# IP INTELLIGENCE BRIEFING: 192.251.226.172/32
Generated: 2026-06-24
Classification: Moderate Risk (Score: 40/100)
---
## EXECUTIVE SUMMARY
IP address 192.251.226.172 is a moderate-risk address located in Gütersloh, Germany (DE), operated under ASN 206813 (FFGT-MNT). The IP presents no active threat indicators but demonstrates concerning neighborhood abuse characteristics. No services are running on the target, and it is firewalled.
---
## TECHNICAL PROFILE
Geolocation: Germany (NW), Gütersloh (51.17°N, 10.45°E)
Risk Score: 40/100 (Moderate)
Classification: Firewalled / No Services
ASN: 206813 (FFGT-MNT)
BGP Prefix: 192.251.226.0/24
DNSBL Status: Listed on 1 of 8 threat feeds
---
## THREAT ASSESSMENT
Active Threat Indicators: None detected
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Blacklist Count: 0
- Known Campaigns: None
Control Plane Analysis:
- Route stability: False
- RPKI state: Not evaluated
- IRR consistency: Not evaluated
- Operator score: 0.1304 (Minimal)
---
## NEIGHBORHOOD ANALYSIS
Subnet: 192.251.226.0/24
- Abuse Density: 0.6367 (High Abuse)
- Total Siblings: 256
- Active Siblings: 184
- Threat Siblings: 163
- Risk Distribution: High (0), Medium (2), Low (98)
Assessment: This /24 subnet exhibits significant abuse activity. The target IP shares network infrastructure with 163 other IPs flagged as threats within the same block.
---
## OBSERVATION HISTORY
Total Observations: 24 signals tracked
Recent Activity (2026-06-24):
- 03:01:03 UTC โ ASN AS49745 (kai siering) detected with threat indicators present (50 pulse signals)
- 03:00:52 UTC โ Operator score: Minimal (raw score: 0)
- 03:00:37 UTC โ Geographic inference confirmed (DE, 51.17°N, 10.45°E)
- 03:00:04 UTC โ DNSBL listing detected (1 of 8 lists, max severity: high)
Persistence: No persistent malicious behavior detected. Threat observation count: 0.
---
## NETWORK RELATIONSHIPS
Total Relationships: 57
- Primary Network Association: FFGT-NET2 (multiple instances)
- Relationship Types: Same Network (network-level associations)
---
## DNS & SERVICES
PTR Records: 192.251.226.172
Forward Resolution: 1 hostname
Email Authentication: No SPF/DMARC/TXT records
Open Ports: None detected
TLS Certificate: None
HTTP Service: Not responding
---
## RECOMMENDED ACTIONS
Firewall Blocking Rules:
iptables:
```
iptables -A INPUT -s 192.251.226.172 -j DROP
```
nftables:
```
nft add rule inet filter input ip saddr 192.251.226.172 drop
```
nginx:
```
deny 192.251.226.172;
```
pfSense:
```
192.251.226.172/32
```
Cloudflare WAF:
```json
{
"description": "Block 192.251.226.172 โ IPDebrief risk score 40",
"action": "block",
"filter": {"expression": "ip.src eq 192.251.226.172"}
}
```
AWS WAF:
```json
{
"Addresses": ["192.251.226.172/32"],
"Description": "IPDebrief risk 40"
}
```
---
## ANALYST NOTES
1. Contextual Risk: While the target IP shows no direct malicious activity, the parent /24 subnet demonstrates high abuse density (0.6367) with 63.67% of IPs flagged as threats.
2. Geographic Validation: ICMP validation blocked; RTT-based validation pending.
3. Infrastructure Status: No services currently running on the target. The IP appears to be either dormant or used for non-interactive purposes.
4. Recommendation: Apply blocking rules as a precautionary measure given neighborhood abuse characteristics, but prioritize investigation of sibling IPs within 192.251.226.0/24 for active threat activity.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | FFGT-MNT |
| ASN | AS206813 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 192.251.226.172 |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 192.251.226.172 |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 33% | 2 | 4 |
| Overall | 22% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:46 UTC |
| Last Seen | 2026-06-26 18:11:46 UTC |
| Profile Built | 2026-06-24 03:08:31 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 21 |
Full dossier details are available via our API.