# IP Intelligence Briefing: 5.167.71.145
Classification: Moderate Risk Residential Endpoint
Date: 2026-06-25
Analyst: IPDebrief Intelligence
---
## Executive Summary
IP 5.167.71.145 is a residential endpoint in Cheboksary, Chuvash Republic, Russia, operating under ER-Telecom Holding ASN 57026. The IP presents a moderate risk profile (score: 40) with no active threat indicators, but operates within a high-abuse-density subnet environment. No malicious campaigns or blacklisting detected.
---
## Ownership & Network Context
| Attribute | Value |
|---|---|
| **ASN** | 57026 |
| **Organization** | Network Operation Center CJSC ER-Telecom Holding Cheboksary branch |
| **Country** | Russian Federation (RU) |
| **Region** | Chuvash Republic |
| **City** | Cheboksary |
| **CIDR Block** | 5.167.68.0/22 (BGP prefix) |
| **Network Type** | Residential PPPoE |
The IP belongs to ERTH-CHEB-PPPOE-22-NET, a large residential subscriber network with 409+ related connections identified in the relationship graph.
---
## Risk Profile
- Overall Risk Score: 40 (Moderate Risk)
- Abuse Confidence Score: Not available
- Threat Indicators: None detected
- Blacklist Status: 0 blacklists
- Known Attacker: No
- Spam Source: No
- Tor Exit: No
---
## Neighborhood Analysis
Subnet: 5.167.71.0/24
| Metric | Value |
|---|---|
| Total Siblings | 256 |
| Active Siblings | 160 |
| Threat Siblings | 256 |
| Abuse Density | High |
| Inherited Risk | 40 |
Risk distribution across monitored neighbors:
- High Risk: 0
- Medium Risk: 41
- Low Risk: 59
The subnet exhibits elevated abuse density despite the target IP having no direct threat indicators. This contextual risk warrants enhanced monitoring.
---
## Technical Observations
DNS Resolution:
- PTR: 5x167x71x145.dynamic.cheb.ertelecom.ru
- Forward Resolution: Confirmed (1 hostname)
- Email Auth: SPF and DMARC records present
Services:
- Open Ports: None detected
- TLS Certificates: None
- HTTP Services: None
Control Plane:
- Route Stability: Stable (5,435+ days)
- RPKI State: Unknown
- DNSBL Listings: 1 of 8 total lists
---
## Historical Analysis
- Total Observations: 58
- Threat Persistence: No persistent malicious activity detected
- Recent Signals (June 2026):
- Geolocation: RU (52% confidence)
- CAA/FrDNS: Minimal labels
- Operator Score: 0
No escalation in threat profile observed over recent observation period.
---
## Recommended Actions
Firewall/Blocking:
- Recommendation: Monitor rather than block
- Rationale: Moderate risk score with no direct threat indicators
- Context: Consider subnet-level awareness due to high-abuse-density classification
Monitoring Priority: Medium
- No immediate blocking required
- Enhanced logging recommended for outbound traffic patterns
- Monitor for any changes in threat indicators
---
## Conclusion
IP 5.167.71.145 represents a legitimate residential endpoint with moderate contextual risk stemming from its subnet environment. No evidence of active malicious use. Recommend monitoring with awareness of elevated neighborhood abuse density, but no immediate defensive actions required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Network Operation Center CJSC ER-Telecom Holding Cheboksary branch |
| ASN | AS57026 |
| Network Name | โ |
| CIDR Block | 5.167.68.0/22 |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 5x167x71x145.dynamic.cheb.ertelecom.ru |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 5x167x71x145.dynamic.cheb.ertelecom.ru |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Residential |
| Service Purpose | Residential Endpoint |
| Network Tier | End-User โ Residential ISP endpoint |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 4 |
| routing | 25% | 3 | 4 |
| services | 17% | 2 | 3 |
| ownership | 24% | 3 | 4 |
| reputation | 30% | 1 | 3 |
| geolocation | 28% | 2 | 3 |
| Overall | 25% | 13 | 21 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:05:28 UTC |
| Last Seen | 2026-06-26 18:12:18 UTC |
| Profile Built | 2026-06-27 11:23:57 UTC |
| Data Freshness | Live |
| Signal Types | 30 |
| Total Observations | 60 |
Full dossier details are available via our API.