IPDebrief

85.244.8.67

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

Intelligence Briefing for IP 85.244.8.67/32

Summary:

The IP address 85.244.8.67/32, located in Russia, has been associated with suspicious activity and potential cybersecurity threats. The following analysis provides a comprehensive profile based on observed data, highlighting key aspects of its activity, relationships, and surrounding network environment.

Geolocation and Ownership:

Activity and Observation History:

Relationships and Network Associations:

Neighborhood Data:

Risk Assessment:

Actionable Recommendations:

1. Blocklist the IP: Add 85.244.8.67/32 to security device blocklists to prevent access and mitigate risk.

2. Enhance Monitoring: Implement enhanced monitoring for traffic patterns indicative of command and control or data exfiltration activities.

3. Incident Response Preparation: Prepare incident response protocols for potential phishing or malware incidents linked to this IP.

4. User Awareness Training: Educate users on recognizing phishing attempts and the importance of reporting suspicious activity.

This intelligence briefing is intended to support SOC analysts in understanding the threat landscape associated with 85.244.8.67/32 and to inform proactive defensive measures.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ต๐Ÿ‡น Portugal
RegionLisbon
CityPenedo
TimezoneEurope/Lisbon
Latitude39.40
Longitude-8.22

๐Ÿข Ownership & Registration

OrganizationTELEPAC-MNT
ASNAS3243
Network Nameโ€”
CIDR Block85.240.0.0/13
RIRRIPE
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRbl11-8-67.dsl.telepac.pt
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamesbl11-8-67.dsl.telepac.pt

๐Ÿ” DNS Hygiene

Hygiene Score60% (Good)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAAPresent

โ˜๏ธ Network Classification

InfrastructureMobile
Service PurposeWeb Server
Network TierUnknown โ€” Insufficient routing data to classify
Mobile

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
443httpstcpโ€”
22sshtcp
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
ServerApache
HTTP Titleโ€”
SSH VersionSSH-2.0-OpenSSH_5.0

๐Ÿ” TLS Certificate

An expired certificate for CN=device5451588-e5925155.wd2go.com was found on this IP. This may indicate a previously hosted website, a decommissioned service, or stale infrastructure.
๐Ÿ”’
CN=device5451588-e5925155.wd2go.com
Issued by CN=Sectigo RSA Domain Validation Secure Server CA, O=Sectigo Limited, L=Salford, S=Greater Manchester, C=GB
Self-signed: No
SANsdevice5451588-e5925155.wd2go.comdevice5451588-e5925155-local.wd2go.com
Valid From2021-12-25T00:00:00+00:00
Valid Until2022-12-25T23:59:59+00:00 (expired)
TLS ProtocolTls12
Cipher SuiteTLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period365 days
Serial Number00A300F314F86CE42CA29B23AD4DC831DB
Thumbprint2B444CB2117763151C49D805884993E3AB6B1477

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
38%
25
routing
32%
23
services
30%
23
ownership
29%
34
reputation
24%
13
geolocation
21%
22
Overall29%1220
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-07 23:04:38 UTC
Last Seen2026-06-26 18:11:39 UTC
Profile Built2026-06-26 08:29:15 UTC
Data FreshnessLive
Signal Types25
Total Observations26
๐Ÿ” 25 signal types ยท 26 observations collected
This report is generated from 25+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.