IP Intelligence Briefing: 46.175.185.90
Date: 2026-06-13
---
**1. Risk Profile**
- Overall Risk: Moderate (Risk Score: 55)
- Provider: BELNET LTD (ASN 44800)
- Geolocation: Odesa, Ukraine (UA)
- Threat Indicators: No malicious activity detected (no indicators, blacklists, or campaigns).
---
**2. Network & Services**
- Network Role: Multi-service host (HTTP, SSH).
- Services:
- HTTP (Port 80): Lighttpd/1.4.39 server, 302 redirect.
- SSH (Port 22): Dropbear SSH server.
- DNS: No PTR records or email auth configurations.
- TLS: No certificates detected.
---
**3. Historical Observations**
- Recent Activity (2026-06-13):
- HTTP service with Lighttpd banner.
- 302 redirect detected.
- Past Activity (2026-06-03):
- Subnet abuse density: 0.5 (mostly clean).
- DNSBL listings: 3 out of 8 total lists (moderate risk).
---
**4. Neighborhood Analysis**
- Subnet: 46.175.185.90/24
- Abuse Density: 1 (high risk due to one malicious neighbor).
- Neighbors:
- 46.175.185.48: Risk Score 80 (high risk).
---
**5. Relationships**
- Network: Linked to BELNET-ISP1 (same provider).
- No Hostnames/Domains: No DNS or email auth records.
---
**6. Recommendations**
- Monitor Subnet: The subnet has a high abuse density due to the neighbor (46.175.185.48).
- Investigate Neighbor: Focus on the high-risk neighbor IP for potential threats.
- Baseline Behavior: The IP itself shows no malicious activity but should be monitored for anomalies.
---
Conclusion: This IP is part of a network with mixed risk. While the IP itself is not malicious, its subnet contains a high-risk neighbor. SOC teams should prioritize monitoring the subnet and investigate the neighbor further.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | BELNET LTD |
| ASN | AS44800 |
| Network Name | β |
| CIDR Block | β |
| RIR | RIPE |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Multi-Service Host |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 22 | ssh | tcp | |
| Closed Ports | 25, 443, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | lighttpd/1.4.39 |
| HTTP Title | β |
| SSH Version | SSH-2.0-dropbear <?/?????L??[n?D?curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-grou |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 29% | 2 | 3 |
| ownership | 24% | 2 | 3 |
| reputation | 15% | 1 | 2 |
| geolocation | 21% | 2 | 2 |
| Overall | 22% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:22 UTC |
| Last Seen | 2026-06-23 14:18:18 UTC |
| Profile Built | 2026-06-23 14:29:10 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 21 |
Full dossier details are available via our API.