IPDebrief

95.182.92.198

IP Intelligence Dossier
Your IP: 216.73.216.5
{ } JSON ๐Ÿ”ง Full Actions API
๐Ÿค– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP INTELLIGENCE BRIEFING: 95.182.92.198/32

Date: 2024

Classification: MODERATE RISK

Risk Score: 40/100

Status: ACTIVE MONITORING

---

## EXECUTIVE SUMMARY

IP address 95.182.92.198 is a web server endpoint operated within the CLOUD-SOFTWARE network infrastructure (ASN 211273, RIPE NCC). The endpoint demonstrates moderate risk characteristics with 2 DNSBL listings and routing instability. No persistent malicious activity observed. Recommended for monitoring with selective firewall rules.

---

## NETWORK OWNERSHIP & ATTRIBUTION

AttributeValue
**ASN**211273
**Organization**MNT-NETART
**Netname**CLOUD-SOFTWARE
**CIDR Block**95.182.92.0/24
**Country**United Kingdom (GB)
**City**London
**RIR**RIPE
**Delegation Age**191 days
**RPKI State**Not Found

---

## THREAT INTELLIGENCE

Risk Assessment: Moderate Risk (40/100)

Threat Indicators:

Temporal Analysis:

---

## NETWORK SERVICES & FINGERPRINTING

Open Ports:

Server Fingerprint:

TLS Certificate:

Application Stack:

---

## NEIGHBORHOOD ANALYSIS

Subnet: 95.182.92.0/24

---

## CONTROL PLANE DATA

MetricValue
BGP Prefix95.182.92.0/24
AS Path6939 โ†’ 211273
Route Changes (30d)3
Route StabilityFalse
DNSSEC ValidYes
Operator Score0.1304 (Minimal)

---

## OBSERVATION HISTORY

Total observations: 64

Recent Signals Include:

---

## RELATIONSHIP MAPPING

Total relationships: 140

---

## RECOMMENDED ACTIONS

Firewall Rules (Risk-Based):

```bash

# iptables

iptables -A INPUT -s 95.182.92.198 -j DROP

# nftables

nft add rule inet filter input ip saddr 95.182.92.198 drop

# Nginx

deny 95.182.92.198;

```

Cloud Provider Actions:

Monitoring Recommendations:

1. Monitor SSH port (22) for brute force attempts

2. Track DNSBL listing status

3. Observe route stability metrics

4. Monitor TLS certificate validity

---

## ASSESSMENT

The IP address presents moderate risk due to DNSBL listings and routing instability. The endpoint appears to be a legitimate cloud hosting service serving WordPress applications. The open SSH port warrants attention for potential unauthorized access attempts. No evidence of persistent malicious activity. Recommend selective blocking with ongoing monitoring.

Confidence Level: High

Last Updated: 2026-08-05

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

๐ŸŒ Geolocation

Country๐Ÿ‡ฌ๐Ÿ‡ง United Kingdom
RegionLondon
CityLondon
TimezoneEurope/London
Latitude51.51
Longitude-0.13

๐Ÿข Ownership & Registration

OrganizationMNT-NETART
ASNAS211273
Network NameCLOUD-SOFTWARE
CIDR Block95.182.92.0/24
RIRRIPE
CountryUS
Abuse ContactAvailable via RDAP

๐ŸŒ DNS Intelligence

PTR RecordNo PTR
Forward ConfirmedNo โ€” PTR hostname does not resolve back to this IP (weak signal)

๐Ÿ” DNS Hygiene

Hygiene Score20% (Poor)
SPFNot configured
DMARCNot configured
FCrDNSNot verified
DNSSECValid
CAANot configured

โ˜๏ธ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierUnknown โ€” Insufficient routing data to classify
No specific classification

๐Ÿ”Œ Services & Open Ports

PortServiceProtocolBanner
80httptcpโ€”
443httpstcpโ€”
22sshtcp
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
Servernginx/1.26.3
HTTP Titleโ€”
SSH VersionSSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13

๐Ÿ” TLS Certificate

A self-signed certificate was detected. This is common for development servers, internal services, or IoT devices.
โš ๏ธ
CN=tinder.com, O=Google Trust Services LLC, L=London, S=London, C=GB
Issued by CN=tinder.com, O=Google Trust Services LLC, L=London, S=London, C=GB
Self-signed: Yes
SANsNone
Valid From2026-07-27T09:41:34+00:00
Valid Until2036-07-24T09:41:34+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period3650 days
Serial Number194FFF230763FD45AB5D854C60F2D373C8AD06E8
ThumbprintFB184D8DD0D6FC8A3BFE372778245E2865D51D44

๐ŸŽฏ Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
41%
25
routing
30%
34
services
31%
23
ownership
37%
36
reputation
26%
13
geolocation
35%
23
Overall33%1324
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
Data CoherenceMostly Consistent (80%) โ€” 1 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
โš  Geo sources disagree on country: GB, RU

๐Ÿ“… Observation Timeline ๐Ÿ”„ Live

First Seen2026-07-21 12:55:57 UTC
Last Seen2026-08-13 06:46:14 UTC
Profile Built2026-08-13 06:57:32 UTC
Data FreshnessLive
Signal Types29
Total Observations60
๐Ÿ” 29 signal types ยท 60 observations collected
This report is generated from 29+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API ๐Ÿ”ง Actions API ๐Ÿ“ง Enterprise Access

โ„น๏ธ About This Report

All data shown is publicly available network metadata โ€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.