# IP Intelligence Briefing: 5.175.218.27/32
## Executive Summary
IP address 5.175.218.27 presents a Low Risk profile with no active threat indicators. The IP is classified as "Firewalled / No Services" with no open ports detected. While the IP exhibits clean neighborhood characteristics, the DNS hostname "vps.darkvps.pro" warrants monitoring due to its naming convention suggesting virtual private server hosting services.
## Risk Profile
- Overall Risk Score: 0 (Low Risk)
- Provider Score: 0
- Authority Score: 0
- Stability Score: 0
- Blacklist Status: Not listed (0/8 DNSBL entries)
- Campaign Correlation: None identified
## Network Attribution & Infrastructure
- ASN: 211619
- BGP Prefix: 5.175.218.0/24
- Geolocation: Discrepant data observed
- Primary classification: US, Newark, NJ
- Historical data: Deutschland (Germany)
- This inconsistency may indicate geo-spoofing or data source variation
- DNS PTR: vps.darkvps.pro
- Forward Resolution: vps.darkvps.pro (1 record)
- Service Status: Firewalled / No Services
## Neighborhood Analysis
- Subnet: 5.175.218.0/24
- Abuse Density: 0 (Clean classification)
- Total Siblings: 2
- Active Siblings: 1 (5.175.218.19, Risk Score: 0)
- Threat Siblings: 0
- Network Stability: Route changes = 0 in last 30 days
## Historical Signals
- Observation Count: 15 signals tracked
- Recent Activity: RIR registration (RIPE), org name (GHOSTNET-MNT), DNSSEC validation active
- Threat Persistence: 0 days
- Malicious Classification: Not persistently malicious
## Relationship Mapping
- DNS Association: vps.darkvps.pro
- No organizational or subnet-level relationships identified
## Recommended Actions
No immediate blocking or mitigation actions recommended based on current risk profile. However, the following considerations apply:
1. Monitor DNS Resolution: The "darkvps" hostname pattern suggests potential VPS hosting services that may be abused by third parties
2. Watch for Geolocation Drift: Continue monitoring for inconsistencies between US and Germany classifications
3. Neighbor Correlation: Monitor sibling IP 5.175.218.19 for any changes in risk profile
## SOC Analyst Guidance
This IP currently poses minimal direct threat but should be retained on watchlists for behavioral correlation. The low risk score and clean neighborhood profile suggest this is not an active threat actor IP. Focus should be on monitoring for changes in DNS associations or geolocation consistency.
---
*Intelligence generated from IPDebrief platform data. Review should be conducted in context of broader threat intelligence and organizational security posture.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | GHOSTNET-MNT |
| ASN | AS211619 |
| Network Name | noezIplease |
| CIDR Block | 5.175.218.0/24 |
| RIR | RIPE |
| Country | DE |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | vps.darkvps.pro |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | placeholder.noez.devps.darkvps.pro |
🔐 DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | 1/2 domains |
| DMARC | 1/2 domains |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
| Domains Checked | 2 domains |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS211619 |
| Network Prefix | 5.175.218.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 42% | 2 | 6 |
| routing | 27% | 2 | 3 |
| services | 19% | 2 | 2 |
| ownership | 38% | 3 | 6 |
| reputation | 26% | 1 | 3 |
| geolocation | 35% | 2 | 3 |
| Overall | 31% | 12 | 23 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-09 19:41:13 UTC |
| Last Seen | 2026-08-30 09:07:31 UTC |
| Profile Built | 2026-08-29 07:19:49 UTC |
| Data Freshness | Live |
| Signal Types | 28 |
| Total Observations | 36 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 5.175.218.27
Who owns the IP address 5.175.218.27?
5.175.218.27 is registered to GHOSTNET-MNT. The address falls within the 5.175.218.0/24 network block. Registration is held at RIPE.
Where is 5.175.218.27 located?
Geolocation data places 5.175.218.27 in New York. The local time zone is Europe/Berlin. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 5.175.218.27 malicious or safe?
5.175.218.27 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 5.175.218.27?
The reverse DNS (PTR) record for 5.175.218.27 is vps.darkvps.pro. This hostname is not forward-confirmed, so it should be treated as a weak signal.
What ports are open on 5.175.218.27?
Responsive ports observed on 5.175.218.27 include 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.