## IP Intelligence Briefing: 95.85.238.18/32
Date: 2026-07-29
Classification: Moderate Risk
Risk Score: 50/100
---
Executive Summary
IP address 95.85.238.18 is a Czech Republic-based host with a moderate risk profile (50/100). The IP is associated with RDP services and exhibits directory enumeration activity targeting WordPress plugin paths. While not currently classified as a known attacker or persistent threat source, the IP operates within a subnet with 33% abuse density and has one active threat sibling. Recommended action: Block traffic at perimeter firewalls.
---
Technical Profile
Ownership & Registration:
- ASN: 209946
- Organization: DGTLS-MNT
- Network Name: ALTAWK-CZ
- CIDR Block: 95.85.238.0/24
- RIR: RIPE (CZ)
- Registration Status: Active
Geolocation:
- Country: Czech Republic (CZ)
- Coordinates: 49.82°N, 15.47°E
- Accuracy Radius: 200km
Network Classification:
- Role: Single-Service Host
- Not classified as cloud, CDN, VPN, proxy, Tor, hosting, or mobile
- DNSSEC: Validated
- Route Stability: Unstable (isRouteStable: false)
Services & Ports:
- Port 3389/TCP: RDP (Remote Desktop Protocol) - Open
---
Threat Indicators
Current Threat Status:
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0
- DNSBL Listed: 1 of 8 lists
Abuse Context:
- Abuse Confidence Score: Not available
- Threat Persistence Days: 0
- Persistently Malicious: No
- Campaign Likelihood: None
---
Observations & Activity History
Recent Activity (19 observations):
- Directory Enumeration (2026-07-29): WordPress plugin path discovery detected at `/wp-content/plugins/wp_qwosxpu/wp_qwosxpu.php` with 10 404 responses in 5 minutes
- Port Scanning (2026-07-27): Multiple port scan activity detected
- Network Scans: 30 hop traceroute via Comcast and Cogent transit networks
Temporal Analysis:
- Ownership Changes: 0
- Threat Observation Count: 0
- Threat Persistence: Low
---
Neighborhood Analysis
Subnet: 95.85.238.0/24
Abuse Density: 33.33%
Classification: Mostly Clean
Sibling IPs:
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 95.85.238.63 | Null | Null |
| 95.85.238.209 | 25 | 50 |
Threat Context: 1 threat sibling identified within subnet, indicating potential coordinated activity or shared infrastructure abuse.
---
Relationships
Connected Entities: 5 relationships identified
- All relationships map to "Same Network" (ALTAWK-CZ)
- No external hostname, organization, or certificate associations detected
---
Recommended Actions
Firewall Rules (Block Recommended):
| Platform | Rule |
|---|---|
| iptables | `iptables -A INPUT -s 95.85.238.18 -j DROP` |
| nftables | `nft add rule inet filter input ip saddr 95.85.238.18 drop` |
| nginx | `deny 95.85.238.18;` |
| pfSense | `95.85.238.18/32` (block rule) |
| Cloudflare WAF | Block expression: `ip.src eq 95.85.238.18` |
| AWS WAF | Address: `95.85.238.18/32` |
---
Intelligence Notes
1. RDP Exposure: The open RDP port (3389) represents a potential lateral movement target if the IP is compromised or being used as an attack vector.
2. WordPress Targeting: Directory enumeration activity suggests automated probing for WordPress installations, consistent with vulnerability scanning or credential harvesting operations.
3. Subnet Context: The 95.85.238.0/24 subnet exhibits elevated abuse density (33.33%). Consider applying broader subnet-level controls if organizational policy permits.
4. Risk Trend: No historical persistence detected; threat activity appears episodic rather than sustained.
---
Analyst Assessment: This IP warrants blocking at perimeter defenses due to moderate risk scoring and active reconnaissance behavior. Monitor for related IPs in the 95.85.238.0/24 subnet.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
| Enumeration | Path/resource enumeration | 1 |
🏢 Ownership & Registration
| Organization | DGTLS-MNT |
| ASN | AS209946 |
| Network Name | ALTAWK-CZ |
| CIDR Block | 95.85.238.0/24 |
| RIR | RIPE |
| Country | CZ |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 3389 | rdp | tcp | — |
| Closed Ports | 22, 25, 80, 443, 8080, 8443 (1 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256RSA |
| Validity Period | 60 days |
🛡️ Public Network Snapshot
| Origin ASN | AS209946 |
| Network Prefix | 95.85.238.0/24 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Enabled |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 21% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 28% | 2 | 4 |
| ownership | 31% | 2 | 5 |
| reputation | 8% | 1 | 2 |
| geolocation | 17% | 2 | 3 |
| Overall | 19% | 10 | 19 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-15 04:06:44 UTC |
| Last Seen | 2026-09-02 17:32:04 UTC |
| Profile Built | 2026-09-02 17:37:27 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 30 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 95.85.238.18
Who owns the IP address 95.85.238.18?
95.85.238.18 is registered to DGTLS-MNT. The address falls within the 95.85.238.0/24 network block. Registration is held at RIPE.
Where is 95.85.238.18 located?
Geolocation data places 95.85.238.18 in London. The local time zone is Europe/Prague. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 95.85.238.18 malicious or safe?
95.85.238.18 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 95.85.238.18?
Responsive ports observed on 95.85.238.18 include 3389. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.