# IP INTELLIGENCE BRIEFING: 84.32.104.50/32
Date: 2026-07-27
Classification: Low Risk
Risk Score: 25/100
Provider Score: 0/100
Authority Score: 0/100
---
## EXECUTIVE SUMMARY
IP address 84.32.104.50 presents a low-risk profile with a score of 25/100. The IP is registered under the netutils-mnt organization within the RIPE RIR registry and operates within the 84.32.104.0/24 subnet. No active threat indicators, known campaigns, or abuse patterns were detected during analysis. The IP is currently firewalled with no open services.
---
## NETWORK OWNERSHIP & REGISTRATION
- ASN: 59642
- Organization: netutils-mnt
- CIDR Block: 84.32.104.0/24
- RIR: RIPE
- Abuse Contact: Available via RDAP
- Abuse Email: report@abuseradar.com
---
## GEOLOCATION ANALYSIS
Current geolocation data indicates New York, United States (US-NY), with timezone America/New_York. However, historical observations revealed conflicting geolocation signals, including Amsterdam, Netherlands (North Holland). This geographic inconsistency warrants periodic monitoring. Multiple geolocation sources were employed, with consensus achieved on the primary location.
---
## DNS & EMAIL REPUTATION
- PTR Hostname: ip-84-32-104-50.001.ptr.cherryservers.net
- Forward Resolution: ip-84-32-104-50.001.ptr.cherryservers.net
- Hosted Domain: cherryservers.net
- SPF Record: Present
- DMARC Record: Not configured
- DNSBL Status: Listed on 1 of 8 DNSBL checks
The IP resolves to a hostname under the cherryservers.net infrastructure. Email authentication is partially configured with SPF but lacks DMARC implementation.
---
## NETWORK BEHAVIOR & SERVICES
- Open Ports: None detected
- Service Status: Firewalled / No Services
- TLS Certificate: None
- HTTP Title: None
- Connection Type: No active services responding
The IP presents no open ports or active services, indicating either a firewalled configuration or passive infrastructure.
---
## THREAT INDICATORS
No threat indicators were observed:
- Tor Exit Node: No
- Known Attacker: No
- Spam Source: No
- Blacklist Count: 0 (general blacklist)
- Known Campaigns: None
- Threat Feeds: None
- Is Proxy: No
- Is Cloud: No
- Is CDN: No
- Is Hosting: No
---
## NETWORK CONTEXT
- Subnet Abuse Density: 0/100
- Neighbor Count: 0
- High-Risk Neighbors: 0
- Medium-Risk Neighbors: 0
- Low-Risk Neighbors: 0
- Threat Siblings: 0
The immediate /24 subnet shows no abuse activity or neighboring threat indicators, suggesting isolated operation.
---
## OBSERVATION HISTORY
Fifteen signal observations were recorded. Key temporal signals include:
- 2026-07-27T18:10:48: Provider classification signal (confidence 0.30)
- 2026-07-27T18:10:31: Geolocation signal showing Netherlands (confidence 0.70)
- 2026-07-27T18:09:26: Organization and ASN signals from RIPE registry
- 2026-07-27T18:09:15: Operator score assessment (Basic, score 0.2609)
Historical data shows no persistent malicious activity pattern. The IP is not classified as persistently malicious.
---
## NETWORK TRAVERSAL & INFRASTRUCTURE
- Traceroute Hops: 30
- Timed Out Hops: 19
- First Hop RTT: 0.2ms
- Last Hop RTT: 95.1ms
- Transit Network: Comcast
Network path shows 19 dropped hops during traceroute, indicating potential network filtering or measurement issues.
---
## SECURITY ACTIONS & RECOMMENDATIONS
No specific security actions or firewall rules were generated due to the low-risk profile. The IP's risk score of 25/100 combined with no active threat indicators supports standard monitoring without blocking.
Recommended Monitoring Actions:
- Monitor for emergence of open services
- Track geolocation consistency
- Watch for DNSBL listing changes
- Review DMARC configuration implementation
---
## CONCLUSION
IP 84.32.104.50 represents a low-risk infrastructure asset with no active malicious indicators. The primary observation is geographic inconsistency in historical data, which should be monitored. No immediate action or blocking is required based on current intelligence. Standard network monitoring practices are sufficient.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | netutils-mnt |
| ASN | AS59642 |
| Network Name | NET-84-32-104-0-24 |
| CIDR Block | 84.32.104.0/24 |
| RIR | RIPE |
| Country | LT |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | ip-84-32-104-50.001.ptr.cherryservers.net |
| Forward Confirmed | Yes — FCrDNS verified |
| Forward Hostnames | ip-84-32-104-50.001.ptr.cherryservers.net |
🔐 DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Not configured |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 — Basic operator with some routing infrastructure |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS59642 |
| Network Prefix | 84.32.104.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Moderate (55%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-14 15:51:32 UTC |
| Last Seen | 2026-09-02 22:34:37 UTC |
| Profile Built | 2026-09-02 22:40:01 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 23 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 84.32.104.50
Who owns the IP address 84.32.104.50?
84.32.104.50 is registered to netutils-mnt. The address falls within the 84.32.104.0/24 network block. Registration is held at RIPE.
Where is 84.32.104.50 located?
Geolocation data places 84.32.104.50 in New York, US-NY, United States. The local time zone is America/New_York. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 84.32.104.50 malicious or safe?
84.32.104.50 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 84.32.104.50?
The reverse DNS (PTR) record for 84.32.104.50 is ip-84-32-104-50.001.ptr.cherryservers.net. This hostname is forward-confirmed, meaning it resolves back to the same address.