IPDebrief

89.134.209.95

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 89.134.209.95/32

Classification: MODERATE RISK

Date: Current Intelligence Cycle

Analyst: IPDebrief Intelligence Team

Authorization: Defensive Security Operations

---

## EXECUTIVE SUMMARY

IP address 89.134.209.95 is a Hungarian residential/fixed-line infrastructure endpoint associated with 2connect-admin (AS21334) operating in Budapest. The IP presents moderate risk (score: 50) with no active threat indicators. Network classification indicates no open services; the endpoint is firewalled. While the subnet is classified as clean, 2 DNSBL listings were observed across 8 total lists.

---

## TECHNICAL PROFILE

Ownership & Network

Geolocation

DNS Configuration

---

## THREAT ASSESSMENT

Risk Indicators

Control Plane Analysis

Service Exposure

---

## NEIGHBORHOOD ANALYSIS

Subnet: 89.134.209.95/24

---

## OBSERVATION HISTORY

Total Observations: 19 signals

Recent Signal Timeline

1. 2026-07-24 02:25:22 UTC - Network role classification (confidence: 30%)

2. 2026-07-24 02:24:41 UTC - Ownership stability confirmation (confidence: 85%)

3. 2026-07-24 02:24:38 UTC - Neighborhood assessment: clean classification (confidence: 40%)

4. 2026-07-24 02:20:24 UTC - Geolocation with threat pulses detected (confidence: 85%)

- Pulses: 8 threat pulses detected (sources pending expansion)

- Location: Budapest, Hungary (AlienVault-OTX)

5. 2026-07-24 02:20:10 UTC - Multi-signal geolocation inference (confidence: 52%)

Temporal Trends

---

## RELATIONSHIP GRAPH

Related Entities Identified:

---

## SECURITY RECOMMENDATIONS

Recommended Actions

Based on current risk profile, the following actions are recommended:

1. Monitoring: Maintain observation due to moderate risk score and DNSBL presence

2. Firewall Rules: Standard allow rules may apply; no immediate block required

3. Traffic Analysis: Monitor for unusual patterns given residential nature

4. Reassessment: Review in 30 days or upon threat indicator emergence

No Immediate Blocking Required

---

## INTELLIGENCE CONCLUSION

IP 89.134.209.95 represents a residential/fixed-line endpoint in Budapest with moderate risk classification. The lack of open services and clean neighborhood profile suggests legitimate residential or small business usage. However, the 2 DNSBL listings and 8 detected

Thinking Process:

1. Analyze the Request:

* Role: IP intelligence analyst for IPDebrief (legitimate cybersecurity threat intelligence platform).

* Task: Continue the intelligence briefing for IP 89.134.209.95/32 exactly where the previous response left off.

* Constraint: Do not repeat text already written. Finish the remaining answer only.

* Tone/Style: Factual, professional, third person, past tense, no speculation beyond data, no AI disclaimers.

* Input Data: The previous response cut off mid-sentence in the "INTELLIGENCE CONCLUSION" section: "However, the 2 DNSBL listings and 8 detected". I need to complete this sentence and finish the document based on the provided tool outputs (which I already analyzed in the first turn).

2. Review Previous Output:

* The last sentence was: "However, the 2 DNSBL listings and 8 detected"

* Context: It was wrapping up the "INTELLIGENCE CONCLUSION" section.

* Data available from tools:

* Risk Score: 50 (Moderate Risk)

* DNSBL Listings: 2 of 8 total (from `controlPlane` -> `dnsblListedCount`: 2, `dnsblTotalLists`: 8)

* Threat Feeds/Indicators: Empty lists (`threat` -> `indicators`: [], `threatFeeds`: [])

* Behavior: No specific behavioral data provided in the snippet (honey...[trimmed]), but neighborhood is clean.

* Campaigns: None (`knownCampaigns`: [])

* Stability: False (route changes) but ownership stable (0 changes).

* Provider: Vodafone Hungary Ltd (AS21334).

3. Drafting the Continuation:

* Complete the sentence: "...threat pulses and DNSBL listings suggest potential transient abuse activity within the provider's broader infrastructure, though this specific endpoint shows no persistent malicious behavior."

* Summarize the final assessment.

* Ensure professional formatting matches the previous section.

* Verify constraints: No new speculations, only based on tool data.

