# IP Intelligence Briefing: 5.167.67.171/32
## Executive Summary
IP address 5.167.67.171 is classified as a Known Attacker with a risk score of 49 (Moderate Risk). The address is associated with ER-Telecom Holding Cheboksary branch (ASN 57026) and is located in Cheboksary, Russia. The IP exhibits threat indicators including listing on blocklist.de and multiple DNSBL entries. Neighborhood analysis reveals high abuse density within the /24 subnet.
## Technical Profile
- Risk Score: 49 (Moderate)
- ASN: 57026
- Organization: Network Operation Center CJSC ER-Telecom Holding Cheboksary branch
- Country: RU (Russia)
- City: Cheboksary, Chuvash Republic
- Network Role: Residential Endpoint
- Network Classification: Known Attacker (isKnownAttacker: true)
## Threat Indicators
- Listed on blocklist.de
- DNSBL Listed: 2 of 8 total lists
- Operator Score: 0.1304 (Minimal)
- BGP Prefix: 5.167.64.0/22
- RPKI State: Not available
- Route Stability: False (0 route changes in 30 days)
## Geolocation & Validation
- Coordinates: Cheboksary, Russia
- Distance from Source: 2,035.6 km
- GeoValidation: GeoPlausible: true; ICMP blocked - unable to validate
- Timezone: Local (Cheboksary)
## Neighborhood Analysis (/24 Subnet: 5.167.67.0/24)
- Abuse Density: High (density: 1)
- Total Siblings: 256
- Active Siblings: 178
- Threat Siblings: 256 (all siblings showing threat activity)
- Inherited Risk: 40
- Risk Distribution: High: 0, Medium: 70, Low: 30
The entire /24 subnet demonstrates pervasive threat activity, with all 256 sibling IPs flagged as threat actors. This indicates either a compromised residential gateway or coordinated abuse pattern.
## Network Relationships
- 351 relationships identified
- Primary association: ERTH-CHEB-PPPOE-22-NET (PPPoE network)
- Multiple network-level relationships to same organizational subnet
## Observation History
- Total Observations: 45
- Recent Activity: Multiple listings and categorization events recorded
- Signal Types: Blacklist listings, operator score assessments, network classification signals
- Temporal Persistence: Threat observation count: 1; Not persistently malicious
## Recommended Actions
Primary Recommendation: Block or rate-limit this IP at the network edge due to suspicious activity indicators.
Firewall Rules:
- iptables: `iptables -A INPUT -s 5.167.67.171 -j DROP`
- nftables: `nft add rule inet filter input ip saddr 5.167.67.171 drop`
- nginx: `deny 5.167.67.171;`
- pfSense: `5.167.67.171/32`
- Cloudflare WAF: Block IP with expression `ip.src eq 5.167.67.171`
- AWS WAF: Add `5.167.67.171/32` to web ACL
## SOC Analyst Notes
The IP is classified as a known attacker with moderate risk. Given the high abuse density of the entire /24 subnet (5.167.67.0/24), consideration should be given to implementing subnet-level blocking or aggressive rate-limiting policies. The IP is residential in origin, which may indicate either compromised home broadband or a botnet distributed across residential connections. No active services or open ports were detected. Historical data shows multiple blacklist listings and consistent threat classification. Immediate blocking is recommended pending correlation with additional threat intelligence.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Network Operation Center CJSC ER-Telecom Holding Cheboksary branch |
| ASN | AS57026 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 5x167x67x171.dynamic.cheb.ertelecom.ru |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 5x167x67x171.dynamic.cheb.ertelecom.ru |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Residential |
| Service Purpose | Residential Endpoint |
| Network Tier | End-User โ Residential ISP endpoint |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 3 | 3 |
| routing | 20% | 1 | 1 |
| services | 20% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 34% | 2 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 27% | 12 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:05:24 UTC |
| Last Seen | 2026-06-26 18:12:14 UTC |
| Profile Built | 2026-06-27 05:34:27 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 49 |
Full dossier details are available via our API.