IPDebrief

5.167.71.28

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING: 5.167.71.28/32

Date: 2026-06-25

Classification: Moderate Risk - Residential Endpoint

Intel Confidence: 85%

---

## EXECUTIVE SUMMARY

IP 5.167.71.28 is a residential endpoint associated with ER-Telecom Holding's Cheboksary infrastructure in Russia. The address carries a risk score of 40, indicating moderate risk. While no active threat indicators or malicious campaigns were detected, the IP belongs to a /24 subnet classified as high abuse with 107 active sibling addresses. No immediate blocking required unless specific threat behavior is observed.

---

## NETWORK IDENTIFICATION

AttributeValue
**IP Address**5.167.71.28/32
**ASN**57026
**Organization**Network Operation Center CJSC ER-Telecom Holding Cheboksary branch
**Country**Russia (RU)
**Region**Chuvash Republic
**City**Cheboksary
**Network Type**Residential Endpoint (PPPoE)
**CIDR Block**5.167.64.0/20

---

## THREAT ASSESSMENT

Current Risk Score: 40 (Moderate)

Operator Score: 0.1304 (Minimal)

Abuse Confidence Score: Not available

Threat Indicators: None detected

Blacklist Status: 0 blacklist hits (1 DNSBL listing out of 8 total lists)

Known Campaigns: None

Tor Exit Node: No

Known Attacker: No

Spam Source: No

---

## NETWORK BEHAVIOR & CLASSIFICATION

---

## SUBNET ANALYSIS (5.167.71.0/24)

MetricValue
**Total Siblings**256
**Active Siblings**107
**Abuse Density**1 (High Abuse)
**Risk Distribution**100 Medium, 0 High, 0 Low
**Subnet Classification**high_abuse
**Inherited Risk**40

Assessment: The /24 subnet shows elevated abuse density with 107 active endpoints. Consistent risk scores of 40 across sibling addresses indicate systematic network-level risk rather than isolated endpoint behavior.

---

## OBSERVATION HISTORY (48 Total Signals)

Recent Activity Timeline:

Temporal Analysis:

---

## RELATIONSHIP GRAPH

Total Relationships: 315

Primary Association: ERT-H-CHEB-PPPOE-22-NET (Same Network)

The IP maintains extensive relationships within the ER-Telecom Cheboksary PPPoE network infrastructure.

---

## RECOMMENDED ACTIONS

Current Risk Level: Moderate (40)

Recommended Action: Monitor - No immediate block required

Firewall Rules (if blocking warranted):

```bash

# iptables

iptables -A INPUT -s 5.167.71.28 -j DROP

# nftables

nft add rule inet filter input ip saddr 5.167.71.28 drop

# nginx

deny 5.167.71.28;

# pfSense

5.167.71.28/32

# Cloudflare WAF

{"description":"Block 5.167.71.28 โ€” IPDebrief risk score 40","action":"block"}

# AWS WAF

{"Addresses":["5.167.71.28/32"],"Description":"IPDebrief risk 40"}

```

---

## INTELLIGENCE NOTES FOR SOC ANALYSTS

1. Residential Nature: This is a standard residential PPPoE endpoint from a major Russian ISP. False positive risk is elevated without additional threat signals.

2. Subnet Context: The /24 subnet shows high abuse density. If this IP exhibits malicious behavior, related IPs in the same subnet may warrant investigation.

3. No Active Threats: No malware, scanning, or abuse indicators detected in current profile.

4. Geolocation Verification: Geo validation showed ICMP blocked (unable to validate). Distance calculated: 2631.2 km from probe location.

5. Monitoring Recommendation: Track for any emergence of threat indicators. If abuse is observed, consider blocking the /24 or /20 prefix rather than individual IPs.

---

Source: IPDebrief Intelligence Platform

Data Freshness: 2026-06-25

Analysis Status: Complete

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ท๐Ÿ‡บ Russia
RegionChuvash Republic
CityCheboksary
Timezoneโ€”
Latitude55.74
Longitude37.61

๐Ÿข Ownership & Registration

OrganizationNetwork Operation Center CJSC ER-Telecom Holding Cheboksary branch
ASNAS57026
Network Nameโ€”
CIDR Blockโ€”
RIRRIPE
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR5x167x71x28.dynamic.cheb.ertelecom.ru
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnames5x167x71x28.dynamic.cheb.ertelecom.ru

๐Ÿ” DNS Hygiene

Hygiene Score60% (Good)
SPFPresent
DMARCPresent
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureResidential
Service PurposeResidential Endpoint
Network TierEnd-User โ€” Residential ISP endpoint
Residential

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
28%
23
routing
20%
11
services
8%
11
ownership
20%
23
reputation
30%
13
geolocation
28%
23
Overall22%914
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (50%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-07 23:05:28 UTC
Last Seen2026-06-26 18:12:18 UTC
Profile Built2026-06-27 11:34:11 UTC
Data FreshnessLive
Signal Types21
Total Observations50
๐Ÿ” 21 signal types ยท 50 observations collected
This report is generated from 21+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.