THREAT INTELLIGENCE BRIEFING: 95.141.17.75/32
Classification: Moderate Risk | Date: 2026-06-24 | Source: IPDebrief Intelligence Platform
---
## EXECUTIVE SUMMARY
IP address 95.141.17.75 is a UK-based infrastructure endpoint with moderate risk score (50/100). The IP belongs to G.Network Administrators (ASN 202596) and is hosted in the City of London. While the IP itself shows no active threat indicators, it resides within a subnet exhibiting high abuse density (0.6914), suggesting proximity to malicious activity. The endpoint is currently firewalled with no open services detected.
---
## OWNERSHIP & NETWORK ATTRIBUTES
| Attribute | Value |
|---|---|
| **IP Address** | 95.141.17.75/32 |
| **ASN** | 202596 |
| **Organization** | G.Network Administrators |
| **Country** | United Kingdom (GB) |
| **Geolocation** | England, City of London |
| **RIR** | RIPE |
| **BGP Prefix** | 95.141.16.0/20 |
| **Service Purpose** | Firewalled / No Services |
---
## THREAT PROFILE
Current Risk Score: 50 (Moderate)
Threat Indicators: None detected
- No known attacker attribution
- Not identified as spam source
- Not a Tor exit node
- No associated threat campaigns
DNS Reputation:
- PTR Record: 95.141.17.75.g.network
- Domain: g.network
- SPF/DMARC: Configured
- DNSBL Listings: 2 of 8 checked lists
---
## NEIGHBORHOOD ANALYSIS
Subnet: 95.141.17.75/24
- Abuse Density: 0.6914 (High)
- Classification: high_abuse
- Total Siblings: 256
- Active Siblings: 99
- Threat Siblings: 177
The endpoint operates within a /24 subnet showing significant abuse concentration. 177 of 99 active siblings have been flagged as threats, indicating this subnet may be associated with coordinated or shared infrastructure.
---
## OBSERVATION HISTORY
Total Observations: 19
Recent Activity:
- 2026-06-24: Reputation signals (Minimal risk), routing, services, ownership, geolocation assessments
- 2026-06-03: Services scanning confirmed no open ports
- 2026-06-03: Geolocation inference confirmed GB location
Temporal Analysis:
- Ownership stability: Stable (0 changes)
- Threat persistence: 0 days
- Persistently malicious: False
---
## SECURITY RECOMMENDATIONS
Based on risk profile and neighborhood context, the following defensive measures are recommended:
| Platform | Recommended Action |
|---|---|
| **iptables** | `iptables -A INPUT -s 95.141.17.75 -j DROP` |
| **nftables** | `nft add rule inet filter input ip saddr 95.141.17.75 drop` |
| **nginx** | `deny 95.141.17.75;` |
| **pfSense** | `95.141.17.75/32` (block rule) |
| **Cloudflare WAF** | Block with expression: `ip.src eq 95.141.17.75` |
| **AWS WAF** | Add `95.141.17.75/32` to whitelist/blacklist rule |
---
## INTELLIGENCE CONTEXT
Network Relationships: 53 relationships identified, primarily same-network associations with UK-GNETWORK-188.
Risk Assessment: The moderate risk score is elevated by the subnet's high abuse density. While the endpoint itself shows no active malicious behavior, the neighborhood context suggests it may be part of broader infrastructure that warrants monitoring.
Operational Note: No services detected on this IP. The endpoint appears to be in a non-service state or actively firewalled at the network level.
---
Report Generated: IPDebrief Intelligence Platform
Data Currency: Real-time as of 2026-06-24
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | G.Network Administrators |
| ASN | AS202596 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 95.141.17.75.g.network |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 95.141.17.75.g.network |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 19% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 24% | 2 | 3 |
| Overall | 17% | 10 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:50 UTC |
| Last Seen | 2026-06-26 18:11:50 UTC |
| Profile Built | 2026-06-24 05:43:57 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 22 |
Full dossier details are available via our API.