IPDebrief

95.156.102.194

IP Intelligence Dossier
Your IP: 216.73.217.34
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

Intelligence Briefing: 95.156.102.194/32

Summary

The IP address 95.156.102.194/32 was assessed with a Moderate Risk reputation (Score: 50) and classified as a Suspicious Host. The address is associated with ASN 12389 (Krasnoyarsk Computer Network/Rostelecom-net) and geolocated to Ilanskiy, Krasnoyarsk Krai, Russia.

Network Characteristics

Network analysis indicated the address was assigned to a mobile carrier, specifically Tele2 RU, and was observed in a firewalled state with no active services or open ports. DNS records were forward confirmed to mail.orion-atc.ru and gate.orion-atc.ru, with SPF and DMARC policies present. The address was listed on 2 DNSBLs out of 8 total lists monitored.

Timeline and Activity

Activity was observed starting 2026-08-29T16:32:16Z and continuing through 2026-09-07T08:46:25Z. Attribution confidence was Moderate (70%).

Threat Assessment and Recommendation

Despite low behavioral activity metrics in specific incident counts, the overall risk assessment was elevated due to multiple threat signals. The recommended action is Block with High Severity.

Mitigation Rules

The following firewall rules were applied based on the risk assessment:

* iptables: `iptables -A INPUT -s {ip} -j DROP`

* nginx: `deny {ip};`

* pf: `block in quick on egress from {ip}`

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ท๐Ÿ‡บ Russia
RegionKrasnoyarsk Krai
CityIlanskiy
Timezoneโ€”
Latitude56.24
Longitude96.06

๐Ÿข Ownership & Registration

OrganizationKrasnoyarsk Computer Network
ASNAS12389
Network NameRostelecom-net
CIDR Block95.156.101.0/24
RIRRIPE
CountryRU
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTRmail.orion-atc.ru
Forward ConfirmedYes โ€” FCrDNS verified
Forward Hostnamesmail.orion-atc.ru
gate.orion-atc.ru
mail.orion-atc.ru

๐Ÿ” DNS Hygiene

Hygiene Score60% (Good)
SPFPresent
DMARCPresent
FCrDNSVerified
DNSSECNot signed
CAANot configured

โ˜๏ธ Network Classification

InfrastructureMobile
Service PurposeFirewalled / No Services
Network TierUnknown โ€” Insufficient routing data to classify
Mobile

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Serverโ€”
HTTP Titleโ€”

๐Ÿ” TLS Certificate

๐Ÿ”’
No certificate
Issued by โ€”
N/A
SANsNone
Valid Fromโ€”
Valid Untilโ€”

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
22%
11
routing
22%
11
services
22%
11
ownership
0%
00
reputation
22%
11
geolocation
22%
11
Overall18%55
Coverage: 4/6 dimensions ยท Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-08-29 16:32:16 UTC
Last Seen2026-09-08 02:53:16 UTC
Profile Built2026-09-08 02:53:47 UTC
Data FreshnessLive
Signal Types15
Total Observations22
๐Ÿ” 15 signal types ยท 22 observations collected
This report is generated from 15+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.