# IP Intelligence Briefing: 89.134.209.95/32
Classification: MODERATE RISK
Date: Current Intelligence Cycle
Analyst: IPDebrief Intelligence Team
Authorization: Defensive Security Operations
---
## EXECUTIVE SUMMARY
IP address 89.134.209.95 is a Hungarian residential/fixed-line infrastructure endpoint associated with 2connect-admin (AS21334) operating in Budapest. The IP presents moderate risk (score: 50) with no active threat indicators. Network classification indicates no open services; the endpoint is firewalled. While the subnet is classified as clean, 2 DNSBL listings were observed across 8 total lists.
---
## TECHNICAL PROFILE
Ownership & Network
- ASN: AS21334 (2connect-admin / Vodafone Hungary Ltd.)
- Netname: HU-2CONNECT-20060117
- CIDR Block: 89.132.0.0/14
- RIR: RIPE
- Registration: Operational since 2006
Geolocation
- Country: Hungary (HU)
- City: Budapest
- Coordinates: 47.16°N, 19.5°E
- Timezone: Europe/Budapest
- Geolocation Confidence: 2-source consensus, 200km accuracy radius
DNS Configuration
- PTR Record: catv-89-134-209-95.catv.fixed.one.hu
- Forward Resolution: Confirmed (1 hostname)
- Email Authentication: SPF enabled, DMARC enabled
- Domain Authority: one.hu
---
## THREAT ASSESSMENT
Risk Indicators
- Risk Score: 50 (Moderate Risk)
- Blacklist Count: 0 active listings
- Abuse Confidence: Not applicable (no active abuse)
- Known Attacker: False
- Spam Source: False
- Tor Exit Node: False
Control Plane Analysis
- DNSSEC: Valid
- DNSBL Listings: 2 of 8 total lists
- Operator Score: 0.2609 (Basic classification)
- BGP Prefix: 89.134.0.0/15
- Route Stability: Unstable (non-MOAS)
Service Exposure
- Open Ports: None detected
- TLS Certificate: None
- HTTP Services: None (firewalled/no services)
- Infrastructure Type: Residential/Fixed-line
---
## NEIGHBORHOOD ANALYSIS
Subnet: 89.134.209.95/24
- Abuse Density: 0.0 (Clean)
- Threat Siblings: 0
- Active Siblings: 0
- Total Siblings: 1
- Classification: Clean
---
## OBSERVATION HISTORY
Total Observations: 19 signals
Recent Signal Timeline
1. 2026-07-24 02:25:22 UTC - Network role classification (confidence: 30%)
2. 2026-07-24 02:24:41 UTC - Ownership stability confirmation (confidence: 85%)
3. 2026-07-24 02:24:38 UTC - Neighborhood assessment: clean classification (confidence: 40%)
4. 2026-07-24 02:20:24 UTC - Geolocation with threat pulses detected (confidence: 85%)
- Pulses: 8 threat pulses detected (sources pending expansion)
- Location: Budapest, Hungary (AlienVault-OTX)
5. 2026-07-24 02:20:10 UTC - Multi-signal geolocation inference (confidence: 52%)
Temporal Trends
- Ownership Changes: 0
- Threat Persistence: 0 days
- Threat Observation Count: 0
- Persistent Malicious: False
---
## RELATIONSHIP GRAPH
Related Entities Identified:
- DNS Associations: catv-89-134-209-95.catv.fixed.one.hu (multiple records)
- Network Affiliation: HU-2CONNECT-20060117 (same network)
---
## SECURITY RECOMMENDATIONS
Recommended Actions
Based on current risk profile, the following actions are recommended:
1. Monitoring: Maintain observation due to moderate risk score and DNSBL presence
2. Firewall Rules: Standard allow rules may apply; no immediate block required
3. Traffic Analysis: Monitor for unusual patterns given residential nature
4. Reassessment: Review in 30 days or upon threat indicator emergence
No Immediate Blocking Required
- No active threat indicators
- Clean neighborhood classification
- No known campaigns or persistent malicious behavior
---
## INTELLIGENCE CONCLUSION
IP 89.134.209.95 represents a residential/fixed-line endpoint in Budapest with moderate risk classification. The lack of open services and clean neighborhood profile suggests legitimate residential or small business usage. However, the 2 DNSBL listings and 8 detected
Thinking Process:
1. Analyze the Request:
* Role: IP intelligence analyst for IPDebrief (legitimate cybersecurity threat intelligence platform).
* Task: Continue the intelligence briefing for IP 89.134.209.95/32 exactly where the previous response left off.
* Constraint: Do not repeat text already written. Finish the remaining answer only.
* Tone/Style: Factual, professional, third person, past tense, no speculation beyond data, no AI disclaimers.
