IPDebrief

5.167.71.249

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING

Subject: 5.167.71.249/32

Classification: Moderate Risk Residential Endpoint

Date: Current Analysis Cycle

---

## EXECUTIVE SUMMARY

IP 5.167.71.249 is a residential endpoint assigned to ER-Telecom Holding's Cheboksary branch infrastructure in Russia (AS57026). The IP presents moderate risk (score: 40) with residential network classification and DNSBL listing on 1 of 8 threat feeds. While the endpoint itself shows no active malicious indicators, it operates within a subnet exhibiting elevated abuse characteristics.

---

## OWNERSHIP & INFRASTRUCTURE

AttributeData
**ASN**57026
**Organization**Network Operation Center CJSC ER-Telecom Holding Cheboksary branch
**Geolocation**Cheboksary, Chuvash Republic, RU
**Network Role**Residential Endpoint
**DNS Record**5x167x71x249.dynamic.cheb.ertelecom.ru
**BGP Prefix**5.167.68.0/22
**Route Stability**Unstable (isRouteStable: false)

The IP is part of the ERTH-CHEB-PPPOE-22-NET network segment, indicating dynamic residential broadband infrastructure with 352 documented relationships primarily within the same network block.

---

## THREAT ASSESSMENT

Current Risk Score: 40 (Moderate Risk)

Threat Indicators:

Abuse Context:

---

## TEMPORAL ANALYSIS

Observation History (49 signals):

Recent observations (June 24, 2026) indicate consistent "Minimal" operator scores across multiple time windows (03:04, 09:12, 15:14, 21:16 UTC). The IP demonstrates no escalating threat behavior, with threat persistence days at zero and no persistent malicious classification.

Stability Metrics:

---

## NEIGHBORHOOD ANALYSIS

Subnet: 5.167.71.249/24

Abuse Density: 0.6641 (High Abuse Classification)

Sibling Statistics:

Risk Distribution (100 sampled neighbors):

Sample neighbor risk scores include 40, 25, 25, 25, 25 (authority scores: 50 across sampled neighbors).

Context: The target IP exists within a subnet exhibiting elevated abuse density. While the endpoint itself shows no active malicious indicators, 66.4% of the subnet demonstrates abuse characteristics, suggesting potential collateral risk from adjacent addresses.

---

## ACTIONABLE INTELLIGENCE

Security Recommendations:

1. Allow with Monitoring: Current data indicates residential use with no active malicious indicators. Permit traffic but monitor for behavioral anomalies.

2. Subnet Context: Be aware of elevated abuse density in 5.167.71.0/24. Consider segment-level policies if traffic patterns suggest abuse correlation.

3. DNSBL Review: Investigate which specific feed lists this IP to determine if the listing is justified or requires appeal.

4. Geographic Context: All traffic originates from Cheboksary, Russia. Consider geographic filtering policies based on organizational risk posture.

No Immediate Blocking Required: The IP demonstrates residential endpoint characteristics with no active threat indicators. Blocking would impact legitimate residential connectivity.

---

## CONCLUSION

IP 5.167.71.249/32 is classified as a moderate-risk residential endpoint operating within ER-Telecom's Cheboksary infrastructure. While the endpoint itself presents no immediate threat, the subnet context requires awareness of elevated abuse density. SOC teams should maintain monitoring rather than blocking, with attention to geographic and subnet-level risk factors.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ท๐Ÿ‡บ Russia
RegionChuvash Republic
CityCheboksary
Timezoneโ€”
Latitude55.74
Longitude37.61

๐Ÿข Ownership & Registration

OrganizationNetwork Operation Center CJSC ER-Telecom Holding Cheboksary branch
ASNAS57026
Network Nameโ€”
CIDR Blockโ€”
RIRRIPE
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR5x167x71x249.dynamic.cheb.ertelecom.ru
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnames5x167x71x249.dynamic.cheb.ertelecom.ru

๐Ÿ” DNS Hygiene

Hygiene Score60% (Good)
SPFPresent
DMARCPresent
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureResidential
Service PurposeResidential Endpoint
Network TierEnd-User โ€” Residential ISP endpoint
Residential

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Closed Ports22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
24
routing
22%
11
services
15%
22
ownership
24%
23
reputation
27%
13
geolocation
26%
23
Overall23%1016
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-07 23:05:29 UTC
Last Seen2026-06-26 18:12:19 UTC
Profile Built2026-06-27 11:18:15 UTC
Data FreshnessLive
Signal Types23
Total Observations52
๐Ÿ” 23 signal types ยท 52 observations collected
This report is generated from 23+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.