# INTELLIGENCE BRIEFING: IP 76.13.242.184
Classification: LOW RISK - DEFENSIVE MONITORING ONLY
Date: Current Analysis
Analyst: SOC Intelligence Division
---
## EXECUTIVE SUMMARY
IP 76.13.242.184 presents as a low-risk infrastructure endpoint associated with Hostinger NOC hosting services. Analysis of the full profile, observation history, relationships, and neighborhood data indicates no active threat indicators. The IP shows minimal risk characteristics suitable for standard monitoring protocols without immediate blocking or escalation requirements.
---
## NETWORK IDENTIFICATION
| Attribute | Value |
|---|---|
| **IP Address** | 76.13.242.184/32 |
| **ASN** | 47583 |
| **Organization** | Hostinger NOC |
| **Network** | HOSTINGER-HOSTING (76.13.240.0/21) |
| **RIR** | ARIN |
| **Geolocation** | Mumbai, Maharashtra, India (IN) |
| **Risk Score** | 25/100 (LOW RISK) |
| **Reputation** | Low Risk |
---
## OBSERVATION HISTORY
Fourteen signal observations recorded across recent monitoring cycles (2026-07-30). Key observations include:
- Infrastructure Type: Consistently classified as ColocationHosting/Hosting infrastructure
- Network Classification: Is hosting infrastructure; not identified as CDN, VPN, proxy, or Tor exit
- Geolocation Signals: Primary consensus indicates Mumbai, India. Historical signals show geolocation variations with Lithuania referencesโcommon in hosting infrastructure where ASN-level registration differs from operational deployment
- Control Plane: DNSSEC validation active; CAA records present; DNSBL listings: 1 of 8 total lists (minor concern)
No threat persistence patterns detected. Ownership stability maintained with zero ownership changes observed.
---
## RELATIONSHIP ANALYSIS
Four relationship entities identified:
- DNS Association: srv1401208.hstgr.cloud (primary hostname)
- Network Association: HOSTINGER-HOSTING network block
- No certificate or campaign correlations detected
- No correlated malicious IPs identified
---
## NEIGHBORHOOD ANALYSIS
Subnet analysis for 76.13.242.0/24:
- Total Siblings: 0 detected
- Active Siblings: 0
- Threat Siblings: 0
- Abuse Density: 0%
- Risk Distribution: No high or medium risk neighbors identified
The /24 subnet shows no adjacent threat indicators.
---
## THREAT INDICATORS
Negative Findings:
- No known attacker indicators
- No spam source classification
- No Tor exit node status
- Zero blacklist hits at time of analysis
- No active threat feeds matches
- No known campaign associations
Services:
- No open ports detected
- No TLS certificates or HTTP services active
- Infrastructure appears firewalled with no accessible services
---
## SECURITY ACTIONS & RECOMMENDATIONS
Based on risk assessment (score: 25), no immediate firewall rules or blocking actions are recommended. The IP presents as legitimate hosting infrastructure with low-risk characteristics.
Recommended Monitoring:
- Standard network logging
- Include in passive DNS monitoring
- No action required for this endpoint
Priority: LOW โ Continue routine monitoring
---
## INTELLIGENCE CONCLUSIONS
IP 76.13.242.184 is classified as legitimate hosting infrastructure with low-risk profile. The absence of threat indicators, open services, and malicious indicators supports classification as benign. The single DNSBL listing (1 of 8) represents a minor concern but does not warrant action given the overall low-risk score and lack of corroborating threat signals.
Recommendation: Maintain standard monitoring protocols. No blocking, quarantining, or escalation required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Hostinger NOC |
| ASN | AS47583 |
| Network Name | HOSTINGER-HOSTING |
| CIDR Block | 76.13.240.0/21 |
| RIR | ARIN |
| Country | IN |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | srv1401208.hstgr.cloud |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | srv1401208.hstgr.cloud |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-29 10:34:37 UTC |
| Last Seen | 2026-07-31 05:28:48 UTC |
| Profile Built | 2026-07-30 22:20:26 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 20 |
Full dossier details are available via our API.