# IP Intelligence Briefing: 89.231.35.49/32
## Executive Summary
IP address 89.231.35.49 is a Polish residential endpoint (ASN 21021, Arknet) with a moderate risk score of 55. No active threat indicators detected. The /24 subnet demonstrates mixed classification with 2 threat-sibling IPs and an abuse density of 0.286, warranting defensive monitoring.
## Profile Overview
| Attribute | Value |
|---|---|
| **IP Address** | 89.231.35.49/32 |
| **Risk Score** | 55 (Moderate Risk) |
| **ASN** | 21021 |
| **Organization** | Arknet (Arkadiusz Fialek) |
| **Country** | Poland (PL) |
| **City** | Sitno, West Pomerania |
| **Classification** | Residential, Firewalled/No Services |
| **DNS** | host-89-231-35-49.dynamic.mm.pl |
## Threat Assessment
- Threat Indicators: None detected
- Blacklist Status: 0 blacklists, but 3 DNSBL listings out of 8 total
- Tor/Proxy: Not a Tor exit node, not a known proxy
- Known Attacker: No
- Spam Source: No
- Active Services: No open ports detected (firewalled)
## Neighborhood Analysis (89.231.35.0/24)
The /24 subnet shows elevated abuse density with 8 total sibling IPs:
- High Risk Siblings: 2 (scores: 80, 80)
- Medium Risk Siblings: 5 (scores: 55)
- Low Risk Siblings: 0
- Abuse Density: 0.286 (28.6%)
- Active Siblings: 3
- Threat Siblings: 2
High-risk neighbors include:
- 89.231.35.27 (Risk: 80)
- 89.231.35.37 (Risk: 80)
## Observation History
24 observations recorded since 2026-06-05. Key findings:
- Subnet abuse density measured at 0.25 (mixed classification) on 2026-06-05
- Control plane routing signals show stable operator score of 0.1304
- No persistent malicious behavior detected
- Threat observation count: 1
- Ownership stability: 0 changes
## Network Relationships
51 relationships identified, primarily Same Network associations with Arknet infrastructure. No certificate matches or correlated campaign indicators.
## Recommended Actions
Given the moderate risk classification and neighborhood context:
1. Monitor traffic from this IP and adjacent high-risk siblings (89.231.35.27, 89.231.35.37)
2. Block if outbound connection attempts detected to internal assets
3. Correlate with any existing alerts from subnet neighbors
4. Review firewall rules for Arknet prefix 89.231.0.0/16 if policy requires
## Conclusion
IP 89.231.35.49 represents a residential endpoint with no direct threat indicators. However, the subnet environment demonstrates 28.6% abuse density, suggesting this IP may be co-located with malicious actors. SOC analysts should monitor for lateral movement patterns and consider blocking inbound connections from the broader /16 prefix if organizational policy mandates.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Arkadiusz Fialek |
| ASN | AS21021 |
| Network Name | โ |
| CIDR Block | 89.231.0.0/16 |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | host-89-231-35-49.dynamic.mm.pl |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | host-89-231-35-49.dynamic.mm.pl |
๐ DNS Hygiene
| Hygiene Score | 60% (Good) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 24% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 8% | 1 | 1 |
| ownership | 20% | 2 | 3 |
| reputation | 19% | 1 | 3 |
| geolocation | 27% | 2 | 3 |
| Overall | 19% | 9 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-08 17:18:21 UTC |
| Last Seen | 2026-06-25 10:14:34 UTC |
| Profile Built | 2026-06-25 10:31:52 UTC |
| Data Freshness | Live |
| Signal Types | 25 |
| Total Observations | 25 |
Full dossier details are available via our API.