# IP Intelligence Briefing: 91.105.32.220/32
Classification: Low Risk / No Active Threat Indicators
Date: July 27, 2026
Analyst: IPDebrief SOC Team
---
## Executive Summary
IP 91.105.32.220 is classified as Low Risk with a risk score of 0. The address belongs to ASN 12578 (LTC Hostmaster / TET-HOME) and shows no active threat indicators, blacklist listings, or malicious campaign associations. No security action recommendations are generated at this time.
---
## Ownership and Network Infrastructure
| Attribute | Value |
|---|---|
| **ASN** | 12578 |
| **Organization** | LTC Hostmaster (TET-HOME) |
| **CIDR Block** | 91.105.0.0/18 |
| **RIR** | RIPE |
| **Abuse Contact** | abuse@tet.lv |
Control Plane: BGP prefix 91.105.0.0/17 with 0 route changes observed in 30 days. DNSSEC validation is enabled. Operator score rated as "Minimal" (0.1304).
---
## Geolocation Analysis
Primary Location: Frankfurt, Germany (DE)
- Confidence: Multiple geo sources with consensus validation
- Accuracy: High (geoPlausible: true)
Notable Observation: Historical signals detected from Latvia (Riga), indicating potential geo-inconsistency or multi-region routing. Minimum RTT measured at 140ms from Frankfurt.
Traceroute: 13 hops with 1 timeout. Transit through Comcast networks observed.
---
## Threat Profile
Current Status: Clean
- Risk Score: 0
- Abuse Confidence Score: None
- Blacklist Count: 0
- Threat Feeds: None populated
Malicious Activity Indicators:
- Not a known attacker
- Not a spam source
- Not a Tor exit node
- Not a proxy or VPN
- Not hosting infrastructure
- No WAF violations detected
Campaign Correlation: No matching certificates, no correlated IPs, no known campaign associations.
---
## Network Role and Services
Classification: Firewalled / No Services
- Open Ports: None detected
- TLS Certificates: None
- HTTP Services: None
- DNS Resolution: No PTR records, no forward resolution
- Email Reputation: Not configured (no SPF/DMARC records)
Behavioral Analysis:
- Zero honeypot hits
- Zero enumeration strikes
- Zero total incidents
- No persistently malicious behavior observed
---
## Neighborhood Analysis (91.105.32.0/24)
| Metric | Value |
|---|---|
| **Subnet Abuse Density** | 0% |
| **Classification** | Clean |
| **Total Siblings** | 1 |
| **Active Siblings** | 0 |
| **Threat Siblings** | 0 |
No neighboring IPs with elevated risk scores detected in the /24 subnet.
---
## Observation History (16 Signals)
Recent activity concentrated on July 27, 2026:
- Ownership signals (RIPE, LTC Hostmaster): Confidence 90-95%
- Geolocation signals (Latvia/Germany): Confidence 75%
- Network role signals: Confidence 30-60%
Temporal analysis shows no ownership changes and zero threat persistence days.
---
## Intelligence Narrative
IP 91.105.32.220 represents a standard residential/business broadband allocation under LTC Hostmaster's TET-HOME network. The address shows no evidence of compromise or malicious activity. While geolocation signals indicate routing through both Germany and Latvia, the IP itself maintains a clean threat profile with no blacklist associations.
The subnet (91.105.32.0/24) demonstrates minimal abuse density, suggesting this is not a targeted or compromised network segment. The IP's classification as "Firewalled / No Services" indicates it is likely an end-user address with no publicly accessible services.
Recommended Action: Standard monitoring only. No firewall rules or blocking recommended at this time.
---
## SOC Analyst Notes
- No immediate threat action required
- Monitor for changes in geolocation consistency
- Subnet-level abuse density remains at baseline
- Historical signals show stable, benign behavior
*End of Briefing*
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | LTC Hostmaster |
| ASN | AS12578 |
| Network Name | TET-HOME |
| CIDR Block | 91.105.0.0/18 |
| RIR | RIPE |
| Country | LV |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
🛡️ Public Network Snapshot
| Origin ASN | AS12578 |
| Network Prefix | 91.105.0.0/17 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 27% | 2 | 4 |
| routing | 8% | 1 | 1 |
| services | 12% | 2 | 2 |
| ownership | 17% | 2 | 3 |
| reputation | 20% | 1 | 3 |
| geolocation | 12% | 2 | 2 |
| Overall | 16% | 10 | 15 |
| Data Coherence | Mostly Consistent (80%) — 1 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-12 08:52:21 UTC |
| Last Seen | 2026-09-02 23:24:01 UTC |
| Profile Built | 2026-09-02 23:30:27 UTC |
| Data Freshness | Live |
| Signal Types | 20 |
| Total Observations | 26 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 91.105.32.220
Who owns the IP address 91.105.32.220?
91.105.32.220 is registered to LTC Hostmaster. The address falls within the 91.105.0.0/18 network block. Registration is held at RIPE.
Where is 91.105.32.220 located?
Geolocation data places 91.105.32.220 in Frankfurt, Jelgava, Germany. The local time zone is Europe/Berlin. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 91.105.32.220 malicious or safe?
91.105.32.220 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.