# IP INTELLIGENCE BRIEFING: 109.175.99.244/32
## Executive Summary
IP address 109.175.99.244 is a moderate-risk infrastructure endpoint assigned to BIHNET-DNS (ASN 9146), a telecommunications provider in Sarajevo, Bosnia and Herzegovina. The address is firewalled with no open services and shows minimal threat indicators. Recommended defensive posture: Block with awareness of legitimate provider context.
## Ownership and Attribution
- Organization: BIHNET-DNS
- ASN: 9146
- Network Name: BIHNET-SE800-SA3
- CIDR Block: 109.175.96.0/19
- RIR: ARIN
- Abuse Contact: abuse@bhtelecom.ba
- Geolocation: Sarajevo, Bosnia and Herzegovina (43.85°N, 18.36°E)
## Threat Assessment
- Overall Risk Score: 40 (Moderate)
- Provider/Authority Scores: 0 (Neutral)
- Blacklist Status: 2 DNSBL listings out of 8 total lists
- Known Threat Indicators: None detected
- Campaign Affiliation: Not associated with known malicious campaigns
- Tor/Proxy/VPN: Not a Tor exit node, proxy, or VPN service
- Network Classification: Firewalled / No Services
## Technical Observations
- Open Ports: None (all services blocked by firewall)
- DNS Resolution: No PTR records, no forward resolution, no hosted domains
- Email Reputation: No SPF/DMARC records configured
- TLS/Certificates: None observed
- Control Plane: BGP origin 109.175.98.0/23, route stability: false
- Operator Score: 0.1304 (Minimal)
## Historical Analysis
Signal observation history from 2026-07-24 shows consistent organizational attribution to BIHNET-DNS with confidence levels between 0.30–0.95. Geolocation data consistently resolves to Sarajevo, Federation of Bosnia and Herzegovina. No evidence of persistent malicious behavior or ownership changes detected.
## Neighborhood Context
- Subnet: 109.175.99.0/24
- Abuse Density: 0%
- Risk Distribution: No high or medium risk neighbors identified
- Total Siblings: No adjacent IPs flagged
## Related Entities
- Network Association: BIHNET-SE800-SA3
- Relationship Count: 1
## Defensive Recommendations
Based on risk profile, the following firewall rules are recommended:
```bash
# iptables
iptables -A INPUT -s 109.175.99.244 -j DROP
# nftables
nft add rule inet filter input ip saddr 109.175.99.244 drop
# nginx
deny 109.175.99.244;
# pfSense
109.175.99.244/32
# Cloudflare WAF
ip.src eq 109.175.99.244
# AWS WAF
Addresses: 109.175.99.244/32
```
## Analyst Notes
While the IP carries a moderate risk score and appears on 2 DNSBL lists, the absence of open services, threat indicators, and malicious campaigns suggests this may be a legitimately misconfigured or over-blocked provider IP. The BIHNET infrastructure appears to be a legitimate telecommunications network. SOC teams should correlate with additional threat intelligence before implementing blocking, particularly if this IP is not generating suspicious traffic. If traffic from this IP is observed, investigate for anomalies rather than assuming malicious intent.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | BIHNET-DNS |
| ASN | AS9146 |
| Network Name | BIHNET-SE800-SA3 |
| CIDR Block | 109.175.96.0/19 |
| RIR | ARIN |
| Country | BA |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS9146 |
| Network Prefix | 109.175.98.0/23 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-07 00:23:32 UTC |
| Last Seen | 2026-08-27 08:46:54 UTC |
| Profile Built | 2026-08-29 04:57:32 UTC |
| Data Freshness | Live |
| Signal Types | 13 |
| Total Observations | 15 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 109.175.99.244
Who owns the IP address 109.175.99.244?
109.175.99.244 is registered to BIHNET-DNS. The address falls within the 109.175.96.0/19 network block. Registration is held at ARIN.
Where is 109.175.99.244 located?
Geolocation data places 109.175.99.244 in Sarajevo, Federation of Bosnia and Herzegovina, BA. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 109.175.99.244 malicious or safe?
109.175.99.244 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.