# IP Intelligence Briefing: 31.20.192.58/32
## Executive Summary
IP address 31.20.192.58 presents a Low Risk profile (Risk Score: 25) with minimal malicious activity indicators. The address is registered to Odido-Netherlands (ASN 50266) and is classified as firewalled with no active services detected.
---
## Ownership & Network Classification
- Organization: Odido-Netherlands (Access & transport)
- Network: 31.20.0.0/16
- ASN: 50266
- RIR: RIPE
- Registration: Odido-Netherlands / netname "Odido-Netherlands"
- Control Plane: Route changes in last 30 days: 0; Is route stable: false
---
## Geolocation
- Country: Netherlands (NL)
- Region: North Brabant
- City: Oss
- Coordinates: 52.13°N, 5.29°E
- Timezone: Europe/Amsterdam
- Geo Accuracy: 150 km radius
- Validation: Geo consensus confirmed; GeoPlausible: false
---
## Threat Assessment
- Overall Risk Score: 25 (Low Risk)
- Abuse Confidence Score: Not available
- Known Attacker: False
- Tor Exit Node: False
- Spam Source: False
- Blacklist Count: 1 DNSBL listing out of 8 total lists
- Known Campaigns: None detected
- Threat Feeds: No indicators
---
## Network Services & DNS
- Open Ports: None detected (Firewalled / No Services)
- HTTP/TLS: No services responding
- PTR Hostname: 58-192-20-31.ftth.glasoperator.nl
- Forward Resolution: Confirmed
- Hosted Domains: 0
- Email Auth: SPF record present; DMARC: Not configured
- DNSSEC: Valid
---
## Relationship Intelligence
- DNS Associations: 58-192-20-31.ftth.glasoperator.nl
- Network Relationships: Odido-Netherlands (multiple entries)
- Related Entities: No external organizations or certificates detected
---
## Neighborhood Analysis (31.20.192.0/24)
- Abuse Density: 1
- Subnet Classification: mostly_clean
- Inherited Risk: 2
- Total Siblings: 1
- Active Siblings: 0
- Threat Siblings: 1
---
## Historical Observations
- Total Observations: 17 signals recorded
- Observation Period: Recent activity detected (2026-07-22)
- Geolocation Consistency: Consistent Netherlands attribution across multiple signals
- Operator Score: 0.2609 (Basic classification)
- Threat Persistence: 0 days (not persistently malicious)
- Ownership Changes: 0
---
## Recommended Actions
- Firewall Rules: None recommended
- Monitoring Status: No active recommendations
- Risk Mitigation: Current risk level (25) does not warrant immediate blocking
---
## Intelligence Assessment
This IP address exhibits characteristics typical of residential or fixed broadband infrastructure under Odido-Netherlands management. The single DNSBL listing represents a minor concern but does not indicate active malicious use. The subnet shows low abuse density with classification "mostly_clean." No evidence of coordination with known malicious infrastructure.
Recommendation: Monitor as standard; no immediate blocking required. The IP's low risk score, firewalled status, and lack of open services suggest it is not currently being leveraged for malicious purposes.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Access & transport |
| ASN | AS50266 |
| Network Name | Odido-Netherlands |
| CIDR Block | 31.20.0.0/16 |
| RIR | RIPE |
| Country | NL |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | 58-192-20-31.ftth.glasoperator.nl |
| Forward Confirmed | Yes — FCrDNS verified |
| Forward Hostnames | 58-192-20-31.ftth.glasoperator.nl |
🔐 DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS50266 |
| Network Prefix | 31.20.0.0/16 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 17% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 17% | 2 | 3 |
| reputation | 14% | 1 | 3 |
| geolocation | 12% | 2 | 2 |
| Overall | 13% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-02 04:21:47 UTC |
| Last Seen | 2026-08-25 04:03:58 UTC |
| Profile Built | 2026-08-29 09:11:43 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 22 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 31.20.192.58
Who owns the IP address 31.20.192.58?
31.20.192.58 is registered to Access & transport. The address falls within the 31.20.0.0/16 network block. Registration is held at RIPE.
Where is 31.20.192.58 located?
Geolocation data places 31.20.192.58 in Oss, North Brabant, Netherlands. The local time zone is Europe/Amsterdam. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 31.20.192.58 malicious or safe?
31.20.192.58 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 31.20.192.58?
The reverse DNS (PTR) record for 31.20.192.58 is 58-192-20-31.ftth.glasoperator.nl. This hostname is forward-confirmed, meaning it resolves back to the same address.