## INTELLIGENCE BRIEFING: IP 176.103.4.89/32
Classification: High Risk | Date: 2026-06-22 | Status: Active Monitoring
EXECUTIVE SUMMARY
IP address 176.103.4.89 is classified as High Risk (70/100) with a stable routing profile. The address belongs to DIALOGKOM-MNT (ASN 56812) and is geolocated to Balakliya, Ukraine (UA). The IP is currently firewalled with no active services detected. Despite the local network's "mostly_clean" classification, this specific IP shows elevated risk indicators with 4 DNSBL listings across 8 total blacklists, including high-severity categorizations.
TECHNICAL PROFILE
| Attribute | Value |
|---|---|
| **ASN** | 56812 |
| **Organization** | DIALOGKOM-MNT |
| **Country** | Ukraine (UA) |
| **City** | Balakliya |
| **CIDR Block** | 176.103.4.89/24 |
| **Risk Score** | 70/100 |
| **Reputation** | High Risk |
| **Services** | None Detected (Firewalled) |
| **Open Ports** | 0 |
THREAT INDICATORS
- DNSBL Listings: 4 out of 8 blacklists (elevated)
- Operator Score: 0.2609 (Basic classification)
- Route Stability: Stable (isRouteStable: true)
- BGP Prefix: 176.103.0.0/20
- AS Path: 6939 48422 56812
- RPKI State: Not validated
- Known Campaigns: None identified
NETWORK CONTEXT
Subnet Analysis (176.103.4.89/24):
- Total Siblings: 46 IPs
- Active Siblings: 18
- Threat Siblings: 8
- Abuse Density: 0.1739 (moderate)
- Inherited Risk: 6/10
- Classification: mostly_clean
High-Risk Neighbors Identified:
- 176.103.4.31 (70)
- 176.103.4.36 (80)
- 176.103.4.58 (80)
- 176.103.4.193 (80)
- 176.103.4.207 (70)
- 176.103.4.239 (70)
OBSERVATION HISTORY
Signal monitoring captured 20 observations with key findings:
- 2026-06-22: Subnet abuse density 0.1739, classification: mostly_clean, inherited risk: 6
- 2026-06-17: Operator score 0.3, DNSBL severity: high across 4 lists, geo confidence: 0.52 (Ukraine)
RELATIONSHIP ANALYSIS
The IP maintains 16 identified relationships, all classified as "Same Network" type, associating the address with DIALOG-NET infrastructure. No certificate, hostname, or organizational relationships beyond network-level associations were identified.
RECOMMENDED ACTIONS
1. Block Traffic: Implement deny rules for inbound/outbound traffic to/from 176.103.4.89 at perimeter firewall
2. Monitor Subnet: Track additional high-risk neighbors (176.103.4.31, 176.103.4.36, 176.103.4.58, 176.103.4.193)
3. DNSBL Review: Investigate source of 4 blacklist listings and verify false positive potential
4. Geolocation Verification: Confirm UA attribution given 500km accuracy radius and multi-signal inference method
ASSESSMENT
This IP presents elevated risk primarily due to DNSBL listings despite no active services. The subnet shows mixed reputation with 8 identified threat siblings. Recommend blocking or rate-limiting traffic from this address pending further investigation into blacklist associations and potential abuse patterns.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | DIALOGKOM-MNT |
| ASN | AS56812 |
| Network Name | β |
| CIDR Block | 176.103.0.0/20 |
| RIR | RIPE |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 37% | 2 | 3 |
| routing | 27% | 2 | 3 |
| services | 15% | 2 | 2 |
| ownership | 30% | 3 | 4 |
| reputation | 21% | 1 | 2 |
| geolocation | 21% | 2 | 2 |
| Overall | 25% | 12 | 16 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:03:55 UTC |
| Last Seen | 2026-06-22 21:48:18 UTC |
| Profile Built | 2026-06-22 21:56:16 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.