Intelligence Briefing: 194.146.107.6
Subject: 194.146.107.6 /32
Location: Stockholm, Sweden (SE)
Ownership: Netnod Administrative Contact (ASN 8674)
Overview
Analysis classified the IP address as Low Risk with a risk score of 25. The address resolved to n.de.net within the de.net domain. Network scanning indicated the host was firewalled with no active services or open ports. DNS hygiene was rated Poor due to the absence of SPF and DMARC records.
Threat Context
Despite the low risk score, the threat actor classification identified the host as Suspicious with a 70% confidence level, noting threat indicators were present but lacked specific campaign attribution. Control plane data showed one listing on a DNS blacklist out of eight total lists. The subnet neighborhood (194.146.107.0/24) remained classified as clean with zero threat siblings. No known attacker signatures or specific campaigns were correlated.
Operational Status
The IP first and last appeared in observation logs on 2026-09-07. Routing data indicated a stable BGP prefix within the 194.146.107.0/24 block. Geolocation validation confirmed plausible location data despite ICMP blockage.
Recommendation
Analysts should continue to monitor the address. Current severity is rated Low due to the clean neighborhood context and lack of active services. No immediate blocking is required pending further correlation.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Netnod Administrative Contact |
| ASN | AS8674 |
| Network Name | NETNOD-DB-LAN-GBG |
| CIDR Block | 194.146.106.0/23 |
| RIR | RIPE |
| Country | SE |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | n.de.net |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | n.de.net |
π DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | 0/2 domains |
| DMARC | 0/2 domains |
| FCrDNS | Verified |
| DNSSEC | Not signed |
| CAA | Not configured |
| Domains Checked | 2 domains |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 33% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 19% | 2 | 2 |
| ownership | 27% | 2 | 3 |
| reputation | 13% | 1 | 2 |
| geolocation | 27% | 2 | 3 |
| Overall | 22% | 10 | 15 |
| Data Coherence | Consistent (100%) |
| Attribution | High (85%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-09-07 09:23:49 UTC |
| Last Seen | 2026-09-26 04:43:42 UTC |
| Profile Built | 2026-09-26 05:02:38 UTC |
| Data Freshness | Live |
| Signal Types | 30 |
| Total Observations | 37 |
Full dossier details are available via our API.