# IP Intelligence Briefing: 5.167.71.215
## Executive Summary
IP address 5.167.71.215 is a residential endpoint originating from ER-Telecom Holding Cheboksary branch (ASN 57026) in Cheboksary, Russia. The IP carries a moderate risk score of 40 and operates within a subnet exhibiting high abuse density (0.6641), with 170 of 256 total sibling IPs flagged as threats.
## Technical Profile
- IP Address: 5.167.71.215/32
- Risk Score: 40 (Moderate Risk)
- ASN: 57026
- Organization: Network Operation Center CJSC ER-Telecom Holding Cheboksary branch
- Geolocation: Russia, Chuvash Republic, Cheboksary
- Network Role: Residential Endpoint
- DNS Resolution: 5x167x71x215.dynamic.cheb.ertelecom.ru (ertelecom.ru)
- Connection Type: Residential (not proxy, CDN, VPN, or Tor)
## Threat Intelligence
- Current Threat Indicators: None detected in threat profile
- Blacklist Status: 0 blacklist listings
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Campaign Correlation: 0 correlated IPs
## Neighborhood Analysis
The IP resides in subnet 5.167.71.215/24, which shows:
- Abuse Density: 0.6641 (High Abuse Classification)
- Active Siblings: 188 of 256 IPs
- Threat Siblings: 170 flagged as threats
- Inherited Risk Score: 26
Neighbor risk distribution: 41 medium-risk, 59 low-risk, 0 high-risk siblings. This suggests the subnet contains a significant proportion of potentially compromised or misconfigured residential endpoints.
## Historical Observations
49 signal observations recorded. Key temporal indicators:
- Recent Abuse Density Fluctuation: Observed values range from 0.3438 to 0.6641
- Subnet Classification: Varied between "mixed" and "high_abuse"
- Ownership Stability: No ownership changes detected
- Threat Persistence: 0 days (not persistently malicious)
## Network Relationships
356 relationships identified, predominantly "Same Network" associations to ERT H-CHEB-PPPOE-22-NET network segment.
## Recommended Actions
Based on risk profile, the following firewall rules are recommended:
```bash
# iptables
iptables -A INPUT -s 5.167.71.215 -j DROP
# nftables
nft add rule inet filter input ip saddr 5.167.71.215 drop
# Cloudflare WAF
filter: ip.src eq 5.167.71.215
# AWS WAF
Addresses: ["5.167.71.215/32"]
```
## Risk Assessment
This IP is classified as Moderate Risk (40). The primary concern stems from the high-abuse environment of its /24 subnet. While the IP itself shows no active malicious indicators, the neighborhood context suggests elevated risk of compromise or abuse. SOC analysts should monitor traffic patterns and consider blocking if the IP initiates connections to internal assets.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Network Operation Center CJSC ER-Telecom Holding Cheboksary branch |
| ASN | AS57026 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 5x167x71x215.dynamic.cheb.ertelecom.ru |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 5x167x71x215.dynamic.cheb.ertelecom.ru |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Residential |
| Service Purpose | Residential Endpoint |
| Network Tier | End-User โ Residential ISP endpoint |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 31% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 30% | 1 | 3 |
| geolocation | 26% | 2 | 3 |
| Overall | 23% | 10 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:05:29 UTC |
| Last Seen | 2026-06-26 18:12:18 UTC |
| Profile Built | 2026-06-27 11:21:40 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 51 |
Full dossier details are available via our API.