# IP INTELLIGENCE BRIEFING
Target: 89.189.62.36/32
Classification: Low Risk Infrastructure
Date: 2026-07-28
Analyst: IPDebrief Intelligence Division
---
## EXECUTIVE SUMMARY
IP address 89.189.62.36 operates as a low-risk web server infrastructure component within the Axera IP Network Department (ASN 34758). The asset demonstrates consistent legitimate behavior with no active threat indicators, minimal abuse density, and stable network characteristics. Recommended classification: Monitor (no immediate blocking required).
---
## RISK PROFILE
| Metric | Value | Assessment |
|---|---|---|
| Overall Risk Score | 25/100 | Low Risk |
| Provider Score | 0 | Standard |
| Authority Score | 0 | Standard |
| Stability Score | 0 | Standard |
| Abuse Confidence Score | N/A | Not Applicable |
| Blacklist Count | 0 | Clean |
---
## OWNERSHIP & NETWORK ATTRIBUTION
| Field | Value |
|---|---|
| Organization | Axera IP Network Department |
| Network Name | IT-TELEMAR-CUSTOMERS |
| ASN | 34758 |
| CIDR Block | 89.189.62.0/24 |
| RIR | RIPE |
| Country | United States (US-MA) |
| City | Boston |
| Abuse Contact | abuse@as34758.net |
---
## SERVICE & DNS CHARACTERISTICS
Network Services:
- Port 443/TCP (HTTPS) — Active
- HTTP Version: 1.1
- Status Code: 200
DNS Resolution:
- PTR Hostname: ip.89.189.62.36.axera.it
- Forward Resolution: Confirmed (1 hostname)
- Email Auth: SPF present, DMARC present
TLS Certificate:
- Issuer: CN=89.189.62.36
- SANs: fritz.box, www.fritz.box, fritzbox.internal, fritzbox.home.arpa, myfritz.box
- Certificate Type: Self-signed (non-production indicator)
- Certificate Status: Valid
Security Headers:
- CSP: `default-src 'none'; connect-src 'self'; font-src 'self'; frame-src https://service.avm.de https://fritzhelp.avm.de/help/ https://www.avm.de https://avm.de https://assets.avm.de https://clickonce.avm.d`
- Referrer Policy: `no-referrer, same-origin`
- X-Frame-Options: `SAMEORIGIN`
- Content-Type Options: `nosniff`
- HSTS: Not enabled
---
## THREAT INDICATORS
| Indicator | Status |
|---|---|
| Tor Exit Node | No |
| Known Attacker | No |
| Spam Source | No |
| Blacklist Presence | Clean (0 lists) |
| Known Campaigns | None |
| DNSBL Listed | 1/8 lists |
---
## GEOLOCATION VALIDATION
| Metric | Value |
|---|---|
| Claimed Location | Boston, US (45.6485°N, 11.6328°E) |
| Distance from Claimed | 839.4 km |
| Minimum Possible RTT | 16.79 ms |
| Average RTT | 122.6 ms |
| Geo Consensus | Plausible (5 probes) |
| Geo Source Count | 2 |
---
## OBSERVATION HISTORY (21 Observations)
Temporal Analysis:
- Total Observations: 21
- Ownership Changes: 0
- Threat Persistence Days: 0
- Is Persistently Malicious: False
- Most Recent Observation: 2026-07-28T22:59:57
Key Signals:
- Signal Type 10 (Ownership): No changes detected
- Signal Type 14 (Campaign): No matches
- Signal Type 12 (Web Fingerprint): Consistent AVM FritzBox web server signatures
- Signal Type 11 (Geo): Validated US location with plausible RTT
- Signal Type 4 (Network): Consistent RIPE allocation
Behavioral Trend: Stable infrastructure with consistent web server characteristics. No escalation in risk profile observed over observation period.
