# IP Intelligence Briefing: 31.172.85.162/32
Classification: Low Risk | Risk Score: 25/100 | Date: 2026-07-27
## Executive Summary
IP 31.172.85.162 is a German infrastructure address (ASN 44066) classified as Low Risk. The IP is currently firewalled with no active services and shows no persistent malicious behavior. However, the /24 subnet contains one threat-adjacent sibling IP, warranting monitoring of related addresses in the 31.172.85.0/24 block.
## Technical Profile
| Attribute | Value |
|---|---|
| **Network** | 31.172.80.0/20 (DE-ACCELERATED-20110401) |
| **Organization** | ACCELERATED-MNT |
| **ASN** | 44066 (RIPE) |
| **Geolocation** | Germany (51.17°N, 10.45°E) |
| **Infrastructure Type** | Firewalled / No Services |
| **DNSBL Status** | 1/8 lists flagged |
| **Abuse Confidence** | Low |
## Threat Indicators
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Known Campaigns: None
- Blacklist Count: 1
- Threat Persistence: 0 days
- Ownership Changes: 0 (stable)
## Network Neighborhood (31.172.85.0/24)
- Subnet Classification: Mostly Clean
- Abuse Density: Low
- Active Siblings: 0
- Threat Siblings: 1 (monitor recommended)
- Total Siblings: 1
## Observations & Behavior
- Total Observations: 16 signals
- Recent Activity: Single threat observation recorded
- Network Role: Infrastructure (firewalled)
- Connection Type: No services exposed
- Route Stability: Unstable (false)
## Recommended Actions
1. Monitor: Track the single threat sibling in the 31.172.85.0/24 subnet for potential lateral activity
2. Allow: No blocking required for 31.172.85.162 based on current risk profile
3. Review: Periodically scan the /24 block for emerging threats given the threat sibling presence
4. Baseline: No immediate firewall rules required; IP is not actively malicious
## Intelligence Assessment
The IP address represents a stable, low-risk infrastructure node within a German hosting block. The primary concern is the presence of a threat-adjacent neighbor in the same /24 subnet. No immediate defensive action is warranted for this specific IP, but ongoing monitoring of the 31.172.85.0/24 block is recommended.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | ACCELERATED-MNT |
| ASN | AS44066 |
| Network Name | DE-ACCELERATED-20110401 |
| CIDR Block | 31.172.80.0/20 |
| RIR | RIPE |
| Country | DE |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS44066 |
| Network Prefix | 31.172.85.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 0% | 0 | 0 |
| services | 0% | 0 | 0 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 8% | 2 | 2 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-15 10:09:07 UTC |
| Last Seen | 2026-09-03 19:44:21 UTC |
| Profile Built | 2026-08-29 13:09:44 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 21 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 31.172.85.162
Who owns the IP address 31.172.85.162?
31.172.85.162 is registered to ACCELERATED-MNT. The address falls within the 31.172.80.0/20 network block. Registration is held at RIPE.
Where is 31.172.85.162 located?
Geolocation data places 31.172.85.162 in Newark. The local time zone is Europe/Berlin. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 31.172.85.162 malicious or safe?
31.172.85.162 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 31.172.85.162?
Responsive ports observed on 31.172.85.162 include 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.