# IP Intelligence Briefing: 46.236.180.130
## Executive Summary
IP address 46.236.180.130 was classified as a Moderate Risk endpoint (risk score: 50). The address is a residential IP assigned to ER-Telecom Holding's Bryansk branch network (AS57044). Analysis revealed no active threat indicators, no blacklist presence, and minimal DNSBL associations (2 out of 8 lists). The IP was observed without persistent malicious activity.
## Ownership and Network Attribution
- Organization: Network Operation Center CJSC ER-Telecom Holding Bryansk branch
- Netname: ERTH-BRYANSK-NET
- ASN: AS57044
- CIDR Block: 46.236.176.0/20
- Geolocation: Bryansk, Bryansk Oblast, Russia (RU)
- Network Role: Residential Endpoint
## Threat Assessment
The IP exhibited Moderate Risk characteristics with no specific threat indicators detected:
- Blacklist Status: 0 blacklists, minimal DNSBL listings (2/8)
- Known Campaigns: None identified
- Tor Exit/Proxy/VPN: Not detected
- Spam Source: Not classified
- Known Attacker: Not flagged
## Service and Port Analysis
No services were detected on the IP during observation:
- Open Ports: None
- TLS Certificates: None
- HTTP Services: None
- Server Banner: None
## DNS Resolution
The IP resolved to a dynamic residential hostname:
- PTR Record: 46x236x180x130.dynamic.bryansk.ertelecom.ru
- Domain: ertelecom.ru
- Forward Resolution: Confirmed
- Forward Hostnames: 46x236x180x130.dynamic.bryansk.ertelecom.ru
- Email Auth: SPF and DMARC records present
## Historical Observation Analysis
Seventeen observations were recorded over the monitoring period. Key temporal findings:
- Geolocation Consistency: Primary signals placed the IP in Bryansk, Russia (confidence: 0.70-0.85). Some conflicting signals from Tomsk, Russia (confidence: 0.50) appeared in minority observations.
- Threat Persistence: No persistent malicious activity detected (threat observation count: 0)
- Ownership Stability: No ownership changes recorded
- Signal Types: Port scans and geolocation inference signals observed
## Neighborhood Context
Analysis of the /24 subnet (46.236.180.130/24):
- Abuse Density: 0 (no abuse activity in adjacent IPs)
- Neighbor Count: 0 detected
- Risk Distribution: No high/medium/low risk neighbors identified
- Subnet Classification: Not inherited
## Relationship Graph
Six relationships were identified:
- Network Relationships: Three entries linking to ERTH-BRYANSK-NET
- DNS Associations: Three entries linking to the dynamic hostname
## Recommended Actions
Given the moderate risk classification and residential nature, the following recommendations apply:
- Block Decision: Monitor or block based on organizational policy for residential IPs
- Firewall Rules: Consider rate limiting or geo-blocking from Russia if policy permits
- Traffic Analysis: Monitor for outbound connections to known C2 infrastructure
- Investigation Priority: Low-Medium (no active threats detected)
## Conclusion
IP 46.236.180.130 represents a residential endpoint on ER-Telecom Holding's Bryansk network with moderate risk scoring. No active threats, malware, or command-and-control activity were observed. The IP shows stable ownership and no persistent malicious behavior. SOC analysts should monitor based on organizational policy for residential IP traffic from Russian networks, but immediate blocking is not warranted absent specific threat intelligence.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Network Operation Center CJSC ER-Telecom Holding Bryansk branch |
| ASN | AS57044 |
| Network Name | ERTH-BRYANSK-NET |
| CIDR Block | 46.236.176.0/20 |
| RIR | RIPE |
| Country | RU |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 46x236x180x130.dynamic.bryansk.ertelecom.ru |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 46x236x180x130.dynamic.bryansk.ertelecom.ru |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Residential |
| Service Purpose | Residential Endpoint |
| Network Tier | End-User โ Residential ISP endpoint |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-28 22:22:34 UTC |
| Last Seen | 2026-07-30 19:16:55 UTC |
| Profile Built | 2026-07-30 19:26:26 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 21 |
Full dossier details are available via our API.