Threat Intelligence Briefing: IP Address 89.238.165.238/32
Overview:
The IP address 89.238.165.238/32 was observed during a recent analysis conducted by IPDebrief. This address is associated with a range of activities and entities based on collected data, providing insights into its potential security implications.
Observation History:
- The IP address 89.238.165.238 has been linked to several online services and platforms. Over time, data indicates varied usage patterns, including both legitimate and potentially malicious activity.
- Historical data points to associations with email services, suggesting possible utilization in communication or spam activities.
- The address has been noted in logs from multiple threat intelligence sources, indicating potential engagement in activities that may warrant further investigation.
Entity Associations:
- Organizational Links: The IP address is registered to an entity that operates within the technology and communication sector. This association suggests that the address could be used for legitimate business operations, although the presence of mixed activity necessitates caution.
- Service Providers: Connections with known cloud service providers have been observed, indicating that the address might be part of infrastructure used for hosting or distributing services.
Relationships and Network Analysis:
- Related IPs and Domains: The IP address shares network infrastructure with other addresses and domains that have been flagged in past analyses for hosting malicious content or engaging in suspicious activities.
- Neighborhood Data: Analysis of neighboring IP addresses reveals a mix of legitimate business operations alongside known malicious actors, suggesting a potentially compromised environment or shared hosting scenario.
Security Implications:
- Potential Risks: Given the mixed nature of activities associated with this IP, there is a risk of encountering phishing attempts, malware distribution, or other cyber threats originating from this address.
- Actionable Insights: SOC teams should monitor traffic to and from this IP address, applying appropriate filtering and inspection measures to mitigate potential threats. Continuous monitoring for changes in activity patterns is recommended.
Recommendations:
- Implement network monitoring tools to track communication patterns involving this IP.
- Cross-reference with existing threat intelligence feeds to update security measures.
- Consider blocking or restricting traffic from this IP if malicious activity is confirmed.
This intelligence briefing provides a comprehensive view of the IP address 89.238.165.238/32, offering actionable insights for SOC analysts to enhance network security posture.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | M247-EU-MNT |
| ASN | AS9009 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
๐ DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
โ๏ธ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Single-Service Host |
| Network Tier | Unknown โ Insufficient routing data to classify |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 8443 | https-alt | tcp | โ |
| Closed Ports | 22, 25, 80, 443, 3389, 8080 (1 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 20% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 24% | 2 | 3 |
| reputation | 19% | 1 | 3 |
| geolocation | 19% | 2 | 2 |
| Overall | 18% | 10 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-07 23:04:41 UTC |
| Last Seen | 2026-06-24 00:31:59 UTC |
| Profile Built | 2026-06-24 00:41:41 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 21 |
Full dossier details are available via our API.