 0
Temporal Analysis:
- Ownership Changes: 0
- Average Ownership Duration: Not available
- Threat Persistence: Absent
---
## Network Relationships
Associated Entities:
- DNS Hostname: 217-78-189-180.pool.koptevo.net
- Relationship Type: DNS Association
Subnet Analysis (217.78.189.0/24):
- Total Siblings: 0
- Active Siblings: 0
- Threat Siblings: 0
- Abuse Density: 0 (clean subnet)
- Subnet Classification: Not classified
---
## Recommended Actions
Immediate Actions:
- No specific firewall or blocking recommendations at this time
- Monitor for service activation or configuration changes
Long-term Considerations:
- The DNSBL listing warrants periodic review
- Route instability should be tracked for potential infrastructure changes
- Consider geolocation-based filtering if Russia traffic is restricted per policy
---
## Intelligence Assessment
The IP address 217.78.189.180 represents a low-risk endpoint with no evidence of active malicious activity. The DNSBL listing indicates a historical or policy-based block but does not correlate with current threat behavior. The absence of open services, combined with the firewall configuration, suggests this address functions as a passive endpoint rather than an active attack vector.
Threat Level: LOW
Recommended Action: Monitor; no immediate blocking required.
---
*Report generated by IPDebrief Intelligence Platform. Data sourced from multiple threat intelligence feeds and network analysis tools.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Michael Osnitskiy |
| ASN | AS30833 |
| Network Name | TNC-NET |
| CIDR Block | 217.78.184.0/22 |
| RIR | RIPE |
| Country | RU |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | 217-78-189-180.pool.koptevo.net |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 217-78-189-180.pool.koptevo.net |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS30833 |
| Network Prefix | 217.78.176.0/20 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-11 14:30:56 UTC |
| Last Seen | 2026-09-02 15:47:05 UTC |
| Profile Built | 2026-09-02 16:01:37 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 23 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 217.78.189.180
Who owns the IP address 217.78.189.180?
217.78.189.180 is registered to Michael Osnitskiy. The address falls within the 217.78.184.0/22 network block. Registration is held at RIPE.
Where is 217.78.189.180 located?
Geolocation data places 217.78.189.180 in Moscow, MOW, Russia. The local time zone is Europe/Moscow. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 217.78.189.180 malicious or safe?
217.78.189.180 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 217.78.189.180?
The reverse DNS (PTR) record for 217.78.189.180 is 217-78-189-180.pool.koptevo.net. This hostname is not forward-confirmed, so it should be treated as a weak signal.