# IP Intelligence Briefing: 46.166.172.194/32
Classification: LOW RISK β Defensive Monitoring Recommended
Report Date: 2026-07-30
## Executive Summary
IP address 46.166.172.194 is a low-risk infrastructure endpoint hosted by Cherry Servers (ASN 16125) in Siauliai, Lithuania. The IP demonstrates no active threat indicators, zero blacklist associations, and operates within a clean subnet environment with an abuse density score of 0. Network activity is consistent with legitimate hosting operations.
## Threat Profile Assessment
- Risk Score: 0/100
- Abuse Confidence Score: Not applicable (no malicious activity observed)
- Blacklist Count: 0
- Campaign Correlation: None identified
- Threat Persistence: Not persistent
- Known Campaigns: 0 matches
## Infrastructure Details
| Attribute | Value |
|---|---|
| **Organization** | Cherry Servers NOC |
| **ASN** | 16125 |
| **CIDR Block** | 46.166.172.192/29 |
| **Registration RIR** | RIPE |
| **Geolocation** | Siauliai, Lithuania (LT) |
| **PTR Hostname** | ip-46-166-172-194.009.ptr.cherryservers.net |
| **Forward Resolution** | Confirmed |
## Network Services & Fingerprint
- Open Ports: TCP/22 (SSH)
- SSH Banner: SSH-2.0-OpenSSH_9.2p1 Debian-2+deb12u10
- TLS Certificate: None detected
- HTTP Service: Not detected
- DNSSEC: Validated
- Operator Classification: Basic (Operator Score: 0.2609)
## Neighborhood Analysis
The /24 subnet 46.166.172.194/24 exhibits clean security characteristics:
- Abuse Density: 0
- Total Siblings: 5 (including subject IP)
- Threat Siblings: 0
- Classification: Clean
Adjacent IP Risk Distribution:
| IP Address | Risk Score | Authority Score |
|---|---|---|
| 46.166.172.195 | 0 | 60 |
| 46.166.172.196 | 25 | 60 |
| 46.166.172.197 | 25 | 60 |
| 46.166.172.198 | 0 | 60 |
All neighboring IPs maintain low-to-medium risk profiles with no high-risk concentrations.
## Historical Signal Analysis
- Total Observations: 18 signal events
- Recent Activity:
- Geolocation validation (RTT: 131.6ms, 1145km distance)
- Ownership confirmation (Cherry Servers NOC)
- Port scanning activity (SSH detected)
- No ownership changes detected
- Malicious Behavior Indicators:
- Threat Observation Count: 0
- Persistently Malicious: False
- Threat Persistence Days: 0
## Relationship Graph
Eight relationships identified:
- DNS Associations: 4 entries pointing to ip-46-166-172-194.009.ptr.cherryservers.net
- Network Associations: 2 entries for net-207177-284086-239806
- No external entity associations (organizations, certificates, or linked hosts)
## Security Recommendations
Acceptable Traffic:
- Permit inbound/outbound SSH (port 22) from trusted sources
- Allow DNS traffic to/from cherryservers.net
Monitoring Triggers:
- Unusual outbound connection patterns
- Non-standard port activity
- SSH brute force attempts
- Port scanning from external sources
Actionable Firewall Rules (iptables example):
```bash
# Allow SSH from trusted sources
iptables -A INPUT -p tcp --dport 22 -s [trusted_networks] -j ACCEPT
# Block all other inbound traffic
iptables -A INPUT -j DROP
# Allow DNS responses
iptables -A INPUT -p udp --dport 53 -j ACCEPT
```
SOC Monitoring Priority:
LOW β This IP represents a legitimate hosting endpoint with no evidence of malicious activity. Routine monitoring is appropriate; immediate alerting is not warranted unless behavioral changes are observed.
---
Sources: IPDebrief Intelligence Platform
Data Freshness: Current as of 2026-07-30
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Cherry Servers NOC |
| ASN | AS16125 |
| Network Name | net-207177-284086-239806 |
| CIDR Block | 46.166.172.192/29 |
| RIR | RIPE |
| Country | LT |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | ip-46-166-172-194.009.ptr.cherryservers.net |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | ip-46-166-172-194.009.ptr.cherryservers.net |
π DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 β Basic operator with some routing infrastructure |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 37% | 2 | 4 |
| routing | 17% | 1 | 1 |
| services | 26% | 2 | 2 |
| ownership | 36% | 2 | 4 |
| reputation | 33% | 1 | 3 |
| geolocation | 24% | 2 | 2 |
| Overall | 29% | 10 | 16 |
| Data Coherence | Mostly Consistent (80%) β 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-07-27 22:38:35 UTC |
| Last Seen | 2026-08-03 05:37:12 UTC |
| Profile Built | 2026-08-03 09:10:53 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 40 |
Full dossier details are available via our API.