# IPDebrief Intelligence Briefing
IP Address: 65.111.26.145/32
Briefing Date: 2026-07-31
Classification: Moderate Risk
## Executive Summary
IP 65.111.26.145 presents a moderate risk profile (risk score: 65/100) with no active malicious indicators. The IP is classified as a single-service host with an open SSH port showing "Exceeded MaxStartups" banner. While not flagged as a known attacker or spam source, the IP appears on multiple DNSBLs (3/8 total lists), suggesting potential reputation issues.
## Ownership and Network Context
- ASN: 200373
- Organization: lir-de-3xktechgmbh-1-MNT
- Network Name: DE-3XKTECHGMBH-20170616
- CIDR Block: 65.111.0.0/19
- RIR: ARIN
The IP belongs to a German-registered network (DE) with geolocation data indicating coordinates near 51.17°N, 10.45°E with 400km accuracy radius. Route stability is marked as false, indicating potential routing changes.
## Threat Assessment
Current Risk Indicators:
- Risk Score: 65/100 (Moderate Risk)
- Abuse Confidence Score: Not assigned
- Blacklist Count: 3 DNSBL listings
- Known Campaigns: None
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
Network Role: Single-Service Host
Open Services:
- Port 22/tcp (SSH) - Banner: "Exceeded MaxStartups"
## Neighborhood Analysis (65.111.26.0/24)
The /24 subnet contains 16 total sibling IPs with the following risk distribution:
- High Risk: 0 IPs
- Medium Risk: 7 IPs
- Low Risk: 8 IPs
- Abuse Density: 0 (classified as "clean")
Notable high-risk neighbors within the same subnet:
- 65.111.26.128 (risk score: 65)
- 65.111.26.197 (risk score: 65)
- Multiple IPs with risk score: 40
## Temporal Analysis
Observation History: 16 observations recorded
- Most recent: 2026-07-31T04:11:31 UTC
- Threat Persistence Days: 0
- Is Persistently Malicious: False
- Ownership Changes: 0
Recent observations include port scanning activity and geolocation inference signals with RTT averaging 107.2ms.
## Network Classification
- Provider: None
- Infrastructure Type: None
- Cloud Service: No
- CDN: No
- VPN: No
- Proxy: No
- Hosting: No
- Mobile/Residential: No
- Bogon: No
- Anycast: No
## Control Plane Intelligence
- Origin ASN: 200373
- BGP Prefix: 65.111.26.0/24
- RPKI State: Not available
- Route Changes (30d): 0
- IS Route Stable: False
- DNSSEC Valid: True
- DNSBL Listed Count: 3
- DNSBL Total Lists: 8
- Operator Score: 0.1304 (Minimal)
## Recommended Security Actions
Immediate Recommendations
Category: Monitoring
- Action: Increase logging verbosity and review recent activity from this IP
- Severity: High
- Reason: Elevated risk score (65/100)
Firewall Rules
iptables:
```bash
iptables -A INPUT -s 65.111.26.145 -j DROP
```
nftables:
```bash
nft add rule inet filter input ip saddr 65.111.26.145 drop
```
nginx:
```nginx
deny 65.111.26.145;
```
pfSense:
```
65.111.26.145/32
```
Cloudflare WAF:
```json
{"description":"Block 65.111.26.145 โ IPDebrief risk score 65","action":"block","filter":{"expression":"ip.src eq 65.111.26.145"}}
```
AWS WAF:
```json
{"Addresses":["65.111.26.145/32"],"Description":"IPDebrief risk 65"}
```
## Intelligence Assessment
IP 65.111.26.145 represents a moderate-risk address with no confirmed malicious activity but notable DNSBL listings and route instability. The open SSH port with "Exceeded MaxStartups" banner indicates potential SSH brute-force targeting or misconfiguration. The subnet shows mixed risk profiles with no high-risk concentrations, suggesting this IP's elevated score may be isolated.
Action Priority: MEDIUM
Recommended Mitigation: Block or monitor based on organizational threat tolerance
Verification Required: Confirm activity patterns before implementing blocking rules
---
*This intelligence briefing is based on data from IPDebrief threat intelligence platform. All recommendations should be validated against internal security policies and corroborated with additional threat intelligence sources.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | lir-de-3xktechgmbh-1-MNT |
| ASN | AS200373 |
| Network Name | DE-3XKTECHGMBH-20170616 |
| CIDR Block | 65.111.0.0/19 |
| RIR | ARIN |
| Country | DE |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 22 | ssh | tcp | |
| Closed Ports | 25, 80, 443, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 0% | 0 | 0 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-30 17:12:31 UTC |
| Last Seen | 2026-08-01 10:25:37 UTC |
| Profile Built | 2026-07-31 04:21:27 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 20 |
Full dossier details are available via our API.