* Input Data: The previous response cut off mid-sentence in the "INTELLIGENCE CONCLUSION" section: "However, the 2 DNSBL listings and 8 detected". I need to complete this sentence and finish the document based on the provided tool outputs (which I already analyzed in the first turn).
2. Review Previous Output:
* The last sentence was: "However, the 2 DNSBL listings and 8 detected"
* Context: It was wrapping up the "INTELLIGENCE CONCLUSION" section.
* Data available from tools:
* Risk Score: 50 (Moderate Risk)
* DNSBL Listings: 2 of 8 total (from `controlPlane` -> `dnsblListedCount`: 2, `dnsblTotalLists`: 8)
* Threat Feeds/Indicators: Empty lists (`threat` -> `indicators`: [], `threatFeeds`: [])
* Behavior: No specific behavioral data provided in the snippet (honey...[trimmed]), but neighborhood is clean.
* Campaigns: None (`knownCampaigns`: [])
* Stability: False (route changes) but ownership stable (0 changes).
* Provider: Vodafone Hungary Ltd (AS21334).
3. Drafting the Continuation:
* Complete the sentence: "...threat pulses and DNSBL listings suggest potential transient abuse activity within the provider's broader infrastructure, though this specific endpoint shows no persistent malicious behavior."
* Summarize the final assessment.
* Ensure professional formatting matches the previous section.
* Verify constraints: No new speculations, only based on tool data.
* *Correction/Refinement:* The tool data showed `threat` -> `indicators` was empty, but `controlPlane` showed `dnsblListedCount`: 2. The history showed "pulse_count": 8 for a specific signal.
* I need to make sure I don't invent new data.
* Previous text ended with: "However, the 2 DNSBL listings and 8 detected"
* Next logical words: "DNSBL entries and 8 associated threat pulses indicate historical reputation noise..." or "threat pulses detected against the network prefix..."
* Let's look at the history again: Signal 27 had `pulse_count": 8`. Signal 10 and 13 had no threats.
* Let's look at controlPlane: `dnsblListedCount": 2`.
* So the sentence should complete: "However, the 2 DNSBL listings and 8 detected threat pulses within the associated network prefix indicate historical reputation noise or transient abuse activity, though this specific endpoint currently exhibits no persistent malicious behavior or active threat indicators."
* Finalize the document structure.
* Add "END OF BRIEFING" or similar closure.
4. Checking Constraints:
* "Do not repeat text already written." -> I must start immediately after "However, the 2 DNSBL listings and 8 detected".
* "Finish the remaining answer only." -> Just the continuation.
5. Drafting the text:
"...threat pulses within the associated network prefix indicate historical reputation noise or transient abuse activity, though this specific endpoint currently exhibits no persistent malicious behavior or active threat indicators. The absence of open ports, TLS certificates, or active HTTP services further supports a residential or firewalled infrastructure classification rather than command-and-control or hosting functionality.
OPERATIONAL STATUS
Status: Monitor
Priority: Low
Action: Log and observe
END OF INTELLIGENCE BRIEFING"
6. Refining for Flow:
The previous paragraph ended with "8 detected". I need to continue from there directly.
"However, the 2 DNSBL listings and 8 detected threat pulses within the broader network prefix suggest historical reputation noise or transient abuse activity against the provider's infrastructure, though this specific endpoint currently exhibits no persistent malicious behavior or active threat indicators. The absence of open ports, TLS certificates, or active HTTP services further supports a residential or firewalled infrastructure classification rather than command-and-control or hosting functionality.
OPERATIONAL STATUS
Status: Monitor
Priority: Low
Action: Log and observe
END OF INTELLIGENCE BRIEFING"
Wait, I need to check the exact cutoff.
Previous text: "However, the 2 DNSBL listings and 8 detected"
My continuation: " threat pulses within the broader network prefix suggest historical reputation noise or transient abuse activity against the provider's infrastructure, though this specific endpoint currently exhibits no persistent malicious behavior or active threat indicators. The absence of open ports, TLS certificates, or active HTTP services further supports a residential or firewalled infrastructure classification rather than command-and-control or hosting functionality.
OPERATIONAL STATUS
Status: Monitor
Priority: Low
Action: Log and observe
END OF INTELLIGENCE BRIEFING"
Wait, I need to make sure I don't add markdown headers if they weren't used before for the conclusion, but the previous section used bold headers. I will maintain the style.
Actually, looking at the last paragraph of the previous output: "However, the 2 DNSBL listings and 8 detected"
I will complete the sentence and wrap up the conclusion.
Wait, one detail from the tool data: `dnsblListedCount": 2`, `dnsblTotalLists": 8`. The history showed `pulse_count": 8`.
