Your IP: 216.73.216.123
๐ค Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.
IP Intelligence Briefing: 158.94.210.98
Date: 2026-06-08
---
**1. Core Profile**
- Risk Score: Moderate (55/100)
- Ownership: Registered to Abuse Contact under OMEGATECH (ASN 202412, ARIN).
- Geolocation: Amsterdam, North Holland, Netherlands (52.37°N, 4.89°E).
- Network Role: Firewalled / No Services (no open ports, no TLS certs, no HTTP services).
- Threat Indicators: No active malware, phishing, or exploit indicators.
---
**2. Observation History**
- Abuse Density: 0.25 (low) over 30 days.
- Subnet Stability: 12 observations; stable ownership with no recent changes.
- Threat Trends: No persistent malicious activity detected.
---
**3. Network Relationships**
- Linked Entities:
- Subnet: 158.94.210.0/24 (owned by OMEGATECH).
- No external DNS, certificates, or hosting domains linked.
- Neighbors:
- 11 IPs in the same subnet.
- High-risk neighbors: 158.94.210.111 (70), 158.94.210.204 (70), 158.94.210.238 (65).
- Low-risk neighbors: 158.94.210.44 (40), 158.94.210.72 (25), 158.94.210.75 (unknown).
---
**4. Threat Context**
- No Direct Malicious Activity: IP shows no signs of exploitation, phishing, or botnet activity.
- Subnet Risk: 4/11 neighbors flagged as medium/high risk. Monitor high-risk neighbors (e.g., 158.94.210.111, 158.94.210.204) for lateral movement or traffic anomalies.
- Geolocation Plausibility: Valid Dutch IP with consistent geolocation data.
---
**5. Recommendations**
- Monitor Neighbors: Focus on high-risk IPs in the subnet for potential correlation with threats.
- Traffic Analysis: Check for unusual traffic patterns between 158.94.210.98 and high-risk neighbors.
- Firewall Rules: Consider blocking high-risk neighbors if they are not part of your network.
- Subnet Review: Validate OMEGATECH's ownership and ensure no unauthorized subnets are active.
Conclusion: 158.94.210.98 is a low-risk IP with no direct threats but shares a subnet with higher-risk IPs. Prioritize monitoring neighboring networks for potential indirect risks.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Abuse Contact |
| ASN | AS202412 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 3389 | rdp | tcp | โ |
| Closed Ports | 22, 25, 80, 443, 8080, 8443 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
No certificate
Issued by โ
N/A
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 27% | 2 | 3 |
| reputation | 19% | 1 | 2 |
| geolocation | 13% | 1 | 1 |
| Overall | 19% | 8 | 10 |
Coverage: 6/6 dimensions ยท Data sufficiency: sufficient
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
โ Geo sources disagree on country: GB, NL
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-16 20:59:44 UTC |
| Last Seen | 2026-06-08 01:14:20 UTC |
| Profile Built | 2026-06-08 01:19:46 UTC |
| Data Freshness | Live |
| Signal Types | 17 |
| Total Observations | 17 |
๐ 17 signal types ยท 17 observations collected
This report is generated from 17+ independent intelligence signals including
ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds,
behavioral fingerprinting, and more.
Full dossier details are available via our API.
Full dossier details are available via our API.
โน๏ธ About This Report
All data shown is publicly available network metadata โ IP addresses do not reliably identify individuals.
Assessments are probabilistic and should not be used as sole basis for access control decisions.
To report an issue or request data review, contact admin@ipdebrief.com.