IP Intelligence Briefing: 185.98.0.89
Date: 2026-06-07
**Key Findings**
1. Risk Profile:
- Risk Score: 40 (Moderate Risk).
- Ownership: Registered to Almedin Beso (AS20875) in Bosnia and Herzegovina (Mostar).
- Geolocation: Mostar, Bosnia (43.34°N, 17.81°E).
2. Threat Indicators:
- No active threat indicators (no malware, spam, or known attacker associations).
- DNSSEC Valid: True.
- DNSBL Listings: 2 out of 8 lists (potential abuse risk).
3. Network Behavior:
- Firewalled/No Services: No open ports or services detected.
- Subnet Abuse Density: 1/24 (low), but 1 threat sibling in the same /24 subnet.
- BGP Stability: Route instability detected (unstable route changes).
4. Historical Observations:
- Single observation (2026-06-07) with low confidence.
- No persistent malicious activity or ownership changes.
5. Relationships:
- Linked to "Mostar1" network (AS20875).
- No hostname or certificate relationships.
**Recommended Actions**
- Block IP: Implement firewall rules to block 185.98.0.89 (see tools for rule templates).
- Monitor Subnet: Investigate the threat sibling in 185.98.0.0/24 for potential lateral movement.
- Verify DNSSEC: Confirm DNSSEC validity and check for spoofing risks.
- Check Ownership: Validate Almedin Besoβs legitimacy via RDAP.
Conclusion: While no direct threats are detected, the IPβs firewalled nature, DNSBL listings, and subnet abuse density warrant closer monitoring. Block the IP and review the subnet for anomalies.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Almedin Beso |
| ASN | AS20875 |
| Network Name | Mostar1 |
| CIDR Block | 185.98.0.0/24 |
| RIR | RIPE |
| Country | BA |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 13% | 1 | 1 |
| ownership | 27% | 2 | 3 |
| reputation | 22% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 20% | 9 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-14 19:28:32 UTC |
| Last Seen | 2026-06-07 08:20:21 UTC |
| Profile Built | 2026-06-07 08:29:36 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 20 |
Full dossier details are available via our API.