# IP Intelligence Briefing: 66.116.224.33/32
Date: 2026-07-28
Classification: Moderate Risk
Prepared For: SOC Analyst
## Executive Summary
Target IP 66.116.224.33 is a web server infrastructure endpoint operating under PDR Solutions FZC administrator (ASN 31898). The IP presents moderate risk (score: 65) with evidence of blacklist presence across 3 of 8 monitored DNS blacklists. No active threat campaigns or known attacker indicators detected.
## Ownership and Network Context
| Attribute | Value |
|---|---|
| Organization | PDR Solutions FZC administrator |
| ASN | 31898 |
| CIDR Block | 66.116.128.0/17 |
| Geolocation | Disputed (AE/India) |
| Service Purpose | Web Server |
| Network Role | Infrastructure |
## Technical Profile
Active Services:
- Port 80/TCP: HTTP (nginx/1.18.0)
- Port 443/TCP: HTTPS (Let's Encrypt certificate)
- Port 22/TCP: SSH (OpenSSH_8.9p1 Ubuntu-3ubuntu0.16)
DNS Resolution:
- PTR Hostname: server.girhoney.com
- Forward Resolution: server.girhoney.com (1 record)
- SPF: Configured (present)
- DMARC: Not configured
HTTP Fingerprint:
- Generator: Odoo CMS
- Server: nginx/1.18.0 (Ubuntu)
- HTTP Version: 1.1
- Response Time: ~1201ms
## Threat Indicators
| Indicator | Status |
|---|---|
| Known Attacker | Not detected |
| Tor Exit Node | No |
| Spam Source | Not flagged |
| Blacklist Count | 3 |
| DNSBL Listed | Yes (3/8 lists) |
| Campaign Association | None |
## Risk Trend Analysis
Observation History: 19 total observations recorded
- Recent subnet classification: Clean
- Threat sibling count: 0
- Ownership changes: 0
- Persistently malicious: No
- Threat persistence days: 0
The IP has demonstrated stability with no significant risk escalation over the observation period.
## Neighborhood Assessment
Subnet: 66.116.224.0/24
- Neighbors analyzed: 3
- Abuse density: 0
- Risk distribution: 3 low-risk, 0 medium, 0 high
Neighbor IPs:
- 66.116.224.58: Risk 25 (Low)
- 66.116.224.143: Risk 25 (Low)
- 66.116.224.161: Risk 0 (Low)
## Recommended Actions
Based on the moderate risk profile and blacklist presence, the following defensive measures are recommended:
1. Monitor SSH traffic (port 22) for unauthorized access attempts
2. Review DNSBL listings to determine source of blacklist entries
3. Investigate geolocation discrepancy (AE country code vs India city coordinates)
4. Block if legitimate business purpose for girhoney.com domain cannot be verified
## Conclusion
IP 66.116.224.33 represents infrastructure-level risk rather than active threat activity. The moderate risk score is primarily driven by blacklist presence rather than observed malicious behavior. No immediate blocking required unless the organization operates girhoney.com and requires strict business-justified traffic policy.
Status: Monitor with logging; no immediate threat action required.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | PDR Solutions FZC administrator |
| ASN | AS31898 |
| Network Name | PDRSOLUTIONSFZC-AP |
| CIDR Block | 66.116.128.0/17 |
| RIR | ARIN |
| Country | AE |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | server.girhoney.com |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | server.girhoney.com |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | 7/14 domains |
| DMARC | 0/14 domains |
| FCrDNS | Not verified |
| DNSSEC | Not signed |
| CAA | Not configured |
| Domains Checked | 14 domains |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | — |
| 443 | https | tcp | — |
| 22 | ssh | tcp | Banner detected |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | Web server detected |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | girhoney.comwww.girhoney.com |
| Valid From | 2026-07-12T10:10:33+00:00 |
| Valid Until | 2026-10-10T10:10:32+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 89 days |
🛡️ Public Network Snapshot
| Origin ASN | AS31898 |
| Network Prefix | 66.116.224.0/22 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Not detected |
| HTTP/2 | Not detected |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 23% | 2 | 3 |
| ownership | 17% | 2 | 3 |
| reputation | 8% | 1 | 2 |
| geolocation | 15% | 2 | 2 |
| Overall | 16% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-17 17:13:21 UTC |
| Last Seen | 2026-09-29 20:37:30 UTC |
| Profile Built | 2026-09-25 08:22:01 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 40 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 66.116.224.33
Who owns the IP address 66.116.224.33?
66.116.224.33 is registered to PDR Solutions FZC administrator. The address falls within the 66.116.128.0/17 network block. Registration is held at ARIN.
Where is 66.116.224.33 located?
Geolocation data places 66.116.224.33 in Mumbai, Maharashtra, United Arab Emirates. The local time zone is Asia/Dubai. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 66.116.224.33 malicious or safe?
66.116.224.33 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 66.116.224.33?
The reverse DNS (PTR) record for 66.116.224.33 is server.girhoney.com. This hostname is not forward-confirmed, so it should be treated as a weak signal.
What ports are open on 66.116.224.33?
Responsive ports observed on 66.116.224.33 include 80, 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.