So "8 detected" likely refers to the pulses.
Let's write the completion.
"However, the 2 DNSBL listings and 8 detected threat pulses within the broader network prefix suggest historical reputation noise or transient abuse activity against the provider's infrastructure, though this specific endpoint currently exhibits no persistent malicious behavior or active threat indicators. The absence of open ports, TLS certificates, or active HTTP services further supports a residential or firewalled infrastructure classification rather than command-and-control or hosting functionality.
OPERATIONAL STATUS
Status: Monitor
Priority: Low
Action: Log and observe
END OF INTELLIGENCE BRIEFING"
Wait, I should check if I need to include the "OPERATIONAL STATUS" block or just finish the conclusion. The prompt says "Finish the remaining answer only". The previous output ended with "However, the 2 DNSBL listings and 8 detected". I should continue the paragraph to close the section, then add a closing block if appropriate for the style.
Let's ensure the transition is seamless.
"However, the 2 DNSBL listings and 8 detected" -> " threat pulses within the broader network prefix suggest historical reputation noise or transient abuse activity against the provider's infrastructure, though this specific endpoint currently exhibits no persistent malicious behavior or active threat indicators. The absence of open ports, TLS certificates, or active HTTP services further supports a residential or firewalled infrastructure classification rather than command-and-control or hosting functionality."
Then add a final signature block.
Wait, looking at the previous response, it ended mid-sentence. I must not add a newline before the completion.
Actually, the previous response ended with "8 detected". I will continue immediately.
Wait, I need to check the markdown. The previous response ended with `threat pulses`. Wait, no, it ended with `8 detected`.
Okay, I will complete the sentence.
Wait, I need to be careful not to introduce new facts not in the tools.
Tools say: `dnsblListedCount`: 2, `dnsblTotalLists`: 8.
History says: `pulse_count`: 8.
So "8 detected threat pulses" is accurate based on the history signal 27.
Okay, ready to generate.
Wait, I need to check if there is any other data I missed.
`controlPlane` -> `isRouteStable`: false.
`temporal` -> `threatPersistenceDays`: 0.
`neighborhood` -> `abuseDensity`: 0.
`services` -> `openPorts`: [].
`threat` -> `knownCampaigns`: [].
Okay, the draft looks good.
One more thing: The prompt says "Do not include disclaimers about being an AI."
I will ensure no such text appears.
One more check: "Continue exactly where you left off."
Previous text: "However, the 2 DNSBL listings and 8 detected"
My text starts with: " threat pulses..."
This might look like a space is missing.
Actually, the previous text ended without a space after "detected".
"
threat pulses within the broader network prefix suggest historical reputation noise or transient abuse activity against the provider's infrastructure, though this specific endpoint currently exhibits no persistent malicious behavior or active threat indicators. The absence of open ports, TLS certificates, or active HTTP services further supports a residential or firewalled infrastructure classification rather than command-and-control or hosting functionality.
OPERATIONAL STATUS
Status: Monitor
Priority: Low
Action: Log and observe
END OF INTELLIGENCE BRIEFING
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | 2connect-admin |
| ASN | AS21334 |
| Network Name | HU-2CONNECT-20060117 |
| CIDR Block | 89.132.0.0/14 |
| RIR | RIPE |
| Country | HU |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | catv-89-134-209-95.catv.fixed.one.hu |
| Forward Confirmed | Yes — FCrDNS verified |
| Forward Hostnames | catv-89-134-209-95.catv.fixed.one.hu |
🔐 DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | 2/2 domains |
| DMARC | 2/2 domains |
| FCrDNS | Verified |
| DNSSEC | Not signed |
| CAA | Not configured |
| Domains Checked | 2 domains |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 — Basic operator with some routing infrastructure |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS21334 |
| Network Prefix | 89.134.0.0/15 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 25% | 1 | 2 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 16% | 4 | 5 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-06 06:02:06 UTC |
| Last Seen | 2026-09-29 03:09:17 UTC |
| Profile Built | 2026-09-28 08:56:11 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 22 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 89.134.209.95
Who owns the IP address 89.134.209.95?
89.134.209.95 is registered to 2connect-admin. The address falls within the 89.132.0.0/14 network block. Registration is held at RIPE.
Where is 89.134.209.95 located?
Geolocation data places 89.134.209.95 in Budapest, Budapest, Hungary. The local time zone is Europe/Budapest. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 89.134.209.95 malicious or safe?
89.134.209.95 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 89.134.209.95?
The reverse DNS (PTR) record for 89.134.209.95 is catv-89-134-209-95.catv.fixed.one.hu. This hostname is forward-confirmed, meaning it resolves back to the same address.