* *Correction/Refinement:* The tool data showed `threat` -> `indicators` was empty, but `controlPlane` showed `dnsblListedCount`: 2. The history showed "pulse_count": 8 for a specific signal.

* I need to make sure I don't invent new data.

* Previous text ended with: "However, the 2 DNSBL listings and 8 detected"

* Next logical words: "DNSBL entries and 8 associated threat pulses indicate historical reputation noise..." or "threat pulses detected against the network prefix..."

* Let's look at the history again: Signal 27 had `pulse_count": 8`. Signal 10 and 13 had no threats.

* Let's look at controlPlane: `dnsblListedCount": 2`.

* So the sentence should complete: "However, the 2 DNSBL listings and 8 detected threat pulses within the associated network prefix indicate historical reputation noise or transient abuse activity, though this specific endpoint currently exhibits no persistent malicious behavior or active threat indicators."

* Finalize the document structure.

* Add "END OF BRIEFING" or similar closure.

4. Checking Constraints:

* "Do not repeat text already written." -> I must start immediately after "However, the 2 DNSBL listings and 8 detected".

* "Finish the remaining answer only." -> Just the continuation.

5. Drafting the text:

"...threat pulses within the associated network prefix indicate historical reputation noise or transient abuse activity, though this specific endpoint currently exhibits no persistent malicious behavior or active threat indicators. The absence of open ports, TLS certificates, or active HTTP services further supports a residential or firewalled infrastructure classification rather than command-and-control or hosting functionality.

OPERATIONAL STATUS

Status: Monitor

Priority: Low

Action: Log and observe

END OF INTELLIGENCE BRIEFING"

6. Refining for Flow:

The previous paragraph ended with "8 detected". I need to continue from there directly.

"However, the 2 DNSBL listings and 8 detected threat pulses within the broader network prefix suggest historical reputation noise or transient abuse activity against the provider's infrastructure, though this specific endpoint currently exhibits no persistent malicious behavior or active threat indicators. The absence of open ports, TLS certificates, or active HTTP services further supports a residential or firewalled infrastructure classification rather than command-and-control or hosting functionality.

OPERATIONAL STATUS

Status: Monitor

Priority: Low

Action: Log and observe

END OF INTELLIGENCE BRIEFING"

Wait, I need to check the exact cutoff.

Previous text: "However, the 2 DNSBL listings and 8 detected"

My continuation: " threat pulses within the broader network prefix suggest historical reputation noise or transient abuse activity against the provider's infrastructure, though this specific endpoint currently exhibits no persistent malicious behavior or active threat indicators. The absence of open ports, TLS certificates, or active HTTP services further supports a residential or firewalled infrastructure classification rather than command-and-control or hosting functionality.

OPERATIONAL STATUS

Status: Monitor

Priority: Low

Action: Log and observe

END OF INTELLIGENCE BRIEFING"

Wait, I need to make sure I don't add markdown headers if they weren't used before for the conclusion, but the previous section used bold headers. I will maintain the style.

Actually, looking at the last paragraph of the previous output: "However, the 2 DNSBL listings and 8 detected"

I will complete the sentence and wrap up the conclusion.

Wait, one detail from the tool data: `dnsblListedCount": 2`, `dnsblTotalLists": 8`. The history showed `pulse_count": 8`.

So "8 detected" likely refers to the pulses.

Let's write the completion.

"However, the 2 DNSBL listings and 8 detected threat pulses within the broader network prefix suggest historical reputation noise or transient abuse activity against the provider's infrastructure, though this specific endpoint currently exhibits no persistent malicious behavior or active threat indicators. The absence of open ports, TLS certificates, or active HTTP services further supports a residential or firewalled infrastructure classification rather than command-and-control or hosting functionality.

OPERATIONAL STATUS

Status: Monitor

Priority: Low

Action: Log and observe

END OF INTELLIGENCE BRIEFING"

Wait, I should check if I need to include the "OPERATIONAL STATUS" block or just finish the conclusion. The prompt says "Finish the remaining answer only". The previous output ended with "However, the 2 DNSBL listings and 8 detected". I should continue the paragraph to close the section, then add a closing block if appropriate for the style.

Let's ensure the transition is seamless.

"However, the 2 DNSBL listings and 8 detected" -> " threat pulses within the broader network prefix suggest historical reputation noise or transient abuse activity against the provider's infrastructure, though this specific endpoint currently exhibits no persistent malicious behavior or active threat indicators. The absence of open ports, TLS certificates, or active HTTP services further supports a residential or firewalled infrastructure classification rather than command-and-control or hosting functionality."

