## Intelligence Briefing: 91.186.208.228/32
Target: 91.186.208.228/32
Classification: Low Risk / Passive Infrastructure
Reporting Date: 2026-07-27
Executive Summary
IP 91.186.208.228 is a low-risk, firewalled host in the FIRST-SERVER-NET-VL network (ASN 59432, FIRSTSERVER-FL-AS). Current risk score is 0 with no active threat indicators. The IP shows no open services, is not associated with known campaigns, and maintains a clean subnet classification. However, historical observations indicate past blacklist activity and geographic inconsistencies warrant continued monitoring.
Network Attribution
- ASN: 59432 (FIRSTSERVER-FL-AS)
- Organization: FIRST-SERVER-MNT
- Netblock: 91.186.208.0/24
- RIR: RIPE
- Geolocation: Discrepancies observed. Profile reports GB (London), but recent ASN and geolocation signals indicate GR (Greece, coordinates 37.9667°N, 23.7167°E).
- Infrastructure Type: Non-cloud, non-CDN, non-VPN, non-hosting. Service status: Firewalled / No Services.
Threat Assessment
- Risk Score: 0
- Provider/Authority Scores: 0
- Blacklist Status: 0 current listings (null abuse confidence)
- Known Campaigns: None detected
- Threat Feeds: No matches
- Is Tor Exit: No
- Is Known Attacker: No
- Is Spam Source: No
Behavioral Indicators
- Open Ports: None detected
- DNS Records: No PTR record, no forward resolution
- Email Auth: SPF and DMARC not configured
- Services: No HTTP/TLS services exposed
- Control Plane: Not a bogon, not MOAS, route stability flagged as false
Neighborhood Analysis
- Subnet: 91.186.208.0/24
- Abuse Density: 0 (clean classification)
- Total Siblings: 2
- Active Siblings: 0
- Threat Siblings: 0
- Elevated Neighbor: 91.186.208.115 (risk score: 25, authority score: 50) — warranting monitoring
Observation History (16 signals)
Recent signals include:
- Blacklist Activity: Multiple listings observed with high severity (signal type 2344)
- DNSSEC: Valid
- Geolocation Conflicts: Historical signals show GR attribution with significant distance from UK registration
- ICMP: Blocked (unable to validate reachability)
Recommended Actions
- Monitor Neighbor: 91.186.208.115 shows elevated risk (score 25); investigate relationship
- Geographic Discrepancy: Investigate routing/misconfiguration between GB registration and GR signals
- Historical Blacklists: Review past blacklist associations for context on IP origin
- No Immediate Block Required: No current threat indicators warranting blocking
Conclusion
This IP represents passive, firewalled infrastructure with no current malicious indicators. The geographic attribution conflict and historical blacklist activity suggest this subnet may have been repurposed or misconfigured. SOC analysts should monitor 91.186.208.115 (elevated risk neighbor) and investigate the origin of conflicting geolocation signals.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
🏢 Ownership & Registration
| Organization | FIRST-SERVER-MNT |
| ASN | AS204339 |
| Network Name | FIRST-SERVER-NET-VL |
| CIDR Block | 91.186.208.0/24 |
| RIR | RIPE |
| Country | FI |
| Abuse Contact | Available via RDAP |
🌐 DNS Intelligence
| PTR | vm4586121.firstbyte.club |
| Forward Confirmed | No — PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | vm4586121.firstbyte.club |
🔐 DNS Hygiene
| Hygiene Score | 20% (Poor) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Not configured |
☁️ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown — Insufficient routing data to classify |
🔌 Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | — |
| HTTP Title | — |
🔐 TLS Certificate
| SANs | None |
| Valid From | — |
| Valid Until | — |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha256RSA |
| Validity Period | 375 days |
🛡️ Public Network Snapshot
| Origin ASN | AS204339 |
| Network Prefix | 91.186.208.0/24 |
| Route mapping | Found |
🎯 Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 3 |
| routing | 8% | 1 | 1 |
| services | 27% | 2 | 4 |
| ownership | 17% | 2 | 3 |
| reputation | 8% | 1 | 2 |
| geolocation | 17% | 2 | 3 |
| Overall | 17% | 10 | 16 |
| Data Coherence | Mixed Signals (68%) — 2 contradiction(s) |
| Attribution | Low (35%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
⚠ TLS certificate claims IT but primary geo says FI
📅 Observation Timeline 🔄 Live
| First Seen | 2026-07-12 08:52:21 UTC |
| Last Seen | 2026-09-05 18:58:04 UTC |
| Profile Built | 2026-09-05 19:11:58 UTC |
| Data Freshness | Live |
| Signal Types | 26 |
| Total Observations | 35 |
Full dossier details are available via our API.
❓ Frequently Asked Questions About 91.186.208.228
Who owns the IP address 91.186.208.228?
91.186.208.228 is registered to FIRST-SERVER-MNT. The address falls within the 91.186.208.0/24 network block. Registration is held at RIPE.
Where is 91.186.208.228 located?
Geolocation data places 91.186.208.228 in London. The local time zone is Europe/Helsinki. IP geolocation is approximate and indicates the network's registered or routed location rather than a precise physical address.
Is 91.186.208.228 malicious or safe?
91.186.208.228 currently carries a low risk assessment, meaning no significant threat indicators have been observed. This assessment is generated from continuously collected signals and can change over time.
What is the hostname for 91.186.208.228?
The reverse DNS (PTR) record for 91.186.208.228 is vm4586121.firstbyte.club. This hostname is not forward-confirmed, so it should be treated as a weak signal.