IP INTELLIGENCE BRIEFING
Target IP: 5.167.66.12/32
Date: Current Analysis Cycle
Classification: Moderate Risk / Known Attacker
---
EXECUTIVE SUMMARY
IP address 5.167.66.12 is a residential endpoint assigned to ER-Telecom Holding's Cheboksary branch network (ASN 57026). The IP has been flagged as a known attacker and is listed on 1 blocklist (blocklist.de). Risk assessment indicates moderate threat potential (score: 49) with residential network classification and elevated neighborhood abuse density.
---
NETWORK OWNERSHIP & GEOLOCATION
- Organization: Network Operation Center CJSC ER-Telecom Holding Cheboksary branch
- ASN: 57026
- Country: RU (Russia)
- City: Cheboksary
- RIR: RIPE
- CIDR Block: 5.167.64.0/22 (BGP origin)
- DNS PTR: 5x167x66x12.dynamic.cheb.ertelecom.ru
---
THREAT INTELLIGENCE
- Risk Score: 49 (Moderate Risk)
- Status: Known Attacker (True)
- Blocklist Count: 1 (blocklist.de)
- Network Classification: Residential Endpoint
- Tor Exit: No
- Spam Source: No
- VPS/Proxy/CDN: Not classified as any infrastructure type
Control Plane Data:
- Route stability: Unstable (false)
- RPKI State: Not evaluated
- DNSSEC: Valid
- DNSBL Listings: 1 of 8 total lists
---
NEIGHBORHOOD ANALYSIS (5.167.66.0/24)
- Subnet Classification: High Abuse
- Inherited Risk Score: 40
- Total Siblings: 256
- Active Siblings: 134
- Abuse Density: 1 (elevated)
- Neighbor Risk Distribution: 100 medium risk IPs observed
- Sample neighboring IPs (5.167.66.0โ5.167.66.5) show consistent risk scores between 40โ49
---
RELATIONSHIP GRAPH
- Total Relationships: 325 entities
- Primary Association: ERTHER-CHEB-PPPOE-22-NET (residential PPPoE network segment)
- Multiple related network and infrastructure entities identified
---
OBSERVATION HISTORY
- Total Observations: 49 signals recorded
- Latest Observation: 2026-06-24 20:26 UTC
- Confidence Range: 0.22โ0.95
- Recent Signals:
- Geolocation inference: Russia, Cheboksary (confidence: 0.52)
- Threat indicators: Multiple Pulse signals detected (confidence: 0.95)
- Operator score: Minimal (0)
- Routing/signal analysis: 14 total dimensions covered
---
RECOMMENDED ACTIONS
Severity: HIGH
Network Edge Action: Block or rate-limit this IP address
Firewall Rules:
- `iptables`: `iptables -A INPUT -s 5.167.66.12 -j DROP`
- `nftables`: `nft add rule inet filter input ip saddr 5.167.66.12 drop`
- `nginx`: `deny 5.167.66.12;`
- `pfSense`: `5.167.66.12/32`
- `Cloudflare WAF`: Block with expression `ip.src eq 5.167.66.12`
- `AWS WAF`: Block address 5.167.66.12/32
---
SOC ANALYST NOTES
This IP represents a residential endpoint from a Russian ISP with known malicious activity indicators. The moderate risk score combined with "known attacker" classification warrants blocking at network boundaries. The subnet (5.167.66.0/24) exhibits high abuse density, suggesting systemic residential network compromise potential. Correlate with any observed connection attempts, port scans, or data exfiltration patterns from this IP or neighboring addresses.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Network Operation Center CJSC ER-Telecom Holding Cheboksary branch |
| ASN | AS57026 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 5x167x66x12.dynamic.cheb.ertelecom.ru |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 5x167x66x12.dynamic.cheb.ertelecom.ru |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Residential |
| Service Purpose | Residential Endpoint |
| Network Tier | End-User โ Residential ISP endpoint |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 3 | 4 |
| routing | 20% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 34% | 2 | 3 |
| geolocation | 28% | 2 | 3 |
| Overall | 23% | 12 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:05:22 UTC |
| Last Seen | 2026-06-26 18:12:12 UTC |
| Profile Built | 2026-06-27 06:07:29 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 51 |
Full dossier details are available via our API.