Intelligence Briefing: 95.156.102.194/32
Summary
The IP address 95.156.102.194/32 was assessed with a Moderate Risk reputation (Score: 50) and classified as a Suspicious Host. The address is associated with ASN 12389 (Krasnoyarsk Computer Network/Rostelecom-net) and geolocated to Ilanskiy, Krasnoyarsk Krai, Russia.
Network Characteristics
Network analysis indicated the address was assigned to a mobile carrier, specifically Tele2 RU, and was observed in a firewalled state with no active services or open ports. DNS records were forward confirmed to mail.orion-atc.ru and gate.orion-atc.ru, with SPF and DMARC policies present. The address was listed on 2 DNSBLs out of 8 total lists monitored.
Timeline and Activity
Activity was observed starting 2026-08-29T16:32:16Z and continuing through 2026-09-07T08:46:25Z. Attribution confidence was Moderate (70%).
Threat Assessment and Recommendation
Despite low behavioral activity metrics in specific incident counts, the overall risk assessment was elevated due to multiple threat signals. The recommended action is Block with High Severity.
Mitigation Rules
The following firewall rules were applied based on the risk assessment:
* iptables: `iptables -A INPUT -s {ip} -j DROP`
* nginx: `deny {ip};`
* pf: `block in quick on egress from {ip}`
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Krasnoyarsk Computer Network |
| ASN | AS12389 |
| Network Name | Rostelecom-net |
| CIDR Block | 95.156.101.0/24 |
| RIR | RIPE |
| Country | RU |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | mail.orion-atc.ru |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | mail.orion-atc.rugate.orion-atc.rumail.orion-atc.ru |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Not signed |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 22% | 1 | 1 |
| routing | 22% | 1 | 1 |
| services | 22% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 22% | 1 | 1 |
| geolocation | 22% | 1 | 1 |
| Overall | 18% | 5 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-08-29 16:32:16 UTC |
| Last Seen | 2026-09-08 02:53:16 UTC |
| Profile Built | 2026-09-08 02:53:47 UTC |
| Data Freshness | Live |
| Signal Types | 15 |
| Total Observations | 22 |
Full dossier details are available via our API.