IPDebrief

85.96.189.27

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

Threat Intelligence Briefing: IP 85.96.189.27/32

Entity Profile:

Observation History:

Relationships:

Neighborhood Data:

Conclusion:

The IP address 85.96.189.27/32 is primarily associated with legitimate web hosting activities, with no direct evidence of malicious behavior. While it is situated in a region known for cyber activity, the specific IP does not show connections to known threat actors or infrastructure. SOC teams should continue monitoring traffic patterns for any anomalies, particularly focusing on any new domains or changes in network behavior. Regular updates to threat intelligence databases are recommended to ensure any emerging threats associated with this IP are quickly identified.

Recommendations:

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡น๐Ÿ‡ท Turkey
RegionBursa Province
CityYฤฑldฤฑrฤฑm
TimezoneEurope/Istanbul
Latitude40.33
Longitude29.56

๐Ÿข Ownership & Registration

OrganizationAS9121-MNT
ASNAS9121
Network Nameโ€”
CIDR Blockโ€”
RIRRIPE
Countryโ€”
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR85.96.189.27.dynamic.ttnet.com.tr
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnames85.96.189.27.dynamic.ttnet.com.tr

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureMobile
Service PurposeWeb Server
Network TierUnknown โ€” Insufficient routing data to classify
Mobile

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
443httpstcpโ€”
22sshtcp
Closed Ports25, 80, 3389, 8080, 8443 (2 open / 7 scanned)
Serverโ€”
HTTP Titleโ€”
SSH VersionSSH-2.0-dropbear_2022.83 ? ??L???? ???(%?curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-n

๐Ÿ” TLS Certificate

A self-signed certificate was detected. This is common for development servers, internal services, or IoT devices.
โš ๏ธ
CN=XWEB PRO, OU=Dixell, O=Emerson Electric Co., L=Belluno, S=Veneto, C=IT
Issued by CN=XWEB PRO, OU=Dixell, O=Emerson Electric Co., L=Belluno, S=Veneto, C=IT
Self-signed: Yes
SANsNone
Valid From2026-04-03T02:00:53+00:00
Valid Until2026-09-30T02:00:53+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period180 days
Serial Number5D5E5CB0A2710437463C09144FF15E6D191A77B3
Thumbprint7E19A266DCFD9C9507A800DF77611D426B69E32A

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
35%
23
routing
13%
11
services
13%
11
ownership
27%
23
reputation
13%
12
geolocation
19%
22
Overall20%912
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceMixed Signals (53%) โ€” 3 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  High authority score (70) but appears on threat lists (risk 70)
โš  Geo sources disagree on country: IT, TR
โš  TLS certificate claims IT but primary geo says TR

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-05-14 13:25:31 UTC
Last Seen2026-06-26 02:15:49 UTC
Profile Built2026-06-24 07:36:29 UTC
Data FreshnessLive
Signal Types20
Total Observations20
๐Ÿ” 20 signal types ยท 20 observations collected
This report is generated from 20+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.