# IP Intelligence Briefing: 5.167.67.135/32
## Executive Summary
IP address 5.167.67.135 is classified as Moderate Risk (Score: 49) with confirmed threat indicators. The address is a residential endpoint operated by ER-Telecom Holding Cheboksary branch (ASN 57026), located in Cheboksary, Russian Federation. While not persistently malicious, the IP has been identified as a known attacker and is listed on blocklist.de. The associated /24 subnet demonstrates high abuse density, warranting monitoring.
## Ownership and Network Context
- ASN: 57026 โ Network Operation Center CJSC ER-Telecom Holding Cheboksary branch
- Organization: Network Operation Center CJSC ER-Telecom Holding Cheboksary branch
- Location: Cheboksary, Chuvash Republic, Russia (RU)
- CIDR Block: 5.167.64.0/22 (originating prefix)
- Network Classification: Residential Endpoint
- DNS Resolution: 5x167x67x135.dynamic.cheb.ertelecom.ru (dynamic residential DNS)
## Threat Indicators
- Risk Score: 49/100 (Moderate Risk)
- Known Attacker: Yes
- Blacklist Count: 1 (blocklist.de)
- DNSBL Listed: 1 of 8 total lists
- Threat Observation Count: 1
- Abuse Confidence: Confirmed malicious activity
- Tor Exit/VPN/Proxy: No
## Historical Activity
47 total observations recorded. Recent signal history (2026-06-24) shows:
- High-severity listing detected at 21:29:42 UTC with maximum severity rating
- Multiple operator score assessments returned "Minimal" (0)
- Signal confidence levels varied between 0.22 and 0.85
- No persistent malicious classification despite single threat observation
## Neighborhood Analysis (/24: 5.167.67.0/24)
- Total Siblings: 256 IPs
- Active Siblings: 178
- Abuse Density: High (1.0)
- Classification: High Abuse
- Inherited Risk: 40
- Risk Distribution: Medium: 70, Low: 30, High: 0
## Network Relationships
320 relationship entities identified, primarily:
- Same network associations to ERT-HEB-CHEB-PPPOE-22-NET
- No cross-organizational or cross-network correlations observed
## Recommended Actions
1. Monitor: Track for additional threat indicators and activity patterns
2. Blocklist Consideration: Evaluate blocking based on organization's risk tolerance (risk score 49/100)
3. Network-Level Filtering: Consider subnet-wide policies for 5.167.67.0/24 due to high abuse density
4. Geographic Context: Russian residential IP โ standard for consumer broadband traffic but elevated risk profile
## Intelligence Notes
The IP exhibits characteristics of compromised residential infrastructure. While individual threat activity is not persistent, the subnet-level abuse density suggests coordinated or opportunistic abuse patterns. Recommend correlation with other indicators for confirmed threat attribution before implementing blocking measures.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Network Operation Center CJSC ER-Telecom Holding Cheboksary branch |
| ASN | AS57026 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 5x167x67x135.dynamic.cheb.ertelecom.ru |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 5x167x67x135.dynamic.cheb.ertelecom.ru |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Residential |
| Service Purpose | Residential Endpoint |
| Network Tier | End-User โ Residential ISP endpoint |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 3 | 3 |
| routing | 20% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 20% | 2 | 3 |
| reputation | 34% | 2 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 24% | 11 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:05:24 UTC |
| Last Seen | 2026-06-26 18:12:14 UTC |
| Profile Built | 2026-06-27 05:36:47 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 49 |
Full dossier details are available via our API.