IPDebrief

89.58.31.106

IP Intelligence Dossier
Your IP: 216.73.217.131
{ } JSON 🔧 Full Actions API
🤖 Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 89.58.31.106

## Executive Summary

IP address 89.58.31.106 presents a Low Risk profile with a risk score of 15. The address is associated with German hosting infrastructure operated by NETCUP and exhibits no active threat indicators. Current monitoring shows clean reputation with no blacklist associations.

## Network Ownership & Classification

## Threat Indicators

Control Plane Observations:

## DNS & Hostname Analysis

## Services & Port Scan Results

## Neighborhood Analysis (Subnet: 89.58.31.106/24)

## Historical Observations (18 signals tracked)

Temporal Trends:

Recent Signal Summary:

## Relationship Graph

## Recommended Security Actions

No specific firewall rules or blocking actions recommended. The IP exhibits low-risk characteristics with no active threat indicators. Standard monitoring and logging is sufficient.

## Risk Assessment Conclusion

IP 89.58.31.106 is classified as Low Risk based on current intelligence. Key findings include:

Monitoring Recommendation: Continue standard observation. No immediate action required.

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

Country🇩🇪 Germany
RegionBavaria
CityNuremberg
TimezoneEurope/Berlin
Latitude51.17
Longitude10.45

🏢 Ownership & Registration

OrganizationNETCUP-MNT
ASNAS197540
Network NameDE-NETCUP-20051123
CIDR Block89.58.0.0/18
RIRRIPE
CountryDE
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRserver8.1.serversnation.com
Forward ConfirmedNo — PTR hostname does not resolve back to this IP (weak signal)
Forward Hostnamesserver8.1.serversnation.com

🔐 DNS Hygiene

Hygiene Score60% (Good)
SPFPresent
DMARCPresent
FCrDNSNot verified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureUnknown
Service PurposeWeb Server
Network TierUnknown — Insufficient routing data to classify
No specific classification

🔌 Services & Open Ports

PortServiceProtocolBanner
80httptcp—
443httpstcp—
22sshtcpBanner detected
Closed Ports25, 3389, 8080, 8443 (3 open / 7 scanned)
ServerWeb server detected
HTTP Title—

🔐 TLS Certificate

A self-signed certificate was detected. This is common for development servers, internal services, or IoT devices.
⚠️
dnQualifier=openlitespeed, I=CP, name=openlitespeed, E=mail@openlitespeed.host, S=NJ, OU=Testing, O=LiteSpeedCommunity, L=Virtual, C=US, CN=openlitespeed.host
Issued by dnQualifier=openlitespeed, I=CP, name=openlitespeed, E=mail@openlitespeed.host, S=NJ, OU=Testing, O=LiteSpeedCommunity, L=Virtual, C=US, CN=openlitespeed.host
Self-signed: Yes
SANsNone
Valid From2026-05-25T11:36:36+00:00
Valid Until2028-08-22T11:36:36+00:00
TLS ProtocolTls13
Cipher SuiteTLS_AES_256_GCM_SHA384
Signature Algorithmsha256RSA
Validity Period820 days

🛡️ Public Network Snapshot

Origin ASNAS197540
Network Prefix89.58.28.0/22
Route mappingFound
HSTSNot detected
CSPNot detected
HTTP/2Enabled

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
31%
23
routing
8%
11
services
23%
22
ownership
17%
23
reputation
8%
12
geolocation
28%
23
Overall19%1014
Coverage: 4/6 dimensions · Data sufficiency: partial
Data CoherenceMixed Signals (68%) — 2 contradiction(s)
AttributionLow (35%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid
⚠ Geo sources disagree on country: US, DE
⚠ TLS certificate claims US but primary geo says DE

📅 Observation Timeline 🔄 Live

First Seen2026-07-08 00:51:54 UTC
Last Seen2026-09-13 19:23:44 UTC
Profile Built2026-09-13 19:33:52 UTC
Data FreshnessLive
Signal Types24
Total Observations29
🔍 24 signal types · 29 observations collected
This report is generated from 24+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API 🔧 Actions API 📧 Enterprise Access

❓ Frequently Asked Questions About 89.58.31.106

Who owns the IP address 89.58.31.106?

89.58.31.106 is registered to NETCUP-MNT. The address falls within the 89.58.0.0/18 network block. Registration is held at RIPE.

Where is 89.58.31.106 located?

Geolocation data places 89.58.31.106 in Nuremberg, Bavaria, Germany. The local time zone is Europe/Berlin. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.

Is 89.58.31.106 malicious or safe?

89.58.31.106 currently carries a moderate risk assessment, meaning some indicators warrant caution, but the evidence is mixed. This assessment is generated from continuously collected signals and can change over time.

What is the hostname for 89.58.31.106?

The reverse DNS (PTR) record for 89.58.31.106 is server8.1.serversnation.com. This hostname is not forward-confirmed, so it should be treated as a weak signal.

What ports are open on 89.58.31.106?

Responsive ports observed on 89.58.31.106 include 80, 443, 22. Port visibility reflects the most recent scan and may change as the host's configuration or firewall rules change.

🏘️ Related IP Addresses

Nearby addresses in 89.58.0.0/18

Browse related networks

ℹ️ About This Report

All data shown is publicly available network metadata — IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.