---
## NETWORK RELATIONSHIPS
Network Associations:
- IT-TELEMAR-CUSTOMERS (4 instances)
- Control plane origin: AS34758
- BGP Prefix: 89.189.56.0/21
DNS Associations:
- ip.89.189.62.36.axera.it (6 instances)
External Entity Links: None detected
---
## SUBNET NEIGHBORHOOD ANALYSIS
Subnet: 89.189.62.36/24
- Abuse Density: 0% (Clean)
- Classification: Clean
- Total Siblings: 1
- Active Siblings: 0
- Threat Siblings: 0
- Risk Distribution: No high/medium risk neighbors
Assessment: The /24 subnet demonstrates minimal abuse activity with no neighboring IPs flagged as threats.
---
## SECURITY ACTIONS & RECOMMENDATIONS
Risk Score: 25 (Low Risk)
Recommended Actions:
- No immediate blocking or firewall rules required
- Continue standard monitoring practices
- No WAF rules necessary based on current risk profile
Note: Recommendations are probabilistic and should be combined with other signals before taking action.
---
## INTELLIGENCE CONCLUSION
IP address 89.189.62.36 represents legitimate infrastructure within the Axera IP Network Department ecosystem. The asset functions as a web server for what appears to be a FritzBox device management interface (indicated by TLS SANs and web fingerprints). The subnet maintains clean security posture with no abuse indicators, and the IP shows no malicious behavior patterns in the observation history.
SOC Action: Standard monitoring. No immediate threat response required.
---
*Generated by IPDebrief Intelligence Platform*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | Axera IP Network Department |
| ASN | AS34758 |
| Network Name | IT-TELEMAR-CUSTOMERS |
| CIDR Block | 89.189.62.0/24 |
| RIR | RIPE |
| Country | IT |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | ip.89.189.62.36.axera.it |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | ip.89.189.62.36.axera.it |
🔐 DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | 2/12 domains |
| DMARC | 2/12 domains |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
| Domains Checked | 12 domains |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Web Server |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 443 | https | tcp | — |
| Closed Ports | 22, 25, 80, 3389, 8080, 8443 (1 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | fritz.boxwww.fritz.boxfritzbox.internalfritzbox.home.arpamyfritz.boxwww.myfritz.boxfritz.naswww.fritz.nas |
| Valid From | 1970-01-01T00:00:37+00:00 |
| Valid Until | 2038-01-16T00:00:37+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_128_GCM_SHA256 |
| Signature Algorithm | sha256RSA |
| Validity Period | 24852 days |
🛡️ Public Network Snapshot
| Origin ASN | AS34758 |
| Network Prefix | 89.189.56.0/21 |
| Route mapping | Found |
| HSTS | Not detected |
| CSP | Enabled |
| HTTP/2 | Not detected |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 34% | 2 | 6 |
| routing | 8% | 1 | 1 |
| services | 17% | 2 | 3 |
| ownership | 23% | 2 | 4 |
| reputation | 33% | 1 | 5 |
| geolocation | 28% | 2 | 3 |
| Overall | 24% | 10 | 22 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-19 18:10:18 UTC |
| Last Seen | 2026-09-05 19:05:43 UTC |
| Profile Built | 2026-09-05 19:10:04 UTC |
| Data Freshness | Live |
| Signal Types | 24 |
| Total Observations | 46 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 89.189.62.36
Who owns the IP address 89.189.62.36?
89.189.62.36 is registered to Axera IP Network Department. The address falls within the 89.189.62.0/24 network block. Registration is held at RIPE.
Where is 89.189.62.36 located?
Geolocation data places 89.189.62.36 in New York, US-NY, United States. The local time zone is America/New_York. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 89.189.62.36 malicious or safe?
89.189.62.36 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 89.189.62.36?
The reverse DNS (PTR) record for 89.189.62.36 is ip.89.189.62.36.axera.it. This hostname is not forward-confirmed, so it should be treated as a weak signal.
What ports are open on 89.189.62.36?
Responsive ports observed on 89.189.62.36 include 443. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.