# IP Intelligence Briefing: 192.251.226.218/32
## Executive Summary
IP address 192.251.226.218 is classified as Moderate Risk (risk score: 40) with active threat indicators and a high-abuse-density neighborhood. The IP is geolocated to Gütersloh, Germany (DE), under AS206813 (FFGT-MNT). Despite showing no open services, the IP maintains a blacklist presence across 8 DNSBL entries and exhibits threat activity in observation history.
## Threat Profile
Risk Assessment: Moderate Risk (40/100)
- Abuse Confidence: DNSBL listed on 8 lists
- Geolocation: Germany (DE), Gütersloh, Region NW
- ASN: 206813 (FFGT-MNT)
- Network Role: Firewalled / No Services
- Reputation Sources: Multiple threat feeds detected
Threat Indicators:
- Threat pulse count: 50 (multiple nested threat indicators)
- DNSBL listings: 8 total
- No known campaigns correlated
- No Tor/VPN/proxy activity detected
## Neighborhood Analysis
The /24 subnet (192.251.226.0/24) demonstrates elevated abuse activity:
- Abuse Density: 0.7188 (High Abuse classification)
- Active Siblings: 191 IPs in subnet
- Threat Siblings: 184 IPs identified as threats (96.3% threat ratio)
- Classification: High abuse density subnet
Neighboring IP Risk Distribution:
- High risk: 0
- Medium risk: 2
- Low risk: 98
This indicates the target IP is part of a subnet with concentrated malicious activity.
## Relationship Mapping
47 relationships detected:
- Primary association: Same Network (FFGT-NET2)
- Multiple network-level connections within the same infrastructure
- No certificate or hostname relationships identified
## Historical Activity
Observation history reveals 17 recorded observations with escalating threat signals:
- June 24, 2026: Threat indicators with 50 pulse hits (highest severity)
- June 10, 2026: DNS blacklist activity (8 total listings)
- June 4, 2026: Operator score assessment (0.1304 - Minimal operator risk)
- June 3, 2026: Subnet abuse density confirmed at 0.7188
The pattern shows persistent threat observation across multiple time windows.
## Recommended Actions
Immediate Mitigation:
1. Block at perimeter firewall - iptables/nftables DROP rule recommended
2. Block in WAF environments - Cloudflare WAF and AWS WAF rules available
3. Monitor for lateral movement - Due to high-threat subnet density
Firewall Rules Generated:
```bash
iptables -A INPUT -s 192.251.226.218 -j DROP
nft add rule inet filter input ip saddr 192.251.226.218 drop
```
WAF Configuration:
- Cloudflare: Block with expression `ip.src eq 192.251.226.218`
- AWS WAF: Add 192.251.226.218/32 to IP set
## Intelligence Context
The IP demonstrates characteristics of a firewalled endpoint with no active services but maintains threat indicators. The high-threat neighborhood context suggests this IP may be part of a coordinated infrastructure or may have been previously compromised. The 96.3% threat sibling ratio in the /24 subnet warrants expanded blocking of adjacent IPs if operational context supports broader mitigation.
Recommendation: Implement block rule and monitor for additional indicators from related network entities (FFGT-NET2).
---
*Report generated: Current timestamp | Data source: IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | FFGT-MNT |
| ASN | AS206813 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | ARIN |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | 192.251.226.218 |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | 192.251.226.218 |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 19% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 24% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 19% | 2 | 2 |
| Overall | 16% | 9 | 11 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:46 UTC |
| Last Seen | 2026-06-26 18:11:46 UTC |
| Profile Built | 2026-06-24 03:16:25 UTC |
| Data Freshness | Live |
| Signal Types | 18 |
| Total Observations | 19 |
Full dossier details are available via our API.