# IP INTELLIGENCE BRIEFING
Target: 213.92.222.40/32
Classification: High Risk
Date: 2026-07-31
Analyst: IPDebrief Intelligence Team
---
## EXECUTIVE SUMMARY
IP 213.92.222.40 presents a high-risk security profile with an overall risk score of 70/100. The address is associated with Polish infrastructure under Arkadiusz Suchy's network (PL-SERVNET4, ASN 29314) in the InowrocΕaw region. While the IP itself is not flagged as a known attacker, spam source, or Tor exit node, it exhibits elevated risk characteristics requiring monitoring.
---
## OWNERSHIP & GEOLOCATION
- Organization: Arkadiusz Suchy (AS29314)
- Network: 213.92.222.0/23 (PL-SERVNET4)
- Registration: RIR RIPE
- Country: Poland (PL)
- City/Region: InowrocΕaw, Kujawsko-Pomorskie
- Coordinates: 51.92°N, 19.15°E
---
## TECHNICAL PROFILE
- DNS Resolution: 213-92-222-40.serv-net.pl (forward confirmed)
- Open Ports: TCP/80 (HTTP), TCP/443 (HTTPS)
- Web Server: lighttpd/1.4.39
- TLS Certificates: Not detected
- Email Auth: SPF enabled, DMARC absent
- Route Stability: Not stable (route changes in 30-day window)
---
## THREAT ASSESSMENT
- Risk Score: 70/100 (High)
- Known Campaigns: None
- Threat Feeds: No active indicators
- Blacklist Status: 0/8 DNSBL lists
- Abuse Confidence: Not scored
- Persistence: Not persistently malicious (1 threat observation)
- Control Plane: DNSSEC valid, 4 DNSBL listings across 8 total lists
---
## NETWORK CONTEXT
- Subnet Analysis: 213.92.222.0/24
- Abuse Density: 10% (0.1)
- Classification: Mostly clean
- Active Siblings: 7/10
- Threat Siblings: 1
- Risk Distribution: 3 high-risk, 6 medium-risk neighbors
High-Risk Neighbors:
- 213.92.222.76 (80)
- 213.92.222.99 (80)
- 213.92.222.237 (80)
---
## OBSERVATION HISTORY
21 signals observed since deployment. Recent observations confirm consistent ownership attribution to Arkadiusz Suchy with abuse contact abuse@vectra.pl. One threat observation recorded; no correlation with active campaigns or correlated IPs detected.
---
## RECOMMENDED ACTIONS
Immediate:
1. Increase logging verbosity for traffic from 213.92.222.40
2. Review recent activity patterns for anomalies
Firewall Rules:
```bash
iptables -A INPUT -s 213.92.222.40 -j DROP
```
Platform-Specific:
- nftables: `nft add rule inet filter input ip saddr 213.92.222.40 drop`
- nginx: `deny 213.92.222.40;`
- Cloudflare WAF: Block with filter expression `ip.src eq 213.92.222.40`
- AWS WAF: Add rule for `213.92.222.40/32`
---
## INTELLIGENCE NOTES
The IP operates as a web server with no malicious indicators directly associated. However, the elevated risk score and presence of three high-risk neighbors in the same /24 subnet suggest potential for lateral threat activity. The absence of DMARC implementation and DNSSEC validation gaps warrant attention. Monitoring is recommended for emerging activity patterns.
---
*Report generated by IPDebrief Intelligence Platform. All data sourced from real-time threat intelligence feeds.*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Arkadiusz Suchy |
| ASN | AS29314 |
| Network Name | PL-SERVNET4 |
| CIDR Block | 213.92.222.0/23 |
| RIR | RIPE |
| Country | PL |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 213-92-222-40.serv-net.pl |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 213-92-222-40.serv-net.pl |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | β |
| 443 | https | tcp | β |
| Closed Ports | 22, 25, 3389, 8080, 8443 (2 open / 7 scanned) | ||
| Server | lighttpd/1.4.39 |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 35% | 2 | 2 |
| routing | 25% | 1 | 1 |
| services | 35% | 2 | 2 |
| ownership | 0% | 0 | 0 |
| reputation | 25% | 1 | 1 |
| geolocation | 0% | 0 | 0 |
| Overall | 20% | 6 | 6 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-30 11:03:50 UTC |
| Last Seen | 2026-08-01 04:25:39 UTC |
| Profile Built | 2026-07-31 02:23:54 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 24 |
Full dossier details are available via our API.