# IP INTELLIGENCE BRIEFING
IP Address: 5.167.64.98
Classification: Residential Endpoint
Report Date: 2026-06-24
---
## EXECUTIVE SUMMARY
IP 5.167.64.98 is a residential endpoint associated with ER-Telecom Holding (Cheboksary branch, Russia). The IP carries a risk score of 49 (Moderate Risk) and is flagged as a known attacker on threat feeds including blocklist.de. The IP belongs to subnet 5.167.64.0/22, which exhibits high abuse density (0.6094) with 156 out of 256 active siblings flagged as threats.
---
## OWNERSHIP & GEOLOCATION
- Organization: Network Operation Center CJSC ER-Telecom Holding Cheboksary branch
- ASN: 57026
- RIR: RIPE
- Location: Cheboksary, Chuvash Republic, Russia
- CIDR Block: 5.167.64.0/22
- Network Classification: Residential PPPoE endpoint
---
## THREAT INDICATORS
| Indicator | Status |
|---|---|
| Is Known Attacker | **YES** |
| Is Tor Exit Node | NO |
| Is Proxy/VPN | NO |
| Blacklist Count | 1 (blocklist.de) |
| DNSBL Listed | 1 of 8 lists |
| ISP Risk Score | 0.3043 (Basic) |
---
## NETWORK CONTEXT
Subnet Analysis (5.167.64.0/24):
- Abuse Density: 0.6094 (High)
- Active Siblings: 219 of 256
- Threat Siblings: 156
- Risk Distribution: 40% Medium, 60% Low
BGP Routing:
- Origin ASN: 57026
- BGP Prefix: 5.167.64.0/22
- Route Stability: Stable (no changes in 30 days)
- RPKI State: Validated
---
## OBSERVATION HISTORY
Total Observations: 52 signals over monitoring period
- Recent Activity: Multiple observations (2026-06-24) showing "Minimal" routing signals
- Threat Persistence: 0 days (transient threat behavior)
- Pattern: No escalating threat trends observed
---
## RELATED ENTITIES
Network Relationships:
- Primary network: ERTH-CHEB-PPPOE-22-NET
- DNS Hostname: 5x167x64x98.dynamic.cheb.ertelecom.ru
- Total Relationships: 294 (primarily internal network associations)
---
## RECOMMENDED ACTIONS
Priority: HIGH
1. Network Edge: Block or rate-limit this IP at the perimeter
2. DNS: No additional DNS-based actions required (forward resolution confirmed)
3. Monitoring: Track for continued activity given high-subnet abuse density
Recommended Firewall Rules:
```bash
# iptables
iptables -A INPUT -s 5.167.64.98 -j DROP
# nftables
nft add rule inet filter input ip saddr 5.167.64.98 drop
# Cloudflare WAF
action: block
filter: ip.src eq 5.167.64.98
```
---
## INTELLIGENCE JUDGMENT
This IP represents a moderate-risk residential endpoint operating within a high-abuse-density subnet. While not exhibiting persistent malicious behavior, the presence on threat feeds and the subnet's abuse profile warrant defensive blocking. The IP appears to be used for legitimate residential purposes but has been associated with attacker activity on threat intelligence platforms.
Recommended Handling: Block with monitoring for 30 days to assess if IP recovers to benign status.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Network Operation Center CJSC ER-Telecom Holding Cheboksary branch |
| ASN | AS57026 |
| Network Name | โ |
| CIDR Block | 5.167.64.0/22 |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 5x167x64x98.dynamic.cheb.ertelecom.ru |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 5x167x64x98.dynamic.cheb.ertelecom.ru |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Residential |
| Service Purpose | Residential Endpoint |
| Network Tier | End-User โ Residential ISP endpoint |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 34% | 3 | 4 |
| routing | 31% | 2 | 3 |
| services | 12% | 2 | 2 |
| ownership | 24% | 3 | 4 |
| reputation | 34% | 2 | 3 |
| geolocation | 28% | 2 | 3 |
| Overall | 27% | 14 | 19 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:05:15 UTC |
| Last Seen | 2026-06-26 18:12:11 UTC |
| Profile Built | 2026-06-27 06:45:41 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 55 |
Full dossier details are available via our API.