# INTELLIGENCE BRIEFING: 95.141.17.194/32
Date: 2026-06-24
Classification: Moderate Risk / High-Abuse Context
Target IP: 95.141.17.194/32
---
## 1. OWNERSHIP & GEOGRAPHY
The target IP belongs to ASN 202596 (G.Network Administrators), registered under RIR RIPE. Geolocation data identifies the IP as located in England, City of London, GB. DNS resolution points to the hostname 95.141.17.194.g.network within the g.network domain infrastructure. Email authentication records show SPF and DMARC configurations present.
Key Attributes:
- Organization: G.Network Administrators
- Country: United Kingdom (GB)
- City: City of London
- RIR: RIPE
- CIDR Block: 95.141.17.0/24
---
## 2. RISK ASSESSMENT
Current Risk Profile:
- Overall Risk Score: 50/100 (Moderate Risk)
- Operator Score: 0.1304 (Minimal)
- Blacklist Count: 0 current listings
- Reputation Label: Moderate Risk
Control Plane Indicators:
- Route stability: Unstable (isRouteStable: false)
- DNSBL status: Listed on 1 of 8 total lists checked
- BGP prefix: 95.141.16.0/20
- Route changes (30-day): 0
---
## 3. CRITICAL CONTEXTUAL RISK: SUBNET ANALYSIS
Subnet: 95.141.17.0/24
| Metric | Value |
|---|---|
| Abuse Density | 71.09% |
| Classification | **HIGH ABUSE** |
| Total Siblings | 256 |
| Active Siblings | 121 |
| Threat Siblings | 182 |
Analysis: The target IP resides in a subnet exhibiting severe abuse characteristics. The 71% abuse density indicates that 182 of 256 addresses in this /24 have been observed with malicious activity. This contextual risk significantly elevates the threat posture beyond the IP's individual risk score of 50. Network defenders should treat all traffic from this subnet with heightened scrutiny.
---
## 4. NETWORK SERVICES & THREAT INDICATORS
Service Discovery:
- Open Ports: None detected
- TLS Certificate: Not detected
- HTTP Title: Not detected
- Service Purpose: Firewalled / No Services
Threat Indicators:
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Is Proxy: No
- Is Hosting: No
Campaign Intelligence:
- Threat Campaigns: None correlated
- Certificate Matches: 0
- Banner Matches: 0
- Correlated IPs: 0
---
## 5. OBSERVATION HISTORY
Historical Activity: 22 total observations recorded
Notable Timeline Events:
- 2026-06-24 05:55 UTC: Recent observation with minimal operator score (0.13)
- 2026-06-04 17:51 UTC: Comprehensive signal observation across 6 dimensions
- 2026-06-03 23:51 UTC: Blacklist listing detected across 8 total lists (2 active listings with high severity)
Temporal Analysis:
- Ownership changes: 0
- Threat persistence days: 0
- Threat observation count: 1
- Persistently malicious: No
---
## 6. RELATIONSHIP MAPPING
Relationships Identified: 66 total
- Primary association: UK-GNETWORK-188 network
- Multiple "Same Network" type relationships detected
- No anomalous external network associations
---
## 7. RECOMMENDATIONS FOR SOC ANALYSTS
Immediate Actions:
1. Block or Rate-Limit: Consider blocking inbound connections to this subnet (95.141.17.0/24) given the 71% abuse density
2. Monitor Outbound: Investigate any outbound connections FROM hosts on this subnet to external networks
3. Log All Traffic: Enable comprehensive logging for all traffic to/from this IP range
Network Defense Rules:
- Add to firewall blocklist: `95.141.17.0/24`
- Apply monitoring rules for traffic patterns from this subnet
- Alert on any established sessions with this IP range
Further Investigation:
- Correlate with threat intelligence feeds for active campaigns involving this ASN
- Review any historical incident logs for connections from this subnet
- Consider requesting AS path filtering from upstream providers
---
Report Generated By: IPDebrief Intelligence Platform
Data Sources: 6+ intelligence feeds, 22 historical observations, 66 relationship mappings
Classification Level: Internal Security Use Only
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | G.Network Administrators |
| ASN | AS202596 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 95.141.17.194.g.network |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 95.141.17.194.g.network |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 24% | 2 | 3 |
| reputation | 31% | 1 | 3 |
| geolocation | 30% | 2 | 3 |
| Overall | 23% | 9 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:51 UTC |
| Last Seen | 2026-06-26 18:11:50 UTC |
| Profile Built | 2026-06-26 08:24:51 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 23 |
Full dossier details are available via our API.