# IP Intelligence Briefing: 31.56.146.239/32
Classification: Low Risk | Risk Score: 0 | Analysis Date: 2026-07-28
---
## Executive Summary
IP address 31.56.146.239 exhibits low-risk characteristics with no active threat indicators. The address belongs to Farhad Soltani's CloudBackbone network (ASN 56971) within RIPE registry. No malicious activity, blacklist presence, or campaign associations detected. Recommended operational posture: Monitor with standard logging.
---
## Network Ownership & Infrastructure
- ASN: 56971
- Organization: Farhad Soltani
- Network Name: CloudBackbone
- CIDR Block: 31.56.146.0/24
- RIR: RIPE
- Service Purpose: Firewalled / No Services
---
## Geolocation Assessment
- Primary Location: Paris, France (99.9% confidence)
- Secondary Location: New York, US (Geo consensus: false)
- Region: Île-de-France
- Operator Score: Minimal (0.1304)
- Route Stability: Stable (0 route changes in 30 days)
*Note: Geolocation data shows discrepancy between primary and secondary sources; monitor for consistency.*
---
## Threat Indicators
- Blacklist Count: 0
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Abuse Confidence Score: Not applicable
- Campaign Associations: None detected
- Certificate Matches: 0
- Banner Matches: 0
---
## Network Behavior
- Open Ports: None detected
- DNS Resolution: Forward resolution count: 0
- Hosted Domains: 0
- Email Auth: SPF/DMARC not configured
- Honeypot Hits: 0
- Enumeration Strikes: 0
- WAF Violations: 0
---
## Neighborhood Analysis
- Subnet: 31.56.146.0/24
- Abuse Density: 0
- Total Siblings: 0
- Threat Siblings: 0
- High/Medium/Low Risk IPs: 0/0/0
---
## Control Plane & Routing
- BGP Prefix: 31.56.146.0/24
- Origin ASN: 56971
- Route Changes (30d): 0
- RPKI State: Not evaluated
- DNSSEC Valid: True
- DNSBL Listings: 0/8 total lists
---
## Observation History
Total Signals Observed: 13
Analysis Period: 2026-07-28
Recent signals indicate:
- Organization attribution (confidence: 0.90)
- Geolocation data from multiple sources (confidence: 0.70)
- Infrastructure classification (confidence: 0.30)
- Operator score assessment (confidence: 0.30)
Temporal Indicators: No persistent malicious activity detected. No ownership changes observed.
---
## Recommended Actions
- Monitoring: Standard logging recommended
- Firewall Rules: No specific rules required
- Threat Response: No action required at this time
- Investigation Priority: Low
---
## Key Observations
1. No evidence of malicious activity or abuse
2. No blacklist associations detected
3. No open services or ports exposed
4. Geoconsensus requires validation (US vs France)
5. Subnet shows zero abuse density
Conclusion: IP 31.56.146.239 presents a benign threat profile. Standard network monitoring practices are sufficient. No immediate security actions required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Farhad Soltani |
| ASN | AS56971 |
| Network Name | CloudBackbone |
| CIDR Block | 31.56.146.0/24 |
| RIR | RIPE |
| Country | FR |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | — |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS56971 |
| Network Prefix | 31.56.146.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 13% | 1 | 2 |
| routing | 8% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 17% | 2 | 3 |
| reputation | 8% | 1 | 1 |
| geolocation | 31% | 2 | 3 |
| Overall | 14% | 8 | 11 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-15 22:24:02 UTC |
| Last Seen | 2026-09-11 09:45:02 UTC |
| Profile Built | 2026-09-11 09:45:10 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 29 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 31.56.146.239
Who owns the IP address 31.56.146.239?
31.56.146.239 is registered to Farhad Soltani. The address falls within the 31.56.146.0/24 network block. Registration is held at RIPE.
Where is 31.56.146.239 located?
Geolocation data places 31.56.146.239 in New York, US-NY, United States. The local time zone is America/New_York. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 31.56.146.239 malicious or safe?
31.56.146.239 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 31.56.146.239?
Responsive ports observed on 31.56.146.239 include 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.