# INTELLIGENCE BRIEFING: 109.207.41.226/32
Date: 2026-07-26
Classification: High Risk (Score: 80)
Status: Active Threat Indicator
## EXECUTIVE SUMMARY
IP 109.207.41.226 is a high-risk (80) endpoint associated with Serbian ISP infrastructure (AS52026 - TRUF). The address is currently firewalled with no active services. Despite the host-level risk score of 80, the broader subnet (109.207.41.0/24) maintains a "mostly_clean" classification with 10.5% abuse density. The IP is listed on 4 DNS blacklists and shows 17-hop traceroute path through Comcast transit networks.
## INFRASTRUCTURE PROFILE
| Attribute | Value |
|---|---|
| **ASN** | 52026 (TRUF) |
| **Organization** | AS6700-MNT |
| **CIDR Block** | 109.207.32.0/20 |
| **Geolocation** | Serbia (RS) |
| **Registration** | ARIN |
| **Network Role** | Firewalled / No Services |
| **Cloud/VPN/Proxy** | None detected |
## THREAT INDICATORS
- Risk Score: 80 (High Risk)
- DNSBL Status: Listed on 4 of 8 total blacklist feeds
- Threat Feeds: No active campaign associations
- Tor Exit: False
- Known Attacker: False
- Spam Source: False
- Abuse Confidence Score: Not applicable (firewalled)
## NETWORK CONTEXT
Subnet Analysis (109.207.41.0/24):
- Total siblings: 19
- Active siblings: 10
- Threat siblings: 2
- Abuse density: 11.1%
- Classification: Mostly clean
Notable High-Risk Neighbors:
- 109.207.41.138 (Risk: 80)
- 109.207.41.208 (Risk: 70)
- 109.207.41.224 (Risk: 80)
## OBSERVATION HISTORY
Thirteen observations recorded as of 2026-07-26. Historical data shows:
- Stable ownership (0 changes)
- No persistent malicious activity
- Consistent subnet classification ("mostly_clean")
- Inherited risk score: 4
## RELATIONSHIPS
Two network-level relationships identified to "TRUF" (same network). No hostname or certificate associations detected.
## RECOMMENDED ACTIONS
| Priority | Action | Rationale |
|---|---|---|
| **BLOCK** | Ingress/egress firewall rules | High risk score (80) with blacklist presence |
| **MONITOR** | Traffic patterns | 4 DNSBL listings indicate reputation concerns |
| **INVESTIGATE** | Neighbor IPs | 3 additional IPs in /24 subnet scored ≥70 risk |
| **ALERT** | SOC teams | Subnet contains multiple high-risk endpoints |
## TECHNICAL DETAILS
- Control Plane: BGP prefix 109.207.40.0/22; DNSSEC valid
- RPKI State: Not validated
- MOAS Status: False
- Traceroute: 17 hops, 5 timed out, final hop 121.2ms
- Services: None detected (firewalled)
- DNS: No PTR records; forward resolution failed
## INTELLIGENCE ASSESSMENT
This IP represents a defensive security concern due to high risk scoring and blacklist presence despite being firewalled. The subnet-level analysis suggests coordinated abuse activity within the 109.207.41.0/24 block, with three additional high-risk neighbors warranting expanded monitoring. The 11.1% abuse density exceeds typical ISP baseline thresholds. Recommend implementing ingress/egress blocking rules and correlating traffic with the identified high-risk neighbor IPs for potential coordinated threat activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | AS6700-MNT |
| ASN | AS52026 |
| Network Name | TRUF |
| CIDR Block | 109.207.32.0/20 |
| RIR | ARIN |
| Country | rs |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 443 | https | tcp | — |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS52026 |
| Network Prefix | 109.207.40.0/22 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-12 02:46:02 UTC |
| Last Seen | 2026-09-02 14:47:07 UTC |
| Profile Built | 2026-09-02 15:01:07 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 27 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 109.207.41.226
Who owns the IP address 109.207.41.226?
109.207.41.226 is registered to AS6700-MNT. The address falls within the 109.207.32.0/20 network block. Registration is held at ARIN.
Where is 109.207.41.226 located?
Geolocation data places 109.207.41.226 in www.kbcnet.rs. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 109.207.41.226 malicious or safe?
109.207.41.226 currently carries a high risk assessment, meaning indicators associated with malicious or abusive activity have been observed. This assessment is generated from continuously collected signals and can change over time.
What ports are open on 109.207.41.226?
Responsive ports observed on 109.207.41.226 include 80, 443. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.