THREAT INTELLIGENCE BRIEFING
Target: 85.113.9.154/32
Classification: HIGH RISK (Risk Score: 80/100)
---
EXECUTIVE SUMMARY
IP address 85.113.9.154 is classified as HIGH RISK with a risk score of 80/100. The address is registered to KTNET (ASN 12997) in Jalalabad Area, Kyrgyzstan (KG). Despite showing no active services or open ports, the IP exhibits concerning blacklist activity with 6 out of 8 DNSBL listings flagged at HIGH severity. The IP is a static residential address with limited service footprint.
---
NETWORK OWNERSHIP & GEOLOCATION
| Attribute | Value |
|---|---|
| ASN | 12997 (KTNET-MNT) |
| Organization | KTNET-JALALABAD-AREA |
| Country | Kyrgyzstan (KG) |
| City | Bishkek |
| Network Block | 85.113.9.0/24 |
| PTR Hostname | 85-113-9-154.static.ktnet.kg |
| RIR | RIPE |
---
THREAT INDICATORS
- DNSBL Status: Listed on 6 of 8 total blacklists
- DNSBL Severity: HIGH (max severity observed)
- Blacklist Count: 6 listings
- Abuse Confidence: Not explicitly scored
- Known Attacker: No
- Tor Exit Node: No
- Spam Source: No
- Honeypot Hits: 0
---
NETWORK INFRASTRUCTURE
- Service Status: Firewalled / No Services Detected
- Open Ports: None
- TLS Certificates: None
- DNSSEC: Valid
- Operator Score: 0.1304 (Minimal)
- Route Stability: Unstable
- BGP Prefix: 85.113.0.0/20
---
OBSERVATION HISTORY
- Total Observations: 12 signals recorded
- Most Recent: 2026-07-30T23:15:06 UTC
- Signal Types: Geolocation, DNS, Routing, Reputation, Threat
- Threat Persistence: 0 days
- Ownership Changes: 0
- Threat Observation Count: 0
Recent signals show consistent geolocation validation to Bishkek, KG, with blacklist activity being the primary concern.
---
SUBNET ANALYSIS
- Subnet: 85.113.9.0/24
- Abuse Density: 0%
- Total Sibling IPs: 0 detected
- High Risk Neighbors: 0
- Threat Siblings: 0
No neighboring IPs detected in the /24 subnet.
---
RELATED ENTITIES
- Network Association: KTNET-JALALABAD-AREA
- DNS Associations: 85-113-9-154.static.ktnet.kg
- Email Authentication: SPF: Yes, DMARC: No
---
RECOMMENDED ACTIONS
Immediate (Critical):
1. Block at Perimeter: Implement blocking rules across all security devices
2. Increase Logging: Enable verbose logging for traffic from this IP
3. Review Recent Activity: Analyze logs for any recent connections or attempts
Firewall Rules Provided:
```bash
# iptables
iptables -A INPUT -s 85.113.9.154 -j DROP
# nftables
nft add rule inet filter input ip saddr 85.113.9.154 drop
# Nginx
deny 85.113.9.154;
# pfSense
85.113.9.154/32
# Cloudflare WAF
Block IP 85.113.9.154 (Risk Score: 80)
# AWS WAF
Block IP 85.113.9.154/32
```
---
ASSESSMENT
This IP represents a HIGH RISK threat primarily driven by blacklist activity despite lacking active services. The combination of DNSBL listings and HIGH severity flags warrants immediate blocking and enhanced monitoring. The IP is associated with a static residential infrastructure in Kyrgyzstan. Given the lack of active services, the threat vector may be related to historical abuse attempts, failed connection attempts, or the IP being used for reconnaissance.
Priority: BLOCK IMMEDIATELY
Severity: CRITICAL
Action Required: Perimeter blocking and log review
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | KTNET-MNT |
| ASN | AS12997 |
| Network Name | KTNET-JALALABAD-AREA |
| CIDR Block | 85.113.9.0/24 |
| RIR | RIPE |
| Country | KG |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 85-113-9-154.static.ktnet.kg |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 85-113-9-154.static.ktnet.kg |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 25% | 1 | 1 |
| Overall | 20% | 5 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-29 16:42:30 UTC |
| Last Seen | 2026-08-07 07:33:44 UTC |
| Profile Built | 2026-07-30 23:20:04 UTC |
| Data Freshness | Live |
| Signal Types | 16 |
| Total Observations | 16 |
Full dossier details are available via our API.