# INTELLIGENCE BRIEFING: 5.167.71.112
Classification: Moderate Risk | Report Date: June 24, 2026
## Executive Summary
IP 5.167.71.112 is a residential endpoint in Cheboksary, Russia (ASN 57026, ER-Telecom Holding) exhibiting moderate risk characteristics (score: 49). The address is flagged as a known attacker and appears on one blacklist (blocklist.de). While the IP itself shows minimal persistent threat activity, it operates within a high-abuse subnet (5.167.71.0/24) with 151 active siblings and elevated abuse density.
## Technical Profile
Ownership & Geolocation:
- ASN: 57026 | Org: Network Operation Center CJSC ER-Telecom Holding Cheboksary branch
- Location: Cheboksary, Chuvash Republic, RU
- Network: 5.167.68.0/22 (BGP stable, route changes: 0 in 30d)
- Connection Type: Residential (PPPoE)
Network Classification:
- Role: Residential Endpoint (not proxy/VPN/CDN)
- DNS: 5x167x71x112.dynamic.cheb.ertelecom.ru
- Email Auth: SPF enabled, DMARC present
- Service Status: No open ports or TLS certificates observed
## Threat Indicators
- Risk Score: 49/100 (Moderate)
- Known Attacker: Yes
- Blacklist Status: 1 listing (blocklist.de)
- DNSBL Listed: 1 of 8 total lists
- Threat Feeds: Empty
- Campaign Association: None detected
## Neighborhood Analysis (5.167.71.0/24)
- Total Siblings: 256 addresses
- Active Siblings: 151
- Abuse Density: High (classification: high_abuse)
- Subnet Risk Distribution: 0 high-risk, 41 medium-risk, 59 low-risk
- Inherited Risk: 40/100
Neighbor IPs consistently show moderate risk scores (25-40 range), indicating this subnet is under active operational monitoring.
## Observation History
- Total Observations: 55 signals
- Recent Activity: Minimal threat indicators across June 24, 2026 timeframe
- Threat Persistence: 0 days (no persistent malicious activity detected)
- Temporal Trend: Stable low-level signals with no escalation pattern
## Recommended Actions
Immediate:
- Monitor inbound/outbound traffic for DDoS, spam, or botnet activity
- Implement rate limiting on residential endpoints from this subnet
- Blocklist IP on outbound connections if organization policy prohibits residential traffic
Network Security:
- Add to monitoring queue for anomalous connection patterns
- Review firewall rules for 5.167.71.0/24 subnet traffic
- Consider blocking at perimeter if residential access is not authorized
Contextual Note: This IP appears to be a standard residential endpoint within a high-abuse subnet. While the IP itself shows minimal current threat activity, the neighborhood context warrants continued monitoring for coordinated malicious activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Network Operation Center CJSC ER-Telecom Holding Cheboksary branch |
| ASN | AS57026 |
| Network Name | โ |
| CIDR Block | 5.167.68.0/22 |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 5x167x71x112.dynamic.cheb.ertelecom.ru |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 5x167x71x112.dynamic.cheb.ertelecom.ru |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Residential |
| Service Purpose | Residential Endpoint |
| Network Tier | End-User โ Residential ISP endpoint |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 28% | 3 | 4 |
| routing | 25% | 2 | 3 |
| services | 20% | 2 | 3 |
| ownership | 24% | 3 | 4 |
| reputation | 34% | 2 | 3 |
| geolocation | 28% | 2 | 3 |
| Overall | 26% | 14 | 20 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:05:28 UTC |
| Last Seen | 2026-06-26 18:12:18 UTC |
| Profile Built | 2026-06-27 13:12:38 UTC |
| Data Freshness | Live |
| Signal Types | 28 |
| Total Observations | 57 |
Full dossier details are available via our API.