# IP Intelligence Briefing: 5.167.65.239/32
## Executive Summary
IP 5.167.65.239 is a residential endpoint assigned to ER-Telecom Holding CJSC (Cheboksary branch, Russia). The IP carries a moderate risk score of 40 and is associated with a high-abuse density subnet. No active threat indicators or blacklisting were observed. The IP is classified as residential with dynamic DNS hosting under ertelecom.ru.
## Ownership and Geolocation
- ASN: 57026 (ERT-Telecom Holding CJSC Cheboksary branch)
- Organization: Network Operation Center CJSC ER-Telecom Holding Cheboksary branch
- Location: Cheboksary, Chuvash Republic, RU (5000km accuracy radius)
- Registration: RIR RIPE
- IP Block: 5.167.64.0/20 (BGP prefix)
## Network Classification and Services
- Role: Residential endpoint (not cloud, CDN, VPN, proxy, or hosting)
- DNS: 5x167x65x239.dynamic.cheb.ertelecom.ru (dynamic residential DNS)
- Open Ports: None detected
- TLS/HTTP: No certificates or web services observed
- Email Auth: SPF and DMARC records present for domain
## Risk Assessment
- Overall Risk Score: 40 (Moderate)
- Provider Score: 0
- Authority Score: 0
- DNSBL Listings: 1 of 8 lists
- Control Plane: Route stability flagged as unstable; RPKI state not evaluated
## Subnet Analysis (5.167.65.0/24)
- Classification: High abuse density
- Abuse Density Score: 1.0 (normalized)
- Active Siblings: 124 out of 256 IPs
- Risk Distribution: 37 medium-risk, 63 low-risk neighbors
- Inherited Risk: 40 (matching subject IP)
## Historical Observations
Analysis of 50 signal observations reveals:
- Recent observations show mixed abuse classification with 120 threat siblings in the subnet
- Geolocation inference points to Russia with 52% confidence
- Operator score remains at 0 (Minimal) across multiple observations
- No persistent malicious activity detected; threat persistence days = 0
## Related Entities
- Network Relationships: 328 relationships detected, primarily to ERTH-CHEB-PPPOE-22-NET
- Same Network: Multiple instances of ERTH-CHEB-PPPOE-22-NET network association
- Campaign Correlation: No certificate or banner matches; zero correlated IPs
## Recommended Actions
Low Priority Monitoring
- The IP shows moderate risk with no active threat indicators
- Residential classification with dynamic DNS suggests legitimate home use
- Monitor for changes in risk score or emergence of threat indicators
Defensive Considerations
- Subnet-level abuse density warrants awareness of lateral threat potential
- Route instability in control plane may indicate transient routing anomalies
- No immediate blocking required; standard residential endpoint handling
## Conclusion
5.167.65.239 is a residential Russian IP with moderate risk characteristics. While the subnet exhibits elevated abuse density, this specific IP shows no active malicious indicators. Recommend standard residential endpoint monitoring without immediate blocking or escalation.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Network Operation Center CJSC ER-Telecom Holding Cheboksary branch |
| ASN | AS57026 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 5x167x65x239.dynamic.cheb.ertelecom.ru |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 5x167x65x239.dynamic.cheb.ertelecom.ru |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Residential |
| Service Purpose | Residential Endpoint |
| Network Tier | End-User โ Residential ISP endpoint |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 2 | 3 |
| routing | 20% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 30% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 24% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:05:22 UTC |
| Last Seen | 2026-06-26 18:12:12 UTC |
| Profile Built | 2026-06-27 06:09:50 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 50 |
Full dossier details are available via our API.