Then add a final signature block.

Wait, looking at the previous response, it ended mid-sentence. I must not add a newline before the completion.

Actually, the previous response ended with "8 detected". I will continue immediately.

Wait, I need to check the markdown. The previous response ended with `threat pulses`. Wait, no, it ended with `8 detected`.

Okay, I will complete the sentence.

Wait, I need to be careful not to introduce new facts not in the tools.

Tools say: `dnsblListedCount`: 2, `dnsblTotalLists`: 8.

History says: `pulse_count`: 8.

So "8 detected threat pulses" is accurate based on the history signal 27.

Okay, ready to generate.

Wait, I need to check if there is any other data I missed.

`controlPlane` -> `isRouteStable`: false.

`temporal` -> `threatPersistenceDays`: 0.

`neighborhood` -> `abuseDensity`: 0.

`services` -> `openPorts`: [].

`threat` -> `knownCampaigns`: [].

Okay, the draft looks good.

One more thing: The prompt says "Do not include disclaimers about being an AI."

I will ensure no such text appears.

One more check: "Continue exactly where you left off."

Previous text: "However, the 2 DNSBL listings and 8 detected"

My text starts with: " threat pulses..."

This might look like a space is missing.

Actually, the previous text ended without a space after "detected".

"

threat pulses within the broader network prefix suggest historical reputation noise or transient abuse activity against the provider's infrastructure, though this specific endpoint currently exhibits no persistent malicious behavior or active threat indicators. The absence of open ports, TLS certificates, or active HTTP services further supports a residential or firewalled infrastructure classification rather than command-and-control or hosting functionality.

OPERATIONAL STATUS

Status: Monitor

Priority: Low

Action: Log and observe

END OF INTELLIGENCE BRIEFING

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇭🇺 Hungary
RegionBudapest
CityBudapest
TimezoneEurope/Budapest
Latitude47.16
Longitude19.50

🏢 Ownership & Registration

Organization2connect-admin
ASNAS21334
Network NameHU-2CONNECT-20060117
CIDR Block89.132.0.0/14
RIRRIPE
CountryHU
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRcatv-89-134-209-95.catv.fixed.one.hu
Forward ConfirmedYes — FCrDNS verified
Forward Hostnamescatv-89-134-209-95.catv.fixed.one.hu

🔐 DNS Hygiene

Hygiene Score60% (Good)
SPF2/2 domains
DMARC2/2 domains
FCrDNSVerified
DNSSECNot signed
CAANot configured
Domains Checked2 domains

☁️ Network Classification

InfrastructureUnknown
Service PurposeFirewalled / No Services
Network TierTier 3 — Basic operator with some routing infrastructure
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Server—
HTTP Title—

🔐 TLS Certificate

🔒
No certificate
Issued by —
N/A
SANsNone
Valid From—
Valid Until—

🛡️ Public Network Snapshot

Origin ASNAS21334
Network Prefix89.134.0.0/15
Route mappingFound

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
25%
11
routing
25%
11
services
25%
11
ownership
25%
12
reputation
0%
00
geolocation
0%
00
Overall16%45
Coverage: 4/6 dimensions · Data sufficiency: partial
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

📅 Observation Timeline 🔄 Live

First Seen2026-07-06 06:02:06 UTC
Last Seen2026-09-29 03:09:17 UTC
Profile Built2026-09-28 08:56:11 UTC
Data FreshnessLive
Signal Types21
Total Observations22
🔍 21 signal types · 22 observations collected
This report is generated from 21+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 89.134.209.95

Who owns the IP address 89.134.209.95?

89.134.209.95 is registered to 2connect-admin. The address falls within the 89.132.0.0/14 network block. Registration is held at RIPE.

Where is 89.134.209.95 located?

Geolocation data places 89.134.209.95 in Budapest, Budapest, Hungary. The local time zone is Europe/Budapest. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 89.134.209.95 malicious or safe?

89.134.209.95 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.

What is the hostname for 89.134.209.95?

The reverse DNS (PTR) record for 89.134.209.95 is catv-89-134-209-95.catv.fixed.one.hu. This hostname is forward-confirmed, meaning it resolves back to the same address.

🏘️ Related IP Addresses

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.