# IP Intelligence Briefing: 46.30.42.155/32
Date: Analysis Complete
Analyst: IPDebrief Intelligence Team
Classification: Operational Intelligence
## Executive Summary
IP address 46.30.42.155/32 presents moderate risk (score: 50/100) with no active threat indicators. The IP is associated with EUROBYTE-NET infrastructure in Amsterdam, Netherlands, and shows evidence of being firewalled with no accessible services. While the IP itself is classified as clean, the recommended defensive posture is to block due to moderate risk classification.
## Technical Profile
Ownership & Registration:
- ASN: 216139 (EUROBYTE-MNT)
- Organization: EUROBYTE-NET
- Network Block: 46.30.42.0/24
- RIR: RIPE
- Registration Contact: Available via RDAP
Geolocation:
- Country: Netherlands (NL)
- Region: North Holland
- City: Amsterdam
- Coordinates: 52.13°N, 5.29°E
- Accuracy Radius: 225 km
Network Classification:
- Service Purpose: Firewalled / No Services
- Infrastructure Type: Unknown
- Classification Flags: Not cloud, CDN, VPN, proxy, Tor, hosting, mobile, residential, bogon, or anycast
- Open Ports: None detected
## Threat Assessment
Current Threat Indicators:
- Threat Score: Moderate Risk (50/100)
- Known Attacker: No
- Spam Source: No
- Tor Exit Node: No
- Blacklist Count: 0
- DNSBL Lists: 2/8
- Known Campaigns: None
Observed Signals:
- No threat indicators detected in threat feed data
- No persistent malicious activity observed
- No correlated IPs in campaign analysis
- No certificate matches or banner matches
## DNS & Email Analysis
DNS Records:
- PTR Hostname: vm667621.eurodir.ru
- Forward Resolution: vm667621.eurodir.ru
- Hosted Domains: None
- Forward Resolution Count: 1
Email Authentication:
- SPF Record: Not configured
- DMARC Record: Not configured
- TXT Record Count: 0
Control Plane:
- DNSSEC Valid: Yes
- Operator Score: 0.1304 (Minimal)
- Route Stability: False
- Route Changes (30 days): 0
- MoAS: No
## Neighborhood Analysis
Subnet: 46.30.42.0/24
- Total Sibling IPs: 2
- Active Siblings: 0
- Threat Siblings: 0
- Abuse Density: 0 (Clean)
- Classification: Clean
Neighbor IP Assessment:
- 46.30.42.34: Risk Score 25 (Low)
- Authority Score: 50
## Historical Observation
Observation Count: 18 signals recorded
Time Range: Recent observation window
Key Historical Signals:
- Geolocation inference consistent (Netherlands, Amsterdam)
- Subnet classification stable (clean)
- Ownership changes: 0
- Threat persistence days: 0
- Is Persistently Malicious: No
Trend Analysis: No significant changes in risk posture observed over the observation period.
## Relationship Graph
Network Relationships:
- Multiple associations to EUROBYTE-NET network
DNS Associations:
- vm667621.eurodir.ru (6 relationships)
## Recommended Security Actions
Firewall Recommendations:
- iptables: DROP traffic from 46.30.42.155
- nftables: DROP rule for saddr 46.30.42.155
- nginx: deny directive for the IP
- pfSense: Block 46.30.42.155/32
- Cloudflare WAF: Block with description "IPDebrief risk score 50"
- AWS WAF: Block with description "IPDebrief risk 50"
Risk-Based Decision Matrix:
- Block Recommendation: Yes (Risk Score 50)
- Monitoring Required: Low priority
- Investigation Priority: Medium
## Intelligence Assessment
The IP 46.30.42.155 is a residential or business endpoint associated with EUROBYTE-NET infrastructure. While currently showing no active malicious behavior, the moderate risk score warrants defensive blocking. The IP is firewalled with no accessible services, suggesting it may be an endpoint behind a NAT or firewall. The associated domain (eurodir.ru) lacks proper email authentication configuration. The subnet shows low abuse density with only one sibling IP present, indicating a relatively quiet network segment.
Priority Level: Medium
Recommended Action: Block with monitoring
Review Period: 30 days
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | EUROBYTE-MNT |
| ASN | AS216139 |
| Network Name | EUROBYTE-NET |
| CIDR Block | 46.30.42.0/24 |
| RIR | RIPE |
| Country | NL |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | vm667621.eurodir.ru |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | vm667621.eurodir.ru |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-07-30 04:59:22 UTC |
| Last Seen | 2026-08-01 01:42:33 UTC |
| Profile Built | 2026-07-31 01:32:14 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 21 |
Full dossier details are available via our API.